auth.secureauth
Introduction
The tags beginning with auth.secureauth
identify events generated by the SecureAuth authentication platform.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as auth.secureauth
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
SecureAuth identity platform
|
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
auth.secureauth.events
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
hostname |
| split(hostchain, "=", 0) | hostchain |
|
cefVersion |
|
|
|
|
embDeviceVendor |
|
|
|
|
embDeviceProduct |
|
|
|
|
deviceVersion |
|
|
|
|
signatureID |
|
|
|
|
name |
|
|
|
|
severity |
|
|
|
|
cat |
|
|
|
|
ipRiskScore |
|
|
|
|
priority |
|
|
|
|
browserSession |
|
|
|
|
analyzeEngineResult |
|
|
|
|
companyName |
|
|
|
|
requestID |
|
|
|
|
requestDuration |
|
|
|
|
userCountryCode |
|
|
|
|
deviceUTCTime |
|
|
|
|
dst |
|
|
|
|
dvc |
|
|
|
|
deviceFacility |
|
|
|
|
msg |
|
|
|
|
outcome |
|
|
|
|
requestClientApplication |
|
|
|
|
sourceServiceName |
|
|
|
|
spid |
|
|
|
|
src |
|
|
|
|
suser |
|
|
|
|
secureAuthIdPAppliance |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |
auth.secureauth.radius
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
timestamp |
|
|
server |
|
|
product |
|
|
logtype |
|
|
process |
|
|
transctionId |
|
|
eventMessage |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |