firewall.watchguard
Introduction
Tags beginning with firewall.watchguard identifies events generated by Watchguard.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as firewall.watchguard. The third level identifies the type of events sent.
Technology | Brand | Type |
---|---|---|
firewall | watchguard | traffic |
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag | Data table |
---|---|
firewall.watchguard.traffic | firewall.watchguard.traffic |
firewall.watchguard.traffic.v2 | firewall.watchguard.traffic |
How is the data send to Devo?
Before sending WatchGuard events, make sure that the aliases don’t contain space characters (" "), as they are used to distinguish between different fields.
The procedure to check and modify the aliases is detailed in this article.
Table structure
This is the set displayed by these tables.
Field | Type | Extra fields |
---|---|---|
eventdate |
| - |
srcIP |
| - |
dstIP |
| - |
protocol |
| - |
srcPORT |
| - |
dstPORT |
| - |
proxy_act |
| - |
cats |
| - |
dstname |
| - |
sni |
| - |
cn |
| - |
cert_issuer |
| - |
cert_subject |
| - |
action |
| - |
app_id |
| - |
app_cat_id |
| - |
sent_bytes |
| - |
rcvd_bytes |
| - |
geo_src |
| - |
geo_dst |
| - |
serial_number |
| - |
fecha |
| - |
disposition |
| - |
interface |
| - |
external |
| - |
request |
| - |
area00 |
| - |
area01 |
| - |
proc_id |
| - |
rc |
| - |
service |
| - |
log_type |
| - |
msg_id |
| - |
fqdn_dst_match |
| - |
srcInterface |
| - |
dstInterface |
| - |
num1 |
| - |
num2 |
| - |
num3 |
| - |
winVersion |
| - |
msg |
| - |
line |
| - |
rule_name |
| - |
header |
| - |
content_type |
| - |
method |
| - |
scheme |
| - |
op |
| - |
arg |
| - |
path |
| - |
elapsed_time |
| - |
reputation |
| - |
signature_name |
| - |
signature_cat |
| - |
signature_id |
| - |
src_user |
| - |
id |
| - |
ip_packet_length |
| - |
ip_header_length |
| - |
ttl |
| - |
new_action |
| - |
tls_profile |
| - |
tls_version |
| - |
seq |
| - |
severity |
| - |
type |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |