MITRE ATT&CK
Reference records linking events or rules to MITRE ATT&CK tactics and techniques for threat correlation.
EnginsightGlobal Fields (4)
Field | Type |
---|---|
ngs.id Unique identifier for the log entry. | string |
ngs.createdAt Timestamp when the event was created locally. | pdate |
ngs.indexedAt Timestamp when the log was indexed into the SIEM. | pdate |
ngs.source Origin or source system of the log. | string |
Reference-Specific Fields (5)
Field | Type |
---|---|
mitre.id | string |
mitre.sub | string |
mitre.type | text_general |
mitre.name | text_general |
mitre.tactics | text_general [] |
Sample Log Event
Below is a representative JSON log entry showing key fields as they’re emitted by the system. Depending on the context of the event, some fields may be omitted if they’re not applicable.