vpn.juniper
Introduction
The tags beginning with vpn.juniper
identify events generated by Juniper Networks.
Valid tags and data tables
The full tag must have three levels. The first two are fixed as vpn.juniper
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product/Service | Tags | Data table |
---|---|---|
Juniper VPN |
|
|
|
|
For more information, read more About Devo tags.
Table structure
vpn.juniper.sa
Field | Type | Extra Fields | Source field name |
---|---|---|---|
eventdate |
| Â | Â |
machine |
| Â | vmachine |
hostchain |
| ✓ |  |
tag |
| ✓ |  |
serverdate |
| Â | Â |
node |
| Â | Â |
srcIp |
| Â | Â |
user |
| Â | Â |
realm |
| Â | Â |
role |
| Â | Â |
msg |
| Â | Â |
rawMessage |
| Â | Â |
vpn.juniper.srx
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
machine |
| Â |
fpc_slot |
| Â |
pic_slot |
| Â |
slot_id |
| Â |
process_name |
| Â |
process_id |
| Â |
log_type |
| Â |
ike_version |
| Â |
message |
| Â |
vpn_name |
| Â |
gateway_name |
| Â |
local_gateway |
| Â |
remote_gateway |
| Â |
tunnel_id |
| Â |
local_id |
| Â |
local_ip |
| Â |
local_port |
| Â |
local_tunnel_if |
| Â |
local_ike_id |
| Â |
remote_id |
| Â |
remote_ip |
| Â |
remote_port |
| Â |
remote_tunnel_ip |
| Â |
remote_ike_id |
| Â |
direction |
| Â |
spi |
| Â |
aux_spi |
| Â |
mode |
| Â |
type |
| Â |
vr_id |
| Â |
sa_type |
| Â |
fc_name |
| Â |
traffic_selector |
| Â |
xauth_username |
| Â |
reason |
| Â |
role |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |