---
title: "box - Operating Systems"
canonical: "https://docs.devo.com/space/latest/94664767/box%20-%20Operating%20Systems"
format: markdown
---
This group includes tags that start with the level `box`. These tags identify data generated by operating systems.

| **Company** | **Product / Service** | **Data tables** |
| --- | --- | --- |
| - | - | - `box.all.win`<br>> ⚠️ **Union table - box.all.win**
> ⚠️ 
> ⚠️ This is a union table that collects events from a set of tables for easy access and analysis.
> ⚠️ 
> ⚠️ Learn more about this union table [in this article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126130). |
| ![image](media://57e9959d-7ba6-4a5c-8fa7-1ab8e5e35aa0) | IBM AS/400 | - `box.as400.audit.type2`
- `box.as400_townsend.logagent.audit`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94665044) |
| IBM z/OS | - `box.ibm.z_os.leef`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348291083) |
| - `box.zos`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348323852) |
| ![image](media://485a983e-6bc9-4eda-b142-ae6f08aa8dc7) | UNIX audit | - `box.audit.unix`<br>> ⚠️ **Union table - box.audit.unix**
> ⚠️ 
> ⚠️ This is a union table that collects events from a set of tables for easy access and analysis.
> ⚠️ 
> ⚠️ Learn more about this union table [in this article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126130).<br>- `box.audit.unix.audispd`
- `box.audit.unix.auditd`
- `box.audit.unix.goAudit`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94664891) |
| UNIX osquery | - `box.osquery.unix.info`
- `box.osquery.unix.results`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348454923) |
| UNIX system logs | - `box.unix`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94664846) |
| UNIX 8 system logs | - `box.unix8`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348094612) |
| CloudWatch logs on UNIX | - `box.unix_cloudwatch`<br>[More information](/wiki/spaces/latest/pages/348160047) |
| UNIX stat logs | - `box.stat.unix.diskstat`
- `box.stat.unix.dstatLt1`
- `box.stat.unix.tags`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348225610) |
| ![image](media://3bc9d351-5c1d-4eac-b525-a3897e575764) | Docker container logs | - `box.docker.stats`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/366968851) |
| ![image](media://3d7e3eb8-0c2a-4c51-9ba3-4c021a4e9b01) | Linux iptables | - `box.iptables`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94664835) |
| ![image](media://6c0fb7f9-5090-4142-b32b-f3ef6bc875bf) | macOS | - `box.macos`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94664943) |
| macOS NXLog | - `box.osx_nxlog`<br>[More information](/wiki/spaces/latest/pages/367067155) |
| ![image](media://7cf2d47a-a561-41a7-8551-c20c21bd2b16) | VMware | - `box.vmware.esx`
- `box.vmware.firewall`
- `box.vmware.vcenter`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94665003) |
| ![image](media://cc1b25e6-b3e9-423f-a917-9498da3674a6) | Microsoft Azure | - `box.stat.azure.dstatLt1`
- `box.stat.azure.tags`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348225610) |
| Windows events | > ⚠️ **Deprecated parser**
> ⚠️ 
> ⚠️ Note that the `box.win` parser is deprecated and no longer supported by Devo. We recommend to use the corresponding `box.win_*` parser for your specific technology. Learn more about these parsers below in this table.<br>- `box.win`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94664961) |
| Windows Classic | - `box.win_classic`
- `box.win_classic.application`
- `box.win_classic.other`
- `box.win_classic.security`
- `box.win_classic.system`<br>[More information](/wiki/spaces/latest/pages/367231004) |
| Windows CloudWatch | - `box.win_cloudwatch`<br>[More information](/wiki/spaces/latest/pages/209125379) |
| Windows InTrust | - `box.win_intrust`
- `box.win_intrust.application`
- `box.win_intrust.invalid`
- `box.win_intrust.other`
- `box.win_intrust.security`
- `box.win_intrust.system`<br>[More information](/wiki/spaces/latest/pages/94664909) |
| Windows Kinesis Agent | - `box.win_kinesis`
- `box.win_kinesis.application`
- `box.win_kinesis.invalid`
- `box.win_kinesis.security`
- `box.win_kinesis.system`<br>[More information](/wiki/spaces/latest/pages/367394844) |
| Windows NXLog | - `box.win_nxlog`
- `box.win_nxlog.adfs`
- `box.win_nxlog.application`
- `box.win_nxlog.dns`
- `box.win_nxlog.group_policy`
- `box.win_nxlog.invalid`
- `box.win_nxlog.other`
- `box.win_nxlog.powershell`
- `box.win_nxlog.print`
- `box.win_nxlog.remote_conn`
- `box.win_nxlog.security`
- `box.win_nxlog.smb`
- `box.win_nxlog.sysmon`
- `box.win_nxlog.system`
- `box.win_nxlog.windows_powershell`<br>[More information](/wiki/spaces/latest/pages/94664981) |
| WinQuest | - `box.win_quest.change_auditor.leef`<br>[More information](/wiki/spaces/latest/pages/367460391) |
| Snare Windows Agent | - `box.win_snare`
- `box.win_snare.application`
- `box.win_snare.other`
- `box.win_snare.powershell`
- `box.win_snare.security`
- `box.win_snare.setup`
- `box.win_snare.system`<br>[More information](/wiki/spaces/latest/pages/94664866) |
| SolarWinds | - `box.win_solarwinds`
- `box.win_solarwinds.application`
- `box.win_solarwinds.other`
- `box.win_solarwinds.powershell`
- `box.win_solarwinds.security`
- `box.win_solarwinds.setup`
- `box.win_solarwinds.system`<br>[More information](/wiki/spaces/latest/pages/366968940) |
| Windows System Monitor (Sysmon) | - `box.win_sysmon`<br>[More information](/wiki/spaces/latest/pages/367263839) |
| Winlogbeat | - `box.win_winlogbeat`
- `box.win_winlogbeat.adpwprotect`
- `box.win_winlogbeat.application`
- `box.win_winlogbeat.applocker`
- `box.win_winlogbeat.authentication`
- `box.win_winlogbeat.bitsClient`
- `box.win_winlogbeat.codeintegrity`
- `box.win_winlogbeat.deviceguard`
- `box.win_winlogbeat.forwarding`
- `box.win_winlogbeat.kernelPnp`
- `box.win_winlogbeat.ntlm`
- `box.win_winlogbeat.oalerts`
- `box.win_winlogbeat.powershell`
- `box.win_winlogbeat.security`
- `box.win_winlogbeat.securityMitigations`
- `box.win_winlogbeat.setup`
- `box.win_winlogbeat.smb`
- `box.win_winlogbeat.sysmon`
- `box.win_winlogbeat.system`
- `box.win_winlogbeat.taskscheduler`
- `box.win_winlogbeat.terminalservices`
- `box.win_winlogbeat.win32k`
- `box.win_winlogbeat.windows_defender`
- `box.win_winlogbeat.windows_firewall`
- `box.win_winlogbeat.windowsupdateclient`
- `box.win_winlogbeat.wmiActivity`<br>[More information](/wiki/spaces/latest/pages/367493206) |
| Windows stat logs | - `box.stat.win.diskstat`
- `box.stat.win.dstatLt1`
- `box.stat.win.heartbeat`
- `box.stat.win.tags`<br>[More information](https://devodocs.atlassian.net/wiki/spaces/latest/pages/348225610) |