...
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Menlo Security Browser Isolation (inside the Menlo Security Cloud Platform) |
|
|
|
| |
|
| |
|
| |
|
|
For more information, read more About Devo tags.
...
These are the fields displayed in these tables:
rbi.menlo.attachment
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
product |
| |
rvlabs_factor |
| |
vendor |
| |
rewritten |
| |
event_time |
| |
file_type |
| |
bytes |
| |
name |
| |
message_tid |
| |
reason |
| |
version |
| |
email_date |
| |
sha256 |
| |
message_id |
| |
mime_type |
| |
severity |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
rbi.menlo.audit
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
product |
| |
vendor |
| |
uid |
| |
event_time |
| |
name |
| |
version |
| |
audit_actions |
| |
sub_event_type |
| |
rev_id |
| |
severity |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
rbi.menlo.email
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
domain |
| |
vendor |
| |
rewritten |
| |
event_time |
| |
message_tid |
| |
charset |
| |
product |
| |
name |
| |
url |
| |
reason |
| |
version |
| |
email_date |
| |
message_id |
| |
severity |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
rbi.menlo.smtp
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
severity |
| |
smtp_reply |
| |
time_handoff_down |
| |
total_links |
| |
rows |
| |
from2 |
| |
next_hop_reason |
| |
event_time |
| |
src_tls |
| |
hostname2 |
| |
src_ip |
| |
to |
| |
version |
| |
message_id |
| |
product |
| |
vendor |
| |
timestamp |
| |
src_port |
| |
reason |
| |
dst_tls |
| |
rewritten_links |
| |
time_taken |
| |
rewrite_success |
| |
time_handoff_up |
| |
name |
| |
message_tid |
| |
region |
| |
unix_time |
| |
unix_time_iso |
| |
mode |
| |
dst_ip |
| |
dst_from_port |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
rbi.menlo.web
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
top_url |
| |
domain |
| |
protocol |
| |
risk_tally |
| |
is_iframe |
| |
origin_ip |
| |
has_password |
| |
file_size |
| |
threat_types_string |
| |
threat_types_array |
| |
threat_types |
| |
browser_and_version |
| |
user_agent |
| |
egress_ip |
| |
severity |
| |
event_time |
| |
dst |
| |
destination_ip |
| |
destination_ip_array |
| |
destination_string |
| |
filename |
| |
risk_score |
| |
version |
| |
soph_dlp_ref |
| |
xff_ip |
| |
product |
| |
vendor |
| |
request_type |
| |
tab_id |
| |
pe_reason |
| |
categories_string |
| |
categories_array |
| |
categories |
| |
x_client_ip |
| |
name |
| |
url |
| |
response_code |
| |
userid |
| |
full_session_id |
| |
pe_action |
| |
ua_type |
| |
content_type |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |