Document toolboxDocument toolbox

siem.absolute

Introduction

The tags beginning with siem.absolute identify events generated by Absolute.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as siem.absolute. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Absolute Platform

siem.absolute.reporting.event

siem.absolute.reporting.event

For more information, read more About Devo tags.

How is data sent to Devo?

To sent logs to the Devo platform, you must use the Absolute collector (more info here).

Table structure

These are the fields displayed in this table:

siem.absolute.reporting.event

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

machine

str

 

id

str

 

event_type

str

 

actor_object_type

str

 

actor_display_name

str

 

actor_display_id

str

 

object_object_type

str

 

object_display_name

str

 

object_display_id

str

 

object_properties

str

 

verb

str

 

created_date_time_utc

timestamp

 

event_date_time_utc

timestamp

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