Key
|
Value
|
Usage
|
source
|
The domain (pod name) of the event source (Source name).
|
In all events
|
src
|
One of the following IP addresses in an IPv4 network (Source IP):
- for network traffic – the IP address of the connection source
- for administration events – the IP address of the action initiator
|
In all events
|
reason
|
Description of the Reason of the Error status.
|
In all events with the Error status, except PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
fname
|
Image or artifact name (Artifact name)
|
CI-ХХХ , SJ-ХХХ , ADM-ХХХ , CVE-ХХХ , MLW-ХХХ , SD-ХХХ , MS-ХХХ , CMP-001 , PLC-ХХХ , NCMP-001
|
suser
|
The name of the user that initiated the action (Username)
|
In all events except PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
dpid
|
Process identifier (PID)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
spid
|
Parent process identifier (PPID)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
flexString1
|
Effective Group Identifier (EGID)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
flexString2
|
Container ID
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
outcome
|
Execution status or mode (Status) The value is defined as follows:
- For runtime events (
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX ), the execution mode (Audit, Enforce, or Other) is specified.
- For other events, the execution status is specified (Success or Error). If the status is Error, the solution also transfers the error text or code (
reason ). |
In all events
|
request
|
Image name
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
fileHash
|
Image digest
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
act
|
One of the following operation types (Operation):
- for file operations – the type of operation (
open , close , read , write , create , delete , chmod , chown , rename )
- for network traffic – direction and type of traffic (
egress , ingress , egress_response , ingress_response )
- for processes – the
exec value
- for File Threat Protection operations – the
ftp value |
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
spt
|
Source port
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
dst
|
IP address of the destination in the IPv4 network (Destination IP)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
dpt
|
Destination port
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
dproc
|
Process name (command)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
duid
|
Effective User Identifier (EUID)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
filePermission
|
File access permissions (mode_t mode )
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
oldFilePath
|
Previously used file path (Old File Path)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
filePath
|
Path to the file (Path)
For events involving access to objects in the file system of a container, filePath is used to pass information about the new path to the file (New File Path).
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
deviceDirection
|
Connection type (Traffic type)
0 for ingress connections, 1 for egress connections.
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cn1
|
New process identifier (New PID)
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs1
|
Cluster name
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs2
|
Node name
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs3
|
Namespace name
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs4
|
Executed command (Command)
For events involving access to objects in the file system of a container, cs4 is used to pass information about the new owner of the file (NewOwner).
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs5
|
Pod name
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs6
|
Container name
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|
cs7
|
Node IP
|
PM-ХХХ , FM-ХХХ , NT-ХХХ , FPM-XXX , FNT-XXX , FFM-XXX , FFTP-XXX
|