Appendix 2 – SOCaaP Supported Logs
The following table provides the details of logs that SOCaaP supports and fetches the data to populate Events fields according to event queries.
|
S.No. |
Log Name |
Vendor Name |
Log Type |
|---|---|---|---|
|
1 |
Mysql |
Oracle |
Database |
|
2 |
Oracle |
Oracle |
Database |
|
3 |
Active Directory |
Unknown |
Audit |
|
4 |
Windows-Linux Audit |
Xcitium Audit Parser |
Audit |
|
5 |
Xcitium UTM |
Xcitium |
Audit |
|
6 |
Juniper |
Juniper Networks |
Firewall |
|
7 |
IPtables |
Linux |
Firewall |
|
8 |
Sonicwall |
SonicWALL |
Firewall |
|
9 |
Cisco-fw |
CISCO |
Firewall |
|
10 |
Squid |
Squid |
Proxy |
|
11 |
Apache |
Apache |
Application |
|
12 |
Xcitium Endpoint Security |
Xcitium |
Content Security |
|
13 |
MyDLP |
Xcitium |
Data Protection |
|
14 |
Snort |
CISCO |
Intrusion Detection |
|
15 |
Tipping Point |
HP |
Intrusion Detection |
|
16 |
Web Inspector |
Xcitium |
Malware |
|
17 |
VPN |
Open VPN |
Access |
|
18 |
DHCP |
Linux |
Access |
|
19 |
Fortigate |
Fortinet |
Firewall |
|
20 |
Xcitium DPI |
Xcitium |
Access |
|
21 |
Xcitium DPI Bro |
Xcitium |
Access |
|
22 |
Snmp Trap Logs |
Snmp |
Audit |
|
23 |
Fortigate 5.0 |
Fortinet |
Firewall |
|
24 |
Sophos Ulogd |
Sophos |
Firewall |
|
25 |
Bro_HTTP |
BRO |
Access |
|
26 |
Bro_FTP |
BRO |
Access |
|
27 |
Bro_Weird |
BRO |
Network Monitoring |
|
28 |
Bro_Files |
BRO |
Access |
|
29 |
Bro_Conn |
BRO |
Firewall |
|
30 |
Bro_Dpd |
BRO |
Access |
|
31 |
Bro_Smtp |
BRO |
Access |
|
32 |
Bro_Dns |
BRO |
Access |
|
33 |
Windows Audit |
Windows |
Audit |
|
34 |
Alarms |
Xcitium Alarm Producer |
Audit |
|
35 |
Cef |
Common Event Format |
Access |
|
36 |
Bro_Ssl |
BRO |
Network Monitoring |
|
37 |
Bro_Irc |
BRO |
Network Monitoring |
|
38 |
Bro_Dhcp |
BRO |
Network Monitoring |
|
39 |
Suricata |
OISF |
Intrusion Detection |
|
40 |
NxIDS |
Xcitium |
Intrusion Detection |
|
41 |
NxSensor_HTTP |
Xcitium |
Access |
|
42 |
NxSensor_FTP |
Xcitium |
Access |
|
43 |
NxSensor_Files |
Xcitium |
Access |
|
44 |
NxSensor_Conn |
Xcitium |
Firewall |
|
45 |
NxSensor_Dpd |
Xcitium |
Access |
|
46 |
NxSensor_Smtp |
Xcitium |
Access |
|
47 |
NxSensor_Dns |
Xcitium |
Access |
|
48 |
NxSensor_Ssl |
Xcitium |
Network Monitoring |
|
49 |
NxSensor_Irc |
Xcitium |
Network Monitoring |
|
50 |
NxSensor_Dhcp |
Xcitium |
Network Monitoring |
|
51 |
NxSensor_Weird |
Xcitium |
Network Monitoring |
|
52 |
analyser |
Xcitium |
Audit |
|
53 |
dome-eapi |
Xcitium |
Audit |
|
54 |
dome-vs |
Xcitium |
Audit |
|
55 |
linux |
Xcitium |
Audit |
|
56 |
JUNOS SYS |
Juniper |
Firewall |
|
57 |
Xcitium-rdns |
Xcitium |
Network Monitoring |
|
58 |
dome-cni |
Xcitium |
Audit |
|
59 |
Bro_Tunnel |
BRO |
Network Monitoring |
|
60 |
Bro_Software |
BRO |
Network Monitoring |
|
61 |
Bro_Pe |
BRO |
Network Monitoring |
|
62 |
Bro_SSH |
BRO |
Network Monitoring |
|
63 |
Bro_MySQL |
BRO |
Network Monitoring |
|
64 |
Bro_Notice |
BRO |
Network Monitoring |
|
65 |
Bro_Fls |
BRO |
Network Monitoring |
|
66 |
NxSensor_Tunnel |
Xcitium |
Network Monitoring |
|
67 |
NxSensor_Software |
Xcitium |
Network Monitoring |
|
68 |
NxSensor_Pe |
Xcitium |
Network Monitoring |
|
69 |
NxSensor_SSH |
Xcitium |
Network Monitoring |
|
70 |
NxSensor_MySQL |
Xcitium |
Network Monitoring |
|
71 |
NxSensor_Notice |
Xcitium |
Network Monitoring |
|
72 |
NxSensor_Fls |
Xcitium |
Network Monitoring |
|
73 |
modsecurity |
Xcitium |
ModSecurity Audit |
|
74 |
Bro_Syslog |
Xcitium |
Network Monitoring |
|
75 |
NxSensor_Syslog |
Xcitium |
Network Monitoring |
|
76 |
cpanelaccess |
CPanel Inc |
Audit |
|
77 |
cpanellogin |
CPanel Inc |
Audit |
|
78 |
Panos |
Palo Alto Inc. |
Firewall |
|
79 |
MySQL_Slow_Queries |
Oracle |
Database |
|
80 |
Apache-Error |
Apache |
Application |
|
81 |
MySQL_Error |
Oracle |
Database |
|
82 |
NxSensor_Fvs |
Xcitium |
File Monitoring |
|
83 |
SOCaaP Endpoint |
Xcitium |
Application |
|
84 |
modsecurity-java |
Xcitium |
Audit |
|
85 |
Internal Events |
Xcitium Internal Event Producer |
Audit |
|
86 |
DbCollector |
Xcitium Db Collector |
Audit |
