mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-01-01 22:03:37 +01:00
354 lines
12 KiB
JSON
354 lines
12 KiB
JSON
{
|
|
"_meta": {
|
|
"documentation": "https://www.elastic.co/guide/en/ecs/current/ecs-tls.html",
|
|
"ecs_version": "1.12.2"
|
|
},
|
|
"template": {
|
|
"mappings": {
|
|
"properties": {
|
|
"tls": {
|
|
"properties": {
|
|
"cipher": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"client": {
|
|
"properties": {
|
|
"certificate": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"certificate_chain": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"hash": {
|
|
"properties": {
|
|
"md5": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"sha1": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"sha256": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"issuer": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"ja3": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"not_after": {
|
|
"type": "date"
|
|
},
|
|
"not_before": {
|
|
"type": "date"
|
|
},
|
|
"server_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"subject": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"supported_ciphers": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"x509": {
|
|
"properties": {
|
|
"alternative_names": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"issuer": {
|
|
"properties": {
|
|
"common_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"distinguished_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"locality": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organization": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organizational_unit": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"state_or_province": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"not_after": {
|
|
"type": "date"
|
|
},
|
|
"not_before": {
|
|
"type": "date"
|
|
},
|
|
"public_key_algorithm": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"public_key_curve": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"public_key_exponent": {
|
|
"doc_values": false,
|
|
"index": false,
|
|
"type": "long"
|
|
},
|
|
"public_key_size": {
|
|
"type": "long"
|
|
},
|
|
"serial_number": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"signature_algorithm": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"subject": {
|
|
"properties": {
|
|
"common_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"distinguished_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"locality": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organization": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organizational_unit": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"state_or_province": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"version_number": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"curve": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"established": {
|
|
"type": "boolean"
|
|
},
|
|
"next_protocol": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"resumed": {
|
|
"type": "boolean"
|
|
},
|
|
"server": {
|
|
"properties": {
|
|
"certificate": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"certificate_chain": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"hash": {
|
|
"properties": {
|
|
"md5": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"sha1": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"sha256": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"issuer": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"ja3s": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"not_after": {
|
|
"type": "date"
|
|
},
|
|
"not_before": {
|
|
"type": "date"
|
|
},
|
|
"subject": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"x509": {
|
|
"properties": {
|
|
"alternative_names": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"issuer": {
|
|
"properties": {
|
|
"common_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"distinguished_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"locality": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organization": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organizational_unit": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"state_or_province": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"not_after": {
|
|
"type": "date"
|
|
},
|
|
"not_before": {
|
|
"type": "date"
|
|
},
|
|
"public_key_algorithm": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"public_key_curve": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"public_key_exponent": {
|
|
"doc_values": false,
|
|
"index": false,
|
|
"type": "long"
|
|
},
|
|
"public_key_size": {
|
|
"type": "long"
|
|
},
|
|
"serial_number": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"signature_algorithm": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"subject": {
|
|
"properties": {
|
|
"common_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"distinguished_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"locality": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organization": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"organizational_unit": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"state_or_province": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"version_number": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"version": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"version_protocol": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
} |