Document toolboxDocument toolbox

ndr.extrahop

Introduction

The tags beginning with ndr.extrahop identify events generated by ExtraHop NDR services.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as ndr.extrahop. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

ExtraHop Reveal(x)

ndr.extrahop.revealx

ndr.extrahop.revealx

ndr.extrahop.revealx360.alerts

ndr.extrahop.revealx360.alerts

ndr.extrahop.revealx360.detection

ndr.extrahop.revealx360.detection

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

ndr.extrahop.revealx

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

name

str

 

event_id

str

 

alert_name

str

 

alert_comment

str

 

object_name

str

 

object_type

str

 

object_id

int8

 

object_str_id

str

 

macaddr

str

 

ipaddr

ip4

 

alert_expression

str

 

alert_value

str

 

alert_severity

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

 

ndr.extrahop.revealx360.alerts

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

id

int4

 

mod_time

timestamp

 

name

str

 

author

str

 

stat_name

str

 

field_name

str

 

field_op

str

 

field_name2

str

 

operator

str

 

operand

str

 

apply_all

bool

 

units

str

 

interval_length

int4

 

refire_interval

int4

 

notify_snmp

bool

 

severity

int4

 

disabled

bool

 

type

str

 

cc

str

 

description

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓

ndr.extrahop.revealx360.detection

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

id

str

 

start_time

timestamp

 

update_time

timestamp

 

end_time

timestamp

 

mod_time

timestamp

 

title

str

 

description

str

 

risk_score

int4

 

type

str

 

recommended_factors

str

 

recommended

bool

 

categories

str

 

server_ipaddr_type

str

 

server_ipaddr_value

str

 

certificate

str

 

cipher_suite

str

 

participants

str

 

ticket_id

str

 

assignee

str

 

status

str

 

resolution

str

 

mitre_tactics

str

 

mitre_techniques

str

 

appliance_id

int4

 

is_user_created

bool

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