Skip to main content
Skip table of contents

Dragos Alerts

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Drago AlertsBase RuleOperations : InformationGeneral Alert Message
Configuration Quad AlertSub RuleSecurity : Activity
General Activity
Indicator Quad AlertSub RuleSecurity : AttackGeneral Attack Activity
Modeling Quad AlertSub RuleSecurity : AttackGeneral Attack Activity
Threat Behavior Quad AlertSub RuleSecurity : AttackGeneral Attack Activity
Unassigned Quad AlertSub RuleSecurity : Activity
General Activity

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
CEF:VersionN/AN/AIdentifies the version of the CEF format.
Device VendorN/AN/AIdentifies the vendor of the sending device.
Device ProductN/AN/AIdentifies the product of the sending device.
Device Version<version>NumberIdentifies the version of the sending device.
Signature IDN/AN/AUnique event-type identifier.
Name<vmid>StringDescription of the event.
Severity<severity>NumberReflects the importance of the event.
ExtensionN/AN/ACollection of key-value pairs.
content<vendorinfo>StringDetailed description of the event.
asset_ipN/AN/A

Asset IP address for single asset events.

asset_hostnameN/AN/A

Asset hostname(s) for single asset events.

dst_asset_ip<dip>IP Address

Destination asset IP address for multiple asset events.

dst_asset_hostname<dname>String

Destination asset host names for directional events.

dst_asset_mac<dmac>String

Destination asset MAC address for multiple asset events.

dst_asset_domainN/AN/A

Destination asset domain names for directional events.

src_asset_ip<sip>IP Address

Destination asset IP address for multiple asset events.

src_asset_hostname<sname>String

Destination asset host names for directional events.

src_asset_mac<smac>StringDestination asset MAC address for multiple asset events.
src_asset_domainN/AN/ADestination asset domain names for directional events.
id<session>NumberUnique ID for the event.
asset_domainN/AN/AAsset domain names for single asset events.
asset_idN/A

N/A

Dragos system asset ID for single asset events.
asset_macN/AN/A

Asset MAC address for single asset events.

createdAtN/AN/A

Date and time when the event was created (not the same as the transmission time sent in syslog).

detection quad<tag1>,<objecttype>String

Name of the quad in the four types of detection quad used in the Dragos platform.

detectorid<object>String

Unique ID of the collector that originated the event.

dst_asset_idN/AN/A

Dragos system destination asset ID for multiple asset events.

matchedRuleIdN/AN/A

Dragos notification rule that triggered sending the alert over syslog.

occurredAtN/AN/A

Date and time the event occurred at based off the record(s) processed by the sensor.

originalSeverityN/AN/A

Original Dragos severity; some events become higher severity if they are repeated over time.

reviewedN/AN/ATrue if the event has been marked reviewed by a human.
src_asset_idN/AN/A

Dragos system destination asset ID for multiple asset events.

typeN/AN/A

Type of event; this field is free form so the values can be inconsistent at times.



JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.