Predefined search fields and values
The following tables display the search fields with predefined values, grouped by category:
Field name | Description | Predefined values |
---|---|---|
| The type of operation that was performed on the file. |
|
| The type of operation involved in changing a file attribute. |
|
| The type of object that was accessed or modified. |
|
Field name | Description | Predefined values |
---|---|---|
| The type of technology that generated the alert. |
|
| Describes the type of alert that was generated. |
|
| Describes the type of scan that triggered the alert. |
|
| Actions taken on the file. |
|
Field name | Description | Predefined values |
---|---|---|
| The direction of the network traffic. |
|
Field name | Description | Predefined values |
---|---|---|
| The integrity of the process. |
|
| The integrity of the parent process. |
|
| Indicates with what privileges the process ran. |
|
process.parent_access_privileges | Indicates with what privileges the parent process ran. |
|
Field name | Description | Predefined values |
---|---|---|
| The type of data access. |
|
| The type of registry data. |
|
Field name | Description | Predefined values |
---|---|---|
| The type of user who performed the operation. |
|
Field name | Definition | Predefined values |
---|---|---|
| The following values indicate the type of user who accessed the mailbox. |
|
Field name | Description | Predefined values |
---|---|---|
| The name of the event. | For a complete list of event names and their description, please refer to XEDR event names. |
| The type of operating system. |
|
| The type of the event. |
|
| The type of detection. |
|
| The sensor that generated the alert. |
|
| The type of architecture of the operating system. |
|
| Indicates that the activity was a Microsoft 365 compliance center event. |
|
| Indicates whether the action was successful or not. |
|