cloud.twistlock
Introduction
The tags beginning with cloud.twistlock
identify events generated by Twistlock.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as cloud.twistlock
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Twistlock |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
cloud.twistlock.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
type |
|
|
|
|
time |
|
|
|
|
timestamp |
| parsedate(time, "MMM DD, YYYY HH:mm:ss [UTC]", "UTC") | time |
|
container |
|
|
|
|
image |
|
|
|
|
host |
|
|
|
|
fqdn |
|
|
|
|
function |
|
|
|
|
region |
|
|
|
|
runtime |
|
|
|
|
appID |
|
|
|
|
rule |
|
|
|
|
message |
|
|
|
|
aggregated |
|
|
|
|
rest |
|
|
|
|
rawMessage |
|
| rawSource | ✓ |
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |