/
monitor.patrol
monitor.patrol
[ Introduction ] [ Valid tags and data tables ] [ Table structure ]
Introduction
The tags beginning with monitor.patrol
identify events generated by BMC.
Valid tags and data tables
The full tag must have three levels. The first two are fixed as monitor.elastic
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
BMC Patrol |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in this table:
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
|
|
|
machine |
|
| vmachine |
clon |
|
| vclon |
rawMessage |
| ✓ |
|
serverdate |
|
|
|
msgId |
|
|
|
eventType |
|
|
|
message |
|
|
|
hostchain |
| ✓ |
|
tag |
| ✓ |
|
, multiple selections available,
Related content
monitor.mainview
monitor.mainview
More like this
monitor.elastic
monitor.elastic
More like this
monitor.datadog
monitor.datadog
More like this
threatintel.socradar
threatintel.socradar
More like this
edr.observeit
edr.observeit
More like this
threatintel.anomaly
threatintel.anomaly
More like this