SIEM Configured Messages
The following messages are configured for sending through SIEM:
Messages Type(SUID)
SUID | Events |
---|---|
8 | Loss / Recovery Connectivity |
9 | Password change performed |
15 | Backup Performed |
17 | Password changed |
153 | Session Started / Ended |
164 | Password Displayed |
dst | IP of event target device |
dhost | Hostname of device affected by event |
Backup
Key | Example | Description |
---|---|---|
msg | Backup sent to server ’localhost:/srv/backup’ via local | |
suid | Message Type | |
sname | Asynchronous Script: 8 | Backup Script Identifier |
suser | Not applicable | |
spid | Notification Unique Identifier | |
dhost | localhost | Name of server where backup is generated |
Loss of Connectivity
Key | Example | Description |
---|---|---|
msg | Localhost appliance (127.0.0.1) has lost SSH connectivity | |
suid | Message Type | |
sname | Asynchronous Script9 | Name of user who has lost connectivity |
suser | Not applicable | |
spid | Notification Unique Identifier | |
dst | .0.1 | Device IP |
dhost | localhost | Name of server where backup is generated |
dport | Device’s Port |
Restored Connectivity
Key | Example | Description |
---|---|---|
msg | Localhost appliance (127.0.0.1) has recovered SSH connectivity | |
suid | Message Type | |
sname | Asynchronous Script: 9 | Name of the user who had the session reinstated |
suser | Not applicable | |
spid | Notification Unique Identifier | |
dst | .0.1 | Device IP |
dhost | localhost | Name of server where backup is generated |
dport | Device’s Port |
Password changed
Key | Example | Description |
---|---|---|
msg | Password localhost (127.0.0.1) - Domain User - root changed by user stlee | |
suid | Notification Unique Identifier | |
sname | Stephen Lee | Username that changed the password |
suser | Not applicable | |
spid | Notification Unique Identifier | |
duser | root | Password Username changed |
duid | ||
dst | .0.1 | Device IP |
dhost | localhost | Password device name |
Password viewed
Key | Example | Description |
---|---|---|
msg | Password localhost (127.0.0.1) - Domain User - root changed by user stlee | |
suid | Message Type | |
sname | Stephen Lee | User who viewed the password |
suser | Not applicable | |
spid | Notification Unique Identifier | |
duser | root duid=35 | Username of password displayed |
dst | .0.1 | Password Device IP |
dhost | localhost | Password device name |
Session Ended
Key | Example | Description |
---|---|---|
msg | Session terminated for localhost (127.0.0.1) - Privileged Domain User - srv_admin by the user Stephen Lee (stlee) | |
suid | Identify the message type | |
sname | Stephen Lee | User who logged out |
suser | stlee | Login of the user who logged out |
spid | Notification Unique Identifier | |
dst | .0.1 | Device’s IP |
dposrt | Device’s Port | |
duser | srv_admin | Login used in remote session |
Session Started
Key | Example | Description |
---|---|---|
msg | Session started for localhost (127.0.0.1) - Privileged Domain User - root by the user Stephen Lee (stlee) | |
suid | Identify the message type | |
sname | Stephen Lee | Login User |
suser | stlee | Login of the logged in user |
spid | Notification Unique Identifier | |
dst | .0.1 | Device’s IP |
dpt | Device’s Port | |
duser | root | Login used in remote session |
Exchange performed
Key | Example | Description |
---|---|---|
msg | Session terminated for localhost (127.0.0.1) - Privileged Domain User - by the user Stephen Lee (stlee) | |
suid | Message Type | |
sname | Asynchronous Script: 17 | Password exchange script identifier |
suser | not used in this interface | |
spid | Identify the message type | |
dst | .0.1 | Device’s IP |
duser | root | password changed user |
Audited command executed
Key | Example | Description |
---|---|---|
msg | An audited command has been detected! Action: ”[system action]” | |
suid | User logged in | |
sname | Stephen Lee | User that started the session |
suser | stlee | Login of the user that started the session |
spid | Not applicable | |
dst | Not applicable | |
dpt | Not applicable | |
duser | Not applicable |
Information viewed
Key | Example | Description |
---|---|---|
msg | Information ’my example’ has been visualized. | |
suid | Logged User | |
sname | Stephen Lee | User that started the session |
