| 
15 | 15 |  - name: policy  | 
16 | 16 |  level: custom  | 
17 | 17 |  type: object  | 
 | 18 | + object_type: keyword  | 
18 | 19 |  description: The policy fields are used to hold information about applied policy.  | 
19 | 20 | 
 
  | 
20 | 21 |  - name: policy.applied  | 
21 | 22 |  level: custom  | 
22 | 23 |  type: object  | 
 | 24 | + object_type: keyword  | 
23 | 25 |  description: information about the policy that is applied  | 
24 | 26 | 
 
  | 
25 | 27 |  - name: policy.applied.actions  | 
 | 
71 | 73 |  - name: policy.applied.response  | 
72 | 74 |  level: custom  | 
73 | 75 |  type: object  | 
 | 76 | + object_type: keyword  | 
74 | 77 |  enabled: false  | 
75 | 78 |  description: the response of actions that failed in the applied policy  | 
76 | 79 | 
 
  | 
77 | 80 |  - name: policy.applied.response.configurations  | 
78 | 81 |  level: custom  | 
79 | 82 |  type: object  | 
 | 83 | + object_type: keyword  | 
80 | 84 |  enabled: false  | 
81 | 85 |  description: the configurations of the applied policy  | 
82 | 86 | 
 
  | 
83 | 87 |  - name: policy.applied.response.configurations.events  | 
84 | 88 |  level: custom  | 
85 | 89 |  type: object  | 
 | 90 | + object_type: keyword  | 
86 | 91 |  description: overall event collection configuration and status of the applied policy  | 
87 | 92 | 
 
  | 
88 | 93 |  - name: policy.applied.response.configurations.events.concerned_actions  | 
 | 
101 | 106 |  - name: policy.applied.response.configurations.logging  | 
102 | 107 |  level: custom  | 
103 | 108 |  type: object  | 
 | 109 | + object_type: keyword  | 
104 | 110 |  description: overall logging configuration and status of the applied policy  | 
105 | 111 | 
 
  | 
106 | 112 |  - name: policy.applied.response.configurations.logging.concerned_actions  | 
 | 
119 | 125 |  - name: policy.applied.response.configurations.antivirus_registration  | 
120 | 126 |  level: custom  | 
121 | 127 |  type: object  | 
 | 128 | + object_type: keyword  | 
122 | 129 |  enabled: false  | 
123 | 130 |  description: overall antivirus registration configuration and status of the applied policy  | 
124 | 131 | 
 
  | 
 | 
138 | 145 |  - name: policy.applied.response.configurations.malware  | 
139 | 146 |  level: custom  | 
140 | 147 |  type: object  | 
 | 148 | + object_type: keyword  | 
141 | 149 |  description: overall malware configuration and status of the applied policy  | 
142 | 150 | 
 
  | 
143 | 151 |  - name: policy.applied.response.configurations.malware.concerned_actions  | 
 | 
156 | 164 |  - name: policy.applied.response.configurations.memory_protection  | 
157 | 165 |  level: custom  | 
158 | 166 |  type: object  | 
 | 167 | + object_type: keyword  | 
159 | 168 |  description: overall memory_protection configuration and status of the applied policy  | 
160 | 169 | 
 
  | 
161 | 170 |  - name: policy.applied.response.configurations.memory_protection.concerned_actions  | 
 | 
174 | 183 |  - name: policy.applied.response.configurations.streaming  | 
175 | 184 |  level: custom  | 
176 | 185 |  type: object  | 
 | 186 | + object_type: keyword  | 
177 | 187 |  description: overall data streaming configuration and status of the applied policy  | 
178 | 188 | 
 
  | 
179 | 189 |  - name: policy.applied.response.configurations.streaming.concerned_actions  | 
 | 
244 | 254 |  - name: policy.applied.response.diagnostic  | 
245 | 255 |  level: custom  | 
246 | 256 |  type: object  | 
 | 257 | + object_type: keyword  | 
247 | 258 |  enabled: false  | 
248 | 259 |  description: the diagnostic configurations of the applied policy  | 
249 | 260 | 
 
  | 
 | 
328 | 339 |  - name: policy.applied.artifacts  | 
329 | 340 |  level: custom  | 
330 | 341 |  type: object  | 
 | 342 | + object_type: keyword  | 
331 | 343 |  enabled: false  | 
332 | 344 |  description: information about protection artifacts applied.  | 
333 | 345 | 
 
  | 
334 | 346 |  - name: policy.applied.artifacts.global  | 
335 | 347 |  level: custom  | 
336 | 348 |  type: object  | 
 | 349 | + object_type: keyword  | 
337 | 350 |  description: information about global protection artifacts applied.  | 
338 | 351 | 
 
  | 
339 | 352 |  - name: policy.applied.artifacts.global.version  | 
 | 
359 | 372 |  - name: policy.applied.artifacts.user  | 
360 | 373 |  level: custom  | 
361 | 374 |  type: object  | 
 | 375 | + object_type: keyword  | 
362 | 376 |  description: information about user protection artifacts applied.  | 
363 | 377 | 
 
