monitor.lacework
[ Introduction ] [ Valid tags and data tables ] [ Table structure ]
Introduction
The tags beginning with monitor.lacework
identify events generated by Lacework.
Valid tags and data tablesÂ
The full tag must have at least three levels. The first two are fixed as monitor.lacework
. The third level identifies the type of events sent and the fourth the subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Lacework |
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables:
monitor.lacework.agent.applications
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
app_name |
| Â |
container_info__vm_type |
| Â |
end_time |
| Â |
exe_path |
| Â |
mid |
| Â |
net_stats__num_bytes_external_client |
| Â |
net_stats__num_bytes_external_server |
| Â |
net_stats__num_bytes_in_external_client |
| Â |
net_stats__num_bytes_in_external_server |
| Â |
net_stats__num_bytes_in_internal_client |
| Â |
net_stats__num_bytes_in_internal_server |
| Â |
net_stats__num_bytes_internal_client |
| Â |
net_stats__num_bytes_internal_server |
| Â |
net_stats__num_bytes_out_internal_client |
| Â |
net_stats__num_bytes_out_internal_server |
| Â |
net_stats__num_in_bytes |
| Â |
net_stats__num_in_client_bytes |
| Â |
net_stats__num_in_server_bytes |
| Â |
net_stats__num_out_bytes |
| Â |
net_stats__num_out_client_bytes |
| Â |
net_stats__num_out_server_bytes |
| Â |
net_stats__num_total_bytes |
| Â |
props_machine__hostname |
| Â |
props_machine__ip_addr |
| Â |
props_machine__mem_kbytes |
| Â |
props_machine__num_users |
| Â |
props_machine__tags__account |
| Â |
props_machine__tags__ami_id |
| Â |
props_machine__tags__external_ip |
| Â |
props_machine__tags__hostname |
| Â |
props_machine__tags__instance_id |
| Â |
props_machine__tags__internal_ip |
| Â |
props_machine__tags__lw_token_short |
| Â |
props_machine__tags__subnet_id |
| Â |
props_machine__tags__vm_instance_type |
| Â |
props_machine__tags__vm_provider |
| Â |
props_machine__tags__vpc_id |
| Â |
props_machine__tags__zone |
| Â |
props_machine__tags__arch |
| Â |
props_machine__tags__os |
| Â |
props_machine__up_time |
| Â |
start_time |
| Â |
username__effective |
| Â |
username__original |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.connnections
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
dst_entity_id__mid |
| Â |
dst_entity_id__port |
| Â |
dst_entity_id__protocol |
| Â |
dst_entity_id__ip_addr |
| Â |
dst_entity_id__ip_internal |
| Â |
dst_entity_id__hostname |
| Â |
dst_entity_type |
| Â |
dst_in_bytes |
| Â |
dst_out_bytes |
| Â |
endpoint_details |
| Â |
end_time |
| Â |
num_conns |
| Â |
src_entity_id__ip_addr |
| Â |
src_entity_id__ip_internal |
| Â |
src_entity_id__mid |
| Â |
src_entity_id__pid_hash |
| Â |
src_entity_type |
| Â |
src_in_bytes |
| Â |
src_out_bytes |
| Â |
start_time |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.dns_query
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
created_time |
| Â |
dns_server_ip |
| Â |
fqdn |
| Â |
host_ip_addr |
| Â |
mid |
| Â |
ttl |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.interfaces
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
created_time |
| Â |
hw_addr |
| Â |
ip_addr |
| Â |
mid |
| Â |
name |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.machine_summary
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
end_time |
| Â |
entity_type |
| Â |
hostname2 |
| Â |
machine_tags__account |
| Â |
machine_tags__ami_id |
| Â |
machine_tags__external_ip |
| Â |
machine_tags__hostname |
| Â |
machine_tags__instance_id |
| Â |
machine_tags__internal_ip |
| Â |
machine_tags__lw_token_short |
| Â |
machine_tags__subnet_id |
| Â |
machine_tags__vm_instance_type |
| Â |
machine_tags__vm_provider |
| Â |
machine_tags__vpc_id |
| Â |
machine_tags__zone |
| Â |
machine_tags__arch |
| Â |
machine_tags__os |
| Â |
mid |
| Â |
primary_ip_addr |
| Â |
start_time |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.new_hashes
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
end_time |
| Â |
filedata_hash |
| Â |
start_time |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.package
