ids.extrahop
Introduction
The tags beginning with ids.extrahop
identify events generated by ExtraHop.
Tag structure
The full tag must have three levels. The first two are fixed as ids.extrahop
. The third level identifies the type of event sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
ExtraHop solution |
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
For more information, read more about Devo tags.
How is the data sent to Devo?
You can send the logs generated by ExtraHop using the tool NXLog. Learn more about how to configure your product and start forwarding logs to Devo here.
Table structure
These are the fields displayed in these tables: