firewall.barracuda
Introduction
The tags beginning with firewall.barracuda
identify events generated by Barracuda Networks.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as firewall.barracuda
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Barracuda Firewall |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
firewall.barracuda.audit
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
machine |
| vmachine |
|
serverdate |
|
|
|
operation |
|
|
|
type |
|
|
|
logType |
|
|
|
InputIF |
|
|
|
proto |
|
|
|
action |
|
|
|
srcIp |
|
|
|
srcPort |
|
|
|
dstIp |
|
|
|
dstPort |
|
|
|
dstService |
|
|
|
Status_code |
|
|
|
operationType |
|
|
|
srcIp2 |
|
|
|
srcPort2 |
|
|
|
dstIp2 |
|
|
|
dstPort2 |
|
|
|
OutputIF |
|
|
|
SCR_MAC |
|
|
|
duration |
|
|
|
inBytes |
|
|
|
inPkts |
|
|
|
outBytes |
|
|
|
outPkts |
|
|
|
totalBytes |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
| rawSource | ✓ |