Document toolboxDocument toolbox

nac.microsoft

Introduction

The tags beginning with nac.microsoftidentify events generated by Microsoft.

Valid tags and data tables 

The full tag must have two levels. The first two are fixed asnac.microsoft. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Microsoft

nac.microsoft.nps.events

nac.microsoft.nps.events

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

host

str

vhost

 

timestamp

str

 

 

computerName

str

 

 

eventSource

str

 

 

acctSessionId

str

 

 

class

str

 

 

MSQuarantineState

int4

 

 

MSExtendedQuarantineState

int4

 

 

quarantineSessionId

str

 

 

quarantineUpdateNonCompliant

int4

 

 

machineInventory

str

 

 

fullyQualifedMachineName

str

 

 

authenticationType

int4

 

 

systemHealthResult

str

 

 

SHVName

str

 

 

configID

int4

 

 

configFriendlyName

str

 

 

healthResult

str

 

 

extendedIsolationState

str

 

 

failureCategory

str

 

 

failureCategoryString

str

 

 

complianceResults

str

 

 

NPPolicyName

str

 

 

framedProtocol

str

 

 

sessionTimeout

int4

 

 

fullyQualifedUserName

str

 

 

SAMAccountName

str

 

 

clientIPv6Address

str

 

 

clientIPAddress

ip4

 

 

clientVendor

int4

 

 

clientFriendlyName

str

 

 

proxyPolicyName

str

 

 

serviceType

int4

 

 

providerType

int4

 

 

packetType

int4

 

 

reasonCode

int4

 

 

unknown

str

 

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

rawSource

✓