ids.tripwire
Introduction
The tags beginning with ids.tripwire
identify events generated by Tripwire.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ids.tripwire
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Tripwire |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.tripwire.audit
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
hostname |
|
|
|
host |
| vhost |
|
LogType |
|
|
|
LogHostName |
|
|
|
LogId |
|
|
|
LogCategory |
|
|
|
LogUser |
|
|
|
AccessType |
|
|
|
EventType |
|
|
|
AppType |
|
|
|
ElementId |
|
|
|
NodeId |
|
|
|
NodeName |
|
|
|
NodeIp |
|
|
|
VerId |
|
|
|
AssociatedObjects |
|
|
|
Msg |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |