nano SIEM
Reference

UDM Fields

Complete reference of all Unified Data Model (UDM) fields available in nano SIEM

Complete reference of all 525+ Unified Data Model (UDM) fields available in nano. These fields provide a standardized schema for security log data based on industry-standard data models.

Showing 505 of 505 fields

Field Name
Type
Category
Description
actionStringEndpointEndpoint
additional_answer_countIntegerDNSDNS
answerStringDNSDNS
answer_countIntegerDNSDNS
appStringSystemSystem
app_idIntegerData AccessData Access
arrayStringInventoryInventory
auth_resultStringAuthenticationAuthentication
auth_typeStringAuthenticationAuthentication
authentication_methodStringAuthenticationAuthentication
authentication_serviceStringAuthenticationAuthentication
authority_answer_countIntegerDNSDNS
availabilityStringDatabasesDatabases
avg_executionsStringDatabasesDatabases
blocksizeStringInventoryInventory
buffer_cache_hit_ratioFloatDatabasesDatabases
bugtraqStringVulnerabilityVulnerability
bytesLongNetworkNetwork
bytes_inLongNetworkNetwork
bytes_outLongNetworkNetwork
cachedStringWebWeb
categoryStringData Loss PreventionData Loss Prevention
certStringVulnerabilityVulnerability
change_typeStringSystemSystem
channelStringNetworkNetwork
cloud_account_idIntegerCloudCloud
cloud_account_nameStringCloudCloud
cloud_providerStringCloudCloud
cloud_regionStringCloudCloud
cloud_serviceStringCloudCloud
clusterStringInventoryInventory
commandStringEndpointEndpoint
command_lineStringEndpointEndpoint
commitsStringDatabasesDatabases
cookieStringWebWeb
cpu_coresStringInventoryInventory
cpu_countIntegerInventoryInventory
cpu_load_mhzFloatPerformancePerformance
cpu_load_percentFloatEndpointEndpoint
cpu_mhzStringInventoryInventory
cpu_usedStringDatabasesDatabases
cpu_user_percentFloatPerformancePerformance
creation_timeTimestampEndpointEndpoint
cursorStringDatabasesDatabases
custom_dest_ip_riskIpAddressCustom EnrichmentCustom Enrichment
custom_dest_ip_tagsArrayCustom EnrichmentCustom Enrichment
custom_domain_riskStringCustom EnrichmentCustom Enrichment
custom_domain_tagsArrayCustom EnrichmentCustom Enrichment
custom_hash_riskStringCustom EnrichmentCustom Enrichment
custom_hash_tagsArrayCustom EnrichmentCustom Enrichment
custom_ioc_dest_ip_confidenceIpAddressCustom EnrichmentCustom Enrichment
custom_ioc_dest_ip_malwareIpAddressCustom EnrichmentCustom Enrichment
custom_ioc_dest_ip_threat_typeIpAddressCustom EnrichmentCustom Enrichment
custom_ioc_domain_confidenceIntegerCustom EnrichmentCustom Enrichment
custom_ioc_domain_threat_typeStringCustom EnrichmentCustom Enrichment
custom_ioc_hash_confidenceIntegerCustom EnrichmentCustom Enrichment
custom_ioc_hash_threat_typeStringCustom EnrichmentCustom Enrichment
custom_ioc_src_ip_confidenceIpAddressCustom EnrichmentCustom Enrichment
custom_ioc_src_ip_malwareIpAddressCustom EnrichmentCustom Enrichment
custom_ioc_src_ip_threat_typeIpAddressCustom EnrichmentCustom Enrichment
custom_src_ip_riskIpAddressCustom EnrichmentCustom Enrichment
custom_src_ip_tagsArrayCustom EnrichmentCustom Enrichment
custom_url_riskStringCustom EnrichmentCustom Enrichment
custom_url_tagsArrayCustom EnrichmentCustom Enrichment
cveStringVulnerabilityVulnerability
cvssStringVulnerabilityVulnerability
dateStringSystemSystem
delayStringEmailEmail
descriptionStringAlertsAlerts
destStringAlertsAlerts
dest_dnsStringNetworkNetwork
dest_hostStringNetworkNetwork
dest_interfaceStringNetworkNetwork
dest_ipIpAddressNetworkNetwork
dest_ip_rangeIpAddressNetworkNetwork
dest_macStringNetworkNetwork
dest_nameStringData AccessData Access
dest_nt_domainStringAuthenticationAuthentication
dest_nt_hostStringNetworkNetwork
dest_portIntegerNetworkNetwork
dest_port_rangeStringNetworkNetwork
dest_translated_ipIpAddressNetworkNetwork
dest_translated_portIntegerNetworkNetwork
dest_typeStringAlertsAlerts
dest_urlStringData AccessData Access
dest_userStringAuthenticationAuthentication
dest_user_identity_account_statusStringEnrichmentEnrichment
dest_user_identity_companyStringEnrichmentEnrichment
dest_user_identity_countryStringEnrichmentEnrichment
dest_user_identity_departmentStringEnrichmentEnrichment
dest_user_identity_display_nameStringEnrichmentEnrichment
dest_user_identity_emailStringEnrichmentEnrichment
dest_user_identity_employee_idIntegerEnrichmentEnrichment
dest_user_identity_employee_typeStringEnrichmentEnrichment
dest_user_identity_groupsStringEnrichmentEnrichment
dest_user_identity_managerStringEnrichmentEnrichment
dest_user_identity_manager_upnStringEnrichmentEnrichment
dest_user_identity_mfa_enabledBooleanEnrichmentEnrichment
dest_user_identity_office_locationStringEnrichmentEnrichment
dest_user_identity_phoneStringEnrichmentEnrichment
dest_user_identity_titleStringEnrichmentEnrichment
dest_zoneStringData Loss PreventionData Loss Prevention
directionStringNetworkNetwork
dlp_typeStringData Loss PreventionData Loss Prevention
dnsStringInventoryInventory
dns_answersStringDNSDNS
dump_area_usedStringDatabasesDatabases
durationStringNetworkNetwork
dvcStringNetworkNetwork
dvc_ipIpAddressNetworkNetwork
dvc_macStringNetworkNetwork
dvc_zoneStringNetworkNetwork
elapsed_timeTimestampDatabasesDatabases
emailStringData AccessData Access
enabledStringInventoryInventory
enrich_timeTimestampSystemSystem
enriched_dest_as_domainStringEnrichmentEnrichment
enriched_dest_as_nameStringEnrichmentEnrichment
enriched_dest_asnStringEnrichmentEnrichment
enriched_dest_continentStringEnrichmentEnrichment
enriched_dest_continent_codeIntegerEnrichmentEnrichment
enriched_dest_countryStringEnrichmentEnrichment
enriched_dest_country_codeIntegerEnrichmentEnrichment
enriched_src_as_domainStringEnrichmentEnrichment
enriched_src_as_nameStringEnrichmentEnrichment
enriched_src_asnStringEnrichmentEnrichment
enriched_src_continentStringEnrichmentEnrichment
enriched_src_continent_codeIntegerEnrichmentEnrichment
enriched_src_countryStringEnrichmentEnrichment
enriched_src_country_codeIntegerEnrichmentEnrichment
error_codeIntegerWebWeb
extStringSystemSystem
familyStringInventoryInventory
fan_speedStringPerformancePerformance
fd_maxStringInventoryInventory
fd_usedStringPerformancePerformance
file_access_timeTimestampEndpointEndpoint
file_aclStringEndpointEndpoint
file_actionStringEndpointEndpoint
file_create_timeTimestampEndpointEndpoint
file_hashStringEndpointEndpoint
file_modify_timeTimestampEndpointEndpoint
file_nameStringEndpointEndpoint
file_pathStringEndpointEndpoint
file_sizeLongEndpointEndpoint
filter_actionStringEmailEmail
filter_scoreFloatEmailEmail
flow_idIntegerNetworkNetwork
free_bytesLongDatabasesDatabases
http_content_typeStringWebWeb
http_methodStringWebWeb
http_referrerStringWebWeb
http_referrer_domainStringWebWeb
http_status_codeIntegerWebWeb
http_user_agentStringWebWeb
http_user_agent_lengthStringWebWeb
hypervisorStringInventoryInventory
hypervisor_idIntegerInventoryInventory
icmp_codeIntegerNetworkNetwork
icmp_typeStringNetworkNetwork
idStringSystemSystem
ids_typeStringAlertsAlerts
image_idIntegerCloudCloud
