Table of Contents | ||||
---|---|---|---|---|
|
...
The full tag must have three levels. The first two are fixed as uba.varonis. The third level identifies the technology type and it can be dataalert (events generated by datAlert) or alerts (events generated by DatAdvantage).
...
Therefore, the valid tags include:
uba.varonis.dataalert
uba.varonis.alerts
uba.varonis.audit
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
uba.varonis.dataalert | uba.varonis.dataalert |
uba.varonis.alerts | uba.varonis.alerts |
uba.varonis.audit | uba.varonis.audit |
Table structure
This is the set displayed by these tables.
Anchor | ||||
---|---|---|---|---|
|
uba.varonis.dataalert
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
host |
| - |
RuleName |
| - |
AlertTime |
| - |
EventTime |
| - |
ActingObject |
| - |
EventType |
| - |
FileServerDomain |
| - |
Path |
| - |
AffectedObject |
| - |
IPAddressHost |
| - |
AdditionalData |
| - |
AlertDescription |
| - |
ChangedPermissions |
| - |
PermissionsBeforeChange |
| - |
PermissionsAfterChange |
| - |
rawMessage |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
uba.varonis.alerts
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
host |
| - |
hostchain |
| ✓ |
cefVersion |
| - |
embDeviceVendor |
| - |
embDeviceProduct |
| - |
deviceVersion |
| - |
signatureID |
| - |
name |
| - |
severity |
| - |
_cefVer |
| - |
act |
| - |
cat |
| - |
ruleID |
| - |
mailRecipient |
| - |
ruleName |
| - |
attachmentName |
| - |
clientAccessType |
| - |
mailboxAccessType |
| - |
changedPermissions |
| - |
cnt |
| - |
deviceCustomDate1Label |
| - |
deviceCustomDate1 |
| - |
dhost |
| - |
dpriv |
| - |
duser |
| - |
dvchost |
| - |
end |
| - |
filePath |
| - |
filePermission |
| - |
fileType |
| - |
fname |
| - |
msg |
| - |
oldFilePermission |
| - |
outcome |
| - |
rt |
| - |
start |
| - |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
uba.varonis.audit
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
host |
| - |
rawMessage |
| ✓ |
RuleID |
| - |
RuleName |
| - |
AlertTime |
| - |
EventTime |
| - |
ActingObject |
| - |
EventType |
| - |
FileServerDomain |
| - |
Path |
| - |
AffectedObject |
| - |
IPAddressHost |
| - |
AdditionalData |
| - |
Severity |
| - |
Threshold |
| - |
FirstEventTime |
| - |
EventStatus |
| - |
ActingObjectSAMAccountName |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
Varonis configuration
To set up message forwarding, you will need to take the following steps in the DatAlert area of the DatAdvantage management tool:
...
Source Port → 13076
Target Tag → uba.varonis.dataalert
Select both Stop Processing and Sent without syslog tag
...
Rule 2 - datAdvantage events
Source Port → 13076
Target Tag → uba.varonis.alerts
Select both Stop Processing and Sent without syslog tag
...