Document toolboxDocument toolbox

av.sophos

Introduction

The tags beginning with av.sophos identify log events generated by Sophos Antivirus.

Valid tags and data tables

The full tag must have at least 2 levels. The first two are fixed as av.sophos. The third level identifies the event type.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Sophos Antivirus

av.sophos

av.sophos

av.sophos.applicationcontrol

av.sophos.applicationcontrol

av.sophos.devicecontrol

av.sophos.devicecontrol

av.sophos.enterprise

av.sophos.enterprise

av.sophos.events

av.sophos.events

av.sophos.tamperprotection

av.sophos.tamperprotection

av.sophos.threatinstances

av.sophos.threatinstances

av.sophos.threats

av.sophos.threats

Once the Sophos Antivirus events are delivered to Devo, they will be accessible from the finder in tables with the same names.

For more information, read more about Devo tags.

Table structure

These are the fields displayed in these tables: