firewall.f5
Introduction
The tags beginning with firewall.f5
identify events generated by F5.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as firewall.f5
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
F5 Web Application Firewall |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
firewall.f5.asm
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
hostname |
|
|
|
host |
| vhost |
|
attack_type |
|
|
|
date_time |
|
|
|
dest_ip |
|
|
|
dest_port |
|
|
|
device_id |
|
|
|
geo_location |
|
|
|
http_class_name |
|
|
|
ip_address_intelligence |
|
|
|
ip_client |
|
|
|
ip_with_route_domain |
|
|
|
is_truncated |
|
|
|
management_ip_address |
|
|
|
method |
|
|
|
policy_apply_date |
|
|
|
policy_name |
|
|
|
protocol |
|
|
|
query_string |
|
|
|
request |
|
|
|
request_status |
|
|
|
response |
|
|
|
response_code |
|
|
|
route_domain |
|
|
|
session_id |
|
|
|
severity |
|
|
|
sig_ids |
|
|
|
sig_names |
|
|
|
sig_set_names |
|
|
|
src_port |
|
|
|
sub_violations |
|
|
|
support_id |
|
|
|
unit_hostname |
|
|
|
uri |
|
|
|
username |
|
|
|
violation_details |
|
|
|
violation_rating |
|
|
|
violations |
|
|
|
virus_name |
|
|
|
websocket_direction |
|
|
|
websocket_message_type |
|
|
|
x_forwarded_for_header_value |
|
|
|
blocking_exception_reason |
|
|
|
captcha_result |
|
|
|
fragment |
|
|
|
management_ip_address_2 |
|
|
|
microservice |
|
|
|
sig_cves |
|
|
|
staged_sig_cves |
|
|
|
staged_sig_ids |
|
|
|
staged_sig_names |
|
|
|
staged_threat_campaign_names |
|
|
|
tap_event_id |
|
|
|
tap_vid |
|
|
|
threat_campaign_names |
|
|
|
vs_name |
|
|
|
web_application_name |
|
|
|
geo_info |
|
|
|
headers |
|
|
|
query_str |
|
|
|
req_status |
|
|
|
resp_code |
|
|
|
unit_host |
|
|
|
ip_route_domain |
|
|
|
manage_ip_addr |
|
|
|
sub_violates |
|
|
|
violate_details |
|
|
|
violate_rate |
|
|
|
x_fwd_hdr_val |
|
|
|
http_class |
|
|
|
req |
|
|
|
resp |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |