dbsec.imperva
Introduction
The tags beginning with dbsec.imperva
identify events generated by Imperva.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as dbsec.imperva
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Imperva SecureSphere |
|
|
|
| |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
dbsec.imperva.securesphere.alerts
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
leefVer |
|
|
vendor |
|
|
product |
|
|
version |
|
|
eventID |
|
|
type |
|
|
Alert_Action |
|
|
Alert_Date |
|
|
Policy_Name |
|
|
usrName |
|
|
host |
|
|
violations |
|
|
Server_Group |
|
|
Service_Name |
|
|
app |
|
|
sourceapp |
|
|
proto |
|
|
src |
|
|
dst |
|
|
spt |
|
|
dpt |
|
|
severity |
|
|
Violated_Item |
|
|
Violation_Description |
|
|
description |
|
|
VIO_LIST |
|
|
Gateway |
|
|
Raw_Data |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|
dbsec.imperva.securesphere.events
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
leefVer |
|
|
vendor |
|
|
product |
|
|
version |
|
|
eventID |
|
|
Server_Group |
|
|
Service_Name |
|
|
Application_Name |
|
|
Source_Type |
|
|
User_Type |
|
|
usrName |
|
|
User_Group |
|
|
Authenticated |
|
|
App_User |
|
|
src |
|
|
Application |
|
|
OS_User |
|
|
Host |
|
|
Service_Type |
|
|
dst |
|
|
Event_Type |
|
|
Operation |
|
|
Operation_type |
|
|
Policy_Name |
|
|
Object_name |
|
|
Object_type |
|
|
Subject |
|
|
Database |
|
|
Schema |
|
|
Table_Group |
|
|
Sensitive |
|
|
Privileged |
|
|
Stored_Proc |
|
|
Completed_Successfully |
|
|
Raw_Data |
|
|
Bind_Variables |
|
|
Error |
|
|
Response_Size |
|
|
Response_Time |
|
|
Affected_Rows |
|
|
devTimeFormat |
|
|
devTime |
|
|
Event |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|
dbsec.imperva.securesphere.system
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
leefVer |
|
|
vendor |
|
|
product |
|
|
version |
|
|
eventID |
|
|
type |
|
|
date |
|
|
severity |
|
|
user |
|
|
inner_message |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|