Document toolboxDocument toolbox

nac.forescout

Introduction

Tags beginning withnac.forescout identify events generated by Forescout.

Valid tags and data tables

The full tag must have 3 levels. The first two are fixed as nac.forescout. The third level identifies the type of events sent, and the fourth level indicates the event subtype. 

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product/Service

Tags

Data table

Product/Service

Tags

Data table

Forescout counterACT

nac.forescout.counteract.actions

nac.forescout.counteract.actions

nac.forescout.counteract.common

nac.forescout.counteract.common

nac.forescout.counteract.log

nac.forescout.counteract.log

nac.forescout.counteract.policy

nac.forescout.counteract.policy

nac.forescout.counteract.system

nac.forescout.counteract.system

Table structure

This is the set displayed by these tables:

nac.forescout.counteract.actions

Field

Type

Source field name

Extra Label

Field

Type

Source field name

Extra Label

eventdate

timestamp

 

 

machine

str

vmachine

 

eventType

str

 

 

ipAddr

ip4

 

 

macAddr

str

 

 

hostName

str

 

 

dnsName

str

 

 

user

str

 

 

rawMessage

str

 

 

unknown

str

 

 

hostchain

str

 

✓

tag

str

 

✓

nac.forescout.counteract.common

Field

Type

Source field name

Extra Label

Field

Type

Source field name

Extra Label

eventdate

timestamp

 

 

machine

str

vmachine

 

eventtype

str

 

 

sourceIp

ip4

 

 

destinationIp

ip4

 

 

destinationPort

str

 

 

rawMessage

str

 

 

unknown

str

 

 

hostchain

str

 

✓

tag

str

 

✓

nac.forescout.counteract.log

Field

Type

Source field name

Extra Label

Field

Type

Source field name

Extra Label

eventdate

timestamp

 

 

machine

str

vmachine

 

log

str

 

 

details

ip4

 

 

severity

ip4

 

 

rawMessage

str

 

 

unknown

str

 

 

hostchain

str

 

✓

tag

str

 

✓

nac.forescout.counteract.policy

Field

Type

Extra Label

Field

Type

Extra Label

eventdate

timestamp

 

machine

str

 

serverdate

str

 

hostname

str

 

procName

str

 

procId

str

 

sourceIp

ip4

 

rule

str

 

details

str

 

match

str

 

category

str

 

rawMessage

str

 

hostchain

str

✓

tag

str

✓

nac.forescout.counteract.system

Field

Type

Extra Label

Field

Type

Extra Label

eventdate

timestamp

 

message

str

 

hostchain

str

✓

tag

str

✓