Skip to main content

AnomalyEvidence

Properties

NameTypeDescriptionNotes
source(optional) stringEvidence source system.[default to undefined]
timestamp(optional) AnomalyEvidenceTimestamp[default to undefined]
agentAttributeType(optional) stringAttribute type captured for SENTINEL detections; null for SIEM detections.[default to undefined]
agentAttributeValue(optional) stringAttribute value captured for SENTINEL detections; null for SIEM detections.[default to undefined]
baseline(optional) AnomalyBaselinePeer-group baseline for SIEM detections; null for SENTINEL detections.[default to undefined]