OS Threat Detail Fields
In addition to the Common Threat Detail Fields, the
details
block for
THREAT
events of
type=OS
also includes an
osVersion
field:
"details": {
...,
"assessments": [...],
"osVersion": "9.0.1"
}
Field | Type | Description |
---|---|---|
|
String | The OS version, for example "10.3". |