nac.forescout
Introduction
Tags beginning withnac.forescout
identify events generated by Forescout.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as nac.forescout
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product/Service | Tags | Data table |
---|---|---|
Forescout counterACT |
|
|
|
| |
|
| |
|
| |
|
|
Table structure
This is the set displayed by these tables:
nac.forescout.counteract.actions
Field | Type | Source field name | Extra Label |
---|---|---|---|
eventdate |
|
|
|
machine |
| vmachine |
|
eventType |
|
|
|
ipAddr |
|
|
|
macAddr |
|
|
|
hostName |
|
|
|
dnsName |
|
|
|
user |
|
|
|
rawMessage |
|
|
|
unknown |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
nac.forescout.counteract.common
Field | Type | Source field name | Extra Label |
---|---|---|---|
eventdate |
|
|
|
machine |
| vmachine |
|
eventtype |
|
|
|
sourceIp |
|
|
|
destinationIp |
|
|
|
destinationPort |
|
|
|
rawMessage |
|
|
|
unknown |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
nac.forescout.counteract.log
Field | Type | Source field name | Extra Label |
---|---|---|---|
eventdate |
|
|
|
machine |
| vmachine |
|
log |
|
|
|
details |
|
|
|
severity |
|
|
|
rawMessage |
|
|
|
unknown |
|
|
|
hostchain |
|
| ✓ |
tag |
|
| ✓ |
nac.forescout.counteract.policy
Field | Type | Extra Label |
---|---|---|
eventdate |
|
|
machine |
|
|
serverdate |
|
|
hostname |
|
|
procName |
|
|
procId |
|
|
sourceIp |
|
|
rule |
|
|
details |
|
|
match |
|
|
category |
|
|
rawMessage |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
nac.forescout.counteract.system
Field | Type | Extra Label |
---|---|---|
eventdate |
|
|
message |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
Relay Rules to dynamically generate tables
Relay rules can be used to dynamically generate nac.forescout.*
tables. The following examples specifie the required ones depending on the Forescout type of log.
Forescout policy logs
Rule name | Forescout-Policy |
---|---|
Port |
|
Source data |
|
Send without syslog tag | [*] |
Target tag |
|
Target message |
|
Stop processing | [*] |
Forescout log logs
Rule name | Forescout-Log |
---|---|
Port |
|
Source data |
|
Send without syslog tag | [*] |
Target tag |
|
Target message |
|
Stop processing | [*] |
Forescout system logs
Rule name | Forescout-System |
---|---|
Port |
|
Source data |
|
Send without syslog tag | [*] |
Target tag |
|
Target message |
|
Stop processing | [*] |