Document toolboxDocument toolbox

drp.cloudsek

Introduction

The tags beginning with drp.cloudsek identify events generated by the CloudSEK Digital Risk Protection platform.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as drp.cloudsek. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

CloudSEK XVigil

drp.cloudsek.xvigil.alerts

drp.cloudsek.xvigil.alerts

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

incident_details__threat_reason

str

 

incident_details__threat_severity

str

 

incident_details__content_identifier

str

 

incident_details__summary

str

 

incident_details__posted_time

str

 

incident_details__acquisition_time

str

 

incident_details__matched_assets

str

 

incident_details__incident_category

str

 

incident_details__incident_time

timestamp

 

incident_details__incident_source_name

str

 

incident_details__webapp_name

str

 

incident_details__webapp_url

str

 

incident_details__scan_date

str

 

incident_details__url

str

 

incident_details__cweid

str

 

incident_details__ip_address

str

 

incident_details__origin_url

str

 

incident_details__original_url

str

 

incident_details__page_url

str

 

incident_details__namesserver

str

 

incident_details__soa

str

 

incident_details__mx

str

 

incident_details__txt

str

 

incident_details__cname

str

 

incident_details__classifications__values

str

 

module_name

str

 

at_devo_pulling_id

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