ndr.extrahop
Introduction
The tags beginning with ndr.extrahop
identify events generated by ExtraHop NDR services.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ndr.extrahop
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
ExtraHop Reveal(x) |
|
|
|
| |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
ndr.extrahop.revealx
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
name |
|
|
event_id |
|
|
alert_name |
|
|
alert_comment |
|
|
object_name |
|
|
object_type |
|
|
object_id |
|
|
object_str_id |
|
|
macaddr |
|
|
ipaddr |
|
|
alert_expression |
|
|
alert_value |
|
|
alert_severity |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|
ndr.extrahop.revealx360.alerts
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
mod_time |
|
|
name |
|
|
author |
|
|
stat_name |
|
|
field_name |
|
|
field_op |
|
|
field_name2 |
|
|
operator |
|
|
operand |
|
|
apply_all |
|
|
units |
|
|
interval_length |
|
|
refire_interval |
|
|
notify_snmp |
|
|
severity |
|
|
disabled |
|
|
type |
|
|
cc |
|
|
description |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
ndr.extrahop.revealx360.detection
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
id |
|
|
start_time |
|
|
update_time |
|
|
end_time |
|
|
mod_time |
|
|
title |
|
|
description |
|
|
risk_score |
|
|
type |
|
|
recommended_factors |
|
|
recommended |
|
|
categories |
|
|
server_ipaddr_type |
|
|
server_ipaddr_value |
|
|
certificate |
|
|
cipher_suite |
|
|
participants |
|
|
ticket_id |
|
|
assignee |
|
|
status |
|
|
resolution |
|
|
mitre_tactics |
|
|
mitre_techniques |
|
|
appliance_id |
|
|
is_user_created |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |