Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleCheck source tables
  • box.win_nxlog.dhcp

  • ddi.infoblox.dhcp.dhcpd

  • dhcp.bluecat.dhcpd

  • dhcp.infoblox.stdout

  • dhcp.isc.stdout

  • dhcp.microsoft.ip4

  • dhcp.microsoft.ip6

  • dhcp.unix.stdout

  • firewall.paloalto.system

...

Rw ui tabs macro
Rw tab
titleTables 1-45

[ box.win_nxlog.dhcp ] [ ddi.infoblox.dhcp.dhcpd ] [ dhcp.bluecat.dhcpd ] [ dhcp.infoblox.stdout ] [dhcp.microsoft.ip4]

Anchor
box.win_nxlog.dhcp
box.win_nxlog.dhcp
box.win_nxlog.dhcp

Anchor
ddi.infoblox.dhcp.dhcpd
ddi.infoblox.dhcp.dhcpd
ddi.infoblox.dhcp.dhcpd

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'ddi.infoblox.dhcp.dhcpd'

str

signature

message_type

 

str

source_ip

-

Code Block
null('')

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

-

Code Block
null('')

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

message

 

str

rawSource

rawMessage

 

str

rawTagged

tag

rawMessage

Code Block
tag + ": " + rawMessage

str

rawMessage

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
dhcp.bluecat.dhcpd
dhcp.bluecat.dhcpd
dhcp.bluecat.dhcpd

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'dhcp.bluecat.dhcpd'

str

signature

signature

 

str

source_ip

srcIp

Code Block
str(srcIp)

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

-

Code Block
null('')

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

message

 

str

rawSource

rawSource

 

str

rawTagged

rawTagged

 

str

rawMessage

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
dhcp.infoblox.stdout
dhcp.infoblox.stdout
dhcp.infoblox.stdout

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'dhcp.infoblox.stdout'

str

signature

packet

 

str

source_ip

-

Code Block
null('')

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

-

Code Block
null('')

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

message

 

str

rawSource

rawSource

 

str

rawTagged

rawTagged

 

str

rawMessage

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
dhcp.isc.stdout
dhcp.isc.stdout
dhcp.isc.stdout

Rw tab
titleTables 6-9

[ dhcp.microsoft.ip4 ] [ dhcp.microsoft.ip6 ] [ dhcp.unix.stdout ] [ firewall.paloalto.system ]

Anchor
dhcp.microsoft.ip4
dhcp.microsoft.ip4
dhcp.microsoft.ip4

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'dhcp.infoblox.ip4'

str

signature

-

Code Block
null('')

str

source_ip

srcIp

Code Block
str(srcIp)

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

description

 

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

-

Code Block
null('')

str

rawSource

-

Code Block
null('')

str

rawTagged

rawTagged

 

str

rawMessage

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Rw tab
titleTables 5-7
[ dhcp.microsoft.ip6 ] [ dhcp.unix.stdout ] [ firewall.paloalto.system ]

Anchor
dhcp.microsoft.ip6
dhcp.microsoft.ip6
dhcp.microsoft.ip6

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'dhcp.infoblox.ip6'

str

signature

-

Code Block
null('')

str

source_ip

srcIp6

 

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

description

 

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

-

Code Block
null('')

str

rawSource

rawSource

 

str

rawTagged

rawTagged

 

str

rawMessage

rawSource

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
dhcp.unix.stdout
dhcp.unix.stdout
dhcp.unix.stdout

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'dhcp.unix.stdout'

str

signature

dhcpMessageType

 

str

source_ip

-

Code Block
null('')

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

-

Code Block
null('')

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

-

Code Block
null('')

str

rawSource

rawSource

 

str

rawTagged

rawTagged

 

str

rawMessage

rawSource

 

str

hostchain

hostchain

 

str

tag

tag

 

str

Anchor
firewall.paloalto.system
firewall.paloalto.system
firewall.paloalto.system

Field in union table

Field in source table

Field transformation

Type

Extra fields

eventdate

eventdate

 

timestamp

source

-

Code Block
'firewall.paloalto.system'

str

signature

-

Code Block
null('')

str

source_ip

client_ip

Code Block
str(client_ip)

str

source_ipv4

source_ipv4

 

ip4

source_hostname

source_hostname

 

str

source_mac

source_mac

 

str

destination_mac

destination_mac

 

str

description

description

 

str

lease_ip

lease_ip

 

str

lease_mac

lease_mac

 

str

message

-

Code Block
null('')

str

rawSource

rawMessage

 

str

rawTagged

tag

rawMessage

Code Block
tag + ": " + rawMessage

str

rawMessage

rawMessage

 

str

hostchain

hostchain

 

str

tag

tag

 

str

...