Table of Contents | ||||
---|---|---|---|---|
|
...
Valid tags and data tables
The full tag must have four levels. The first three are fixed asgateway.okta.oag
. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Okta Access Gateway |
|
|
|
| |
|
|
...
These are the fields displayed in these tables:
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
rawHostName |
| ✓ | |
rawHostIp |
| ✓ | |
rawMessage |
| ✓ | message |
hostchain |
| ✓ | |
tag |
| ✓ | |
TIMESTAMP |
| ✓ | |
HOSTNAME |
| ✓ | |
label |
| ✓ | |
App_Hostname |
| ✓ | |
Client_IP |
| ✓ | |
Request |
| ✓ | |
URL |
| ✓ | |
HTTP_Status_Code |
| ✓ | |
Request_size |
| ✓ | |
HTTP_Referrer |
| ✓ | |
User_Agent |
| ✓ | |
X_Forwarded_For |
| ✓ | |
Request_Time |
| ✓ | |
Response_Time |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
rawHostName |
| ✓ | |
rawHostIp |
| ✓ | |
rawMessage |
| ✓ | message |
hostchain |
| ✓ | |
tag |
| ✓ | |
TIMESTAMP |
| ✓ | |
HOSTNAME |
| ✓ | |
APPLICATION |
| ✓ | |
SUB_PROCESS |
| ✓ | |
COMPONENT |
| ✓ | |
SUB_COMPONENT |
| ✓ | |
LOG_LEVEL |
| ✓ | |
EVENT |
| ✓ | |
STRUCTURED_DATA |
| ✓ | |
NAME |
| ✓ | |
DOMAIN |
| ✓ | |
TYPE |
| ✓ | |
RESULT |
| ✓ | |
REASON |
| ✓ | |
SESSION_ID |
| ✓ | |
RESOURCE |
| ✓ | |
METHOD |
| ✓ | |
POLICY |
| ✓ | |
POLICY_TYPE |
| ✓ | |
DURATION |
| ✓ | |
APP |
| ✓ | |
APP_TYPE |
| ✓ | |
APP_DOMAIN |
| ✓ | |
REMOTE_IP |
| ✓ | |
USER_AGENT |
| ✓ | |
USERNAME |
| ✓ | |
USER |
| ✓ | |
SOURCE |
| ✓ | |
ACTION |
| ✓ | |
REALM |
| ✓ | |
SUBJECT |
| ✓ | |
STATUS |
| ✓ | |
MESSAGE |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
rawHostName |
| ✓ | |
rawHostIp |
| ✓ | |
rawMessage |
| ✓ | message |
hostchain |
| ✓ | |
tag |
| ✓ | |
TIMESTAMP |
| ✓ | |
HOSTNAME |
| ✓ | |
APPLICATION |
| ✓ | |
SUB_PROCESS |
| ✓ | |
COMPONENT |
| ✓ | |
LOG_LEVEL |
| ✓ | |
EVENT |
| ✓ | |
STRUCTURED_DATA |
| ✓ | |
STATUS |
| ✓ | |
DU_HOSTNAME |
| ✓ | |
FILESYSTEM |
| ✓ | |
MOUNT |
| ✓ | |
USAGE |
| ✓ | |
CACHE_SIZE |
| ✓ | |
CURRENT_USAGE |
| ✓ | |
USAGE_PERCENT |
| ✓ | |
USER |
| ✓ | |
EXPIRY |
| ✓ | |
SERVICE |
| ✓ | |
NAME |
| ✓ | |
UUID |
| ✓ | |
MESSAGE |
| ✓ |