Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />
2.6 Event Fields<br />
Mandatory – no default values, have always to be set when creating a new plugin<br />
plugin_id<br />
plugin_sid<br />
Event Type<br />
Event Subtype<br />
Mandatory – default values are assigned by the OSSIM Agent<br />
Optional<br />
date<br />
sensor<br />
interface<br />
protocol<br />
src_ip<br />
src_port<br />
dst_ip<br />
dst_port<br />
username<br />
password<br />
filename<br />
The time the event has been collected from the device<br />
The IP Address of the sensor collecting the event<br />
The interface where the event has been collected<br />
IP Protocol (see /etc/protocols)<br />
The Source IP Address<br />
The Source Port<br />
The Destination IP Address<br />
The Destination Port<br />
The User referred in the event<br />
The Password referred in the event<br />
The Filename referred in the event<br />
userdata1 – userdata9 User defined fields that could be used in custom reports,<br />
correlation directives, etc.<br />
Special types of events and the list of fields that can be used in each event type:<br />
Host-os-event Host-mac-event Host-service-event<br />
host host host<br />
os mac sensor<br />
sensor vendor interface<br />
interface sensor port<br />
date interface protocol<br />
date<br />
service<br />
application<br />
date<br />
Page 18 Copyright © Alienvault 2010