...
Tag | Data table |
---|---|
casb.netskope.alert | casb.netskope.alert |
casb.proofpoint.event | casb.proofpoint.event |
Table structure
[casb.proofpoint.alert][casb.proofpoint.alert]
Anchor | ||||
---|---|---|---|---|
|
casb.proofpoint.alert
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
id |
| - |
timestamp |
| - |
description |
| - |
related_events__user_email |
| - |
related_events__user_id |
| - |
related_events__event_id |
| - |
related_events__geo_location |
| - |
related_events__user_agent |
| - |
related_events__intelligence |
| - |
related_events__timestamp |
| - |
related_events__cloud_service |
| - |
related_events__location |
| - |
related_events__meta_data |
| - |
related_events__meta_data__extracted_fields |
| - |
related_events__event_classification__id |
| - |
related_events__event_classification__sub_category |
| - |
related_events__event_classification__threat |
| - |
related_events__event_classification__category |
| - |
related_events__full_name |
| - |
tenantId |
| - |
severity |
| - |
type |
| - |
title |
| - |
subType |
| - |
related_events_found |
| - |
related_events_id |
| - |
at_devo_environment |
| - |
at_devo_pulling_id |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
casb.proofpoint.alert
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
id |
| - |
timestamp |
| - |
description |
| - |
related_events__user_email |
| - |
related_events__user_id |
| - |
related_events__event_id |
| - |
related_events__geo_location |
| - |
related_events__user_agent |
| - |
related_events__intelligence |
| - |
related_events__timestamp |
| - |
related_events__cloud_service |
| - |
related_events__location |
| - |
related_events__meta_data |
| - |
related_events__meta_data__extracted_fields |
| - |
related_events__event_classification__id |
| - |
related_events__event_classification__sub_category |
| - |
related_events__event_classification__threat |
| - |
related_events__event_classification__category |
| - |
related_events__full_name |
| - |
tenantId |
| - |
severity |
| - |
type |
| - |
title |
| - |
subType |
| - |
related_events_found |
| - |
related_events_id |
| - |
at_devo_environment |
| - |
at_devo_pulling_id |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
How is the data sent to Devo?
...