casb.trendmicro
Introduction
The tags beginning with casb.trendmicro
identify events generated by Trend Micro.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as casb.trendmicro
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Trend Micro |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
casb.trendmicro.security
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
hostname |
|
|
|
|
logItemId |
|
|
|
|
service |
|
|
|
|
event |
|
|
|
|
scanType |
|
|
|
|
affectedUser |
|
|
|
|
location |
|
|
|
|
detectionTime |
|
|
|
|
triggeredPolicyName |
|
|
|
|
triggeredSecurityFilter |
|
|
|
|
action |
|
|
|
|
actionResult |
|
|
|
|
mailMessageId |
|
|
|
|
mailMessageSender |
|
|
|
|
mailMessageRecipient_str |
| join(mailMessageRecipient, ',') | mailMessageRecipient |
|
mailMessageSubmitTime |
|
|
|
|
mailMessageDeliveryTime |
|
|
|
|
mailMessageSubject |
|
|
|
|
mailMessageFileName |
|
|
|
|
securityRiskName |
|
|
|
|
detectedBy |
|
|
|
|
riskLevel |
|
|
|
|
detectionType |
|
|
|
|
fileSha1 |
|
|
|
|
ransomwareName |
|
|
|
|
fileName |
|
|
|
|
fileUploadTime |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |