/
mail.darktrace

mail.darktrace

Introduction

The tags beginning with mail.darktrace identify events generated by Darktrace.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as mail.darktrace. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

DarkTrace Email

mail.darktrace.detect_respond.event

mail.darktrace.detect_respond.event

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

machine

str

 

 

 

syslog_event_version

str

 

 

 

syslog_event_time

str

 

 

 

syslog_hostname

str

 

 

 

syslog_process_name

str

 

 

 

syslog_pid

str

 

 

 

syslog_message_id

str

 

 

 

syslog_structured_data

str

 

 

 

uuid

str

 

 

 

direction

str

 

 

 

from

str

 

 

 

subject

str

 

 

 

timestamp

str

 

 

 

anomaly_score

int4

 

 

 

tags

str

join(tags_array, ',')

tags_array

 

recipients

str

join(recipients_array, ',')

recipients_array

 

link_hosts

str

join(link_hosts_array, ',')

link_hosts_array

 

message_id

str

 

 

 

time

timestamp

 

 

 

url

str

 

 

 

hostchain

str

 

 

tag

str

 

 

rawMessage

str

 

 

Related content

ids.darktrace
ids.darktrace
More like this
edr.darktrace
edr.darktrace
More like this
mail.abnormalsecurity
mail.abnormalsecurity
More like this
mail.trellix
mail.trellix
More like this
mail.cisco
mail.cisco
More like this
mail.knowbe4
mail.knowbe4
More like this