Event Fields
151
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
CustomerVar161-170
cv161-170
Reserved for use by customers
for customer-specific data.
(Date; Not stored in DB)
Y
CustomerVar171-180
cv171-180
Reserved for use by customers
for customer-specific data.
(UUID; Not stored in DB)
Y
CustomerVar181-190
cv181-190
Reserved for use by customers
for customer-specific data.
(IPv4; Not stored in DB)
Y
CustomerVar191-200
cv191-200
Reserved for use by customers
for customer-specific data.
(String; Not stored in DB)
Y
CustomerVar21-99
cv21-99
Reserved for use by customers
for customer-specific data.
(String)
Y
DataCotext
rv36
Container for the FileName
data object (for example, a
directory for a file or a database
instance for a database table)
Y
Y
DataTagId
rv3
An Id for user-defined event
tagging.
DataValue43
rv43
Data Value. (String)
Y
DeviceCategory
rv32
Device category (FW, IDS, AV,
OS, DB).
DeviceName
rv31
The name of the device
generating the event. If this
device is supported by Advisor,
the name should match the
name known by Advisor.
(String)
Y
Y
EffectiveUserDomain
eudom
The domain (namespace) in
which the effective user
account exists.
Y
EffectiveUserID
euid
Numerical ID of the user that
the InitUser is impersonating
(
root
using
su
, for example),
based on the raw data reported
by the device.
Y
EffectiveUserName
euname
The name of the account that is
effectively being used.
Y
EventContext
rv33
Event context (threat level).
Y
EventGroupID
evtgrpid
A source-specific identifier to
group multiple related events
together.
Y
Field
Short Name
Description
Tokenized
Visible in
Basic
View
Visible in
Detailed
View
Summary of Contents for SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Page 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...