cef0.varonisInc
Introduction
The tables beginning with cef0.zscaler
identify events in CEF format generated by Varonis products.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
cef0.zscaler.nssweblog
cef0.zscaler.nssfwlog
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
cef0.zscaler.nssfwlog
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
hostname |
|
|
|
priorityCode |
|
|
|
cefTag |
|
|
|
cefVersion |
|
|
|
embDeviceVendor |
|
|
|
embDeviceProduct |
|
|
|
deviceVersion |
|
|
|
signatureID |
|
|
|
name |
|
|
|
severity |
|
|
|
_cefVer |
|
|
|
act |
|
|
|
app |
|
|
|
cat |
|
|
|
cn1 |
|
|
|
cn2 |
|
|
|
cn3 |
|
|
|
cs1 |
|
|
|
cs2 |
|
|
|
cs3Label |
|
|
|
cs3 |
|
|
|
cs4 |
|
|
|
destinationServiceName |
|
|
|
destinationTranslatedAddress |
|
|
|
dst |
|
|
|
dpt |
|
|
|
in |
|
|
|
out |
|
|
|
proto |
|
|
|
sourceTranslatedAddress |
|
|
|
spriv |
|
|
|
src |
|
|
|
spt |
|
|
|
suser |
|
|
|
hostchain |
|
| ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|
|
|
cef0.zscaler.nssweblog
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
hostname |
|
|
|
priorityCode |
|
|
|
cefTag |
|
|
|
cefVersion |
|
|
|
embDeviceVendor |
|
|
|
embDeviceProduct |
|
|
|
deviceVersion |
|
|
|
signatureID |
|
|
|
name |
|
|
|
severity |
|
|
|
_cefVer |
|
|
|
act |
|
|
|
app |
|
|
|
cat |
|
|
|
cn1Label |
|
|
|
cn1 |
|
|
|
cs1Label |
|
|
|
cs1 |
|
|
|
cs2Label |
|
|
|
cs2 |
|
|
|
cs3Label |
|
|
|
cs3 |
|
|
|
cs4Label |
|
|
|
cs4 |
|
|
|
cs5Label |
|
|
|
cs5 |
|
|
|
cs6Label |
|
|
|
cs6 |
|
|
|
destinationServiceName |
|
|
|
dhost |
|
|
|
dst |
|
|
|
externalId |
|
|
|
fileType |
|
|
|
in |
|
|
|
outcome |
|
|
|
out |
|
|
|
reason |
|
|
|
requestClientApplication |
|
|
|
requestMethod |
|
|
|
request |
|
|
|
rt |
|
|
|
sourceTranslatedAddress |
|
|
|
spriv |
|
|
|
src |
|
|
|
spt |
|
|
|
suser |
|
|
|
ZscalerNSSWeblogDLPDictionaries |
|
|
|
ZscalerNSSWeblogURLClass |
|
|
|
requestContext |
|
|
|
hostchain |
|
| ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|
|
|