Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

Introduction

The tags beginning with iam.cyberark identify events generated by Cyberark.

Valid tags and data tables 

The full tag must have at least three levels. The first two are fixed as iam.cyberark. The third level identifies the type of events sent. The fourth indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Cyberark

iam.cyberark.audit

iam.cyberark.audit

iam.cyberark.vault.cef

iam.cyberark.vault

iam.cyberark.vault_leef

iam.cyberark.vault_leef

For more information, read more about Devo tags.

Table structure

These are the fields displayed in these tables:

Field

Type

Extra field

eventdate

timestamp

Hostname

str

EventReceivedTime

str

SourceModuleName

str

SourceModuleType

str

SourceName

str

Message

str

hostchain

str

tag

str

rawMessage

str

Field

Type

Extra field

Source field name

eventdate

timestamp

 

host

str

vhost

act

str

 

rt

str

 

suser

str

 

fname

str

 

dvc

ip4

 

shost

ip4

 

dhost

str

 

duser

str

 

externalId

str

 

app

str

 

reason

str

 

cs1Label

str

 

cs1

str

 

cs2Label

str

 

cs2

str

 

cs3Label

str

 

cs3

str

 

cs4Label

str

 

cs4

str

 

cs5Label

str

 

cs5

str

 

cn1Label

str

 

cn1

str

 

cn2Label

str

 

cn2

str

 

msg

str

 

hostchain

str

 

tag

str

 

rawMessage

str

rawSource

Field

Type

Extra Label

Source field name

eventdate

timestamp

 

host

str

vhost

leefVer

str

 

vendor

str

 

product

str

 

version

str

 

eventID

str

 

sev

int4

 

Action

str

 

EventMessage

str

 

OSUser

str

 

usrName

str

 

src

ip4

 

SourceUser

str

 

TargetUser

str

 

File

str

 

Safe

str

 

Location

str

 

Category

str

 

RequestId

str

 

Reason

str

 

ExtraDetails

str

 

GatewayStation

str

 

CAPolicy

str

 

hostchain

str

 

tag

str

 

rawMessage

str

 

  • No labels