Schema: Network Activity
Network connections, DNS queries, HTTP requests, and TLS sessions. Includes source/destination IPs, domains, geolocation, DNS resolution chains, HTTP user agents, and TLS certificates.
37 fields available
[← Back to Schema Field Reference](schema-field-reference-guide.md)
destination.network_endpoint.domain
destination.network_endpoint.domainDomain name of the destination endpoint.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
destination.network_endpoint.ip
destination.network_endpoint.ipIP address of the destination endpoint.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
destination.network_endpoint.isp
destination.network_endpoint.ispInternet service provider associated with the destination endpoint. Mirrors source.network_endpoint.isp. Defender reports the literal "Internal" for on-premise destinations such as a domain controller. Not yet populated: the only IMs mapping it (Defender IdentityDirectoryEvents) are inactive.
Providers: Not specified
destination.network_endpoint.location.country
destination.network_endpoint.location.countryCountry of the destination endpoint geolocation. Mirrors source.network_endpoint.location.country for events whose geolocation describes the endpoint being acted upon rather than the actor, such as Defender IdentityDirectoryEvents where the only address in the payload is the domain controller. Not yet populated: the only IMs mapping it (Defender IdentityDirectoryEvents) are inactive.
Providers: Not specified
destination.network_endpoint.mac
destination.network_endpoint.macMAC address of the destination endpoint as observed on the local segment. Only populated when the reporting host shares a layer-2 broadcast domain with the peer; routed traffic reports the gateway MAC instead. Defender emits the sentinel values 12:34:56:78:9a:bc and 00:aa:bb:cc:dd:ee as placeholders -- exclude both when using this field.
Providers: azure_event_hub,microsoft_defender
destination.network_endpoint.port
destination.network_endpoint.portPort number of the destination endpoint.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
destination.network_endpoint.public_ip
destination.network_endpoint.public_ipPublic (NAT) address of the monitored endpoint that was externally scanned. Belongs to the same endpoint as destination.network_endpoint.ip, which carries its private address. OCSF has no public/NAT address attribute on network_endpoint, so this is a NOCSF extension placed on the endpoint it describes.
Providers: azure_event_hub,microsoft_defender
destination.network_endpoint.public_port
destination.network_endpoint.public_portPort reached on the externally scanned public address of the monitored endpoint. Typed Int64 to match destination.network_endpoint.port.
Providers: azure_event_hub,microsoft_defender
dns.question.class
dns.question.classDNS query class field from the DNS protocol. C_INTERNET (IN) indicates standard internet DNS queries and is present in nearly all modern DNS requests. Other classes (CH for CHAOS, HS for Hesiod) are rare. Microsoft Defender provides human-readable names, CrowdStrike uses numeric codes.
Providers: crowdstrike,sentinel_one,microsoft_defender
dns.question.name
dns.question.nameThe domain name or hostname requested in the DNS query. Forward lookups contain FQDNs (browser.events.data.msn.com), reverse lookups contain in-addr.arpa PTR format (13.33.82.16.in-addr.arpa). This is the QUESTION section of the DNS protocol - what the client is trying to resolve.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
dns.question.type
dns.question.typeDNS record type being queried. Common types: 1 (A/IPv4), 28 (AAAA/IPv6), 5 (CNAME), 12 (PTR/reverse lookup), 15 (MX/mail), 16 (TXT), 33 (SRV/service), 65 (HTTPS). CrowdStrike/Elastic use numeric codes, Microsoft Defender may use names. PTR queries (12) indicate reverse DNS lookups. HTTPS queries (65) are used for modern encrypted DNS resolution.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
dns.rcode
dns.rcodeDNS response code name returned for the query, for example NOERROR, NXDOMAIN or SERVFAIL. A raised per-host NXDOMAIN rate is the primary signal for DGA and DNS tunnelling. Named rcode to match the OCSF DNS Activity class attribute.
Providers: azure_event_hub,microsoft_defender
dns_answers
dns_answersArray of IP addresses (IPv4/IPv6) returned in the DNS ANSWER section. Contains the resolved IPs for A (1) and AAAA (28) record queries. Empty/null for failed queries, CNAME-only responses, or non-address record types (MX, TXT, SRV). Check dns_cnames for CNAME resolution chains. For reverse PTR lookups, this field is typically empty - the hostname is in the ANSWER section but not captured here.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
dns_cnames
dns_cnamesArray of CNAME (Canonical Name) records in the DNS resolution chain. Shows domain aliases before final IP resolution (e.g., api.example.com → cdn.cloudprovider.com → final IPs in dns_answers). Order represents resolution chain. Useful for identifying CDN usage, domain fronting, and tracking infrastructure dependencies. Empty when query directly resolves to IPs without aliases.
Providers: crowdstrike,sentinel_one,microsoft_defender
http_request.http_method
http_request.http_methodHTTP request method. Named http_method to match the OCSF http_request object attribute.
Providers: azure_event_hub,microsoft_defender
http_request.url.path
http_request.url.pathRequest URI or path from the HTTP request line. OCSF models http_request.url as a url object, so the path is addressed as url.path; url.hostname and url.query_string remain available for future mappings.
Providers: azure_event_hub,microsoft_defender
http_request.url.url_string
http_request.url.url_stringAbsolute request URL including scheme, host and query string. Matches the OCSF url object attribute url_string. Use this rather than http_request.url.path when the source carries a full URL -- Defender Graph audit RequestUri is absolute, whereas the Zeek HTTP inspection uri is a path.
Providers: Not specified
http_request.user.name
http_request.user.nameAccount name presented in HTTP authentication, for example HTTP Basic. Never contains the password.
Providers: azure_event_hub,microsoft_defender
http_request.user_agent
http_request.user_agentHTTP user agent string from the request.
Providers: okta,duo,crowdstrike,microsoft_defender,gcp_pubsub
http_response.code
http_response.codeHTTP response status code returned for the request. Lives on the OCSF http_response object, not http_request.
Providers: azure_event_hub,microsoft_defender
network.direction
network.directionDirection of the network traffic. Values derived during normalization (e.g., egress, ingress, loopback).
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
network.protocol
network.protocolTransport protocol. Defender and CrowdStrike report protocol names, which are lowercased to tcp, udp or icmp during normalization; Defender's address-family variants (TcpV4, TcpV6, UdpV4, UdpV6, IcmpV4, IcmpV6) fold to the same value, so a filter on tcp matches all of them. Jamf Protect is different: it maps socket_protocol unchanged, so this field holds IANA protocol NUMBERS as strings for that provider -- 6 (TCP), 17 (UDP), 1 (ICMP), 58 (ICMPv6). A consumer matching on 'tcp' must handle '6' as well, or scope the query by provider. Values outside both sets pass through as the vendor emitted them -- Defender Kerberos, Jamf Apple Fabric.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
network.type
network.typeNetwork boundary or type classification. Known values: Loopback, Public, Private, FourToSixMapping, LinkLocal.
Providers: crowdstrike,sentinel_one,microsoft_defender
source.network_endpoint.ip
source.network_endpoint.ipIP address of the source endpoint.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic,okta,gcp_pubsub
source.network_endpoint.isp
source.network_endpoint.ispInternet service provider associated with the source endpoint.
Providers: okta,microsoft_defender,azure_event_hub
source.network_endpoint.location.city
source.network_endpoint.location.cityCity of the source endpoint geolocation.
Providers: okta
source.network_endpoint.location.country
source.network_endpoint.location.countryCountry of the source endpoint geolocation.
Providers: okta,microsoft_defender,azure_event_hub
source.network_endpoint.location.lat
source.network_endpoint.location.latLatitude of the source endpoint geolocation.
Providers: okta
source.network_endpoint.location.long
source.network_endpoint.location.longLongitude of the source endpoint geolocation.
Providers: okta
source.network_endpoint.location.state
source.network_endpoint.location.stateGeo State of the network endpoint
Providers: okta
source.network_endpoint.mac
source.network_endpoint.macMAC address of the source endpoint as observed on the local segment. Only populated when the reporting host shares a layer-2 broadcast domain with the peer; routed traffic reports the gateway MAC instead. Defender emits the sentinel values 12:34:56:78:9a:bc and 00:aa:bb:cc:dd:ee as placeholders -- exclude both when using this field.
Providers: azure_event_hub,microsoft_defender
source.network_endpoint.network_proxy.ip
source.network_endpoint.network_proxy.ipExternal/public-facing IP address of the endpoint agent as seen by the EDR cloud (NAT or proxy IP). CrowdStrike: aip field.
Providers: crowdstrike
source.network_endpoint.port
source.network_endpoint.portPort number of the source endpoint.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
tls.certificate.issuer
tls.certificate.issuerIssuer distinguished name of the server certificate. Reveals internal and rogue certificate authorities.
Providers: azure_event_hub,microsoft_defender
tls.certificate.subject
tls.certificate.subjectSubject distinguished name of the server certificate. Equal to tls.certificate.issuer on a self-signed certificate.
Providers: azure_event_hub,microsoft_defender
tls.cipher
tls.cipherNegotiated TLS cipher suite. Suites naming RC4 or MD5 indicate a weak negotiation.
Providers: azure_event_hub,microsoft_defender
tls.version
tls.versionNegotiated TLS protocol version, for example TLSv10, TLSv12 or TLSv13. TLSv10 and TLSv11 are deprecated by RFC 8996.
Providers: azure_event_hub,microsoft_defender
Updated 1 day ago