איסוף יומנים של Fluentd

גרסת מנתח הנתונים: 16.0

נתמך ב:

במאמר הזה מוסבר איך לאסוף יומנים של Fluentd באמצעות הגדרה של Fluentd ושל מעביר נתונים של Google Security Operations. במסמך הזה מפורטים גם סוגי היומנים הנתמכים וגרסת Fluentd הנתמכת.

מידע נוסף זמין במאמר בנושא העברת נתונים אל Google Security Operations.

סקירה כללית

בתרשים דיאגרמת ארכיטקטורת הפריסה הבא מוצג אופן ההתקנה של Fluentd בשרת ה-Forwarder ובשרת ה-Aggregator כדי לשלוח יומנים אל Google Security Operations. הפריסה של כל לקוח עשויה להיות שונה מהייצוג הזה, ואולי מורכבת יותר.

ארכיטקטורת פריסה

דיאגרמת הארכיטקטורה מציגה את הרכיבים הבאים:

  • מערכת Linux. מערכת Linux שרוצים לנטר. מערכת Linux מורכבת מהקבצים למעקב ומשרת Fluentd forwarder.

  • מערכת Microsoft Windows. מערכת Microsoft Windows שרוצים לעקוב אחריה, שבה מותקן שרת Fluentd forwarder.

  • Fluentd forwarder. הכלי להעברת נתונים Fluentd אוסף מידע ממערכת Microsoft Windows או Linux ומעביר את המידע לאגרגטור Fluentd.

  • אגרגטור Fluentd. האגרגטור Fluentd מקבל יומנים מה-forwarder של Fluentd ומעביר אותם ל-forwarder של Google Security Operations.

  • Bindplane agent. הסוכן של Bindplane מאחזר יומנים מ-Zscaler ZPA ושולח אותם ל-Google SecOps.

  • Google Security Operations forwarder. הכלי להעברת נתונים של Google Security Operations הוא רכיב תוכנה קל משקל שמוטמע ברשת של הלקוח ותומך ב-syslog. הכלי להעברת נתונים של Google Security Operations מעביר את היומנים אל Google Security Operations.

  • Google Security Operations. ‫Google Security Operations שומרת את היומנים מהאגרגטור Fluentd ומנתחת אותם.

תווית הטמעה מזהה את מנתח הנתונים שמנרמל נתוני יומן גולמיים לפורמט UDM מובנה. המידע במסמך הזה רלוונטי למנתח התוכן עם תווית ההטמעה FLUENTD.

לפני שמתחילים

  • מוודאים ש-Fluentd forwarder מותקן במערכות Microsoft Windows או Linux שאתם מתכננים לעקוב אחריהן. מידע נוסף על התקנת Fluentd forwarder

  • משתמשים בגרסת Fluentd שהכלי לניתוח של Google Security Operations תומך בה. הכלי לניתוח נתונים של Google Security Operations תומך בגרסה 1.0 של Fluentd.

  • מוודאים שהצבירה של Fluentd מותקנת ומוגדרת בשרת Linux המרכזי.

  • מוודאים שכל המערכות בארכיטקטורת הפריסה מוגדרות לאזור הזמן UTC.

  • בודקים את סוגי היומנים שכלי הניתוח של Google Security Operations תומך בהם. בטבלה הבאה מפורטים המוצרים ונתיבי קובצי היומן שהכלי לניתוח של Google Security Operations תומך בהם:

    מערכת ההפעלה מוצר נתיב קובץ היומן
    Microsoft Windows Microsoft Windows יומני אירועים
    Linux Linux /var/log/audit/audit.log
    Linux Linux /var/log/syslog
    Linux apache2 /var/log/apache2/access.log
    Linux apache2 /var/log/apache2/error.log
    Linux apache2 /var/log/apache2/other_vhosts_access.log
    Linux apache2 /var/log/apache2/novnc-server-access.log
    Linux OpenVpn /var/log/openvpnas.log
    Linux Nginx /var/log/nginx/access.log
    Linux Nginx /var/log/nginx/error.log
    Linux rkhunter /var/log/rkhunter.log
    Linux Linux /var/log/auth.log
    Linux Linux /var/log/kern.log
    Linux rundeck /var/log/rundeck/service.log
    Linux Samba /var/log/samba/log.winbindd
    Linux Linux /var/log/mail.log

