Document toolboxDocument toolbox

dsp.accellion

Introduction

The tags beginning with dsp.accellion identify events generated by Accellion.

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed as dsp.accellion. The third level identifies the type of events sent, and the fourth level indicates the event subtype. 

Technology

Brand

Type

Subtype

dsp

accellion

sft


events


These are the valid tags and corresponding data tables that will receive the parsers' data:

Tag

Data table

dsp.accellion.sft.eventsdsp.accellion.sft.events

Log samples

The following are sample logs sent to each of the dsp.accellion data tables. Also, find how the information will be parsed in your data table under each sample log.

Extra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.

dsp.accellion.sft.events

2021-09-27 18:28:08.485 localhost=127.0.0.1=95.18.57.137 dsp.accellion.sft.events: Feb 4 03:25:25 sgqa-h123 rest_server.py: {"user_id": 1, "description": "Logged in", "successful": 1, "tenant_id": 0, "client_name": "testapp", "flag": 1, "user_type": "katherinejones", "data": {}, "user_ip": "lthompson", "application": "kiteworks", "app_host": "sgqa-.accc.gur", "client_device": "None", "url_host": "sgqa-.accc.gur", "user_agent": "liuregina", "client_id": "5d286ee0-9de0-5d94-b210-c1739a7e761a", "user_name": "christiangillespie", "event": "user_logged_in"}
2021-09-27 18:32:04.113 localhost=127.0.0.1=95.18.57.137 dsp.accellion.sft.events: Feb 4 03:25:25 sgqa-h123 rest_server.py: {"user_id": 3245, "description": "activities_test_folder_add_folder_top_1580499603: Created folder activities_test_folder_add_folder_nested_1580499604", "successful": 1, "tenant_id": 0, "client_name": "kiteworks Web User", "flag": 1, "user_type": "delgadomichael", "data": {"is_folder_upload": 0, "parent_folder": {"path": "activities_test_folder_add_folder_top_1580499603", "id": 39309, "name": "activities_test_folder_add_folder_top_1580499603"}, "session": "56c304986d7d84257d882bb7b6f317f40d9180f6", "folder": {"name": "activities_test_folder_add_folder_nested_1580499604", "path": "activities_test_folder_add_folder_top_1580499603/activities_test_folder_add_folder_nested_1580499604", "id": 39310}}, "user_ip": "edwardsheidi", "application": "kiteworks", "app_host": "sgqa-.accc.gur", "client_device": "None", "url_host": "sgqa-.accc.gur", "user_agent": "mwoods", "client_id": "kw_user", "user_name": "abutler", "event": "add_folder"}
2021-09-27 18:35:33.472 localhost=127.0.0.1=95.18.57.137 dsp.accellion.sft.events: Feb 4 03:25:25 sgqa-h123 rest_server.py: {"user_id": 3245, "description": "activities_test_folder_add_folder_top_1580499603: Created folder activities_test_folder_add_folder_nested_1580499604", "successful": 1, "tenant_id": 0, "client_name": "kiteworks Web User", "flag": 1, "user_type": "delgadomichael", "data": {"is_folder_upload": 0, "parent_folder": {"path": "activities_test_folder_add_folder_top_1580499603", "id": 39309, "name": "activities_test_folder_add_folder_top_1580499603"}, "session": "56c304986d7d84257d882bb7b6f317f40d9180f6", "folder": {"name": "activities_test_folder_add_folder_nested_1580499604", "path": "activities_test_folder_add_folder_top_1580499603/activities_test_folder_add_folder_nested_1580499604", "id": 39310}}, "user_ip": "edwardsheidi", "application": "kiteworks", "app_host": "sgqa-.accc.gur", "client_device": "None", "url_host": "sgqa-.accc.gur", "user_agent": "mwoods", "client_id": "kw_user", "user_name": "abutler", "event": "add_folder"}
2021-09-27 18:36:36.982 localhost=127.0.0.1=95.18.57.137 dsp.accellion.sft.events: Jan 31 19:40:36 sgqa-h123 rest_server.py: {"full_log": "File /var/log/kwlog/tws/cloud_handler.log was added.\nSymbolic path: /log/tws/cloud_handler.log.\n", "application": "kiteworks", "timestamp": "2020-02-05T09:50:03.467+0000", "agent": {"id": "000", "name": "sgqa-h123"}, "syscheck": {"gid_after": "501", "symbolic_path": "/log/tws/cloud_handler.log", "uid_after": "500", "perm_after": "100644", "uname_after": "prometheus", "path": "/var/log/kwlog/tws/cloud_handler.log", "gname_after": "prometheus", "event": "added"}, "manager": {"name": "sgqa-h123"}, "rule": {"firedtimes": 1, "description": "File added to the system.", "level": 5, "groups": ["local", "syslog", "ossec", "syscheck", "rootcheck", "syscheck"], "mail": false, "id": "554"}, "decoder": {"name": "syscheck_new_entry"}, "id": "1580896203.959", "location": "syscheck"}

And this is how the log would be parsed:

Field

Value

Type

Extra fields

eventdate

2021-09-27 18:28:08.485

timestamp


host

localhost

str


date_str

"Feb 4 03:25:25 "

str
server_name"sgqa-h123"str
process"rest_server.py"str

user_id

1

int8


description

Logged in

str


successful

1

int8


tenant_id

0

int8


client_name

testapp

str


flag

1

int8


user_type

katherinejones

str


data_is_folder_upload

null

int8


data_parent_folder_path

null

str


data_parent_folder_id

null

int8


data_parent_folder_name

null

str


data_session

null

str


data_folder_name

null

str


data_folder_path

null

str


data_folder_id

null

int8


data_file_owner_id

null

int8


data_file_owner_name

null

str


data_scanning_type

null

str


data_skipped

null

str


data_service_name

null

str


data_ec_source_id

null

str


data_ec_source_name

null

str


data_dlp_locked

null

bool


data_prohibited

null

bool


data_file_hash

null

str


data_file_name

null

str


data_file_hash_algo

null

str


data_file_mime

null

str


data_file_file_id

null

int8


data_file_path

null

str


data_file_id

null

int8


data_file_size

null

int8


data_kp_xfer_transaction_id

null

str


data_status_reason

null

str


data_malicious

null

bool


data_quarantined

null

bool


data_notified

null

bool


data_sw_version

null

str


data_email

null

str


data_dest_folder_name

null

str


data_dest_folder_path

null

str


data_dest_folder_id

null

int8


data_source_file_path

null

str


data_source_file_file_id

null

str


data_source_file_id

null

int8


data_source_file_name

null

str


data_version_added

null

str


data_source_folder_name

null

str


data_source_folder_path

null

str


data_source_folder_id

null

int8


data_mail_sender

null

str


data_mail_secure_body

null

int8


data_mail_self_copy

null

int8


data_mail_email_package_id

null

int8


data_mail_id

null

int8


data_mail_subject

null

str


data_user_name

null

str


data_error_msg

null

str


data_token_type

null

str


data_role_name

null

str


data_enable

null

bool


data_hostname

null

str


data_attachments

null

str


data_mime

null

str


data_name

null

str


data_node_ip

null

str


user_ip

lthompson

str


application

kiteworks

str


app_host

sgqa-.accc.gur

str


client_device

None

str


url_host

sgqa-.accc.gur

str


user_agent

liuregina

str


client_id

5d286ee0-9de0-5d94-b210-c1739a7e761a

str


user_name

christiangillespie

str


event

user_logged_in

str


full_log

null

str


timestamp

null

timestamp


agent_id

null

str


agent_name

null

str


syscheck_gid_after

null

str


syscheck_symbolic_path

null

str


syscheck_uid_after

null

str


syscheck_perm_after

null

str


syscheck_uname_after

null

str


syscheck_path

null

str


syscheck_gname_after

null

str


syscheck_event

null

str


manager_name

null

str


rule_firedtimes

null

int8


rule_description

null

str


rule_level

null

int8


rule_groups

null

str


rule_mail

null

bool


rule_id

null

str


decoder_name

null

str


id

null

str


location

null

str


hostchain

localhost=127.0.0.1=95.18.57.137

str

✓

tag

dsp.accellion.sft.events

str

✓

rawMessage

{"user_id": 1, "description": "Logged in", "successful": 1, "tenant_id": 0, "client_name": "testapp", "flag": 1, "user_type": "katherinejones", "data": {}, "user_ip": "lthompson", "application": "kiteworks", "app_host": "sgqa-.accc.gur", "client_device": "None", "url_host": "sgqa-.accc.gur", "user_agent": "liuregina", "client_id": "5d286ee0-9de0-5d94-b210-c1739a7e761a", "user_name": "christiangillespie", "event": "user_logged_in"}

str

✓