Administration Guide

  • Docs Home
  • Community Home

3. Tales Event Attributes

The following table lists available event attributes.

AttributeDescription
agentCollector name from which the event came (such as zensyslog or zentrap).
componentComponent of the associated device, if applicable. (Examples: eth0, httpd.)
countNumber of times this event has been seen.
dedupidKey used to correlate duplicate events. By default, this is: device, component, eventClass, eventKey, severity.
deviceID of the associated device, if applicable.
DeviceClassDevice class from device context.
DeviceGroupsDevice systems from device context, separated by |.
eventClassEvent class associated with this device. If not specified, may be added by the rule process. If this fails, then will be /Unknown.
eventClassKeyKey by which rules processing begins. Often equal to component.
eventGroupLogical group of event source (such as syslog, ping, or nteventlog).
eventKeyPrimary criteria for mapping events into event classes. Use if a component needs further de-duplication specification.
eventStateState of event. 0 = new, 1 = acknowledged, 2 = suppressed.
evidUnique ID for the event.
facilitysyslog facility, if this is a syslog event.
firstTimeUNIX timestamp when event is received.
ipAddressIP Address of the associated device, if applicable.
lastTimeLast time this event was seen and its count incremented.
LocationDevice location from device context.
managerFully qualified domain name of the collector from which this event came.
messageFull message text.
ntevidnt event ID, if this is an nt eventlog event.
prioritysyslog priority, if this is a syslog event.
prodStateprodState of the device context.
severityOne of 0 (Clear), 1 (Debug), 2 (Info), 3 (Warning), 4 (Error) or 5 (Critical).
stateChangeTime the MySQLrecord for this event was last modified.
summaryText description of the event. Limited to 150 characters.
suppidID of the event that suppressed this event.
SystemsDevice systems from device context, separated by |.

zProperties and Custom Properties

zProperties and custom properties also are available for devices, and use the same syntax as shown in the previous sections.