הגדרת המעביר והמצבר של Fluentd, והמעביר של Google Security Operations

  1. כדי לעקוב אחרי היומנים שמערכות Linux יוצרות, יוצרים קובץ td-agent.conf כדי לציין את הגדרות המעקב אחרי היומנים עבור Fluentd forwarder. זוהי דוגמה לקובץ הגדרה של Fluentd forwarder במערכת Linux:

    <source>
    @type tail
    path /var/log/nginx/access.log
    pos_file /var/log/td-agent/nginx-access.log.pos
    tag mytag.nginx.access
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/nginx/error.log
    pos_file /var/log/td-agent/nginx-error.log.pos
    tag mytag.nginx.error
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/apache2/access.log
    pos_file /var/log/td-agent/apache-access.log.pos
    tag mytag.apache.access
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/apache2/error.log
    pos_file /var/log/td-agent/apache-error.log.pos
    tag mytag.apache.error
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/audit/audit.log
    pos_file /var/log/td-agent/audit.log.pos
    tag mytag.audit
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/syslog/syslog.log
    pos_file /var/log/td-agent/syslog.log.pos
    tag mytag.syslog
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path  /var/log/apache2/other_vhosts_access.log
    pos_file /var/log/td-agent/vhost.log.pos
    tag mytag.apache.other_vhosts_access
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path  /var/log/apache2/novnc-server-access.log
    pos_file /var/log/td-agent/novnc.log.pos
    tag mytag.apache.novnc-server-access
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/openvpnas.log
    pos_file /var/log/td-agent/openvpnas.log.pos
    tag mytag.openvpnas
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/auth.log
    pos_file /var/log/td-agent/auth.log.pos
    tag mytag.auth
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/kern.log
    pos_file /var/log/td-agent/kern.log.pos
    tag mytag.kern
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/rundeck/service.log
    pos_file /var/log/td-agent/rundeck.log.pos
    tag mytag.rundeck
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/mail.log
    pos_file /var/log/td-agent/mail.log.pos
    tag mytag.mail
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    path /var/log/rkhunter.log
    pos_file /var/log/td-agent/rkhunter.log.pos
    tag mytag.rkhunter
    <parse>
    @type none
    </parse>
    </source>
    
    <source>
    @type tail
    Path /var/log/samba/log.winbindd
    pos_file /var/log/td-agent/winbindd.log.pos
    tag mytag.winbindd
    <parse>
    @type none
    </parse>
    </source>
    
    <filter  mytag.**>
    @type record_transformer
    <record>
    forwarder_hostname "#{Socket.gethostname}"
    </record>
    </filter>
    
    <filter  mytag.nginx.access.**>
    @type record_transformer
    <record>
    path "/var/log/nginx/access.log"
    </record>
    </filter>
    
    <filter  mytag.nginx.error.**>
    @type record_transformer
    <record>
    path "/var/log/nginx/error.log"
    </record>
    </filter>
    
    <filter  mytag.apache.access.**>
    @type record_transformer
    <record>
    path "/var/log/apache2/access.log"
    </record>
    </filter>
    
    <filter  mytag.apache.error.**>
    @type record_transformer
    <record>
    path "/var/log/apache2/error.log"
    </record>
    </filter>
    
    <filter  mytag.audit.**>
    @type record_transformer
    <record>
    path "/var/log/audit/audit.log"
    </record>
    </filter>
    
    <filter  mytag.syslog.**>
    @type record_transformer
    <record>
    path "/var/log/syslog/syslog.log"
    </record>
    </filter>
    
    <filter  mytag.apache.other_vhosts_access.**>
    @type record_transformer
    <record>
    path "/var/log/apache2/other_vhosts_access.log"
    </record>
    </filter>
    
    <filter  mytag.apache.novnc-server-access.**>
    @type record_transformer
    <record>
    path "/var/log/apache2/novnc-server-access.log"
    </record>
    </filter>
    
    <filter mytag.openvpnas.**>
    @type record_transformer
    <record>
    path "/var/log/openvpnas.log"
    </record>
    </filter>
    
    <filter mytag.auth.**>
    @type record_transformer
    <record>
    path "/var/log/auth.log"
    </record>
    </filter>
    
    <filter mytag.kern.**>
    @type record_transformer
    <record>
    path "/var/log/kern.log"
    </record>
    </filter>
    
    <filter mytag.rundeck.**>
    @type record_transformer
    <record>
    path "/var/log/rundeck/service.log"
    </record>
    </filter>
    
    <filter mytag.mail.**>
    @type record_transformer
    <record>
    path "/var/log/mail.log"
    </record>
    </filter>
    
    <filter mytag.rkhunter.**>
    @type record_transformer
    <record>
    path "/var/log/rkhunter.log"
    </record>
    </filter>
    
    <filter mytag.winbindd.**>
    @type record_transformer
    <record>
    path "/var/log/samba/log.winbindd"
    </record>
    </filter>
    
    <match mytag.**>
    @type forward
    # primary host
    <server>
    host <AGGREGATOR_HOSTNAME>
    port <AGGREGATOR_PORT>
    </server>
    </match>
    
  2. כדי לעקוב אחרי היומנים שמערכות Microsoft Windows יוצרות, צריך ליצור קובץ td-agent.conf כדי לציין את הגדרות המעקב אחרי היומנים עבור Fluentd forwarder. דוגמה לקובץ תצורה של Fluentd forwarder במערכת Microsoft Windows:

    <source>
    @type windows_eventlog
    @id windows_eventlog
    channels application,security,system
    read_existing_events true
    read_interval 2
    tag windows.raw
    render_as_xml true
    <storage>
    @type local
    persistent true
    path E:\windows.pos
    </storage>
    </source>
    <match windowslog>
    @type forward
    <server>
    host <AGGREGATOR_HOSTNAME>
    port <AGGREGATOR_PORT>
    username <AGGREGATOR_USERNAME>
    password <AGGREGATOR_PASSWORD>
    </server>
    </match>
    
    
  3. כדי להעביר את היומנים מהצובר Fluentd למעביר של Google Security Operations, צריך ליצור קובץ תצורה בפורמט הבא:

    <source>
    @type forward
    port <AGGREGATOR_PORT>
    </source>
    
    ## Forwarding
    <match mytag.**>
    @id output_system_forward
    @type forward
    # IP and port of the forwarder
    <server>
     host <CHRONICLE_FORWARDER_HOSTNAME>
     port <CHRONICLE_FORWARDER_PORT>
    </server>
    </match>
    
  4. מגדירים את מעביר היומנים של Google Security Operations לשליחת יומנים אל Google Security Operations. מידע נוסף זמין במאמר התקנה והגדרה של המעביר ב-Linux. הנה דוגמה להגדרת מעביר ב-Google Security Operations:

    common:
      enabled: true
      data_type: FLUENTD
      batch_n_seconds: 10
      batch_n_bytes: 1048576
    tcp_address: 0.0.0.0:10514
    connection_timeout_sec: 60
    

העברת יומנים ל-Google SecOps באמצעות סוכן Bindplane

  1. מתקינים ומגדירים מכונה וירטואלית של Linux.
  2. איך מתקינים ומגדירים את סוכן Bindplane ב-Linux כדי להעביר יומנים ל-Google SecOps. מידע נוסף על התקנה והגדרה של סוכן Bindplane זמין בהוראות להתקנה ולהגדרה של סוכן Bindplane.

אם נתקלתם בבעיות ביצירת פידים, פנו לתמיכה של Google SecOps.

