mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Merge pull request #9240 from Security-Onion-Solutions/fix/add_s7comm_upload_download_ingest_pipeline
Add Zeek s7comm upload download ingest pipeline
This commit is contained in:
18
salt/elasticsearch/files/ingest/zeek.s7comm_upload_download
Normal file
18
salt/elasticsearch/files/ingest/zeek.s7comm_upload_download
Normal file
@@ -0,0 +1,18 @@
|
||||
{
|
||||
"description" : "zeek.s7comm_upload_download",
|
||||
"processors" : [
|
||||
{ "remove": { "field": ["host"], "ignore_failure": true } },
|
||||
{ "json": { "field": "message", "target_field": "message2", "ignore_failure": true } },
|
||||
{ "rename": { "field": "message2.rosctr", "target_field": "s7.ros.control.name", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.pdu_reference", "target_field": "s7.pdu_reference", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.function_code", "target_field": "s7.function_code", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.function_status", "target_field": "s7.function_status", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.session_id", "target_field": "s7.session_id", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.blocklength", "target_field": "s7.block.length", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.filename", "target_field": "s7.file.name", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.block_type", "target_field": "s7.block.type", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.block_number", "target_field": "s7.block.number", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.destination_filesystem", "target_field": "s7.destination.filesystem", "ignore_missing": true } },
|
||||
{ "pipeline": { "name": "zeek.common" } }
|
||||
]
|
||||
}
|
||||
@@ -99,6 +99,8 @@
|
||||
"::profinet_dce_rpc": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "profinet.operation", "log.id.uid" ],
|
||||
"::s7comm": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.ros.control.name", "s7.function.name", "log.id.uid" ],
|
||||
"::s7comm_plus": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.opcode.name", "s7.version", "log.id.uid" ],
|
||||
"::s7comm_read_szl": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.szl_id_name", "s7.return_code_name", "log.id.uid" ],
|
||||
"::s7comm_upload_download": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "s7.ros.control.name", "s7.function_code", "log.id.uid" ],
|
||||
"::tds": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "tds.command", "log.id.uid", "event.dataset" ],
|
||||
"::tds_rpc": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "tds.procedure_name", "log.id.uid", "event.dataset" ],
|
||||
"::tds_sql_batch": ["soc_timestamp", "source.ip", "source.port", "destination.ip", "destination.port", "tds.header_type", "log.id.uid", "event.dataset" ]
|
||||
|
||||
Reference in New Issue
Block a user