cef0.sonicwall
Introduction
The tags beginning with cef0.sonicwall
identify events in CEF format generated by SonicWall.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
Tags | Data tables |
---|---|
|
|
|
|
|
|
|
|
|
|
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in these tables:
cef0.sonicwall.nsa2700
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
c6a4Label |
| Â | Â |
cn1Label |
| Â | Â |
cn2Label |
| Â | Â |
cn3Label |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs4Label |
| Â | Â |
cs6 |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dmac |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
dvc |
| Â | Â |
in |
| Â | Â |
out |
| Â | Â |
reason |
| Â | Â |
request |
| Â | Â |
rt |
| Â | Â |
smac |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
ad_dnpt |
| Â | Â |
ad_dpi |
| Â | Â |
ad_fw__action |
| Â | Â |
ad_gcat |
| Â | Â |
ad_snpt |
| Â | Â |
agentZoneURI |
| Â | Â |
agt |
| Â | Â |
ahost |
| Â | Â |
aid |
| Â | Â |
amac |
| Â | Â |
art |
| Â | Â |
at |
| Â | Â |
atz |
| Â | Â |
av |
| Â | Â |
customerURI |
| Â | Â |
destinationZoneURI |
| Â | Â |
deviceSeverity |
| Â | Â |
deviceZoneURI |
| Â | Â |
dtz |
| Â | Â |
eventId |
| Â | Â |
geid |
| Â | Â |
sourceZoneURI |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.sonicwall.nsa3600
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
c6a4Label |
| Â | Â |
cn1Label |
| Â | Â |
cn1 |
| Â | Â |
cn2Label |
| Â | Â |
cn2 |
| Â | Â |
cn3Label |
| Â | Â |
cs1Label |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs4Label |
| Â | Â |
cs5Label |
| Â | Â |
cs6 |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dmac |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
dvc |
| Â | Â |
in |
| Â | Â |
msg |
| Â | Â |
out |
| Â | Â |
rt |
| Â | Â |
smac |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
ad_dnpt |
| Â | Â |
ad_dpi |
| Â | Â |
ad_dstV6 |
| Â | Â |
ad_fw__action |
| Â | Â |
ad_gcat |
| Â | Â |
ad_snpt |
| Â | Â |
ad_srcV6 |
| Â | Â |
ad_susr |
| Â | Â |
agentZoneURI |
| Â | Â |
agt |
| Â | Â |
ahost |
| Â | Â |
aid |
| Â | Â |
amac |
| Â | Â |
art |
| Â | Â |
at |
| Â | Â |
atz |
| Â | Â |
av |
| Â | Â |
categoryBehavior |
| Â | Â |
categoryDeviceGroup |
| Â | Â |
categoryObject |
| Â | Â |
categoryOutcome |
| Â | Â |
categorySignificance |
| Â | Â |
customerURI |
| Â | Â |
destinationZoneURI |
| Â | Â |
deviceSeverity |
| Â | Â |
deviceZoneURI |
| Â | Â |
dtz |
| Â | Â |
eventId |
| Â | Â |
geid |
| Â | Â |
sourceZoneURI |
| Â | Â |
type |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.sonicwall.nsa4600
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
c6a4Label |
| Â | Â |
cn1Label |
| Â | Â |
cn2Label |
| Â | Â |
cn3Label |
| Â | Â |
cs3Label |
| Â | Â |
cs4Label |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dmac |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
dvc |
| Â | Â |
in |
| Â | Â |
out |
| Â | Â |
rt |
| Â | Â |
smac |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
ad_appName |
| Â | Â |
ad_dpi |
| Â | Â |
ad_fw__action |
| Â | Â |
ad_gcat |
| Â | Â |
agentZoneURI |
| Â | Â |
agt |
| Â | Â |
ahost |
| Â | Â |
aid |
| Â | Â |
amac |
| Â | Â |
art |
| Â | Â |
at |
| Â | Â |
atz |
| Â | Â |
av |
| Â | Â |
categoryBehavior |
| Â | Â |
categoryDeviceGroup |
| Â | Â |
categoryObject |
| Â | Â |
categoryOutcome |
| Â | Â |
categorySignificance |
| Â | Â |
customerURI |
| Â | Â |
destinationZoneURI |
| Â | Â |
deviceSeverity |
| Â | Â |
deviceZoneURI |
| Â | Â |
dtz |
| Â | Â |
eventId |
| Â | Â |
geid |
| Â | Â |
sourceZoneURI |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.sonicwall.tz500
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
c6a4Label |
| Â | Â |
cn1Label |
| Â | Â |
cn2Label |
| Â | Â |
cn3Label |
| Â | Â |
cs1 |
| Â | Â |
cs3Label |
| Â | Â |
cs4Label |
| Â | Â |
cs5Label |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dmac |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
dvc |
| Â | Â |
in |
| Â | Â |
out |
| Â | Â |
rt |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
ad_gcat |
| Â | Â |
ad_susr |
| Â | Â |
agentZoneURI |
| Â | Â |
agt |
| Â | Â |
ahost |
| Â | Â |
aid |
| Â | Â |
amac |
| Â | Â |
art |
| Â | Â |
at |
| Â | Â |
atz |
| Â | Â |
av |
| Â | Â |
destinationZoneURI |
| Â | Â |
deviceSeverity |
| Â | Â |
deviceZoneURI |
| Â | Â |
dtz |
| Â | Â |
eventId |
| Â | Â |
geid |
| Â | Â |
sourceZoneURI |
| Â | Â |
type |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |
cef0.sonicwall.tz600
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
app |
| Â | Â |
cat |
| Â | Â |
c6a4Label |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs3Label |
| Â | Â |
cs4Label |
| Â | Â |
cs5Label |
| Â | Â |
cs6 |
| Â | Â |
deviceInboundInterface |
| Â | Â |
deviceOutboundInterface |
| Â | Â |
dhost |
| Â | Â |
dmac |
| Â | Â |
dst |
| Â | Â |
dpt |
| Â | Â |
dvc |
| Â | Â |
in |
| Â | Â |
out |
| Â | Â |
reason |
| Â | Â |
requestMethod |
| Â | Â |
request |
| Â | Â |
rt |
| Â | Â |
shost |
| Â | Â |
smac |
| Â | Â |
src |
| Â | Â |
spt |
| Â | Â |
ad_dnpt |
| Â | Â |
ad_dpi |
| Â | Â |
ad_fw__action |
| Â | Â |
ad_gcat |
| Â | Â |
ad_snpt |
| Â | Â |
ad_susr |
| Â | Â |
agentZoneURI |
| Â | Â |
agt |
| Â | Â |
ahost |
| Â | Â |
aid |
| Â | Â |
amac |
| Â | Â |
art |
| Â | Â |
at |
| Â | Â |
atz |
| Â | Â |
av |
| Â | Â |
categoryBehavior |
| Â | Â |
categoryDeviceGroup |
| Â | Â |
categoryObject |
| Â | Â |
categoryOutcome |
| Â | Â |
categorySignificance |
| Â | Â |
customerURI |
| Â | Â |
destinationZoneURI |
| Â | Â |
deviceSeverity |
| Â | Â |
deviceZoneURI |
| Â | Â |
dtz |
| Â | Â |
eventId |
| Â | Â |
geid |
| Â | Â |
sourceZoneURI |
| Â | Â |
type |
| Â | Â |
hostchain |
|  | ✓ |
tag |
| cefTag | ✓ |
rawMessage |
|  | ✓ |