Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

Introduction

The tags beginning with threatintel.farsight identify events generated by DNS Changes channel belonging to Farsight.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as threatintel.farsight. The third level identifies the type of events sent and the fourth indicates the event subtypes.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

DNS Changes channel

threatintel.farsight.dns.ch212

threatintel.farsight.dns.ch212

threatintel.farsight.dns.ch213

threatintel.farsight.dns.ch213

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

  • threatintel.farsight.dns.ch212

  • threatintel.farsight.dns.ch213

threatintel.farsight.dns.ch212

Field

Type

Extra fields

eventdate

timestamp

time

timestamp

vname

str

mname

str

source

str

message_domain

str

message_time_seen

timestamp

message_bailiwick

str

message_rrname

str

message_rrclass

str

message_rrtype

str

message_rdata

str

message_keys

str

message_new_rr

str

hostchain

str

tag

str

rawMessage

str

threatintel.farsight.dns.ch213

Field

Type

Extra fields

eventdate

timestamp

source

str

time

timestamp

mname

str

message_time_seen

timestamp

message_rrclass

str

message_rrname

str

message_bailiwick

str

message_rrtype

str

message_new_rr

str

message_keys

str

message_rdata

str

message_domain

str

vname

str

hostchain

str

tag

str

rawMessage

str

  • No labels