Recopilar registros de Corelight Sensor
En este documento se describe cómo puede recoger registros de Corelight Sensor configurando Corelight Sensor y un reenviador de Google Security Operations. En este documento también se indican los tipos de registros admitidos que genera el sensor de Corelight y las versiones de Corelight compatibles.
Para obtener más información, consulta Ingestión de datos en Google Security Operations.
Antes de empezar
- Verifica la versión de Corelight Sensor. El analizador de Corelight Google SecOps se diseñó para la versión 27.12 y anteriores. Es posible que las versiones posteriores del sensor Corelight tengan registros adicionales que el analizador no reconozca, y que esos registros reciban un análisis de campos limitado o nulo. Sin embargo, el contenido del registro seguirá estando disponible en formato de registro sin procesar en Google SecOps.
- Asegúrate de que todos los sistemas de la arquitectura de implementación estén configurados con la zona horaria UTC.
- Asegúrate de que tienes las credenciales de la documentación de Corelight.
Métodos de implementación e ingestión de registros
En el siguiente diagrama de arquitectura de implementación se muestra cómo se configura un sensor Corelight para enviar registros a Google Security Operations mediante dos arquitecturas de ingesta diferentes. Es importante tener en cuenta que la implementación de cada cliente puede variar con respecto a esta representación y podría ser más compleja.
Una etiqueta de ingestión identifica el analizador que normaliza los datos de registro sin procesar en formato UDM estructurado. La información de este documento se aplica al analizador con la etiqueta de ingestión CORELIGHT.
Ingerir registros en Google SecOps mediante exportadores de Corelight
 
 
En el diagrama de arquitectura se muestran los siguientes componentes:
- Sensor Corelight: el sistema que ejecuta el sensor Corelight . 
- Exportadores de sensores de Corelight: el exportador de sensores de Corelight recoge datos de registro del sensor y los reenvía a Google Security Operations. 
- Google Security Operations: Google Security Operations conserva y analiza los registros de Corelight Sensor. 
Configurar el exportador de registros de Corelight para Google SecOps
- Inicia sesión en Corelight Sensor como administrador. 
- Selecciona la pestaña Exportadores (dinámico) y, a continuación, Google SecOps. 
- Configure los siguientes parámetros de entrada: - Nombre del exportador: el nombre del exportador.
- ID de cliente de Google SecOps: el ID de cliente de Google SecOps.
- Espacio de nombres de Google SecOps: espacio de nombres único asociado a Google SecOps para organizar y gestionar datos.
- Etiquetas de Google SecOps: un conjunto de pares clave-valor que representan las etiquetas.
- Región: la región geográfica en la que se implementa Google SecOps.
- Credenciales: los detalles de autenticación necesarios para conectarse de forma segura y exportar datos a Google SecOps.
- URL del proxy: la URL del servidor proxy que se usa para enrutar el tráfico entre el exportador y Google SecOps.
- Filtro de tipo de registro: especifica si quieres incluir o excluir determinados tipos de registros.
- Registros de Zeek: selecciona los tipos de registro que quieras incluir o excluir marcando todas las opciones aplicables.
 
- Haz clic en Hecho. 
Ingerir registros en Google SecOps mediante un reenviador
 
 
En el diagrama de arquitectura se muestran los siguientes componentes:
- Sensor Corelight: el sistema que ejecuta el sensor Corelight . 
- Exportador de sensores de Corelight: el exportador de sensores de Corelight recoge datos de registro del sensor y los reenvía al reenviador de Google Security Operations. 
- Reenviador de Google Security Operations: el reenviador de Google Security Operations es un componente de software ligero que se implementa en la red del cliente y que admite syslog. El reenviador de Google Security Operations reenvía los registros a Google Security Operations. 
- Google Security Operations: Google Security Operations conserva y analiza los registros de Corelight Sensor. 
Configurar el reenviador de Google Security Operations
Para configurar el reenviador de Google Security Operations, haz lo siguiente:
- Configura un reenviador de Google Security Operations. Consulta Instalar y configurar el reenviador en Linux. 
- Configura el reenviador de Google Security Operations para que envíe registros a Google Security Operations. - collectors: - syslog: common: enabled: true data_type: CORELIGHT data_hint: batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: <Chronicle forwarder listening IP:Port> tcp_buffer_size: 524288 udp_address: <Chronicle forwarder listening IP:Port> connection_timeout_sec: 60
Configurar el exportador de sensores de Corelight
- Inicia sesión en Corelight Sensor como administrador.
- Seleccione la pestaña Exportar.
- Busca y habilita la opción EXPORT TO SYSLOG (EXPORTAR A SYSLOG).
- En EXPORT TO SYSLOG (EXPORTAR A SYSLOG), configura los siguientes campos:
- SERVIDOR SYSLOG: especifica la dirección IP y el puerto del receptor syslog del reenviador de Google Security Operations.
- Ve a Ajustes avanzados > FORMATO SYSLOG y cambia el ajuste a Antiguo.
 
- Haz clic en Aplicar cambios.
Tipos de registros de Corelight admitidos
El analizador de Corelight admite los siguientes tipos de registros generados por el sensor de Corelight.
Log Type
- conn
- conn_long
- conn_red
- dce_rpc
- dns
- dns_red
- files
- files_red
- http
- http2
- http_red
- intel
- irc
- notice
- rdp
- sip
- smb_files
- smb_mapping
- smtp
- smtp_links
- ssh
- ssl
- ssl_red
- suricata_corelight
- bacnet
- cip
- corelight_burst
- corelight_overall_capture_loss
- corelight_profiling
- datared
- dga
- dhcp
- dnp3
- dpd
- encrypted_dns
- enip
- enip_debug
- enip_list_identity
- etc_viz
- ftp
- generic_dns_tunnels
- generic_icmp_tunnels
- icmp_specific_tunnels
- ipsec
- iso_cotp
- kerberos
- known_certs
- known_devices
- known_domains
- known_hosts
- known_names
- known_remotes
- known_services
- known_users
- ldap
- ldap_search
- local_subnets
- local_subnets_dj
- local_subnets_graphs
- log4shell
- modbus
- mqtt_connect
- mqtt_publish
- mqtt_subscribe
- mysql
- napatech_shunting
- ntlm
- ntp
- pe
- profinet
- profinet_dce_rpc
- profinet_debug
- radius
- reporter
- rfb
- s7comm
- smartpcap
- snmp
- socks
- software
- specific_dns_tunnels
- stepping
- stun
- stun_nat
- suricata_eve
- suricata_stats
- syslog
- tds
- tds_rpc
- tds_sql_batch
- traceroute
- tunnel
- unknown-smartpcap
- vpn
- weird
- weird_red
- wireguard
- x509
- x509_red
- conn_agg
- dns_agg
- files_agg
- http_agg
- ssl_agg
- weird_agg
Referencia de asignación de campos
En esta sección se explica cómo asigna el analizador de Google Security Operations los campos de Corelight a los campos del modelo de datos unificado (UDM) de Google Security Operations.
Referencia de asignación de campos: CORELIGHT - Common Fields
En la siguiente tabla se enumeran los campos habituales del registro CORELIGHT y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.vendor_name | The metadata.vendor_nameUDM field is set toCorelight. | |
| _path (string) | metadata.product_event_type | |
| _system_name (string) | observer.hostname | |
| ts (time) | metadata.event_timestamp | |
| uid (string) | about.labels [uid], additional.fields [uid] | |
| id.orig_h (string - addr) | principal.ip | |
| id.orig_p (integer - port) | principal.port | |
| id.resp_h (string - addr) | target.ip | |
| id.resp_p (integer - port) | target.port | |
| _write_ts | metadata.collected_timestamp | |
| id.vlan (integer - int) | additional.fields [id_vlan] | |
| id.vlan_inner (integer - int) | additional.fields [id_vlan_inner] | |
| id.orig_ep_cid (string) | additional.fields [id_orig_ep_cid] | |
| id.orig_ep_source (string) | additional.fields [id_orig_ep_source] | |
| id.orig_ep_status (string) | additional.fields [id_orig_ep_status] | |
| id.orig_ep_uid (string) | additional.fields [id_orig_ep_uid] | |
| id.resp_ep_cid (string) | additional.fields [id_resp_ep_cid] | |
| id.resp_ep_source (string) | additional.fields [id_resp_ep_source] | |
| id.resp_ep_status (string) | additional.fields [id_resp_ep_status] | |
| id.resp_ep_uid (string) | additional.fields [id_resp_ep_uid] | |
| uids (array[string] - vector of string) | additional.fields [uid] | |
| count (integer - int) | additional.fields [count] | |
| ts_last | additional.fields [ts_last] | 
Referencia de asignación de campos: CORELIGHT - conn, conn_red, conn_long, conn_agg
En la siguiente tabla se enumeran los campos de registro del tipo de registro conn, conn_red, conn_long, conn_agg y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| proto (string - enum) | network.ip_protocol | |
| service (string) | network.application_protocol | |
| duration (number - interval) | network.session_duration | |
| orig_bytes (integer - count) | network.sent_bytes | |
| resp_bytes (integer - count) | network.received_bytes | |
| conn_state (string) | metadata.description | If the conn_statelog field value is equal toS0, then themetadata.descriptionUDM field is set toS0: Connection attempt seen, no reply.Else, if the conn_statelog field value is equal toS1, then themetadata.descriptionUDM field is set toS1: Connection established, not terminated.Else, if the conn_statelog field value is equal toS2, then themetadata.descriptionUDM field is set toS2: Connection established and close attempt by originator seen (but no reply from responder).Else, if the conn_statelog field value is equal toS3, then themetadata.descriptionUDM field is set toS3: Connection established and close attempt by responder seen (but no reply from originator).Else, if the conn_statelog field value is equal toSF, then themetadata.descriptionUDM field is set toSF: Normal SYN/FIN completion.Else, if the conn_statelog field value is equal toREJ, then themetadata.descriptionUDM field is set toREJ: Connection attempt rejected.Else, if the conn_statelog field value is equal toRSTO, then themetadata.descriptionUDM field is set toRSTO: Connection established, originator aborted (sent a RST).Else, if the conn_statelog field value is equal toRSTOS0, then themetadata.descriptionUDM field is set toRSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder.Else, if the conn_statelog field value is equal toRSTOSH, then themetadata.descriptionUDM field is set toRSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator.Else, if the conn_statelog field value is equal toRSTR, then themetadata.descriptionUDM field is set toRSTR: Established, responder aborted.Else, if the conn_statelog field value is equal toSH, then themetadata.descriptionUDM field is set toSH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open).Else, if the conn_statelog field value is equal toSHR, then themetadata.descriptionUDM field is set toSHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator.Else, if the conn_statelog field value is equal toOTH, then themetadata.descriptionUDM field is set toOTH: No SYN seen, just midstream traffic (a partial connection that was not later closed). | 
| local_orig (boolean - bool) | about.labels [local_orig] | |
| local_resp (boolean - bool) | about.labels [local_resp] | |
| missed_bytes (integer - count) | about.labels [missed_bytes] | |
| history (string) | about.labels [history] | |
| orig_pkts (integer - count) | network.sent_packets | |
| orig_ip_bytes (integer - count) | principal.labels [orig_ip_bytes] | |
| resp_pkts (integer - count) | network.received_packets | |
| resp_ip_bytes (integer - count) | target.labels [resp_ip_bytes] | |
| tunnel_parents (array[string] - set[string]) | intermediary.labels [tunnel_parent] | |
| orig_cc (string) | principal.ip_geo_artifact.location.country_or_region | |
| resp_cc (string) | target.ip_geo_artifact.location.country_or_region | |
| suri_ids (array[string] - set[string]) | security_result.rule_id | |
| spcap.url (string) | security_result.url_back_to_product | |
| spcap.rule (integer - count) | security_result.rule_labels [spcap_rule] | |
| spcap.trigger (string) | security_result.detection_fields [spcap_trigger] | |
| app (array[string] - vector of string) | about.application | |
| corelight_shunted (boolean - bool) | about.labels [corelight_shunted] | |
| orig_shunted_pkts (integer - count) | principal.labels [orig_shunted_pkts] | |
| orig_shunted_bytes (integer - count) | principal.labels [orig_shunted_bytes] | |
| resp_shunted_pkts (integer - count) | target.labels [resp_shunted_pkts] | |
| resp_shunted_bytes (integer - count) | target.labels [resp_shunted_bytes] | |
| orig_l2_addr (string) | principal.mac | |
| resp_l2_addr (string) | target.mac | |
| id_orig_h_n.src (string) | principal.labels [id_orig_h_n_src] | |
| id_orig_h_n.vals (array[string] - set[string]) | principal.labels [id_orig_h_n_val] | |
| id_resp_h_n.src (string) | target.labels [id_resp_h_n_src] | |
| id_resp_h_n.vals (array[string] - set[string]) | target.labels [id_resp_h_n_val] | |
| vlan (integer - int) | intermediary.labels [vlan] | |
| inner_vlan (integer - int) | intermediary.labels [inner_vlan] | |
| community_id (string) | network.community_id | |
| security_result.severity | The security_result.severityUDM field is set toINFORMATIONAL. | |
| service (string) | about.labels [service] | |
| orig_ep_cid (string) | additional.fields [orig_ep_cid] | |
| orig_ep_source (string) | additional.fields [orig_ep_source] | |
| orig_ep_status (string) | additional.fields [orig_ep_status] | |
| orig_ep_uid (string) | additional.fields [orig_ep_uid] | |
| resp_ep_cid (string) | additional.fields [resp_ep_cid] | |
| resp_ep_source (string) | additional.fields [resp_ep_source] | |
| resp_ep_status (string) | additional.fields [resp_ep_status] | |
| resp_ep_uid (string) | additional.fields [resp_ep_uid] | |
| id_orig_h_n | principal.ip | |
| id_resp_h_n | target.ip | |
| netskope_site_ids | additional.fields[netskope_site_ids] | Iterate through log field netskope_site_ids, thennetskope_site_id_%{index}log field is mapped to theadditional.fields.keyUDM field andnetskope_site_idlog field is mapped to theadditional.fields.valueUDM field. | 
| netskope_user_ids | additional.fields[netskope_user_ids] | Iterate through log field netskope_user_ids, thennetskope_user_id_%{index}log field is mapped to theadditional.fields.keyUDM field andnetskope_user_idlog field is mapped to theadditional.fields.valueUDM field. | 
| write_ts | additional.fields[write_ts] | |
| spcap.urls (array[string] - vector of string) | security_result.url_back_to_product | Iterate through log field spcap.urls, thenspcap.urlslog field is mapped to thesecurity_result.url_back_to_productUDM field. | 
| community_ids (array[string] - vector of string) | network.community_id | Iterate through log field community_ids, thenif index is equal to 0then,community_idlog field is mapped to thenetwork.community_idUDM field.Else, community_id_%{index}log field is mapped to theadditional.fields.keyUDM field andcommunity_idlog field is mapped to theadditional.fields.valueUDM field. | 
Referencia de asignación de campos: CORELIGHT - dce_rpc
En la siguiente tabla se enumeran los campos de registro del tipo de registro dce_rpc y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| rtt (number - interval) | network.session_duration | |
| named_pipe (string) | intermediary.resource.name | |
| intermediary.resource.resource_type | If the named_pipelog field value is not empty, then theintermediary.resource.resource_typeUDM field is set toPIPE. | |
| endpoint (string) | target.labels [endpoint] | |
| operation (string) | target.labels [operation] | |
| network.application_protocol | The network.application_protocolUDM field is set toDCERPC. | |
| security_result.severity | The security_result.severityUDM field is set toINFORMATIONAL. | |
| operation, endpoint, named_pipe (string) | metadata.description | The metadata.descriptionUDM field is set withoperation,endpoint,named_pipelog fields as "operationoperationonendpointusing named pipenamed_pipe". | 
| network.ip_protocol | The network.ip_protocolUDM field is set toTCP. | 
Referencia de asignación de campos: CORELIGHT - dns, dns_red, dns_agg
En la siguiente tabla se enumeran los campos de registro del tipo de registro dns, dns_red, dns_agg y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_DNS. | |
| network.application_protocol | The network.application_protocolUDM field is set toDNS. | |
| proto (string - enum) | network.ip_protocol | |
| trans_id (integer - count) | network.dns.id | |
| rtt (number - interval) | network.session_duration | |
| query (string) | network.dns.questions.name | |
| qclass (integer - count) | network.dns.questions.class | |
| qclass_name (string) | about.labels [qclass_name] | |
| qtype (integer - count) | network.dns.questions.type | |
| qtype_name (string) | about.labels [qtype_name] | |
| rcode (integer - count) | network.dns.response_code | |
| rcode (integer - count) | network.dns.response | If the rcodelog field value is not empty, then thenetwork.dns.responseUDM field is set totrue. | 
| rcode_name (string) | about.labels [rcode_name] | |
| AA (boolean - bool) | network.dns.authoritative | |
| TC (boolean - bool) | network.dns.truncated | |
| RD (boolean - bool) | network.dns.recursion_desired | |
| RA (boolean - bool) | network.dns.recursion_available | |
| Z (integer - count) | about.labels [Z] | |
| answers (array[string] - vector of string) | network.dns.answers.name | |
| TTLs (array[number] - vector of interval) | network.dns.answers.ttl | |
| rejected (boolean - bool) | about.labels [rejected] | |
| is_trusted_domain (string) | about.labels [is_trusted_domain] | |
| icann_host_subdomain (string) | about.labels [icann_host_subdomain] | |
| icann_domain (string) | network.dns_domain | |
| icann_tld (string) | about.labels [icann_tld] | |
| num (integer - count) | security_result.detection_fields [num] | 
Referencia de la asignación de campos: CORELIGHT - http, http_red, http2, http_agg
En la siguiente tabla se enumeran los campos de registro del tipo de registro http, http_red, http2, http_agg y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_HTTP. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| trans_depth (integer - count) | about.labels [trans_depth] | |
| method (string) | network.http.method | |
| host (string) | target.hostname | |
| uri (string) | target.url | |
| referrer (string) | network.http.referral_url | |
| version (string) | network.application_protocol_version | |
| user_agent (string) | network.http.user_agent | |
| origin (string) | principal.hostname | |
| request_body_len (integer - count) | network.sent_bytes | |
| response_body_len (integer - count) | network.received_bytes | |
| status_code (integer - count) | network.http.response_code | |
| status_msg (string) | about.labels [status_msg] | |
| info_code (integer - count) | about.labels [info_code] | |
| info_msg (string) | about.labels [info_msg] | |
