Fleet uses osquery tables to query operating system, hardware, and software data. Each table provides specific data for analysis and filtering.
es_process_file_events
File integrity monitoring events from EndpointSecurity including process context.
Column | Type | Description |
---|---|---|
dest_filename | text | Destination filename for the event |
eid | text | Event ID Not returned in SELECT * FROM es_process_file_events . |
event_type | text | Type of EndpointSecurity event |
filename | text | The source or target filename for the event |
global_seq_num | bigint | Global sequence number |
parent | bigint | Parent process ID |
path | text | Path of executed file |
pid | bigint | Process (or thread) ID |
seq_num | bigint | Per event sequence number |
time | bigint | Time of execution in UNIX time |
version | integer | Version of EndpointSecurity event |