ids.snort
Introduction
The tags beginning with ids.snort
identify events generated by Snort.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as ids.snort
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Snort Intrusion Detection |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
ids.snort.unified2
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
sensor |
| Â | vmachine | Â |
linktype |
| Â | Â | Â |
pktSec |
| Â | Â | Â |
pktUSec |
| Â | Â | Â |
pktMicros |
| int8(pktSec) * 1000000 + pktUSec | pktSec pktUSec | Â |
pktDate |
| timestamp(pktMicros / 1000) | pktMicros | Â |
pktLen |
| Â | Â | Â |
srcmac |
| str(ethersrc(pcp)) | pcp | Â |
dstmac |
| pcp | Â | |
ttl |
| pcp | Â | |
ds |
| pcp | Â | |
ip4flags |
| pcp | Â | |
tcpflags |
| pcp | Â | |
srcPort |
| pcp | Â | |
dstPort |
| pcp | Â | |
tcpPayload |
| dstPort srcPort pcp | Â | |
pkt |
| Â | Â | Â |
protocol |
| Â | Â | Â |
srcIp |
| Â | Â | Â |
dstIp |
| Â | Â | Â |
recordTypeName |
| Â | Â | Â |
priorityId |
| Â | Â | Â |
eventId |
| Â | Â | Â |
impact |
| Â | Â | Â |
signatureRevision |
| Â | Â | Â |
generatorId |
| Â | Â | Â |
blocked |
| Â | Â | Â |
dp |
| Â | Â | Â |
classificationId |
| Â | Â | Â |
eventSecond |
| Â | Â | Â |
sp |
| Â | Â | Â |
sensorId |
| Â | Â | Â |
tvUSec |
| Â | Â | Â |
msgLen |
| Â | Â | Â |
signatureId |
| Â | Â | Â |
pktAction |
| Â | Â | Â |
unknown |
| Â | Â | Â |
hostchain |
| Â | Â | Â |
tag |
|  |  | ✓ |