Table of Contents | ||||
---|---|---|---|---|
|
...
The tags beginning with network.vmware
identify events generated by VMware.
Tag structure
The full tag must have four levels. The first two are fixed asnetwork.vmware
. The third level identifies the type of event sent, and the fourth level identifies the subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
VMware AirWatch |
|
|
VMware NSX Advanced Load Balancer (Avi Networks) |
|
|
VMware NSX Controller |
|
|
|
| |
VMware NSX Edge |
|
|
|
| |
|
| |
VMware NSX SHA |
|
|
VMware NSX Manager |
|
|
|
| |
|
| |
|
| |
|
| |
VMware NSX’s other events |
|
|
VMware Unified Access Gateway |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
...
Rw tab | ||
---|---|---|
|
...
How is the data sent to Devo?
Logs must be sent to the Devo platform via the Devo Relay to secure communication. See the required relay rules below:
network.vmware.nsx_controller.falcon
Source port - Any available port
Target tag -
network.vmware.nsx_controller.falcon
Source message -
comp=\"nsx-controller\" subcomp=\"falcon\"
Stop processing - ✓
network.vmware.nsx_
...
edge.
...
datapathd
Source port - Any available port
Target tag -
network.vmware.nsx_
...
edge.datapathd
Source message -
comp=\"nsx-edge\" subcomp=\"datapathd\"
Stop processing - ✓
network.vmware.nsx_edge
...
-integrity_checker
Source port - Any available port
Target tag -
network.vmware.
...
Field
...
Type
nsx_edge-integrity_checker
Source message -
comp=\"nsx-edge\" subcomp=\"integrity-checker\"
Stop processing - ✓
network.vmware.nsx_manager.appl_proxy
Source port - Any available port
Target tag -
network.vmware.nsx_manager.appl_proxy
Source message -
comp=\"nsx-manager\" subcomp=\"appl-proxy\"
Stop processing - ✓
network.vmware.nsx_manager.ccp
Source port - Any available port
Target tag -
network.vmware.nsx_manager.ccp
Source message -
comp=\"nsx-manager\" subcomp=\"ccp\"
Stop processing - ✓
network.vmware.nsx_manager.node_mgmt
Source port - Any available port
Target tag -
network.vmware.nsx_manager.node_mgmt
Source message -
comp=\"nsx-manager\" subcomp=\"node-mgmt\"
Stop processing - ✓
network.vmware.nsx_manager.nsx_sha
Source port - Any available port
Target tag -
network.vmware.nsx_manager.nsx_sha
Source message -
.comp=\"nsx-manager\" subcomp=\"nsx-sha\"
Stop processing - ✓
network.vmware.nsx_other
Source port - Any available port
Target tag -
network.vmware.nsx_other
Source message -
comp=\"nsx-
Stop processing - ✓
Table structure
These are the fields displayed in these tables:
Rw ui tabs macro | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
event_category
event_data str
event_module
| tag2 | tag2 | network.vmware.nsx_avi.generic_event
Field | Type | Field transformation | Source field name | Extra fields | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
eventdate |
| |||||||||||||||||||||
process_name |
|
|
| |||||||||||||||||||
hostpid |
|
| vhost | |||||||||||||||||||
serviceuser_nameip |
|
|
| |||||||||||||||||||
logserver_levelip |
|
|
| |||||||||||||||||||
resourceserver_internal_nameip |
|
| reason | |||||||||||||||||||
server_port |
|
|
| timestamp |
|
| timestamp_tmp | |||||||||||||||
event_type |
|
|
|
| ||||||||||||||||||
avg_uptime |
|
|
| |||||||||||||||||||
eventhit_subtypethreshold |
|
|
| |||||||||||||||||||
object_namemessage |
|
|
| |||||||||||||||||||
tenant_namehostchain |
|
|
| ✓ | ||||||||||||||||||
usernametag |
|
|
| ✓ | ||||||||||||||||||
process_namerawMessage |
|
|
| pid |
|
|
| user_ip |
|
|
| server_ip |
|
|
| server_internal_ip |
|
|
| server_port |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
subtype |
| vsubtype | |
proc_id |
|
| |
msg_id |
|
|
sd_ |
id |
ip4
|
|
component |
float8
|
| |
subcomponent |
|
|
hit_threshold
float8
severity |
|
| |
message |
|
| |
transaction_id |
|
| |
hostchain |
|
|
✓ | |
tag |
|
| ✓ | |
rawMessage |
|
| ✓ |
Anchor |
---|
|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost |
