schema:Sophos.Centraldescription:Sophos Central eventsreferenceURL:https://support.sophos.com/support/s/article/KB-000038307?language=en_USfields: - name:endpoint_idrequired:truedescription:Endpoint ID associated with the eventtype:string - name:endpoint_typerequired:truedescription:Type of endpointtype:string - name:customer_iddescription:Customer IDtype:string - name:severitydescription:Severity of the eventtype:string - name:source_infodescription:Source IP of the endpointtype:objectfields: - name:ipdescription:First IPv4 address of the endpointtype:stringindicators: - ip - name:namedescription:Name of threat, or other event detailstype:string - name:idrequired:truedescription:Unique identifier for the eventtype:string - name:typerequired:truedescription:Type of eventtype:string - name:groupdescription:Category of eventtype:string - name:endrequired:truedescription:Time the event occurred on the endpointtype:timestamptimeFormats: - rfc3339isEventTime:true - name:rtdescription:Time the event was uploaded to Sophos Centraltype:timestamptimeFormats: - rfc3339 - name:dhostdescription:Source host of the eventtype:string - name:suserdescription:Logged in usertype:stringindicators: - username - name:datastreamdescription:Alert, or Event, to distinguish between event typestype:string - name:duiddescription:Undocumented fieldtype:string - name:threatdescription:Name of the threattype:string - name:detection_identity_namedescription:Name of the detectiontype:string - name:filePathdescription:Path to the threattype:string - name:userdescription:Undocumented field, but should be same as Usertype:string - name:ruledescription:DLP ruletype:string - name:user_actiondescription:DLP user actiontype:string - name:app_namedescription:DLP application nametype:string - name:actiondescription:DLP actiontype:string - name:file_typedescription:DLP file typetype:string - name:file_sizedescription:DLP file sizetype:bigint - name:file_pathdescription:DLP file pathtype:string - name:appSha256description:SHA 256 hash of the application associated with the threat, if availabletype:stringindicators: - sha256 - name:appCertsdescription:Certificate information for the application associated with the threat, if availabletype:arrayelement:type:objectfields: - name:signerdescription:PUA app certificate signertype:string - name:thumbprintdescription:PUA app certificate thumbprinttype:string - name:origindescription:Originating component of a detectiontype:string - name:core_remedy_itemsdescription:Details of the items cleaned or restoredtype:objectfields: - name:itemsdescription:List of remediationstype:arrayelement:type:objectfields: - name:typedescription:Type of itemtype:string - name:resultdescription:Remedy outcometype:string - name:descriptordescription:Path to filetype:string - name:processPathdescription:Undocumented fieldtype:string - name:totalItemsdescription:Remediation counttype:int