casb.illumio
Introduction
The tags beginning with casb.illumio
identify events generated by Illumio.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as casb.illumio
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Illumio |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
casb.illumio.events
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
href |
| Â |
timestamp |
| Â |
pce_fqdn |
| Â |
created_by__user__href |
| Â |
created_by__user__username |
| Â |
event_type |
| Â |
status |
| Â |
severity |
| Â |
action__uuid |
| Â |
action__api_endpoint |
| Â |
action__api_method |
| Â |
action__http_status_code |
| Â |
action__src_ip |
| Â |
resource_changes |
| Â |
notifications |
| Â |
version |
| Â |
pn |
| Â |
un |
| Â |
src_ip |
| Â |
dst_ip |
| Â |
class |
| Â |
proto |
| Â |
dst_port |
| Â |
dir |
| Â |
state |
| Â |
src_hostname |
| Â |
src_href |
| Â |
dst_hostname |
| Â |
dst_href |
| Â |
src_labels__app |
| Â |
src_labels__env |
| Â |
src_labels__loc |
| Â |
dst_labels__app |
| Â |
dst_labels__env |
| Â |
dst_labels__loc |
| Â |
dst_labels__role |
| Â |
pd |
| Â |
count |
| Â |
interval_sec |
| Â |
fqdn |
| Â |
sn |
| Â |
type |
| Â |
code |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |