Enum usiem::events::field::SiemField [−][src]
pub enum SiemField {
Text(Cow<'static, str>),
IP(SiemIp),
Domain(String),
User(String),
AssetID(String),
U32(u32),
U64(u64),
I64(i64),
F64(f64),
Date(i64),
}
Variants
A basic String field
IP(SiemIp)
IPv4 or IPv6
Tuple Fields of IP
0: SiemIp
Domain(String)
Tuple Fields of Domain
0: String
User(String)
Tuple Fields of User
0: String
AssetID(String)
This is a special field. Uniquely identifies an asset like a system, a computer or a mobile phone. Reason: the network is dynamic, the IP address is not fixed certain devices and the hostname of a system can be changed.
This field should be used with a dataset to recover information about an asset during the enchance phase: Getting the IP address, the users logged in the system or another information.
Can be multiple AssetsID associated with the same event because multiple virtual machines can be running in the same asset.
Tuple Fields of AssetID
0: String
U32(u32)
unsigned number with 32 bits
Tuple Fields of U32
0: u32
U64(u64)
unsigned number with 64 bits
Tuple Fields of U64
0: u64
I64(i64)
signed number with 64 bits
Tuple Fields of I64
0: i64
F64(f64)
decimal number with 64 bits
Tuple Fields of F64
0: f64
Date(i64)
A date in a decimal number format with 64 bits
Tuple Fields of Date
0: i64
Implementations
Trait Implementations
Auto Trait Implementations
impl RefUnwindSafe for SiemField
impl UnwindSafe for SiemField
Blanket Implementations
Mutably borrows from an owned value. Read more