...
In this case, the valid data tables are:
Tag | Data table |
---|---|
|
|
How is the data sent to Devo?
...
cef0.trendMicro.deepSecurityAgent
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
| hostchain | |||
deviceVersion |
|
|
| |||
signatureID |
|
|
| |||
name |
|
|
| |||
severity |
|
|
| |||
TrendMicroDsFrameType |
|
|
| |||
TrendMicroDsTenant |
|
|
| |||
TrendMicroDsTenantId |
|
|
| |||
dvchost |
|
|
| |||
act |
|
|
| |||
src |
|
|
| |||
dst |
|
|
| |||
in |
|
|
| |||
msg |
|
|
| |||
smac |
|
|
| |||
dmac |
|
|
| |||
cnt |
|
|
| |||
spt |
|
|
| |||
dpt |
|
|
| |||
app |
|
|
| |||
cat |
|
|
| |||
c6a1Label |
|
|
| |||
c6a1 |
|
|
| |||
c6a2Label |
|
|
| |||
c6a2 |
|
|
| |||
c6a3Label |
|
|
| |||
c6a3 |
|
|
| |||
c6a4Label |
|
|
| |||
c6a4 |
|
|
| |||
cfp1Label |
|
|
| |||
cfp1 |
|
|
| |||
cfp2Label |
|
|
| |||
cfp2 |
|
|
| |||
cfp3Label |
|
|
| |||
cfp3 |
|
|
| |||
cfp4Label |
|
|
| |||
cfp4 |
|
|
| |||
cn1Label |
|
|
| |||
cn1 |
|
|
| |||
cn2Label |
|
|
| |||
cn2 |
|
|
| |||
cn3Label |
|
|
| |||
cn3 |
|
|
| |||
cs1Label |
|
|
| |||
cs1 |
|
|
| |||
cs2Label |
|
|
| |||
cs2 |
|
|
| |||
cs3Label |
|
|
| |||
cs3 |
|
|
| |||
cs4Label |
|
|
| |||
cs4 |
|
|
| |||
cs5Label |
|
|
| |||
cs5 |
|
|
| |||
cs6Label |
|
|
| |||
cs6 |
|
|
| |||
destinationDnsDomain |
|
|
| |||
destinationServiceName |
|
|
| |||
destinationTranslatedAddress |
|
|
| |||
destinationTranslatedPort |
|
|
| |||
deviceCustomDate1Label |
|
|
| |||
deviceCustomDate1 |
|
|
| |||
deviceCustomDate2Label |
|
|
| |||
deviceCustomDate2 |
|
|
| |||
deviceDirection |
|
|
| |||
deviceDnsDomain |
|
|
| |||
deviceExternalId |
|
|
| |||
deviceInboundInterface |
|
|
| |||
deviceMacAddress |
|
|
| |||
deviceNtDomain |
|
|
| |||
deviceOutboundInterface |
|
|
| |||
deviceProcessName |
|
|
| |||
deviceTranslatedAddress |
|
|
| |||
dhost |
|
|
| |||
dntdom |
|
|
| |||
dpid |
|
|
| |||
dpriv |
|
|
| |||
dproc |
|
|
| |||
duid |
|
|
| |||
duser |
|
|
| |||
dvc |
|
|
| |||
dvcpid |
|
|
| |||
end |
|
|
| |||
deviceFacility |
|
|
| |||
externalId |
|
|
| |||
fileCreateTime |
|
|
| |||
fileHash |
|
|
| |||
fileId |
|
|
| |||
fileModificationTime |
|
|
| |||
filePath |
|
|
| |||
filePermission |
|
|
| |||
fileType |
|
|
| |||
fname |
|
|
| |||
fsize |
|
|
| |||
oldFileCreateTime |
|
|
| |||
oldFileHash |
|
|
| |||
oldFileId |
|
|
| |||
oldFileModificationTime |
|
|
| |||
oldFileName |
|
|
| |||
oldFilePath |
|
|
| |||
oldFilePermission |
|
|
| |||
oldFileSize |
|
|
| |||
oldFileType |
|
|
| |||
outcome |
|
|
| |||
out |
|
|
| |||
proto |
|
|
| |||
reason |
|
|
| |||
requestClientApplication |
|
|
| |||
requestCookies |
|
|
| |||
requestMethod |
|
|
| |||
request |
|
|
| |||
result |
|
|
| |||
rt |
|
|
| |||
shost |
|
|
| |||
sntdom |
|
|
| |||
sourceDnsDomain |
|
|
| |||
sourceServiceName |
|
|
| |||
sourceTranslatedAddress |
|
|
| |||
sourceTranslatedPort |
|
|
| |||
spid |
|
|
| |||
spriv |
|
|
| |||
sproc |
|
|
| |||
start |
|
|
| |||
suid |
|
|
| |||
suser |
|
|
| |||
host_id |
|
| cn1 cn1Label | |||
tcp_flags |
|
| cs2Label cs2 | |||
dpi_note |
|
| cs1 cs1Label | |||
dpi_flags |
|
| cs6Label cs6 | |||
dpi_packet_position |
|
| cn3 cn3Label | |||
dpi_stream_position |
|
| cs5Label cs5 | |||
fragmentation_bits |
|
| cs3 cs3Label | |||
hostchain |
|
|
| ✓ | ||
tag |
|
| cefTag | ✓ | ||
rawMessage |
|
|
| ✓ |