cef0.skyformation
Introduction
The tags beginning with cef0.skyformation
identify events in CEF format generated by Sky Formation.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
Tags | Data tables |
---|---|
|
|
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in this table:
cef0.skyformation.skyformationCloudAppsSecurity
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
hostname |
| Â | Â |
priorityCode |
| Â | Â |
cefTag |
| Â | Â |
cefVersion |
| Â | Â |
embDeviceVendor |
| Â | Â |
embDeviceProduct |
| Â | Â |
deviceVersion |
| Â | Â |
signatureID |
| Â | Â |
name |
| Â | Â |
severity |
| Â | Â |
_cefVer |
| Â | Â |
act |
| Â | Â |
cat |
| Â | Â |
cn1Label |
| Â | Â |
cn1 |
| Â | Â |
cs1Label |
| Â | Â |
cs1 |
| Â | Â |
cs2Label |
| Â | Â |
cs2 |
| Â | Â |
cs6Label |
| Â | Â |
cs6 |
| Â | Â |
destinationServiceName |
| Â | Â |
deviceInboundInterface |
| Â | Â |
dhost |
| Â | Â |
dpriv |
| Â | Â |
dproc |
| Â | Â |
duid |
| Â | Â |
duser |
| Â | Â |
dvchost |
| Â | Â |
dvcpid |
| Â | Â |
end |
| Â | Â |
fileHash |
| Â | Â |
filePath |
| Â | Â |
fileType |
| Â | Â |
fname |
| Â | Â |
msg |
| Â | Â |
oldFilePath |
| Â | Â |
outcome |
| Â | Â |
out |
| Â | Â |
proto |
| Â | Â |
reason |
| Â | Â |
requestClientApplication |
| Â | Â |
requestCookies |
| Â | Â |
requestMethod |
| Â | Â |
request |
| Â | Â |
shost |
| Â | Â |
smac |
| Â | Â |
sntdom |
| Â | Â |
sourceServiceName |
| Â | Â |
src |
| Â | Â |
suid |
| Â | Â |
suser |
| Â | Â |
devicePayloadId |
| Â | Â |
dtz |
| Â | Â |
ext_Act |
| Â | Â |
ext_AppId |
| Â | Â |
ext_AttCnt |
| Â | Â |
ext_AttSize |
| Â | Â |
ext_ClientAppId |
| Â | Â |
ext_ClientIP |
| Â | Â |
ext_ClientIPAddress |
| Â | Â |
ext_ClientInfoString |
| Â | Â |
ext_ClientRequestId |
| Â | Â |
ext_CreationTime |
| Â | Â |
ext_Dir |
| Â | Â |
ext_ExternalAccess |
| Â | Â |
ext_Folders_0__FolderItems_0__InternetMessageId |
| Â | Â |
ext_Folders_0__Id |
| Â | Â |
ext_Folders_0__Path |
| Â | Â |
ext_Id |
| Â | Â |
ext_InternalLogonType |
| Â | Â |
ext_Item_Attachments |
| Â | Â |
ext_Item_Id |
| Â | Â |
ext_Item_InternetMessageId |
| Â | Â |
ext_Item_IsRecord |
| Â | Â |
ext_Item_ParentFolder_Id |
| Â | Â |
ext_Item_ParentFolder_Path |
| Â | Â |
ext_Item_SizeInBytes |
| Â | Â |
ext_Item_Subject |
| Â | Â |
ext_LogonType |
| Â | Â |
ext_LogonUserSid |
| Â | Â |
ext_MailboxGuid |
| Â | Â |
ext_MailboxOwnerSid |
| Â | Â |
ext_MailboxOwnerUPN |
| Â | Â |
ext_ModifiedProperties_0_ |
| Â | Â |
ext_MsgId |
| Â | Â |
ext_MsgSize |
| Â | Â |
ext_Operation |
| Â | Â |
ext_OperationCount |
| Â | Â |
ext_OperationProperties_0__Name |
| Â | Â |
ext_OperationProperties_0__Value |
| Â | Â |
ext_OperationProperties_1__Name |
| Â | Â |
ext_OperationProperties_1__Value |
| Â | Â |
ext_OrganizationId |
| Â | Â |
ext_OrganizationName |
| Â | Â |
ext_OriginatingServer |
| Â | Â |
ext_Rcpt |
| Â | Â |
ext_RcptActType |
| Â | Â |
ext_RcptHdrType |
| Â | Â |
ext_RecordType |
| Â | Â |
ext_ResultStatus |
| Â | Â |
ext_Sender |
| Â | Â |
ext_SessionId |
| Â | Â |
ext_Subject |
| Â | Â |
ext_UserId |
| Â | Â |
ext_UserKey |
| Â | Â |
ext_UserType |
| Â | Â |
ext_Version |
| Â | Â |
ext_Workload |
| Â | Â |
ext__action_taken_ |
| Â | Â |
ext__action_taken_by_ |
| Â | Â |
ext__admin_id_ |
| Â | Â |
ext__admin_role_ |
| Â | Â |
ext__asset_id_ |
| Â | Â |
ext__cloud_app_instance_ |
| Â | Â |
ext__event_category___tag |
| Â | Â |
ext__event_type_ |
| Â | Â |
ext__event_type___tag |
| Â | Â |
ext__event_type__description |
| Â | Â |
ext__incident_id_ |
| Â | Â |
ext__involve_non_team_member_ |
| Â | Â |
ext__item_creator_ |
| Â | Â |
ext__item_name_ |
| Â | Â |
ext__item_owner_ |
| Â | Â |
ext__item_type_ |
| Â | Â |
ext__log_type_ |
| Â | Â |
ext__policy_rule_name_ |
| Â | Â |
ext__resource_value_new_ |
| Â | Â |
ext__resource_value_old_ |
| Â | Â |
ext__riskEventTypes_v2_ |
| Â | Â |
ext__source_ip_ |
| Â | Â |
ext__target_type_ |
| Â | Â |
ext_aCode |
| Â | Â |
ext_acc |
| Â | Â |
ext_action |
| Â | Â |
ext_actor__tag |
| Â | Â |
ext_actor_user__tag |
| Â | Â |
ext_actor_user_account_id_ |
| Â | Â |
ext_actor_user_display_name_ |
| Â | Â |
ext_actor_user_email |
| Â | Â |
ext_actor_user_team_member_id_ |
| Â | Â |
ext_appDisplayName |
| Â | Â |
ext_appId |
| Â | Â |
