Document toolboxDocument toolbox

sse.forcepoint

Introduction

The tags beginning with sse.forcepoint identify events generated by Forcepoint.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as sse.forcepoint. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Forcepoint

sse.forcepoint.access.event

sse.forcepoint.access.event

sse.forcepoint.admin.event

sse.forcepoint.admin.event

sse.forcepoint.healthproxy.event

sse.forcepoint.healthproxy.event

sse.forcepoint.swgweb.event

sse.forcepoint.swgweb.event

For more information, read more About Devo tags.

How is the data sent to Devo?

To send logs to these tables, Devo provides a collector that you can download and use to send the required events to your Devo domain. You can learn how to use it in this article.

Table structure

These are the fields displayed in these tables:

sse.forcepoint.access.event

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

machine

str

 

syslogheader

str

 

time

str

 

user

str

 

email

str

 

device

str

 

application

str

 

ipaddress

str

 

ipaddress_ipv4

ip4

 

ipaddress_ipv6

ip6

 

destination_location

str

 

activity

str

 

action

str

 

user_agent

str

 

request

str

 

transactionid

str

 

email_from

str

 

email_to

str

 

email_subject

str

 

email_cc

str

 

email_bcc

str

 

email_sent_time

str

 

file_name

str

 

dlp_pattern

str

 

page_title

str

 

url

str

 

details

str

 

org_id

str

 

instance_name

str

 

user_group

str

 

device_guid

str

 

policy_id

str

 

at_devo_pulling_id

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

sse.forcepoint.admin.event

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

machine

str

 

syslogheader

str

 

time

str

 

user

str

 

email

str

 

device

str

 

application

str

 

ipaddress

str

 

ipaddress_ipv4

ip4

 

ipaddress_ipv6

ip6

 

destination_location

str

 

activity

str

 

action

str

 

user_agent

str

 

request

str

 

transactionid

str

 

email_from

str

 

email_to

str

 

email_subject

str

 

email_cc

str

 

email_bcc

str

 

email_sent_time

str

 

file_name

str

 

dlp_pattern

str

 

page_title

str

 

url

str

 

details

str

 

at_devo_pulling_id

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

sse.forcepoint.healthproxy.event

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

machine

str

 

syslogheader

str

 

time

str

 

user

str

 

email

str

 

user_group

str

 

device

str

 

application

str

 

activity

str

 

url

str

 

response_code

int4

 

transactionid

str

 

device_guid

str

 

ipaddress

str

 

ipaddress_ipv4

ip4

 

ipaddress_ipv6

ip6

 

destination_location

str

 

request_method

str

 

user_agent

str

 

at_devo_pulling_id

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

sse.forcepoint.swgweb.event

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

machine

str

 

syslogheader

str

 

protocol

str

 

custom_location

str

 

request_port

str

 

request_method

str

 

user_group

str

 

bg_categories

str

 

size

str

 

city

str

 

device_guid

str

 

destination_ip

str

 

destination_ipv4

ip4

 

destination_ipv6

ip6

 

ipaddress

str

 

ipaddress_ipv4

ip4

 

ipaddress_ipv6

ip6

 

web_reputation

str

 

long

str

 

application

str

 

request_domain

str

 

setransactionid

str

 

arguments

str

 

indexed_time

timestamp

 

email

str

 

bg_cloud_score

str

 

firstname

str

 

lastname

str

 

device_hostname

str

 

region_code

str

 

policy_id

str

 

latitude

str

 

uploaded_bytes

str

 

web_categories

str

 

countrycode

str

 

referrer

str

 

url

str

 

country

str

 

region

str

 

uri

str

 

custom_categories

str

 

time

str

 

action

str

 

user_agent

str

 

web_category_class

str

 

at_devo_pulling_id

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