mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-28 20:03:44 +01:00
227 lines
6.2 KiB
JSON
227 lines
6.2 KiB
JSON
{
|
|
"_meta": {
|
|
"documentation": "https://www.elastic.co/guide/en/ecs/current/ecs-host.html",
|
|
"ecs_version": "1.12.2"
|
|
},
|
|
"template": {
|
|
"mappings": {
|
|
"properties": {
|
|
"host": {
|
|
"properties": {
|
|
"architecture": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"cpu": {
|
|
"properties": {
|
|
"usage": {
|
|
"scaling_factor": 1000,
|
|
"type": "scaled_float"
|
|
}
|
|
}
|
|
},
|
|
"disk": {
|
|
"properties": {
|
|
"read": {
|
|
"properties": {
|
|
"bytes": {
|
|
"type": "long"
|
|
}
|
|
}
|
|
},
|
|
"write": {
|
|
"properties": {
|
|
"bytes": {
|
|
"type": "long"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"domain": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"geo": {
|
|
"properties": {
|
|
"city_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"continent_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"continent_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country_iso_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"country_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"location": {
|
|
"type": "geo_point"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"postal_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"region_iso_code": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"region_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"timezone": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"hostname": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"ip": {
|
|
"type": "ip"
|
|
},
|
|
"mac": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"network": {
|
|
"properties": {
|
|
"egress": {
|
|
"properties": {
|
|
"bytes": {
|
|
"type": "long"
|
|
},
|
|
"packets": {
|
|
"type": "long"
|
|
}
|
|
}
|
|
},
|
|
"ingress": {
|
|
"properties": {
|
|
"bytes": {
|
|
"type": "long"
|
|
},
|
|
"packets": {
|
|
"type": "long"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"os": {
|
|
"properties": {
|
|
"family": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"full": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"kernel": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"platform": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"type": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"version": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"type": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"uptime": {
|
|
"type": "long"
|
|
},
|
|
"user": {
|
|
"properties": {
|
|
"domain": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"email": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"full_name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"group": {
|
|
"properties": {
|
|
"domain": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
},
|
|
"hash": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"id": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"name": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
},
|
|
"roles": {
|
|
"ignore_above": 1024,
|
|
"type": "keyword"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
} |