ids.wazuh
Introduction
The tags beginning with ids.wazuh
identify events generated by Wazuh.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ids.wazuh
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Wazuh |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.wazuh.alerts
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
timestamp |
| Â | Â | Â |
rule__level |
| Â | Â | Â |
rule__description |
| Â | Â | Â |
rule__id |
| Â | Â | Â |
rule__firedtimes |
| Â | Â | Â |
rule__mail |
| Â | Â | Â |
rule__groups_str |
| join(rule__groups, ',') | rule__groups | Â |
rule__pci_dss_str |
| join(rule__pci_dss, ',') | rule__pci_dss | Â |
rule__gdpr_str |
| join(rule__gdpr, ',') | rule__gdpr | Â |
rule__hipaa_str |
| rule__hipaa | Â | |
rule__nist_800_53_str |
| rule__nist_800_53 | Â | |
rule__tsc_str |
| rule__tsc | Â | |
rule__mitre__id_str |
| rule__mitre__id | Â | |
rule__mitre__tactic_str |
| rule__mitre__tactic | Â | |
rule__mitre__technique_str |
| rule__mitre__technique | Â | |
rule__gpg13_str |
| rule__gpg13 | Â | |
agent__id |
| Â | Â | Â |
agent__name |
| Â | Â | Â |
agent__ip |
| Â | Â | Â |
manager__name |
| Â | Â | Â |
id |
| Â | Â | Â |
full_log |
| Â | Â | Â |
syscheck__path |
| Â | Â | Â |
syscheck__size_after |
| Â | Â | Â |
syscheck__uid_after |
| Â | Â | Â |
syscheck__gid_after |
| Â | Â | Â |
syscheck__md5_before |
| Â | Â | Â |
syscheck__md5_after |
| Â | Â | Â |
syscheck__sha1_before |
| Â | Â | Â |
syscheck__sha1_after |
| Â | Â | Â |
syscheck__changed_attributes_str |
| syscheck__changed_attributes | Â | |
syscheck__event |
| Â | Â | Â |
predecoder__program_name |
| Â | Â | Â |
predecoder__timestamp |
| Â | Â | Â |
predecoder__hostname |
| Â | Â | Â |
decoder__parent |
| Â | Â | Â |
decoder__name |
| Â | Â | Â |
data__srcuser |
| Â | Â | Â |
data__dstuser |
| Â | Â | Â |
data__uid |
| Â | Â | Â |
data__id |
| Â | Â | Â |
data__status |
| Â | Â | Â |
data__extra_data |
| Â | Â | Â |
data__system_name |
| Â | Â | Â |
data__type |
| Â | Â | Â |
data__title |
| Â | Â | Â |
data__file |
| Â | Â | Â |
data__subject__security_id |
| Â | Â | Â |
data__subject__account_name |
| Â | Â | Â |
data__subject__account_domain |
| Â | Â | Â |
data__subject__login_id |
| Â | Â | Â |
data__win__system__providerName |
| Â | Â | Â |
data__win__system__providerGuid |
| Â | Â | Â |
data__win__system__eventID |
| Â | Â | Â |
data__win__system__version |
| Â | Â | Â |
data__win__system__level |
| Â | Â | Â |
data__win__system__task |
| Â | Â | Â |
data__win__system__opcode |
| Â | Â | Â |
data__win__system__keywords |
| Â | Â | Â |
data__win__system__systemTime |
| Â | Â | Â |
data__win__system__eventRecordID |
| Â | Â | Â |
data__win__system__processID |
| Â | Â | Â |
data__win__system__threadID |
| Â | Â | Â |
data__win__system__channel |
| Â | Â | Â |
data__win__system__computer |
| Â | Â | Â |
data__win__system__severityValue |
| Â | Â | Â |
data__win__system__message |
| Â | Â | Â |
data__win__eventdata__targetUserSid |
| Â | Â | Â |
data__win__eventdata__targetUserName |
| Â | Â | Â |
data__win__eventdata__targetDomainName |
| Â | Â | Â |
data__win__eventdata__targetLogonId |
| Â | Â | Â |
data__win__eventdata__logonType |
| Â | Â | Â |
data__win__eventdata__serviceName |
| Â | Â | Â |
data__win__eventdata__serviceSid |
| Â | Â | Â |
data__win__eventdata__ticketOptions |
| Â | Â | Â |
data__win__eventdata__ticketEncryptionType |
| Â | Â | Â |
data__win__eventdata__ipAddress |
| Â | Â | Â |
data__win__eventdata__ipPort |
| Â | Â | Â |
data__win__eventdata__status |
| Â | Â | Â |
data__win__eventdata__logonGuid |
| Â | Â | Â |
location |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |