ips.toplayer
Introduction
The tags beginning with ips.toplayer
identify events generated by IBM Top Layer IPS.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ips.toplayer
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
IBM Top Layer IPS |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ips.toplayer.common
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
model |
| vmodel |
|
sensor |
| vsensor |
|
msgId |
|
|
|
pt |
|
|
|
prot |
|
|
|
cip |
|
|
|
cprt |
|
|
|
sip |
|
|
|
sprt |
|
|
|
atck |
|
|
|
disp |
|
|
|
ckt |
|
|
|
src |
|
|
|
msg |
|
|
|
code |
|
|
|
type |
|
|
|
host |
|
|
|
rule |
|
|
|
user |
|
|
|
acc |
|
|
|
adm |
|
|
|
app |
|
|
|
arg |
|
|
|
bld |
|
|
|
bw |
|
|
|
bd |
|
|
|
cause |
|
|
|
cbtx |
|
|
|
cc1 |
|
|
|
cc2 |
|
|
|
cc3 |
|
|
|
cc4 |
|
|
|
cmac |
|
|
|
cname |
|
|
|
cptx |
|
|
|
cfg |
|
|
|
cnt |
|
|
|
ctd |
|
|
|
dup |
|
|
|
dur |
|
|
|
et |
|
|
|
flags |
|
|
|
fwd |
|
|
|
mtu |
|
|
|
op |
|
|
|
oper |
|
|
|
path |
|
|
|
qos |
|
|
|
red |
|
|
|
ref |
|
|
|
rel |
|
|
|
res |
|
|
|
sbtx |
|
|
|
ser |
|
|
|
spd |
|
|
|
smac |
|
|
|
sname |
|
|
|
sptx |
|
|
|
spt |
|
|
|
term |
|
|
|
thret |
|
|
|
thrsh |
|
|
|
uri |
|
|
|
upt |
|
|
|
vlan |
|
|
|
cckt |
|
|
|
sckt |
|
|
|
unknown |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |