Table of Contents | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Introduction
The tags beginning with iam.cyberark
identify events generated by Cyberark.
...
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Cyberark |
|
|
|
| |
|
| |
|
|
For more information, read more about Devo tags.
...
These are the fields displayed in these tables:
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra field |
---|---|---|
eventdate |
| |
Hostname |
| |
EventReceivedTime |
| |
SourceModuleName |
| |
SourceModuleType |
| |
SourceName |
| |
Message |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
old_entity |
|
|
entity_name |
|
|
entity_uuid |
|
|
normalized_user |
|
|
internal_session_id |
|
|
impersonator_uuid |
|
|
template_name |
|
|
az_deployment_id |
|
|
event_type |
|
|
application_name |
|
|
directory_service_uuid |
|
|
internal_tracking_id |
|
|
auth_method |
|
|
entity_type |
|
|
when_occurred |
|
|
az_role_id |
|
|
when_logged |
|
|
table_name |
|
|
new_entity |
|
|
tenant |
|
|
application_id |
|
|
thread_type |
|
|
from_ip_address |
|
|
from_ip_addressv4 |
|
|
from_ip_addressv6 |
|
|
request_device_os |
|
|
request_is_mobile_device |
|
|
level2 |
|
|
directory_service_partner_name |
|
|
application_type |
|
|
user_guid |
|
|
id |
|
|
az_role_name |
|
|
request_host_name |
|
|
request_host_namev4 |
|
|
request_host_namev6 |
|
|
at_devo_pulling_id |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
act |
|
| |
rt |
|
| |
suser |
|
| |
fname |
|
| |
dvc |
|
| |
shost |
|
| |
dhost |
|
| |
duser |
|
| |
externalId |
|
| |
app |
|
| |
reason |
|
| |
cs1Label |
|
| |
cs1 |
|
| |
cs2Label |
|
| |
cs2 |
|
| |
cs3Label |
|
| |
cs3 |
|
| |
cs4Label |
|
| |
cs4 |
|
| |
cs5Label |
|
| |
cs5 |
|
| |
cn1Label |
|
| |
cn1 |
|
| |
cn2Label |
|
| |
cn2 |
|
| |
msg |
|
| |
hostchain |
| ✓ |
|
tag |
| ✓ |
|
rawMessage |
| rawSource |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label | Source field name |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
leefVer |
|
| |
vendor |
|
| |
product |
|
| |
version |
|
| |
eventID |
|
| |
sev |
|
| |
Action |
|
| |
EventMessage |
|
| |
OSUser |
|
| |
usrName |
|
| |
src |
|
| |
SourceUser |
|
| |
TargetUser |
|
| |
File |
|
| |
Safe |
|
| |
Location |
|
| |
Category |
|
| |
RequestId |
|
| |
Reason |
|
| |
ExtraDetails |
|
| |
GatewayStation |
|
| |
CAPolicy |
|
| |
hostchain |
| ✓ |
|
tag |
| ✓ |
|
rawMessage |
|
|