endpoint.vmware
Introduction
The tags beginning with endpoint.vmware identify events generated by VM Ware Carbon Black.Â
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as endpoint.vmware. The third level identifies the type of events sent, and the fourth level indicates the event subtype.Â
Technology | Brand | Type | Subtype |
---|---|---|---|
endpoint | vmware |
|
|
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
endpoint.vmware.cbc_api.alerts | endpoint.vmware.cbc_api.alerts |
endpoint.vmware.cbc_defender.audit_logs | endpoint.vmware.cbc_defender.audit_logs |
endpoint.vmware.cbc_event_forwarder.kognos_alerts | endpoint.vmware.cbc_event_forwarder.kognos_alerts |
endpoint.vmware.cbc_event_forwarder.kognos_events | endpoint.vmware.cbc_event_forwarder.kognos_events |
endpoint.vmware.cbc_event_forwarder.cb_analytics | endpoint.vmware.cbc_event_forwarder.cb_analytics |
endpoint.vmware.cbc_event_forwarder.endpoint_event_apicall | endpoint.vmware.cbc_event_forwarder.endpoint_event_apicall |
endpoint.vmware.cbc_event_forwarder.endpoint_event_crossproc | endpoint.vmware.cbc_event_forwarder.endpoint_event_crossproc |
endpoint.vmware.cbc_event_forwarder.endpoint_event_filemod | endpoint.vmware.cbc_event_forwarder.endpoint_event_filemod |
endpoint.vmware.cbc_event_forwarder.endpoint_event_moduleload | endpoint.vmware.cbc_event_forwarder.endpoint_event_moduleload |
endpoint.vmware.cbc_event_forwarder.endpoint_event_netconn | endpoint.vmware.cbc_event_forwarder.endpoint_event_netconn |
endpoint.vmware.cbc_event_forwarder.endpoint_event_procstart | endpoint.vmware.cbc_event_forwarder.endpoint_event_procstart |
endpoint.vmware.cbc_event_forwarder.endpoint_event_procend | endpoint.vmware.cbc_event_forwarder.endpoint_event_procend |
endpoint.vmware.cbc_event_forwarder.endpoint_event_regmod | endpoint.vmware.cbc_event_forwarder.endpoint_event_regmod |
endpoint.vmware.cbc_event_forwarder.endpoint_event_scriptload | endpoint.vmware.cbc_event_forwarder.endpoint_event_scriptload |
endpoint.vmware.cbc_event_forwarder.unknown | endpoint.vmware.cbc_event_forwarder.unknown |