260 lines
4.2 KiB
YAML
260 lines
4.2 KiB
YAML
---
|
|
DSPEmailAuditReport:
|
|
- UNIQUE_ID
|
|
- TIME_GENERATED
|
|
# - COMPLETION_TIME
|
|
# - SOURCE_ID
|
|
# - ENDPOINT_ID
|
|
- ENDPOINT_NAME
|
|
- USER_SID
|
|
- USER_NAME
|
|
# - ATTACHMENT_ID
|
|
# - ACCESS_TYPE
|
|
# - ACCESS_TYPE_MESSAGE
|
|
# - PROCESS_NAME
|
|
- MAIL_FROM
|
|
- MAIL_TO
|
|
- MAIL_BCC
|
|
- MAIL_CC
|
|
# - MAIL_SUBJECT
|
|
# - MAIL_SENT_TIME
|
|
# - MAIL_CLASSFICATION_VALUE
|
|
# - MAIL_CLASSFICATION
|
|
# - PROFILE_ID
|
|
- PROFILE_NAME
|
|
# - PROFILETYPE_ID
|
|
# - PROFILETYPE_NAME
|
|
DSPEndpointAuditReport:
|
|
- UNIQUE_ID
|
|
- TIME_GENERATED
|
|
# - COMPLETION_TIME
|
|
# - ENDPOINT_ID
|
|
- ENDPOINT_NAME
|
|
# - SOURCE_ID
|
|
- USER_SID
|
|
- USERNAME
|
|
# - PROCESS_ID
|
|
# - LAST_ACCESS_TIME
|
|
# - LAST_WRITE_TIME
|
|
# - CREATION_TIME
|
|
# - FILE_ATTRIBUTES
|
|
# - UNC_NAME
|
|
# - LOCATION
|
|
# - MESSAGE
|
|
# - FILE_FOLDER_NAME
|
|
# - NEW_FILE_NAME
|
|
# - IMAGE_FILE_NAME
|
|
# - OLD_SHARE_PATH
|
|
# - NEW_SHARE_PATH
|
|
# - SHARE_ID
|
|
# - IS_SUCCESS_EVENT
|
|
# - IS_DIRECTORY
|
|
# - IS_TRANSACTION
|
|
# - ACTION_ID
|
|
# - ACCESS_MASK
|
|
# - THREAD_ID
|
|
# - CALLBACK_MAJOR_ID
|
|
# - CALLBACK_MINOR_ID
|
|
# - PROFILE_ID
|
|
# - USER_ID
|
|
# - OLD_SACL
|
|
# - NEW_SACL
|
|
# - DIFF_SACL
|
|
# - FILE_SIZE
|
|
- CLIENT_IP
|
|
- CLIENT_HOST
|
|
- OWNER_INFO
|
|
# - OTHERINFO_1
|
|
# - OTHERINFO_2
|
|
# - IS_SENSITIVE_DATA
|
|
# - FILETYPE_EXTENSION
|
|
# - FILETYPE_CATEGORY
|
|
# - ACCESS_FROM
|
|
# - EVENT_GENERATED_BY
|
|
# - LOGIN_ID
|
|
- LOGIN_NAME
|
|
- OWNER_SID
|
|
# - IS_USB_EVENT
|
|
# - IS_NETWORK_COPY
|
|
# - LAST_KNOWN_COPY
|
|
# - PROFILETYPE_ID
|
|
# - PROFILETYPE_NAME
|
|
DSPEndpointClassificationReport:
|
|
- UNIQUE_ID
|
|
- TIME_GENERATED
|
|
# - COMPLETION_TIME
|
|
# - SOURCE_ID
|
|
# - ENDPOINT_ID
|
|
- ENDPOINT_NAME
|
|
- USER_SID
|
|
- USER_NAME
|
|
# - CLASSIFICATION_ID
|
|
# - CLASSIFICATION_VALUE
|
|
# - CLASSIFICATION_MSG
|
|
# - LOCAL_PATH
|
|
# - FILE_FOLDER_NAME
|
|
# - LAST_ACCESS_TIME
|
|
# - LAST_WRITE_TIME
|
|
# - CREATION_TIME
|
|
# - FILE_ATTRIBUTES
|
|
- FILE_OWNER
|
|
- OWNER_SID
|
|
# - FILE_SIZE
|
|
# - FILETYPE_EXTENSION
|
|
# - IS_HIDDEN
|
|
# - MEDIA_FILE
|
|
# - FILETYPE_EXTENSION_CATEGORY
|
|
DSPEndpointIncidentReport:
|
|
- INCIDENT_ID
|
|
- SOURCE
|
|
# - MODULE_NAME
|
|
# - INCIDENT_TIME
|
|
# - COMPLETION_TIME
|
|
- TIME_GENERATED
|
|
# - MESSAGE
|
|
# - LOCATION
|
|
# - ENDPOINT_ID
|
|
# - INCIDENT_STATUS
|
|
# - VIOLATED_POLICY
|
|
# - DOMAIN_ID
|
|
- ENDPOINT_NAME
|
|
- USERNAME
|
|
# - USER_ID
|
|
# - LAST_ACCESS_TIME
|
|
# - LAST_WRITE_TIME
|
|
# - FILE_SIZE
|
|
# - CREATION_TIME
|
|
# - REPORT_GENERATION_ID
|
|
