Document toolboxDocument toolbox

directory.redhat

Introduction

The tags beginning with directory.redhat identify events generated by Red Hat.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as directory.redhat. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Red Hat

directory.redhat.389directory.access

directory.redhat.389directory.access

directory.redhat.389directory.error

directory.redhat.389directory.error

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

directory.redhat.389directory.access

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

message

str

 

 

datetime

str

 

 

conn

str

 

 

op

str

 

 

fd

str

 

 

slot

str

 

 

srcIp

str

 

 

dstIp

str

 

 

action

str

 

 

request

str

 

 

response

str

 

 

base

str

 

 

scope

str

 

 

filter

str

 

 

attrs

str

 

 

dn

str

 

 

method

str

 

 

version

str

 

 

oid

str

 

 

name

str

 

 

targetop

str

 

 

msgid

str

 

 

nentries

str

 

 

etime

str

 

 

err

str

 

 

Tag

str

 

 

wtime

str

 

 

optime

str

 

 

rawMessage

str

message

✓

hostchain

str

 

✓

tag

str

 

✓

directory.redhat.389directory.error

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

message

str

 

 

datetime

str

 

 

severity

str

 

 

function

str

 

 

msg

str

 

 

base

str

 

 

scope

str

 

 

filter

str

 

 

conn

str

 

 

op

str

 

 

fd

str

 

 

rawMessage

str

message

✓

hostchain

str

 

✓

tag

str

 

✓