New

The executive guide to generative AI

Read more
IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Sysmon module fields

edit

These are the event fields specific to the Sysmon module.

sysmon.dns.status

Windows status code returned for the DNS query.

type: keyword

sysmon.file.archived

Indicates if the deleted file was archived.

type: boolean

sysmon.file.is_executable

Indicates if the deleted file was an executable.

type: boolean

Was this helpful?
Feedback