threatintel.anomaly
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as threatintel.anomaly
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
- |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
threatintel.anomaly.threatstream
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
rawMessage |
|
| ✓ |
host |
| vhost |
|
search_name |
|
|
|
search_now |
|
|
|
info_min_time |
|
|
|
info_max_time |
|
|
|
info_search_time |
|
|
|
event__time |
|
|
|
event_action |
|
|
|
event_count |
|
|
|
event_dest |
|
|
|
event_dest_port |
|
|
|
event_et |
|
|
|
event_host |
|
|
|
event_source |
|
|
|
event_sourcetype |
|
|
|
event_src |
|
|
|
event_src_port |
|
|
|
event_ts_asn |
|
|
|
event_ts_classification |
|
|
|
event_ts_confidence |
|
|
|
event_ts_country |
|
|
|
event_ts_date_first |
|
|
|
event_ts_date_last |
|
|
|
event_ts_detail |
|
|
|
event_ts_id |
|
|
|
event_ts_ip |
|
|
|
event_ts_itype |
|
|
|
event_ts_lat |
|
|
|
event_ts_lon |
|
|
|
event_ts_lookup_key_value |
|
|
|
event_ts_maltype |
|
|
|
event_ts_org |
|
|
|
event_ts_resource_uri |
|
|
|
event_ts_severity |
|
|
|
event_ts_source |
|
|
|
event_ts_type |
|
|
|
event_victim |
|
|
|
hostname |
|
|
|
message |
| rawMessage |
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |