ImportantThis data source query method is no longer available after February 2, 2026. For more
information on the currently available data sources for use in XDR Data Explorer queries,
go to https://trendmicro.github.io/tm-v1-schema/pages/index.
|
Secure Access Activity Data
|
Field Name
|
Type |
General Field
|
Description
|
Example
|
Products
|
|
act
|
The action
|
|
|
||
|
application
|
The name of the requested application
|
|
|
||
|
authType
|
The authentication method
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
clientIp
|
|
The endpoint internet protocol (IP)
|
10.64.23.45 |
|
|
|
clientProtocol
|
The client protocol
|
HTTP/1.1 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
clientTls
|
The transport layer security (TLS) of the client
|
TLS 1.2 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
cloudAppCat
|
The category of the event in Cloud Reputation Service
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
companyName
|
The company name
|
Trend Micro |
Trend Vision OneZero Trust Secure Access Private Access
|
||
|
contentEncoding
|
The content encoding of the request or the response
|
gzip |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
detectionType
|
The traffic detection type
|
|
|
||
|
deviceGUID
|
The globally unique identifier (GUID) of a non-endpoint object such as a network appliance
|
11111111-1111-1111-1111-111111111111 |
|
||
|
dpt
|
Port
|
The service destination port of the private application server (dstport)
|
443 |
|
|
|
dst
|
|
The destination IP (dstaddr)
|
10.10.10.10 |
|
|
|
dstLocation
|
|
-
|
The destination country
|
JP |
|
|
duration
|
The time it took the scanner to complete the scan (in milliseconds)
|
1599465660123 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
e2eLatency
|
The end-to-end traffic latency time (in milliseconds)
|
10000 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
endpointGuid
|
EndpointID
|
The device GUID
|
|
|
|
|
endpointHostName
|
EndpointName
|
The hostname of the device on which the event was detected
|
|
|
|
|
eventName
|
The name of the log event
|
|
|
||
|
eventSubName
|
The Zero Trust Secure Access - Internet Access cloud app action or the Palo Alto Networks
firewall log sub-type
|
|
|
||
|
eventTime
|
The time the agent or product detected the event |
1657135700000
|
|
||
|
failedHTTPSInspection
|
Whether the hypertext transfer protocol secure (HTTPS) traffic inspection failed
|
true |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
fileHash
|
FileSHA1
|
The secure hash algorithm 1 (SHA-1) of the file that violated the policy
|
1e15bf99022a9164708cebb3eace8fd61ad45cba
|
|
|
|
fileHashSha256
|
FileSHA2
|
The SHA-256 of the file that violated the policy
|
ba9edecdd09de1307714564c24409bd25508e22fe11c768053a08f173f263e93
|
|
|
|
fileName
|
|
The name of file that violated the policy
|
word.doc |
|
|
|
fileSize
|
The size of file that violated the policy
|
12134
|
|
||
|
fileType
|
The type of file that violated the policy
|
Microsoft Word |
|
||
|
filterRiskLevel
|
The top level risk level of the event
|
|
Security Analytics Engine
|
||
|
groupId
|
The group ID for the management scope filter
|
11111111-1111-1111-1111-111111111111 |
Security Analytics Engine
|
||
|
isPrivateApp
|
Whether the requested application is private
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
isRetroScan
|
Whether the event matches the Security Analytics Engine filter
|
true |
Security Analytics Engine
|
||
|
logReceivedTime
|
The time when the Extended Detection and Response (XDR) log was received
|
1656324260000 |
Security Analytics Engine
|
||
|
malName
|
The name of the detected malware
|
Trend Vision One Zero Trust Secure Access Internet Access
|
|||
|
mimeType
|
The mime type or content type of the response body
|
Text/HTML |
|
||
|
objectId
|
The universally unique identifier (UUID) of Trend Vision One Zero Trust Secure Access Private Access
|
|
Trend Vision OneZero Trust Secure Access Private Access
|
||
|
originEventSourceType
|
The source type of the original event which matches the Security Analytics Engine
filter
|
EVENT_SOURCE_NETWORK_ACTIVITY |
Security Analytics Engine
|
||
|
originUUID
|
The UUID of the original event which matches the Security Analytics Engine filter
|
11111111-1111-1111-1111-111111111111 |
Security Analytics Engine
|
||
|
osName
|
The host operating system (OS) name
|
|
|
||
|
pname
|
The product name
|
|
|
||
|
policyTemplate
|
The Data Loss Prevention template names
|
Australia, New Zealand: Healthcare Template, Germany: Banking and Financial Information |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
policyTreePath
|
The policy tree path (endpoint only)
|
policyname1/policyname2/policyname3 |
Security Analytics Engine
|
||
|
policyUuid
|
The policy UUID
|
|
|
||
|
principalName
|
UserAccount
|
The User Principal Name
|
sample_email@trendmicro.com |
|
|
|
productCode
|
The internal product code
|
|
|
||
|
profile
|
The name of the triggered Threat Protection template or Data Loss Prevention profile
|
Trend Vision One Zero Trust Secure Access Internet Access
|
|||
|
pver
|
The product version
|
1
|
|
||
|
request
|
URL
|
The destination uniform resource locator (URL) that the user is accessing
|
|
|
|
|
requestBase
|
|
The URL domain
|
|
|
|
|
requestMethod
|
The network protocol request method
|
POST |
|
||
|
requestMimeType
|
The type of request content
|
application/json; charset=utf-8 |
|
||
|
requestSize
|
The request length
|
1324 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
responseSize
|
The response length
|
1324 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
ruleName
|
The name of the triggered cloud access rule
|
|
|
||
|
ruleUuid
|
The risk assessment and control design that is defined by Zero Trust Secure Access
risk control rules
|
11111111-1111-1111-1111-111111111111 |
Trend Vision OneZero Trust Secure Access Private Access
|
||
|
sender
|
The Zero Trust Internet Access gateway location
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
serverProtocol
|
The version of the HTTP protocol between the Service Gateway and server or website
|
HTTP/1.1 |
|
||
|
serverRespTime
|
The time the server took to respond to the request (in milliseconds)
|
1599465660123 |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
serverTls
|
The TLS version between the Service Gateway and server or website
|
TLS 1.2 |
|
||
|
sessionEnd
|
The session end time (in seconds)
|
1575462989 |
|
||
|
sessionStart
|
Session start time (in seconds)
|
1575462989 |
|
||
|
spt
|
Port
|
The virtual port assigned to the Secure Access Module (srcport)
|
57763 |
|
|
|
src
|
|
Source IP (srcaddr)
|
100.100.100.100 |
|
|
|
srcLocation
|
|
-
|
The source country
|
JP |
|
|
suid
|
UserAccount
|
The user name or IP address (IPv4)
|
|
|
|
|
tags
|
Technique
|
The detected technique ID based on the alert filter
|
|
Security Analytics Engine
|
|
|
tlsJA3Fingerprint
|
JA3 fingerprint
|
|
|||
|
trafficType
|
The Zero Trust Internet Access gateway service mode
|
|
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
userDepartment
|
The user department request method
|
Sales |
Trend Vision One Zero Trust Secure Access Internet Access
|
||
|
userDomain
|
|
The Microsoft Entra ID domain or the domain of the Trend Micro Anti-Spam administrator portal user name
|
trendmicro.com |
|
|
|
uuid
|
The unique key of the log
|
11111111-1111-1111-1111-111111111111 |
Security Analytics Engine
|
