vuln.beyondtrust
Introduction
The tags beginning with vuln.beyondtrust
identify events generated by BeyondTrust vulnerability management.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as vuln.beyondtrust
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Beyond Trust vulnerability management |
|
|
| ||
|
| |
| ||
|
|
For more information, read more About Devo tags.
Send it
Data should be sent using the relay.
In BeyondTrust solutions, you can set up a connector that enables syslog event forwarding. The events should be directed to a Devo relay where a relay rule applies the correct tag, then forwards the events securely to your Devo domain.
For information about setting up syslog event forwarding, see the BeyondInsight and Password Safe Third-Party Integration Guide.
Example relay rules
Source message:
Source data: Agent ID: ([^ ]+)
Source tag:
Target tag: vuln.beyondtrust.\\D1
Sent without syslog tag: false
Stop processing: true
Table structure
These are the fields displayed in these tables:
vuln.beyondtrust.applaudit
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
host |
|
|
|
|
agent_desc |
|
|
|
|
agent_id |
|
|
|
|
agent_ver |
|
|
|
|
category |
|
|
|
|
source_host |
|
|
|
|
event_desc |
|
|
|
|
event_name |
|
|
|
|
os |
|
|
|
|
event_severity |
|
|
|
|
source_ip |
|
|
|
|
event_subject |
|
|
|
|
event_type |
|
|
|
|
user |
|
|
|
|
workgroup_desc |
|
|
|
|
workgroup_id |
|
|
|
|
workgroup_location |
|
|
|
|
audit_id |
|
|
|
|
action_type |
|
|
|
|
system_name |
|
|
|
|
app_user_id |
|
|
|
|
create_date |
| parsedate(mycreatedate, "M/DD/YYYY h:mm:ss A")
| mycreatedate |
|
ip_address |
|
|
|
|
user_name2 |
|
|
|
|
groupp |
|
|
|
|
auth_type |
|
|
|
|
domain_name |
|
|
|
|
sam_account_name |
|
|
|
|
source |
|
|
|
|
message |
|
|
|
|
address_group_name |
|
|
|
|
id |
|
|
|
|
smart_rule_name |
|
|
|
|
report_name |
|
|
|
|
asset_name |
|
|
|
|
unknown |
|
|
|
|
rawMessage |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
vuln.beyondtrust.pbps
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
host |
| split(hostchain, "=", 0)
| hostchain |
|
agent_desc |
|
|
|
|
agent_id |
|
|
|
|
agent_ver |
|
|
|
|
category |
|
|
|
|
source_host |
|
|
|
|
event_desc |
|
|
|
|
event_name |
|
|
|
|
os |
|
|
|
|
event_severity |
|
|
|
|
source_ip |
|
|
|
|
event_subject |
|
|
|
|
event_type |
|
|
|
|
user |
|
|
|
|
workgroup_desc |
|
|
|
|
workgroup_id |
|
|
|
|
workgroup_location |
|
|
|
|
log_system_id |
|
|
|
|
log_time |
|
|
|
|
user_name |
|
|
|
|
role_used |
|
|
|
|
object_type_id |
| parsedate(mycreatedate, "M/DD/YYYY h:mm:ss A")
| mycreatedate |
|
object_type |
|
|
|
|
object_id |
|
|
|
|
operation |
|
|
|
|
failed |
|
|
|
|
target |
|
|
|
|
details |
|
|
|
|
user_id |
|
|
|
|
time_stamp |
|
|
|
|
ip_address |
|
|
|
|
unknown |
|
|
|
|
rawMessage |
|
|
|
|
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
vuln.beyondtrust.retina
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
|
|
host |
| split(hostchain, "=", 0)
| hostchain |
|
agent_desc |
|
|
|
|
agent_id |
|
|
|
|
agent_ver |
|
|
|
|
category |
|
|
|