Corelight_v2_files_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (29 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
_write_ts_t datetime
analyzers_s string
conn_uids_s string
depth_d real
duration_d real
extracted_cutoff_b bool
extracted_s string
extracted_size_d real
filename_s string
fuid_s string
is_orig_b bool
local_orig_b bool
mime_type_s string
missing_bytes_d real
overflow_bytes_d real
parent_fuid_s string
rx_hosts_s string
seen_bytes_d real
sha1_s string
sha256_s string
sid string
source_s string
timedout_b bool
TimeGenerated datetime
total_bytes_d real
ts_t datetime
tx_hosts_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (5)

Hunting Queries (1)

In solution Corelight:

Hunting Query Selection Criteria
Corelight - Files in logs

Workbooks (4)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Alert_Aggregations
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_files Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index