Configuring DSMs
236
N
AME
V
ALUE
P
AIR
EventName
Type the event name that you want to use to identity the
event in the Events interface when using the Event
Mapping functionality. For more information on mapping
events, see the
SIEM Users Guide.
This is a required parameter.
EventCategory
Type the event category you want to use to identify the
event in the Events interface. If this value is not included in
the log message, the value
NameValuePair
value is
used.
SourceIp
Type the source IP address for the message.
SourcePort
Type the source port for the message.
SourceIpPreNAT
Type the source IP address for the message before
Network Address Translation (NAT) occurred.
SourceIpPostNAT
Type the source IP address for the message after NAT
occurs.
SourceMAC
Type the source MAC address for the message.
SourcePortPreNAT
Type the source port for the message before NAT occurs.
SourcePortPostNAT
Type the source port for the message after NAT occurs.
DestinationIp
Type the destination IP address for the message.
DestinationPort
Type the destination port for the message.
DestinationIpPreNAT
Type the destination IP address for the message before
NAT occurs.
DestinationIpPostNAT
Type the IP address for the message after NAT occurs.
DestinationPortPreNAT
Type the destination port for the message before NAT
occurs.
DestinationPortPostNAT Type the destination port for the message after NAT
occurs.
DestinationMAC
Type the destination MAC address for the message.
DeviceTime
Type the time that the event was sent, according to the
device. The format is: YY/MM/DD hh:mm:ss. If no specific
time is provided, the syslog header or DeviceType
parameter is applied.
UserName
Type the user name associated with the event.
HostName
Type the host name associated with the event. Typically,
this parameter is only associated with identity events.
GroupName
Type the group name associated with the event. Typically,
this parameter is only associated with identity events.
NetBIOSName
Type the NetBIOS name associated with the event.
Typically, this parameter is only associated with identity
events.
Table 44-1
NVP Log Format Tags (continued)
Tag
Description
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......