Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

Introduction

The tags beginning with ids.wazuh identify events generated by Wazuh.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as ids.wazuh. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Wazuh

ids.wazuh.alerts

ids.wazuh.alerts

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

ids.wazuh.alerts

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

hostname

str

 

 

timestamp

timestamp

 

 

rule__level

int4

 

 

rule__description

str

 

 

rule__id

str

 

 

rule__firedtimes

int4

 

 

rule__mail

bool

 

 

rule__groups_str

str

join(rule__groups, ',')

rule__groups

rule__pci_dss_str

str

join(rule__pci_dss, ',')

rule__pci_dss

rule__gdpr_str

str

join(rule__gdpr, ',')

rule__gdpr

rule__hipaa_str

str

join(rule__hipaa, ',')

rule__hipaa

rule__nist_800_53_str

str

join(rule__nist_800_53, ',')

rule__nist_800_53

rule__tsc_str

str

join(rule__tsc, ',')

rule__tsc

rule__mitre__id_str

str

join(rule__mitre__id, ',')

rule__mitre__id

rule__mitre__tactic_str

str

join(rule__mitre__tactic, ',')

rule__mitre__tactic

rule__mitre__technique_str

str

join(rule__mitre__technique, ',')

rule__mitre__technique

rule__gpg13_str

str

join(rule__gpg13, ',')

rule__gpg13

agent__id

str

 

 

agent__name

str

 

 

agent__ip

ip4

 

 

manager__name

str

 

 

id

str

 

 

full_log

str

 

 

syscheck__path

str

 

 

syscheck__size_after

str

 

 

syscheck__uid_after

str

 

 

syscheck__gid_after

str

 

 

syscheck__md5_before

str

 

 

syscheck__md5_after

str

 

 

syscheck__sha1_before

str

 

 

syscheck__sha1_after

str

 

 

syscheck__changed_attributes_str

str

join(syscheck__changed_attributes, ',')

syscheck__changed_attributes

syscheck__event

str

 

 

predecoder__program_name

str

 

 

predecoder__timestamp

str

 

 

predecoder__hostname

str

 

 

decoder__parent

str

 

 

decoder__name

str

 

 

data__srcuser

str

 

 

data__dstuser

str

 

 

data__uid

str

 

 

data__id

str

 

 

data__status

str

 

 

data__extra_data

str

 

 

data__system_name

str

 

 

data__type

str

 

 

data__title

str

 

 

data__file

str

 

 

data__subject__security_id

str

 

 

data__subject__account_name

str

 

 

data__subject__account_domain

str

 

 

data__subject__login_id

str

 

 

data__win__system__providerName

str

 

 

data__win__system__providerGuid

str

 

 

data__win__system__eventID

str

 

 

data__win__system__version

str

 

 

data__win__system__level

str

 

 

data__win__system__task

str

 

 

data__win__system__opcode

str

 

 

data__win__system__keywords

str

 

 

data__win__system__systemTime

str

 

 

data__win__system__eventRecordID

str

 

 

data__win__system__processID

str

 

 

data__win__system__threadID

str

 

 

data__win__system__channel

str

 

 

data__win__system__computer

str

 

 

data__win__system__severityValue

str

 

 

data__win__system__message

str

 

 

data__win__eventdata__targetUserSid

str

 

 

data__win__eventdata__targetUserName

str

 

 

data__win__eventdata__targetDomainName

str

 

 

data__win__eventdata__targetLogonId

str

 

 

data__win__eventdata__logonType

str

 

 

data__win__eventdata__serviceName

str

 

 

data__win__eventdata__serviceSid

str

 

 

data__win__eventdata__ticketOptions

str

 

 

data__win__eventdata__ticketEncryptionType

str

 

 

data__win__eventdata__ipAddress

str

 

 

data__win__eventdata__ipPort

str

 

 

data__win__eventdata__status

str

 

 

data__win__eventdata__logonGuid

str

 

 

location

str

 

 

hostchain

str

 

 

tag

str

 

 

rawMessage

str

 

 

  • No labels