Skip to content

Module Guidelines

Apply the following guidelines for module names when creating a package:

  • If a module name is already used in other packages, reuse the same name for consistency.
  • If you are adding a new module name make sure that it is clear and concise.

Review this table for examples of module names that are used in parsers for the #event.module tag.

#Vendor#event.module
abnormalemailsecurity
akamaiasec
broadcomproxysg
dellisilon
zscalerzia
Vendor#event.moduleProduct Full Name
1passworddevicetrust1Password Device Trust
1passwordpasswordmanager1Password Password Manager
a10thunderA10 Thunder Application Delivery Controller
abnormalemail-securityAbnormal Email Security
airlockdigitalairlockAirlock Application Control
akamaiapiAkamai API Gateway
akamaiasecAkamai Security Events
akamaicdnAkamai Content Delivery Network
akamaieaaAkamai Enterprise Application Access
akamaiguardicoreAkamai Guardicore Centra
apachehttpserverApache HTTP Server
apachetomcatApache Tomcat
appomnithreatdetectionAppOmni Threat Detection
aristandrArista NDR Platform
armiscentrixiotArmis Centrix IoT Security
arubaclearpassAruba ClearPass
arubaorchestratorAruba Orchestrator
asimilyiomtAsimily IoMT Security Platform
atlassianjiraAtlassian Jira
awsaws-genericAmazon Web Services Generic
awscloudtrailAWS CloudTrail
awscloudwatchAWS CloudWatch
awsconfigAWS Config
awsfsxAmazon FSx
awsguarddutyAWS GuardDuty
awsnetwork-firewallAWS Network Firewall
awsrdsAmazon Relational Database Service
awsroute53Amazon Route 53
awss3accessAmazon S3 Server Access
awssecurity-hubAWS Security Hub
awssecuritylakeAWS Security Lake
awsvpcflowAmazon VPC Flow Logs
awswafAWS Web Application Firewall
barracudacgfBarracuda CloudGen Firewall
barracudaemailgatewaydefenseBarracuda Email Gateway Defense
beyondtrustbeyondinsightBeyondTrust BeyondInsight
boxenterpriseBox Enterprise
broadcombluecoatBroadcom Blue Coat Proxy
broadcomfosBroadcom Fabric Operating System
broadcomproxysgBroadcom ProxySG
broadcomsymantec-endpointprotectionBroadcom Symantec Endpoint Protection
catosaseCato SASE Cloud
cetupipelinesCeTu Pipelines
checkpointharmonyemailcollaborationCheck Point Harmony Email & Collaboration
checkpointngfwCheck Point Next Generation Firewall
ciscoasaCisco Adaptive Security Appliance
ciscoduoCisco Duo Security
ciscofirepowerCisco Firepower
ciscoiosCisco IOS
ciscoiseCisco Identity Services Engine
ciscomerakiCisco Meraki
ciscoprimeCisco Prime
ciscosecure-network-analyticsCisco Secure Network Analytics
ciscosegCisco Secure Email Gateway
ciscothreatgridCisco Threat Grid
ciscoumbrellaCisco Umbrella
citrixadcCitrix Application Delivery Controller
clarotyctdClaroty Continuous Threat Detection
cloudflarewafCloudflare Web Application Firewall
cloudflarezerotrustCloudflare Zero Trust
cofensetriageCofense Triage
contrastsecurityadrContrast Security Application Defense and Response
corelightidsCorelight Network Detection and Response
corelightinvestigatorCorelight Investigator
corelightndrCorelight Network Detection and Response
crowdstrikefalconCrowdStrike Falcon
crowdstrikesaas-securityCrowdStrike SaaS Security
cyberarkvaultCyberArk Privileged Access Security
cyneriohealthcarendrCynerio Healthcare Network Detection and Response
darktracedetectDarktrace Enterprise Immune System
delineasecretserverDelinea Secret Server
dellisilonDell PowerScale OneFS
dellpowerprotectDell PowerProtect Data Manager
dope-securitydope-swgDope Security Secure Web Gateway
dragosplatformDragos Platform
druvarealizeDruva Data Resiliency Cloud
enzoice4adEnzoic for Active Directory
epicsecurityepicEpic Electronic Health Records
extrahoprevealx-360ExtraHop Reveal(x) 360
f5networksbigipF5 BIG-IP
f5networksnginxF5 NGINX
fidelisauditFidelis Audit
fidelisfidelisFidelis Network
forcepointdlpForcepoint Data Loss Prevention
forcepointngfwForcepoint Next Generation Firewall
forgerockidentityForgeRock Identity Platform
fortinetfortigateFortinet FortiGate
fortinetfortimailFortinet FortiMail
fortinetfortindrFortinet FortiNDR
gigamonamiGigamon Application Metadata Intelligence
googlechromeenterpriseGoogle Chrome Enterprise
googlecloudGoogle Cloud Identity
googlegcpGoogle Cloud Platform
googleworkspaceGoogle Workspace
gytpolmisconfigurationsGYTPOL Misconfigurations
haproxyhaproxyHAProxy Load Balancer
hashicorpvaultHashiCorp Vault
impervacloudwafImperva Cloud Web Application Firewall
infobloxniosInfoblox Network Identity Operating System
ironscalesespIRONSCALES Email Security Platform
islandislandIsland Enterprise Browser
junipersrxJuniper SRX Series
keepersecurityenterpriseKeeper Enterprise Password Management
linuxauditdLinux Audit Daemon
linuxlinuxLinux Operating System
linuxsyslogLinux System Logging
logbindersharepointLogBinder SharePoint
lookoutmobileLookout Mobile Endpoint Security
menlomsipMenlo Security Isolation Platform
microsoftadMicrosoft Active Directory
microsoftazureMicrosoft Azure
microsoftazure-devopsMicrosoft Azure DevOps
microsoftdefenderMicrosoft Defender
microsoftdefender-identityMicrosoft Defender for Identity
microsoftedgeMicrosoft Edge
microsoftentraidMicrosoft Entra ID
microsoftexchangeMicrosoft Exchange
microsoftgithubMicrosoft GitHub Enterprise
microsoftiisMicrosoft Internet Information Services
microsoftintuneMicrosoft Intune
microsoftm365Microsoft 365
microsoftmessagetraceMicrosoft Message Trace
microsoftsentinelMicrosoft Sentinel
microsoftsqlMicrosoft SQL Server
microsoftwindowsMicrosoft Windows
microsoftwindows-defender-365Microsoft Defender for Office 365
mimecastemailsecurityMimecast Email Security
nasuniedgeNasuni Edge Appliance
nasunimanagementconsoleNasuni Management Console
netgatepfsenseNetgate pfSense
netskopesseNetskope Security Service Edge
netskopetransactionNetskope Transaction Logs
nozomiidsNozomi Networks Guardian
nozominozomiNozomi Networks Platform
nutanixdatalensNutanix Data Lens
obsidiansecuritysecuritydataObsidian Security Platform
oktassoOkta Single Sign-On
oneidentityoneloginOneLogin Identity Platform
ordrordraiOrdr Systems Control Engine
paloaltodlpPalo Alto Networks Enterprise DLP
paloaltongfwPalo Alto Networks Next-Generation Firewall
paloaltoprismaPalo Alto Networks Prisma Access
paloaltoprismasdwanPalo Alto Networks Prisma SD-WAN
paloaltosaas-securityPalo Alto Networks SaaS Security
pingidentitypingonePingOne Platform
proofpointcasbProofpoint Cloud App Security Broker
proofpointemailprotectionProofpoint Email Protection
proofpointsegProofpoint Email Security Gateway
proofpointtapProofpoint Targeted Attack Protection
pulsesecurePulse Secure VPN
purestorageflasharrayPure Storage FlashArray
purestorageflashbladePure Storage FlashBlade
qualysvmQualys Vulnerability Management
radwarealteonRadware Alteon Application Delivery Controller
radwarewafRadware Cloud Web Application Firewall
raynetraynetoneRayNet One Platform
redhatjbossRed Hat JBoss Enterprise Application Platform
rubriksecuritycloudRubrik Security Cloud
sailpointidentitynowSailPoint IdentityNow
salesforcesalesforceSalesforce Platform
saltsecurityapisecuritySalt Security API Protection Platform
seraphicseraphicsecuritySeraphic Security Platform
servicenowservicenowServiceNow Platform
silverfortitdrSilverfort Identity Threat Detection and Response
skyhighsseSkyhigh Security Service Edge
softerraadaxesSofterra Adaxes
sonicwallsonicosSonicWall SonicOS
sophossfosSophos Firewall Operating System
squidproxySquid Proxy Server
supernasecurityeditionSuperna Eyeglass Data Security Edition
tausightephiTausight ePHI Security Platform
trellixfireeyenxTrellix Network Security
trendmicrovisiononeTrend Micro Vision One
tufinsecuretrackTufin SecureTrack
varonisvaronisVaronis Data Security Platform
vectrabrainVectra Cognito Detect
vectrarespond-uxVectra Respond User Experience
veeamvbrVeeam Backup & Replication
vercaraultradnsVercara UltraDNS
veritiinsightVeriti Security Posture Management
versasaseVersa SASE
versavosVersa Operating System
viaviobserverapexVIAVI Observer Apex
vmwareairwatchVMware Workspace ONE UEM
vmwareesxiVMware ESXi
vmwarevcenterVMware vCenter Server
watchguardfireboxWatchGuard Firebox
workdayworkdayWorkday Platform
zimperiummtdZimperium Mobile Threat Defense
zoomqssZoom Quality of Service Subscription
zoomzoomZoom Communications Platform
zscalerdeceptionZscaler Deception
zscalerziaZscaler Internet Access
zscalerzpaZscaler Private Access