File tree Expand file tree Collapse file tree 4 files changed +12
-0
lines changed Expand file tree Collapse file tree 4 files changed +12
-0
lines changed Original file line number Diff line number Diff line change @@ -10,6 +10,10 @@ This event is generated when a file is renamed.
1010| Field |
1111| ---|
1212| @timestamp |
13+ | Effective_process.entity_id |
14+ | Effective_process.executable |
15+ | Effective_process.name |
16+ | Effective_process.pid |
1317| agent.id |
1418| agent.type |
1519| agent.version |
Original file line number Diff line number Diff line change @@ -118,6 +118,8 @@ This is an internal state management document that includes metrics on Endpoint'
118118| Endpoint.metrics.system_impact.registry_events.week_ms |
119119| Endpoint.metrics.system_impact.threat_intelligence_events.week_idle_ms |
120120| Endpoint.metrics.system_impact.threat_intelligence_events.week_ms |
121+ | Endpoint.metrics.system_impact.win32k_events.week_idle_ms |
122+ | Endpoint.metrics.system_impact.win32k_events.week_ms |
121123| Endpoint.metrics.threads.cpu.mean |
122124| Endpoint.metrics.threads.name |
123125| Endpoint.metrics.uptime.endpoint |
Original file line number Diff line number Diff line change @@ -15,6 +15,10 @@ identification:
1515fields :
1616 endpoint :
1717 - ' @timestamp'
18+ - Effective_process.entity_id
19+ - Effective_process.executable
20+ - Effective_process.name
21+ - Effective_process.pid
1822 - agent.id
1923 - agent.type
2024 - agent.version
Original file line number Diff line number Diff line change @@ -125,6 +125,8 @@ fields:
125125 - Endpoint.metrics.system_impact.registry_events.week_ms
126126 - Endpoint.metrics.system_impact.threat_intelligence_events.week_idle_ms
127127 - Endpoint.metrics.system_impact.threat_intelligence_events.week_ms
128+ - Endpoint.metrics.system_impact.win32k_events.week_idle_ms
129+ - Endpoint.metrics.system_impact.win32k_events.week_ms
128130 - Endpoint.metrics.threads.cpu.mean
129131 - Endpoint.metrics.threads.name
130132 - Endpoint.metrics.uptime.endpoint
You can’t perform that action at this time.
0 commit comments