You are viewing an old version of this page. View the current version.
Compare with Current
View Page History
Version 1
Next »
Introduction
The tags beginning with ids.rscope
identify events generated by Reservoir Labs R-Scope.
The full tag must have at least 2 levels. The first two are fixed as ids.rscope
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|
Reservoir R-Scope Advanced Threat Detection | ids.rscope
| ids.rscope
|
ids.rscope.communication
| ids.rscope.communication
|
ids.rscope.conn
| ids.rscope.conn
|
ids.rscope.dce_rpc
| ids.rscope.dce_rpc
|
ids.rscope.dhcp
| ids.rscope.dhcp
|
ids.rscope.dns
| ids.rscope.dns
|
ids.rscope.dpd
| ids.rscope.dpd
|
ids.rscope.files
| ids.rscope.files
|
ids.rscope.ftp
| ids.rscope.ftp
|
ids.rscope.http
| ids.rscope.http
|
ids.rscope.intel
| ids.rscope.intel
|
ids.rscope.irc
| ids.rscope.irc
|
ids.rscope.kerberos
| ids.rscope.kerberos
|
ids.rscope.known_hosts
| ids.rscope.known_hosts
|
ids.rscope.known_services
| ids.rscope.known_services
|
ids.rscope.modbus
| ids.rscope.modbus
|
ids.rscope.mysql
| ids.rscope.mysql
|
ids.rscope.notice
| ids.rscope.notice
|
ids.rscope.ntlm
| ids.rscope.ntlm
|
ids.rscope.pe
| ids.rscope.pe
|
ids.rscope.protocolstats_orig
| ids.rscope.protocolstats_orig
|
ids.rscope.protocolstats_resp
| ids.rscope.protocolstats_resp
|
ids.rscope.radius
| ids.rscope.radius
|
ids.rscope.rdp
| ids.rscope.rdp
|
ids.rscope.removed_files
| ids.rscope.removed_files
|
ids.rscope.reporter
| ids.rscope.reporter
|
ids.rscope.rfb
| ids.rscope.rfb
|
ids.rscope.rscopestats_byte
| ids.rscope.rscopestats_byte
|
ids.rscope.rscopestats_core
| ids.rscope.rscopestats_core
|
ids.rscope.rscopestats_misc
| ids.rscope.rscopestats_misc
|
ids.rscope.rscopestats_pckt
| ids.rscope.rscopestats_pckt
|
ids.rscope.rscopestats_port
| ids.rscope.rscopestats_port
|
ids.rscope.rscopestats_sys
| ids.rscope.rscopestats_sys
|
ids.rscope.sip
| ids.rscope.sip
|
ids.rscope.smb_files
| ids.rscope.smb_files
|
ids.rscope.smb_mapping
| ids.rscope.smb_mapping
|
ids.rscope.smtp
| ids.rscope.smtp
|
ids.rscope.snmp
| ids.rscope.snmp
|
ids.rscope.socks
| ids.rscope.socks
|
ids.rscope.software
| ids.rscope.software
|
ids.rscope.ssh
| ids.rscope.ssh
|
ids.rscope.ssl
| ids.rscope.ssl
|
ids.rscope.stats
| ids.rscope.stats
|
ids.rscope.stderr
| ids.rscope.stderr
|
ids.rscope.stdout
| ids.rscope.stdout
|
ids.rscope.syslog
| ids.rscope.syslog
|
ids.rscope.tunnel
| ids.rscope.tunnel
|
ids.rscope.weird
| ids.rscope.weird
|
ids.rscope.x509
| ids.rscope.x509
|
For more information, read more About Devo tags.