suser | stlee | Login of the user that started the session |
spid | Message Type | |
dst | Not applicable | |
dpt | Not applicable | |
duser | Not applicable |
Information changed
Key | Example | Description |
---|---|---|
msg | Information ’my example’ has been changed. | |
suid | Logged user | |
sname | Stephen Lee | User that started the session |
suser | stlee | Login of the user that started the session |
spid | Message Type | |
dst | Not applicable | |
dpt | Not applicable | |
duser | Not applicable |
Password Access Request
Key | Example | Description |
---|---|---|
msg | User ’Stephen Lee’ has created a request. Request Details: View password action for cqss credential on win2012 device (192.168.10.156) | |
suid | Logged User | |
sname | Stephen Lee | Name of the logged user |
suser | stlee | logged user’s username |
spid | Process PID | |
dst | .10.156 | Target IP |
dpt | Not applicable | |
duser | cqss | User requested |
cs1Label | GMUD | Field’s label |
cs1 | File’s ID | |
cs2Label | Validity Start | Field’s label |
cs2 | -01-19 10:41:00 | Request Start Date |
cs3Label | Validity End | Field’s label |
cs3 | -01-19 11:41:00 | Request expiration date |
cs4Label | Approver | Field’s label |
cs4 | Administrator | Approved User |
cs5Label | Requester | Field label |
cs5 | Stephen | Field’s label |
Cs6 | Action | Field’s label |
Cs7 | View password | Action’s description |
Request approved
Key | Example | Description |
---|---|---|
msg | Application approved by Administrator on 19/01/2017 10:44:30. Code: S000296 Requestor: Steven Lee Requested on: 19/01/2017 10:44:13 Request detail: View password action for cqss credential on device win2012 (192.168.10.156) | |
suid | Logged User | |
sname | Leia West | Name of the logged user |
suser | lwest | logged user’s username |
spid | Process PID | |
dst | .10.156 | Target IP |
dpt | Not used | |
duser | cqss | Requested Credential User |
cs1Label | GMUD | Field’s label |
cs1 | File’s ID | |
cs2Label | Validity End | Field’s label |
cs2 | -01-19 10:41:00 | Request Start Date |
cs3Label | Validity End | Field’s label |
cs3 | -01-19 11:41:00 | Request Expiration Date |
cs4Label | Approver | Field’s label |
cs4 | Administrator | Approver User |
cs5Label | Requester | Field’s label |
cs5 | Steven Lee | Requesting User |
Cs6 | Action | Field’s label |
Cs7 | View Password | Action’s description |
Request disapproved
Key | Example | Description |
---|---|---|
msg | Information ’test’ viewed. | |
suid | Logged User | |
sname | Steven Lee | Name of the logged user |
suser | stlee | logged user’s username |
spid | Process PID | |
dst | .10.156 | Target IP |
dpt | Not used | |
duser | cqss | Requested user login |
cs1Label | GMUD | Field’s label |
cs1 | File’s ID | |
cs2Label | Validity Start | Field’s label |
cs2 | -01-19 10:41:00 | Request start date |
cs3Label | Validity End | Field’s label |
cs3 | -01-19 11:41:00 | Request expiration date |
cs4Label | Approver | Field’s label |
cs4 | Administrator | Approver User |
cs5Label | Requester | Field’s label |
cs5 | Leia West | User Requester |
Cs6 | Action | Field’s Label |
Cs7 | View password | Action description |
Command Detected - Lock and Stop Session
Key | Example | Description |
---|---|---|
msg | An audited command has been detected! Action: Command blocked and session interrupted | |
suid | Logged user | |
sname | Caleb | User that started the session |
suser | caleb | Username of the user that started the session |
spid | Message Type | |
dst | .0.1 | Target IP |
dpt | Port used | |
duser | usrmanut | User used to start the session |
Command Detected - Block
Key | Example | Description |
---|---|---|
msg | An audited command has been detected! Action: Command Notified and Allowed | |
suid | Logged User | |
sname | Caleb | User that started the session |
suser | caleb | Username of the user that started the session |
spid | Message Type | |
dst | .0.1 | Target IP |
dpt | Port used | |
duser | usrmanut | User used to start the session |
Password change error
Key | Example | Description |
---|---|---|
msg | Error changing password ’Windows SQL Test Remote App (192.168.30.55) - Domain User – ’stleeadm’: The device ’Windows SQL Test Remote App (192.168.30.55)’ has no Windows RPC connectivity | |
suid | Logged User | |
sname | Stephen Lee | Name of the user that started the session |