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
arch |
| Â |
created_time |
| Â |
mid |
| Â |
package_name |
| Â |
version |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.agent.process_summary
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
cmdline_hash |
| Â |
end_time |
| Â |
file_path |
| Â |
mid |
| Â |
pid |
| Â |
ppid |
| Â |
process_start_time |
| Â |
start_time |
| Â |
uid |
| Â |
username |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.alerts.events
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
event_title |
| Â |
event_link |
| Â |
lacework_account |
| Â |
event_source |
| Â |
event_description |
| Â |
event_timestamp |
| Â |
event_type |
| Â |
event_id |
| Â |
event_severity |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.lacework.alerts
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
subtype |
| Â | vsubtype |
event_title |
| Â | Â |
event_link |
| Â | Â |
lacework_account |
| Â | Â |
event_source |
| Â | Â |
event_description |
| Â | Â |
event_timestamp |
| Â | Â |
event_type |
| Â | Â |
event_id |
| Â | Â |
event_severity |
| Â | Â |
hostchain |
| ✓ |  |
tag |
| ✓ |  |
rawMessage |
| ✓ |  |
monitor.lacework.awscloudtrail.alert_details
Field | Type | Extra field | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
end_time |
| Â | Â | Â |
entity_map_api_key__api_str |
| Â | join(entity_map_api_key__api, ',') | entity_map_api_key__api |
entity_map_api_key__service_str |
| Â | join(entity_map_api_key__service, ',') | entity_map_api_key__service |
entity_map_api_props__all_timestamps_str |
| Â | join(entity_map_api_props__all_timestamps, ',') | entity_map_api_props__all_timestamps |
entity_map_api_props__source_ip_address_list_str |
| Â | entity_map_api_props__source_ip_address_list | |
entity_map_api_props__user_list_str |
| Â | entity_map_api_props__user_list | |
entity_map_ct_raw_time_key__first_time_str |
| Â | entity_map_ct_raw_time_key__first_time | |
entity_map_ct_raw_time_key__last_time_str |
| Â | entity_map_ct_raw_time_key__last_time | |
entity_map_ct_raw_time_props__all_timestamps_str |
| Â | entity_map_ct_raw_time_props__all_timestamps | |
entity_map_ct_user_key__account_str |
| Â | entity_map_ct_user_key__account | |
entity_map_ct_user_key__mfa_str |
| Â | entity_map_ct_user_key__mfa | |
entity_map_ct_user_key__principal_id_str |
| Â | entity_map_ct_user_key__principal_id | |
entity_map_ct_user_key__username_str |
| Â | entity_map_ct_user_key__username | |
entity_map_ct_user_props__all_timestamps_str |
| Â | entity_map_ct_user_props__all_timestamps | |
entity_map_ct_user_props__api_list_str |
| Â | entity_map_ct_user_props__api_list | |
entity_map_ct_user_props__region_list_str |
| Â | entity_map_ct_user_props__region_list | |
entity_map__region_key__region_str |
| Â | entity_map__region_key__region | |
entity_map__region_props__account_list_str |
| Â | entity_map__region_props__account_list | |
entity_map__rules_triggered_key__triggered_rule_id_str |
| Â | entity_map__rules_triggered_key__triggered_rule_id | |
entity_map__rules_triggered_props__rule_description_str |
| Â | entity_map__rules_triggered_props__rule_description | |
entity_map__rules_triggered_props__rule_id_str |
| Â | entity_map__rules_triggered_props__rule_id | |
entity_map__rules_triggered_props__rule_severity_str |
| Â | entity_map__rules_triggered_props__rule_severity | |
entity_map__rules_triggered_props__rule_title_str |
| Â | entity_map__rules_triggered_props__rule_title | |
entity_map__source_ip_address_key__ip_addr_str |
| Â | entity_map__source_ip_address_key__ip_addr | |
entity_map__source_ip_address_props__api_list_str |
| Â | entity_map__source_ip_address_props__api_list | |
entity_map__resource_key__name_str |
| Â | entity_map__resource_key__name | |
entity_map__resource_key__value_str |
| Â | entity_map__resource_key__value | |
event_actor |
| Â | Â | Â |
event_id |
| Â | Â | Â |
event_model |
| Â | Â | Â |
event_type |
| Â | Â | Â |
start_time |
| Â | Â | Â |
hostchain |
| ✓ |  |  |
tag |
| ✓ |  |  |
rawMessage |
| ✓ |  |  |