...
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
IBM Cloud Activity Tracker |
|
|
IBM SoftLayer |
|
|
IBM Cloud Virtual Private Cloud (VPC) |
|
|
For more information, read more About Devo tags.
...
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
|
| |||
account |
|
|
| |||
cluster |
|
|
| |||
host |
|
|
| |||
ingester |
|
|
| |||
logtype |
|
|
| |||
file |
|
|
| |||
line |
|
|
| |||
rawline |
|
|
| |||
ts |
|
|
| |||
platform |
|
|
| |||
app |
|
|
| |||
ip_v4 |
|
| ip | |||
ip_v6 |
|
| ip | |||
_key2 |
|
|
| |||
level2 |
|
|
| |||
bid |
|
|
| |||
data_event |
|
|
| |||
log_source_crn |
|
|
| |||
save_service_copy |
|
|
| |||
id |
|
|
| |||
event_id |
|
|
| |||
correlation_id |
|
|
| |||
event_time |
|
|
| |||
event_outcome |
|
|
| |||
action |
|
|
| |||
severity |
|
|
| |||
message |
|
|
| |||
mezmo_line_size |
|
|
| |||
observer__name |
|
|
| |||
initiator__id |
|
|
| |||
initiator__name |
|
|
| |||
initiator__authn_id |
|
|
| |||
initiator__authn_name |
|
|
| |||
initiator__type_uri |
|
|
| |||
initiator__host__agent |
|
|
| |||
initiator__host__address_ip4 |
|
| initiator__host__address | |||
initiator__host__address_vp6 |
|
| initiator__host__address | |||
initiator__host__address_type |
|
|
| |||
initiator__credential__type |
|
|
| |||
reason__reason_code |
|
|
| |||
reason__reason_type |
|
|
| |||
destination_ip__id |
|
|
| |||
destination_ip__type_uri |
|
|
| |||
destination_ip__name |
|
|
| |||
request_data__local_time |
|
|
| |||
request_data__tag_type |
|
|
| |||
request_data__body__tag_names |
|
|
| |||
request_data__body__o_resources |
|
|
| |||
response_data__results |
|
|
| |||
at_devo_environment |
|
|
| |||
at_devo_pulling_id |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
|
| |||
account_id |
|
|
| |||
event_create_date |
|
|
| |||
event_name |
|
|
| |||
ipv4 |
|
| ip | |||
ipv6 |
|
| ip | |||
label |
|
|
| |||
meta_data |
|
|
| |||
object_id |
|
|
| |||
object_name |
|
|
| |||
trace_id |
|
|
| |||
user_id |
|
|
| |||
user_type |
|
|
| |||
open_id_connect_user_name |
|
|
| |||
username |
|
|
| |||
at_devo_environment |
|
|
| |||
at_devo_pulling_id |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
| |
hostname |
|
|
| |
account |
|
|
|
key |
|
|
|
version |
|
|
|
collector_crn |
|
|
|
logtype
str
file
str
line
str
rawline
str
ts
timestamp
app
str
ip4
ip4
Code Block |
---|
ip4(ip) |
ip
ip6
ip6
Code Block |
---|
ip6(ip) |
ip
bid
str
attached_endpoint_type |
|
|
|
level2
str
network_interface_id |
|
|
|
state
str
capture_start_time
timestamp
instance_crn |
|
|
|
version
str
vpc_crn |
|
|
| |
capture_end_time |
|
|
|
capture_ |
start_ |
time |
str
|
|
|
state |
|
|
| |
flow_log_start_time |
str
|
|
| |
flow_log_end_time |
str
|
|
|
flow_ |
timestamp
log_direction |
|
|
| |
flow_log_action |
|
|
| |
flow_log_initiator_ip_ |
v4 |
|
| flow_log_initiator_ip | |||
flow_log_initiator_ |
ip_v6 |
|
| flow_log_initiator_ip | |||
flow_log_initiator_port |
|
|
| |||
flow_log_target_ |
ip_v4 |
|
| flow_log_target_ip | |||
flow_log_target_ip_ |
v6 |
|
| flow_log_target_ip |
initiator_port
int4
flow_log_target_port |
|
|
| |
flow_log_transport_protocol |
|
|
| |
flow_log_ether_type |
|
|
| |
flow_log_was_initiated |
|
|
| |
flow_log_was_terminated |
|
|
| |
flow_log_bytes_from_initiator |
|
|
| |
flow_log_packets_from_initiator |
|
|
| |
flow_log_bytes_from_target |
|
|
| |
flow_log_packets_from_target |
|
|
| |
flow_log_cumulative_ |
packets_from_initiator |
|
|
| |
flow_log_cumulative_packets_from_ |
target |
|
|
| |
flow_log_cumulative_bytes_from_target |
int4
|
|
| |
flow_log_cumulative_ |
bytes_from_ |
int4
key
str
mezmo_line_size
int4
id
str
initiator |
|
|
| |
at_devo_environment |
|
|
| |
at_devo_pulling_id |
|
|
| |
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |