Appendix 2 – SOCaaP Supported Logs
The following table provides the details of logs that SOCaaP supports and fetches the data to populate Events fields according to event queries.
S.No. |
Log Name |
Vendor Name |
Log Type |
---|---|---|---|
1 |
Mysql |
Oracle |
Database |
2 |
Oracle |
Oracle |
Database |
3 |
Active Directory |
Unknown |
Audit |
4 |
Windows-Linux Audit |
Xcitium Audit Parser |
Audit |
5 |
Xcitium UTM |
Xcitium |
Audit |
6 |
Juniper |
Juniper Networks |
Firewall |
7 |
IPtables |
Linux |
Firewall |
8 |
Sonicwall |
SonicWALL |
Firewall |
9 |
Cisco-fw |
CISCO |
Firewall |
10 |
Squid |
Squid |
Proxy |
11 |
Apache |
Apache |
Application |
12 |
Xcitium Endpoint Security |
Xcitium |
Content Security |
13 |
MyDLP |
Xcitium |
Data Protection |
14 |
Snort |
CISCO |
Intrusion Detection |
15 |
Tipping Point |
HP |
Intrusion Detection |
16 |
Web Inspector |
Xcitium |
Malware |
17 |
VPN |
Open VPN |
Access |
18 |
DHCP |
Linux |
Access |
19 |
Fortigate |
Fortinet |
Firewall |
20 |
Xcitium DPI |
Xcitium |
Access |
21 |
Xcitium DPI Bro |
Xcitium |
Access |
22 |
Snmp Trap Logs |
Snmp |
Audit |
23 |
Fortigate 5.0 |
Fortinet |
Firewall |
24 |
Sophos Ulogd |
Sophos |
Firewall |
25 |
Bro_HTTP |
BRO |
Access |
26 |
Bro_FTP |
BRO |
Access |
27 |
Bro_Weird |
BRO |
Network Monitoring |
28 |
Bro_Files |
BRO |
Access |
29 |
Bro_Conn |
BRO |
Firewall |
30 |
Bro_Dpd |
BRO |
Access |
31 |
Bro_Smtp |
BRO |
Access |
32 |
Bro_Dns |
BRO |
Access |
33 |
Windows Audit |
Windows |
Audit |
34 |
Alarms |
Xcitium Alarm Producer |
Audit |
35 |
Cef |
Common Event Format |
Access |
36 |
Bro_Ssl |
BRO |
Network Monitoring |
37 |
Bro_Irc |
BRO |
Network Monitoring |
38 |
Bro_Dhcp |
BRO |
Network Monitoring |
39 |
Suricata |
OISF |
Intrusion Detection |
40 |
NxIDS |
Xcitium |
Intrusion Detection |
41 |
NxSensor_HTTP |
Xcitium |
Access |
42 |
NxSensor_FTP |
Xcitium |
Access |
43 |
NxSensor_Files |
Xcitium |
Access |
44 |
NxSensor_Conn |
Xcitium |
Firewall |
45 |
NxSensor_Dpd |
Xcitium |
Access |
46 |
NxSensor_Smtp |
Xcitium |
Access |
47 |
NxSensor_Dns |
Xcitium |
Access |
48 |
NxSensor_Ssl |
Xcitium |
Network Monitoring |
49 |
NxSensor_Irc |
Xcitium |
Network Monitoring |
50 |
NxSensor_Dhcp |
Xcitium |
Network Monitoring |
51 |
NxSensor_Weird |
Xcitium |
Network Monitoring |
52 |
analyser |
Xcitium |
Audit |
53 |
dome-eapi |
Xcitium |
Audit |
54 |
dome-vs |
Xcitium |
Audit |
55 |
linux |
Xcitium |
Audit |
56 |
JUNOS SYS |
Juniper |
Firewall |
57 |
Xcitium-rdns |
Xcitium |
Network Monitoring |
58 |
dome-cni |
Xcitium |
Audit |
59 |
Bro_Tunnel |
BRO |
Network Monitoring |
60 |
Bro_Software |
BRO |
Network Monitoring |
61 |
Bro_Pe |
BRO |
Network Monitoring |
62 |
Bro_SSH |
BRO |
Network Monitoring |
63 |
Bro_MySQL |
BRO |
Network Monitoring |
64 |
Bro_Notice |
BRO |
Network Monitoring |
65 |
Bro_Fls |
BRO |
Network Monitoring |
66 |
NxSensor_Tunnel |
Xcitium |
Network Monitoring |
67 |
NxSensor_Software |
Xcitium |
Network Monitoring |
68 |
NxSensor_Pe |
Xcitium |
Network Monitoring |
69 |
NxSensor_SSH |
Xcitium |
Network Monitoring |
70 |
NxSensor_MySQL |
Xcitium |
Network Monitoring |
71 |
NxSensor_Notice |
Xcitium |
Network Monitoring |
72 |
NxSensor_Fls |
Xcitium |
Network Monitoring |
73 |
modsecurity |
Xcitium |
ModSecurity Audit |
74 |
Bro_Syslog |
Xcitium |
Network Monitoring |
75 |
NxSensor_Syslog |
Xcitium |
Network Monitoring |
76 |
cpanelaccess |
CPanel Inc |
Audit |
77 |
cpanellogin |
CPanel Inc |
Audit |
78 |
Panos |
Palo Alto Inc. |
Firewall |
79 |
MySQL_Slow_Queries |
Oracle |
Database |
80 |
Apache-Error |
Apache |
Application |
81 |
MySQL_Error |
Oracle |
Database |
82 |
NxSensor_Fvs |
Xcitium |
File Monitoring |
83 |
SOCaaP Endpoint |
Xcitium |
Application |
84 |
modsecurity-java |
Xcitium |
Audit |
85 |
Internal Events |
Xcitium Internal Event Producer |
Audit |
86 |
DbCollector |
Xcitium Db Collector |
Audit |