Corelight_v3_files_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (37 columns)

Source: KQL validation test schema

Column Name Type
analyzers dynamic
conn_uids dynamic
depth long
duration real
extracted string
extracted_cutoff bool
extracted_size long
filename string
fuid string
id_orig_h string
id_orig_p int
id_resp_h string
id_resp_p int
is_orig bool
local_orig bool
md5 string
mime_type string
missing_bytes long
num real
overflow_bytes long
parent_fuid string
path string
rx_hosts dynamic
seen_bytes long
sha1 string
sha256 string
source string
system_name string
timedout bool
TimeGenerated datetime
total_bytes long
ts datetime
tx_hosts dynamic
Type string
uid string
vlan real
write_ts datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (4)

Hunting Queries (1)

In solution Corelight:

Hunting Query Selection Criteria
Corelight - Files in logs

Workbooks (3)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_files Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index