Document toolboxDocument toolbox

threatintel.farsight

Introduction

The tags beginning with threatintel.farsight identify events generated by DNS Changes channel belonging to Farsight.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as threatintel.farsight. The third level identifies the type of events sent and the fourth indicates the event subtypes.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

DNS Changes channel

threatintel.farsight.dns.ch212

threatintel.farsight.dns.ch212

threatintel.farsight.dns.ch213

threatintel.farsight.dns.ch213

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

threatintel.farsight.dns.ch212

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

time

timestamp

 

vname

str

 

mname

str

 

source

str

 

message_domain

str

 

message_time_seen

timestamp

 

message_bailiwick

str

 

message_rrname

str

 

message_rrclass

str

 

message_rrtype

str

 

message_rdata

str

 

message_keys

str

 

message_new_rr

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓

threatintel.farsight.dns.ch213

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

source

str

 

time

timestamp

 

mname

str

 

message_time_seen

timestamp

 

message_rrclass

str

 

message_rrname

str

 

message_bailiwick

str

 

message_rrtype

str

 

message_new_rr

str

 

message_keys

str

 

message_rdata

str

 

message_domain

str

 

vname

str

 

hostchain

str

✓

tag

str

✓

rawMessage

str

✓

Â