ids.darktrace
Introduction
The tags beginning with ids.darktrace
identify events generated by Darktrace.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ids.darktrace
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Darktrace platform |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.darktrace.threats
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
host |
| Â | vhost | Â |
creationTime |
| Â | Â | Â |
breachUrl |
| Â | Â | Â |
commentCount |
| Â | Â | Â |
pbid |
| Â | Â | Â |
time |
| Â | Â | Â |
model_name |
| Â | Â | Â |
model_pid |
| Â | Â | Â |
model_phid |
| Â | Â | Â |
model_uuid |
| Â | Â | Â |
model_logic_data_str |
| stringify(json(model_logic_data)) | model_logic_data | Â |
model_logic_type |
| Â | Â | Â |
model_logic_version |
| Â | Â | Â |
model_throttle |
| Â | Â | Â |
model_sharedEndpoints |
| Â | Â | Â |
model_actions_alert |
| Â | Â | Â |
model_actions_breach |
| Â | Â | Â |
model_actions_model |
| Â | Â | Â |
model_actions_setPriority |
| Â | Â | Â |
model_actions_setTag |
| Â | Â | Â |
model_actions_setType |
| Â | Â | Â |
model_tags_str |
| join(model_tags, ",") | model_tags | Â |
model_interval |
| Â | Â | Â |
model_sequenced |
| Â | Â | Â |
model_active |
| Â | Â | Â |
model_modified |
| Â | Â | Â |
model_activeTimes_type |
| Â | Â | Â |
model_activeTimes_version |
| Â | Â | Â |
model_priority |
| Â | Â | Â |
model_autoUpdate |
| Â | Â | Â |
model_autoSuppress |
| Â | Â | Â |
model_description |
| Â | Â | Â |
model_behaviour |
| Â | Â | Â |
model_created_by |
| Â | Â | Â |
model_edited_by |
| Â | Â | Â |
model_version |
| Â | Â | Â |
score |
| Â | Â | Â |
device_os |
| Â | Â | Â |
device_hostname |
| Â | Â | Â |
device_did |
| Â | Â | Â |
device_ip |
| Â | Â | Â |
device_sid |
| Â | Â | Â |
device_firstSeen |
| Â | Â | Â |
device_lastSeen |
| Â | Â | Â |
device_typename |
| Â | Â | Â |
device_typelabel |
| Â | Â | Â |
ips_ip_str |
| join(ips_ip, ",") | ips_ip | Â |
ips_timems_str |
| ips_timems | Â | |
ips_time_str |
| ips_time | Â | |
ips_sid_str |
| ips_sid | Â | |
triggeredFilters_message |
| Â | Â | Â |
triggeredFilters_sourcePort |
| Â | Â | Â |
triggeredFilters_destinationIP |
| Â | Â | Â |
triggeredFilters_destinationPort |
| Â | Â | Â |
triggeredFilters_connectionHostname |
| Â | Â | Â |
triggeredFilters_uri |
| Â | Â | Â |
triggeredFilters_httpMethod |
| Â | Â | Â |
triggeredFilters_httpContentType |
| Â | Â | Â |
triggeredFilters_userAgent |
| Â | Â | Â |
triggeredFilters_dnsHostLooup |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  | rawSource | ✓ |