- JSON representation
- NounType
- TypeEnrichmentProvenance
- EnrichmentType
- EnrichmentSource
- FieldEnrichmentProvenance
- EnrichingEvent
- EnrichingEventType
JSON representation |
---|
{ "nounType" : enum ( |
Fields | |
---|---|
nounType
|
|
typeEnrichmentProvenances[]
|
|
NounType
Enums | |
---|---|
NOUN_TYPE_UNSPECIFIED
|
|
PRINCIPAL
|
|
SRC
|
|
TARGET
|
TypeEnrichmentProvenance
JSON representation |
---|
{ "enrichmentType" : enum ( |
Fields | |
---|---|
enrichmentType
|
|
enrichmentSources[]
|
|
fieldEnrichmentProvenances[]
|
|
EnrichmentType
Enums | |
---|---|
ENRICHMENT_TYPE_UNSPECIFIED
|
|
ASSET
|
|
USER
|
|
PROCESS
|
|
VT_FILE_HASH
|
|
GEOIP
|
|
PARENT_PROCESS_FROM_CURRENT_PROCESS
|
EnrichmentSource
JSON representation |
---|
{ // Union field |
Union field source
.
source
can be only one of the following:
logType
enum (
LogType
)
noLogEnrichmentSource
enum (
NoLogEnrichmentSource
)
FieldEnrichmentProvenance
JSON representation |
---|
{
"enrichingEvents"
:
[
{
object (
|
Fields | |
---|---|
enrichingEvents[]
|
|
EnrichingEvent
JSON representation |
---|
{
"enrichingEventType"
:
enum (
|
Fields | |
---|---|
enrichingEventType
|
|
eventId
|
A base64-encoded string. |
EnrichingEventType
Enums | |
---|---|
ENRICHING_EVENT_TYPE_UNSPECIFIED
|
|
DHCP
|
|
EDR_MAPPING
|
|
ASSET_CONTEXT
|
|
USER_CONTEXT
|
|
FILE_CONTEXT
|
|
EDR_PROCESS_LAUNCH
|
|
EDR
|