box.audit
Introduction
The tags beginning with box.audit
identify events generated by go-audit Linux auditing.
Valid tags and data tables
The full tag must have at least 3 levels. The first two are fixed as box.audit
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
UNIX audit |
|
Union table This is a union table that collects events from a set of tables for easy access and analysis. Learn more about this union table in this article. |
|
| |
|
| |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
box.audit.uni.audispd
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
machine |
| vmachine |
|
node |
|
|
|
type |
|
|
|
audit_timestamp |
|
|
|
audit_id |
|
|
|
pid |
|
|
|
uid |
|
|
|
gid |
|
|
|
auid |
|
|
|
ses |
|
|
|
old_auid |
|
|
|
old_ses |
|
|
|
op |
|
|
|
opType |
|
|
|
acct |
|
|
|
id |
|
|
|
exe |
|
|
|
hostname |
|
|
|
addr |
|
|
|
terminal |
|
|
|
res |
|
|
|
comm |
|
|
|
reason |
|
|
|
sig |
|
|
|
dev |
|
|
|
prom |
|
|
|
old_prom |
|
|
|
fver |
|
|
|
fp |
|
|
|
fi |
|
|
|
fe |
|
|
|
old_pp |
|
|
|
old_pi |
|
|
|
old_pe |
|
|
|
old_pa |
|
|
|
pp |
|
|
|
pi |
|
|
|
pe |
|
|
|
pa |
|
|
|
grantors |
|
|
|
kind |
|
|
|
direction |
|
|
|
spid |
|
|
|
suid |
|
|
|
cipher |
|
|
|
ksize |
|
|
|
mac |
|
|
|
pfs |
|
|
|
rport |
|
|
|
laddr |
|
|
|
lport |
|
|
|
cwd |
|
|
|
argc |
|
|
|
a0 |
|
|
|
a1 |
|
|
|
a2 |
|
|
|
a3 |
|
|
|
tty |
|
|
|
table |
|
|
|
family |
|
|
|
entries |
|
|
|
item |
|
|
|
name |
|
|
|
inode |
|
|
|
mode |
|
|
|
ouid |
|
|
|
ogid |
|
|
|
rdev |
|
|
|
objtype |
|
|
|
cap_fp |
|
|
|
cap_fi |
|
|
|
cap_fe |
|
|
|
cap_fver |
|
|
|
proctitle |
|
|
|
arch |
|
|
|
syscall |
|
|
|
compat |
|
|
|
ip |
|
|
|
code |
|
|
|
unit |
|
|
|
saddr |
|
|
|
sw |
|
|
|
sw_type |
|
|
|
key_enforce |
|
|
|
gpg_res |
|
|
|
root_dir |
|
|
|
success |
|
|
|
exit |
|
|
|
items |
|
|
|
ppid |
|
|
|
euid |
|
|
|
fsuid |
|
|
|
egid |
|
|
|
sgid |
|
|
|
fsgid |
|
|
|
key |
|
|
|
new_level |
|
|
|
old_level |
|
|
|
cmd |
|
|
|
user |
|
|
|
ctr_id_short |
|
|
|
vm_pid |
|
|
|
vm |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |
box.audit.unix.auditd
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
machine |
|
| vmachine |
|
type |
|
|
|
|
msg_audit |
|
|
|
|
msg_audit_timestamp |
|
|
|
|
msg_audit_id |
|
|
|
|
pid |
|
|
|
|
ppid |
|
|
|
|
uid |
|
|
|
|
gid |
|
|
|
|
gid_2 |
|
|
|
|
auid |
|
|
|
|
