Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Converted from version 'v7.0.8'.

Table of Contents
maxLevel2
typeflat

...

The tags beginning with iam.hitachi identify events generated by Hitachi ID products.

Tag structure

The full tag must have four levels. The first two are fixed as iam.hitachi. The third and fourth levels identify the type and subtype of events sent. 

Technology

Brand

Type

Subtype

iam

hitachi

password

events

...

  • iam.hitachi.password.events

How is the data sent to Devo?

You can send the forward logs generated by Hitachi ID using the tool NXLogany Syslog drain (for example, Syslog-ng). You can also use the Devo relay if required; in this case, you can get in touch with us if you need additional information.

Log samples

...

The following are is a sample logs log sent to each of the iam.hitachi tags:

...

.

...

password.events table:

...

Code Block
2021-

...

10-26 10:03:27.030 localhost=127.0.0.1 iam.hitachi.password.events: default[

...

ida.exe(

...

5024,

...

12784)] Help-desk assisted account unlock successful.|Profile=KHepbu|

...

ChangedBy=SGuida


Note
titleExtra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.

And this is how the log would be parsed:

iam.hitachi.password.events"""psf""8028""12224""User failed to identify."profiletarget'PSYNCH'identity'L00390135''Not Found'str

Field

Value

Type

Extra fields

hostchain

localhost=127.0.0.1

str

tag

eventdate

2021-10-26 10:03:27.03

timestamp


hostname

localhost

str


layer

default

str


module

ida.exe

str


pid

5024

str


parent_pid

12784

str


message

Help-desk assisted account unlock successful.

str


type

"User"

str

Help-desk

str


ChangedBy

SGuida

str


Profile

KHepbu

str


AuthChain

null

str


Language

null

str


Skin

null

str


Target

null

str


Platform

null

str


Operation

null

str


Identity

null

str


Reason

null

str


QSetI

null

str


QSetType

null

str


Node

null

str


Arguments

null

str

reason


Runtime

null

str


rawMessage

{"field1": "c", "field2": "789", "field3": "7.8.9.3", ...}

default[ida.exe(5024,12784)] Help-desk assisted account unlock successful.|Profile=KHepbu|ChangedBy=SGuida

str


hostchain

localhost=127.0.0.1

str

tag

iam.hitachi.password.events

str