vuln.beyondtrust
Introduction
The tags beginning with vuln.beyondtrust
identify events generated by BeyondTrust vulnerability management.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as vuln.beyondtrust
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Beyond Trust vulnerability management |
|
|
| ||
|
| |
| ||
|
|
For more information, read more About Devo tags.
How is data sent to Devo?
In BeyondTrust solutions, you can set up a connector that enables syslog event forwarding. The events should be directed to a Devo relay where a relay rule applies the correct tag, then forwards the events securely to your Devo domain.
For information about setting up syslog event forwarding, see the BeyondInsight and Password Safe Third-Party Integration Guide.
Set up the Devo relay rule
You will need to set up just one rule that can correctly identify the event type and apply the correct Devo tag. These will be type-4 rules that apply a dynamic tag based upon specific data contained in the inbound event.
In this example we're using port 13007, but you should use the port on your relay that you specified when you set up the remote syslog server in BeyondTrust.
Source port →
13007
Source data →Â
Agent ID: ([^ ]+)
Target tag →Â
vuln.beyondtrust.\\D1
Select the Stop processing checkbox
Click Add rule.
Within a few minutes, the new tables should appear in your Finder.
Table structure
These are the fields displayed in these tables:
vuln.beyondtrust.applaudit
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
host |
| Â | Â | Â |
agent_desc |
| Â | Â | Â |
agent_id |
| Â | Â | Â |
agent_ver |
| Â | Â | Â |
category |
| Â | Â | Â |
source_host |
| Â | Â | Â |
event_desc |
| Â | Â | Â |
event_name |
| Â | Â | Â |
os |
| Â | Â | Â |
event_severity |
| Â | Â | Â |
source_ip |
| Â | Â | Â |
event_subject |
| Â | Â | Â |
event_type |
| Â | Â | Â |
user |
| Â | Â | Â |
workgroup_desc |
| Â | Â | Â |
workgroup_id |
| Â | Â | Â |
workgroup_location |
| Â | Â | Â |
audit_id |
| Â | Â | Â |
action_type |
| Â | Â | Â |
system_name |
| Â | Â | Â |
app_user_id |
| Â | Â | Â |
create_date |
| parsedate(mycreatedate, "M/DD/YYYY h:mm:ss A") Â | mycreatedate | Â |
ip_address |
| Â | Â | Â |
user_name2 |
| Â | Â | Â |
groupp |
| Â | Â | Â |
auth_type |
| Â | Â | Â |
domain_name |
| Â | Â | Â |
sam_account_name |
| Â | Â | Â |
source |
| Â | Â | Â |
message |
| Â | Â | Â |
address_group_name |
| Â | Â | Â |
id |
| Â | Â | Â |
smart_rule_name |
| Â | Â | Â |
report_name |
| Â | Â | Â |
asset_name |
| Â | Â | Â |
unknown |
| Â | Â | Â |
rawMessage |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
vuln.beyondtrust.pbps
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
host |
| split(hostchain, "=", 0) Â | hostchain | Â |
agent_desc |
| Â | Â | Â |
agent_id |
| Â | Â | Â |
agent_ver |
| Â | Â | Â |
category |
| Â | Â | Â |
source_host |
| Â | Â | Â |
event_desc |
| Â | Â | Â |
event_name |
| Â | Â | Â |
os |
| Â | Â | Â |
event_severity |
| Â | Â | Â |
source_ip |
| Â | Â | Â |
event_subject |
| Â | Â | Â |
event_type |
| Â | Â | Â |
user |
| Â | Â | Â |
workgroup_desc |
| Â | Â | Â |
workgroup_id |
| Â | Â | Â |
workgroup_location |
| Â | Â | Â |
log_system_id |
| Â | Â | Â |
log_time |
| Â | Â | Â |
user_name |
| Â | Â | Â |
role_used |
| Â | Â | Â |
object_type_id |
| parsedate(mycreatedate, "M/DD/YYYY h:mm:ss A") Â | mycreatedate | Â |
object_type |
| Â | Â | Â |
object_id |
| Â | Â | Â |
operation |
| Â | Â | Â |
failed |
| Â | Â | Â |
target |
| Â | Â | Â |
details |
| Â | Â | Â |
user_id |
| Â | Â | Â |
time_stamp |
| Â | Â | Â |
ip_address |
| Â | Â | Â |
unknown |
| Â | Â | Â |
rawMessage |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
vuln.beyondtrust.retina
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
host |
| Â | hostchain | Â |
agent_desc |
| Â | Â | Â |
agent_id |
| Â | Â | Â |
agent_ver |
| Â | Â | Â |
category |
| Â | Â | Â |
source_host |
| Â | Â | Â |
event_desc |
| Â | Â | Â |
event_name |
| Â | Â | Â |
os |
| Â | Â | Â |
event_severity |
| Â | Â | Â |
source_ip |
| Â | Â | Â |
event_subject |
| Â | Â | Â |
event_type |
| Â | Â | Â |
user |
| Â | Â | Â |
workgroup_desc |
| Â | Â | Â |
workgroup_id |
| Â | Â | Â |
workgroup_location |
| Â | Â | Â |
company_name |
| Â | Â | Â |
description |
| Â | Â | Â |
filename |
| Â | Â | Â |
md5 |
| Â | Â | Â |
signer |
| Â | mycreatedate | Â |
version |
| Â | Â | Â |
product_name |
| Â | Â | Â |
author |
| Â | Â | Â |
idle_time |
| Â | Â | Â |
last_result |
| Â | Â | Â |
logon_mode |
| Â | Â | Â |
power_management |
| Â | Â | Â |
run_as_user |
| Â | Â | Â |
volume_name |
| Â | Â | Â |
stop_task_hours |
| Â | Â | Â |
task_name |
| Â | Â | Â |
task_to_run |
| Â | Â | Â |
startup_type |
| Â | Â | Â |
disable_auditing |
| Â | Â | Â |
disable_auditing_01 |
| Â | Â | Â |
rth_id |
| Â | Â | Â |
detected_protocol |
| Â | Â | Â |
port_state |
| Â | Â | Â |
port_type |
| Â | Â | Â |
response_type |
| Â | Â | Â |
wb_checked |
| Â | Â | Â |
wb_text |
| Â | Â | Â |
wb_context |
| Â | Â | Â |
cpe |
| Â | Â | Â |
product |
| Â | Â | Â |
image_path |
| Â | Â | Â |
detected_protocol_01 |
| Â | mydetected_protocol | Â |
port_state_01 |
| Â | Â | Â |
port_type_01 |
| Â | Â | Â |
version_01 |
| Â | Â | Â |
response_type_01 |
| Â | Â | Â |
free_vir_mem_01 |
| Â | Â | Â |
drive_desc_01 |
| Â | Â | Â |
sys_model_01 |
| Â | Â | Â |
member_count_01 |
| Â | Â | Â |
sid_01 |
| Â | Â | Â |
bad_pw_count_01 |
| Â | Â | Â |
enum_src_01 |
| Â | Â | Â |
asset_name_01 |
| Â | Â | Â |
dns_server |
| Â | Â | Â |
dhcp_name_server |
| Â | Â | Â |
destination |
| Â | Â | Â |
dcal |
| Â | Â | Â |
dependencies |
| Â | Â | Â |
state |
| Â | Â | Â |
alias |
| Â | Â | Â |
antispy_sig_last_update |
| Â | Â | Â |
attributes |
| Â | Â | Â |
dist_name_0 |
| Â | Â | Â |
registry_value |
| Â | Â | Â |
dns_name_01 |
| Â | Â | Â |
prin_group_id |
| Â | Â | Â |
base_address |
| Â | Â | Â |
folder_path |
| Â | Â | Â |
rth_ids_0 |
| Â | Â | Â |
rth_ids_1 |
| Â | Â | Â |
rth_ids_2 |
| Â | Â | Â |
rth_ids_3 |
| Â | Â | Â |
rth_ids_4 |
| Â | Â | Â |
rth_ids_5 |
| Â | Â | Â |
rth_ids_6 |
| Â | Â | Â |
rth_ids_7 |
| Â | Â | Â |
rth_ids_8 |
| Â | Â | Â |
rth_ids_9 |
| Â | Â | Â |
rth_ids_10 |
| Â | Â | Â |
rth_ids_11 |
| Â | Â | Â |
rth_ids_12 |
| Â | Â | Â |
rth_ids_13 |
| Â | Â | Â |
unknown |
| Â | Â | Â |
rawMessage |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |