cloud.sophos
Introduction
The tags beginning with cloud.sophos
identify events generated by Sophos.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as cloud.sophos
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Sophos Central |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
cloud.sophos.central.alerts
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
info |
|
|
threatCleanable |
|
|
threat |
|
|
eventServiceEventId |
|
|
customerId |
|
|
severity |
|
|
createdAt |
|
|
when |
|
|
description |
|
|
location |
|
|
id |
|
|
type |
|
|
source |
|
|
dataCreatedAt |
|
|
dataEndpointId |
|
|
dataEndpointJavaId |
|
|
dataEndpointPlatform |
|
|
dataEndpointType |
|
|
dataEventServiceId |
|
|
dataEventServiceId_type |
|
|
dataEventServiceId_data |
|
|
dataInsertedAt |
|
|
dataMakeActionableAt |
|
|
dataSourceAppId |
|
|
dataSourceInfoIp |
|
|
dataUserMatchId |
|
|
dataUserMatchUuid |
|
|
dataUserMatchUuid_type |
|
|
dataUserMatchUuid_data |
|
|
dataThreatId |
|
|
dataThreatStatus |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|
cloud.sophos.central.events
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
appSha256 |
|
|
appCerts |
|
|
userId |
|
|
threat |
|
|
endpointId |
|
|
endpointType |
|
|
createdAt |
|
|
customerId |
|
|
severity |
|
|
sourceInfoIp |
|
|
origin |
|
|
when |
|
|
coreRemedyItems |
|
|
name |
|
|
location |
|
|
id |
|
|
type |
|
|
source |
|
|
group2 |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |