CCFH-202B · Question #15
You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?
The correct answer is A. Events Data Dictionary. The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because it provides a reference of information about the events found in the Investigate > Event Search page of the Falcon Console. The Events Data Dictionary describes each event…
Question
You need details about key data fields and sensor events which you may expect to find from Hosts running the Falcon sensor. Which documentation should you access?
Options
- AEvents Data Dictionary
- BStreaming API Event Dictionary
- CHunting and Investigation
- DEvent stream APIs
How the community answered
(36 responses)- A92% (33)
- B6% (2)
- D3% (1)
Explanation
The Events Data Dictionary found in the Falcon documentation is useful for writing hunting queries because it provides a reference of information about the events found in the Investigate > Event Search page of the Falcon Console. The Events Data Dictionary describes each event type, field name, data type, description, and example value that can be used to query and analyze event data. The Streaming API Event Dictionary, Hunting and Investigation, and Event stream APIs are not documentation that provide details about key data fields and sensor events.
Topics
Community Discussion
No community discussion yet for this question.