  | 
364 | 378 |  - name: policy.applied.artifacts.user.version  | 
 | 
384 | 398 |  - name: metrics  | 
385 | 399 |  level: custom  | 
386 | 400 |  type: object  | 
 | 401 | + object_type: keyword  | 
387 | 402 |  description: Metrics fields hold the endpoint and system's performance metrics  | 
388 | 403 | 
 
  | 
389 | 404 |  - name: metrics.documents_volume  | 
390 | 405 |  level: custom  | 
391 | 406 |  type: object  | 
 | 407 | + object_type: keyword  | 
392 | 408 |  description: Statistics about sent documents  | 
393 | 409 | 
 
  | 
394 | 410 |  - name: metrics.documents_volume.overall  | 
 | 
619 | 635 |  - name: metrics.documents_volume.api_events.sources  | 
620 | 636 |  level: custom  | 
621 | 637 |  type: object  | 
 | 638 | + object_type: keyword  | 
622 | 639 |  description: An array of API Event document statistics per source  | 
623 | 640 | 
 
  | 
624 | 641 |  - name: metrics.documents_volume.api_events.sources.source  | 
 | 
649 | 666 |  - name: metrics.uptime  | 
650 | 667 |  level: custom  | 
651 | 668 |  type: object  | 
 | 669 | + object_type: keyword  | 
652 | 670 |  description: Number of seconds since boot  | 
653 | 671 | 
 
  | 
654 | 672 |  - name: metrics.uptime.endpoint  | 
 | 
664 | 682 |  - name: metrics.cpu  | 
665 | 683 |  level: custom  | 
666 | 684 |  type: object  | 
 | 685 | + object_type: keyword  | 
667 | 686 |  description: CPU statistics  | 
668 | 687 | 
 
  | 
669 | 688 |  - name: metrics.cpu.endpoint  | 
670 | 689 |  level: custom  | 
671 | 690 |  type: object  | 
 | 691 | + object_type: keyword  | 
672 | 692 |  description: CPU metrics for the endpoint  | 
673 | 693 | 
 
  | 
674 | 694 |  - name: metrics.cpu.endpoint.mean  | 
 | 
693 | 713 |  - name: metrics.memory  | 
694 | 714 |  level: custom  | 
695 | 715 |  type: object  | 
 | 716 | + object_type: keyword  | 
696 | 717 |  description: Memory statistics  | 
697 | 718 | 
 
  | 
698 | 719 |  - name: metrics.memory.endpoint  | 
699 | 720 |  level: custom  | 
700 | 721 |  type: object  | 
 | 722 | + object_type: keyword  | 
701 | 723 |  description: Endpoint memory utilization  | 
702 | 724 | 
 
  | 
703 | 725 |  - name: metrics.memory.endpoint.private  | 
704 | 726 |  level: custom  | 
705 | 727 |  type: object  | 
 | 728 | + object_type: keyword  | 
706 | 729 |  description: The memory private to the endpoint  | 
707 | 730 | 
 
  | 
708 | 731 |  - name: metrics.memory.endpoint.private.mean  | 
 | 
718 | 741 |  - name: metrics.disks  | 
719 | 742 |  level: custom  | 
720 | 743 |  type: object  | 
 | 744 | + object_type: keyword  | 
721 | 745 |  enabled: false  | 
722 | 746 |  description: An array of disk information for the host  | 
723 | 747 | 
 
  | 
 | 
766 | 790 |  - name: metrics.malicious_behavior_rules  | 
767 | 791 |  level: custom  | 
768 | 792 |  type: object  | 
 | 793 | + object_type: keyword  | 
769 | 794 |  enabled: false  | 
770 | 795 |  description: An array of performance information about each malicious behavior rule  | 
771 | 796 | 
 
  | 
 | 
784 | 809 |  - name: metrics.system_impact  | 
785 | 810 |  level: custom  | 
786 | 811 |  type: object  | 
 | 812 | + object_type: keyword  | 
787 | 813 |  enabled: false  | 
788 | 814 |  index: false  | 
789 | 815 |  description: An array of system impact information  | 
 | 
1011 | 1037 |  # using an object here even though it is actually an array because you can only have a limited number  | 
1012 | 1038 |  # of nested fields  | 
1013 | 1039 |  type: object  | 
 | 1040 | + object_type: keyword  | 
1014 | 1041 |  enabled: false  | 
1015 | 1042 |  description: Statistics about the individual Endpoint threads (array)  | 
1016 | 1043 | 
 
  | 
 | 
1029 | 1056 |  - name: configuration  | 
1030 | 1057 |  level: custom  | 
1031 | 1058 |  type: object  | 
 | 1059 | + object_type: keyword  | 
1032 | 1060 |  description:  | 
1033 | 1061 |  Configuration fields represent the intended and applied setting for fields not part of a Policy setting  | 
1034 | 1062 |  This reflects what a given field is configured to do. The actual state of that same field is found in Endpoint.state  | 
 | 
1041 | 1069 |  - name: state  | 
1042 | 1070 |  level: custom  | 
1043 | 1071 |  type: object  | 
 | 1072 | + object_type: keyword  | 
1044 | 1073 |  description:  | 
1045 | 1074 |  Represents the current state of a non-policy setting  | 
1046 | 1075 |  These fields reflect the current status of a field, which may differ from what it is configured to be (see Endpoint.configuration)  | 
 | 
0 commit comments