/
nac.cyberx
nac.cyberx
[ 1 Introduction ] [ 2 Valid tags and data tables ] [ 3 Table structure ]
Introduction
The tags beginning with nac.cyberx
identify events generated by CyberX.
Valid tags and data tables
The full tag must have two levels. The first two are fixed asnac.cyberx
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
CyberX |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
cefVersion |
|
|
embDeviceVendor |
|
|
embDeviceProduct |
|
|
deviceVersion |
|
|
signatureID |
|
|
name |
|
|
severity |
|
|
_cefVer |
|
|
msg |
|
|
start |
|
|
dst_ip |
|
|
dst_mac |
|
|
protocol |
|
|
log_severity |
|
|
src_ip |
|
|
src_mac |
|
|
type |
|
|
hostchain |
| ✓ |
rawMessage |
| ✓ |
, multiple selections available,