Common substitution variables in Kaspersky Anti Targeted Attack Platform
You can use common variables to substitute current values in Kaspersky Anti Targeted Attack Platform. You can use common variables in the following settings:
- Headers and descriptions of events in user-defined settings for event registration
- Settings of event forwarding, application messages, or audit records using the email connector
To insert a common variable into an input field:
Start typing the name of the variable with the leading $ character and select the common variable from the displayed list.
Common variables can be used for interpolation in different settings, depending on the purpose of the variable (see the table below).
Common variables for value substitution
Variable |
Description |
Usage |
|
Network interaction description strings (one string per network interaction), specifying the protocol and sender and recipient addresses of the network packet |
|
|
Network packet recipient address (depending on the information provided by the protocol, this can be an IP address, port number, MAC address and/or other address information) |
|
|
Extra variable added using the |
|
|
Name of the monitoring point whose traffic caused the event to be registered |
|
|
Date and time of registration |
|
|
Name of the application layer protocol for which the event was logged |
|
|
Network packet sender address (depending on the information provided by the protocol, this can be an IP address, port number, MAC address and/or other address information) |
|
|
Name of the rule in the event. |
|
|
Name of the top-level protocol. |
|
|
Code of the event type, application message, or audit entry. |
|
|
Date and time when a status of Resolved was assigned or the date and time of the event regeneration period (for events that are not aggregate events), or the date and time of registration of the last event included in the incident (for aggregate events). |
|
|
How many times a nested or aggregate event was triggered |
|
|
Description |
|
|
Unique ID of the registered event, application message, or audit entry. |
|
|
Category of transmitted data (event, application message, or audit record). |
|
|
Number of transmitted events, application messages or audit records. |
|
|
Template that consists of a block containing a list of data. |
|
|
Email notification string template |
|
|
Node with the installed application component that sent the data. |
|
|
Operation result in the audit entry. |
|
|
Event score value. |
|
|
Event severity level. |
|
|
Application message status |
|
|
Application process that caused the message to be registered |
|
|
Technology associated with the event. |
|
|
Event title, message text, or registered action. |
|
|
Name of the user that performed the registered action. |
|