Symantec 10521146 Administration Guide - Page 329

Table B-2, Field Name, Description, Notes, Oracle Event Table

Page 329 highlights

SQL reference 329 Using Oracle tables Table B-2 Field Name atkproc atkuser class clusterID contextBuffer contextDesc crtTime custID dips dst_etheraddr dvName endTime eventCode eventNum Oracle Event Table Type Description Notes varchar(3000) varchar(255) varchar(33) integer varchar(512) varchar(512) integer varchar(41) varchar(195) varchar(33) varchar(41) integer varchar(65) integer Indicates the process name of the attacker, or blank if not applicable. Indicates the username of the attacker, or blank if not applicable. Indicates the event class. sniffer - for security events generic - for operational events, etc. Indicates the user-defined Network Security cluster ID where the incident originated. Indicates additional information sent by the sensor. Not every event will have context information. Example: For HTTP events, this may be a URL. For FTP events, this may be a username. Indicates the description of the data in contextBuffer. Base-64 encoded. Indicates the time when this event was realized in Standard UNIX time the Analysis Framework. format (seconds since 1970 GMT) Indicates the Customer ID that this event is associated with. Indicates a list of destination IPs for this event. Indicates the destination ethernet address. Indicates the name of the network device where the event was detected. Indicates the end time for this event, according to Standard UNIX time the sensor. format. Indicates the Symantec standard code representing the event. Indicates the event number for this incident. The first event in an incident will have an eventNum of 1. The eventNum will be incremented by 1 for each subsequent event.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

329
SQL reference
Using Oracle tables
atkproc
varchar(3000)
Indicates the process name of the attacker, or
blank if not applicable.
atkuser
varchar(255)
Indicates the username of the attacker, or blank if
not applicable.
class
varchar(33)
Indicates the event class.
sniffer
- for
security events
generic
- for
operational events,
etc.
clusterID
integer
Indicates the user-defined Network Security
cluster ID where the incident originated.
contextBuffer
varchar(512)
Indicates additional information sent by the
sensor. Not every event will have context
information.
Example: For HTTP
events, this may be a
URL. For FTP events,
this may be a
username.
contextDesc
varchar(512)
Indicates the description of the data in
contextBuffer
.
Base-64 encoded.
crtTime
integer
Indicates the time when this event was realized in
the Analysis Framework.
Standard UNIX time
format (seconds since
1970 GMT)
custID
varchar(41)
Indicates the Customer ID that this event is
associated with.
dips
varchar(195)
Indicates a list of destination IPs for this event.
dst_etheraddr
varchar(33)
Indicates the destination ethernet address.
dvName
varchar(41)
Indicates the name of the network device where
the event was detected.
endTime
integer
Indicates the end time for this event, according to
the sensor.
Standard UNIX time
format.
eventCode
varchar(65)
Indicates the Symantec standard code
representing the event.
eventNum
integer
Indicates the event number for this incident. The
first event in an incident will have an
eventNum
of 1. The
eventNum
will be incremented by 1 for
each subsequent event.
Table B-2
Oracle Event Table
Field Name
Type
Description
Notes