Introduction
The tags beginning with ndr.darktrace
identify events generated by Darktrace NDR.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as ndr.darktrace
. The third level identifies the type of events sent. The fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Darktrace NDR |
|
|
|
| |
|
| |
|
| |
|
|
For more information, read more About Devo tags.
How is the data sent to Devo?
Logs generated by Darktrace NDR may be sent to the Devo platform via the Devo Relay to secure communication. See the required relay rules below:
Rule for Darktrace Audit (threat)
events
Source port - Any available port and the same port for all rules in this section.
Source data -
darktrace_audit
Sent without syslog tag - ✓
Target tag -
ndr.darktrace.threat.event
Target message -
\\D0
Stop processing - ✓
Rule for Darktrace Alert (model_breach)
events
Source port - Any available port and the same port for all rules in this section.
Source data -
\"model\": ?\{
Sent without syslog tag - ✓
Target tag -
ndr.darktrace.model_breach.event
Target message -
\\D0
Stop processing - ✓
Rule for Darktrace Action
events
Source port - Any available port and the same port for all rules in this section.
Source data -
\"url\": ?\"https:\/\/.*\/#actions\/
Sent without syslog tag - ✓
Target tag -
ndr.darktrace.action.event
Target message -
\\D0
Stop processing - ✓
Rule for Darktrace System
events
Source port - Any available port and the same port for all rules in this section.
Source data -
\"url\": ?\"https:\/\/.*\/sysstatus
Sent without syslog tag - ✓
Target tag -
ndr.darktrace.system.event
Target message -
\\D0
Stop processing - ✓
Rule for Darktrace Others
events
This is a sink rule to gather all events that do not match with any of the criteria above.
Source port - Any available port and the same port for all rules in this section.
Leave Source data empty
Sent without syslog tag - ✓
Target tag -
ndr.darktrace.other.event
Target message -
\\D0
Stop processing - ✓
Table structure
These are the fields displayed in these tables:
ndr.darktrace.action.event
Field | Type | Extra Label |
---|---|---|
eventdate |
| |
machine |
| |
url |
| |
iris_event_type |
| |
code_uuid |
| |
code_id |
| |
action_family |
| |
action |
| |
username |
| |
reason |
| |
start |
| |
end |
| |
device_modeled_id |
| |
policy_breach_id |
| |
action_creator |
| |
model |
| |
inhibitor |
| |
device_ip |
| |
device_ipv4 |
| |
device_ipv6 |
| |
device_ips |
| |
device_subnet_id |
| |
device_first_seen |
| |
device_last_seen |
| |
device_os |
| |
device_ossource |
| |
device_typename |
| |
device_typelabel |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
ndr.darktrace.model_breach.event
Field | Type | Extra Label |
---|---|---|
eventdate |
| |
machine |
| |
model_description |
| |
model_created_by |
| |
model_edited_by |
| |
model_name |
| |
model_priority |
| |
model_policy_id |
| |
model_uuid |
| |
model_category |
| |
model_compliance |
| |
model_policy_history_id |
| |
model_logic_data |
| |
model_logic_target_score |
| |
model_logic_type |
| |
model_logic_version |
| |
model_throttle |
| |
model_shared_endpoints |
| |
model_actions_alert |
| |
model_actions_model |
| |
model_actions_breach |
| |
model_actions_set_tag |
| |
model_actions_set_type |
| |
model_actions_aianalyst_hypotheses |
| |
model_actions_set_priority |
| |
model_tags |
| |
model_interval |
| |
model_delay |
| |
model_sequenced |
| |
model_active |
| |
model_modified |
| |
model_active_times_type |
| |
model_active_times_version |
| |
model_auto_updatable |
| |
model_auto_update |
| |
model_auto_suppress |
| |
model_behaviour |
| |
model_defeats |
| |
model_version |
| |
model_mitre_tactics |
| |
model_mitre_techniques |
| |
device_ip |
| |
device_ipv4 |
| |
device_ipv6 |
| |
device_hostname |
| |
device_mac_address |
| |
device_vendor |
| |
device_label |
| |
device_modeled_id |
| |
device_subnet_id |
| |
device_uuid |
| |
device_ips |
| |
device_first_seen |
| |
device_last_seen |
| |
device_os |
| |
device_os_source |
| |
device_type_name |
| |
device_type_label |
| |
device_tags |
| |
triggered_components |
| |
breach_url |
| |
policy_breach_id |
| |
score |
| |
creation_time |
| |
time |
| |
mitre_techniques |
| |
comment_count |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
ndr.darktrace.other.event
Field | Type | Extra Label | Source field name |
---|---|---|---|
eventdate |
|
| |
machine |
|
| |
message |
| rawMessage | |
hostchain |
| ✓ |
|
tag |
| ✓ |
|
rawMessage |
| ✓ |
|
ndr.darktrace.system.event
Field | Type | Extra Label |
---|---|---|
eventdate | timestamp | |
machine | str | |
hostname | str | |
label | str | |
address_ipv4 | ip4 | |
address_ipv6 | ip6 | |
address_ip | str | |
child_id | str | |
name |
| |
priority |
| |
priority_level |
| |
alert_name |
| |
status |
| |
message |
| |
last_updated |
| |
last_updated_status |
| |
acknowledge_time |
| |
acknowledge_timeout |
| |
uuid |
| |
url |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
ndr.darktrace.threat.event
Field | Type | Extra Label |
---|---|---|
eventdate |
| |
machine |
| |
username |
| |
method |
| |
endpoint |
| |
address_ip |
| |
address_ipv4 |
| |
address_ipv6 |
| |
status |
| |
description |
| |
additional_info__details |
| |
additional_info__user |
| |
additional_info__changes__display__threat_tray_display_mode |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |