ESET PROTECT – Table of Contents

Open XDR Data Format

Open XDR Data Format is based on Elastic Common Schema (ECS), which is the normalized format used for ESET Open XDR. ECS simplifies writing queries and enables correlating data across different data sources. Telemetry events, indicators and incidents are normalized into this schema across products and integrations that are part of the Open XDR Platform.


Note

Open XDR Data is available from computers running ESET Management Agent version 13.0+ and ESET Inspect Connector 3.0+.

Find more about unifying ESET Inspect and ESET PROTECT (Open XDR).

Field Sets

ECS defines multiple groups of related fields, known as Field Sets.

arrow_down_businessAgent Field Set
arrow_down_businessBase Field Sets
arrow_down_businessCloud Field Set
arrow_down_businessCode Signature Field Set
arrow_down_businessDestination Field Set
arrow_down_businessDevice Field Set
arrow_down_businessDLL Field Set
arrow_down_businessECS Field Set
arrow_down_businessEvent Field Set
arrow_down_businessFile Field Set
arrow_down_businessHash Field Set
arrow_down_businessHost Field Set
arrow_down_businessNetwork Field Set
arrow_down_businessOperating System Field Set
arrow_down_businessPE Field Set
arrow_down_businessProcess Field Set
arrow_down_businessRelated Field Set
arrow_down_businessRule Field Set
arrow_down_businessSource Field Set
arrow_down_businessURL Field Set
arrow_down_businessUser Field Set

Extensions

Custom ECS extensions are additional field sets introduced by integrations to capture data that is not covered by the standard Elastic Common Schema. These fields allow for richer context and vendor-specific attributes while maintaining compatibility with ECS. Extensions must follow ECS naming conventions and are grouped under a clear namespace to avoid conflicts with standard ECS fields.

arrow_down_businessESET Extension