/
firewall.vyatta

firewall.vyatta

Introduction

Tags beginning with firewall.vyatta identify events generated by VyOS.

Tag structure

The full tag must have 3 levels. The first two are fixed as firewall.vyatta. The third level identifies the type of events sent.

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Vyatta Firewall

firewall.vyatta.session_table

firewall.vyatta.session_table

firewall.vyatta.traffic

firewall.vyatta.traffic

How is the data sent to Devo?

First, enable logging: https://docs.vyos.io/en/latest/configuration/system/syslog.html#display-logs. VyOS logs may be sent without defining a relay rule.

Table structure

These are the fields displayed in these tables:

firewall.vyatta.session_table

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

serverdate_str

str

 

origin_host

str

 

service_name

str

 

service_tag

str

 

service_pid

str

 

unknown_field_1

str

 

unknown_field_2

str

 

session_id

str

 

session_status

str

 

protocol

str

 

protocol_id

str

 

timeout

str

 

src_ip

ip4

 

src_port

str

 

dst_ip

ip4

 

dst_port

str

 

ifname

str

 

hostchain

str

tag

str

rawMessage

str

firewall.vyatta.traffic

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

serverdate_str

str

 

origin_host

str

 

service_name

str

 

service_tag

str

 

service_pid

str

 

unknown_field_1

str

 

unknown_field_2

str

 

traffic_direction

str

 

ifname

str

 

action

str

 

rule_type

str

 

rule_name

str

 

rule_number

str

 

protocol

str

 

protocol_id

str

 

src_ip

ip4

 

dst_ip

ip4

 

src_port

str

 

dst_port

str

 

v4_len

str

 

v4_ttl

str

 

v4_tos

str

 

v4_ecn

str

 

v4_prot

str

 

v4_hl

str

 

tcp_flags

str

 

tcp_res

str

 

tcp_doff

str

 

tcp_seq

str

 

tcp_ack

str

 

tcp_win

str

 

tcp_urgp

str

 

hostchain

str

tag

str

rawMessage

str

 

Related content

firewall.velocloud
firewall.velocloud
More like this
firewall.meraki
firewall.meraki
More like this
firewall.iptables
firewall.iptables
More like this
firewall.f5
firewall.f5
More like this
firewall.barracuda
firewall.barracuda
More like this
network.velocloud
network.velocloud
More like this