Document toolboxDocument toolbox

endpoint.airlock

Introduction

The tags beginning with endpoint.airlock identify events generated by Airlock Digital.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as endpoint.airlock. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Airlock Digital

endpoint.airlock.allowlist.audit

endpoint.airlock.allowlist.audit

For more information, read more About Devo tags.

How is the data sent to Devo?

Logs generated by Airlock Digital are forwarded to Devo using a dedicated collector. Read this article to learn more about

Table structure

These are the fields displayed in this table:

endpoint.airlock.allowlist.audit

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

machine

str

 

checkpoint

str

 

type

int4

 

username

str

 

hostname

str

 

netdomain

str

 

file_name

str

 

ppolicy

str

 

policyname

str

 

policyver

str

 

commandline

str

 

publisher

str

 

pprocess

str

 

sha256

str

 

datetime

timestamp

 

md5

str

 

sha128

str

 

sha384

str

 

sha512

str

 

at_devo_pulling_id

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