פורמטים נתמכים של יומנים ב-Fluentd

מנתח הנתונים של Fluentd תומך ביומנים בפורמט SYSLOG+JSON.

יומנים לדוגמה של Fluentd שנתמכים

  • ‫SYSLOG + JSON

    "2022-06-30T17:10:10+05:30 mytag.apache.error {\"message\":\"[Sat Jun 02 00:30:55 2022] New connection: [connection: gTxkX8Z6tjk] [client 172.17.0.1:50786]\",\"forwarder_hostname\":\"Ubuntu18\",\"path\":\"/var/log/apache2/error.log\"}"
    

הפניה למיפוי שדות

בקטע הזה מוסבר איך מנתח התוכן משתמש בתבניות grok במערכות Linux ו-Microsoft Windows, ואיך הוא ממפה שדות של יומן Fluentd לשדות של מודל הנתונים המאוחד (UDM) של Google Security Operations לכל סוג יומן.

מידע על מיפוי הפניה של שדות נפוצים זמין במאמר שדות נפוצים

למידע על נתיבי יומנים, דפוסי grok ליומנים לדוגמה, סוגי אירועים ושדות UDM במערכות Linux, אפשר לעיין בקטעים הבאים:

מידע על אירועים נתמכים ב-Microsoft Windows ושדות UDM תואמים זמין במאמר נתונים של אירועים ב-Microsoft Windows

שדות נפוצים

בטבלה הבאה מפורטים שדות נפוצים ביומן והשדות התואמים להם ב-UDM.

שדה יומן נפוץ שדה UDM
collected_time metadata.collected_timestamp
inner_message.message inner_message
inner_message.forwarder_hostname target.hostname או principal.hostname
inner_message.path event_source

מערכת Linux

בטבלה הבאה מפורטים נתיבי היומן של מערכת Linux, דפוס grok לדוגמאות של יומנים, סוג האירוע ומיפויים של UDM:

נתיב היומן יומן לדוגמה תבנית Grok סוג אירוע מיפוי UDM
/var/log/apache2/error.log [Thu Apr 28 16:13:01.283342 2022] [core:notice] [pid 18394:tid 140188660751296] [client 1.200.32.47:59840] failed to make connection [{timestamp}][{log_module}:{log_level}][pid{pid}(<optional_field>:tid{tid}|)](<optional_field> [client {client_ip}:{client_port}]|) (?<error_message>.*) NETWORK_UNCATEGORIZED

חותמת הזמן ממופה אל metadata.event_timestamp

log_module ממופה ל-target.resource.name

‫log_level ממופה ל-security_result.severity

‫pid ממופה אל target.process.parent_process.pid

‫tid ממופה ל-target.process.pid

‫client_ip ממופה אל principal.ip

‫client_port ממופה ל-principal.port

error_message ממופה ל-security_result.description

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/error.log [Thu Apr 28 16:13:01.283342 2022] [core:notice] [pid 18394:tid 140188660751296] failed to make connection [{timestamp}][{log_module}:{severity}][pid{pid}(<optional_field>:tid{tid}|)]{error_message} NETWORK_UNCATEGORIZED

חותמת הזמן ממופה אל metadata.event_timestamp

log_module ממופה ל-target.resource.name

‫log_level ממופה ל-security_result.severity

‫pid ממופה אל target.process.parent_process.pid

‫tid ממופה ל-target.process.pid

error_message ממופה ל-security_result.description

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/error.log [Thu Apr 28 16:13:01.283342 2022] [core:notice] [pid 18394:tid 140188660751296] AH00094: שורת פקודה: '/usr/sbin/apache2' [{timestamp}][{log_module}:{log_level}][pid{pid}(<optional_field>:tid{tid}|)](<optional_field> [client {client_ip}:{client_port}]|) (?<error_message>.*),referer{referer_url} NETWORK_UNCATEGORIZED

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

חותמת הזמן ממופה אל metadata.event_timestamp

log_module ממופה ל-target.resource.name

‫log_level ממופה ל-security_result.severity

‫pid ממופה אל target.process.parent_process.pid

‫tid ממופה ל-target.process.pid

‫client_ip ממופה אל principal.ip

‫client_port ממופה ל-principal.port

error_message ממופה ל-security_result.description

הערך של target.platform מוגדר כ-'LINUX'

המאפיין referer_url ממופה אל network.http.referral_url

/var/log/apache2/error.log ‪[Sun Jan 30 15:14:47.260309 2022] [proxy_http:error] [pid 12515:tid 140035781285632] [client 1.200.32.47:59840] AH01114: HTTP: failed to make connection to backend: 192.0.2.1 , referer http:// ‫[{timestamp}] [{log_module}:{log_level}] [pid {pid}(<optional_field>:tid{tid}|)] [client {client_ip}:{client_port}]( <message_text>HTTP: )?{error_message}:( {target_ip})(<optional_field>,referer{referer_url})?" NETWORK_HTTP

חותמת הזמן ממופה אל metadata.event_timestamp

log_module ממופה ל-target.resource.name

‫log_level ממופה ל-security_result.severity

‫pid ממופה אל target.process.parent_process.pid

‫tid ממופה ל-target.process.pid

‫client_ip ממופה אל principal.ip

‫client_port ממופה ל-principal.port

error_message ממופה ל-security_result.description

‫target_ip ממופה אל target.ip

המאפיין referer_url ממופה למאפיין network.http.referral_url

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/error.log ‫[Sat Feb 02 00:30:55 2019] New connection: [connection: gTxkX8Z6tjk] [client 192.0.2.1:50786] [{timestamp}]<message_text>connection:[connection:{connection_id}][client{client_ip}:{client_port}] NETWORK_UNCATEGORIZED

חותמת הזמן ממופה אל metadata.event_timestamp

‫client_ip ממופה אל principal.ip

‫client_port ממופה ל-principal.port

‫connection_id ממופה אל network.session_id

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/error.log [Sat Feb 02 00:30:55 2019] New request: [connection: j8BjX4Z5tjk] [request: ACtkX1Z5tjk] [pid 8] [client 192.0.2.1:50784] [{timestamp}]<message_text>request:[connection:{connection_id}][request:{request_id}][pid{pid}][client{client_ip}:{client_port}] NETWORK_UNCATEGORIZED

חותמת הזמן ממופה אל metadata.event_timestamp

‫request_id ממופה ל-security_result.detection_fields.(key/value)

‫client_ip ממופה אל principal.ip

‫client_port ממופה ל-principal.port

‫pid ממופה אל target.process.parent_process.pid

‫connection_id ממופה אל network.session_id

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/error.log [Sat Feb 02 00:30:55 2019] [info] [C: j8BjX4Z5tjk] [R: p7pjX4Z5tjk] [pid 8] core.c(4739): [client 192.0.2.1:50784] AH00128: File does not exist: /usr/local/apache2/htdocs/favicon.ico ‫[{timestamp}] [{log_level}][C:{connection_id}][R:{request_id}][pid {pid}(<optional_field>:tid{tid}|)]<message_text>[client {client_ip}:{client_port}]{error_message}:{file_path} NETWORK_UNCATEGORIZED

חותמת הזמן ממופה אל metadata.event_timestamp

‫log_level ממופה ל-security_result.severity

‫request_id ממופה ל-security_result.detection_fields.(key/value)

‫client_ip ממופה אל principal.ip

‫client_port ממופה ל-principal.port

‫pid ממופה אל target.process.parent_process.pid

‫connection_id ממופה אל network.session_id

error_message ממופה ל-security_result.description

‫file_path ממופה אל target.file.full_path

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/access.log ‪192.0.2.1 - - [28/Apr/2022:17:35:52 +0530] "GET / HTTP/1.1" 200 3476 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/192.0.2.1 Safari/537.36" ({client_ip})?<message_text>{userid}[{timestamp}](<optional_field>{method}/(<optional_field>{resource}?) {client_protocol}?){result_status}{object_size}(<optional_field>(<optional_field>{referer_url}?)(<optional_field>{user_agent}?)? NETWORK_HTTP

