An EDR event associated with an asset as delivered to the UI. To convey EDR events internally within the server, use AssetRawEdrEvent instead.
JSON representation |
---|
{ "eventTime": string, "displayName": string, "chip": { object ( |
Fields | |
---|---|
eventTime |
Date/time of the event. Uses RFC 3339, where generated output will always be Z-normalized and uses 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
displayName |
The canonical string to display for the event. |
chip |
The chip to display. |
filterProperties |
A list of filter properties associated the event. |
sidebarEntries[] |
All the sidebar entries. |
rawLogsToken |
A token to request raw logs, this is opaque to the client. If empty, no raw logs can be requested. |
assetIndicator |
AssetIndicator used for pivoting. |
fileNames[] |
This field is only used for hash view timeline: it contains the file names associated with the queried file hash. |