Document toolboxDocument toolbox

cef0.patownsend

Introduction

The tags beginning with cef0.patownsend identify events in CEF format generated by Townsend Security.

Tag structure

Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.

In this case, the valid data tables are:

Tags

Data tables

Tags

Data tables

cef0.patownsend.ibmQaudjrn

cef0.patownsend.ibmQaudjrn

How is the data sent to Devo?

Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.

Table structure

These are the fields displayed in this table:

cef0.patownsend.ibmQaudjrn

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

hostname

str

 

 

priorityCode

str

 

 

cefTag

str

 

 

cefVersion

str

 

 

embDeviceVendor

str

 

 

embDeviceProduct

str

 

 

deviceVersion

str

 

 

signatureID

str

 

 

name

str

 

 

severity

int4

 

 

_cefVer

str

 

 

act

str

 

 

dproc

str

 

 

dvchost

str

 

 

msg

str

 

 

suser

str

 

 

user_profile

str

 

 

JUID

str

 

 

device

str

 

 

IPC_handle

str

 

 

IPC_type

str

 

 

actual_type

str

 

 

act_user

str

 

 

action_type

str

 

 

admin_user

str

 

 

auth_user

str

 

 

eff_user

str

 

 

cmd_type

str

 

 

ifs_path

str

 

 

object

str

 

 

object_library

str

 

 

object_type

str

 

 

object_name

str

 

 

des_job_name

str

 

 

des_job_no

str

 

 

des_job_user

str

 

 

des_profile

str

 

 

func_reg_desc

str

 

 

old_owner

str

 

 

new_owner

str

 

 

audit_value

str

 

 

path

str

 

 

service_tool

str

 

 

chg_command

str

 

 

info_type

str

 

 

workstation

str

 

 

op_violation

str

 

 

violation

str

 

 

pgm_name

str

 

 

pgm_libr

str

 

 

causing_user

str

 

 

val_user

str

 

 

val_job

str

 

 

val_jobno

str

 

 

key_operation

str

 

 

cert_label

str

 

 

primary_group_own

str

 

 

program_lib

str

 

 

program_name

str

 

 

owner

str

 

 

old_group

str

 

 

New_group

str

 

 

object_exist

str

 

 

object_manage

str

 

 

password_oper

str

 

 

object_alter

str

 

 

object_ref

str

 

 

execute_auth

str

 

 

revoke_old_auth

str

 

 

job_number

str

 

 

jrn_seq

str

 

 

logical_partition

str

 

 

sev

str

 

 

srcIp

ip4

 

 

spt

int4

 

 

timestamp

str

 

 

hostchain

str

 

✓

tag

str

cefTag

✓

rawMessage

str

 

✓