Document toolboxDocument toolbox

ids.tripwire

Introduction

The tags beginning with ids.tripwire identify events generated by Tripwire.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as ids.tripwire. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Tripwire

ids.tripwire.audit

ids.tripwire.audit

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

ids.tripwire.audit 

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

hostname

str

 

 

host

str

vhost

 

LogType

str

 

 

LogHostName

str

 

 

LogId

str

 

 

LogCategory

str

 

 

LogUser

str

 

 

AccessType

str

 

 

EventType

str

 

 

AppType

str

 

 

ElementId

str

 

 

NodeId

str

 

 

NodeName

str

 

 

NodeIp

str

 

 

VerId

str

 

 

AssociatedObjects

str

 

 

Msg

str

 

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

 

✓