Views:
Field Name
Type
General Field
Description
Example
Products
clusterId
-
-
The cluster ID of the container
  • TestCluster-2HJdImvH6eO1fgTnCBK3xYA7Sph
  • Trend Cloud One - Container Security
clusterName
-
-
The cluster name of the container
  • TestCluster
  • Trend Cloud One - Container Security
containerId
-
-
The Kubernetes container ID
  • 7d1e00176d78
  • Trend Cloud One - Container Security
containerImage
-
-
The Kubernetes container image
  • debian:latest
  • Trend Cloud One - Container Security
containerName
-
-
The Kubernetes container name
  • k8s_democon_longrunl_default_09451f51-7124-4aa5-a5c4-ada24efe9da9_0
  • Trend Cloud One - Container Security
dpt
-
  • Port
The destination port
-
  • Trend Cloud One - Container Security
dst
-
  • IPv4
  • IPv6
The destination IP
  • ::
  • 0.0.0.0
  • 127.0.0.1
  • Trend Cloud One - Container Security
eventId
-
-
The event type
-
  • Trend Cloud One - Container Security
eventSubId
-
-
The access type
  • 2 - TELEMETRY_PROCESS_CREATE
  • 101 - TELEMETRY_FILE_CREATE
  • 204 - TELEMETRY_CONNECTION_CONNECT_OUTBOUND
  • Trend Cloud One - Container Security
eventTime
-
-
The time the agent detected the event
  • 1657781088000
  • Trend Cloud One - Container Security
filterRiskLevel
-
-
The top-level risk level of the event
  • info
  • low
  • medium
  • Security Analytics Engine
k8sNamespace
-
-
The Kubernetes namespace of the container
  • default
  • Trend Cloud One - Container Security
k8sPodId
-
-
The Kubernetes pod ID of the container
  • 09451f51-7124-4aa5-a5c4-ada24efe9da9
  • Trend Cloud One - Container Security
k8sPodName
-
-
The Kubernetes pod name of the container
  • longrunl
  • Trend Cloud One - Container Security
objectFilePath
-
  • FileFullPath
  • FileName
The file path of the target process image or target file
  • /usr/bin/bash
  • /bin/bash
  • /opt/nimsoft/probes/system/processes/processes
  • Trend Cloud One - Container Security
objectUser
-
  • UserAccount
The owner name of the target process or the sign-in user name
  • root
  • SYSTEM
  • oracle
  • Trend Cloud One - Container Security
parentCmd
-
  • CLICommand
The command line entry of the parent process
  • C:\WINDOWS\system32\services.exe
  • C:\Windows\system32\services.exe
  • /sbin/launchd
  • Trend Cloud One - Container Security
parentFilePath
-
  • FileFullPath
  • FileName
The file path of the parent process
  • c:\windows\system32\services.exe
  • /usr/bin/bash
  • c:\windows\system32\svchost.exe
  • Trend Cloud One - Container Security
parentPid
-
-
The PID of the parent process
  • 4
  • 1
  • 784
  • 792
  • Trend Cloud One - Container Security
processCmd
-
  • CLICommand
The command line entry of the subject process
  • C:\WINDOWS\system32\services.exe
  • C:\Windows\system32\services.exe
  • /sbin/launchd
  • Trend Cloud One - Container Security
processFilePath
-
  • ProcessFullPath
The file path of the subject process
  • c:\windows\system32\services.exe
  • /usr/bin/bash
  • c:\windows\system32\svchost.exe
  • Trend Cloud One - Container Security
processName
-
  • ProcessName
The image name of the process that triggered the event
  • /usr/bin/bash
  • c:\windows\system32\svchost.exe
  • c:\windows\system32\lsass.exe
  • Trend Cloud One - Container Security
processPid
-
-
The PID of the subject process
  • 4
  • 1
  • 784
  • 792
  • Trend Cloud One - Container Security
productCode
-
-
The internal product code
  • scs
  • Security Analytics Engine
pver
-
-
The product version
  • 1.2.0.2752
  • 1.0.345
  • 1.2.0.2657
  • Trend Cloud One - Container Security
spt
-
  • Port
The source port
  • 53
  • 5353
  • 443
  • Trend Cloud One - Container Security
src
-
  • IPv4
  • IPv6
The source IP
  • ::
  • 172.20.0.10
  • 192.168.0.10
  • Trend Cloud One - Container Security
srcFilePath
-
  • FileFullPath
  • FileName
The source file path
  • \\cnva-apps\megaclockprod\traveler\travelerprint.accdb
  • c:\program files\common files\microsoft shared\clicktorun\officesvcmgrschedule.xml
  • q:\a7_dbs\a4_pkg\a4_packaging.accde
  • Trend Cloud One - Container Security
tags
-
  • Technique
  • Tactic
The detected ID based on the alert filter
  • MITREV9.T1057
  • MITREV9.T1059.003
  • XSAE.F2924
  • Security Analytics Engine
  • Trend Cloud One - Container Security
uuid
-
-
The unique key of the log
  • 00000003-be87-4aad-add2-d395e4efad3e
  • 00000014-0493-459d-9f90-93565402f41e
  • 0000006b-b5ea-4f5e-8d56-ddec452ef3bd
  • Security Analytics Engine