...
Field | Data type | Description | ||||||||
---|---|---|---|---|---|---|---|---|---|---|
alertHost |
|
| ||||||||
domain |
| Devo domain to which the alert belongs. | ||||||||
priority
|
| Priority level assigned to the alert, represented as a numerical value:
| ||||||||
context |
| Contextualization of the alert resulting from a combination of its category, domain and name.
| ||||||||
category |
|
| ||||||||
alertId |
| Unique ID assigned to the alert when triggered. | ||||||||
status |
| Condition of the triggered alert regarding their life cycle, represented as a numerical value:
| ||||||||
srcIp |
|
| ||||||||
srcPort |
|
| ||||||||
srcHost |
|
| ||||||||
dstIp |
|
| ||||||||
dstPort |
|
| ||||||||
dstHost |
|
| ||||||||
protocol |
|
| ||||||||
username |
| User who created the alert definition. | ||||||||
application |
|
| ||||||||
engine |
|
| ||||||||
extraData |
| Information extracted from the other different fields , gathered to demonstrate indicate the conditions that triggered the alert (more info here). | ||||||||
AlertContextSubscription |
|
| ||||||||
Alertcreationdate |
| Exact date on which the specified alert conditions were met and the alert triggered, which may reveal a slight delay with the eventdate (date on which the event was registered in the Devo table). |
...
Field | Data type | Description | ||||||
---|---|---|---|---|---|---|---|---|
alertHost |
|
| ||||||
errorCode |
| Explanation about the reason for the alert not being triggered. The most common are:
| ||||||
domain |
| Domain to which the alert belongs. | ||||||
priority |
| Priority level assigned to the alert, represented as a numerical value:
| ||||||
context |
| Contextualization of the alert resulting from a combination of its category, domain and name.
| ||||||
category |
|
| ||||||
status |
| Condition of the triggered alert regarding their life cycle, represented as a numerical value:
| ||||||
alertId |
| Unique ID assigned to the alert when triggered. | ||||||
srcIp |
|
| ||||||
srcPort |
|
| ||||||
srcHost |
|
| ||||||
dstIp |
|
| ||||||
dstPort |
|
| ||||||
dstHost |
|
| ||||||
protocol |
|
| ||||||
username |
| User who created the alert definition. | ||||||
application |
|
| ||||||
engine |
|
| ||||||
extraData |
| Information extracted from the other different fields , gathered to demonstrate indicate the conditions that triggered the alert (more info here). | ||||||
AlertContextSubscription |
|
| ||||||
Alertcreationdate |
| Exact date on which the specified alert conditions were met but did not trigger an alert due to an error, which may indicate a slight delay with the event date (date on which the error event was registered in the Devo table). |
...