Data Source: Ivanti VTM Audit

Description

Data source object for Ivanti Virtual Traffic Manager (vTM)

Details

Property Value
Source ivanti_vtm
Sourcetype ivanti_vtm_audit

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">IP</span>
  
  <span class="pill kill-chain">MODUSER</span>
  
  <span class="pill kill-chain">OPERATION</span>
  
  <span class="pill kill-chain">MODGROUP</span>
  
  <span class="pill kill-chain">AUTH</span>
  
  <span class="pill kill-chain">USER</span>
  
  <span class="pill kill-chain">GROUP</span>
  
</div>

Example Log

1[19/Aug/2024:19:41:22 +0000]    USER=!!ABSENT!! GROUP=!!ABSENT!!        AUTH=!!ABSENT!! IP=!!ABSENT!!   OPERATION=adduser       MODUSER=newadmin        MODGROUP=admin

Source: GitHub | Version: 1