av.sophos
Introduction
The tags beginning with av.sophos
identify log events generated by Sophos Antivirus.
Valid tags and data tables
The full tag must have at least 2 levels. The first two are fixed as av.sophos
. The third level identifies the event type.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Sophos Antivirus |
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
Once the Sophos Antivirus events are delivered to Devo, they will be accessible from the finder in tables with the same names.
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables: