Document toolboxDocument toolbox

cloud.rubrik

Introduction

The tags beginning with cloud.rubrik identify events generated by Rubrik.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as cloud.rubrik. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Rubrik cloud data management

cloud.rubrik.audit

cloud.rubrik.audit

cloud.rubrik.events

cloud.rubrik.events

cloud.rubrik.events.rfc5424

cloud.rubrik.events.json

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

cloud.rubrik.audit

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

user_note

str

 

username

str

 

id

str

 

message

str

 

time

timestamp

 

severity

str

 

status

str

 

cluster_id

str

 

cluster_name

str

 

cluster_timezone

str

 

cluster_typename

str

 

org_id

str

 

org_name

str

 

typename

str

 

at_devo_pulling_id

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓

cloud.rubrik.events

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

machine

str

 

 

timestamp

timestamp

 

 

application_name

str

 

 

pid

str

 

 

event_id

str

 

 

event_name

str

 

 

event_series_id

str

 

 

event_severity

str

 

 

event_type

str

 

 

object_id

str

 

 

object_name

str

 

 

object_type

str

 

 

cluster_id

str

 

 

cluster_name

str

 

 

error_id

str

 

 

error_code

str

 

 

error_message

str

 

 

error_reason

str

 

 

error_remedy

str

 

 

job_instance_id

str

 

 

location_name

str

 

 

node_id

str

 

 

node_ip_address

ip4

 

 

audit_user_name

str

 

 

audit_user_id

str

 

 

status

str

 

 

url

str

 

 

message

str

 

 

source

str

 

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

rawSource

✓