In the search query, you can enter the alias, or abbreviated term, for a field name rather than entering the full name. For the fields shown in the following table, you can also use the presentable field names, such as Agent Address. Search suggests presentable names.
Field |
Aliases |
---|---|
agentAddress |
|
agentHostName |
ahost |
agentId |
aid |
agentMacAddress |
|
agentReceiptTime |
art |
agentTimeZone |
atz |
agentTranslatedAddress |
agent translated ip |
agentType |
at |
agentVersion |
av |
applicatonProtocol |
|
baseEventCount |
cnt |
bytesIn |
in |
bytesOut |
out |
categoryBehavior |
behavior |
categoryDeviceGroup |
device group |
categoryObject |
object |
categorySignificance |
significance |
categoryTechnique |
technique |
destinationAddress |
|
destinationHostName |
|
destinationMacAddress |
|
destinationNtDomain |
dntdom |
destinationPort |
|
destinationProcessId |
dpid |
destinationProcessName |
dproc |
destinationTranslatedAddress |
destination translated ip |
destinationuserId |
duid |
destinationUserName |
|
destinationUserPrivileges |
dpriv |
deviceAction |
act |
deviceAddress |
|
deviceCustomFloatingPointn
|
cfpn For example: cfp1 |
deviceCustomFloatingPointnLabel
|
cfpnLabel For example: cfp1Label |
deviceCustomIPv6Addressn
|
For example: c6a2 |
deviceCustomIPv6AddressnLabel
|
c6anLabel For example: c6a2Label |
deviceCustomNumbern
|
cnn For example: cn3 |
deviceCustomNumbernLabel
|
cnnLabel For example: cn6Label |
deviceCustomStringn
|
Csn For example: Cs5 |
deviceEventCategory |
cat |
deviceHostName |
dvchost |
deviceMacAddress |
|
deviceProcessId |
dvcpid |
deviceReceiptTime |
rt |
deviceTimeZone |
dtz |
deviceTranslatedAddress |
device translated ip |
endTime |
end |
eventOutcome |
outcome |
fileNme |
fname |
fileSize |
fsize |
message |
msg |
requestUrl |
|
sourceAddress |
|
sourceHostName |
shost |
sourceMacAddress |
|
sourceNtDomain |
sntdomain |
sourcePort |
|
sourceProcessId |
spid |
sourceProcessName |
sproc |
sourceTranslatedAddress |
source translated ip |
sourceUserId |
suid |
sourceuserName |
|
sourceUserPrivileges |
spriv |
startTime |
start |
transportProtocol |
proto |