ids.darktrace
Introduction
The tags beginning with ids.darktrace
identify events generated by Darktrace.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ids.darktrace
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Darktrace platform |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.darktrace.threats
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
host |
|
| vhost |
|
creationTime |
|
|
|
|
breachUrl |
|
|
|
|
commentCount |
|
|
|
|
pbid |
|
|
|
|
time |
|
|
|
|
model_name |
|
|
|
|
model_pid |
|
|
|
|
model_phid |
|
|
|
|
model_uuid |
|
|
|
|
model_logic_data_str |
| stringify(json(model_logic_data)) | model_logic_data |
|
model_logic_type |
|
|
|
|
model_logic_version |
|
|
|
|
model_throttle |
|
|
|
|
model_sharedEndpoints |
|
|
|
|
model_actions_alert |
|
|
|
|
model_actions_breach |
|
|
|
|
model_actions_model |
|
|
|
|
model_actions_setPriority |
|
|
|
|
model_actions_setTag |
|
|
|
|
model_actions_setType |
|
|
|
|
model_tags_str |
| join(model_tags, ",") | model_tags |
|
model_interval |
|
|
|
|
model_sequenced |
|
|
|
|
model_active |
|
|
|
|
model_modified |
|
|
|
|
model_activeTimes_type |
|
|
|
|
model_activeTimes_version |
|
|
|
|
model_priority |
|
|
|
|
model_autoUpdate |
|
|
|
|
model_autoSuppress |
|
|
|
|
model_description |
|
|
|
|
model_behaviour |
|
|
|
|
model_created_by |
|
|
|
|
model_edited_by |
|
|
|
|
model_version |
|
|
|
|
score |
|
|
|
|
device_os |
|
|
|
|
device_hostname |
|
|
|
|
device_did |
|
|
|
|
device_ip |
|
|
|
|
device_sid |
|
|
|
|
device_firstSeen |
|
|
|
|
device_lastSeen |
|
|
|
|
device_typename |
|
|
|
|
device_typelabel |
|
|
|
|
ips_ip_str |
| join(ips_ip, ",") | ips_ip |
|
ips_timems_str |
| ips_timems |
| |
ips_time_str |
| ips_time |
| |
ips_sid_str |
| ips_sid |
| |
triggeredFilters_message |
|
|
|
|
triggeredFilters_sourcePort |
|
|
|
|
triggeredFilters_destinationIP |
|
|
|
|
triggeredFilters_destinationPort |
|
|
|
|
triggeredFilters_connectionHostname |
|
|
|
|
triggeredFilters_uri |
|
|
|
|
triggeredFilters_httpMethod |
|
|
|
|
triggeredFilters_httpContentType |
|
|
|
|
triggeredFilters_userAgent |
|
|
|
|
triggeredFilters_dnsHostLooup |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
| rawSource | ✓ |