Corelight_v2_x509_red_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (26 columns)

Source: KQL validation test schema

Column Name Type
_path_s string
_system_name_s string
_write_ts_t datetime
basic_constraints_ca_b bool
basic_constraints_path_len_d real
certificate_curve_s string
certificate_exponent_s string
certificate_issuer_s string
certificate_key_alg_s string
certificate_key_length_d real
certificate_key_type_s string
certificate_not_valid_after_t datetime
certificate_not_valid_before_t datetime
certificate_serial_s string
certificate_sig_alg_s string
certificate_subject_s string
certificate_version_d real
client_cert_b bool
fingerprint_s string
host_cert_b bool
san_dns_s string
san_email_s string
san_ip_s string
san_uri_s string
TimeGenerated datetime
ts_t datetime

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (4)

Workbooks (4)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Alert_Aggregations
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (2)

Other Parsers (2)

Parser Solution Selection Criteria
corelight_x509 Corelight
corelight_x509_red Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index