suser | stlee | Username of the user that started the session |
spid | Message Type | |
dst | .30.55 | Target IP |
dpt | Not applicable | |
duser | stleeadm | User used to start the session |
Warehouse archive changed
Key | Example | Description |
---|---|---|
msg | A session file has been modified! | |
suid | User logged | |
sname | Asynchronous Script: 12 | Name of the logged user |
suser | asc_12 | Username of the logged user |
spid | Process PID | |
dst | Not applicable | |
dpt | Not applicable | |
duser | Not applicable | |
cs1Label | Id | Field’s Label |
cs1 | File’s ID | |
cs2Label | Initial Size | Field’s Label |
cs2 | Initial file size in bytes | |
cs3Label | Final size | Field label |
cs3 | Final file size in bytes | |
cs4Label | Initial Checksum | Field label |
cs4 | f5751777b74f8e2f2… | Previously file checksum |
cs5Label | Final Checksum | Field’s Label |
cs5 | 284f1555574548901… | Current File Checksum |
Master Key - User viewed his part of the key
Key | Example | Description |
---|---|---|
msg | User has seen his part of the key request. | |
suid | User logged | |
sname | Stephen Lee | Name of the logged user |
suser | stlee | Username of the user that started the session |
Method | POST | |
act | User has seen his part of the key source | |
ServiceName | Backup |
Master Key - User downloaded the PDF with his part of the key
Key | Example | Description |
---|---|---|
msg | User downloaded the PDF with his part of the key request. | |
suid | User logged | |
sname | Stephen Lee | Name of the logged user |
suser | stlee | Username of the user that started the session |
Method | POST | |
act | User downloaded the PDF with his part of the key source | |
ServiceName | Backup |
Master Key - Ceremony process initiated
Key | Example | Description |
---|---|---|
msg | Ceremony process started. | |
suid | User logged | |
sname | José da Silva | Name of the logged user |
suser | jsilva | Username of the user that started the session |
spriv | Administrator | |
Method | POST | Fixed value |
act | Ceremony process started | Action performed |
ServiceName | Backup |
Master Key - Ceremony process finished
Key | Example | Description |
---|---|---|
msg | Ceremony process completed. | |
suid | User logged | |
sname | José da Silva | Name of the logged user |
suser | jsilva | Username of the user that started the session |
spriv | Administrator | |
Method | GET | |
act | Ceremony process completed | |
ServiceName | Backup |
Master Key - Master key guardian inactive
Key | Example | Description |
---|---|---|
msg | Master key guardian inactice. | |
suid | ||
sname | ||
suser | ||
spriv | User | |
dvc | .225.14 | |
spid | ||
act | Incident | |
dproc | master_key_guardian |
Master Key - Failed recovery attempt
Key | Example | Description |
---|---|---|
msg | Failed recovery attempt. | The used key fractions are invalid |
requestMethod | POST | Fixed value |
act | Failed recovery attempt | Master key recovery failure type |
sourceServiceName | Master Key | Operation module |
originIP | .148.162 | Request user IP |
country | Brazil | Request geo location country |
state | Sao Paulo | Request geo location state |
city | Taboao da Serra | Request geo location city |
latitude | Request geo location GPS latitude | |
longitude | Request geo location GPS longitude | |
partsNeeded | Fractions needed to accomplish the recovery | |
partsSent | Attempt number of sent fractions | |
suid | Logged user id | |
sname | Logged user name | |
suser | Logged username | |
spriv | User | Application layer |
dvc | .2.17 | Device host IPv4 |
spid | Internal PID | |
src | .0.1 | Source IP Address |
act | Incident | Action performed |
dproc | master_key_guardian | Destination process name |
Master Key - Successful recovery attempt
Key | Example | Description |
---|---|---|
msg | Successful recovery attempt. | The used key fractions are valid |
requestMethod | POST | Fixed value |
act | Successful recovery attempt | Master key recovery successful type |
sourceServiceName | Master Key | Operation module |
originIP | .10.13 | Request user IP |
country | Brazil | Request geo location country |
state | Sao Paulo | Request geo location state |
city | Taboao da Serra | Request geo location city |
latitude | Request geo location GPS latitude | |
