IMPORTANT: No additional bug fixes or documentation updates
will be released for this version. For the latest information, see the
current release documentation.
Sysmon module fields
editSysmon module fields
editThese are the event fields specific to the Sysmon module.
-
sysmon.dns.status
-
Windows status code returned for the DNS query.
type: keyword
-
sysmon.file.archived
-
Indicates if the deleted file was archived.
type: boolean
-
sysmon.file.is_executable
-
Indicates if the deleted file was an executable.
type: boolean