box.win_kinesis
Introduction
The tags beginning with box.win_kinesis
identify events generated by the Windows Kinesis Agent.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as box.win_kinesis
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Windows Kinesis Agent |
|
|
|
| |
|
| |
|
| |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
box.win_kinesis
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
hostname |
|
|
|
hostIp |
|
|
|
type |
| vtype |
|
EventId |
|
|
|
Description |
|
|
|
LevelDisplayName |
|
|
|
LogName |
|
|
|
MachineName |
|
|
|
ProviderName |
|
|
|
TimeCreated |
|
|
|
Index |
|
|
|
UserName |
|
|
|
Keywords |
|
|
|
subject__security_id |
|
|
|
subject__account_name |
|
|
|
subject__account_domain |
|
|
|
subject__logon_id |
|
|
|
account_information__security_id |
|
|
|
account_information__account_name |
|
|
|
account_information__account_domain |
|
|
|
network_information__workstation_name |
|
|
|
network_information__source_address |
|
|
|
network_information__source_port |
|
|
|
network_information__destination_address |
|
|
|
network_information__destination_port |
|
|
|
failure_reason__failure_reason |
|
|
|
failure_reason__status |
|
|
|
failure_reason__sub_status |
|
|
|
process_information__process_id |
|
|
|
process_information__process_name |
|
|
|
service_information__service_id |
|
|
|
service_information__service_name |
|
|
|
service_information__service_file_name |
|
|
|
service_information__service_type |
|
|
|
service_information__service_start_type |
|
|
|
service_information__service_account |
|
|
|
access_request_information__access_mask |
|
|
|
access_request_information__accesses |
|
|
|
access_request_information__access_reasons |
|
|
|
access_request_information__properties |
|
|
|
logon_type |
|
|
|
object_server |
|
|
|
object_name |
|
|
|
object_type |
|
|
|
object_value_name |
|
|
|
object_handle_id |
|
|
|
operation_type |
|
|
|
share_information__share_name |
|
|
|
share_information__share_path |
|
|
|
share_information__relative_target_name |
|
|
|
task_information__task_name |
|
|
|
task_information__task_content |
|
|
|
attribute__sam_account_name |
|
|
|
attribute__ldap_display_name |
|
|
|
attribute__value |
|
|
|
additional_information__ticket_options |
|
|
|
additional_information__ticket_encryption_type |
|
|
|
additional_information__privileges |
|
|
|
audit_policy__changes |
|
|
|
change_information__new_value |
|
|
|
filter_information__layer_runtime_id |
|
|
|
detailed_authentication_information__authentication_package |
|
|
|
detailed_authentication_information__key_length |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
|
|
box.win_kinesis.application
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
EventId |
|
|
Description |
|
|
LevelDisplayName |
|
|
LogName |
|
|
MachineName |
|
|
ProviderName |
|
|
TimeCreated |
|
|
Index |
|
|
UserName |
|
|
Keywords |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|
box.win_kinesis.invalid
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
host |
| split(hostchain, "=", 0) | hostchain |
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
|
|
box.win_kinesis.security
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
EventId |
|
|
Description |
|
|
LevelDisplayName |
|
|
LogName |
|
|
MachineName |
|
|
ProviderName |
|
|
TimeCreated |
|
|
Index |
|
|
UserName |
|
|
Keywords |
|
|
account_information__security_id |
|
|
account_information__account_name |
|
|
account_information__account_domain |
|
|
account_information__logon_guid |
|
|
service_information__service_name |
|
|
service_information__service_id |
|
|
service_information__service_file_name |
|
|
service_information__service_type |
|
|
service_information__service_start_type |
|
|
service_information__service_account |
|
|
application_information__process_id |
|
|
application_information__application_name |
|
|
subject__security_id |
|
|
subject__account_name |
|
|
subject__account_domain |
|
|
subject__logon_id |
|
|
logon_type |
|
|
new_logon__security_id |
|
|
new_logon__account_name |
|
|
new_logon__account_domain |
|
|
new_logon__logon_id |
|
|
new_logon__logon_guid |
|
|
failure_reason__failure_reason |
|
|
failure_reason__status |
|
|
failure_reason__sub_status |
|
|
process_information__process_id |
|
|
process_information__process_name |
|
|
network_information__direction |
|
|
network_information__workstation_name |
|
|
network_information__source_network_address |
|
|
network_information__source_address |
|
|
network_information__source_port |
|
|
network_information__client_address |
|
|
network_information__client_port |
|
|
network_information__destination_address |
|
|
network_information__destination_port |
|
|
network_information__protocol |
|
|
network_information__object_type |
|
|
share_information__share_name |
|
|
share_information__share_path |
|
|
share_information__relative_target_name |
|
|
task_information__task_name |
|
|
task_information__task_content |
|
|
access_request_information__access_mask |
|
|
access_request_information__accesses |
|
|
access_request_information__properties |
|
|
access_request_information__access_reasons |
|
|
access_check_results |
|
|
filter_information__filter_runtime_id |
|
|
filter_information__layer_name |
|
|
filter_information__layer_runtime_id |
|
|
detailed_authentication_information__logon_process |
|
|
detailed_authentication_information__authentication_package |
|
|
detailed_authentication_information__transited_services |
|
|
detailed_authentication_information__package_name |
|
|
detailed_authentication_information__key_length |
|
|
additional_information__ticket_options |
|
|
additional_information__ticket_encryption_type |
|
|
additional_information__failure_code |
|
|
additional_information__result_code |
|
|
additional_information__transited_services |
|
|
additional_information__pre_authentication_type |
|
|
object_server |
|
|
object_name |
|
|
object_type |
|
|
object_value_name |
|
|
object_handle_id |
|
|
operation_type |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|
box.win_kinesis.system
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
EventId |
|
|
Description |
|
|
LevelDisplayName |
|
|
LogName |
|
|
MachineName |
|
|
ProviderName |
|
|
TimeCreated |
|
|
Index |
|
|
UserName |
|
|
Keywords |
|
|
service_information__service_name |
|
|
service_information__service_file_name |
|
|
service_information__service_type |
|
|
service_information__service_start_type |
|
|
service_information__service_account |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
|
|