Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Introduction

Tags beginning withnac.forescout identify events generated by Forescout.

...

The full tag must have 3 levels. The first two are fixed asnac.forescout. The third level identifies the type of events sent, and the fourth level indicates the event subtype. 

...

Technology

...

Brand

...

Type

...

Subtype

...

nac

...

forescout

...

  • counteract

...

  • policy

These are the valid tags and corresponding data tables that will receive the parsers' data:

TagProduct/Service

Tags

Data table

Forescout counterACT

nac.forescout.counteract.actions

nac.forescout.counteract.actions

nac.forescout.counteract.common

nac.forescout.counteract.common

nac.forescout.counteract.log

nac.forescout.counteract.log

nac.forescout.counteract.policy

nac.forescout.counteract.policy

nac.forescout.counteract.system

nac.forescout.counteract.system

Table structure

This is the set displayed by these tables:

Anchor
nac.forescout.counteract.actions
nac.forescout.counteract.actions
nac.forescout.counteract.actions

Field

Type

Source field name

Extra Label

eventdate

timestamp

machine

str

vmachine

eventType

str

ipAddr

ip4

macAddr

str

hostName

str

dnsName

str

user

str

rawMessage

str

unknown

str

hostchain

str

tag

str

Anchor
nac.forescout.counteract.common
nac.forescout.counteract.common
nac.forescout.counteract.common

Field

Type

Source field name

Extra Label

eventdate

timestamp

machine

str

vmachine

eventtype

str

sourceIp

ip4

destinationIp

ip4

destinationPort

str

rawMessage

str

unknown

str

hostchain

str

tag

str

Anchor
nac.forescout.counteract.log
nac.forescout.counteract.log
nac.forescout.counteract.log

Field

Type

Source field name

Extra Label

eventdate

timestamp

machine

str

vmachine

log

str

details

ip4

severity

ip4

rawMessage

str

unknown

str

hostchain

str

tag

str

nac.forescout.counteract.policy
Anchor
nac.forescout.counteract.policy
nac.forescout.counteract.policy

Field

Type

Extra Label

eventdate

timestamp-

machine

str-

serverdate

str

-

hostname

str

-

procName

str-

procId

str

-

sourceIp

ip4

-

rule

str

-

details

str

match

-str

matchcategory

str

rawMessage

-str

categoryhostchain

str

-

rawMessagetag

str-

Anchor
nac.forescout.counteract.system
nac.forescout.counteract.system
nac.forescout.counteract.system

Field

Type

Extra Label

eventdate

timestamp

message

str

hostchain

str

tag

str