...
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Absolute Platform |
|
|
For more information, read more About Devo tags.
...
To sent logs to the Devo platform, you must use the Absolute collector (more info here).
Table structure
These are the fields displayed in this table:
siem.absolute.reporting.event
Field | Type | Extra Label fields |
---|---|---|
eventdate |
| |
machine |
| |
id |
| |
event_type |
| |
actor_object_type |
| |
actor_display_name |
| |
actor_display_id |
| |
object_object_type |
| |
object_display_name |
| |
object_display_id |
| |
object_properties |
| |
verb |
| |
created_date_time_utc |
| |
event_date_time_utc |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |