Corelight_v2_rdp_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (32 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
_write_ts_t datetime
auth_success_b bool
cert_count_d real
cert_permanent_b bool
cert_type_s string
channels_joined_d real
client_build_s string
client_channels_s string
client_dig_product_id_s string
client_name_s string
cookie_s string
desktop_height_d real
desktop_width_d real
encryption_level_s string
encryption_method_s string
id_orig_h_s string
id_orig_p_d real
id_resp_h_s string
id_resp_p_d real
inferences_s string
keyboard_layout_s string
rdfp_hash_s string
rdfp_string_s string
rdpeudp_uid_s string
requested_color_depth_s string
result_s string
security_protocol_s string
TimeGenerated datetime
ts_t datetime
uid_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (4)

Workbooks (4)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Alert_Aggregations
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_rdp Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index