Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Current »

Introduction

The tags beginning with ids.rscope identify events generated by Reservoir Labs R-Scope.

Valid tags and data tables 

The full tag must have at least 2 levels. The first two are fixed as ids.rscope. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Reservoir R-Scope Advanced Threat Detection

ids.rscope

ids.rscope

ids.rscope.communication

ids.rscope.communication

ids.rscope.conn

ids.rscope.conn

ids.rscope.dce_rpc

ids.rscope.dce_rpc

ids.rscope.dhcp

ids.rscope.dhcp

ids.rscope.dns

ids.rscope.dns

ids.rscope.dpd

ids.rscope.dpd

ids.rscope.files

ids.rscope.files

ids.rscope.ftp

ids.rscope.ftp

ids.rscope.http

ids.rscope.http

ids.rscope.intel

ids.rscope.intel

ids.rscope.irc

ids.rscope.irc

ids.rscope.kerberos

ids.rscope.kerberos

ids.rscope.known_hosts

ids.rscope.known_hosts

ids.rscope.known_services

ids.rscope.known_services

ids.rscope.modbus

ids.rscope.modbus

ids.rscope.mysql

ids.rscope.mysql

ids.rscope.notice

ids.rscope.notice

ids.rscope.ntlm

ids.rscope.ntlm

ids.rscope.pe

ids.rscope.pe

ids.rscope.protocolstats_orig

ids.rscope.protocolstats_orig

ids.rscope.protocolstats_resp

ids.rscope.protocolstats_resp

ids.rscope.radius

ids.rscope.radius

ids.rscope.rdp

ids.rscope.rdp

ids.rscope.removed_files

ids.rscope.removed_files

ids.rscope.reporter

ids.rscope.reporter

ids.rscope.rfb

ids.rscope.rfb

ids.rscope.rscopestats_byte

ids.rscope.rscopestats_byte

ids.rscope.rscopestats_core

ids.rscope.rscopestats_core

ids.rscope.rscopestats_misc

ids.rscope.rscopestats_misc

ids.rscope.rscopestats_pckt

ids.rscope.rscopestats_pckt

ids.rscope.rscopestats_port

ids.rscope.rscopestats_port

ids.rscope.rscopestats_sys

ids.rscope.rscopestats_sys

ids.rscope.sip

ids.rscope.sip

ids.rscope.smb_files

ids.rscope.smb_files

ids.rscope.smb_mapping

ids.rscope.smb_mapping

ids.rscope.smtp

ids.rscope.smtp

ids.rscope.snmp

ids.rscope.snmp

ids.rscope.socks

ids.rscope.socks

ids.rscope.software

ids.rscope.software

ids.rscope.ssh

ids.rscope.ssh

ids.rscope.ssl

ids.rscope.ssl

ids.rscope.stats

ids.rscope.stats

ids.rscope.stderr

ids.rscope.stderr

ids.rscope.stdout

ids.rscope.stdout

ids.rscope.syslog

ids.rscope.syslog

ids.rscope.tunnel

ids.rscope.tunnel

ids.rscope.weird

ids.rscope.weird

ids.rscope.x509

ids.rscope.x509

For more information, read more About Devo tags.

  • No labels