Table of Contents | ||||
---|---|---|---|---|
|
Introduction
The tables beginning withcef0.zscaler
identify events in CEF format generated by Varonis products.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
cef0.zscaler.nssweblog
cef0.zscaler.nssfwlog
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
cef0.zscaler.nssfwlog
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
hostname |
|
| |
priorityCode |
|
| |
cefTag |
|
| |
cefVersion |
|
| |
embDeviceVendor |
|
| |
embDeviceProduct |
|
| |
deviceVersion |
|
| |
signatureID |
|
| |
name |
|
| |
severity |
|
| |
_cefVer |
|
| |
act |
|
| |
app |
|
| |
cat |
|
| |
cn1 |
|
| |
cn2 |
|
| |
cn3 |
|
| |
cs1 |
|
| |
cs2 |
|
| |
cs3Label |
|
| |
cs3 |
|
| |
cs4 |
|
| |
destinationServiceName |
|
| |
destinationTranslatedAddress |
|
| |
dst |
|
| |
dpt |
|
| |
in |
|
| |
out |
|
| |
proto |
|
| |
sourceTranslatedAddress |
|
| |
spriv |
|
| |
src |
|
| |
spt |
|
| |
suser |
|
| |
hostchain |
| ✓ | |
tag |
| cefTag | ✓ |
rawMessage |
|
cef0.zscaler.nssweblog
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
hostname |
|
| |
priorityCode |
|
| |
cefTag |
|
| |
cefVersion |
|
| |
embDeviceVendor |
|
| |
embDeviceProduct |
|
| |
deviceVersion |
|
| |
signatureID |
|
| |
name |
|
| |
severity |
|
| |
_cefVer |
|
| |
act |
|
| |
app |
|
| |
cat |
|
| |
cn1Label |
|
| |
cn1 |
|
| |
cs1Label |
|
| |
cs1 |
|
| |
cs2Label |
|
| |
cs2 |
|
| |
cs3Label |
|
| |
cs3 |
|
| |
cs4Label |
|
| |
cs4 |
|
| |
cs5Label |
|
| |
cs5 |
|
| |
cs6Label |
|
| |
cs6 |
|
| |
destinationServiceName |
|
| |
dhost |
|
| |
dst |
|
| |
externalId |
|
| |
fileType |
|
| |
in |
|
| |
outcome |
| ||
out |
| ||
reason |
| ||
requestClientApplication |
| ||
requestMethod |
| ||
request |
| ||
rt |
| ||
sourceTranslatedAddress |
| ||
spriv |
| ||
src |
| ||
spt |
| ||
suser |
| ||
ZscalerNSSWeblogDLPDictionaries |
| ||
ZscalerNSSWeblogURLClass |
| ||
requestContext |
| ||
hostchain |
| ✓ | |
tag |
| cefTag | ✓ |
rawMessage |
|