Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

Introduction

The tags beginning with network.vmware identify events generated by VMware.

Tag structure

The full tag must have four levels. The first two are fixed as network.vmware. The third level identifies the type of event sent, and the fourth level identifies the subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

VMware AirWatch

network.vmware.airwatch.events

network.vmware.airwatch.events

VMware Unified Access Gateway

network.vmware.uag.events

network.vmware.uag.events

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

network.vmware.airwatch.events

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

host

str

vhost

event_type

str

 

event

str

 

user

str

 

event_source

str

 

event_module

str

 

event_category

str

 

event_data

str

 

event_timestamp

str

 

hostchain

str

 

tag

str

 

rawMessage

str

 

network.vmware.uag.events

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

host

str

vhost

type

str

 

action

str

 

srcDate

timestamp

 

id

str

 

device

str

 

srcIp

str

 

src

str

 

dstIp

str

 

dstPort

str

 

dst

str

 

node

str

 

arguments

str

 

runtime

str

 

procedure

str

 

errorCode

str

 

profile

str

 

authChain

str

 

language

str

 

skin

str

 

target

str

 

identity

str

 

reason

str

 

authUser

str

 

effectiveUser

str

 

OTPLogin

str

 

message

str

 

rawMessage

str

 

hostchain

str

 

tag

str

 

  • No labels