Document toolboxDocument toolbox

monitor.elastic

[ Introduction ] [ Valid tags and data tables  ] [ Table structure ]

Introduction

The tags beginning with monitor.elastic identify events generated by Elastic.

Valid tags and data tables 

The full tag must have four levels. The first two are fixed as monitor.elastic. The third level identifies the type of events sent and the fourth the subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Elastic

monitor.elastic.auditbeat.fileintegrity

monitor.elastic.auditbeat.fileintegrity

For more information, read more about Devo tags.

Table structure

These are the fields displayed in this table:

Field

Type

Extra field

Field

Type

Extra field

eventdate

timestamp

 

hostname

str

 

agent__hostname

str

 

agent__name

str

 

agent__id

str

 

agent__ephemeral_id

str

 

agent__type

str

 

agent__version

str

 

APP_NAME

str

 

type

str

 

tags

str

 

at_timestamp

timestamp

 

file__owner

str

 

file__extension

str

 

file__gid

str

 

file__mtime

timestamp

 

file__type

str

 

file__mode

str

 

file__inode

str

 

file__path

str

 

file__uid

str

 

file__size

int4

 

file__ctime

timestamp

 

file__hash__sha1

str

 

file__group

str

 

ecs__version

str

 

service__type

str

 

host__name

str

 

at_version

str

 

SUB_SYSTEM

str

 

event__kind

str

 

event__module

str

 

event__action

str

 

event__category

str

 

event__type

str

 

event__dataset

str

 

hash__sha1

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