Introduction
The tags beginning with auth.secureauth
identify events generated by the SecureAuth authentication platform.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as auth.secureauth
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
SecureAuth identity platform |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
auth.secureauth.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| |||
hostname |
| split(hostchain, "=", 0) | hostchain | |
cefVersion |
| |||
embDeviceVendor |
| |||
embDeviceProduct |
| |||
deviceVersion |
| |||
signatureID |
| |||
name |
| |||
severity |
| |||
cat |
| |||
ipRiskScore |
| |||
priority |
| |||
browserSession |
| |||
analyzeEngineResult |
| |||
companyName |
| |||
requestID |
| |||
requestDuration |
| |||
userCountryCode |
| |||
deviceUTCTime |
| |||
dst |
| |||
dvc |
| |||
deviceFacility |
| |||
msg |
| |||
outcome |
| |||
requestClientApplication |
| |||
sourceServiceName |
| |||
spid |
| |||
src |
| |||
suser |
| |||
secureAuthIdPAppliance |
| |||
hostchain |
| ✓ | ||
tag |
| ✓ | ||
rawMessage |
| ✓ |
auth.secureauth.radius
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
timestamp |
| |
server |
| |
product |
| |
logtype |
| |
process |
| |
transctionId |
| |
eventMessage |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |