/
drp.cloudsek

drp.cloudsek

Introduction

The tags beginning with drp.cloudsek identify events generated by the CloudSEK Digital Risk Protection platform.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as drp.cloudsek. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

CloudSEK XVigil

drp.cloudsek.xvigil.alerts

drp.cloudsek.xvigil.alerts

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

Field

Type

Extra Label

Source field name

Field

Type

Extra Label

Source field name

eventdate

timestamp

no

 

machine

str

no

 

module_name

str

no

 

incident_threat_reason

str

no

incident_details__threat_reason

incident_threat_severity

str

no

incident_details__threat_severity

incident_content_identifier

str

no

incident_details__content_identifier

incident_summary

str

no

incident_details__summary

incident_posted_time

str

no

incident_details__posted_time

incident_acquisition_time

str

no

incident_details__acquisition_time

incident_matched_assets

str

no

incident_details__matched_assets

incident_incident_category

str

no

incident_details__incident_category

incident_incident_time

timestamp

no

incident_details__incident_time

incident_incident_source_name

str

no

incident_details__incident_source_name

incident_webapp_name

str

no

incident_details__webapp_name

incident_webapp_url

str

no

incident_details__webapp_url

incident_scan_date

str

no

incident_details__scan_date

incident_url

str

no

incident_details__url

incident_cweid

str

no

incident_details__cweid

incident_ip_address

str

no

incident_details__ip_address

incident_origin_url

str

no

incident_details__origin_url

incident_original_url

str

no

incident_details__original_url

incident_page_url

str

no

incident_details__page_url

incident_namesserver

str

no

incident_details__namesserver

incident_soa

str

no

incident_details__soa

incident_mx

str

no

incident_details__mx

incident_txt

str

no

incident_details__txt

incident_cname

str

no

incident_details__cname

incident_classifications

json

no

incident_details__classifications

incident_classifications_values

str

no

incident_details__classifications__values

event_id

str

no

 

event_url

str

no

 

source_group

str

no

 

source_name

str

no

 

source_url

str

no

 

event_summary

str

no

 

threat_magnitude

str

no

 

posted_time

str

no

 

acquisition_time

str

no

 

analyzed_time

str

no

 

updated_time

str

no

 

threat_tags

str

no

 

incident_details_incident_id

str

no

 

incident_details_incident_url

str

no

 

incident_details_priority

str

no

 

incident_details_created_time

timestamp

no

 

incident_details_matched_alert_rule

str

no

 

incident_details_incident_status

str

no

 

incident_details_assignee

str

no

 

scan_date

str

no

 

attachments

str

no

 

sub_module

str

no

 

vendor

str

no

 

created_at

timestamp

no

 

updated_at

timestamp

no

 

hostchain

str

yes

 

tag

str

yes

 

rawMessage

str

yes

 

 

Related content

cdn.cloudflare
cdn.cloudflare
More like this
cloud.paloalto
cloud.paloalto
More like this
cloud.sophos
cloud.sophos
More like this
cloud.cloudflare
cloud.cloudflare
More like this
CloudSEK XVigil collector
CloudSEK XVigil collector
More like this
cloud.aws.guardduty
cloud.aws.guardduty
More like this