subtype
str
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
severity |
|
| |
message |
|
| |
transaction_id |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor |
---|
|
|
edge
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
host |
| vhost | |
subtype |
|
vsubtype | |||
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
message |
|
| |
action |
|
| |
reason |
|
|
name |
|
| |
hostchain |
|
| ✓ |
tag |
str
✓
rawMessage
str
✓
|
| ✓ | |
rawMessage |
|
| ✓ |
Rw tab | ||
---|---|---|
|
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost |
subtype
str
proc_id |
|
| |
msg |
str
_id |
str
component
str
subcomponent
str
user_name
str
|
|
sd_id |
|
|
component |
|
|
subcomponent |
|
|
s2comp |
|
|
severity |
|
|
message |
|
|
✓
name |
|
|
✓
vrf_id |
|
|
UUID |
|
title | 6-10 |
---|
Field | Type | Source field name | Extra fields | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
eventdate |
|
| host |
| vhost | proc_id |
|
| msg_id |
|
| sd_id |
|
| component |
|
| subcomponent |
|
| s2comp |
|
| severity |
|
| message |
|
| name |
|
| vrf_id |
|
| UUID |
|
| adress_family |
|
| reason |
|
| action |
|
| rule_id |
|
| direction |
|
| packet_lenght |
|
| protocol_number |
|
| protocol |
|
| source_ip_port |
|
| destination_ip_port |
|
| TCP_flags | |
adress_family |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
reason |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
action |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
rule_id |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
direction |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
packet_lenght |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
protocol_number |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
protocol |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
source_ip_port |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
destination_ip_port |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
TCP_flags |
|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
hostchain |
|
| ✓ | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
tag |
|
| ✓ | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
message |
|
| |
action |
|
| |
reason |
|
| |
name |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor |
---|
|
|
esx.
integritynsx_
checkersha
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
message |
|
|
repeats_number |
|
|
repeats_in |
|
|
message_body |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
subtype |
| vsubtype | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
tid |
|
| |
message |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
tid |
|
| |
message |
|
| |
forwarding_engine |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
message |
|
| |
transport_node |
|
| |
transaction |
|
| |
received_from |
|
| |
items_size |
|
| |
full_sync |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Rw tab | ||
---|---|---|
|
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
message |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
proc_id |
|
| |
msg_id |
|
| |
sd_id |
|
| |
component |
|
| |
subcomponent |
|
| |
user_name |
|
| |
severity |
|
| |
s2comp |
|
| |
message |
|
| |
repeats_number |
|
| |
repeats_in |
|
| |
message_body |
|
| |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
subtype |
| vsubtype | |
message |
| rawMessage | |
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
| |
host |
| vhost | |
type |
|
| |
action |
|
| |
srcDate |
|
| |
id |
|
| |
device |
|
| |
srcIp |
|
| |
src |
|
| |
dstIp |
|
| |
dstPort |
|
| |
dst |
|
| |
node |
|
| |
arguments |
|
| |
runtime |
|
| |
procedure |
|
| |
errorCode |
|
| |
profile |
|
| |
authChain |
|
| |
language |
|
| |
skin |
|
| |
target |
|
| |
identity |
|
| |
reason |
|
| |
authUser |
|
| |
effectiveUser |
|
| |
OTPLogin |
|
| |
message |
|
| |
rawMessage |
|
| ✓ |
hostchain |
|
| ✓ |
tag |
|
| ✓ |