mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-18 23:13:20 +01:00
220 lines
6.1 KiB
Plaintext
220 lines
6.1 KiB
Plaintext
{
|
|
"_meta": {
|
|
"documentation": "https://www.elastic.co/guide/en/ecs/current/ecs-observer.html",
|
|
"ecs_version": "1.12.2"
|
|
},
|
|
"template": {
|
|
"mappings": {
|
|
"properties": {
|
|
"observer": {
|
|
"properties": {
|
|
"egress": {
|
|
"properties": {
|
|
"interface": {
|
|
"properties": {
|
|
"alias": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"vlan": {
|
|
"properties": {
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"zone": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
},
|
|
"type": "object"
|
|
},
|
|
"geo": {
|
|
"properties": {
|
|
"city_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"continent_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"continent_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country_iso_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"location": {
|
|
"type": "geo_point"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"postal_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"region_iso_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"region_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"timezone": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"hostname": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"ingress": {
|
|
"properties": {
|
|
"interface": {
|
|
"properties": {
|
|
"alias": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"vlan": {
|
|
"properties": {
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"zone": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
},
|
|
"type": "object"
|
|
},
|
|
"ip": {
|
|
"type": "ip"
|
|
},
|
|
"mac": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword",
|
|
"fields": {
|
|
"keyword": {
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"os": {
|
|
"properties": {
|
|
"family": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"full": {
|
|
"fields": {
|
|
"text": {
|
|
"type": "match_only_text"
|
|
}
|
|
},
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"kernel": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"fields": {
|
|
"text": {
|
|
"type": "match_only_text"
|
|
}
|
|
},
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"platform": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"type": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"version": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"product": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"serial_number": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"type": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"vendor": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"version": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|