schema: Crowdstrike.AIDMaster
name: Crowdstrike.AIDMaster
description: Sensor and Host information provided by Falcon Insight
referenceURL: https://developer.crowdstrike.com/crowdstrike/docs/falcon-data-replicator-guide#section-aid-master
description: Timestamp of when the event was received by the CrowdStrike cloud. This is not to be confused with the time the event was generated locally on the system (the _timeevent). This is the timestamp of the event from the cloud's point of view. This value can be converted to any time format and can be used for calculations.
description: 'Whether the sensor loaded during or after the Windows host''s boot process. Example values: 0, 1'
description: The local time for the sensor in epoch format.
description: The time since the last reboot in epoch format.
description: The version of the sensor running on a host.
description: The sensor ID. This value is unique to each installation of a Falcon sensor. When a sensor is updated or reinstalled, the host gets a new aid. In those situations, a single host could have multiple aid values over time.
description: The customer ID.
description: The sensor’s IP, as seen from the CrowdStrike cloud. This is typically the public IP of the sensor. This helps determine the location of a computer, depending on your network.
description: The manufacturer of the host's BIOS.
description: The version of the host's BIOS.
description: Type of system chassis, as defined in SMBIOS Standard.
description: The system's city of origin.
description: The system's country of origin.
description: The sensor's continent, as seen from the CrowdStrike cloud.
description: The name of the host.
description: ConfigBuild field
description: Build number used as part of the ConfigID.
description: 'The platform the sensor is running on. Example values: ''Win'', ''Lin'', ''Mac''.'
- name: FalconGroupingTags
description: FalconGroupingTags field
description: The first time the sensor was seen by the CrowdStrike cloud in epoch format.
description: The Windows domain name to which the host is currently joined.
description: The organizational unit of the host as seen by the sensor (defined by system admin).
description: 'The processor architecture (in decimal, non-hex format): ''4'' for 32-bit, ''8'' for 64-bit, or ''none'' for unknown.'
description: 'The type of product (in decimal, non-hex format). Example values: ''1'' (Workstation), ''2'' (Domain Controller), ''3'' (Server).'
- name: SensorGroupingTags
description: SensorGroupingTags field
description: 'The major version # of the OS Service Pack (in decimal, non-hex format).'
description: The site name of the domain to which the host is joined (defined by system admin).
- name: SystemManufacturer
description: The host's system manufacturer.
- name: SystemProductName
description: The host's product name.
description: The sensor's time zone, as seen from the CrowdStrike cloud.
description: The host's system version.
description: Whether the host is visible or not.