ext_appliedConditionalAccessPolicies_0__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_0__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_0__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_0__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_0__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_10__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_10__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_10__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_10__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_10__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_11__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_11__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_11__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_11__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_11__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_12__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_12__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_12__enforcedSessionControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_12__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_12__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_13__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_13__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_13__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_13__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_13__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_14__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_14__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_14__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_14__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_14__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_15__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_15__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_15__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_15__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_15__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_16__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_16__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_16__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_16__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_16__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_1__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_1__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_1__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_1__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_1__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_2__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_2__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_2__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_2__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_2__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_3__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_3__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_3__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_3__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_3__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_4__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_4__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_4__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_4__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_4__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_5__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_5__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_5__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_5__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_5__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_6__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_6__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_6__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_6__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_6__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_7__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_7__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_7__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_7__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_7__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_8__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_8__enforcedGrantControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_8__enforcedSessionControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_8__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_8__result |
| Â | Â |
ext_appliedConditionalAccessPolicies_9__displayName |
| Â | Â |
ext_appliedConditionalAccessPolicies_9__enforcedGrantControls_0_ |
| Â | Â |
ext_appliedConditionalAccessPolicies_9__enforcedSessionControls |
| Â | Â |
ext_appliedConditionalAccessPolicies_9__id |
| Â | Â |
ext_appliedConditionalAccessPolicies_9__result |
| Â | Â |
ext_assets |
| Â | Â |
ext_auditType |
| Â | Â |
ext_authorization_action |
| Â | Â |
ext_authorization_scope |
| Â | Â |
ext_caller |
| Â | Â |
ext_category |
| Â | Â |
ext_category_localizedValue |
| Â | Â |
ext_category_value |
| Â | Â |
ext_channels |
| Â | Â |
ext_claims_aio |
| Â | Â |
ext_claims_appid |
| Â | Â |
ext_claims_appidacr |
| Â | Â |
ext_claims_aud |
| Â | Â |
ext_claims_exp |
| Â | Â |
ext_claims_groups |
| Â | Â |
ext_claims_iat |
| Â | Â |
ext_claims_iss |
| Â | Â |
ext_claims_nbf |
| Â | Â |
ext_claims_rh |
| Â | Â |
ext_claims_uti |
| Â | Â |
ext_claims_ver |
| Â | Â |
ext_claims_xms_tcdt_ |
| Â | Â |
ext_clientAppUsed |
| Â | Â |
ext_conditionalAccessStatus |
| Â | Â |
ext_context__tag |
| Â | Â |
ext_context_account_id_ |
| Â | Â |
ext_context_display_name_ |
| Â | Â |
ext_context_email |
| Â | Â |
ext_context_team_member_id_ |
| Â | Â |
ext_correlationId |
| Â | Â |
ext_createdDateTime |
| Â | Â |
ext_datetime |
| Â | Â |
ext_description |
| Â | Â |
ext_details__tag |
| Â | Â |
ext_details_user_agent_ |
| Â | Â |
ext_deviceDetail_browser |
| Â | Â |
ext_deviceDetail_deviceId |
| Â | Â |
ext_deviceDetail_displayName |
| Â | Â |
ext_deviceDetail_isCompliant |
| Â | Â |
ext_deviceDetail_isManaged |
| Â | Â |
ext_deviceDetail_operatingSystem |
| Â | Â |
ext_deviceDetail_trustType |
| Â | Â |
ext_eventDataId |
| Â | Â |
ext_eventInfo |
| Â | Â |
ext_eventName_localizedValue |
| Â | Â |
ext_eventName_value |
| Â | Â |
ext_eventTime |
| Â | Â |
ext_eventTimestamp |
| Â | Â |
ext_field |
| Â | Â |
ext_httpRequest_clientIpAddress |
| Â | Â |
ext_httpRequest_clientRequestId |
| Â | Â |
ext_httpRequest_method |
| Â | Â |
ext_id |
| Â | Â |
ext_ip |
| Â | Â |
ext_ipAddress |
| Â | Â |
ext_isInteractive |
| Â | Â |
ext_level |
| Â | Â |
ext_location |
| Â | Â |
ext_location_city |
| Â | Â |
ext_location_countryOrRegion |
| Â | Â |
ext_location_geoCoordinates_latitude |
| Â | Â |
ext_location_geoCoordinates_longitude |
| Â | Â |
ext_location_state |
| Â | Â |
ext_operationId |
| Â | Â |
ext_operationName_localizedValue |
| Â | Â |
ext_operationName_value |
| Â | Â |
ext_origin_access_method___tag |
| Â | Â |
ext_origin_access_method__end_user___tag |
| Â | Â |
ext_origin_access_method__end_user__session_id_ |
| Â | Â |
ext_origin_geo_location__city |
| Â | Â |
ext_origin_geo_location__country |
| Â | Â |
ext_origin_geo_location__ip_address_ |
| Â | Â |
ext_origin_geo_location__region |
| Â | Â |
ext_participants |
| Â | Â |
ext_properties_eventCategory |
| Â | Â |
ext_properties_serviceRequestId |
| Â | Â |
ext_properties_statusCode |
| Â | Â |
ext_resourceDisplayName |
| Â | Â |
ext_resourceGroupName |
| Â | Â |
ext_resourceId |
| Â | Â |
ext_resourceProviderName_localizedValue |
| Â | Â |
ext_resourceProviderName_value |
| Â | Â |
ext_resourceType_localizedValue |
| Â | Â |
ext_resourceType_value |
| Â | Â |
ext_riskDetail |
| Â | Â |
ext_riskEventTypes |
| Â | Â |
ext_riskLevelAggregated |
| Â | Â |
ext_riskLevelDuringSignIn |
| Â | Â |
ext_riskState |
| Â | Â |
ext_serial |
| Â | Â |
ext_severity |
| Â | Â |
ext_status_errorCode |
| Â | Â |
ext_status_failureReason |
| Â | Â |
ext_status_localizedValue |
| Â | Â |
ext_status_value |
| Â | Â |
ext_subStatus_localizedValue |
| Â | Â |
ext_subStatus_value |
| Â | Â |
ext_submissionTimestamp |
| Â | Â |
ext_subscriptionId |
| Â | Â |
ext_tenantId |
| Â | Â |
ext_timestamp |
| Â | Â |
ext_user |
| Â | Â |
ext_userDisplayName |
| Â | Â |
ext_userId |
| Â | Â |
ext_userPrincipalName |
| Â | Â |
externalID |
| Â | Â |
flexString1 |
| Â | Â |
flexString1Label |
| Â | Â |
flexString2 |
| Â | Â |
flexString2Label |
| Â | Â |
requestContext |
| Â | Â |
hostchain |
|  | ✓ |
rawMessage |
|  | ✓ |
tag |
| cefTag | ✓ |