WARNING: Version 6.2 of Filebeat has passed its EOL date.
This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.
Osquery fields
editOsquery fields
editFields exported by the osquery
module
osquery fields
editresult fields
editCommon fields exported by the result metricset.
osquery.result.name
edittype: keyword
The name of the query that generated this event.
osquery.result.action
edittype: keyword
For incremental data, marks whether the entry was added or removed. It can be one of "added", "removed", or "snapshot".
osquery.result.host_identifier
edittype: keyword
The identifier for the host on which the osquery agent is running. Normally the hostname.
osquery.result.unix_time
edittype: long
Unix timestamp of the event, in seconds since the epoch. Used for computing the @timestamp
column.
osquery.result.calendar_time
editString representation of the collection time, as formatted by osquery.