Corelight_v3_rdp_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: KQL validation test schema

Column Name Type
auth_success bool
cert_count long
cert_permanent bool
cert_type string
channels_joined int
client_build string
client_channels dynamic
client_dig_product_id string
client_name string
cookie string
desktop_height long
desktop_width long
encryption_level string
encryption_method string
id_orig_h string
id_orig_p int
id_resp_h string
id_resp_p int
inferences dynamic
keyboard_layout string
path string
rdfp_hash string
rdfp_string string
rdpeudp_uid string
requested_color_depth string
result string
security_protocol string
system_name string
TimeGenerated datetime
ts datetime
Type string
uid string
write_ts datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (4)

Workbooks (4)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Data_Explorer
Corelight_Data_Insights
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_rdp Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index