longitude | Request geo location GPS longitude | |
partsNeeded | Fractions needed to accomplish the recovery | |
partsSent | Attempt number of sent fractions | |
suid | Logged user id | |
sname | Logged user name | |
suser | Logged username | |
spriv | User | Application layer |
dvc | .10.20 | Device host IPv4 |
spid | Internal PID | |
src | .10.13 | Source IP Address |
act | Incident | Action performed |
dproc | master_key_guardian | Destination process name |
Scheduling email reports - Creation
Key | Example | Description |
---|---|---|
dvc | .20.30 | senhasegura Server IP |
spid | Process ID in Operating System | |
src | .20.10 | IP of the user who performed the operation |
suid | User ID that performed the operation | |
sname | John Doe | User name that performed the operation |
suser | jdoe | Username of the user who performed the operation |
spriv | Administrator | Privilege Senhora Used to perform the operation |
msg | Report scheduling - Creation | Operation that was performed |
requestMethod | POST | HTTP method used client hair |
act | Report scheduling - Creation | Operation that was performed |
sourceServiceName | Report scheduling | Operation category that was performed |
cs1Label | User | Label from the requesting user name |
cs1 | John Doe | Applicant User Name |
cs2Label | User ID | User ID Label |
cs2 | User ID | |
cs3Label | Schedule | Label from the name of the schedule |
cs3 | My schedule | Scheduling Name |
cs4Label | Schedule ID | Label Scheduling ID |
cs4 | Scheduling ID | |
cs5Label | Added reports | Label from added reports |
cs5 | Settings -> Authentication -> Multi-factor authentication -> Providers | Added reports |
cs7Label | Added users | Label from added users |
cs7 | jdoe - John Doe | Users added to receive notification |
Scheduling email reports - Update
Key | Example | Description |
---|---|---|
dvc | .20.30 | senhasegura Server IP |
spid | Process ID in Operating System | |
src | .20.10 | IP of the user who performed the operation |
suid | User ID that performed the operation | |
sname | John Doe | User name that performed the operation |
suser | jdoe | Username of the user who performed the operation |
spriv | Administrator | Privilege Senhora Used to perform the operation |
msg | Report scheduling - Update | Operation that was performed |
requestMethod | POST | HTTP method used client hair |
act | Report scheduling - Update | Operation that was performed |
sourceServiceName | Report scheduling | Operation category that was performed |
cs1Label | User | Label from the requesting user name |
cs1 | John Doe | Applicant User Name |
cs2Label | User ID | User ID Label |
cs2 | User ID | |
cs3Label | Schedule | Label from the name of the schedule |
cs3 | My schedule | Scheduling Name |
cs4Label | Schedule ID | Label Scheduling ID |
cs4 | Scheduling ID | |
cs5Label | Added reports | Label from added reports |
cs5 | None | Added reports |
cs6Label | Removed reports | Label from the reports removed |
cs6 | None | Removed reports |
cs7Label | Added users | Label from added users |
cs7 | None | Added Users |
cs8Label | Removed users | Label from users removed |
cs8 | None | Removed users |
Scheduling email reports - Deletion
Key | Example | Description |
---|---|---|
dvc | .20.30 | senhasegura Server IP |
spid | Process ID in Operating System | |
src | .20.10 | IP of the user who performed the operation |
suid | User ID that performed the operation | |
sname | John Doe | User name that performed the operation |
suser | jdoe | Username of the user who performed the operation |
spriv | Administrator | Privilege Senhora Used to perform the operation |
msg | Report scheduling - Deletion | Operation that was performed |
requestMethod | POST | HTTP method used client hair |
act | Report scheduling - Deletion | Operation that was performed |
sourceServiceName | Report scheduling | Operation category that was performed |
cs1Label | User | Label from the requesting user name |
cs1 | John Doe | Applicant User Name |
cs2Label | User ID | User ID Label |
cs2 | User ID | |
cs3Label | Schedule | Label from the name of the schedule |
cs3 | My schedule | Scheduling Name |
cs4Label | Schedule ID | Label Scheduling ID |
cs4 | Scheduling ID |
info
See the Appendix chapter to consult the Table with Possible Values for System Services and Listeners