Skip to main content

The Devo Parser is one of the secret spices of our unique Hyperstream technology. The Parsers organize raw events stored in tags in different columns and display them in the corresponding tables. This method completely bypasses data indexing and contributes to Devo’s amazing search speeds. Every data source is unique, so we have a great catalog of existing parsers. Our teams review parser performance, build new parsers and update parsers on a regular basis. This article covers all the updated and new parsers available this month. If you require a new parser, please open a support ticket through the support portal located here. You can also visit the new Resources Portal, a single page for all your customer resources!

 

Table of Contents

 

Updated Parsers

cloud.azure

Link to Documentation

Change Log

  • New fields added to the union for cloud.zure.ad.audit

 

box.win_nxlog

Link to Documentation

Change Log

  • Added new fields for box.win_nxlog*

 

box.win_snare

Link to Documentation

Change Log

  • Added new table for box.win_snare.fim

  • Added new fields and refactored powershell logs for box.win_snare*

  • Parser adapted to variable number of spaces between keys and values

  • Two new event types parsed

  • New log source added Sysmon

 

firewall.sophos

Link to Documentation

Change Log

  • Made timestamp a string so timezone is preserved for firewall.sophos.securenet.packetfilter

 

firewall.cisco

Link to Documentation

Change Log

  • Added new types for firewall.cisco.ftd

 

box.all.win

Link to Documentation

Change Log

  • Added new fields for box.all.win

 

firewall.fortinet

Link to Documentation

Change Log

  • Added missing fields from tables:

    • firewall.fortinet.event

    • firewall.fortinet.event.connector

    • firewall.fortinet.event.dhcp

 

Iam.pingdentity

Documentation in Progress

Change Log

  • Added new table for iam.pingidentity.pingaccess.server

 

cef0.checkpoint

Link to Documentation

Change Log

  • Added a new fields for: 

    • cef0.checkPoint.unknown

    • cef0.checkPoint.connectra

 

 

 

 

 

 

 

It would be helpful to have a change log on the Devo Docs pages with details of the low level changes.

 

For example, this update outlines there are new fields in the box.win_nxlog tables. Going to that page doesn't tell me exactly what new fields have been added. How am i supposed to tell which are the new fields with out keeping a copy of the fields before the changes to compare?


Check the date of the page, some pages might still be in progress of updating.  Normally these changes are integrated when the page is updated.