ndr.extrahop
Introduction
The tags beginning with ndr.extrahop
identify events generated by ExtraHop NDR services.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ndr.extrahop
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
ExtraHop Reveal(x) |
|
|
|
| |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
ndr.extrahop.revealx
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
name |
| Â |
event_id |
| Â |
alert_name |
| Â |
alert_comment |
| Â |
object_name |
| Â |
object_type |
| Â |
object_id |
| Â |
object_str_id |
| Â |
macaddr |
| Â |
ipaddr |
| Â |
alert_expression |
| Â |
alert_value |
| Â |
alert_severity |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| Â |
ndr.extrahop.revealx360.alerts
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
id |
| Â |
mod_time |
| Â |
name |
| Â |
author |
| Â |
stat_name |
| Â |
field_name |
| Â |
field_op |
| Â |
field_name2 |
| Â |
operator |
| Â |
operand |
| Â |
apply_all |
| Â |
units |
| Â |
interval_length |
| Â |
refire_interval |
| Â |
notify_snmp |
| Â |
severity |
| Â |
disabled |
| Â |
type |
| Â |
cc |
| Â |
description |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
ndr.extrahop.revealx360.detection
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
id |
| Â |
start_time |
| Â |
update_time |
| Â |
end_time |
| Â |
mod_time |
| Â |
title |
| Â |
description |
| Â |
risk_score |
| Â |
type |
| Â |
recommended_factors |
| Â |
recommended |
| Â |
categories |
| Â |
server_ipaddr_type |
| Â |
server_ipaddr_value |
| Â |
certificate |
| Â |
cipher_suite |
| Â |
participants |
| Â |
ticket_id |
| Â |
assignee |
| Â |
status |
| Â |
resolution |
| Â |
mitre_tactics |
| Â |
mitre_techniques |
| Â |
appliance_id |
| Â |
is_user_created |
| Â |
hostchain |
|  ✓ |
tag |
|  ✓ |
rawMessage |
|  ✓ |