Class CommonEvent

  • Direct Known Subclasses:
    CefRev23

    public abstract class CommonEvent
    extends Object
    Implements a struct like class that holds headers and extension fields defined in the Common Event Format maintained by HP Enterprise and used by a number of cyber security solutions.
    • Constructor Detail

      • CommonEvent

        public CommonEvent()
        Default constructor for Common Events
    • Method Detail

      • setHeader

        public abstract void setHeader​(Map<String,​Object> headers)
                                throws CEFHandlingException
        Set headers using named key to object value
        Parameters:
        headers - A map containing the keys and values of headers of CEF event
        Throws:
        CEFHandlingException - when it has issues writing the values of the headers
      • setExtension

        public abstract void setExtension​(Map<String,​String> extensions)
                                   throws CEFHandlingException
        Set extensions using named key to object value
        Parameters:
        extensions - A map containing the keys and values of extensions of CEF event
        Throws:
        CEFHandlingException - when it has issues populating the extensions
      • setExtension

        public abstract void setExtension​(Map<String,​String> extensions,
                                          boolean allowNulls)
                                   throws CEFHandlingException
        Set extensions using named key to object value with specified handling for null values
        Parameters:
        extensions - A map containing the keys and values of extensions of CEF event
        allowNulls - If true, extensions with an empty value will be seen as null. If false, parsing may fail depending on extension types
        Throws:
        CEFHandlingException - when it has issues populating the extensions
      • getExtension

        public abstract Map<String,​Object> getExtension​(boolean populatedOnly)
                                                       throws CEFHandlingException
        Get map of named extensions
        Parameters:
        populatedOnly - Boolean defining if Map should include all fields supported by the supported CEF standard
        Returns:
        A map containing the keys and values of CEF extensions
        Throws:
        CEFHandlingException - when it hits issues (e.g. IllegalAccessException) reading the extensions
      • getExtension

        public abstract Map<String,​Object> getExtension​(boolean populatedOnly,
                                                              boolean includeCustomExtensions)
                                                       throws CEFHandlingException
        Get map of named extensions after applying specified filtering
        Parameters:
        populatedOnly - Boolean defining if Map should include all fields supported by CefRev23
        includeCustomExtensions - Boolean defining if Map should include parsed keys that are not supported part of the base CEF Rev23 specification
        Returns:
        A map containing the keys and values of CEF extensions
        Throws:
        CEFHandlingException - when it hits issues (e.g. IllegalAccessException) reading the extensions