Document toolboxDocument toolbox

ids.juniper

Introduction

The tags beginning with ids.juniper identify events generated by Juniper.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as ids.juniper. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Juniper SRX Firewall

ids.juniper.srx

ids.juniper.srx

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

ids.juniper.srx

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

host

str

vhost

 

eventType

str

 

 

user

str

 

 

attackName

str

 

 

sourceAddress

str

 

 

destinationAddress

str

 

 

sourceZoneName

str

 

 

interfaceName

str

 

 

protocolId

str

 

 

action

str

 

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

rawSource

✓