Table of Contents | ||||
---|---|---|---|---|
|
...
Valid tags and data tables
The full tag can have 4 or 5 levels. In some cases, there can be an optional level containing the process name and the process ID, which would occupy the fifth or the sixth level. The first two are fixed asadn.f5
. The third level identifies the type of events sent, and the fourth, fifth, and sixth levels indicate the event subtypes.
* Required or optional if it is a process name and ID.
** Optional. It is a process name and ID.
These are the valid tags and corresponding data tables that will receive the parsers' data:
...
For more information, read more About Devo tags.
How is the data sent to Devo?
The F5 BigIp platform has two different mechanisms for sending data and/or management plane logs to remote syslog servers or a pool of them:
...
Rw ui tabs macro | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Anchor | | adn.f5.bigip.pktfilter | adn.f5.bigip.pktfilter | adn.f5.bigip.pktfilter||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Field | Type | Extra fields | eventdate |
| hostName |
| facility |
| logLevel |
| processName |
| processId |
| logId |
| message |
| accessProfile |
| partition |
| sessionId |
| packet |
| filter |
| action |
| vlan |
| len |
| srcIp |
| srcPort |
| dstIp |
| dstPort |
| protocol
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostName |
| |
facility |
| |
logLevel |
| |
processName |
| |
processId |
| |
logId |
| |
message |
| |
user |
| |
folder |
| |
module |
| |
status |
| |
cmdData |
| |
rawMessage |
| ✓ |
hostchain |
| ✓ |
tag |
| ✓ |
Rw tab | ||
---|---|---|
|
Field
Type
Extra fields
eventdate
timestamp
hostName
str
facility
str
logLevel
str
processName
str
processId
str
logId
str
eventType
str
message
str
iqueryPeer
ip4
rawMessage
str
✓
hostchain
str
✓
tag
str
✓
Field
Type
Source field name
Extra fields
eventdate
timestamp
facility
str
log_level
str
logLevel
process_name
str
processName
process_id
str
processId
log_id
str
logId
message
str
rule
str
rule_type
str
ruleType
rule_message
str
ruleMessage
pool
str
pool_member
str
poolMember
node
str
node_ip
ip4
nodeIp
node_port
str
nodePort
route_domain_id
str
routeDomainId
status
str
status_to
str
status_from
str
protocol
str
instance_id
str
virtual_ip
str
group_device
str
local_device
str
error_code
str
error_context
str
error_description
str
source_ip
str
source_ipv4
ip4
source_port
str
destination_ip
str
destination_ipv4
ip4
destination_port
str
rawMessage
str
✓
hostchain
str
✓
tag
str
✓
| ||
rawMessage |
| ✓ |
hostchain |
| ✓ |
tag |
| ✓ |
Rw tab | ||
---|---|---|
|
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
machine |
|
| |
facility |
|
| |
log_level |
| logLevel | |
process_name |
| processName | |
process_id |
| processId | |
log_id |
| logId | |
event_type |
| eventType | |
message |
|
| |
query_ts |
| queryTs | |
client_ip |
|
| |
client_ipv4 |
| clientIp | |
client_port |
| clientPort | |
view |
|
| |
query_name |
| queryName | |
query_class |
| queryClass | |
query_type |
| queryType | |
query_flags |
| queryFlags | |
response_status |
| responseStatus | |
response_flags |
| responseFlags | |
response_ttl |
| responseTtl | |
response_record |
| responseRecord | |
dns_server_ip |
|
| |
dns_server_ipv4 |
| dnsServerIp | |
server |
|
| |
virtual_server |
|
| |
virtual_ip |
|
| |
virtual_ipv4 |
|
| |
virtual_port |
|
| |
iquery_peer |
|
| |
iquery_peer_ipv4 |
| iqueryPeer | |
iquery_peer_port |
|
| |
server_status |
| serverStatus | |
rule |
|
| |
rule_type |
| ruleType | |
rule_message |
| ruleMessage | |
pool |
|
| |
pool_member |
|
| |
instance |
|
| |
error_code |
|
| |
error_description |
|
| |
rawMessage |
|
| ✓ |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
facility |
|
| |
log_level |
| logLevel | |
process_name |
| processName | |
process_id |
| processId | |
log_id |
| logId | |
message |
|
| |
rule |
|
| |
rule_type |
| ruleType | |
rule_message |
| ruleMessage | |
pool |
|
| |
pool_member |
| poolMember | |
node |
|
| |
node_ip |
| nodeIp | |
node_port |
| nodePort | |
route_domain_id |
| routeDomainId | |
status |
|
| |
status_to |
|
| |
status_from |
|
| |
protocol |
|
| |
instance_id |
|
| |
virtual_ip |
|
| |
group_device |
|
| |
local_device |
|
| |
error_code |
|
| |
error_context |
|
| |
error_description |
|
| |
source_ip |
|
| |
source_ipv4 |
|
| |
source_port |
|
| |
destination_ip |
|
| |
destination_ipv4 |
|
| |
destination_port |
|
| |
rawMessage |
|
| ✓ |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostName |
| |
facility |
| |
logLevel |
| |
processName |
| |
processId |
| |
logId |
| |
message |
| |
accessProfile |
| |
partition |
| |
sessionId |
| |
packet |
| |
filter |
| |
action |
| |
vlan |
| |
len |
| |
srcIp |
| |
srcPort |
| |
dstIp |
| |
dstPort |
| |
protocol |
| |
rawMessage |
| ✓ |
hostchain |
| ✓ |
tag |
| ✓ |
...