Global Search Default Table Columns

Global Search Default Table Columns

This table provides an overview of the system columns as available in the Global Search table. The majority of the columns for each tab are based on the default Threat Rules, which are not listed further mentioned below. If you create your own Threat Rules, those will also be available in Global Search.

TabColumnDescription
IdentitiesIdentity IdA 32-bit UUID for the found identity.
Identity NameThe name under which the identity was established in the system.
Identity EmailThe email associated with the established identity.
Mapped AccountsNumber of accounts mapped to the specific identity.
AccountsPlatformThe system platform from which the account was collection.
Data SourceThe collector module that retrieved the account data.
IdA 32-bit UUID for the found account.
Data Source IdA 32-bit UUID for the data source that collected the account data.
Login ShellShell used for the service account.
Home DirIf applicable the home directory for account.
DomainCorporate domain for the account.
ProviderThe OpenID provider established for the this account.
Computer NameThe device name if part of the collected account data.
TypeOne of four: User, Service, Resource, or Computer account as it exists on a platform. The type defines what object the account is, for example, an account of Type: User with a Classification: Service.
Display NameThe established display name for the collected account.
Account NameThe name under which the account was initially created.
Mapped IdentitiesThe names of the mapped identities for the account.
PathLocation of the account object, like the OU of account. Location where the account object exists.
EmailThe email address associated with the account.
UPNThe User Principal Name for the established account (name and email slug or domain reference)
Login AgeTime past since the last sign in to this account.
Password AgeTime past since the password on the account was last rotated.
MFAMulti-factor authentication is enable or disabled for the account.
StatusMFA status availability for the account.
GroupsGroup PlatformThe system platform on which this group was discovered.
Data SourceThe collector module that retrieved the group data.
Group DomainThe directory service domain for the retrieved group.
Group ProviderThe OpenID provider established for the this group.
Group Computer NameThe device name for the group if part of the collected account data.
Group NameThe group name of the group as established in the directory service.
Group Display NameThe group display name under which the group was established in the directory service.
Group PathLocation where the group object exists.
Direct Member CountNumber of direct members in the group.
Expanded Member CountNumber of expanded members in the group.