Document toolboxDocument toolbox

uba.exabeam

Introduction

The tags beginning with uba.exabeam identify events generated by Exabeam Security Analytics belonging to Exabeam.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as uba.exabeam and the third identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Exabeam Security Analytics

uba.exabeam.notables

uba.exabeam.notables

uba.exabeam.skyformation

uba.exabeam.skyformation

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

uba.exabeam.notables

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

timestamp

str

 

id

str

 

score

str

 

user

str

 

src_ip

str

 

dest_ip

str

 

event_time

str

 

event_type

str

 

host

str

 

rawlog_time

str

 

time

str

 

source

str

 

vendor

str

 

lockout_id

str

 

session_id

str

 

isp

str

 

country_code

str

 

session_order

str

 

account

str

 

failure_reason

str

 

rule_id

str

 

rule_name

str

 

rule_description

str

 

rule_reason

str

 

src_host

str

 

rawlog_refs

str

 

alert_name

str

 

local_asset

str

 

outcome

str

 

alert_type

str

 

additional_info

str

 

alert_id

str

 

alert_severity

str

 

url

str

 

start_time

str

 

end_time

str

 

status

str

 

accounts

str

 

labels

str

 

assets

str

 

zones

str

 

top_reasons

str

 

reasons_count

str

 

events_count

str

 

alerts_count

str

 

sequence_type

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓

uba.exabeam.skyformation

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

datestamp

str

 

time

str

 

devname

str

 

device_id

str

 

log_id

str

 

type

str

 

subtype

str

 

pri

str

 

description

str

 

msg

str

 

action

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