cef0.anubisnetworks
Introduction
The tags beginning with cef0.anubisnetworks
identify events in CEF format generated by AnubisNetworks.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
Tags | Data tables |
---|---|
|
|
|
|
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in these tables:
cef0.anubisnetworks.cyberfeed
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
selfDomain |
| Â | Â |
cat |
| Â | Â |
trojanFamily |
| cs1 | Â |
geoEnvRemoteAddrASNName |
| cs2 | Â |
geoEnvRemoteAddrCountryName |
| cs3 | Â |
geoEnvRemoteAddrCountryCode |
| cs4 | Â |
geoEnvRemoteAddrRegion |
| cs5 | Â |
geoEnvRemoteAddrCity |
| cs6 | Â |
geoEnvRemoteAddrASNNumber |
| cn1 | Â |
geoEnvRemoteAddrLongitude |
| cn2 | Â |
geoEnvRemoteAddrLatitude |
| cn3 | Â |
dhost |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
end |
| Â | Â |
fsize |
| Â | Â |
msg |
| Â | Â |
proto |
| Â | Â |
requestClientApplication |
| Â | Â |
requestCookies |
| Â | Â |
requestMethod |
| Â | Â |
request |
| Â | Â |
rt |
| Â | Â |
shost |
| Â | Â |
spt |
| Â | Â |
src |
| Â | Â |
suser |
| Â | Â |
antivirus |
| Â | Â |
args |
| Â | Â |
attc |
| Â | Â |
avgsCurIpa |
| Â | Â |
avgsCurIpc |
| Â | Â |
avgsOldIpa |
| Â | Â |
avgsOldIpc |
| Â | Â |
avgsOldSeen |
| Â | Â |
bad |
| Â | Â |
class |
| Â | Â |
dataExtUris |
| Â | Â |
dataHelo |
| Â | Â |
dataHSender |
| Â | Â |
dataMailFrom |
| Â | Â |
dataPTR |
| Â | Â |
dataRemoteSysFlavor |
| Â | Â |
dataRemoteSysLinkType |
| Â | Â |
dataRemoteSysOS |
| Â | Â |
dataSpike |
| Â | Â |
dataUnknownSMTPCmdsCount |
| Â | Â |
dataUris |
| Â | Â |
domains |
| Â | Â |
endDate |
| Â | Â |
flags |
| Â | Â |
good |
| Â | Â |
ham |
| Â | Â |
hits |
| Â | Â |
httpXFF |
| Â | Â |
lnkFrom |
| Â | Â |
lnkFromSig |
| Â | Â |
lnkTo |
| Â | Â |
paction |
| Â | Â |
payload0ResultActive |
| Â | Â |
payload0ResultCtime |
| Â | Â |
payload0ResultDups |
| Â | Â |
payload0ResultH1 |
| Â | Â |
payload0ResultH2 |
| Â | Â |
payload0ResultH3 |
| Â | Â |
payload0ResultH4 |
| Â | Â |
payload0ResultHash |
| Â | Â |
payload0ResultHit |
| Â | Â |
payload0ResultOhash |
| Â | Â |
payload0ResultOsig |
| Â | Â |
payload0ResultReply |
| Â | Â |
payload0ResultSz |
| Â | Â |
payload0ResultWeight |
| Â | Â |
payload0ResultWords |
| Â | Â |
payload14Data |
| Â | Â |
payload15ResultPatternsHits |
| Â | Â |
payload16ResultUris |
| Â | Â |
payload4Data |
| Â | Â |
payload4ResultHit |
| Â | Â |
payload4ResultReply |
| Â | Â |
payloadFullurisData |
| Â | Â |
payloadHashdb2ResultReply |
| Â | Â |
payloadHashdb2Txtdata |
| Â | Â |
payloadHashdbResultReply |
| Â | Â |
payloadHashdbTxtdata |
| Â | Â |
payloadMailsigsResultReply |
| Â | Â |
payloadMailsigsTextdata |
| Â | Â |
payloadMsnwData |
| Â | Â |
payloadTawlData |
| Â | Â |
payloadTemplatesData |
| Â | Â |
payloadTemplatesResultReply |
| Â | Â |
payloadUriblData |
| Â | Â |
permalink |
| Â | Â |
points |
| Â | Â |
qtype |
| Â | Â |
reqid |
| Â | Â |
sd |
| Â | Â |
signatures |
| Â | Â |
snort |
| Â | Â |
spam |
| Â | Â |
tags |
| Â | Â |
targetCategory |
| Â | Â |
targetMd5 |
| Â | Â |
targetSha1 |
| Â | Â |
targetSha256 |
| Â | Â |
targetType |
| Â | Â |
thits |
