---
title: "ras.beyondtrust"
canonical: "https://docs.devo.com/space/latest/358875159/ras.beyondtrust"
format: markdown
---
> Macro (toc)

## Introduction

The tags beginning with `ras.beyondtrust` identify events generated by [BeyondTrust](https://www.beyondtrust.com/).

## Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as** **`ras.beyondtrust`. The third level identifies the type of events sent. 

These are the valid tags and corresponding data tables that will receive the parsers' data:

| **Product / Service** | **Tags** | **Data tables** |
| --- | --- | --- |
| BeyondTrust | `ras.beyondtrust.events` | `ras.beyondtrust.events` |

For more information, read more [About Devo tags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126204).

## Send it

Data should be sent using the [relay](https://docs.devo.com/space/latest/96468993/Devo+Relay).

### Example [relay rules](https://docs.devo.com/space/latest/96469377/Defining+a+relay+rule)

```
         Source message: 
            Source data: 
             Source tag: 
             Target tag: ras.beyondtrust.events
Sent without syslog tag: false
        Stop processing: true
```

## Table structure

These are the fields displayed in this table:

### ras.beyondtrust.events

| **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
| --- | --- | --- | --- | --- |
| *eventdate* | `timestamp` |  | * * |  |
| *serverdate* | `timestamp` | ```
parsedate(replace(serverdate_str, "T", " "), dateformat("YYYY-MM-DD HH:mm:ssZZ"))
``` | *serverdate_str* |  |
| *app_name* | `str` |  | * * |  |
| *proc_id* | `str` |  | * * |  |
| *msg_id* | `str` |  | * * |  |
| *sequence_id* | `str` |  | * * |  |
| *side_id* | `str` |  | * * |  |
| *segment_number* | `str` |  | * * |  |
| *total_segments* | `str` |  | * * |  |
| *event_type* | `str` |  | * * |  |
| *reason* | `str` |  | * * |  |
| *site* | `str` |  | * * |  |
| *status* | `str` |  | * * |  |
| *target* | `str` |  | * * |  |
| *when_tmp* | `int8` |  | * * |  |
| *when* | `timestamp` | ```
timestamp(when_tmp * 1000)
``` | *when_tmp* |  |
| *who* | `str` |  | * * |  |
| *who_ip* | `ip4` |  | * * |  |
| *hostchain* | `str` |  | * * | **✓** |
| *tag* | `str` |  | * * | **✓** |
| *rawMessage* | `str` |  | *rawSource* | **✓** |