VMware_SDWAN_FirewallLogs_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (36 columns)

Source: KQL validation test schema

Column Name Type
actionTaken string
application string
attackSource string
attackTarget string
bytesReceived int
bytesSent int
category string
closeReason string
destination string
destinationIp string
destinationPort int
domainName string
edgeLogicalId string
edgeName datetime
enterpriseLogicalId string
extensionHeader string
firewallPolicyName string
idsAlert int
inputInterface datetime
ipsAlert int
logType string
protocol int
ruleId string
ruleVersion int
segmentLogicalId string
segmentName string
sessionDurationSecs int
sessionId int
severity int
signature string
signatureId int
sourceIp string
sourcePort int
TimeGenerated datetime
timestamp datetime
verdict string

Solutions (1)

This table is used by the following solutions:


Content Items Using This Table (1)

Analytic Rules (1)

In solution VMware SASE:

Analytic Rule Selection Criteria
VMware SD-WAN Edge - IDS/IPS Alert triggered (Search API)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index