20.06.2015 Views

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />

2.6 Event Fields<br />

Mandatory – no default values, have always to be set when creating a new plugin<br />

plugin_id<br />

plugin_sid<br />

Event Type<br />

Event Subtype<br />

Mandatory – default values are assigned by the OSSIM Agent<br />

Optional<br />

date<br />

sensor<br />

interface<br />

protocol<br />

src_ip<br />

src_port<br />

dst_ip<br />

dst_port<br />

username<br />

password<br />

filename<br />

The time the event has been collected from the device<br />

The IP Address of the sensor collecting the event<br />

The interface where the event has been collected<br />

IP Protocol (see /etc/protocols)<br />

The Source IP Address<br />

The Source Port<br />

The Destination IP Address<br />

The Destination Port<br />

The User referred in the event<br />

The Password referred in the event<br />

The Filename referred in the event<br />

userdata1 – userdata9 User defined fields that could be used in custom reports,<br />

correlation directives, etc.<br />

Special types of events and the list of fields that can be used in each event type:<br />

Host-os-event Host-mac-event Host-service-event<br />

host host host<br />

os mac sensor<br />

sensor vendor interface<br />

interface sensor port<br />

date interface protocol<br />

date<br />

service<br />

application<br />

date<br />

Page 18 Copyright © Alienvault 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!