Field Reference
Events Table Fields
| Field | Description | Example |
|---|---|---|
|
Source IP address |
|
|
Destination IP |
|
|
Source port |
|
|
Destination port |
|
|
Username from log |
|
|
Log source ID |
|
|
QRadar event ID |
|
|
Aggregated count |
|
|
Severity (1-10) |
|
|
Timestamp (epoch ms) |
|
|
Raw log data |
(text) |
|
Category ID |
|
Flows Table Fields
| Field | Description |
|---|---|
|
Source IP |
|
Destination IP |
|
Source port |
|
Destination port |
|
Bytes from source |
|
Bytes from destination |
|
Total bytes |
|
Aggregated flow count |
|
6=TCP, 17=UDP |
|
Layer 7 app name (flows only!) |