| Â | Â |
tmpl |
| Â | Â |
urisdata |
| Â | Â |
yara |
| Â | Â |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
hostchain |
|  | ✓ |
cef0.anubisnetworks.cyberfeedRealTimeThreatIntelligence
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
selfDomain |
| Â | Â |
cat |
| Â | Â |
trojanFamily |
| cs1 | Â |
geoEnvRemoteAddrASNName |
| cs2 | Â |
geoEnvRemoteAddrCountryName |
| cs3 | Â |
geoEnvRemoteAddrCountryCode |
| cs4 | Â |
geoEnvRemoteAddrRegion |
| cs5 | Â |
geoEnvRemoteAddrCity |
| cs6 | Â |
geoEnvRemoteAddrASNNumber |
| cn1 | Â |
geoEnvRemoteAddrLongitude |
| cn2 | Â |
geoEnvRemoteAddrLatitude |
| cn3 | Â |
dhost |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
end |
| Â | Â |
fsize |
| Â | Â |
msg |
| Â | Â |
proto |
| Â | Â |
requestClientApplication |
| Â | Â |
requestCookies |
| Â | Â |
requestMethod |
| Â | Â |
request |
| Â | Â |
rt |
| Â | Â |
shost |
| Â | Â |
spt |
| Â | Â |
src |
| Â | Â |
suser |
| Â | Â |
antivirus |
| Â | Â |
args |
| Â | Â |
attc |
| Â | Â |
avgsCurIpa |
| Â | Â |
avgsCurIpc |
| Â | Â |
avgsOldIpa |
| Â | Â |
avgsOldIpc |
| Â | Â |
avgsOldSeen |
| Â | Â |
bad |
| Â | Â |
class |
| Â | Â |
dataExtUris |
| Â | Â |
dataHelo |
| Â | Â |
dataHSender |
| Â | Â |
dataMailFrom |
| Â | Â |
dataPTR |
| Â | Â |
dataRemoteSysFlavor |
| Â | Â |
dataRemoteSysLinkType |
| Â | Â |
dataRemoteSysOS |
| Â | Â |
dataSpike |
| Â | Â |
dataUnknownSMTPCmdsCount |
| Â | Â |
dataUris |
| Â | Â |
domains |
| Â | Â |
endDate |
| Â | Â |
flags |
| Â | Â |
good |
| Â | Â |
ham |
| Â | Â |
hits |
| Â | Â |
httpXFF |
| Â | Â |
lnkFrom |
| Â | Â |
lnkFromSig |
| Â | Â |
lnkTo |
| Â | Â |
paction |
| Â | Â |
payload0ResultActive |
| Â | Â |
payload0ResultCtime |
| Â | Â |
payload0ResultDups |
| Â | Â |
payload0ResultH1 |
| Â | Â |
payload0ResultH2 |
| Â | Â |
payload0ResultH3 |
| Â | Â |
payload0ResultH4 |
| Â | Â |
payload0ResultHash |
| Â | Â |
payload0ResultHit |
| Â | Â |
payload0ResultOhash |
| Â | Â |
payload0ResultOsig |
| Â | Â |
payload0ResultReply |
| Â | Â |
payload0ResultSz |
| Â | Â |
payload0ResultWeight |
| Â | Â |
payload0ResultWords |
| Â | Â |
payload14Data |
| Â | Â |
payload15ResultPatternsHits |
| Â | Â |
payload16ResultUris |
| Â | Â |
payload4Data |
| Â | Â |
payload4ResultHit |
| Â | Â |
payload4ResultReply |
| Â | Â |
payloadFullurisData |
| Â | Â |
payloadHashdb2ResultReply |
| Â | Â |
payloadHashdb2Txtdata |
| Â | Â |
payloadHashdbResultReply |
| Â | Â |
payloadHashdbTxtdata |
| Â | Â |
payloadMailsigsResultReply |
| Â | Â |
payloadMailsigsTextdata |
| Â | Â |
payloadMsnwData |
| Â | Â |
payloadTawlData |
| Â | Â |
payloadTemplatesData |
| Â | Â |
payloadTemplatesResultReply |
| Â | Â |
payloadUriblData |
| Â | Â |
permalink |
| Â | Â |
points |
| Â | Â |
qtype |
| Â | Â |
reqid |
| Â | Â |
sd |
| Â | Â |
signatures |
| Â | Â |
snort |
| Â | Â |
spam |
| Â | Â |
tags |
| Â | Â |
targetCategory |
| Â | Â |
targetMd5 |
| Â | Â |
targetSha1 |
| Â | Â |
targetSha256 |
| Â | Â |
targetType |
| Â | Â |
thits |
| Â | Â |
tmpl |
| Â | Â |
urisdata |
| Â | Â |
yara |
| Â | Â |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
hostchain |
|  | ✓ |