# - NEW_FILE_NAME
|
|
# - IMAGE_FILE_NAME
|
|
# - FILE_FOLDER_NAME
|
|
- USER_SID
|
|
# - FILETYPE_EXTENSION
|
|
# - IS_USB_EVENT
|
|
- NOTIFY_NAME
|
|
- MAIL_FROM
|
|
- MAIL_TO
|
|
- MAIL_BCC
|
|
- MAIL_CC
|
|
# - MAIL_SUBJECT
|
|
# - MAIL_SENT_TIME
|
|
# - MAIL_CLASSFICATION
|
|
# - PRINTER_NAME
|
|
# - FILENAME
|
|
# - PORT_NAME
|
|
- MACHINE_NAME
|
|
- PRINTER_USERNAME
|
|
# - TOTAL_PAGES
|
|
- CLIENTIPLIST
|
|
- URL
|
|
# - CLASSIFICATION_VALUE
|
|
# - INCIDENT_PROFILE_ID
|
|
# - INCIDENT_PROFILE_NAME
|
|
# - INCIDENT_SEVERITY
|
|
# - PROFILETYPE_ID
|
|
# - PROFILETYPE_NAME
|
|
# - IS_NETWORK_COPY
|
|
# - LAST_KNOWN_COPY
|
|
- CLIENT_HOST
|
|
DspEndpointPrinterAuditReport:
|
|
- UNIQUE_ID
|
|
- TIME_GENERATED
|
|
# - COMPLETION_TIME
|
|
# - SOURCE_ID
|
|
# - ENDPOINT_ID
|
|
- ENDPOINT_NAME
|
|
- USER_SID
|
|
- USER_NAME
|
|
# - PRINTER_NAME
|
|
# - FILENAME
|
|
# - LOCAL_PATH
|
|
# - PORT_NAME
|
|
- MACHINE_NAME
|
|
- PRINTER_USERNAME
|
|
- NOTIFY_NAME
|
|
# - TOTAL_PAGES
|
|
# - FILE_SIZE
|
|
# - CREATION_TIME
|
|
- CLIENTIPLIST
|
|
# - PROFILE_ID
|
|
- PROFILE_NAME
|
|
# - PROFILETYPE_ID
|
|
# - PROFILETYPE_NAME
|
|
DspEndpointWebAuditReport:
|
|
- UNIQUE_ID
|
|
- TIME_GENERATED
|
|
# - SOURCE_ID
|
|
# - ENDPOINT_ID
|
|
- ENDPOINT_NAME
|
|
- USER_SID
|
|
- USER_NAME
|
|
# - NEW_FILE_NAME
|
|
# - FILE_SIZE
|
|
# - FILETYPE_EXTENSION
|
|
# - PROCESS_NAME
|
|
# - MESSAGE
|
|
# - URL
|
|
- CLIENT_IP
|
|
# - PROFILE_ID
|
|
- PROFILE_NAME
|
|
DSPFileAnalysisAlerts:
|
|
- INCIDENT_ID
|
|
# - VIOLATED_PROFILE
|
|
# - SERVER_ID
|
|
# - DRIVE_LETTER
|
|
# - SOURCE_ID
|
|
- TIME_GENERATED
|
|
# - SECURITY_ID
|
|
- SERVERNAME
|
|
# - FILE_ATTRIBUTES
|
|
# - LAST_ACCESS_TIME
|
|
# - LAST_WRITE_TIME
|
|
# - FILE_SIZE
|
|
# - CREATION_TIME
|
|
# - REPORT_GENERATION_ID
|
|
# - YEAR_CREATED
|
|
# - FILE_FOLDER_NAME
|
|
# - LOCAL_PATH
|
|
# - FILETYPE_EXTENSION
|
|
# - IS_HIDDEN
|
|
# - IS_DIRECTORY
|
|
# - IS_STALE
|
|
# - NON_BUSINESS_FILE
|
|
# - FILETYPE_EXTENSION_CATEGORY
|
|
RAAlertHistory:
|
|
- INCIDENT_ID
|
|
# - FILE_NAME
|
|
# - FILE_TYPE
|
|
# - LOCATION
|
|
- SERVER_NAME
|
|
# - POLICY_ID
|
|
# - POLICY_NAME
|
|
- TIME_GENERATED
|
|
# - NO_OF_OCCURRENCES
|
|
- FILE_OWNER
|
|
# - DATA_SOURCE
|
|
# - RISK_SCORE
|
|
# - ENTITY_ID
|
|
RAIncidents:
|
|
- INCIDENT_ID
|
|
# - FILE_NAME
|
|
# - FILE_TYPE
|
|
# - LOCATION
|
|
- SERVER_NAME
|
|
# - POLICY_ID
|
|
# - POLICY_NAME
|
|
- TIME_GENERATED
|
|
# - NO_OF_OCCURRENCES
|
|
- FILE_OWNER
|
|
# - DATA_SOURCE
|
|
# - RAISED_INCIDENT
|
|
# - SOURCE_ID
|
|
# - RISK_SCORE
|
|
# - VIOLATION_SCORE
|
|
# - POLICY_SCORE
|
|
# - PERMISSION_SCORE
|
|
# - AUDIT_SCORE
|
|
# - USER_SCORE
|
|
# - SCORE_DESCRIPTION
|
|
# - ENTITY_ID
|