Document toolboxDocument toolbox

sase.appgate

Introduction

The tags begin with sase.appgate identify events generated by Appgate SDP belonging to Appgate.

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed as sase.appgate. The third level indicates the product and the fourth identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Appgate SDP

sase.appgate.sdp.events

sase.appgate.sdp.events

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

sase.appgate.sdp.events

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

version

int4

 

timestamp

timestamp

 

hostname2

str

 

daemon

str

 

log__action

str

 

log__action_id

str

 

log__client_ip

ip4

 

log__client_port

int4

 

log__collective_id

str

 

log__connection_type

str

 

log__destination_ip

ip4

 

log__destination_port

int4

 

log__direction

str

 

log__distinguished_name

str

 

log__distinguished_name_device_id

str

 

log__distinguished_name_ou

str

 

log__distinguished_name_user

str

 

log__entitlement_token_id

str

 

log__event_type

str

 

log__geoip__ip

ip4

 

log__geoip__time_zone

str

 

log__geoip__continent_code

str

 

log__geoip__city_name

str

 

log__geoip__country_name

str

 

log__geoip__country_code2

str

 

log__geoip__dma_code

int4

 

log__geoip__country_code3

str

 

log__geoip__region_code

str

 

log__geoip__region_name

str

 

log__geoip__postal_code

str

 

log__geoip__location__lon

float8

 

log__geoip__location__lat

float8

 

log__geoip__latitude

float8

 

log__geoip__longitude

float8

 

log__geoip__cordinates

str

 

log__id

str

 

log__packet_size

int4

 

log__protocol

str

 

log__rule_name

str

 

log__source_ip

ip4

 

log__source_port

int4

 

log__timestamp

timestamp

 

log__version

int4

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