indexes_hitStringDatabasesDatabases
ingest_timeTimestampSystemSystem
inline_natStringInventoryInventory
instance_nameStringDatabasesDatabases
instance_readsStringDatabasesDatabases
instance_typeStringCloudCloud
instance_versionStringDatabasesDatabases
instance_writesStringDatabasesDatabases
interactiveStringInventoryInventory
interfaceStringInventoryInventory
internal_message_idIntegerEmailEmail
ioc_confidenceIntegerThreat IntelligenceThreat Intelligence
ioc_dest_ip_confidenceIpAddressThreat IntelligenceThreat Intelligence
ioc_dest_ip_malwareIpAddressThreat IntelligenceThreat Intelligence
ioc_dest_ip_threat_typeIpAddressThreat IntelligenceThreat Intelligence
ioc_domain_confidenceIntegerThreat IntelligenceThreat Intelligence
ioc_domain_malwareStringThreat IntelligenceThreat Intelligence
ioc_domain_threat_typeStringThreat IntelligenceThreat Intelligence
ioc_hash_confidenceIntegerThreat IntelligenceThreat Intelligence
ioc_hash_malwareStringThreat IntelligenceThreat Intelligence
ioc_hash_threat_typeStringThreat IntelligenceThreat Intelligence
ioc_matchedBooleanThreat IntelligenceThreat Intelligence
ioc_sourceStringThreat IntelligenceThreat Intelligence
ioc_src_ip_confidenceIpAddressThreat IntelligenceThreat Intelligence
ioc_src_ip_malwareIpAddressThreat IntelligenceThreat Intelligence
ioc_src_ip_threat_typeIpAddressThreat IntelligenceThreat Intelligence
ioc_tagsArrayThreat IntelligenceThreat Intelligence
ipIpAddressInventoryInventory
last_call_minuteStringDatabasesDatabases
latencyStringInventoryInventory
lb_methodStringInventoryInventory
lease_durationStringNetworkNetwork
lease_scopeStringNetworkNetwork
lock_modeStringDatabasesDatabases
lock_session_idIntegerDatabasesDatabases
logical_readsStringDatabasesDatabases
logon_timeTimestampAuthenticationAuthentication
macStringInventoryInventory
machineStringEndpointEndpoint
memStringInventoryInventory
mem_committedStringPerformancePerformance
mem_freeStringPerformancePerformance
mem_usedStringEndpointEndpoint
memory_sortsLongDatabasesDatabases
messageStringSystemSystem
message_idIntegerEmailEmail
message_infoStringEmailEmail
metadataStringSystemSystem
mfa_usedStringAuthenticationAuthentication
mitre_technique_idIntegerAlertsAlerts
mountStringInventoryInventory
msftStringVulnerabilityVulnerability
mskbStringVulnerabilityVulnerability
nameStringSystemSystem
namespaceStringSystemSystem
nodeStringInventoryInventory
node_portIntegerInventoryInventory
number_of_usersStringDatabasesDatabases
obj_nameStringDatabasesDatabases
objectStringEndpointEndpoint
object_attrsStringEndpointEndpoint
object_categoryStringEndpointEndpoint
object_idIntegerEndpointEndpoint
object_pathStringEndpointEndpoint
object_sizeLongData AccessData Access
operationStringWebWeb
orig_destStringEmailEmail
orig_recipientStringEmailEmail
orig_srcStringEmailEmail
original_file_nameStringEndpointEndpoint
osStringEndpointEndpoint
os_pidIntegerEndpointEndpoint
ownerStringData AccessData Access
owner_emailStringData AccessData Access
owner_idIntegerData AccessData Access
packetsStringNetworkNetwork
packets_inStringNetworkNetwork
packets_outStringNetworkNetwork
parentStringInventoryInventory
parent_command_lineStringEndpointEndpoint
parent_objectStringData AccessData Access
parent_object_categoryStringData AccessData Access
parent_object_idIntegerData AccessData Access
parent_process_execStringEndpointEndpoint
parent_process_guidStringEndpointEndpoint
parent_process_idIntegerEndpointEndpoint
parent_process_nameStringEndpointEndpoint
parent_process_pathStringEndpointEndpoint
passwordStringInventoryInventory
physical_readsStringDatabasesDatabases
powerStringPerformancePerformance
prevalence_dest_domainIntegerPrevalencePrevalence
prevalence_dest_ipIpAddressPrevalencePrevalence
prevalence_file_hashIntegerPrevalencePrevalence
prevalence_minIntegerPrevalencePrevalence
prevalence_process_hashIntegerPrevalencePrevalence
process_current_directoryStringEndpointEndpoint
process_execStringEndpointEndpoint
process_guidStringEndpointEndpoint
process_hashStringEndpointEndpoint
process_idIntegerEndpointEndpoint
process_integrity_levelStringEndpointEndpoint
process_limitStringDatabasesDatabases
process_nameStringEndpointEndpoint
process_pathStringEndpointEndpoint
processesStringDatabasesDatabases
productStringAuthenticationAuthentication
product_versionStringEndpointEndpoint
protocolStringNetworkNetwork
protocol_versionStringNetworkNetwork
queryStringDNSDNS
query_countIntegerDNSDNS
query_idIntegerDatabasesDatabases
query_plan_hitStringDatabasesDatabases
query_timeTimestampDatabasesDatabases
query_typeStringDNSDNS
read_blocksStringInventoryInventory
read_latencyStringInventoryInventory
read_opsStringInventoryInventory
reasonStringAuthenticationAuthentication
recipientStringEmailEmail
recipient_countIntegerEmailEmail
recipient_domainStringEmailEmail
recipient_statusStringEmailEmail
record_typeStringDNSDNS
records_affectedStringDatabasesDatabases
registry_hiveStringEndpointEndpoint
registry_key_nameStringEndpointEndpoint
registry_pathStringEndpointEndpoint
registry_value_dataStringEndpointEndpoint
registry_value_nameStringEndpointEndpoint
registry_value_textStringEndpointEndpoint
registry_value_typeStringEndpointEndpoint
reply_codeIntegerDNSDNS
reply_code_idIntegerDNSDNS
resource_idIntegerCloudCloud
resource_nameStringCloudCloud
resource_typeStringCloudCloud
response_timeTimestampAuthenticationAuthentication
resultStringSystemSystem
result_idIntegerSystemSystem
retriesStringEmailEmail
return_addrStringEmailEmail
risk_entityStringRiskRisk
risk_levelStringRiskRisk
risk_scoreFloatRiskRisk
ruleStringNetworkNetwork
rule_actionStringNetworkNetwork
rule_idIntegerAlertsAlerts
rule_nameStringAlertsAlerts
seconds_in_waitStringDatabasesDatabases
senderStringEmailEmail
sender_domainStringEmailEmail
serialStringInventoryInventory
serial_numStringDatabasesDatabases
serviceStringEndpointEndpoint
service_dllStringEndpointEndpoint
service_dll_hashStringEndpointEndpoint
service_dll_pathStringEndpointEndpoint
service_dll_signature_existsStringEndpointEndpoint
service_dll_signature_verifiedStringEndpointEndpoint
service_execStringEndpointEndpoint
service_hashStringEndpointEndpoint
service_idIntegerEndpointEndpoint
service_nameStringEndpointEndpoint
service_pathStringEndpointEndpoint
service_signature_existsStringEndpointEndpoint
service_signature_verifiedStringEndpointEndpoint
session_idIntegerAuthenticationAuthentication
session_limitStringDatabasesDatabases
session_statusStringDatabasesDatabases
sessionsStringDatabasesDatabases
severityStringAlertsAlerts
severity_idIntegerAlertsAlerts
sga_buffer_cache_sizeLongDatabasesDatabases
sga_buffer_hit_limitStringDatabasesDatabases
sga_data_dict_hit_ratioFloatDatabasesDatabases
sga_fixed_area_sizeLongDatabasesDatabases
sga_free_memoryLongDatabasesDatabases
sga_library_cache_sizeLongDatabasesDatabases
sga_redo_log_buffer_sizeLongDatabasesDatabases
sga_shared_pool_sizeLongDatabasesDatabases
sga_sql_area_sizeLongDatabasesDatabases
shellStringInventoryInventory
