Corelight_v3_corelight_metrics_zeek_doctor_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (21 columns)

Source: KQL validation test schema

Column Name Type
check_bursty_percent real
check_dns_half_duplex_orig_percent real
check_dns_half_duplex_resp_percent real
check_local_to_local_percent real
check_remote_to_remote_percent real
check_tcp_backscatter_percent real
check_tcp_byte_counts_wrong_percent real
check_tcp_checksum_errors_percent real
check_tcp_half_duplex_percent real
check_tcp_missed_bytes_percent real
check_tcp_no_service_on_443_percent real
check_tcp_no_ssl_on_443_percent real
check_tcp_no_three_way_handshake_percent real
check_tcp_retransmissions_percent real
check_tcp_scan_percent real
path string
system_name string
TimeGenerated datetime
ts datetime
Type string
write_ts datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (1)

Workbooks (1)

In solution Corelight:

Workbook Selection Criteria
Corelight_Operations

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_corelight_metrics_zeek_doctor Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index