| tags (array[string] - set[enum]) | about.labels [tags] | |
| username (string) | principal.user.user_display_name | |
| password (string) | extensions.auth.auth_details | |
| proxied (array[string] - set[string]) | intermediary.hostname | |
| orig_fuids (array[string] - vector of string) | about.labels [orig_fuid] | |
| orig_filenames (array[string] - vector of string) | src.file.names | The orig_filenameslog field is mapped tosrc.file.namesUDM field when index value inorig_filenamesis equal to0.For every other index value, orig_filenameslog field is mapped to theabout.file.names. | 
| orig_mime_types (array[string] - vector of string) | src.file.mime_type | The orig_mime_typeslog field is mapped tosrc.file.mime_typeUDM field when index value inorig_mime_typesis equal to0.For every other index value, orig_mime_typeslog field is mapped to theabout.file.mime_type. | 
| resp_fuids (array[string] - vector of string) | about.labels [resp_fuid] | |
| resp_filenames (array[string] - vector of string) | target.file.names | The resp_filenameslog field is mapped totarget.file.namesUDM field when index value inresp_filenamesis equal to0.For every other index value, resp_filenameslog field is mapped to theabout.file.names. | 
| resp_mime_types (array[string] - vector of string) | target.file.mime_type | The resp_mime_typeslog field is mapped totarget.file.mime_typeUDM field when index value inresp_mime_typesis equal to0.For every other index value, resp_mime_typeslog field is mapped to theabout.file.mime_type. | 
| post_body (string) | about.labels [post_body] | |
| stream_id (integer - count) | about.labels [stream_id] | |
| encoding (string) | about.labels [encoding] | |
| push (boolean - bool) | about.labels [push] | |
| versions (array[float] - vector of float) | network.application_protocol_version | Iterate through log field versions, thenif index is equal to 0then,versionlog field is mapped to thenetwork.application_protocol_versionUDM field.Else, version_%{index}log field is mapped to theadditional.fields.keyUDM field andversionlog field is mapped to theadditional.fields.valueUDM field. | 
| user_agents (array[string] - vector of string) | network.http.user_agent | Iterate through log field user_agents, thenif index is equal to 0then,user_agentlog field is mapped to thenetwork.http.user_agentUDM field.Else, user_agent_%{index}log field is mapped to theadditional.fields.keyUDM field anduser_agentlog field is mapped to theadditional.fields.valueUDM field. | 
Referencia de asignación de campos: CORELIGHT - smtp_links
En la siguiente tabla se enumeran los campos de registro del tipo de registro smtp_links y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_SMTP. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toSMTP. | |
| fuid (string) | about.labels [fuid] | |
| link (string) | about.url | |
| domain (string) | about.domain.name | 
Referencia de asignación de campos: CORELIGHT - irc
En la siguiente tabla se enumeran los campos de registro del tipo de registro irc y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| nick (string) | principal.user.user_display_name | |
| user (string) | principal.user.userid | If the userlog field value is less than or equal to 255, then theuserlog field is mapped to theprincipal.user.useridUDM field.Else, the userlog field is mapped to theabout.labelsUDM field. | 
| command, value, addl | principal.process.command_line | |
| dcc_file_name (string) | src.file.names | |
| dcc_file_size (integer - count) | src.file.size | |
| dcc_mime_type (string) | src.file.mime_type | |
| fuid (string) | about.labels [fuid] | 
Referencia de mapeado de campos: CORELIGHT - files, files_red, files_agg
En la siguiente tabla se enumeran los campos de registro del tipo de registro files, files_red, files_agg y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| fuid (string) | about.labels [fuid] | |
| tx_hosts (array[string] - set[addr]) | principal.ip | |
| rx_hosts (array[string] - set[addr]) | target.ip | |
| conn_uids (array[string] - set[string]) | about.labels [conn_uid] | |
| source (string) | about.labels [source] | |
| depth (integer - count) | about.labels [depth] | |
| analyzers (array[string] - set[string]) | about.labels [analyzer] | |
| mime_type (string) | about.file.mime_type | |
| filename (string) | about.file.names | |
| duration (number - interval) | about.labels [duration] | |
| local_orig (boolean - bool) | about.labels [local_orig] | |
| is_orig (boolean - bool) | about.labels [is_orig] | |
| seen_bytes (integer - count) | about.file.size | |
| total_bytes (integer - count) | about.labels [total_bytes] | |
| missing_bytes (integer - count) | about.labels [missing_bytes] | |
| overflow_bytes (integer - count) | about.labels [overflow_bytes] | |
| timedout (boolean - bool) | about.labels [timedout] | |
| parent_fuid (string) | about.labels [parent_fuid] | |
| md5 (string) | about.file.md5 | |
| sha1 (string) | about.file.sha1 | |
| sha256 (string) | about.file.sha256 | |
| md5 (string) | network.tls.client.certificate.md5 | If the sourcelog field value is equal tossland themime_typelog field value is equal toapplication/x-x509-user-certand the_pathlog field value is equal tofiles, then thenetwork.tls.client.certificate.md5UDM field is set tomd5. | 
| sha1 (string) | network.tls.client.certificate.sha1 | If the sourcelog field value is equal tossland themime_typelog field value is equal toapplication/x-x509-user-certand the_pathlog field value is equal tofiles, then thenetwork.tls.client.certificate.sha1UDM field is set tosha1. | 
| sha256 (string) | network.tls.client.certificate.sha256 | If the sourcelog field value is equal tossland themime_typelog field value is equal toapplication/x-x509-user-certand the_pathlog field value is equal tofiles, then thenetwork.tls.client.certificate.sha256UDM field is set tosha256. | 
| md5 (string) | network.tls.server.certificate.md5 | If the sourcelog field value is equal tossland themime_typelog field value is equal toapplication/x-x509-ca-certand the_pathlog field value is equal tofiles, then thenetwork.tls.server.certificate.md5UDM field is set tomd5. | 
| sha1 (string) | network.tls.server.certificate.sha1 | If the sourcelog field value is equal tossland themime_typelog field value is equal toapplication/x-x509-ca-certand the_pathlog field value is equal tofiles, then thenetwork.tls.server.certificate.sha1UDM field is set tosha1. | 
| sha256 (string) | network.tls.server.certificate.sha256 | If the sourcelog field value is equal tossland themime_typelog field value is equal toapplication/x-x509-ca-certand the_pathlog field value is equal tofiles, then thenetwork.tls.server.certificate.sha256UDM field is set tosha256. | 
| extracted (array[string] - set[string]) | about.file.names | |
| extracted_cutoff (boolean - bool) | about.labels [extracted_cutoff] | |
| extracted_size (integer - count) | about.labels [extracted_size] | |
| num (integer - count) | about.labels [num] | |
| vlan (integer - int) | additional.fields [vlan] | |
| vlan_inner (integer - int) | additional.fields [vlan_inner] | |
| mime_types (array[string] - vector of string) | target.file.mime_type | Iterate through log field mime_type, thenif index is equal to 0then,mime_typelog field is mapped to thetarget.file.mime_typeUDM field.Else, mime_type_%{index}log field is mapped to theadditional.fields.keyUDM field andmime_typelog field is mapped to theadditional.fields.valueUDM field. | 
| timedouts (array[boolean] - vector of bool) | additional.fields[timedouts] | Iterate through log field timedouts, thentimedout_%{index}log field is mapped to theadditional.fields.keyUDM field andtimedoutslog field is mapped to theadditional.fields.valueUDM field. | 
Referencia de asignación de campos: CORELIGHT - aviso
En la siguiente tabla se enumeran los campos de registro del tipo de registro notice y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| fuid (string) | about.labels [fuid] | |
| file_mime_type (string) | target.file.mime_type | |
| file_desc (string) | about.labels [file_desc] | |
| proto (string - enum) | network.ip_protocol | |
| note (string - enum) | security_result.description | |
| msg (string) | metadata.description | |
| sub (string) | about.labels [sub] | |
| src (string - addr) | principal.ip | |
| dst (string - addr) | target.ip | |
| p (integer - port) | about.port | |
| n (integer - count) | about.labels [n] | |
| peer_descr (string) | about.labels [peer_descr] | |
| security_result.action  | The security_result.actionUDM field is set toALLOW. | |
| actions (array[string] - set[enum]) | security_result.action_details | |
| suppress_for (number - interval) | about.labels [suppress_for] | |
| remote_location.country_code (string) | about.location.country_or_region | The about.location.country_or_regionUDM field is set withremote_location.country_code,remote_location.regionlog fields as "remote_location.country_code:remote_location.region". | 
| remote_location.region (string) | about.location.country_or_region | The about.location.country_or_regionUDM field is set withremote_location.country_code,remote_location.regionlog fields as "remote_location.country_code:remote_location.region". | 
| remote_location.city (string) | about.location.city | |
| remote_location.latitude (number - double) | about.location.region_coordinates.latitude | |
| remote_location.longitude (number - double) | about.location.region_coordinates.longitude | |
| security_result.severity | If the severity.levellog field value contain one of the following values
   security_result.severity UDM field is set toHIGH.Else, If severity.levellog field value is equal to 2 then, the  security_result.severity UDM field is set toCRITICAL.Else, If severity.levellog field value is equal to 3 then, the  security_result.severity UDM field is set toERROR.Else, If severity.levellog field value contain one of the following values
   security_result.severity UDM field is set toINFORMATIONAL.Else, If severity.levellog field value is equal to 7 then, the  security_result.severity UDM field is set toLOW.Else The   security_result.severity UDM field is set toUNKNOWN_SEVERITY. | |
| severity.name | security_result.severity_details | |
| severity.level | security_result.detection_fields [severity_level] | |
| resp_vulnerable_host.criticality (string) | target.asset.vulnerabilities.severity | If the resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Critical" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toCRITICAL.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)High" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toHIGH.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Low" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toLOW.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Medium" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toMEDIUM.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Unknown_Severity" or theresp_vulnerable_host.criticalitylog field value is equal to "0 " then, the "target.asset.vulnerabilities.severity" UDM field is set toUNKNOWN_SEVERITY. | 
| resp_vulnerable_host.criticality (string) | target.asset.vulnerabilities.severity_details | |
| resp_vulnerable_host.cve (string) | target.asset.vulnerabilities.cve_id | |
| resp_vulnerable_host.host_uid (string) | additional.fields [resp_vulnerable_host_uid] | |
| resp_vulnerable_host.hostname (string) | target.asset.hostname | |
| resp_vulnerable_host.machine_domain (string) | target.asset.network_domain | |
| resp_vulnerable_host.os_version (string) | target.asset.platform_software.platform_version | |
| resp_vulnerable_host.source (string) | target.asset.vulnerabilities.cve_description | |
| orig_vulnerable_host.criticality (string) | principal.asset.vulnerabilities.severity | If the orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Critical" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toCRITICAL.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)High" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toHIGH.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Low" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toLOW.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Medium" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toMEDIUM.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Unknown_Severity" or theorig_vulnerable_host.criticalitylog field value is equal to "0 " then, the "principal.asset.vulnerabilities.severity" UDM field is set toUNKNOWN_SEVERITY. | 
| orig_vulnerable_host.criticality (string) | principal.asset.vulnerabilities.severity_details | |
| orig_vulnerable_host.cve (array[string] - vector of string) | principal.asset.vulnerabilities.cve_id | |
| orig_vulnerable_host.host_uid (string) | additional.fields [orig_vulnerable_host_uid] | |
| orig_vulnerable_host.hostname (string) | principal.asset.hostname | |
| orig_vulnerable_host.machine_domain (string) | principal.asset.network_domain | |
| orig_vulnerable_host.os_version (string) | principal.asset.platform_software.platform_version | |
| orig_vulnerable_host.source (string) | principal.asset.vulnerabilities.cve_description | 
Referencia de asignación de campos: CORELIGHT - smb_files
En la siguiente tabla se enumeran los campos de registro del tipo de registro smb_files y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | If the actionlog field value is equal toSMB::FILE_READ, then themetadata.event_typeUDM field is set toFILE_READ.Else, if the actionlog field value is equal toSMB::FILE_WRITE, then themetadata.event_typeUDM field is set toFILE_MODIFICATION.Else, if the actionlog field value is equal toSMB::FILE_OPEN, then themetadata.event_typeUDM field is set toFILE_OPEN.Else, if the actionlog field value is equal toSMB::FILE_CLOSE, then themetadata.event_typeUDM field is set toFILE_UNCATEGORIZED.Else, if the actionlog field value is equal toSMB::FILE_DELETE, then themetadata.event_typeUDM field is set toFILE_DELETION.Else, if the actionlog field value is equal toSMB::FILE_RENAME, then themetadata.event_typeUDM field is set toFILE_MOVE.Else, if the actionlog field value is equal toSMB::FILE_SET_ATTRIBUTE, then themetadata.event_typeUDM field is set toFILE_UNCATEGORIZED.Else, the metadata.event_typeUDM field is set toFILE_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toSMB. | |
| network.ip_protocol | The network.ip_protocolUDM field is set toTCP. | |
| action, name | metadata.description | The metadata.descriptionUDM field is set withaction,namelog fields as "action:actionon:name". | 
| security_result.severity | The security_result.severityUDM field is set toINFORMATIONAL. | |
| security_result.action | The security_result.actionUDM field is set toALLOW. | |
| fuid (string) | about.labels [fuid] | |
| action (string - enum) | target.labels [action] | |
| path (string) | target.file.full_path | |
| name (string) | target.file.names | |
| size (integer - count) | target.file.size | |
| prev_name (string) | src.file.names | |
| times.modified (time) | target.file.last_modification_time | |
| times.accessed (time) | target.file.last_seen_time | |
| times.created (time) | target.file.first_seen_time | |
| times.changed (time) | target.labels [times_changed] | |
| data_offset_req (integer - count) | target.labels [data_offset_req] | |
| data_len_req (integer - count) | target.labels [data_len_req] | |
| data_len_rsp (integer - count) | target.labels [data_len_rsp] | 
Referencia de asignación de campos: CORELIGHT - smb_mapping
En la siguiente tabla se enumeran los campos de registro del tipo de registro smb_mapping y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toSMB. | |
| network.ip_protocol | The network.ip_protocolUDM field is set toTCP. | |
| security_result.severity | The security_result.severityUDM field is set toINFORMATIONAL. | |
| security_result.action | The security_result.actionUDM field is set toALLOW. | |
| path (string) | target.resource.attribute.labels [path] | |
| service (string) | target.application | |
| native_file_system (string) | target.resource.attribute.labels [native_file_system] | |
| share_type (string) | target.resource.resource_type | If the share_typelog field value is equal toDISK, then thetarget.resource.resource_typeUDM field is set toSTORAGE_OBJECT.Else, if the share_typelog field value is equal toPIPE, then thetarget.resource.resource_typeUDM field is set toPIPE.Else, the target.resource.resource_typeUDM field is set toUNSPECIFIED. | 
| share_type (string) | target.resource.resource_subtype | 
Referencia de la asignación de campos: CORELIGHT - ssl, ssl_red, ssl_agg
En la siguiente tabla se enumeran los campos de registro del tipo de registro ssl, ssl_red, ssl_agg y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toHTTPS. | |
| network.ip_protocol | The network.ip_protocolUDM field is set toTCP. | |
| security_result.severity | The security_result.severityUDM field is set toINFORMATIONAL. | |
| security_result.action | The security_result.actionUDM field is set toALLOW. | |
| version (string) | network.tls.version | |
| cipher (string) | network.tls.cipher | |
| curve (string) | network.tls.curve | |
| server_name (string) | network.tls.client.server_name | |
| resumed (boolean - bool) | network.tls.resumed | |
| last_alert (string) | security_result.description | |
| next_protocol (string) | network.tls.next_protocol | |
| established (boolean - bool) | network.tls.established | |
| ssl_history (string) | about.labels [ssl_history] | |
| cert_chain_fps (array[string] - vector of string) | target.labels [cert_chain_fps] | |
| client_cert_chain_fps (array[string] - vector of string) | principal.labels [client_cert_chain_fps] | |
| sni_matches_cert (boolean - bool) | about.labels [sni_matches_cert] | |
| validation_status (string) | security_result.detection_fields [validation_status] | |
| ja3 (string) | network.tls.client.ja3 | |
| ja3s (string) | network.tls.server.ja3s | 
Referencia de asignación de campos: CORELIGHT - rdp
En la siguiente tabla se enumeran los campos de registro del tipo de registro rdp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| cookie (string) | about.labels [cookie] | |
| result (string) | about.labels [result] | |
| security_protocol (string) | target.labels [security_protocol] | |
| client_channels (array[string] - vector of string) | intermediary.labels [client_channels] | |
| keyboard_layout (string) | principal.labels [keyboard_layout] | |
| client_build (string) | principal.labels [client_build] | |
| client_name (string) | principal.hostname | |
| client_dig_product_id (string) | principal.labels [client_dig_product_id ] | |
| desktop_width (integer - count) | principal.labels [desktop_width] | |
| desktop_height (integer - count) | principal.labels [desktop_height] | |
| requested_color_depth (string) | principal.labels [requested_color_depth] | |
| cert_type (string) | about.labels [cert_type] | |
| cert_count (integer - count) | about.labels [cert_count] | |
| cert_permanent (boolean - bool) | about.labels [cert_permanent ] | |
| encryption_level (string) | about.labels [encryption_level] | |
| encryption_method (string) | about.labels [encryption_method] | |
| auth_success (boolean - bool) | about.labels [auth_success] | |
| channels_joined (integer - int) | intermediary.labels [channels_joined] | |
| inferences (array[string] - set[string]) | about.labels [inferences] | |
| rdpeudp_uid (string) | about.labels [rdpeudp_uid] | |
| network.ip_protocol | The network.ip_protocolUDM field is set toTCP. | |
| rdfp_string (string) | principal.labels [rdfp_string] | |
| rdfp_hash (string) | principal.labels [rdfp_hash] | |
| result, security_protocol | security_result.description | The security_result.descriptionUDM field is set withresult,security_protocollog fields as "resultconnection with security protocolsecurity_protocol". | 
| security_result.severity | The security_result.severityUDM field is set toINFORMATIONAL. | 
Referencia de asignación de campos: CORELIGHT - sip
En la siguiente tabla se enumeran los campos de registro del tipo de registro sip y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toSIP. | |
| trans_depth (integer - count) | about.labels [trans_depth] | |
| method (string) | about.labels [method] | |
| uri (string) | target.url | |
| date (string) | about.labels [date] | |
| request_from (string) | principal.labels [request_from] | |
| request_to (string) | target.labels [request_to] | |
| response_from | principal.labels [response_from] | |
| response_to (string) | target.labels [response_to] | |
| reply_to (string) | about.labels [reply_to] | |
| call_id (string) | network.session_id | |
| seq (string) | about.labels [seq] | |
| subject (string) | about.labels [subject] | |
| request_path (array[string] - vector of string) | about.labels [request_path] | |
| response_path (array[string] - vector of string) | about.labels [response_path] | |
| user_agent (string) | about.labels [user_agent] | |
| status_code (integer - count) | about.labels [status_code] | |
| status_msg (string) | security_result.description | |
| warning (string) | security_result.summary | |
| request_body_len (integer - count) | network.sent_bytes | |
| response_body_len (integer - count) | network.received_bytes | |
| content_type (string) | about.labels [content_type] | 
Referencia de la asignación de campos: CORELIGHT - intel
En la siguiente tabla se enumeran los campos de registro del tipo de registro intel y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toSCAN_NETWORK. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| seen.indicator_type (string - enum) | entity.metadata.entity_type | If the indicator.typelog field value is equal toIntel::ADDR, then themetadata.entity_typeUDM field is set toIP_ADDRESS.Else, if the indicator.typelog field value is equal toIntel::SUBNETorIntel::SOFTWAREorIntel::CERT_HASHorIntel::PUBKEY_HASH, then themetadata.entity_typeUDM field is set toRESOURCE.Else, if the indicator.typelog field value is equal toIntel::URL, then themetadata.entity_typeUDM field is set toURL.Else, if the indicator.typelog field value is equal to theIntel::EMAILorIntel::USER_NAME, then themetadata.entity_typeUDM field is set toUSER.Else, if the indicator.typelog field value is equal toIntel::DOMAIN, then themetadata.entity_typeUDM field is set toDOMAIN_NAME.Else, if the indicator.typelog field value is equal to theIntel::FILE_HASHorIntel::FILE_NAME, then themetadata.entity_typeUDM field is set toFILE.Else, the metadata.entity_typeUDM field is set toRESOURCE. | 
| seen.indicator (string) | entity.ip | If the indicator.typelog field value is equal toIntel::ADDR, then theseen.indicatorlog field is mapped to theentity.ipUDM field. | 
| seen.indicator (string) | entity.url | If the indicator.typelog field value is equal toIntel::URL, then theseen.indicatorlog field is mapped to theentity.urlUDM field. | 
| seen.indicator (string) | entity.domain.name | If the indicator.typelog field value is equal toIntel::DOMAIN, then theseen.indicatorlog field is mapped to theentity.domain.nameUDM field. | 
| seen.indicator (string) | entity.user.email_address | If the indicator.typelog field value is equal toIntel::USER_NAMEorIntel::EMAIL, then theseen.indicatorlog field is mapped to theentity.user.email_addressUDM field. | 
| seen.indicator (string) | entity.file.names | If the indicator.typelog field value is equal toIntel::FILE_HASHorIntel::FILE_NAME, then theseen.indicatorlog field is mapped to theentity.file.full_pathUDM field. | 
| seen.indicator (string) | entity.resource.name | If the metadata.entity_typelog field value is equal toRESOURCE, then theseen.indicatorlog field is mapped to theentity.resource.nameUDM field. | 
| entity.resource.resource_type | If the indicator.typelog field value is equal toIntel::SUBNET, then theentity.resource.resource_nameUDM field is set toVPC_NETWORK. | |
| seen.indicator_type (string - enum) | entity.resource.resource_sub_type | If the metadata.entity_typelog field value is equal toRESOURCE, then theseen.indicator_typelog field is mapped to theentity.resource.resource_sub_typeUDM field. | 
| seen.where (string - enum) | entity.metadata.source_labels [seen_where] | |
| matched (array[string] - set[enum]) | entity.labels [matched] | |
| sources (array[string] - set[string]) | entity.metadata.source_labels [source] | |
| fuid (string) | about.labels [fuid] | |
| file_mime_type (string) | entity.file.mime_type | |
| file_desc (string) | metadata.threat.detection_fields [file_desc] | |
| desc (array[string] - set[string]) | ioc.description | The desclog field is mapped toioc.descriptionUDM field when index value indescis equal to0.For every other index value, entity.labels.keyUDM field is set todescanddesclog field is mapped to theentity.labels.value. | 
| url (array[string] - set[string]) | metadata.threat.url_back_to_product | |
| confidence (array[number] - set[double]) | ioc.confidence_score | The confidencelog field is mapped toioc.confidence_scoreUDM field when index value inconfidenceis equal to0.For every other index value, entity.labels.keyUDM field is set toconfidenceandconfidencelog field is mapped to theentity.labels.value. | 
| firstseen (array[string] - set[string]) | ioc.active_timerange.start | The firstseenlog field is mapped toioc.active_timerange.startUDM field when index value infirstseenis equal to0.For every other index value, entity.labels.keyUDM field is set tofirstseenandfirstseenlog field is mapped to theentity.labels.value. | 
| lastseen (array[string] - set[string]) | ioc.active_timerange.end | The lastseenlog field is mapped toioc.active_timerange.endUDM field when index value inlastseenis equal to0.For every other index value, entity.labels.keyUDM field is set tolastseenandlastseenlog field is mapped to theentity.labels.value. | 
| associated (array[string] - set[string]) | entity.labels [associated] | |
| category (array[string] - set[string]) | ioc.categorization | The categorylog field is mapped toioc.categorizationUDM field when index value incategoryis equal to0.For every other index value, entity.labels.keyUDM field is set tocategoryandcategorylog field is mapped to theentity.labels.value. | 
| campaigns (array[string] - set[string]) | entity.labels [campaign] | |
| reports (array[string] - set[string]) | entity.labels [report] | |
| seen.indicator (string) | about.labels [indicator] | |
| seen.indicator_type (string - enum) | about.labels [indicator_type] | |
| seen.where (string - enum) | about.labels [where] | |
| sources (array[string] - set[string]) | about.labels [sources] | |
| confidence (array[number] - set[double]) | about.labels [confidence] | |
| category (array[string] - set[string]) | about.labels [category] | |
| threat_score (array[number] - set[double]) | entity.security_result.detection_fields[threat_score] | |
| verdict (array[string] - set[string]) | entity.security_result.verdict_info.verdict_response | Iterate through verdict,If theverdictlog field value matches the regular expression pattern "(?i)Malicious" or the then, the        "entity.security_result.verdict_info.verdict_response" UDM field is set toMALICIOUS.Else, If verdictlog field value matches the regular expression pattern "(?i)Benign" or the then, the        "entity.security_result.verdict_info.verdict_response" UDM field is set toBENIGN.Else The         "entity.security_result.verdict_info.verdict_response" UDM field is set toVERDICT_RESPONSE_UNSPECIFIED. | 
| verdict_source (array[string] - set[string]) | entity.security_result.verdict_info.source_provider | Iterate through verdict_source,verdict_sourcelog field is mapped to the    entity.security_result.VerdictInfo.source_provider UDM field. | 
Referencia de la asignación de campos: CORELIGHT - smtp
En la siguiente tabla se enumeran los campos de registro del tipo de registro smtp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_SMTP. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toSMTP. | |
| trans_depth (integer - count) | about.labels [trans_depth] | |
| helo (string) | target.domain.name | |
| mailfrom (string) | network.smtp.mail_from | |
| rcptto (array[string] - set[string]) | network.smtp.rcpt_to | |
| date (string) | about.labels [date] | |
| from (string) | network.email.from | |
| to (array[string] - set[string]) | network.email.to | |
| cc (array[string] - set[string]) | network.email.cc | |
| reply_to (string) | network.email.reply_to | |
| msg_id (string) | network.email.mail_id | |
| in_reply_to (string) | about.labels [in_reply_to] | |
| subject (string) | network.email.subject | |
| x_originating_ip (string - addr) | principal.ip | |
| first_received (string) | about.labels [first_received] | |
| second_received (string) | about.labels [second_received] | |
| last_reply (string) | network.smtp.server_response | |
| path (array[string] - vector of addr) | intermediary.ip | |
| user_agent (string) | about.labels [user_agent] | |
| tls (boolean - bool) | network.smtp.is_tls | |
| fuids (array[string] - vector of string) | about.labels [fuid] | |
| is_webmail (boolean - bool) | network.smtp.is_webmail | |
| urls (array[string] - set[string]) | about.url | |
| domains (array[string] - set[string]) | about.domain.name | 
Referencia de asignación de campos: CORELIGHT - ssh
En la siguiente tabla se enumeran los campos de registro del tipo de registro ssh y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toSSH. | |
| version (integer - count) | network.application_protocol_version | The network.application_protocol_versionUDM field is set withversionlog field as "SSHversion". | 
| auth_success (boolean - bool) | security_result.action_details | |
| auth_success (boolean - bool) | security_result.action | If the auth_successlog field value is not equal totrue, then thesecurity_result.actionUDM field is set toALLOW.Else, the security_result.actionUDM field is set toBLOCK. | 
| auth_attempts (integer - count) | extensions.auth.auth_details | The extensions.auth.auth_detailsUDM field is set withauth_attemptslog field as "auth_attempts:auth_attempts". | 
| direction (string - enum) | network.direction | If the directionlog field value is equal toINBOUND, then thenetwork.directionUDM field is set toINBOUND.Else, if the directionlog field value is equal toOUTBOUND, then thenetwork.directionUDM field is set toOUTBOUND. | 
| client (string) | principal.application | |
| server (string) | target.application | |
| cipher_alg (string) | network.tls.cipher | |
| mac_alg (string) | security_result.detection_fields [mac_alg] | |
| compression_alg (string) | security_result.detection_fields [compression_alg] | |
| kex_alg (string) | security_result.detection_fields [kex_alg] | |
| host_key_alg (string) | security_result.detection_fields [host_key_alg] | |
| host_key (string) | security_result.detection_fields [host_key] | |
| remote_location.country_code (string) | target.location.country_or_region | |
| remote_location.region (string) | target.location.country_or_region | |
| remote_location.city (string) | target.location.city | |
| remote_location.latitude (number - double) | target.location.region_coordinates.latitude | |
| remote_location.longitude (number - double) | target.location.region_coordinates.longitude | |
| hasshVersion (string) | about.labels [hassh_version] | |
| hassh (string) | principal.labels [hassh] | |
| hasshServer (string) | target.labels [hassh_server] | |
| cshka (string) | about.labels [cshka] | |
| hasshAlgorithms (string) | about.labels [hassh_algorithms] | |
| sshka (string) | about.labels [sshka] | |
| hasshServerAlgorithms (string) | about.labels [hassh_server_algorithms] | |
| inferences (array[string] - set[string]) | security_result.summary, security_result.description | If the inferenceslog field value is equal toABP, then thesecurity_result.summaryUDM field is set toClient Authentication Bypassand thesecurity_result.descriptionUDM field is set toA client wasn't adhering to expectations of SSH either through server exploit or by the client and server switching to a protocol other than SSH after enctyption begins.If the inferenceslog field value is equal toAFR, then thesecurity_result.summaryUDM field is set toSSH Agent Forwarding Requestedand thesecurity_result.descriptionUDM field is set toAgent Forwarding is requested by tge Client.If the inferenceslog field value is equal toAPWA, then thesecurity_result.summaryUDM field is set toAutomated Password Authenticationand thesecurity_result.descriptionUDM field is set toThe client authenticated with an automated password tool (like sshpass).If the inferenceslog field value is equal toAUTO, then thesecurity_result.summaryUDM field is set toAutomated Interactionand thesecurity_result.descriptionUDM field is set toThe client is a script automated utility and not driven by a user.If the inferenceslog field value is equal toBAN, then thesecurity_result.summaryUDM field is set toServer Bannerand thesecurity_result.descriptionUDM field is set toThe server sent the client a pre-authentication banner, likely for legal reasons.If the inferenceslog field value is equal toBF, then thesecurity_result.summaryUDM field is set toClient Brute Force Guessingand thesecurity_result.descriptionUDM field is set toA client made a number of authentication attempts that exceeded some configured, pre-connection threshold.If the inferenceslog field value is equal toBFS, then thesecurity_result.summaryUDM field is set toClient Brute Force Successand thesecurity_result.descriptionUDM field is set toA client made a number of authentication attempts that exceeded some configured, pre-connection threshold.If the inferenceslog field value is equal toCTS, then thesecurity_result.summaryUDM field is set toClient Trusted Serverand thesecurity_result.descriptionUDM field is set toThe client already has an entry in its known_hosts file for this server.If the inferenceslog field value is equal toCUS, then thesecurity_result.summaryUDM field is set toClient Untrusted Serverand thesecurity_result.descriptionUDM field is set toThe client did not have an entry in its known_hosts file for this server.If the inferenceslog field value is equal toIPWA, then thesecurity_result.summaryUDM field is set toInteractive Password Authenticationand thesecurity_result.descriptionUDM field is set toThe client interactively typed their password to authenticate.If the inferenceslog field value is equal toKS, then thesecurity_result.summaryUDM field is set toKeystrokesand thesecurity_result.descriptionUDM field is set toAn interactive session occurred in which the client set user-driven keystrokes to the server.If the inferenceslog field value is equal toLFD, then thesecurity_result.summaryUDM field is set toLarge Client File Downloadand thesecurity_result.descriptionUDM field is set toA file transfer occurred in which the server sent a sequence of bytes to the client.If the inferenceslog field value is equal toLFU, then thesecurity_result.summaryUDM field is set toLarge Client File Uploadand thesecurity_result.descriptionUDM field is set toA file transfer occurred in which the client sent a sequence of bytes to the server. Large file are identified dynamically based on trains of MTU-sized packets.If the inferenceslog field value is equal toMFA, then thesecurity_result.summaryUDM field is set toMultifactor Authenticationand thesecurity_result.descriptionUDM field is set toThe server required a second form of authentication (a code) after password or public key was accepted, and the client successfully provided it.If the inferenceslog field value is equal toNA, then thesecurity_result.summaryUDM field is set toNone Authenticationand thesecurity_result.descriptionUDM field is set toThe client successfully authenticated using the None method.If the inferenceslog field value is equal toNRC, then thesecurity_result.summaryUDM field is set toNo Remote Commandand thesecurity_result.descriptionUDM field is set toThe -N flag was used in SSH authentication.If the inferenceslog field value is equal toPKA, then thesecurity_result.summaryUDM field is set toPublic Key Authenticationand thesecurity_result.descriptionUDM field is set toThe client automatically authenticated using pubkey authentication.If the inferenceslog field value is equal toRSI, then thesecurity_result.summaryUDM field is set toReverse SSH Initiatedand thesecurity_result.descriptionUDM field is set toThe Reverse session is initiated from the server back to the client.If the inferenceslog field value is equal toRSIA, then thesecurity_result.summaryUDM field is set toReverse SSH Initiated Automatedand thesecurity_result.descriptionUDM field is set toThe inititation of the Reverse session happened very early in the packet stream, indicating automation.If the inferenceslog field value is equal toRSK, then thesecurity_result.summaryUDM field is set toReverse SSH Keystrokesand thesecurity_result.descriptionUDM field is set toKeystrokes are detected within the Reverse tunnel.If the inferenceslog field value is equal toRSL, then thesecurity_result.summaryUDM field is set toReverse SSH Logged Inand thesecurity_result.descriptionUDM field is set toThe Reverse Tunnel login has succeeded.If the inferenceslog field value is equal toRSP, then thesecurity_result.summaryUDM field is set toReverse SSH Provisionedand thesecurity_result.descriptionUDM field is set toThe client connected with -R flag, which provisions the port to be used for a Reverse Session set up at any future time.If the inferenceslog field value is equal toSA, then thesecurity_result.summaryUDM field is set toAuthentication Scanningand thesecurity_result.descriptionUDM field is set toThe client scanned authentication method with the server and then disconnected.If the inferenceslog field value is equal toSC, then thesecurity_result.summaryUDM field is set toCapabilities Scanningand thesecurity_result.descriptionUDM field is set toThe client exchanged capabilities with the server and then disconnected.If the inferenceslog field value is equal toSFD, then thesecurity_result.summaryUDM field is set toSmall Client File Downloadand thesecurity_result.descriptionUDM field is set toA file transfer occurred in which the server sent a sequence of bytes to the client.If the inferenceslog field value is equal toSFU, then thesecurity_result.summaryUDM field is set toSmall Client File Uploadand thesecurity_result.descriptionUDM field is set toA file transfer occurred in which the client sent a sequence of bytes to the server.If the inferenceslog field value is equal toSP, then thesecurity_result.summaryUDM field is set toOther Scanningand thesecurity_result.descriptionUDM field is set toA client and server didn't exchange encrypted packets but the client wasn't a version or capabilities scanner.If the inferenceslog field value is equal toSV, then thesecurity_result.summaryUDM field is set toVersion Scanningand thesecurity_result.descriptionUDM field is set toA client exchanged version strings with the server and than disconnected.If the inferenceslog field value is equal toUA, then thesecurity_result.summaryUDM field is set toUnknown Authenticationand thesecurity_result.descriptionUDM field is set toThe authentication method is not determinated or is unknown. | 
Referencia de asignación de campos: CORELIGHT - suricata_corelight
En la siguiente tabla se enumeran los campos de registro del tipo de registro suricata_corelight y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toSCAN_NETWORK. | |
| metadata.product_name | The metadata.product_nameUDM field is set toSuricata. | |
| id.vlan (integer - count) | intermediary.labels [id_vlan] | |
| id.vlan_inner (integer - count) | intermediary.labels [id_vlan_inner] | |
| icmp_type (integer - count) | about.labels [icmp_type] | |
| icmp_code (integer - count) | about.labels [icmp_code] | |
| suri_id (string) | metadata.product_log_id | |
| service (string) | network.application_protocol | |
| flow_id (integer - count) | network.session_id | |
| tx_id (integer - count) | about.labels [tx_id] | |
| pcap_cnt (integer - count) | about.labels [pcap_cnt] | |
| alert.action (string) | security_result.action_details | |
| alert.gid (integer - count) | security_result.detection_fields [alert_gid] | |
| alert.signature_id (integer - count) | security_result.rule_id | |
| alert.rev (integer - count) | security_result.detection_fields [alert_rev] | |
| alert.signature (string) | security_result.summary | |
| alert.signature (string) | security_result.rule_name | |
| alert.category (string) | security_result.category_details | |
| alert.severity (integer - count) | security_result.severity_details | |
| alert.metadata (array[string] - vector of string) | security_result.detection_fields [alert_metadata] | |
| community_id (string) | network.community_id | |
| payload (string) | about.labels [payload] | |
| payload (string) | about.labels [payload_decoded] | |
| packet (string) | about.labels [packet] | |
| packet (string) | about.labels [packet_decoded] | |
| metadata (array[string] - vector of string) | security_result.detection_fields [metadata] | |
| orig_cve (string) | extensions.vulns.vulnerabilities.cve_id | |
| resp_cve (string) | extensions.vulns.vulnerabilities.cve_id | |
| signature_severity | security_result.severity | If alert.rulelog field value matches the grok patternsignature_severity (?then If thesignature_severityextracted field value is equal toCriticalthen, thesecurity_result.severityUDM field is set toCRITICALandsignature_severityextracted field is mapped to thesecurity_result.severity_detailsUDM field.Else, If signature_severityextracted field value is equal toMajorthen, thesecurity_result.severityUDM field is set toMEDIUMandsignature_severityextracted field is mapped to the security_result.severity_detailsUDM field.Else, If signature_severityextracted field value is equal toMinorthen, thesecurity_result.severityUDM field is set toLOWandsignature_severityextracted field is mapped to thesecurity_result.severity_detailsUDM field.Else, If signature_severityextracted field value is equal toInformationalthen, thesecurity_result.severityUDM field is set toINFORMATIONALandsignature_severityextracted field is mapped to thesecurity_result.severity_detailsUDM field. | 
| orig_vulnerable_host.cve (array[string] - vector of string) | principal.asset.vulnerabilities.cve_id | |
| orig_vulnerable_host.hostname(string) | principal.asset.hostname | |
| orig_vulnerable_host.host_uid(string) | about.labels [orig_vulnerable_host_uid] | |
| orig_vulnerable_host.machine_domain(string) | principal.asset.network_domain | |
| orig_vulnerable_host.os_version(string) | principal.asset.platform_software.platform_version | |
| orig_vulnerable_host.source(string) | principal.asset.vulnerabilities.cve_description | |
| resp_vulnerable_host.cve(string) | target.asset.vulnerabilities.cve_id | |
| resp_vulnerable_host.hostname(string) | target.asset.hostname | |
| resp_vulnerable_host.host_uid(string) | about.labels [resp_vulnerable_host_uid] | |
| resp_vulnerable_host.machine_domain(string) | target.asset.network_domain | |
| resp_vulnerable_host.os_version(string) | target.asset.platform_software.platform_version | |
| resp_vulnerable_host.source(string) | target.asset.vulnerabilities.cve_description | |
| service (string) | about.labels [service] | |
| alert.rule (string) | security_result.description | |
| alert.references (array[string] - vector of string) | security_result.detection_fields[alert_references] | iterate through alert.references, alert.referenceslog field is mapped to the security_result.detection_fields.alert_references UDM field. | 
| payload_printable (string) | security_result.detection_fields[payload_printable] | |
| references (array[string] - vector of string) | security_result.detection_fields[references] | iterate through references, referenceslog field is mapped to the security_result.detection_fields.references UDM field. | 
| orig_vulnerable_host.criticality (string) | principal.asset.vulnerabilities.severity | If the orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Critical" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toCRITICAL.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)High" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toHIGH.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Low" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toLOW.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Medium" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toMEDIUM.Else, If orig_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Unknown_Severity" or the then, the "principal.asset.vulnerabilities.severity" UDM field is set toUNKNOWN_SEVERITY. | 
| orig_vulnerable_host.criticality (string) | principal.asset.vulnerabilities.severity_details | |
| resp_vulnerable_host.criticality (string) | target.asset.vulnerabilities.severity | If the resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Critical" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toCRITICAL.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)High" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toHIGH.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Low" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toLOW.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Medium" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toMEDIUM.Else, If resp_vulnerable_host.criticalitylog field value matches the regular expression pattern "(?i)Unknown_Severity" or the then, the "target.asset.vulnerabilities.severity" UDM field is set toUNKNOWN_SEVERITY. | 
| resp_vulnerable_host.criticality (string) | target.asset.vulnerabilities.severity_details | |
| rule_content | security_result.detection_fields[alert_rule_content] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}content:\\"%{GREEDYDATA:rule_content}\\"then, therule_contentextracted field is mapped tosecurity_result.detection_fields [alert_rule_content]UDM field. | 
| rule_classtype | security_result.detection_fields [alert_rule_classtype] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}classtype:%{DATA:rule_classtype};then, therule_classtypeextracted field is mapped tosecurity_result.detection_fields [alert_rule_classtype]UDM field. | 
| reference_url | security_result.detection_fields[alert_rule_reference_url] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}reference:url,%{DATA:reference_url};then, thereference_urlextracted field is mapped tosecurity_result.detection_fields [alert_rule_reference_url]UDM field. | 
| attack_target | security_result.detection_fields[alert_rule_attack_target] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}metadata:%{DATA:rule_metadata};and, Theattack_targetis extracted fromrule_metadatausingkv filterthen the extractedattack_targetfield is mapped tosecurity_result.detection_fields [alert_rule_attack_target]UDM field. | 
| created_at | security_result.detection_fields[alert_rule_created_at] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}metadata:%{DATA:rule_metadata};and, Thecreated_atis extracted fromrule_metadatausingkv filterthen the extractedcreated_atfield is mapped tosecurity_result.detection_fields [alert_rule_created_at]UDM field. | 
| deployment | security_result.detection_fields[alert_rule_deployment] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}metadata:%{DATA:rule_metadata};and, Thedeploymentis extracted fromrule_metadatausingkv filterthen the extracteddeploymentfield is mapped tosecurity_result.detection_fields [alert_rule_deployment]UDM field. | 
| performance_impact | security_result.detection_fields[alert_rule_performance_impact] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}metadata:%{DATA:rule_metadata};and, Theperformance_impactis extracted fromrule_metadatausingkv filterthen the extractedperformance_impactfield is mapped tosecurity_result.detection_fields [alert_rule_performance_impact]UDM field. | 
| updated_at | security_result.detection_fields[alert_rule_updated_at] | If alert.rulelog field value matches the grok pattern%{GREEDYDATA:_}metadata:%{DATA:rule_metadata};and, Theupdated_atis extracted fromrule_metadatausingkv filterthen the extractedupdated_atfield is mapped tosecurity_result.detection_fields [alert_rule_updated_at]UDM field. | 
| uri | target.url | If the payload_printablelog field isnot emptythen, Ifpayload_printablelog field value matches the grok pattern%{WORD:http_method} %{NOTSPACE:uri} HTTP/%{NOTSPACE:proto_version}then, theuriextracted field is mapped totarget.urlUDM field.Else If the payloadlog field isnot emptythen, Ifpayloadlog field value matches the grok pattern%{WORD:http_method} %{NOTSPACE:uri} HTTP/%{NOTSPACE:proto_version}then, theuriextracted field is mapped totarget.urlUDM field. | 
| http_method | network.http.method | If the payload_printablelog field isnot emptythen, Ifpayload_printablelog field value matches the grok pattern%{WORD:http_method} %{NOTSPACE:uri} HTTP/%{NOTSPACE:proto_version}then, thehttp_methodextracted field is mapped tonetwork.http.methodUDM field.Else If the payloadlog field isnot emptythen, Ifpayloadlog field value matches the grok pattern%{WORD:http_method} %{NOTSPACE:uri} HTTP/%{NOTSPACE:proto_version}then, thehttp_methodextracted field is mapped tonetwork.http.methodUDM field. | 
| proto_version | network.application_protocol_version | If the payload_printablelog field isnot emptythen, Ifpayload_printablelog field value matches the grok pattern%{WORD:http_method} %{NOTSPACE:uri} HTTP/%{NOTSPACE:proto_version}then, theproto_versionextracted field is mapped tonetwork.application_protocol_versionUDM field.Else If the payloadlog field isnot emptythen, Ifpayloadlog field value matches the grok pattern%{WORD:http_method} %{NOTSPACE:uri} HTTP/%{NOTSPACE:proto_version}then, theproto_versionextracted field is mapped tonetwork.application_protocol_versionUDM field. | 
| user_agent | target.http.useragent | If the payload_printablelog field isnot emptythen, Ifpayload_printablelog field value matches the grok pattern ^User-Agent: %{GREEDYDATA:user_agent}then, theuser_agentextracted field is mapped totarget.http.useragentUDM field.Else If the payloadlog field isnot emptythen, Ifpayloadlog field value matches the grok pattern ^User-Agent: %{GREEDYDATA:user_agent}then, theuser_agentextracted field is mapped totarget.http.useragentUDM field. | 
| hostname | target.hostname | If the payload_printablelog field isnot emptythen, Ifpayload_printablelog field value matches the grok pattern^Host: %{IPORHOST:hostname}then, thehostnameextracted field is mapped totarget.hostnameUDM field.Else If the payloadlog field isnot emptythen, Ifpayloadlog field value matches the grok pattern^Host: %{IPORHOST:hostname}then, thehostnameextracted field is mapped totarget.hostnameUDM field. | 
| meta (array[string] - vector of string) | additional.fields [meta] | 
Referencia de asignación de campos: CORELIGHT - bacnet
En la siguiente tabla se enumeran los campos de registro del tipo de registro bacnet y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| bvlc_function (string) | about.labels [bvlc_function] | |
| bvlc_len (integer - count) | about.labels [bvlc_len] | |
| apdu_type (string) | about.labels [apdu_type] | |
| service_choice (string) | about.labels [service_choice] | |
| data (array[string] - vector of string) | about.labels [data] | |
| invoke_id (integer - count) | additional.fields [invoke_id] | |
| is_orig (boolean - bool) | additional.fields [is_orig] | |
| pdu_service (string) | additional.fields [pdu_service] | |
| pdu_type (string) | additional.fields [pdu_type] | |
| result_code (string) | additional.fields [result_code] | 
Referencia de asignación de campos: CORELIGHT - cip
En la siguiente tabla se enumeran los campos de registro del tipo de registro cip y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| service (string) | about.labels [service] | |
| status (string) | about.labels [status] | |
| tags (string) | about.labels [tag] | |
| attribute_id (string) | additional.fields [attribute_id] | |
| cip_extended_status (string) | additional.fields [cip_extended_status] | |
| cip_extended_status_code (string) | additional.fields [cip_extended_status_code] | |
| cip_sequence_count (integer - count) | additional.fields [cip_sequence_count] | |
| cip_service (string) | additional.fields [cip_service] | |
| cip_service_code (string) | additional.fields [cip_service_code] | |
| cip_status (string) | additional.fields [cip_status] | |
| cip_status_code (string) | additional.fields [cip_status_code] | |
| class_id (string) | additional.fields [class_id] | |
| class_name (string) | additional.fields [class_name] | |
| direction (string) | additional.fields [direction] | |
| instance_id (string) | additional.fields [instance_id] | |
| is_orig (boolean - bool) | additional.fields [is_orig] | 
Referencia de asignación de campos: CORELIGHT - corelight_burst
En la siguiente tabla se enumeran los campos de registro del tipo de registro corelight_burst y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toSCAN_NETWORK. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| proto (string - enum) | network.ip_protocol | |
| orig_size (integer - count) | network.sent_bytes | |
| resp_size (integer - count) | network.received_bytes | |
| mbps (number - double) | about.labels [mbps] | |
| age_of_conn (number - interval) | about.labels [age_of_conn] | 
Referencia de asignación de campos: CORELIGHT - corelight_overall_capture_loss
En la siguiente tabla se enumeran los campos de registro del tipo de registro corelight_overall_capture_loss y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| gaps (number - double) | security_result.detection_fields [gaps] | |
| acks (number - double) | security_result.detection_fields [acks] | |
| percent_lost (number - double) | security_result.detection_fields [percent_lost] | |
| metadata.description | The metadata.descriptionUDM field is set with_system_name,percent_lost,ts.log fields as "node_system_nameexperiencedpercent_lost% packet loss atts.". | 
Referencia de asignación de campos: CORELIGHT - corelight_profiling
En la siguiente tabla se enumeran los campos de registro del tipo de registro corelight_profiling y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toSCAN_NETWORK. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| node (string) | principal.hostname | |
| prof.core_stack (string) | about.labels [prof_core_stack] | |
| prof.script_stack (string) | about.labels [prof_script_stack] | |
| prof.sched_wait_ns (integer - count) | about.labels [prof_sched_wait_ns] | 
Referencia de asignación de campos: CORELIGHT - datared
En la siguiente tabla se enumeran los campos de registro del tipo de registro datared y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| conn_red (integer - count) | about.labels [conn_red] | |
| conn_total (integer - count) | about.labels [conn_total] | |
| dns_red (integer - count) | about.labels [dns_red] | |
| dns_total (integer - count) | about.labels [dns_total] | |
| dns_coal_miss (integer - count) | about.labels [dns_coal_miss] | |
| files_red (integer - count) | about.labels [files_red] | |
| files_total (integer - count) | about.labels [files_total] | |
| files_coal_miss (integer - count) | about.labels [files_coal_miss] | |
| http_red (integer - count) | about.labels [http_red] | |
| http_total (integer - count) | about.labels [http_total] | |
| ssl_red (integer - count) | about.labels [ssl_red] | |
| ssl_total (integer - count) | about.labels [ssl_total] | |
| ssl_coal_miss (integer - count) | about.labels [ssl_coal_miss] | |
| weird_red (integer - count) | about.labels [weird_red] | |
| weird_total (integer - count) | about.labels [weird_total] | |
| x509_red (integer - count) | about.labels [x509_red] | |
| x509_total (integer - count) | about.labels [x509_total] | |
| x509_coal_miss (integer - count) | about.labels [x509_coal_miss] | 
Referencia de asignación de campos: CORELIGHT - dhcp
En la siguiente tabla se enumeran los campos de registro del tipo de registro dhcp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_DHCP. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toDHCP. | |
| uids (array[string] - set[string]) | about.labels [uid] | |
| client_addr (string - addr) | network.dhcp.ciaddr | |
| server_addr (string - addr) | network.dhcp.siaddr | |
| mac (string) | network.dhcp.chaddr | |
| host_name (string) | network.dhcp.client_hostname | |
| client_fqdn (string) | principal.domain.name | |
| domain (string) | target.domain.name | |
| requested_addr (string - addr) | network.dhcp.requested_address | |
| assigned_addr (string - addr) | network.dhcp.yiaddr | |
| lease_time (number - interval) | network.dhcp.lease_time_seconds | |
| client_message (string) | security_result.description | |
| server_message (string) | security_result.description | |
| msg_types (array[string] - vector of string) | network.dhcp.type | The msg_typeslog field is mapped tonetwork.dhcp.typeUDM field when index value inmsg_typesis equal to0.For every other index value, about.labels.keyUDM field is set tomsg_typesandmsg_typeslog field is mapped to theabout.labels.value. | 
| duration (number - interval) | about.labels [duration] | 
Referencia de asignación de campos: CORELIGHT - dga
En la siguiente tabla se enumeran los campos de registro del tipo de registro dga y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_DNS. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toDNS. | |
| query (string) | network.dns.questions.name | |
| family (string) | about.labels [family] | |
| qtype_name (string) | about.labels [qtype_name] | |
| rcode (integer - count) | network.dns.response_code | |
| is_collision_heavy (boolean - bool) | security_result.detection_fields [is_collision_heavy] | |
| ruse (boolean - bool) | about.labels [ruse] | 
Referencia de asignación de campos: CORELIGHT - dnp3
En la siguiente tabla se enumeran los campos de registro del tipo de registro dnp3 y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| fc_request (string) | about.labels [fc_request] | |
| fc_reply (string) | about.labels [fc_reply] | |
| iin (integer - count) | about.labels [iin] | 
Referencia de la asignación de campos: CORELIGHT - iso_cotp
En la siguiente tabla se enumeran los campos de registro del tipo de registro iso_cotp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| pdu_type (string) | about.labels [pdu_type] | 
Referencia de asignación de campos: CORELIGHT - kerberos
En la siguiente tabla se enumeran los campos de registro del tipo de registro kerberos y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toKRB5. | |
| request_type (string) | principal.application | |
| client (string) | principal.hostname | |
| service (string) | target.application | |
| success (boolean - bool) | security_result.action | If the successlog field value is equal totrue, then thesecurity_result.actionUDM field is set toALLOW.Else, the security_result.actionUDM field is set toFAIL. | 
| error_msg (string) | security_result.action_details | |
| from (time) | about.labels [from] | |
| till (time) | about.labels [till] | |
| cipher (string) | about.labels [cipher] | |
| forwardable (boolean - bool) | about.labels [forwardable] | |
| renewable (boolean - bool) | about.labels [renewable] | |
| client_cert_subject (string) | about.labels [client_cert_subject] | |
| client_cert_fuid (string) | about.labels [client_cert_fuid] | |
| server_cert_subject (string) | about.labels [server_cert_subject] | |
| server_cert_fuid (string) | about.labels [server_cert_fuid] | 
Referencia de la asignación de campos: CORELIGHT - ldap
En la siguiente tabla se enumeran los campos de registro del tipo de registro ldap y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toLDAP. | |
| proto (string) | about.labels [proto] | |
| message_id (integer - int) | about.labels [message_id] | |
| version (integer - int) | network.application_protocol_version | |
| opcode (array[string] - set[string]) | security_result.detection_fields [opcode] | |
| result (array[string] - set[string]) | security_result.detection_fields [result] | |
| diagnostic_message (array[string] - vector of string) | security_result.description | |
| object (array[string] - vector of string) | about.labels [object] | |
| argument (array[string] - vector of string) | about.labels [argument] | 
Referencia de la asignación de campos: CORELIGHT - ldap_search
En la siguiente tabla se enumeran los campos de registro del tipo de registro ldap_search y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toLDAP. | |
| proto (string) | about.labels [proto] | |
| message_id (integer - int) | about.labels [message_id] | |
| scope (array[string] - set[string]) | about.labels [scope] | |
| deref (array[string] - set[string]) | about.labels [deref] | |
| base_object (array[string] - vector of string) | about.labels [base_object] | |
| result_count (integer - count) | security_result.detection_fields [result_count] | |
| result (array[string] - set[string]) | security_result.detection_fields [result] | |
| diagnostic_message (array[string] - vector of string) | security_result.description | |
| filter (string) | about.labels [filter] | |
| attributes (array[string] - vector of string) | about.labels [attributes] | 
Referencia de asignación de campos: CORELIGHT - local_subnets
En la siguiente tabla se enumeran los campos de registro del tipo de registro local_subnets y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| round (integer - count) | about.labels [round] | |
| ip_version (integer - count) | about.labels [ip_version] | |
| subnets (array[string] - set[subnet]) | about.labels [subnet] | |
| component_ids (array[integer] - set[count]) | about.labels [component_id] | |
| size_of_component (integer - count) | about.labels [size_of_component] | |
| bipartite (boolean - bool) | about.labels [bipartite] | |
| inferred_site (boolean - bool) | about.labels [inferred_site] | |
| other_ips (array[string] - set[addr]) | about.ip | 
Referencia de asignación de campos: CORELIGHT - local_subnets_dj
En la siguiente tabla se enumeran los campos de registro del tipo de registro local_subnets_dj y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| ip_version (integer - count) | about.labels [ip_version] | |
| v (string - addr) | about.ip | |
| side (string) | about.labels [side] | |
| component_id (integer - count) | additional.fields [component_id] | |
| round (integer - count) | additional.fields [round] | 
Referencia de la asignación de campos: CORELIGHT - local_subnets_graphs
En la siguiente tabla se enumeran los campos de registro del tipo de registro local_subnets_graphs y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| ip_version (integer - count) | about.labels [ip_version] | |
| v1 (string - addr) | about.ip | |
| v2 (string - addr) | about.ip | 
Referencia de asignación de campos: CORELIGHT - syslog
En la siguiente tabla se enumeran los campos de registro del tipo de registro syslog y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toSTATUS_UPDATE. | |
| proto (string - enum) | network.ip_protocol | |
| facility (string) | about.labels [facility] | |
| severity (string) | about.labels [severity] | |
| message (string) | metadata.description | 
Referencia de asignación de campos: CORELIGHT - tds
En la siguiente tabla se enumeran los campos de registro del tipo de registro tds y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| command (string) | principal.process.command_line | 
Referencia de la asignación de campos: CORELIGHT - tds_rpc
En la siguiente tabla se enumeran los campos de registro del tipo de registro tds_rpc y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| procedure_name (string) | about.labels [procedure_name] | |
| parameters (array[string] - vector of string) | about.labels [parameter] | 
Referencia de asignación de campos: CORELIGHT - tds_sql_batch
En la siguiente tabla se enumeran los campos de registro del tipo de registro tds_sql_batch y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toSTATUS_UPDATE. | |
| target.resource.resource_type | The target.resource.resource_typeUDM field is set toDATABASE. | |
| header_type (string) | target.resource.attribute.labels [header_type] | |
| query (string) | target.resource.attribute.labels [query] | 
Referencia de asignación de campos: CORELIGHT - traceroute
En la siguiente tabla se enumeran los campos de registro del tipo de registro traceroute y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| src (string - addr) | principal.ip | |
| dst (string - addr) | target.ip | |
| proto (string) | network.ip_protocol | 
Referencia de asignación de campos: CORELIGHT - tunnel
En la siguiente tabla se enumeran los campos de registro del tipo de registro tunnel y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| tunnel_type (string - enum) | intermediary.labels [tunnel_type] | |
| action (string - enum) | security_result.action_details | |
| security_result.description | The security_result.descriptionUDM field is set withaction,tunnel_typelog fields as "actionactionon tunnel typetunnel_type". | 
Referencia de asignación de campos: CORELIGHT - weird, weird_red, weird_agg
En la siguiente tabla se enumeran los campos de registro del tipo de registro weird, weird_red, weird_agg y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| name (string) | about.labels [name] | |
| addl (string) | about.labels [addl] | |
| notice (boolean - bool) | about.labels [notice] | |
| source (string) | about.labels [source] | |
| peer (string) | about.labels [peer] | 
Referencia de asignación de campos: CORELIGHT - wireguard
En la siguiente tabla se enumeran los campos de registro del tipo de registro wireguard y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| established (boolean - bool) | about.labels [established] | |
| initiations (integer - count) | about.labels [initiations] | |
| responses (integer - count) | about.labels [responses] | 
Referencia de asignación de campos: CORELIGHT - vpn
En la siguiente tabla se enumeran los campos de registro del tipo de registro vpn y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| proto (string - enum) | network.ip_protocol | |
| vpn_type (string - enum) | about.labels [vpn_type] | |
| service (string) | target.application | |
| inferences (array[string] - set[string]) | about.labels [inference] | |
| server_name (string) | network.tls.client.server_name | |
| client_info (string) | principal.labels [client_info] | |
| duration (number - interval) | network.session_duration | |
| orig_bytes (integer - count) | network.sent_bytes | |
| resp_bytes (integer - count) | network.received_bytes | |
| orig_cc (string) | principal.location.country_or_region | |
| orig_region (string) | principal.location.country_or_region | |
| orig_city (string) | principal.location.city | |
| resp_cc (string) | target.location.country_or_region | |
| resp_region (string) | target.location.country_or_region | |
| resp_city (string) | target.location.city | |
| subject (string) | network.tls.client.certificate.subject | |
| issuer (string) | network.tls.client.certificate.issuer | |
| ja3 (string) | network.tls.client.ja3 | |
| ja3s (string) | network.tls.server.ja3s | 
Referencia de asignación de campos: CORELIGHT - x509, x509_red
En la siguiente tabla se enumeran los campos de registro del tipo de registro x509, x509_red y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| fingerprint (string) | about.labels [fingerprint] | |
| certificate.version (integer - count) | network.tls.server.certificate.version | |
| certificate.serial (string) | network.tls.server.certificate.serial | |
| certificate.subject (string) | network.tls.server.certificate.subject | |
| certificate.issuer (string) | network.tls.server.certificate.issuer | |
| certificate.not_valid_before (time) | network.tls.server.certificate.not_before | |
| certificate.not_valid_after (time) | network.tls.server.certificate.not_after | |
| certificate.key_alg (string) | about.labels [certificate_key_alg] | |
| certificate.sig_alg (string) | about.labels [certificate_sig_alg] | |
| certificate.key_type (string) | about.labels [certificate_key_type] | |
| certificate.key_length (integer - count) | about.labels [certificate_key_length] | |
| certificate.exponent (string) | about.labels [certificate_exponent] | |
| certificate.curve (string) | network.tls.curve | |
| san.dns (array[string] - vector of string) | about.labels [san_dns] | |
| san.uri (array[string] - vector of string) | about.url | |
| san.email (array[string] - vector of string) | about.labels [san_email] | |
| san.ip (array[string] - vector of addr) | about.ip | |
| basic_constraints.ca (boolean - bool) | about.labels [basic_constraints_ca] | |
| basic_constraints.path_len (integer - count) | about.labels [basic_constraints_path_len] | |
| host_cert (boolean - bool) | about.labels [host_cert] | |
| client_cert (boolean - bool) | about.labels [client_cert] | |
| vlan (integer - int) | additional.fields [vlan] | |
| vlan_inner (integer - int) | additional.fields [vlan_inner] | 
Referencia de asignación de campos: CORELIGHT - unknown-smartpcap
En la siguiente tabla se enumeran los campos de registro del tipo de registro unknown-smartpcap y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toSmartpcap. | |
| tid (string) | about.labels [tid] | |
| pkts (integer - count) | about.labels [pkts] | |
| url (string) | security_result.url_back_to_product | 
Referencia de asignación de campos: CORELIGHT - mysql
En la siguiente tabla se enumeran los campos de registro del tipo de registro mysql y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toUSER_RESOURCE_ACCESS. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| cmd (string) | target.resource.attribute.labels [cmd] | |
| arg (string) | principal.process.command_line | |
| success (boolean - bool) | target.resource.attribute.labels [success] | |
| rows (integer - count) | target.resource.attribute.labels [rows] | |
| response (string) | target.resource.attribute.labels [response] | |
| target.resource.resource_type | The target.resource.resource_typeUDM field is set toDATABASE. | 
Referencia de asignación de campos: CORELIGHT - napatech_shunting
En la siguiente tabla se enumeran los campos de registro del tipo de registro napatech_shunting y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| peer (string) | about.labels [peer] | |
| terminated_flows (integer - count) | about.labels [terminated_flows] | |
| shunted_flows (integer - count) | security_result.detection_fields [shunted_flows] | 
Referencia de asignación de campos: CORELIGHT - ntlm
En la siguiente tabla se enumeran los campos de registro del tipo de registro ntlm y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toUSER_LOGIN. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| username (string) | target.user.userid | |
| hostname (string) | principal.hostname | |
| domainname (string) | principal.domain.name | |
| server_nb_computer_name (string) | target.hostname | |
| server_dns_computer_name (string) | target.domain.name | |
| server_tree_name (string) | target.labels [server_tree_name] | |
| success (boolean - bool) | extensions.auth.auth_details | If the successlog field value is equal totrue, then theextensions.auth.auth_detailsUDM field is set toAuthentication successful.Else, the extensions.auth.auth_detailsUDM field is set toAuthentication failed. | 
Referencia de asignación de campos: CORELIGHT - pe
En la siguiente tabla se enumeran los campos de registro del tipo de registro pe y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| id (string) | about.labels [id] | |
| machine (string) | target.labels [machine] | |
| compile_ts (time) | about.labels [compile_ts] | |
| os (string) | target.platform | If the oslog field value is equal towindows, then thetarget.platformUDM field is set toWINDOWS.Else, if is equal to linux, then thetarget.platformUDM field is set toLINUX.Else, if the oslog field value is equal tomac or the  | 
| subsystem (string) | target.application | |
| is_exe (boolean - bool) | about.file.file_type | If the is_exelog field value is equal totrue, then theabout.file.file_typeUDM field is set toFILE_TYPE_PE_EXE. | 
| is_64bit (boolean - bool) | about.labels [is_64bit] | |
| uses_aslr (boolean - bool) | about.labels [uses_aslr] | |
| uses_dep (boolean - bool) | about.labels [uses_dep] | |
| uses_code_integrity (boolean - bool) | about.labels [uses_code_integrity] | |
| uses_seh (boolean - bool) | about.labels [uses_seh ] | |
| has_import_table (boolean - bool) | about.labels [has_import_table] | |
| has_export_table (boolean - bool) | about.labels [has_export_table] | |
| has_cert_table (boolean - bool) | about.labels [has_cert_table] | |
| has_debug_data (boolean - bool) | about.labels [has_debug_data] | |
| section_names (array[string] - vector of string) | about.labels [section_names] | 
Referencia de la asignación de campos: CORELIGHT - ntp
En la siguiente tabla se enumeran los campos de registro del tipo de registro ntp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toNTP. | |
| network.ip_protocol | The network.ip_protocolUDM field is set toUDP. | |
| version (integer - count) | network.application_protocol_version | |
| mode (integer - count) | about.labels [mode] | |
| stratum (integer - count) | about.labels [stratum] | |
| poll (number - interval) | about.labels [poll] | |
| precision (number - interval) | about.labels [precision] | |
| root_delay (number - interval) | about.labels [root_delay] | |
| root_disp (number - interval) | about.labels [root_disp] | |
| ref_id (string) | target.ip | If the ref_idlog field value is matched with regex of IP, then theref_idlog field is mapped to thetarget.ipUDM field.Else, the ref_idlog field is mapped to thetarget.labelsUDM field. | 
| ref_id (string) | target.labels [ref_id] | If the ref_idlog field value is matched with regex of IP, then theref_idlog field is mapped to thetarget.ipUDM field.Else, the ref_idlog field is mapped to thetarget.labelsUDM field. | 
| ref_time (time) | about.labels [ref_time] | |
| org_time (time) | about.labels [org_time] | |
| rec_time (time) | about.labels [rec_time] | |
| xmt_time (time) | about.labels [rec_time] | |
| num_exts (integer - count) | about.labels [num_exts] | 
Referencia de asignación de campos: CORELIGHT - radio
En la siguiente tabla se enumeran los campos de registro del tipo de registro radius y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toUSER_LOGIN. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| username (string) | target.user.userid | |
| mac (string) | principal.mac | |
| framed_addr (string - addr) | intermediary.ip | |
| tunnel_client (string) | intermediary.ip | If the tunnel_clientlog field value is matched with regex of IP, then thetunnel_clientlog field is mapped to theintermediary.ipUDM field.Else, the tunnel_clientlog field is mapped to theintermediary.domain.nameUDM field. | 
| tunnel_client (string) | intermediary.domain.name | If the tunnel_clientlog field value is matched with regex of IP, then thetunnel_clientlog field is mapped to theintermediary.ipUDM field.Else, the tunnel_clientlog field is mapped to theintermediary.domain.nameUDM field. | 
| connect_info (string) | about.labels [connect_info] | |
| reply_msg (string) | about.labels [reply_msg] | |
| result (string) | extensions.auth.auth_details | |
| ttl (number - interval) | network.session_duration | 
Referencia de asignación de campos: CORELIGHT - reporter
En la siguiente tabla se enumeran los campos de registro del tipo de registro reporter y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| level (string - enum) | security_result.severity | If the levellog field value is equal toCRITICALorERRORorHIGHorINFORMATIONALorLOWorMEDIUM, then thelevellog field is mapped to thesecurity_result.severityUDM field. | 
| level (string - enum) | security_result.severity_details | |
| message (string) | security_result.description | |
| location (string) | about.labels [location] | 
Referencia de asignación de campos: CORELIGHT - log4shell
En la siguiente tabla se enumeran los campos de registro del tipo de registro log4shell y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toSCAN_HOST. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| extensions.vulns.vulnerabilities.cve_id | The extensions.vulns.vulnerabilities.cve_idUDM field is set toCVE-2021-44228. | |
| http_uri (string) | about.labels [http_uri] | |
| uri (string) | target.url | |
| stem (string) | target.labels [stem] | |
| target_host (string) | target.hostname | |
| target_port (string) | target.port | |
| method (string) | network.http.method | |
| is_orig (boolean - bool) | about.labels [is_orig] | |
| name (string) | about.labels.key | |
| value (string) | about.labels.value | |
| matched_name (boolean - bool) | about.labels [matched_name] | |
| matched_value (boolean - bool) | about.labels [matched_value] | 
Referencia de la asignación de campos: CORELIGHT - modbus
En la siguiente tabla se enumeran los campos de registro del tipo de registro modbus y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toMODBUS. | |
| func (string) | about.labels [func] | |
| exception (string) | security_result.description | |
| pdu_type (string) | additional.fields [pdu_type] | |
| tid (integer - count) | additional.fields [tid] | |
| unit (integer - count) | additional.fields [unit] | 
Referencia de asignación de campos: CORELIGHT - mqtt_connect
En la siguiente tabla se enumeran los campos de registro del tipo de registro mqtt_connect y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toMQTT. | |
| proto_name (string) | about.labels [proto_name] | |
| proto_version (string) | network.application_protocol_version | |
| client_id (string) | principal.labels [client_id] | |
| connect_status (string) | security_result.description | |
| will_topic (string) | about.labels [will_topic] | |
| will_payload (string) | about.labels [will_payload] | 
Referencia de asignación de campos: CORELIGHT - mqtt_publish
En la siguiente tabla se enumeran los campos de registro del tipo de registro mqtt_publish y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toMQTT. | |
| from_client (boolean - bool) | about.labels [from_client] | |
| retain (boolean - bool) | target.labels [retain] | |
| qos (string) | about.labels [qos] | |
| status (string) | security_result.description | |
| topic (string) | about.labels [topic] | |
| payload (string) | about.labels [payload] | |
| payload_len (integer - count) | about.labels [payload_len] | 
Referencia de asignación de campos: CORELIGHT - mqtt_subscribe
En la siguiente tabla se enumeran los campos de registro del tipo de registro mqtt_subscribe y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toMQTT. | |
| action (string - enum) | security_result.action_details | |
| topics (array[string] - vector of string) | about.labels [topics] | |
| qos_levels (array[integer] - vector of count) | about.labels [qos_levels] | |
| granted_qos_level (integer - count) | about.labels [granted_qos_level] | |
| ack (boolean - bool) | security_result.detection_fields [ack] | 
Referencia de la asignación de campos: CORELIGHT - dpd
En la siguiente tabla se enumeran los campos de registro del tipo de registro dpd y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| proto (string - enum) | network.ip_protocol | |
| analyzer (string) | about.labels [analyzer] | |
| failure_reason (string) | about.labels [failure_reason] | 
Referencia de asignación de campos: CORELIGHT - encrypted_dns
En la siguiente tabla se enumeran los campos de registro del tipo de registro encrypted_dns y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toDNS. | |
| resp_h (string - addr) | target.ip | |
| cert.cn (string) | about.labels [cert_cn] | |
| cert.sans (array[string] - set[string]) | about.labels [cert_sans] | |
| sni (string) | network.tls.client.server_name | |
| match (string) | about.labels [match] | 
Referencia de asignación de campos: CORELIGHT - enip
En la siguiente tabla se enumeran los campos de registro del tipo de registro enip y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| command (string) | principal.process.command_line | |
| length (integer - count) | about.labels [length] | |
| session_handle (string) | network.session_id | |
| status (string) | about.labels [status] | |
| sender_context (string) | about.labels [sender_context] | |
| options (string) | about.labels [options] | |
| enip_command (string) | additional.fields [enip_command] | |
| enip_command_code (string) | additional.fields [enip_command_code] | |
| enip_status (string) | additional.fields [enip_status] | |
| is_orig (boolean - bool) | additional.fields [is_orig] | 
Referencia de asignación de campos: CORELIGHT - enip_debug
En la siguiente tabla se enumeran los campos de registro del tipo de registro enip_debug y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toSTATUS_UPDATE. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| raw_data (string) | about.labels [raw_data] | 
Referencia de asignación de campos: CORELIGHT - enip_list_identity
En la siguiente tabla se enumeran los campos de registro del tipo de registro enip_list_identity y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| device_type (string) | target.asset.attribute.labels [device_type] | |
| vendor (string) | target.asset.hardware.manufacturer | |
| product_name (string) | target.asset.attribute.labels [product_name] | |
| serial_number (string) | target.asset.asset_id | The target.asset.asset_idUDM field is set withserial_numberlog fields as "CORELIGHT:serial_number". | 
| product_code (integer - count) | target.asset.attribute.labels [product_code] | |
| revision (number - double) | target.asset.attribute.labels [revision] | |
| status (string) | about.labels [status] | |
| state (string) | target.asset.attribute.labels [state] | |
| device_ip (string - addr) | target.asset.ip | 
Referencia de asignación de campos: CORELIGHT - etc_viz
En la siguiente tabla se enumeran los campos de registro del tipo de registro etc_viz y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| server_a (string - addr) | target.ip | |
| server_p (integer - port) | target.port | |
| service (array[string] - set[string]) | target.application | The servicelog field is mapped totarget.applicationUDM field when index value inserviceis equal to0.For every other index value, target.labels.keyUDM field is set toserviceandservicelog field is mapped to thetarget.labels.value. | 
| viz_stat (string) | about.labels [viz_stat] | |
| c2s_viz.size (integer - count) | about.labels [c2s_viz_size] | |
| c2s_viz.enc_dev (number - double) | about.labels [c2s_viz_enc_dev] | |
| c2s_viz.enc_frac (number - double) | about.labels [c2s_viz_enc_frac] | |
| c2s_viz.pdu1_enc (boolean - bool) | about.labels [c2s_viz_pdu1_enc] | |
| c2s_viz.clr_frac (number - double) | about.labels [c2s_viz_clr_frac] | |
| c2s_viz.clr_ex (string) | about.labels [c2s_viz_clr_ex] | |
| s2c_viz.size (integer - count) | about.labels [s2c_viz_size] | |
| s2c_viz.enc_dev (number - double) | about.labels [s2c_viz_enc_dev] | |
| s2c_viz.enc_frac (number - double) | about.labels [s2c_viz_enc_frac] | |
| s2c_viz.pdu1_enc (boolean - bool) | about.labels [s2c_viz_pdu1_enc] | |
| s2c_viz.clr_frac (number - double) | about.labels [s2c_viz_clr_frac] | |
| s2c_viz.clr_ex (string) | about.labels [s2c_viz_clr_ex] | 
Referencia de asignación de campos: CORELIGHT - ftp
En la siguiente tabla se enumeran los campos de registro del tipo de registro ftp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_FTP. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| user (string) | principal.user.user_display_name | |
| password (string) | extensions.auth.auth_details | |
| command (string), arg (string) | network.ftp.command | The network.ftp.commandUDM field is set withcommand,arglog fields as "commandarg". | 
| mime_type (string) | target.file.mime_type | |
| file_size (integer - count) | target.file.size | |
| reply_code (integer - count) | about.labels [reply_code] | |
| reply_msg (string) | about.labels [reply_msg] | |
| data_channel.passive (boolean - bool) | about.labels [data_channel_passive] | |
| data_channel.orig_h (string - addr) | principal.ip | |
| data_channel.resp_h (string - addr) | target.ip | |
| data_channel.resp_p (integer - port) | target.labels [data_channel_resp_p] | |
| fuid (string) | about.labels [fuid] | 
Referencia de asignación de campos: CORELIGHT - generic_dns_tunnels
En la siguiente tabla se enumeran los campos de registro del tipo de registro generic_dns_tunnels y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_DNS. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toDNS. | |
| dns_client (string - addr) | principal.ip | |
| domain (string) | network.dns_domain | |
| domain (string) | network.dns.questions.name | |
| bytes (integer - int) | about.labels [bytes] | |
| capture_secs (number - interval) | about.labels [capture_secs] | 
Referencia de asignación de campos: CORELIGHT - generic_icmp_tunnels
En la siguiente tabla se enumeran los campos de registro del tipo de registro generic_icmp_tunnels y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.ip_protocol | The network.ip_protocolUDM field is set toICMP. | |
| detection (string) | security_result.detection_fields [detection] | |
| orig (string - addr) | principal.ip | |
| resp (string - addr) | target.ip | |
| id (integer - count) | about.labels [id] | |
| seq (integer - count) | about.labels [seq] | |
| bytes (integer - count) | about.labels [bytes] | |
| payload_len (integer - count) | about.labels [payload_len] | |
| payload (string) | about.labels [payload] | 
Referencia de asignación de campos: CORELIGHT - icmp_specific_tunnels
En la siguiente tabla se enumeran los campos de registro del tipo de registro icmp_specific_tunnels y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.ip_protocol | The network.ip_protocolUDM field is set toICMP. | |
| start_time (time) | about.labels [start_time] | |
| duration (number - interval) | network.session_duration | |
| tunnel (string) | intermediary.labels [tunnel] | |
| seq (integer - count) | about.labels [seq] | |
| icmp_id (integer - count) | about.labels [icmp_id] | |
| payload (string) | about.labels [payload] | 
Referencia de asignación de campos: CORELIGHT - ipsec
En la siguiente tabla se enumeran los campos de registro del tipo de registro ipsec y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| initiator_spi (string) | principal.labels [initiator_spi] | |
| responder_spi (string) | target.labels [responder_spi] | |
| maj_ver (integer - count) | about.labels [maj_ver] | |
| min_ver (integer - count) | about.labels [min_ver] | |
| exchange_type (integer - count) | about.labels [exchange_type] | |
| flag_e (boolean - bool) | about.labels [flag_e] | |
| flag_c (boolean - bool) | about.labels [flag_c] | |
| flag_a (boolean - bool) | about.labels [flag_a] | |
| flag_i (boolean - bool) | about.labels [flag_i] | |
| flag_v (boolean - bool) | about.labels [flag_v] | |
| flag_r (boolean - bool) | about.labels [flag_r] | |
| message_id (integer - count) | about.labels [message_id] | |
| vendor_ids (array[string] - vector of string) | about.labels [vendor_id] | |
| notify_messages (array[string] - vector of string) | about.labels [notify_message] | |
| transforms (array[string] - vector of string) | about.labels [transform] | |
| ke_dh_groups (array[integer] - vector of count) | about.labels [ke_dh_group] | |
| proposals (array[integer] - vector of count) | about.labels [proposal] | |
| protocol_id (integer - count) | about.labels [protocol_id] | |
| certificates (array[string] - vector of string) | about.labels [certificate] | |
| transform_attributes (array[string] - vector of string) | about.labels [transform_attribute] | |
| length (integer - count) | about.labels [length] | |
| hash (string) | about.labels [hash] | |
| doi (integer - count) | about.labels [doi] | |
| situation (string) | about.labels [situation] | |
| is_orig (boolean - bool) | additional.fields [is_orig] | 
Referencia de la asignación de campos: CORELIGHT - profinet
En la siguiente tabla se enumeran los campos de registro del tipo de registro profinet y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| operation_type (string) | about.labels [operation_type] | |
| block_version (string) | about.labels [block_version] | |
| slot_number (integer - count) | about.labels [slot_number] | |
| subslot_number (integer - count) | about.labels [subslot_number] | |
| index (string) | about.labels [index] | 
Referencia de asignación de campos: CORELIGHT - profinet_dce_rpc
En la siguiente tabla se enumeran los campos de registro del tipo de registro profinet_dce_rpc y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toDCERPC. | |
| version (integer - count) | about.labels [version] | |
| packet_type (integer - count) | about.labels [packet_type] | |
| object_uuid (string) | about.labels [object_uuid] | |
| interface_uuid (string) | about.labels [interface_uuid] | |
| activity_uuid (string) | about.labels [activity_uuid] | |
| server_boot_time (integer - count) | about.labels [server_boot_time] | |
| operation (string) | about.labels [operation] | 
Referencia de asignación de campos: CORELIGHT - profinet_debug
En la siguiente tabla se enumeran los campos de registro del tipo de registro profinet_debug y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| raw_data (string) | about.labels [raw_data] | 
Referencia de asignación de campos: CORELIGHT - rfb
En la siguiente tabla se enumeran los campos de registro del tipo de registro rfb y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| client_major_version (string) | principal.labels [client_major_version] | |
| client_minor_version (string) | principal.labels [client_minor_version] | |
| server_major_version (string) | target.labels [server_major_version] | |
| server_minor_version (string) | target.labels [server_minor_version] | |
| authentication_method (string) | extension.auth.mechanism | If the authentication_methodlog field value is equal toVNC, then theextension.auth.mechanismUDM field is set toREMOTE_INTERACTIVE.Else, the extensions.auth.mechanismUDM field is set toMECHANISM_OTHER. | 
| authentication_method (string) | extension.auth.auth_details | |
| auth (boolean - bool) | security_result.action | If the authlog field value is equal totrue, then thesecurity_result.actionUDM field is set toALLOW.Else, the security_result.actionUDM field is set toFAIL. | 
| share_flag (boolean - bool) | about.labels [share_flag] | |
| desktop_name (string) | principal.labels [desktop_name] | |
| width (integer - count) | principal.labels [width] | |
| height (integer - count) | principal.labels [height] | 
Referencia de asignación de campos: CORELIGHT - known_certs
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_certs y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toRESOURCE. | |
| entity.resource.resource_subtype | The entity.resource.resource_subtypeUDM field is set toCERTIFICATE. | |
| ts (time) | metadata.interval.start_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| hash (string) | entity.resource.attribute.labels [hash] | |
| port (integer - port) | entity.port | |
| protocol (string - enum) | entity.labels [protocol] | |
| serial (string) | entity.resource.attribute.labels [serial] | |
| subject (string) | entity.resource.attribute.labels [subject] | |
| issuer_subject (string) | entity.resource.attribute.labels [issuer_subject] | |
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | |
| port_num (integer - port) | entity.port | 
Referencia de asignación de campos: CORELIGHT - known_devices
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_devices y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toRESOURCE. | |
| ts (time) | metadata.interval.start_time | |
| ts (time) | entity.asset.first_seen_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.asset.ip | |
| mac (string) | entity.asset.mac | |
| vendor_mac (string) | entity.asset.hardware.manufacturer | |
| protocols (array[string] - set[string]) | entity.labels [protocol] | |
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | 
Referencia de asignación de campos: CORELIGHT - known_domains
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_domains y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toDOMAIN_NAME. | |
| ts (time) | metadata.interval.start_time | |
| ts (time) | entity.domain.first_seen_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| domain (string) | entity.domain.name | |
| protocols (array[string] - set[string]) | entity.labels [protocol] | |
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | 
Referencia de asignación de campos: CORELIGHT - known_hosts
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_hosts y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toIP_ADDRESS. | |
| ts (time) | metadata.interval.start_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| conns_opened (integer - count) | metadata.threat.detection_fields [conns_opened] | |
| conns_closed (integer - count) | metadata.threat.detection_fields [conns_closed] | |
| conns_pending (integer - count) | metadata.threat.detection_fields [conns_pending] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| ep.cid (string) | additional.fields [ep_cid] | |
| ep.criticality (string) | entity.security_result.detection_fields[ep_criticality] | |
| ep.desc (string) | metadata.description | |
| ep.os_version (string) | entity.platform_version | |
| ep.source (string) | additional.fields [ep_source] | |
| ep.status (string) | additional.fields [ep_status] | |
| ep.uid (string) | additional.fields [ep_uid] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | 
Referencia de asignación de campos: CORELIGHT - known_names
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_names y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toRESOURCE. | |
| ts (time) | metadata.interval.start_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| hostname (string) | entity.hostname | |
| protocols (array[string] - set[string]) | entity.labels [protocol] | |
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | 
Referencia de asignación de campos: CORELIGHT - known_remotes
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_remotes y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toIP_ADDRESS. | |
| ts (time) | metadata.interval.start_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | 
Referencia de asignación de campos: CORELIGHT - known_services
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_services y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toRESOURCE. | |
