Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

Example of the Telemetry events generated by a Snare Enterprise Agent for Windows:

Note

This example shows the events in Snare format. The first four fields are the event header and may be formatted differently in other event formats (i.e. SYSLOG)

Below is a table describing the contents of a Telemetry Event generated by Snare Agent. 

FieldTypeDescription
HostnameStringThe host name of the originating computer.
EventTypeStringTelemetryLog - the type of event generated.

SecurityLevel

IntegerThe severity level (Criticality) of the generated event.
TimeCreatedDatetimeThe time at which the telemetry event was . (YYYY-MM-DDThh:mm:ss)
DigestTypeStringSHA512 - the hashing algorithm used.
EventActionStringOne of CHANGE, DELETE, RENAME or NEW.
MetricTypeStringCPU|DSK|MEM|NET

InstanceName

(May change to ObjectName)

StringThe name of the hardware interface the event is sourced.
EventNameStringThe name of the metric of the hardware interface.
ValueFloatThe value of the metric.
ObjectOwnerStringThe owner of the object that the change was detected on.
ObjectMTimeDatetimeThe modification time (mtime) of the object when the change is detected. (YYYY-MM-DDThh:mm:ss)
EventChecksumStringThe calculated digest (checksum) value.

Please refer to The Web User Interface (UI) File Integrity Monitoring page in this User Guide for instructions on how to configure periodic FIM scans in the Snare Agent.

  • No labels