signatureStringAlertsAlerts
signature_extraStringEmailEmail
signature_idIntegerAlertsAlerts
signature_versionStringEndpointEndpoint
siteStringWebWeb
sizeStringEmailEmail
snapshotStringInventoryInventory
sourceStringSystemSystem
source_typeStringSystemSystem
srcStringAlertsAlerts
src_dnsStringNetworkNetwork
src_hostStringNetworkNetwork
src_interfaceStringNetworkNetwork
src_ipIpAddressNetworkNetwork
src_ip_rangeIpAddressNetworkNetwork
src_macStringNetworkNetwork
src_nt_domainStringAuthenticationAuthentication
src_nt_hostStringNetworkNetwork
src_portIntegerNetworkNetwork
src_port_rangeStringNetworkNetwork
src_translated_ipIpAddressNetworkNetwork
src_translated_portIntegerNetworkNetwork
src_typeStringAlertsAlerts
src_userStringAuthenticationAuthentication
src_user_domainStringAuthenticationAuthentication
src_user_idIntegerAuthenticationAuthentication
src_user_identity_account_statusStringEnrichmentEnrichment
src_user_identity_companyStringEnrichmentEnrichment
src_user_identity_countryStringEnrichmentEnrichment
src_user_identity_departmentStringEnrichmentEnrichment
src_user_identity_display_nameStringEnrichmentEnrichment
src_user_identity_emailStringEnrichmentEnrichment
src_user_identity_employee_idIntegerEnrichmentEnrichment
src_user_identity_employee_typeStringEnrichmentEnrichment
src_user_identity_groupsStringEnrichmentEnrichment
src_user_identity_managerStringEnrichmentEnrichment
src_user_identity_manager_upnStringEnrichmentEnrichment
src_user_identity_mfa_enabledBooleanEnrichmentEnrichment
src_user_identity_office_locationStringEnrichmentEnrichment
src_user_identity_phoneStringEnrichmentEnrichment
src_user_identity_titleStringEnrichmentEnrichment
src_user_nameStringAuthenticationAuthentication
src_user_roleStringAuthenticationAuthentication
src_user_typeStringAuthenticationAuthentication
src_zoneStringData Loss PreventionData Loss Prevention
ssidStringNetworkNetwork
ssl_end_timeTimestampCertificatesCertificates
ssl_engineStringCertificatesCertificates
ssl_hashStringCertificatesCertificates
ssl_is_validStringCertificatesCertificates
ssl_issuerStringCertificatesCertificates
ssl_issuer_common_nameStringCertificatesCertificates
ssl_issuer_emailStringCertificatesCertificates
ssl_issuer_email_domainStringCertificatesCertificates
ssl_issuer_localityStringCertificatesCertificates
ssl_issuer_organizationStringCertificatesCertificates
ssl_issuer_stateStringCertificatesCertificates
ssl_issuer_streetStringCertificatesCertificates
ssl_issuer_unitStringCertificatesCertificates
ssl_nameStringCertificatesCertificates
ssl_policiesStringCertificatesCertificates
ssl_publickeyStringCertificatesCertificates
ssl_publickey_algorithmStringCertificatesCertificates
ssl_serialStringCertificatesCertificates
ssl_session_idIntegerCertificatesCertificates
ssl_signature_algorithmStringCertificatesCertificates
ssl_start_timeTimestampCertificatesCertificates
ssl_subjectStringCertificatesCertificates
ssl_subject_common_nameStringCertificatesCertificates
ssl_subject_emailStringCertificatesCertificates
ssl_subject_email_domainStringCertificatesCertificates
ssl_subject_localityStringCertificatesCertificates
ssl_subject_organizationStringCertificatesCertificates
ssl_subject_stateStringCertificatesCertificates
ssl_subject_streetStringCertificatesCertificates
ssl_subject_unitStringCertificatesCertificates
ssl_validity_windowStringCertificatesCertificates
ssl_versionStringCertificatesCertificates
start_modeStringEndpointEndpoint
start_timeTimestampSystemSystem
stateStringEndpointEndpoint
