Document toolboxDocument toolbox

casb.illumio

Introduction

The tags beginning with casb.illumio identify events generated by Illumio.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as casb.illumio. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Illumio

casb.illumio.events

casb.illumio.events

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

casb.illumio.events

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

href

str

 

timestamp

str

 

pce_fqdn

str

 

created_by__user__href

str

 

created_by__user__username

str

 

event_type

str

 

status

str

 

severity

str

 

action__uuid

str

 

action__api_endpoint

str

 

action__api_method

str

 

action__http_status_code

int4

 

action__src_ip

ip4

 

resource_changes

str

 

notifications

str

 

version

int4

 

pn

str

 

un

str

 

src_ip

ip4

 

dst_ip

ip4

 

class

str

 

proto

int4

 

dst_port

int4

 

dir

str

 

state

str

 

src_hostname

str

 

src_href

str

 

dst_hostname

str

 

dst_href

str

 

src_labels__app

str

 

src_labels__env

str

 

src_labels__loc

str

 

dst_labels__app

str

 

dst_labels__env

str

 

dst_labels__loc

str

 

dst_labels__role

str

 

pd

int4

 

count

int4

 

interval_sec

int4

 

fqdn

str

 

sn

str

 

type

int4

 

code

int4

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