...
Introduction
Tags beginning with authcspm.rsahorangi identify events generated by RSA SecurID.
...
The full tag must have 4 levels. The first two are fixed as auth cspm.rsahorangi. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
Technology | Brand | Type | Subtype | |
---|---|---|---|---|
authcspm | rsahorangi |
|
|
|
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
authcspm.rsahorangi.secureidwarden.systemalertsauth | cspm.rsahorangi.secureid.system |
auth.rsa.secureid.runtime | auth.rsa.secureid.runtime |
auth.rsa.secureid.admin | auth.rsa.secureid.admin |
auth.rsa.secureid.trace | auth.rsa.secureid.tracewarden.alerts |
Table structure
This is the set displayed by these tables.
...
Rw tab | ||
---|---|---|
|
...
cspm.horangi.warden.alerts
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
...
hostname |
| - |
...
alert__ |
...
id |
...
| - |
...
alert__monitoring_groups |
| - |
...
alert__severity |
| - |
...
alert__ |
...
title |
| - |
...
alert__ |
...
type |
| - |
...
alert__warden_url |
| - |
...
client_ip
...
cloud__account__id |
| - |
...
server_ip
...
cloud__account__name |
| - |
...
cloud__provider |
| - |
...
cloud__ |
...
region |
| - |
...
event__action |
| - |
...
identity__id |
| - |
...
session_id
identity__is_service |
| - |
...
identity__ |
...
name |
| - |
...
identity_ |
...
_ |
...
type |
| - |
...
identity_ |
...
_ |
...
user_ |
...
agent |
| - |
...
identity__metadata_ |
...
_ |
...
etag |
| - |
...
identity__metadata_ |
...
_name |
| - |
...
identity__metadata_ |
...
_ |
...
| - |
...
arg_1
identity__metadata__horangi |
| - |
...
identity__metadata__uniqueId |
| - |
...
identity__metadata__projectId |
| - |
...
identity__metadata__displayName |
| - |
...
identity__metadata__oauth2ClientId |
| - |
...
arg_6
identity__metadata__policyanalyzer |
| - |
...
identity__metadata__id |
| - |
...
identity__metadata__kind |
|
...
✓
...
- | |
identity__metadata__emails |
|
...
✓
...
Field
...
Type
...
Extra Label
...
eventdate
...
timestamp
...
-
...
- | ||
identity__metadata__aliases |
| - |
...
identity__metadata__isAdmin |
| - |
identity__metadata__archived |
| - |
identity__metadata__addresses |
| - |
identity__metadata__languages |
| - |
...
server_date
...
identity__metadata__locations |
| - |
...
identity__metadata__relations |
| - |
...
category
...
identity__metadata__suspended |
| - |
...
identity__metadata__customerId |
| - |
...
identity__metadata__externalIds |
| - |
...
identity__metadata__orgUnitPath |
| - |
...
client_ip
...
identity__metadata__creationTime |
| - |
...
server_ip
...
identity__metadata__primaryEmail |
| - |
...
action
...
identity__metadata__agreedToTerms |
| - |
...
action_id
...
identity__metadata__ipWhitelisted |
| - |
...
result
...
identity__metadata__lastLoginTime |
| - |
...
identity__metadata__organizations |
| - |
...
identity__metadata__posixAccounts |
| - |
...
identity__metadata__recoveryEmail |
| - |
...
identity__ |
...
metadata_ |
...
_ |
...
recoveryPhone |
| - |
...
identity__ |
...
metadata_ |
...
_ |
...
sshPublicKeys |
| - |
...
identity__metadata_ |
...
_ |
...
isMailboxSetup |
...
| - |
...
identity__metadata_ |
...
_ |
...
isEnforcedIn2Sv |
...
| - |
...
identity__metadata_ |
...
_ |
...
isEnrolledIn2Sv |
...
| - |
...
agent_id
...
identity__metadata__isDelegatedAdmin |
| - |
...
identity__ |
...
metadata_ |
...
_ |
...
changePasswordAtNextLogin |
...
| - |
...
agent_address
identity__metadata__includeInGlobalAddressList |
| - |
...
identity__metadata__thumbnailPhotoUrl |
| - |
...
identity__metadata__thumbnailPhotoEtag |
| - |
...
identity__metadata__gender |
| - |
identity__metadata__description |
| - |
...
resource_ |
...
_ |
...
category |
| - |
...
resource__id |
| - |
...
resource__ |
...
type |
| - |
...
resource__metadata |
| - |
...
rule__name |
| - |
...
rule__description |
| - |
...
source__geo__city |
| - |
...
source__geo__continent |
| - |
...
source__geo__country |
| - |
...
source__ip |
| - |
...
timestamp |
| - |
at_devo_collector_version |
| - |
...
at_devo_source_id |
| - |
...
at_devo_project_id |
| - |
...
more_args
at_devo_retrieving_timestamp |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
...
✓ |