ips.f5
Introduction
The tags beginning with ips.f5
identify events generated by F5 BIG-IP.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ips.f5
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
F5 BIG-IP Intrusion Prevention System |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ips.f5.bigip
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
host |
|
| vhost |
|
serverdate |
|
|
|
|
rule |
|
|
|
|
message |
|
|
|
|
clientIp |
|
|
|
|
clientPort |
|
|
|
|
vIp |
|
|
|
|
vIpPort |
|
|
|
|
nodeIp |
|
|
|
|
nodePort |
|
|
|
|
URL |
|
|
|
|
severity |
|
|
|
|
process |
| process1 -> '[' ? split(process1, '[', 0) : process1 | process1 |
|
user |
|
|
|
|
command |
|
|
|
|
sslSrcIP |
|
|
|
|
sslSrcIdentd |
|
|
|
|
sslUser |
|
|
|
|
sslServerdate |
|
|
|
|
sslUrl |
|
|
|
|
sslStatusCode |
|
|
|
|
sslResponseLength |
|
|
|
|
rawMessage |
|
|
| ✓ |
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |