Resource Details

resource_details

The Resource Details object describes details about resources that were affected by the activity/event.

Attributes

CaptionNameTypeDescription
Agent Listagent_listAgent[]A list of agent objects associated with a device, endpoint, or resource.
Cloud Partitioncloud_partitionStringThe canonical cloud partition name to which the region is assigned (e.g. AWS Partitions: aws, aws-cn, aws-us-gov).
Created Timecreated_timeTimestampThe time when the resource was created.
CriticalitycriticalityStringThe criticality of the resource as defined by the event source.
DatadataJSONAdditional data describing the resource.
Data Classificationdata_classificationData Classification[]Group:context

The Data Classification object includes information about data classification levels and data category types.

🚧 WARNING: DEPRECATED

Data Classification has been deprecated since 1.4.0. Use the attribute data_classifications instead

Data Classificationdata_classificationsData Classification[]Group:context

A list of Data Classification objects, that include information about data classification levels and data category types, identified by a classifier.
GroupgroupGroup[]The name of the related resource group.
HostnamehostnameHostnameEntity:HOSTNAME

The fully qualified name of the resource.
IP AddressipIP AddressEntity:IP_ADDRESS

The IP address of the resource, in either IPv4 or IPv6 format.
Back Ups Configuredis_backed_upBooleanIndicates whether the device or resource has a backup enabled, such as an automated snapshot or a cloud backup. For example, this is indicated by the cloudBackupEnabled value within JAMF Pro mobile devices or the registration of an AWS ARN with the AWS Backup service.
LabelslabelsString[]The list of labels associated to the resource.
Modified Timemodified_timeTimestampThe time when the resource was last modified.
NamenameStringEntity:RESOURCE_DETAILS_OBJECT_NAME

The name of the resource.
NamespacenamespaceStringThe namespace is useful when similar entities exist that you need to keep separate.
OwnerownerUser[]Entity:USER

The identity of the service or user account that owns the resource.
Raw Dataraw_dataJSONGroup:context

The event data as received from the event source.
Record IDrecord_idStringGroup:primary

Unique identifier for the object
RegionregionStringThe cloud region of the resource.
Resource Relationshipresource_relationshipGraph[]A graph representation showing how this resource relates to and interacts with other entities in the environment. This can include parent/child relationships, dependencies, or other connections.
RoleroleStringThe role of the resource in the context of the event or finding, normalized to the caption of the role_id value. In the case of 'Other', it is defined by the event source.
Role IDrole_idIntegerThe normalized identifier of the resource's role in the context of the event or finding.
  • 1: Target (TARGET)
  • 2: Actor (ACTOR)
  • 3: Affected (AFFECTED)
  • 4: Related (RELATED)
  • 0: Unknown (UNKNOWN)
  • 99: Other (OTHER)
TagstagsKey:Value object[]The list of tags; key:value pairs associated to the resource.
TypetypeStringThe resource type as defined by the event source.
Unique IDuidResource UIDEntity:RESOURCE_UID

The unique identifier of the resource.
Alternate IDuid_altResource UIDEntity:RESOURCE_UID

The alternative unique identifier of the resource.
UnmappedunmappedUnmapped[]Data from the source that was not mapped into the schema.
VersionversionStringThe version of the resource. For example 1.2.3.
Cloud Availability ZonezoneStringThe specific availability zone within a cloud region where the resource is located.

Relationships

Resource Details shown in context

Inbound Relationships

These objects and events reference Resource Details in their attributes:

Outbound Relationships

Resource Details references the following objects and events in its attributes:

This page describes qdm-1.5.1+ocsf-1.6.0


Did this page help you?