sase.cato
Introduction
The tags begin with sase.cato
identify events generated by Cato Networks.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as sase.cato
. The third level indicates the product.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Cato Networks |
|
|
| ||
| ||
| ||
| ||
| ||
| ||
|
| |
| ||
| ||
| ||
| ||
| ||
| ||
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
sase.cato.security
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
machine |
|
|
|
subtype |
| vsubtype |
|
isp_name |
|
|
|
account_id |
|
|
|
action |
|
|
|
app_stack |
|
|
|
application |
|
|
|
categories |
|
|
|
destination_ip |
|
|
|
destination_ipv4 |
|
|
|
destination_ipv6 |
|
|
|
dest_is_site_or_vpn |
|
|
|
destination_port |
|
|
|
dest_site |
|
|
|
dest_site_name |
|
|
|
dest_user_id |
|
|
|
event_count |
|
|
|
event_sub_type |
|
|
|
event_type |
|
|
|
internal_id |
|
|
|
ip_protocol |
|
|
|
os_type |
|
|
|
pop_name |
|
|
|
rule |
|
|
|
rule_id |
|
|
|
rule_name |
|
|
|
source_geo_country_name |
|
|
|
src_country_code |
|
|
|
source_ip |
|
|
|
source_ipv4 |
|
|
|
source_ipv6 |
|
|
|
src_is_site_or_vpn |
|
|
|
src_isp_ip |
|
|
|
src_isp_ipv4 |
|
|
|
src_isp_ipv6 |
|
|
|
src_site |
|
|
|
src_site_name |
|
|
|
subnet_name |
|
|
|
time |
|
|
|
time_str |
|
|
|
user_id |
|
|
|
destination_geo_country_name |
|
|
|
dest_country_code |
|
|
|
device_name |
|
|
|
domain_name |
|
|
|
http_host_name |
|
|
|
cato_app |
|
|
|
full_path_url |
|
|
|
http_request_method |
|
|
|
mitre_attack_subtechniques |
|
|
|
mitre_attack_tactics |
|
|
|
mitre_attack_techniques |
|
|
|
risk_level |
|
|
|
signature_id |
|
|
|
source_port |
|
|
|
threat_name |
|
|
|
threat_reference |
|
|
|
threat_type |
|
|
|
traffic_direction |
|
|
|
xff |
|
|
|
ad_name |
|
|
|
tls_error_description |
|
|
|
tls_error_type |
|
|
|
tls_version |
|
|
|
vpn_user_email |
|
|
|
configured_host_name |
|
|
|
dns_protection_category |
|
|
|
dns_query |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
sase.cato.connectivity
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
machine |
|
|
|
subtype |
| vsubtype |
|
account_id |
|
|
|
device_name |
|
|
|
event_count |
|
|
|
event_message |
|
|
|
event_sub_type |
|
|
|
event_type |
|
|
|
host_ip |
|
|
|
host_ipv4 |
|
|
|
host_ipv6 |
|
|
|
host_mac |
|
|
|
internal_id |
|
|
|
pop_name |
|
|
|
socket_interface |
|
|
|
src_is_site_or_vpn |
|
|
|
src_site |
|
|
|
src_site_name |
|
|
|
subnet_name |
|
|
|
time |
|
|
|
time_str |
|
|
|
action |
|
|
|
ad_name |
|
|
|
always_on_configuration |
|
|
|
auth_method |
|
|
|
client_version |
|
|
|
confidence_level |
|
|
|
connect_on_boot |
|
|
|
destination_ip |
|
|
|
destination_ipv4 |
|
|
|
destination_ipv6 |
|
|
|
device_certificate |
|
|
|
device_posture_profile |
|
|
|
network_access |
|
|
|
office_mode |
|
|
|
os_type |
|
|
|
os_version |
|
|
|
pac_file |
|
|
|
rule |
|
|
|
rule_id |
|
|
|
rule_name |
|
|
|
split_tunnel_configuration |
|
|
|
source_geo_country_name |
|
|
|
src_country_code |
|
|
|
source_ip |
|
|
|
source_ipv4 |
|
|
|
source_ipv6 |
|
|
|
trusted_networks |
|
|
|
tunnel_ip_protocol |
|
|
|
user_id |
|
|
|
visible_device_id |
|
|
|
vpn_lan_access |
|
|
|
vpn_user_email |
|
|
|
isp_name |
|
|
|
client_cert_expires |
|
|
|
client_cert_name |
|
|
|
link_type |
|
|
|
src_isp_ip |
|
|
|
src_isp_ipv4 |
|
|
|
src_isp_ipv6 |
|
|
|
tunnel_protocol |
|
|
|
api_name |
|
|
|
api_type |
|
|
|
authentication_type |
|
|
|
key_name |
|
|
|
login_type |
|
|
|
username |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |