casb.illumio
Introduction
The tags beginning with casb.illumio
identify events generated by Illumio.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as casb.illumio
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Illumio |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
casb.illumio.events
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
href |
|
|
timestamp |
|
|
pce_fqdn |
|
|
created_by__user__href |
|
|
created_by__user__username |
|
|
event_type |
|
|
status |
|
|
severity |
|
|
action__uuid |
|
|
action__api_endpoint |
|
|
action__api_method |
|
|
action__http_status_code |
|
|
action__src_ip |
|
|
resource_changes |
|
|
notifications |
|
|
version |
|
|
pn |
|
|
un |
|
|
src_ip |
|
|
dst_ip |
|
|
class |
|
|
proto |
|
|
dst_port |
|
|
dir |
|
|
state |
|
|
src_hostname |
|
|
src_href |
|
|
dst_hostname |
|
|
dst_href |
|
|
src_labels__app |
|
|
src_labels__env |
|
|
src_labels__loc |
|
|
dst_labels__app |
|
|
dst_labels__env |
|
|
dst_labels__loc |
|
|
dst_labels__role |
|
|
pd |
|
|
count |
|
|
interval_sec |
|
|
fqdn |
|
|
sn |
|
|
type |
|
|
code |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |