/
ids.juniper
ids.juniper
[ 1 Introduction ] [ 2 Valid tags and data tables ] [ 3 Table structure ]
Introduction
The tags beginning with ids.juniper
identify events generated by Juniper.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ids.juniper
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Juniper SRX Firewall |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.juniper.srx
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
host |
| vhost |
|
eventType |
|
|
|
user |
|
|
|
attackName |
|
|
|
sourceAddress |
|
|
|
destinationAddress |
|
|
|
sourceZoneName |
|
|
|
interfaceName |
|
|
|
protocolId |
|
|
|
action |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
| rawSource | ✓ |