Activity Log Event Fdr/Ingest

Event for FDR ingest

Field TypeTypeValueAvailabilityDescription
0]    
@id    
@ingesttimestamp    
@rawstring    
@timestamp    
@timestamp.nanos    
@timezone    
bucket    Bucket for FDR events
category    Category of the event, such as Alert, Request, IngestFeed, Fdr, Query, Action, and ScheduledSearch
dataspace    Repository or view name
dataspaceId    Dataspace ID
eventsCount    Count of FDR events
exception    Path of the exception file and the exception message of the event; only for scheduled search events
exceptionCause[0]    
exceptionMessage    Detailed error message that will include errors at the cluster-level that may have contributed; for example permission, API, or network issues
fdrFeedId    FDR feed ID
fdrFeedName    FDR feed name
#category    
#repo    
#severity    
key    Location of the block loaded when processing bucket data
message    Message of the alert or event
orgId    Organization ID
s3File.bucket    
s3File.key    
s3File.size    
severity    Severity of the event
size    Size of the incoming data during FDR ingest
sqsAckResponse.content    Content of SQS acknowledgement response
sqsAckResponse.statusCode    Status code of SQS acknowledgement response
sqsMessage.body    body of SQS message
sqsMessage.bodyChecksum    Checksum for body of SQS message
sqsMessage.bucket    Bucket of SQS message
sqsMessage.cid    CID of the SQS message
sqsMessage.fileCount    Number of files from SQS message included in the event
sqsMessage.id    SQS message ID
sqsMessage.latestReceiveTimestamp    
sqsMessage.pathPrefix    Path prefix of the SQS message
sqsMessage.receiptHandle    The receipt handle of the SQS message; the receipt handle is specific to the action of receiving the message and not the SQS message itself
sqsMessage.timestamp    Timestamp of SQS message
sqsMessage.totalSize    Total size of SQS message
sqsMessageAttribute.ApproximateFirstReceiveTimestamp    
sqsMessageAttribute.ApproximateReceiveCount    
sqsMessageAttribute.SenderId    
sqsMessageAttribute.SentTimestamp    
startFileDownloadTimestamp    
streamId    Stream ID
subCategory    Subcategory of the event
timestamp    Timestamp in milliseconds of the event