endpoint.carbonblack
Introduction
The tags beginning with endpoint.carbonblack
identify events generated by VMware Carbon Black.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as endpoint.carbonblack
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Carbon Black Protection |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
endpoint.carbonblack.protection
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
hostname |
|
|
|
|
leefVer |
|
|
|
|
vendor |
|
|
|
|
product |
|
|
|
|
version |
|
|
|
|
eventID |
|
|
|
|
cat |
|
|
|
|
sev |
|
|
|
|
devTime |
|
parsedate(devTime_tmp, dateformat("MMM DD YYYY HH:mm:ss.SSS [UTC]", "UTC", "en-US"))
| devTime_tmp |
|
msg |
|
|
|
|
externalId |
|
|
|
|
src |
|
|
|
|
srcHostName |
|
|
|
|
policy |
|
|
|
|
dstHostName |
|
|
|
|
receivedTime |
|
parsedate(receivedTime_tmp, dateformat("MMM DD YYYY HH:mm:ss.SSS [UTC]", "UTC", "en-US"))
| receivedTime_tmp |
|
srcProcess |
|
|
|
|
usrName |
|
|
|
|
filePath |
|
|
|
|
fileName |
|
|
|
|
fileHash |
|
|
|
|
fileId |
|
|
|
|
rootHash |
|
|
|
|
installerFileName |
|
|
|
|
ruleName |
|
|
|
|
processKey |
|
|
|
|
fileTrust |
|
|
|
|
fileThreat |
|
|
|
|
processTrust |
|
|
|
|
processThreat |
|
|
|
|
prevalence |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |