Introduction
The tags beginning with ids.bro
identify events generated by Zeek Network Security Monitor.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ids.bro
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
| | |
---|
Bro IDS (now Zeek Network Security Monitor) | ids.bro.captureloss
| ids.bro.captureloss
|
ids.bro.communication
| ids.bro.communication
|
ids.bro.conn
| ids.bro.conn
|
ids.bro.dce_rpc
| ids.bro.dce_rpc
|
ids.bro.dhcp
| ids.bro.dhcp
|
ids.bro.dns
| ids.bro.dns
|
ids.bro.dpd
| ids.bro.dpd
|
ids.bro.files
| ids.bro.files
|
ids.bro.ftp
| ids.bro.ftp
|
ids.bro.http
| ids.bro.http
|
ids.bro.kerberos
| ids.bro.kerberos
|
ids.bro.knownhosts
| ids.bro.knownhosts
|
ids.bro.knownservices
| ids.bro.knownservices
|
ids.bro.notice
| ids.bro.notice
|
ids.bro.ntlm
| ids.bro.ntlm
|
ids.bro.ntp
| ids.bro.ntp
|
ids.bro.packet_filter
| ids.bro.packet_filter
|
ids.bro.pe
| ids.bro.pe
|
ids.bro.rdp
| ids.bro.rdp
|
ids.bro.reporter
| ids.bro.reporter
|
ids.bro.smb_files
| ids.bro.smb_files
|
ids.bro.smb_mapping
| ids.bro.smb_mapping
|
ids.bro.snmp
| ids.bro.snmp
|
ids.bro.software
| ids.bro.software
|
ids.bro.ssh
| ids.bro.ssh
|
ids.bro.ssl
| ids.bro.ssl
|
ids.bro.stats
| ids.bro.stats
|
ids.bro.weird
| ids.bro.weird
|
ids.bro.x509
| ids.bro.x509
|
For more information, read more About Devo tags.