auid_2 |
|
|
|
|
tty |
|
|
|
|
old_ses |
|
|
|
|
ses |
|
|
|
|
grantors |
|
|
|
|
comm |
|
|
|
|
reason |
|
|
|
|
sig |
|
|
|
|
dev |
|
|
|
|
prom |
|
|
|
|
old_prom |
|
|
|
|
audit_backlog_limit |
|
|
|
|
audit_backlog_wait_time |
|
|
|
|
audit_failure |
|
|
|
|
old |
|
|
|
|
key |
|
|
|
|
list |
|
|
|
|
old_auid |
|
|
|
|
old_auid_2 |
|
|
|
|
cwd |
|
|
|
|
subj |
|
|
|
|
ver |
|
|
|
|
format |
|
|
|
|
kernel |
|
|
|
|
uid_2 |
|
|
|
|
table |
|
|
|
|
family |
|
|
|
|
entries |
|
|
|
|
item |
|
|
|
|
name |
|
|
|
|
nametype |
|
|
|
|
inode |
|
|
|
|
mode |
|
|
|
|
ouid |
|
|
|
|
ouid_2 |
|
|
|
|
ogid |
|
|
|
|
ogid_2 |
|
|
|
|
saddr |
|
|
|
|
saddr_2 |
|
|
|
|
sauid_2 |
|
|
|
|
lsm |
|
|
|
|
rdev |
|
|
|
|
objtype |
|
|
|
|
cap_fp |
|
|
|
|
cap_fi |
|
|
|
|
cap_fe |
|
|
|
|
cap_fver |
|
|
|
|
cap_frootid |
|
|
|
|
proctitle |
|
|
|
|
a0 |
|
|
|
|
a1 |
|
|
|
|
a2 |
|
|
|
|
a3 |
|
|
|
|
a4 |
|
|
|
|
a5 |
|
|
|
|
a6 |
|
|
|
|
a7 |
|
|
|
|
a8 |
|
|
|
|
a9 |
|
|
|
|
a10 |
|
|
|
|
arch |
|
|
|
|
arch_2 |
|
|
|
|
argc |
|
|
|
|
syscall |
|
|
|
|
syscall_2 |
|
|
|
|
success |
|
|
|
|
exit |
|
|
|
|
items |
|
|
|
|
euid |
|
|
|
|
euid_2 |
|
|
|
|
fsuid |
|
|
|
|
fsuid_2 |
|
|
|
|
egid |
|
|
|
|
egid_2 |
|
|
|
|
sgid |
|
|
|
|
sgid_2 |
|
|
|
|
fsgid |
|
|
|
|
fsgid_2 |
|
|
|
|
res |
|
|
|
|
state |
|
|
|
|
exe |
|
|
|
|
op |
|
|
|
|
op_type |
|
|
|
|
msg |
|
|
|
|
msg_old_level |
|
|
|
|
msg_new_level |
|
|
|
|
msg_op |
|
|
|
|
msg_acct |
|
|
|
|
msg_exe |
|
|
|
|
msg_hostname |
|
|
|
|
msg_addr |
|
|
|
|
msg_terminal |
|
|
|
|
msg_res |
|
|
|
|
msg_kind |
|
|
|
|
msg_fp |
|
|
|
|
msg_direction |
|
|
|
|
msg_spid |
|
|
|
|
msg_suid |
|
|
|
|
msg_comm |
|
|
|
|
msg_rport |
|
|
|
|
msg_laddr |
|
|
|
|
msg_lport |
|
|
|
|
msg_cipher |
|
|
|
|
msg_ksize |
|
|
|
|
msg_mac |
|
|
|
|
msg_pfs |
|
|
|
|
msg_id |
|
|
|
|
msg_id_2 |
|
|
|
|
msg_auid |
|
|
|
|
msg_unit |
|
|
|
|
msg_sw |
|
|
|
|
msg_sw_type |
|
|
|
|
msg_key_enforce |
|
|
|
|
msg_gpg_res |
|
|
|
|
msg_root_dir |
|
|
|
|
msg_size |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
message |
|
| rawMessage | ✓ |
rawMessage |
|
|
| ✓ |
box.audit.unix.goAudit
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
|
|
|
machine |
| vmachine |
|
sequence |
|
|
|
timestamp |
|
|
|
messages |
|
|
|
uid_map |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
rawMessage |
|
| ✓ |