firewall.iptables
Introduction
The tags beginning with firewall.iptables
identify events generated by Linux iptables.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as firewall.iptables
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Linux kernel firewall - iptables |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
firewall.iptables.std
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
host |
| vhost | Â |
application |
| Â | Â |
stamp |
| Â | Â |
logtype |
| Â | Â |
srcIp |
| Â | Â |
dstIp |
| Â | Â |
srcPort |
| Â | Â |
dstPort |
| Â | Â |
ifaceIn |
| Â | Â |
ifaceOut |
| Â | Â |
srcMac |
| Â | Â |
dstMac |
| Â | Â |
etherType |
| Â | Â |
proto |
| Â | Â |
len |
| Â | Â |
window |
| Â | Â |
tos |
| Â | Â |
prec |
| Â | Â |
ttl |
| Â | Â |
id |
| Â | Â |
frag |
| Â | Â |
opt |
| Â | Â |
ceFlag |
| Â | Â |
dfFlag |
| Â | Â |
mfFlag |
| Â | Â |
seq |
| Â | Â |
ack |
| Â | Â |
res |
| Â | Â |
urgp |
| Â | Â |
urgFlag |
| Â | Â |
ackFlag |
| Â | Â |
pshFlag |
| Â | Â |
rstFlag |
| Â | Â |
synFlag |
| Â | Â |
finFlag |
| Â | Â |
protoOpt |
| Â | Â |
protoLen |
| Â | Â |
icmpType |
| Â | Â |
icmpCode |
| Â | Â |
icmpId |
| Â | Â |
hostchain |
|  | ✓ |
tag |
|  | ✓ |
rawMessage |
| rawSource | ✓ |
Â