Document toolboxDocument toolbox

proxy.isaserver

Introduction

The tags beginning with proxy.isaserver identify events generated by Microsoft Forefront Threat Management Gateway (formerly Microsoft ISA Server) belonging to Microsoft.

Valid tags and data tables 

The full tag must have 6 levels. The first two are fixed as proxy.isaserver. The third level identifies the type of events sent and the rest of them indicate the event subtypes.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Microsoft Forefront Threat Management Gateway (formerly Microsoft ISA Server)

proxy.isaserver.access-w3c-ab.pro.www.1

proxy.isaserver.accessW3cAb

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

proxy.isaserver.accessW3cAb

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

environment

str

venv

 

site

str

vsite

 

clon

str

vclon

 

serverdate

timestamp

 

 

srcIp

ip4

 

 

user

str

 

 

method

str

 

 

url

str

 

 

proto

str

 

 

statusCode

int4

 

 

action

str

 

 

userAgent

str

 

 

servername

str

 

 

referer

str

 

 

dstHost

str

 

 

dstIp

ip4

 

 

dstPort

int4

 

 

responseTime

int4

 

 

responseLength

int8

 

 

requestLength

int8

 

 

objSrc

str

 

 

rule

str

 

 

filterInfo

str

 

 

srcNet

str

 

 

dstNet

str

 

 

errInfo

str

 

 

authServer

str

 

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

rawSource

✓