ids.zeek
Introduction
The tags beginning with ids.zeek
identify events generated by Zeek.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ids.zeek
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Zeek |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.zeek.ssl
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
ts |
| Â | Â | Â |
uid |
| Â | Â | Â |
orig_h |
| Â | Â | Â |
orig_p |
| Â | Â | Â |
resp_h |
| Â | Â | Â |
resp_p |
| Â | Â | Â |
resumed |
| Â | Â | Â |
established |
| Â | Â | Â |
ja3 |
| Â | Â | Â |
ja3_version |
| Â | Â | Â |
ja3_ciphers |
| Â | Â | Â |
ja3_extensions |
| Â | Â | Â |
ja3_ec |
| Â | Â | Â |
ja3_ec_fmt |
| Â | Â | Â |
ja3s |
| Â | Â | Â |
ja3s_version |
| Â | Â | Â |
ja3s_cipher |
| Â | Â | Â |
ja3s_extensions |
| Â | Â | Â |
version |
| Â | Â | Â |
cipher |
| Â | Â | Â |
validation_status |
| Â | Â | Â |
cert_chain_fuids_str |
| join(cert_chain_fuids, ',') | cert_chain_fuids | Â |
client_cert_chain_fuids_str |
| join(client_cert_chain_fuids, ',') | client_cert_chain_fuids | Â |
subject |
| Â | Â | Â |
issuer |
| Â | Â | Â |
client_subject |
| Â | Â | Â |
client_issuer |
| Â | Â | Â |
server_name |
| Â | Â | Â |
last_alert |
| Â | Â | Â |
next_protocol |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |