Corelight_v2_http_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (36 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
_write_ts_t datetime
host_s string
id_orig_h_s string
id_orig_p_d real
id_resp_h_s string
id_resp_p_d real
info_code_d real
info_msg_s string
method_s string
orig_filenames_s string
orig_fuids_s string
orig_mime_types_s string
origin_s string
password_s string
post_body_s string
proxied_s string
referrer_s string
request_body_len_d real
resp_filenames_s string
resp_fuids_s string
resp_mime_types_s string
response_body_len_d real
sid string
status_code_d real
status_msg_s string
tags_s string
TimeGenerated datetime
trans_depth_d real
ts_t datetime
uid_s string
uri_s string
user_agent_s string
username_s string
version_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (15)

Analytic Rules (6)

In solution Corelight:

Analytic Rule Selection Criteria
Corelight - External Proxy Detected
Corelight - Multiple Compressed Files Transferred over HTTP
Corelight - Multiple files sent over HTTP with abnormal requests
Corelight - Possible Typo Squatting or Punycode Phishing HTTP Request
Corelight - Possible Webshell
Corelight - Possible Webshell (Rare PUT or POST)

Hunting Queries (5)

In solution Corelight:

Hunting Query Selection Criteria
Corelight - Compressed Files Transferred over HTTP
Corelight - File uploads by source
Corelight - Obfuscated binary filenames
Corelight - Rare PUT or POST
Corelight - Top sources of data transferred

Workbooks (4)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Alert_Aggregations
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_http Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index