statusStringSystemSystem
status_codeIntegerWebWeb
storageStringInventoryInventory
storage_freeStringPerformancePerformance
storage_free_percentFloatPerformancePerformance
storage_nameStringWebWeb
storage_usedStringPerformancePerformance
storage_used_percentFloatPerformancePerformance
stored_procedures_calledStringDatabasesDatabases
subjectStringEmailEmail
swapStringPerformancePerformance
swap_freeStringPerformancePerformance
swap_usedStringPerformancePerformance
table_scansStringDatabasesDatabases
tables_hitStringDatabasesDatabases
tablespace_nameStringDatabasesDatabases
tablespace_readsStringDatabasesDatabases
tablespace_statusStringDatabasesDatabases
tablespace_usedStringDatabasesDatabases
tablespace_writesStringDatabasesDatabases
tagStringAlertsAlerts
tcp_flagStringNetworkNetwork
temperatureStringPerformancePerformance
thruputStringPerformancePerformance
thruput_maxStringPerformancePerformance
timeTimestampSystemSystem
timestampTimestampSystemSystem
tosStringNetworkNetwork
transaction_idIntegerDNSDNS
transportStringNetworkNetwork
transport_dest_portIntegerEndpointEndpoint
ttlStringDNSDNS
typeStringAlertsAlerts
uri_pathStringWebWeb
uri_queryStringWebWeb
urlStringWebWeb
url_domainStringWebWeb
url_lengthStringWebWeb
userStringAuthenticationAuthentication
user_agentStringWebWeb
user_domainStringAuthenticationAuthentication
user_groupStringData AccessData Access
user_idIntegerAuthenticationAuthentication
user_identity_account_statusStringEnrichmentEnrichment
user_identity_companyStringEnrichmentEnrichment
user_identity_countryStringEnrichmentEnrichment
user_identity_departmentStringEnrichmentEnrichment
user_identity_display_nameStringEnrichmentEnrichment
user_identity_emailStringEnrichmentEnrichment
user_identity_employee_idIntegerEnrichmentEnrichment
user_identity_employee_typeStringEnrichmentEnrichment
user_identity_groupsStringEnrichmentEnrichment
user_identity_managerStringEnrichmentEnrichment
user_identity_manager_upnStringEnrichmentEnrichment
user_identity_mfa_enabledBooleanEnrichmentEnrichment
user_identity_office_locationStringEnrichmentEnrichment
user_identity_phoneStringEnrichmentEnrichment
user_identity_titleStringEnrichmentEnrichment
user_nameStringAuthenticationAuthentication
user_roleStringAuthenticationAuthentication
user_typeStringAuthenticationAuthentication
vendorStringAuthenticationAuthentication
vendor_accountStringAlertsAlerts
vendor_productStringAuthenticationAuthentication
vendor_product_idIntegerAlertsAlerts
vendor_regionStringAlertsAlerts
versionStringInventoryInventory
vip_portIntegerInventoryInventory
vlanStringNetworkNetwork
wait_stateStringDatabasesDatabases
wait_timeTimestampDatabasesDatabases
wifiStringNetworkNetwork
write_blocksStringInventoryInventory
write_latencyStringInventoryInventory
write_opsStringInventoryInventory
xdelayStringEmailEmail
xrefStringEmailEmail

Data Types

Array(6 fields)
Boolean(4 fields)
Float(9 fields)
Integer(63 fields)
IpAddress(23 fields)
Long(14 fields)
String(370 fields)
Timestamp(16 fields)

Categories

Alerts(18 fields)
Authentication(27 fields)
Certificates(32 fields)
Cloud(10 fields)
Custom Enrichment(20 fields)
DNS(13 fields)
Data Access(12 fields)
Data Loss Prevention(4 fields)
Databases(52 fields)
Email(22 fields)
Endpoint(63 fields)
Enrichment(59 fields)
Inventory(37 fields)
Network(50 fields)
Performance(17 fields)
Prevalence(5 fields)
Risk(3 fields)
System(19 fields)
Threat Intelligence(16 fields)
Vulnerability(6 fields)
Web(20 fields)
On this page

On this page