Corelight_v2_pe_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (21 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
_write_ts_t datetime
compile_ts_t datetime
has_cert_table_b bool
has_debug_data_b bool
has_export_table_b bool
has_import_table_b bool
id_s string
is_64bit_b bool
is_exe_b bool
machine_s string
os_s string
section_names_s string
subsystem_s string
TimeGenerated datetime
ts_t datetime
uses_aslr_b bool
uses_code_integrity_b bool
uses_dep_b bool
uses_seh_b bool

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (3)

Workbooks (3)

In solution Corelight:

Workbook Selection Criteria
Corelight_Alert_Aggregations
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_pe Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index