ids.tripwire
Introduction
The tags beginning with ids.tripwire
identify events generated by Tripwire.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ids.tripwire
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Tripwire |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.tripwire.auditÂ
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
host |
| vhost | Â |
LogType |
| Â | Â |
LogHostName |
| Â | Â |
LogId |
| Â | Â |
LogCategory |
| Â | Â |
LogUser |
| Â | Â |
AccessType |
| Â | Â |
EventType |
| Â | Â |
AppType |
| Â | Â |
ElementId |
| Â | Â |
NodeId |
| Â | Â |
NodeName |
| Â | Â |
NodeIp |
| Â | Â |
VerId |
| Â | Â |
AssociatedObjects |
| Â | Â |
Msg |
| Â | Â |
hostchain |
|  | ✓ |
tag |
|  | ✓ |
rawMessage |
|  | ✓ |