Table of Contents | ||||
---|---|---|---|---|
|
Introduction
The tags beginning with {2-level parser name
} db.mssql_snare
identify events generated by {product type} belonging to {Company-site} Snare MSSQL.
Valid tags and data tables
The full tag must have {X} 3 levels. The first two are fixed as {2-level parser name
}db.mssql_snare
. The third level identifies the type of events sent. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|
{Service name}
{tag name}
{data table name}
{tag name}
{data table name}
Snare MSSQL |
|
|
For more information, read more About Devo tags.
How is the data sent to Devo?
Currently the latest version of the Snare Agent for MSSQL (Snare product) is used, and events are sent as Syslog and JSON (not the default Snare format).
Logs generated by Snare MSSQL must be sent to the Devo platform via the Devo Relay to secure communication. See the required relay rule below:
Rule for events of Snare MSSQL
Source port - Any available port
Sent without syslog tag - ✓
Target tag -
db.mssql_snare.audit
Stop processing - ✓
Table structure
These are the fields displayed in this table:
db.mssql_snare.audit
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
machine |
|
|
| |||
snare_time |
|
|
| |||
snare_hostname |
|
|
| |||
snare_application_id |
|
|
| |||
snare_log_type |
|
|
| |||
snare_criticality |
|
|
| |||
start_time |
|
|
| |||
sql_version |
|
|
| |||
event_id |
|
|
| |||
event_class |
|
|
| |||
spid |
|
|
| |||
database_name |
|
| action_database_name database_name_aux | |||
username |
|
| username_aux action_username | |||
nt_username |
|
| nt_username_aux action_nt_username | |||
application_name |
|
| application_name_aux client_app_name | |||
transaction_id |
|
| trans_id action_transaction_id | |||
event_hostname |
|
| event_hostname_aux client_hostname | |||
event_timestamp |
|
|
| |||
session_login_name |
|
|
| |||
num_response_rows |
|
|
| |||
sql_text |
|
|
| |||
session_server_principal_name |
|
|
| |||
session_nt_username |
|
|
| |||
server_principal_name |
|
|
| |||
action_server_instance_name |
|
|
| |||
database_id |
|
|
| |||
task_time |
|
|
| |||
last_error |
|
|
| |||
event_sequence |
|
|
| |||
collect_system_time |
|
|
| |||
attach_activity_id_xfer |
|
|
| |||
attach_activity_id |
|
|
| |||
resource_type |
|
|
| |||
resource_type_text |
|
|
| |||
mode |
|
|
| |||
mode_text |
|
|
| |||
owner_type |
|
|
| |||
owner_type_text |
|
|
| |||
object_id |
|
|
| |||
associated_object_id |
|
|
| |||
resource_description |
|
|
| |||
object_name |
|
|
| |||
object_type |
|
|
| |||
object_type_text |
|
|
| |||
state |
|
|
| |||
state_text |
|
|
| |||
ddl_phase |
|
|
| |||
ddl_phase_text |
|
|
| |||
duration |
|
|
| |||
statement |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |