---
title: "ids.juniper"
canonical: "https://docs.devo.com/space/latest/366837762/ids.juniper"
format: markdown
---
> Macro (toc)

## Introduction

The tags beginning with `ids.juniper` identify events generated by [Juniper](https://www.juniper.net/).

## Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as** **`ids.juniper`. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

| **Product / Service** | **Tags** | **Data tables** |
| --- | --- | --- |
| Juniper SRX Firewall | `ids.juniper.srx` | `ids.juniper.srx` |

For more information, read more [About Devo tags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126204).

## Table structure

These are the fields displayed in this table:

### ids.juniper.srx

| **Field** | **Type** | **Source field name** | ***Extra***** fields** |
| --- | --- | --- | --- |
| *eventdate* | `timestamp` |  |  |
| *host* | `str` | *vhost* |  |
| *eventType* | `str` | * * |  |
| *user* | `str` | * * |  |
| *attackName* | `str` | * * |  |
| *sourceAddress* | `str` | * * |  |
| *destinationAddress* | `str` | * * |  |
| *sourceZoneName* | `str` | * * |  |
| *interfaceName* | `str` | * * |  |
| *protocolId* | `str` | * * |  |
| *action* | `str` | * * |  |
| *hostchain* | `str` | * * | **✓** |
| *tag* | `str` | * * | **✓** |
| *rawMessage* | `str` | *rawSource* | **✓** |