cabs.proofpoint
Introduction
The tags beginning with casb.proofpoint identify events generated by CASB Proofpoint.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as casb.proofpoint. The third level identifies the type of events sent.
Technology | Brand | Type |
---|---|---|
casb | proffpoint |
|
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
casb.netskope.alert | casb.netskope.alert |
casb.proofpoint.event | casb.proofpoint.event |
Table structure
[casb.proofpoint.alert][casb.proofpoint.event]
casb.proofpoint.alert
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
id |
| - |
timestamp |
| - |
description |
| - |
related_events__user_email |
| - |
related_events__user_id |
| - |
related_events__event_id |
| - |
related_events__geo_location |
| - |
related_events__user_agent |
| - |
related_events__intelligence |
| - |
related_events__timestamp |
| - |
related_events__cloud_service |
| - |
related_events__location |
| - |
related_events__meta_data |
| - |
related_events__meta_data__extracted_fields |
| - |
related_events__event_classification__id |
| - |
related_events__event_classification__sub_category |
| - |
related_events__event_classification__threat |
| - |
related_events__event_classification__category |
| - |
related_events__full_name |
| - |
tenantId |
| - |
severity |
| - |
type |
| - |
title |
| - |
subType |
| - |
related_events_found |
| - |
related_events_id |
| - |
at_devo_environment |
| - |
at_devo_pulling_id |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
casb.proofpoint.event
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
id |
| - |
timestamp |
| - |
description |
| - |
related_events__user_email |
| - |
related_events__user_id |
| - |
related_events__event_id |
| - |
related_events__geo_location |
| - |
related_events__user_agent |
| - |
related_events__intelligence |
| - |
related_events__timestamp |
| - |
related_events__cloud_service |
| - |
related_events__location |
| - |
related_events__meta_data |
| - |
related_events__meta_data__extracted_fields |
| - |
related_events__event_classification__id |
| - |
related_events__event_classification__sub_category |
| - |
related_events__event_classification__threat |
| - |
related_events__event_classification__category |
| - |
related_events__full_name |
| - |
tenantId |
| - |
severity |
| - |
type |
| - |
title |
| - |
subType |
| - |
related_events_found |
| - |
related_events_id |
| - |
at_devo_environment |
| - |
at_devo_pulling_id |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
How is the data sent to Devo?
Logs generated by CASB Proofpoint are forwarded to Devo using a dedicated collector. Contact us if you need to forward these events to your Devo domain so we can guide you through the process.