Table of Contents |
---|
maxLevel | 2 |
---|
minLevel | 2 |
---|
type | flat |
---|
|
Introduction
The tags beginning wirthcef0.arcsight
identify events in CEF format generated by ArcSight.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
...
Tags
...
Data tables
...
cef0.arcsight.arcsight
...
cef0.arcsight.arcsight
...
cef0.arcsight.cpmiClient
...
cef0.arcsight.cpmiClient
...
cef0.arcsight.firewall
...
cef0.arcsight.firewall
...
cef0.arcsight.logger
...
cef0.arcsight.logger
...
cef0.arcsight.panOs
...
cef0.arcsight.panOs
...
cef0.arcsight.smartdashboard
...
cef0.arcsight.smartdashboard
...
cef0.arcsight.smartdefense
...
cef0.arcsight.smartdefense
...
cef0.arcsight.smartviewTracker
...
cef0.arcsight.smartviewTracker
...
cef0.arcsight.unityone
...
cef0.arcsight.unityone
...
cef0.arcsight.vpn1Firewall1
...
cef0.arcsight.vpn1Firewall1
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in these tables:
...
...
Field
...
Type
...
Source field name
...
Extra fields
...
eventdate
...
timestamp
...
...
priorityCode
...
str
...
...
cefTag
...
str
...
...
cefVersion
...
str
...
...
embDeviceVendor
...
str
...
...
embDeviceProduct
...
str
...
...
deviceVersion
...
str
...
...
signatureID
...
str
...
...
name
...
str
...
...
severity
...
str
...
...
_cefVer
...
str
...
...
cat
...
str
...
...
cn1Label
...
str
...
...
cn1
...
int8
...
...
cn2Label
...
str
...
...
cn2
...
int8
...
...
cn3Label
...
str
...
...
cn3
...
int8
...
...
cnt
...
int4
...
...
cs1Label
...
str
...
...
cs1
...
str
...
...
cs2Label
...
str
...
...
cs2
...
str
...
...
cs3Label
...
str
...
...
cs3
...
str
...
...
cs4Label
...
str
...
...
cs4
...
str
...
...
cs5Label
...
str
...
...
cs5
...
str
...
...
cs6Label
...
str
...
...
cs6
...
str
...
...
dhost
...
str
...
...
dst
...
ip4
...
...
duid
...
str
...
...
duser
...
str
...
...
dvchost
...
str
...
...
dvc
...
ip4
...
...
end
...
timestamp
...
...
fname
...
str
...
...
msg
...
str
...
...
rt
...
timestamp
...
...
shost
...
str
...
...
src
...
ip4
...
...
start
...
timestamp
...
...
suid
...
str
...
...
agentZoneURI
...
str
...
...
agt
...
ip4
...
...
ahost
...
str
...
...
aid
...
str
...
...
arcSightEventPath
...
str
...
...
art
...
str
...
...
assetCriticality
...
int4
...
...
at
...
str
...
...
atz
...
str
...
...
av
...
str
...
...
baseEventIds
...
str
...
...
catdt
...
str
...
...
categoryBehavior
...
str
...
...
categoryDeviceGroup
...
str
...
...
categoryObject
...
str
...
...
categoryOutcome
...
str
...
...
categorySignificance
...
str
...
...
categoryTechnique
...
str
...
...
customerID
...
str
...
...
customerURI
...
str
...
...
destinationAssetId
...
str
...
...
destinationGeoCountryCode
...
str
...
...
destinationGeoLocationInfo
...
str
...
...
destinationGeoRegionCode
...
str
...
...
destinationZoneID
...
str
...
...
destinationZoneURI
...
str
...
...
deviceAssetId
...
str
...
...
deviceFacility
...
str
...
...
deviceSeverity
...
str
...
...
deviceZoneID
...
str
...
...
deviceZoneURI
...
str
...
...
dlat
...
float8
...
...
dlong
...
float8
...
...
dpt
...
int4
...
...
dtz
...
str
...
...
eventAnnotationAuditTrail
...
str
...
...
eventAnnotationEndTime
...
timestamp
...
...
eventAnnotationEventId
...
str
...
...
eventAnnotationFlags
...
str
...
...
eventAnnotationManagerReceiptTime
...
timestamp
...
...
eventAnnotationModificationTime
...
timestamp
...
...
eventAnnotationStageID
...
str
...
...
eventAnnotationStageUpdateTime
...
timestamp
...
...
eventAnnotationStageURI
...
str
...
...
eventAnnotationVersion
...
int4
...
...
eventId
...
str
...
...
flexString1
...
str
...
...
generatorID
...
str
...
...
generatorURI
...
str
...
...
locality
...
int4
...
...
modelConfidence
...
int4
...
...
mrt
...
timestamp
...
...
priority
...
int4
...
...
relevance
...
int4
...
...
ruleThreadId
...
str
...
...
sessionId
...
str
...
...
slat
...
float8
...
...
slong
...
float8
...
...
sourceAssetId
...
str
...
...
sourceGeoCountryCode
...
str
...
...
sourceZoneID
...
str
...
...
sourceZoneURI
...
Table of Contents |
---|
maxLevel | 2 |
---|
minLevel | 2 |
---|
type | flat |
---|
|
Introduction
The tags beginning wirthcef0.arcsight
identify events in CEF format generated by ArcSight.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
Tags | Data tables |
---|
cef0.arcsight.arcsight
| cef0.arcsight.arcsight
|
cef0.arcsight.cpmiClient
| cef0.arcsight.cpmiClient
|
cef0.arcsight.firewall
| cef0.arcsight.firewall
|
cef0.arcsight.logger
| cef0.arcsight.logger
|
cef0.arcsight.panOs
| cef0.arcsight.panOs
|
cef0.arcsight.smartdashboard
| cef0.arcsight.smartdashboard
|
cef0.arcsight.smartdefense
| cef0.arcsight.smartdefense
|
cef0.arcsight.smartviewTracker
| cef0.arcsight.smartviewTracker
|
cef0.arcsight.unityone
| cef0.arcsight.unityone
|
cef0.arcsight.vpn1Firewall1
| cef0.arcsight.vpn1Firewall1
|
How is the data sent to Devo?
CEF data can be sent directly to Devo or by using a relay. To use the CEF default relay rule, send to the relay’s port 13000. Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in these tables:
Rw ui tabs macro |
---|
cef0.arcsight.arcsightField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cn3Label | str
| | | cn3 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | cs3Label | str
| | | cs3 | str
| | | cs4Label | str
| | | cs4 | str
| | | cs5Label | str
| | | cs5 | str
| | | cs6Label | str
| | | cs6 | str
| | | dhost | str
| | | dst | ip4
| | | duid | str
| | | duser | str
| | | dvchost | str
| | | dvc | ip4
| | | end | timestamp
| | | fname | str
| | | msg | str
| | | rt | timestamp
| | | shost | str
| | | src | ip4
| | | start | timestamp
| | | suid | str
| | | agentZoneURI | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | baseEventIds | str
| | | catdt | str
| | | categoryBehavior | str
| | | categoryDeviceGroup | str
| | | categoryObject | str
| | | categoryOutcome | str
| | | categorySignificance | str
| | | categoryTechnique | str
| | | customerID | str
| | | customerURI | str
| | | destinationAssetId | str
| | | destinationGeoCountryCode | str
| | | destinationGeoLocationInfo | str
| | | destinationGeoRegionCode | str
| | | destinationZoneID | str
| | | destinationZoneURI | str
| | | deviceAssetId | str
| | | deviceFacility | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dlat | float8
| | | dlong | float8
| | | dpt | int4
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | flexString1 | str
| | | generatorID | str
| | | generatorURI | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | ruleThreadId | str
| | | sessionId | str
| | | slat | float8
| | | slong | float8
| | | sourceAssetId | str
| | | sourceGeoCountryCode | str
| | | sourceZoneID | str
| | | sourceZoneURI | str
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
cef0.arcsight.cpmiClientField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
cef0.arcsight.firewallField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | rawMessage | str
| | ✓ | hostchain | str
| | ✓ | tag | str
| cefTag | ✓ |
cef0.arcsight.loggerField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
cef0.arcsight.panOsField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
cef0.arcsight.smartdashboardField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
tag2tag2cef0.arcsight.cpmiClientsmartdefenseField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
tag3tag3cef0.arcsight.firewallsmartviewTrackerField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | rawMessage hostchaintagcefTag tag4tag4cef0.arcsight.loggerunityoneField | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID | str
| | | eventAnnotationStageUpdateTime | timestamp
| | | eventAnnotationStageURI | str
| | | eventAnnotationVersion | int4
| | | eventId | str
| | | generatorID | str
| | | locality | int4
| | | modelConfidence | int4
| | | mrt | timestamp
| | | priority | int4
| | | relevance | int4
| | | type | int4
| | | tag | str
| cefTag | ✓ | rawMessage | str
| | ✓ | hostchain | str
| | ✓ |
tag5tag5cef0.arcsight.panOsvpn1Firewall1Field | Type | Source field name | Extra fields |
---|
eventdate | timestamp
| | | priorityCode | str
| | | cefTag | str
| | | cefVersion | str
| | | embDeviceVendor | str
| | | embDeviceProduct | str
| | | deviceVersion | str
| | | signatureID | str
| | | name | str
| | | severity | str
| | | _cefVer | str
| | | cat | str
| | | cn1Label | str
| | | cn1 | int8
| | | cn2Label | str
| | | cn2 | int8
| | | cnt | int4
| | | cs1Label | str
| | | cs1 | str
| | | cs2Label | str
| | | cs2 | str
| | | dvchost | str
| | | dvc | ip4
| | | deviceFacility | str
| | | filePath | str
| | | fileType | str
| | | fname | str
| | | agt | ip4
| | | ahost | str
| | | aid | str
| | | arcSightEventPath | str
| | | art | str
| | | assetCriticality | int4
| | | at | str
| | | atz | str
| | | av | str
| | | deviceAssetId | str
| | | deviceSeverity | str
| | | deviceZoneID | str
| | | deviceZoneURI | str
| | | dtz | str
| | | eventAnnotationAuditTrail | str
| | | eventAnnotationEndTime | timestamp
| | | eventAnnotationEventId | str
| | | eventAnnotationFlags | str
| | | eventAnnotationManagerReceiptTime | timestamp
| | | eventAnnotationModificationTime | timestamp
| | | eventAnnotationStageID |
str
| | eventAnnotationStageUpdateTime | timestamp
| | eventAnnotationStageURI | eventAnnotationVersion | int4
| | eventId | str
| | generatorID | str
| | locality | int4
| | modelConfidence | int4
| | mrt | timestamp priority | eventAnnotationStageUpdateTime |
int4 relevanceint4 type | eventAnnotationVersion | int4
| | tagcefTag✓ | rawMessage✓hostchain | str ✓ rw-tabtitle Anchor |
---|
| tag6 | tag6 | cef0.arcsight.smartdashboard Anchor |
---|
tag7 | tag7 | cef0.arcsight.smartdefense Anchor |
---|
tag8 | tag8 | cef0.arcsight.smartviewTracker Anchor |
---|
tag9 | tag9 | cef0.arcsight.unityone Anchor |
---|
tag10 | tag10 | cef0.arcsight.vpn1Firewall16-10 | mrt | timestamp
| | |
priority | int4
| | |
relevance | int4
| | |
type | int4
| | |
tag | str
| cefTag | ✓ |
rawMessage | str
| | ✓ |
hostchain | str
| | ✓ |