| ts (time) | metadata.interval.start_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| port (integer - port) | entity.port | |
| protocol (string - enum) | entity.labels [protocol] | |
| service (array[string] - vector of string) | entity.labels [service] | |
| software (array[string] - set[string]) | entity.asset.software.name | |
| app (array[string] - set[string]) | entity.application | The applog field is mapped toentity.applicationUDM field when index value inappis equal to0.For every other index value, entity.labels.keyUDM field is set toappandapplog field is mapped to theentity.labels.value. | 
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | |
| num_conns_complete (integer - count) | entity.security_result.detection_fields[num_conns_complete] | |
| num_conns_pending (integer - int) | entity.security_result.detection_fields[num_conns_pending] | |
| port_num (integer - port) | entity.port | 
Referencia de asignación de campos: CORELIGHT - known_users
En la siguiente tabla se enumeran los campos de registro del tipo de registro known_users y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| metadata.entity_type | The metadata.entity_typeUDM field is set toRESOURCE. | |
| ts (time) | metadata.interval.start_time | |
| duration (number - interval) | entity.labels [duration] | |
| kuid (string) | entity.labels [kuid] | |
| host_ip (string - addr) | entity.ip | |
| remote_ip (string - addr) | entity.ip | |
| user (string) | entity.user.user_display_name | |
| protocol (string) | entity.labels [protocol] | |
| num_conns (integer - count) | metadata.threat.detection_fields [num_conns] | |
| annotations (array[string] - vector of string) | metadata.threat.detection_fields [annotations] | |
| last_active_session (string) | entity.labels [last_active_session] | |
| last_active_interval (number - interval) | entity.labels [last_active_interval] | |
| host_inner_vlan (integer - int) | additional.fields [host_inner_vlan] | |
| host_vlan (integer - int) | additional.fields [host_vlan] | |
| remote_inner_vlan (integer - int) | additional.fields [remote_inner_vlan] | |
| remote_vlan (integer - int) | additional.fields [remote_vlan] | |
| long_conns (integer - count) | metadata.threat.detection_fields [long_conns] | 
Referencia de asignación de campos: CORELIGHT - s7comm
En la siguiente tabla se enumeran los campos de registro del tipo de registro s7comm y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set toZeek. | |
| rosctr (string) | about.labels [rosctr] | |
| parameter (array[string] - vector of string) | about.labels [parameter] | |
| item_count (integer - count) | about.labels [item_count] | |
| data_info (array[string] - vector of string) | about.labels [data_info] | |
| error_class (string) | additional.fields [error_class] | |
| error_code (string) | additional.fields [error_code] | |
| function_code (string) | additional.fields [function_code] | |
| function_name (string) | additional.fields [function_name] | |
| is_orig (boolean - bool) | additional.fields [is_orig] | |
| pdu_reference (integer - count) | additional.fields [pdu_reference] | |
| rosctr_code (integer - count) | additional.fields [rosctr_code] | |
| rosctr_name (string) | additional.fields [rosctr_name] | |
| subfunction_code (string) | additional.fields [subfunction_code] | |
| subfunction_name (string) | additional.fields [subfunction_name] | 
Referencia de asignación de campos: CORELIGHT - smartpcap
En la siguiente tabla se enumeran los campos de registro del tipo de registro smartpcap y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toSmartpcap. | |
| logstr (string) | metadata.description | 
Referencia de asignación de campos: CORELIGHT - snmp
En la siguiente tabla se enumeran los campos de registro del tipo de registro snmp y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_UNCATEGORIZED. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| duration (number - interval) | network.session_duration | |
| version (string) | network.application_protocol_version | |
| community (string) | about.labels [community] | |
| get_requests (integer - count) | about.labels [get_requests] | |
| get_bulk_requests (integer - count) | about.labels [get_bulk_requests] | |
| get_responses (integer - count) | about.labels [get_responses] | |
| set_requests (integer - count) | about.labels [set_requests] | |
| display_string (string) | about.labels [display_string] | |
| up_since (time) | about.labels [up_since] | 
Referencia de asignación de campos: CORELIGHT - socks
En la siguiente tabla se enumeran los campos de registro del tipo de registro socks y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| version (integer - count) | about.labels [version] | |
| user (string) | principal.user.userid | |
| password (string) | extensions.auth.auth_details | |
| status (string) | about.labels [status] | |
| request.host (string - addr) | target.ip | |
| request.name (string) | target.hostname | |
| request_p (integer - port) | target.labels [request_p] | |
| bound.host (string - addr) | intermediary.ip | |
| bound.name (string) | intermediary.hostname | |
| bound_p (integer - port) | intermediary.port | 
Referencia de asignación de campos: CORELIGHT - software
En la siguiente tabla se enumeran los campos de registro del tipo de registro software y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| host (string - addr) | target.asset.ip | |
| host_p (integer - port) | target.port | |
| software_type (string - enum) | target.asset.software.description | |
| name (string) | target.asset.software.name | |
| version.major (integer - count) | target.asset.software.version | |
| version.minor (integer - count) | target.asset.attribute.labels [version_minor] | |
| version.minor2 (integer - count) | target.asset.attribute.labels [version_minor2] | |
| version.minor3 (integer - count) | target.asset.attribute.labels [version_minor3] | |
| version.addl (string) | target.asset.attribute.labels [version_addl] | |
| unparsed_version (string) | target.asset.attribute.labels [unparsed_version] | 
Referencia de asignación de campos: CORELIGHT - specific_dns_tunnels
En la siguiente tabla se enumeran los campos de registro del tipo de registro specific_dns_tunnels y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_DNS. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| network.application_protocol | The network.application_protocolUDM field is set toDNS. | |
| trans_id (integer - count) | network.dns.id | |
| dns_client (string - addr) | principal.ip | |
| resolver (string - addr) | target.ip | |
| query (string) | network.dns.questions.name | |
| program (string - enum) | principal.application | |
| session_id (integer - count) | network.session_id | |
| detection (string) | security_result.detection_fields [detection] | |
| sods_id (integer - count) | about.labels [sods_id] | 
Referencia de asignación de campos: CORELIGHT - stepping
En la siguiente tabla se enumeran los campos de registro del tipo de registro stepping y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| dt (number - interval) | about.labels [dt] | |
| uid1 (string) | about.labels [uid1] | |
| uid2 (string) | about.labels [uid2] | |
| direct (boolean - bool) | about.labels [direct] | |
| client1_h (string - addr) | principal.ip | |
| client1_p (integer - port) | principal.port | |
| server1_h (string - addr) | target.ip | |
| server1_p (integer - port) | target.port | |
| client2_h (string - addr) | principal.ip | |
| client2_p (integer - port) | principal.labels [client2_p] | |
| server2_h (string - addr) | target.labels [server2_h] | |
| server2_p (integer - port) | target.labels [server2_p] | 
Referencia de asignación de campos: CORELIGHT - stun
En la siguiente tabla se enumeran los campos de registro del tipo de registro stun y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| proto (string - enum) | network.ip_protocol | |
| is_orig (boolean - bool) | about.labels [is_orig] | |
| trans_id (string) | network.session_id | |
| method (string) | about.labels [method] | |
| class (string) | about.labels [class] | |
| attr_types (array[string] - vector of string) | about.labels.key  | |
| attr_vals (array[string] - vector of string) | about.labels.value | 
Referencia de asignación de campos: CORELIGHT - stun_nat
En la siguiente tabla se enumeran los campos de registro del tipo de registro stun_nat y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toNETWORK_CONNECTION. | |
| metadata.product_name | The metadata.product_nameUDM field is set tozeek. | |
| proto (string - enum) | network.ip_protocol | |
| is_orig (boolean - bool) | about.labels [is_orig] | |
| wan_addrs (array[string] - vector of addr) | principal.nat_ip | |
| wan_ports (array[integer] - vector of count) | principal.nat_port | The wan_portslog field is mapped toprincipal.nat_portUDM field when index value inwan_portsis equal to0.For every other index value, principal.labels.keyUDM field is set towan_portandwan_portslog field is mapped to theprincipal.labels.value. | 
| lan_addrs (array[string] - vector of addr) | principal.ip | 
Referencia de asignación de campos: CORELIGHT - suricata_stats
En la siguiente tabla se enumeran los campos de registro del tipo de registro suricata_stats y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| metadata.product_name | The metadata.product_nameUDM field is set toSuricata. | |
| raw_mgmt | about.labels  [raw_mgmt] | |
| timestamp(time) | metadata.event_timestamp | |
| event_type(string) | about.labels  [event_type] | |
| stats.uptime(integer) | about.labels [stats_uptime] | |
| stats.napa_total.pkts(integer) | about.labels [stats_napa_total_pkts] | |
| stats.napa_total.byte(integer) | about.labels [stats_napa_total_byte] | |
| stats.napa_total.overflow_drop_pkts(integer) | about.labels [stats_napa_total_overflow_drop_pkts] | |
| stats.napa_total.overflow_drop_byte(integer) | about.labels [stats_napa_total_overflow_drop_byte] | |
| stats.napa_dispatch_host.pkts(integer) | about.labels [stats_napa_dispatch_host_pkts] | |
| stats.napa_dispatch_host.byte(integer) | about.labels [stats_napa_dispatch_host_byte] | |
| stats.napa_dispatch_drop.pkts(integer) | about.labels [stats_napa_dispatch_drop_pkts] | |
| stats.napa_dispatch_drop.byte(integer) | about.labels [stats_napa_dispatch_drop_byte] | |
| stats.decoder.pkts(integer) | about.labels [stats_decoder_pkts] | |
| stats.decoder.bytes(integer) | about.labels [stats_decoder_bytes] | |
| stats.decoder.invalid(integer) | about.labels [stats_decoder_invalid] | |
| stats.decoder.ipv4(integer) | about.labels [stats_decoder_ipv4] | |
| stats.decoder.ipv6(integer) | about.labels [stats_decoder_ipv6] | |
| stats.decoder.ethernet(integer) | about.labels [stats_decoder_ethernet] | |
| stats.decoder.chdlc(integer) | about.labels [stats_decoder_chdlc] | |
| stats.decoder.raw(integer) | about.labels [stats_decoder_raw] | |
| stats.decoder.null(integer) | about.labels [stats_decoder_null] | |
| stats.decoder.sll(integer) | about.labels [stats_decoder_sll] | |
| stats.decoder.tcp(integer) | about.labels [stats_decoder_tcp] | |
| stats.decoder.udp(integer) | about.labels [stats_decoder_udp] | |
| stats.decoder.sctp(integer) | about.labels [stats_decoder_sctp] | |
| stats.decoder.icmpv4(integer) | about.labels [stats_decoder_icmpv4] | |
| stats.decoder.icmpv6(integer) | about.labels [stats_decoder_icmpv6] | |
| stats.decoder.ppp(integer) | about.labels [stats_decoder_ppp] | |
| stats.decoder.pppoe(integer) | about.labels [stats_decoder_pppoe] | |
| stats.decoder.geneve(integer) | about.labels [stats_decoder_geneve] | |
| stats.decoder.gre(integer) | about.labels [stats_decoder_gre] | |
| stats.decoder.vlan(integer) | about.labels [stats_decoder_vlan] | |
| stats.decoder.vlan_qinq(integer) | about.labels [stats_decoder_vlan_qinq] | |
| stats.decoder.vxlan(integer) | about.labels [stats_decoder_vxlan] | |
| stats.decoder.vntag(integer) | about.labels [stats_decoder_vntag] | |
| stats.decoder.ieee8021ah(integer) | about.labels [stats_decoder_ieee8021ah] | |
| stats.decoder.teredo(integer) | about.labels [stats_decoder_teredo] | |
| stats.decoder.ipv4_in_ipv6(integer) | about.labels [stats_decoder_ipv4_in_ipv6] | |
| stats.decoder.ipv6_in_ipv6(integer) | about.labels [stats_decoder_ipv6_in_ipv6] | |
| stats.decoder.mpls(integer) | about.labels [stats_decoder_mpls] | |
| stats.decoder.avg_pkt_size(integer) | about.labels [stats_decoder_avg_pkt_size] | |
| stats.decoder.max_pkt_size(integer) | about.labels [stats_decoder_max_pkt_size] | |
| stats.decoder.max_mac_addrs_src(integer) | about.labels [stats_decoder_max_mac_addrs_src] | |
| stats.decoder.max_mac_addrs_dst(integer) | about.labels [stats_decoder_max_mac_addrs_dst] | |
| stats.decoder.erspan(integer) | about.labels [stats_decoder_erspan] | |
| stats.decoder.event.ipv4.pkt_too_small(integer) | about.labels [stats_decoder_event_ipv4_pkt_too_small] | |
| stats.decoder.event.ipv4.hlen_too_small(integer) | about.labels [stats_decoder_event_ipv4_hlen_too_small] | |
| stats.decoder.event.ipv4.iplen_smaller_than_hlen(integer) | about.labels [stats_decoder_event_ipv4_iplen_smaller_than_hlen] | |
| stats.decoder.event.ipv4.trunc_pkt(integer) | about.labels [stats_decoder_event_ipv4_trunc_pkt] | |
| stats.decoder.event.ipv4.opt_invalid(integer) | about.labels [stats_decoder_event_ipv4_opt_invalid] | |
| stats.decoder.event.ipv4.opt_invalid_len(integer) | about.labels [stats_decoder_event_ipv4_opt_invalid_len] | |
| stats.decoder.event.ipv4.opt_malformed(integer) | about.labels [stats_decoder_event_ipv4_opt_malformed] | |
| stats.decoder.event.ipv4.opt_pad_required(integer) | about.labels [stats_decoder_event_ipv4_opt_pad_required] | |
| stats.decoder.event.ipv4.opt_eol_required(integer) | about.labels [stats_decoder_event_ipv4_opt_eol_required] | |
| stats.decoder.event.ipv4.opt_duplicate(integer) | about.labels [stats_decoder_event_ipv4_opt_duplicate] | |
| stats.decoder.event.ipv4.opt_unknown(integer) | about.labels [stats_decoder_event_ipv4_opt_unknown] | |
| stats.decoder.event.ipv4.wrong_ip_version(integer) | about.labels [stats_decoder_event_ipv4_wrong_ip_version] | |
| stats.decoder.event.ipv4.icmpv6(integer) | about.labels [stats_decoder_event_ipv4_icmpv6] | |
| stats.decoder.event.ipv4.frag_pkt_too_large(integer) | about.labels [stats_decoder_event_ipv4_frag_pkt_too_large] | |
| stats.decoder.event.ipv4.frag_overlap(integer) | about.labels [stats_decoder_event_ipv4_frag_overlap] | |
| stats.decoder.event.ipv4.frag_ignored(integer) | about.labels [stats_decoder_event_ipv4_frag_ignored] | |
| stats.decoder.event.icmpv4.pkt_too_small(integer) | about.labels [stats_decoder_event_icmpv4_pkt_too_small] | |
| stats.decoder.event.icmpv4.unknown_type(integer) | about.labels [stats_decoder_event_icmpv4_unknown_type] | |
| stats.decoder.event.icmpv4.unknown_code(integer) | about.labels [stats_decoder_event_icmpv4_unknown_code] | |
| stats.decoder.event.icmpv4.ipv4_trunc_pkt(integer) | about.labels [stats_decoder_event_icmpv4_ipv4_trunc_pkt] | |
| stats.decoder.event.icmpv4.ipv4_unknown_ver(integer) | about.labels [stats_decoder_event_icmpv4_ipv4_unknown_ver] | |
| stats.decoder.event.icmpv6.unknown_type(integer) | about.labels [stats_decoder_event_icmpv6_unknown_type] | |
| stats.decoder.event.icmpv6.unknown_code(integer) | about.labels [stats_decoder_event_icmpv6_unknown_code] | |
| stats.decoder.event.icmpv6.pkt_too_small(integer) | about.labels [stats_decoder_event_icmpv6_pkt_too_small] | |
| stats.decoder.event.icmpv6.ipv6_unknown_version(integer) | about.labels [stats_decoder_event_icmpv6_ipv6_unknown_version] | |
| stats.decoder.event.icmpv6.ipv6_trunc_pkt(integer) | about.labels [stats_decoder_event_icmpv6_ipv6_trunc_pkt] | |
| stats.decoder.event.icmpv6.mld_message_with_invalid_hl(integer) | about.labels [stats_decoder_event_icmpv6_mld_message_with_invalid_hl] | |
| stats.decoder.event.icmpv6.unassigned_type(integer) | about.labels [stats_decoder_event_icmpv6_unassigned_type] | |
| stats.decoder.event.icmpv6.experimentation_type(integer) | about.labels [stats_decoder_event_icmpv6_experimentation_type] | |
| stats.decoder.event.ipv6.pkt_too_small(integer) | about.labels [stats_decoder_event_ipv6_pkt_too_small] | |
| stats.decoder.event.ipv6.trunc_pkt(integer) | about.labels [stats_decoder_event_ipv6_trunc_pkt] | |
| stats.decoder.event.ipv6.trunc_exthdr(integer) | about.labels [stats_decoder_event_ipv6_trunc_exthdr] | |
| stats.decoder.event.ipv6.exthdr_dupl_fh(integer) | about.labels [stats_decoder_event_ipv6_exthdr_dupl_fh] | |
| stats.decoder.event.ipv6.exthdr_useless_fh(integer) | about.labels [stats_decoder_event_ipv6_exthdr_useless_fh] | |
| stats.decoder.event.ipv6.exthdr_dupl_rh(integer) | about.labels [stats_decoder_event_ipv6_exthdr_dupl_rh] | |
| stats.decoder.event.ipv6.exthdr_dupl_hh(integer) | about.labels [stats_decoder_event_ipv6_exthdr_dupl_hh] | |
| stats.decoder.event.ipv6.exthdr_dupl_dh(integer) | about.labels [stats_decoder_event_ipv6_exthdr_dupl_dh] | |
| stats.decoder.event.ipv6.exthdr_dupl_ah(integer) | about.labels [stats_decoder_event_ipv6_exthdr_dupl_ah] | |
| stats.decoder.event.ipv6.exthdr_dupl_eh(integer) | about.labels [stats_decoder_event_ipv6_exthdr_dupl_eh] | |
| stats.decoder.event.ipv6.exthdr_invalid_optlen(integer) | about.labels [stats_decoder_event_ipv6_exthdr_invalid_optlen] | |
| stats.decoder.event.ipv6.wrong_ip_version(integer) | about.labels [stats_decoder_event_ipv6_wrong_ip_version] | |
| stats.decoder.event.ipv6.exthdr_ah_res_not_null(integer) | about.labels [stats_decoder_event_ipv6_exthdr_ah_res_not_null] | |
| stats.decoder.event.ipv6.hopopts_unknown_opt(integer) | about.labels [stats_decoder_event_ipv6_hopopts_unknown_opt] | |
| stats.decoder.event.ipv6.hopopts_only_padding(integer) | about.labels [stats_decoder_event_ipv6_hopopts_only_padding] | |
| stats.decoder.event.ipv6.dstopts_unknown_opt(integer) | about.labels [stats_decoder_event_ipv6_dstopts_unknown_opt] | |
| stats.decoder.event.ipv6.dstopts_only_padding(integer) | about.labels [stats_decoder_event_ipv6_dstopts_only_padding] | |
| stats.decoder.event.ipv6.rh_type_0(integer) | about.labels [stats_decoder_event_ipv6_rh_type_0] | |
| stats.decoder.event.ipv6.zero_len_padn(integer) | about.labels [stats_decoder_event_ipv6_zero_len_padn] | |
| stats.decoder.event.ipv6.fh_non_zero_reserved_field(integer) | about.labels [stats_decoder_event_ipv6_fh_non_zero_reserved_field] | |
| stats.decoder.event.ipv6.data_after_none_header(integer) | about.labels [stats_decoder_event_ipv6_data_after_none_header] | |
| stats.decoder.event.ipv6.unknown_next_header(integer) | about.labels [stats_decoder_event_ipv6_unknown_next_header] | |
| stats.decoder.event.ipv6.icmpv4(integer) | about.labels [stats_decoder_event_ipv6_icmpv4] | |
| stats.decoder.event.ipv6.frag_pkt_too_large(integer) | about.labels [stats_decoder_event_ipv6_frag_pkt_too_large] | |
| stats.decoder.event.ipv6.frag_overlap(integer) | about.labels [stats_decoder_event_ipv6_frag_overlap] | |
| stats.decoder.event.ipv6.frag_invalid_length(integer) | about.labels [stats_decoder_event_ipv6_frag_invalid_length] | |
| stats.decoder.event.ipv6.frag_ignored(integer) | about.labels [stats_decoder_event_ipv6_frag_ignored] | |
| stats.decoder.event.ipv6.ipv4_in_ipv6_too_small(integer) | about.labels [stats_decoder_event_ipv6_ipv4_in_ipv6_too_small] | |
| stats.decoder.event.ipv6.ipv4_in_ipv6_wrong_version(integer) | about.labels [stats_decoder_event_ipv6_ipv4_in_ipv6_wrong_version] | |
| stats.decoder.event.ipv6.ipv6_in_ipv6_too_small(integer) | about.labels [stats_decoder_event_ipv6_ipv6_in_ipv6_too_small] | |
| stats.decoder.event.ipv6.ipv6_in_ipv6_wrong_version(integer) | about.labels [stats_decoder_event_ipv6_ipv6_in_ipv6_wrong_version] | |
| stats.decoder.event.tcp.pkt_too_small(integer) | about.labels [stats_decoder_event_tcp_pkt_too_small] | |
| stats.decoder.event.tcp.hlen_too_small(integer) | about.labels [stats_decoder_event_tcp_hlen_too_small] | |
| stats.decoder.event.tcp.invalid_optlen(integer) | about.labels [stats_decoder_event_tcp_invalid_optlen] | |
| stats.decoder.event.tcp.opt_invalid_len(integer) | about.labels [stats_decoder_event_tcp_opt_invalid_len] | |
| stats.decoder.event.tcp.opt_duplicate(integer) | about.labels [stats_decoder_event_tcp_opt_duplicate] | |
| stats.decoder.event.udp.pkt_too_small(integer) | about.labels [stats_decoder_event_udp_pkt_too_small] | |
| stats.decoder.event.udp.hlen_too_small(integer) | about.labels [stats_decoder_event_udp_hlen_too_small] | |
| stats.decoder.event.udp.hlen_invalid(integer) | about.labels [stats_decoder_event_udp_hlen_invalid] | |
| stats.decoder.event.udp.len_invalid(integer) | about.labels [stats_decoder_event_udp_len_invalid] | |
| stats.decoder.event.sll.pkt_too_small(integer) | about.labels [stats_decoder_event_sll_pkt_too_small] | |
| stats.decoder.event.ethernet.pkt_too_small(integer) | about.labels [stats_decoder_event_ethernet_pkt_too_small] | |
| stats.decoder.event.ppp.pkt_too_small(integer) | about.labels [stats_decoder_event_ppp_pkt_too_small] | |
| stats.decoder.event.ppp.vju_pkt_too_small(integer) | about.labels [stats_decoder_event_ppp_vju_pkt_too_small] | |
| stats.decoder.event.ppp.ip4_pkt_too_small(integer) | about.labels [stats_decoder_event_ppp_ip4_pkt_too_small] | |
| stats.decoder.event.ppp.ip6_pkt_too_small(integer) | about.labels [stats_decoder_event_ppp_ip6_pkt_too_small] | |
| stats.decoder.event.ppp.wrong_type(integer) | about.labels [stats_decoder_event_ppp_wrong_type] | |
| stats.decoder.event.ppp.unsup_proto(integer) | about.labels [stats_decoder_event_ppp_unsup_proto] | |
| stats.decoder.event.pppoe.pkt_too_small(integer) | about.labels [stats_decoder_event_pppoe_pkt_too_small] | |
| stats.decoder.event.pppoe.wrong_code(integer) | about.labels [stats_decoder_event_pppoe_wrong_code] | |
| stats.decoder.event.pppoe.malformed_tags(integer) | about.labels [stats_decoder_event_pppoe_malformed_tags] | |
| stats.decoder.event.gre.pkt_too_small(integer) | about.labels [stats_decoder_event_gre_pkt_too_small] | |
| stats.decoder.event.gre.wrong_version(integer) | about.labels [stats_decoder_event_gre_wrong_version] | |
| stats.decoder.event.gre.version0_recur(integer) | about.labels [stats_decoder_event_gre_version0_recur] | |
| stats.decoder.event.gre.version0_flags(integer) | about.labels [stats_decoder_event_gre_version0_flags] | |
| stats.decoder.event.gre.version0_hdr_too_big(integer) | about.labels [stats_decoder_event_gre_version0_hdr_too_big] | |
| stats.decoder.event.gre.version0_malformed_sre_hdr(integer) | about.labels [stats_decoder_event_gre_version0_malformed_sre_hdr] | |
| stats.decoder.event.gre.version1_chksum(integer) | about.labels [stats_decoder_event_gre_version1_chksum] | |
| stats.decoder.event.gre.version1_route(integer) | about.labels [stats_decoder_event_gre_version1_route] | |
| stats.decoder.event.gre.version1_ssr(integer) | about.labels [stats_decoder_event_gre_version1_ssr] | |
| stats.decoder.event.gre.version1_recur(integer) | about.labels [stats_decoder_event_gre_version1_recur] | |
| stats.decoder.event.gre.version1_flags(integer) | about.labels [stats_decoder_event_gre_version1_flags] | |
| stats.decoder.event.gre.version1_no_key(integer) | about.labels [stats_decoder_event_gre_version1_no_key] | |
| stats.decoder.event.gre.version1_wrong_protocol(integer) | about.labels [stats_decoder_event_gre_version1_wrong_protocol] | |
| stats.decoder.event.gre.version1_malformed_sre_hdr(integer) | about.labels [stats_decoder_event_gre_version1_malformed_sre_hdr] | |
| stats.decoder.event.gre.version1_hdr_too_big(integer) | about.labels [stats_decoder_event_gre_version1_hdr_too_big] | |
| stats.decoder.event.vlan.header_too_small(integer) | about.labels [stats_decoder_event_vlan_header_too_small] | |
| stats.decoder.event.vlan.unknown_type(integer) | about.labels [stats_decoder_event_vlan_unknown_type] | |
| stats.decoder.event.vlan.too_many_layers(integer) | about.labels [stats_decoder_event_vlan_too_many_layers] | |
| stats.decoder.event.ieee8021ah.header_too_small(integer) | about.labels [stats_decoder_event_ieee8021ah_header_too_small] | |
| stats.decoder.event.vntag.header_too_small(integer) | about.labels [stats_decoder_event_vntag_header_too_small] | |
| stats.decoder.event.vntag.unknown_type(integer) | about.labels [stats_decoder_event_vntag_unknown_type] | |
| stats.decoder.event.ipraw.invalid_ip_version(integer) | about.labels [stats_decoder_event_ipraw_invalid_ip_version] | |
| stats.decoder.event.ltnull.pkt_too_small(integer) | about.labels [stats_decoder_event_ltnull_pkt_too_small] | |
| stats.decoder.event.ltnull.unsupported_type(integer) | about.labels [stats_decoder_event_ltnull_unsupported_type] | |
| stats.decoder.event.sctp.pkt_too_small(integer) | about.labels [stats_decoder_event_sctp_pkt_too_small] | |
| stats.decoder.event.mpls.header_too_small(integer) | about.labels [stats_decoder_event_mpls_header_too_small] | |
| stats.decoder.event.mpls.pkt_too_small(integer) | about.labels [stats_decoder_event_mpls_pkt_too_small] | |
| stats.decoder.event.mpls.bad_label_router_alert(integer) | about.labels [stats_decoder_event_mpls_bad_label_router_alert] | |
| stats.decoder.event.mpls.bad_label_implicit_null(integer) | about.labels [stats_decoder_event_mpls_bad_label_implicit_null] | |
| stats.decoder.event.mpls.bad_label_reserved(integer) | about.labels [stats_decoder_event_mpls_bad_label_reserved] | |
| stats.decoder.event.mpls.unknown_payload_type(integer) | about.labels [stats_decoder_event_mpls_unknown_payload_type] | |
| stats.decoder.event.vxlan.unknown_payload_type(integer) | about.labels [stats_decoder_event_vxlan_unknown_payload_type] | |
| stats.decoder.event.geneve.unknown_payload_type(integer) | about.labels [stats_decoder_event_geneve_unknown_payload_type] | |
| stats.decoder.event.erspan.header_too_small(integer) | about.labels [stats_decoder_event_erspan_header_too_small] | |
| stats.decoder.event.erspan.unsupported_version(integer) | about.labels [stats_decoder_event_erspan_unsupported_version] | |
| stats.decoder.event.erspan.too_many_vlan_layers(integer) | about.labels [stats_decoder_event_erspan_too_many_vlan_layers] | |
| stats.decoder.event.dce.pkt_too_small(integer) | about.labels [stats_decoder_event_dce_pkt_too_small] | |
| stats.decoder.event.chdlc.pkt_too_small(integer) | about.labels [stats_decoder_event_chdlc_pkt_too_small] | |
| stats.decoder.too_many_layers(integer) | about.labels [stats_decoder_too_many_layers] | |
| stats.flow.memcap(integer) | about.labels [stats_flow_memcap] | |
| stats.flow.tcp(integer) | about.labels [stats_flow_tcp] | |
| stats.flow.udp(integer) | about.labels [stats_flow_udp] | |
| stats.flow.icmpv4(integer) | about.labels [stats_flow_icmpv4] | |
| stats.flow.icmpv6(integer) | about.labels [stats_flow_icmpv6] | |
| stats.flow.tcp_reuse(integer) | about.labels [stats_flow_tcp_reuse] | |
| stats.flow.get_used(integer) | about.labels [stats_flow_get_used] | |
| stats.flow.get_used_eval(integer) | about.labels [stats_flow_get_used_eval] | |
| stats.flow.get_used_eval_reject(integer) | about.labels [stats_flow_get_used_eval_reject] | |
| stats.flow.get_used_eval_busy(integer) | about.labels [stats_flow_get_used_eval_busy] | |
| stats.flow.get_used_failed(integer) | about.labels [stats_flow_get_used_failed] | |
| stats.flow.wrk.spare_sync_avg(integer) | about.labels [stats_flow_wrk_spare_sync_avg] | |
| stats.flow.wrk.spare_sync(integer) | about.labels [stats_flow_wrk_spare_sync] | |
| stats.flow.wrk.spare_sync_incomplete(integer) | about.labels [stats_flow_wrk_spare_sync_incomplete] | |
| stats.flow.wrk.spare_sync_empty(integer) | about.labels [stats_flow_wrk_spare_sync_empty] | |
| stats.flow.wrk.flows_evicted_needs_work(integer) | about.labels [stats_flow_wrk_flows_evicted_needs_work] | |
| stats.flow.wrk.flows_evicted_pkt_inject(integer) | about.labels [stats_flow_wrk_flows_evicted_pkt_inject] | |
| stats.flow.wrk.flows_evicted(integer) | about.labels [stats_flow_wrk_flows_evicted] | |
| stats.flow.wrk.flows_injected(integer) | about.labels [stats_flow_wrk_flows_injected] | |
| stats.flow.mgr.full_hash_pass(integer) | about.labels [stats_flow_mgr_full_hash_pass] | |
| stats.flow.mgr.closed_pruned(integer) | about.labels [stats_flow_mgr_closed_pruned] | |
| stats.flow.mgr.new_pruned(integer) | about.labels [stats_flow_mgr_new_pruned] | |
| stats.flow.mgr.est_pruned(integer) | about.labels [stats_flow_mgr_est_pruned] | |
| stats.flow.mgr.bypassed_pruned(integer) | about.labels [stats_flow_mgr_bypassed_pruned] | |
| stats.flow.mgr.rows_maxlen(integer) | about.labels [stats_flow_mgr_rows_maxlen] | |
| stats.flow.mgr.flows_checked(integer) | about.labels [stats_flow_mgr_flows_checked] | |
| stats.flow.mgr.flows_notimeout(integer) | about.labels [stats_flow_mgr_flows_notimeout] | |
| stats.flow.mgr.flows_timeout(integer) | about.labels [stats_flow_mgr_flows_timeout] | |
| stats.flow.mgr.flows_timeout_inuse(integer) | about.labels [stats_flow_mgr_flows_timeout_inuse] | |
| stats.flow.mgr.flows_evicted(integer) | about.labels [stats_flow_mgr_flows_evicted] | |
| stats.flow.mgr.flows_evicted_needs_work(integer) | about.labels [stats_flow_mgr_flows_evicted_needs_work] | |
| stats.flow.spare(integer) | about.labels [stats_flow_spare] | |
| stats.flow.emerg_mode_entered(integer) | about.labels [stats_flow_emerg_mode_entered] | |
| stats.flow.emerg_mode_over(integer) | about.labels [stats_flow_emerg_mode_over] | |
| stats.flow.memuse(integer) | about.labels [stats_flow_memuse] | |
| stats.defrag.ipv4.fragments(integer) | about.labels [stats_defrag_ipv4_fragments] | |
| stats.defrag.ipv4.reassembled(integer) | about.labels [stats_defrag_ipv4_reassembled] | |
| stats.defrag.ipv4.timeouts(integer) | about.labels [stats_defrag_ipv4_timeouts] | |
| stats.defrag.ipv6.fragments(integer) | about.labels [stats_defrag_ipv6_fragments] | |
| stats.defrag.ipv6.reassembled(integer) | about.labels [stats_defrag_ipv6_reassembled] | |
| stats.defrag.ipv6.timeouts(integer) | about.labels [stats_defrag_ipv6_timeouts] | |
| stats.defrag.max_frag_hits(integer) | about.labels [stats_defrag_max_frag_hits] | |
| stats.flow_bypassed.local_pkts(integer) | about.labels [stats_flow_bypassed_local_pkts] | |
| stats.flow_bypassed.local_bytes(integer) | about.labels [stats_flow_bypassed_local_bytes] | |
| stats.flow_bypassed.local_capture_pkts(integer) | about.labels [stats_flow_bypassed_local_capture_pkts] | |
| stats.flow_bypassed.local_capture_bytes(integer) | about.labels [stats_flow_bypassed_local_capture_bytes] | |
| stats.flow_bypassed.closed(integer) | about.labels [stats_flow_bypassed_closed] | |
| stats.flow_bypassed.pkts(integer) | about.labels [stats_flow_bypassed_pkts] | |
| stats.flow_bypassed.bytes(integer) | about.labels [stats_flow_bypassed_bytes] | |
| stats.tcp.sessions(integer) | about.labels [stats_tcp_sessions] | |
| stats.tcp.ssn_memcap_drop(integer) | about.labels [stats_tcp_ssn_memcap_drop] | |
| stats.tcp.pseudo(integer) | about.labels [stats_tcp_pseudo] | |
| stats.tcp.pseudo_failed(integer) | about.labels [stats_tcp_pseudo_failed] | |
| stats.tcp.invalid_checksum(integer) | about.labels [stats_tcp_invalid_checksum] | |
| stats.tcp.no_flow(integer) | about.labels [stats_tcp_no_flow] | |
| stats.tcp.syn(integer) | about.labels [stats_tcp_syn] | |
| stats.tcp.synack(integer) | about.labels [stats_tcp_synack] | |
| stats.tcp.rst(integer) | about.labels [stats_tcp_rst] | |
| stats.tcp.midstream_pickups(integer) | about.labels [stats_tcp_midstream_pickups] | |
| stats.tcp.pkt_on_wrong_thread(integer) | about.labels [stats_tcp_pkt_on_wrong_thread] | |
| stats.tcp.segment_memcap_drop(integer) | about.labels [stats_tcp_segment_memcap_drop] | |
| stats.tcp.stream_depth_reached(integer) | about.labels [stats_tcp_stream_depth_reached] | |
| stats.tcp.reassembly_gap(integer) | about.labels [stats_tcp_reassembly_gap] | |
| stats.tcp.overlap(integer) | about.labels [stats_tcp_overlap] | |
| stats.tcp.overlap_diff_data(integer) | about.labels [stats_tcp_overlap_diff_data] | |
| stats.tcp.insert_data_normal_fail(integer) | about.labels [stats_tcp_insert_data_normal_fail] | |
| stats.tcp.insert_data_overlap_fail(integer) | about.labels [stats_tcp_insert_data_overlap_fail] | |
| stats.tcp.insert_list_fail(integer) | about.labels [stats_tcp_insert_list_fail] | |
| stats.tcp.memuse(integer) | about.labels [stats_tcp_memuse] | |
| stats.tcp.reassembly_memuse(integer) | about.labels [stats_tcp_reassembly_memuse] | |
| stats.detect.engines.id(array) | about.labels [stats_detect_engines_id] | |
| stats.detect.engines.last_reload(array) | about.labels [stats_detect_engines_last_reload] | |
| stats.detect.engines.rules_loaded(array) | about.labels [stats_detect_engines_rules_loaded] | |
| stats.detect.engines.rules_failed(array) | about.labels [stats_detect_engines_rules_failed] | |
| stats.detect.alert(integer) | about.labels [stats_detect_alert] | |
| stats.detect.alert_queue_overflow(integer) | about.labels [stats_detect_alert_queue_overflow] | |
| stats.detect.alerts_suppressed(integer) | about.labels [stats_detect_alerts_suppressed] | |
| stats.app_layer.flow.http(integer) | about.labels [stats_app_layer_flow_http] | |
| stats.app_layer.flow.ftp(integer) | about.labels [stats_app_layer_flow_ftp] | |
| stats.app_layer.flow.smtp(integer) | about.labels [stats_app_layer_flow_smtp] | |
| stats.app_layer.flow.tls(integer) | about.labels [stats_app_layer_flow_tls] | |
| stats.app_layer.flow.ssh(integer) | about.labels [stats_app_layer_flow_ssh] | |
| stats.app_layer.flow.imap(integer) | about.labels [stats_app_layer_flow_imap] | |
| stats.app_layer.flow.smb(integer) | about.labels [stats_app_layer_flow_smb] | |
| stats.app_layer.flow.dcerpc_tcp(integer) | about.labels [stats_app_layer_flow_dcerpc_tcp] | |
| stats.app_layer.flow.dns_tcp(integer) | about.labels [stats_app_layer_flow_dns_tcp] | |
| stats.app_layer.flow.nfs_tcp(integer) | about.labels [stats_app_layer_flow_nfs_tcp] | |
| stats.app_layer.flow.ntp(integer) | about.labels [stats_app_layer_flow_ntp] | |
| stats.app_layer.flow.ftp-data(integer) | about.labels [stats_app_layer_flow_ftp-data] | |
| stats.app_layer.flow.tftp(integer) | about.labels [stats_app_layer_flow_tftp] | |
| stats.app_layer.flow.ikev2(integer) | about.labels [stats_app_layer_flow_ikev2] | |
| stats.app_layer.flow.krb5_tcp(integer) | about.labels [stats_app_layer_flow_krb5_tcp] | |
| stats.app_layer.flow.dhcp(integer) | about.labels [stats_app_layer_flow_dhcp] | |
| stats.app_layer.flow.rfb(integer) | about.labels [stats_app_layer_flow_rfb] | |
| stats.app_layer.flow.rdp(integer) | about.labels [stats_app_layer_flow_rdp] | |
| stats.app_layer.flow.failed_tcp(integer) | about.labels [stats_app_layer_flow_failed_tcp] | |
| stats.app_layer.flow.dcerpc_udp(integer) | about.labels [stats_app_layer_flow_dcerpc_udp] | |
| stats.app_layer.flow.dns_udp(integer) | about.labels [stats_app_layer_flow_dns_udp] | |
| stats.app_layer.flow.nfs_udp(integer) | about.labels [stats_app_layer_flow_nfs_udp] | |
| stats.app_layer.flow.krb5_udp(integer) | about.labels [stats_app_layer_flow_krb5_udp] | |
| stats.app_layer.flow.failed_udp(integer) | about.labels [stats_app_layer_flow_failed_udp] | |
| stats.app_layer.tx.http(integer) | about.labels [stats_app_layer_tx_http] | |
| stats.app_layer.tx.ftp(integer) | about.labels [stats_app_layer_tx_ftp] | |
| stats.app_layer.tx.smtp(integer) | about.labels [stats_app_layer_tx_smtp] | |
| stats.app_layer.tx.tls(integer) | about.labels [stats_app_layer_tx_tls] | |
| stats.app_layer.tx.ssh(integer) | about.labels [stats_app_layer_tx_ssh] | |
| stats.app_layer.tx.imap(integer) | about.labels [stats_app_layer_tx_imap] | |
| stats.app_layer.tx.smb(integer) | about.labels [stats_app_layer_tx_smb] | |
| stats.app_layer.tx.dcerpc_tcp(integer) | about.labels [stats_app_layer_tx_dcerpc_tcp] | |
| stats.app_layer.tx.dns_tcp(integer) | about.labels [stats_app_layer_tx_dns_tcp] | |
| stats.app_layer.tx.nfs_tcp(integer) | about.labels [stats_app_layer_tx_nfs_tcp] | |
| stats.app_layer.tx.ntp(integer) | about.labels [stats_app_layer_tx_ntp] | |
| stats.app_layer.tx.ftp-data(integer) | about.labels [stats_app_layer_tx_ftp-data] | |
| stats.app_layer.tx.tftp(integer) | about.labels [stats_app_layer_tx_tftp] | |
| stats.app_layer.tx.ikev2(integer) | about.labels [stats_app_layer_tx_ikev2] | |
| stats.app_layer.tx.krb5_tcp(integer) | about.labels [stats_app_layer_tx_krb5_tcp] | |
| stats.app_layer.tx.dhcp(integer) | about.labels [stats_app_layer_tx_dhcp] | |
| stats.app_layer.tx.rfb(integer) | about.labels [stats_app_layer_tx_rfb] | |
| stats.app_layer.tx.rdp(integer) | about.labels [stats_app_layer_tx_rdp] | |
| stats.app_layer.tx.dcerpc_udp(integer) | about.labels [stats_app_layer_tx_dcerpc_udp] | |
| stats.app_layer.tx.dns_udp(integer) | about.labels [stats_app_layer_tx_dns_udp] | |
| stats.app_layer.tx.nfs_udp(integer) | about.labels [stats_app_layer_tx_nfs_udp] | |
| stats.app_layer.tx.krb5_udp(integer) | about.labels [stats_app_layer_tx_krb5_udp] | |
| stats.app_layer.expectations(integer) | about.labels [stats_app_layer_expectations] | |
| stats.http.memuse(integer) | about.labels [stats_http_memuse] | |
| stats.http.memcap(integer) | about.labels [stats_http_memcap] | |
| stats.ftp.memuse(integer) | about.labels [stats_ftp_memuse] | |
| stats.ftp.memcap(integer) | about.labels [stats_ftp_memcap] | 
Referencia de asignación de campos: CORELIGHT - logschema
En la siguiente tabla se enumeran los campos de registro del tipo de registro logschema y sus campos de UDM correspondientes.
| Log field | UDM mapping | Logic | 
|---|---|---|
| metadata.event_type | The metadata.event_typeUDM field is set toGENERIC_EVENT. | |
| name(string) | about.labels [name] | |
| text(string) | about.labels [text] | |
| schema(string) | about.labels [schema] | |
| avro(string) | about.labels [avro] | 
Siguientes pasos
¿Necesitas más ayuda? Recibe respuestas de los miembros de la comunidad y de los profesionales de Google SecOps.