‫client_ip ממופה אל principal.ip

‫userid ממופה אל principal.user.userid

המארח ממופה אל principal.hostname

חותמת הזמן ממופה אל metadata.event_timestamp

השיטה ממופה ל-network.http.method

המשאב ממופה אל principal.resource.name

client_protocol ממופה ל-network.application_protocol

result_status ממופה ל-network.http.response_code

‫object_size ממופה ל-network.sent_bytes

המאפיין referer_url ממופה אל network.http.referral_url

‫user_agent ממופה ל-network.http.user_agent

הערך של network.ip_protocol הוא TCP

הערך של network.direction הוא OUTBOUND

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

var/log/apache2/other_vhosts_access.log wintest.example.com:80 ::1 - - [14/Jan/2022:14:08:16 -0700] \"GET /server-status?auto HTTP/1.1\" 200 1415 \"-\" \"Python-urllib/2.7\" {target_host}:{NUMBER:target_port} {client_ip} - (<optional_field>{host}?) [{timestamp}](<optional_field>{method}/(<optional_field>{resource}?){client_protocol}?){result_status}{object_size}(<optional_field>{referer_url}?)(<optional_field>{user_agent}?) NETWORK_HTTP ‫target_host ממופה אל target.hostname

‫target_port ממופה אל target.port

‫client_ip ממופה אל principal.ip

‫userid ממופה אל principal.user.userid

המארח ממופה אל principal.hostname

חותמת הזמן ממופה אל metadata.event_timestamp

השיטה ממופה ל-network.http.method

המשאב ממופה אל principal.resource.name

result_status ממופה ל-network.http.response_code

‫object_size ממופה ל-network.sent_bytes

המאפיין referer_url ממופה אל network.http.referral_url

‫user_agent ממופה ל-network.http.user_agent

הערך של network.ip_protocol הוא TCP

הערך של network.direction הוא OUTBOUND

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

ההגדרה של network.application_protocol היא HTTP

var/log/apache2/novnc-server-access.log wintest.example.com:80 ::1 - - [14/Jan/2022:14:08:16 -0700] \"GET /server-status?auto HTTP/1.1\" 200 1415 \"-\" \"http://\" {target_host}:{NUMBER:target_port} {client_ip} - (<optional_field>{host}?) [{timestamp}](<optional_field>{method}/(<optional_field>{resource}?){client_protocol}?){result_status}{object_size}(<optional_field>{referer_url}?)(<optional_field>{user_agent}?) NETWORK_HTTP

‫client_ip ממופה אל principal.ip

‫userid ממופה אל principal.user.userid

השיטה ממופה ל-network.http.method

הנתיב ממופה אל target.url

result_status ממופה ל-network.http.response_code

‫object_size ממופה ל-network.sent_bytes

המאפיין referer_url ממופה אל network.http.referral_url

‫user_agent ממופה ל-network.http.user_agent

הערך של network.ip_protocol הוא TCP

הערך של network.direction הוא OUTBOUND

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

ההגדרה של network.application_protocol היא HTTP

/var/log/apache2/access.log ‪"http://192.0.2.1/test/first.html" -> /google.com (<optional_field>{referer_url}?)->(<optional_field>{path}?) GENERIC_EVENT

הנתיב ממופה אל target.url

המאפיין referer_url ממופה למאפיין network.http.referral_url

הערך של network.direction הוא OUTBOUND

הערך של target.platform מוגדר כ-'LINUX'

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

/var/log/apache2/access.log Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Code/1.67.0 Chrome/98.0.4758.141 Electron/17.4.1 Safari/537.36 (<optional_field>{user_agent}) GENERIC_EVENT

‫user_agent ממופה ל-network.http.user_agent

הערך של network.direction הוא OUTBOUND

הערך של target.platform מוגדר כ-'LINUX'

ההגדרה של network.application_protocol היא HTTP

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא Apache

הערך של metadata.product_name הוא Apache HTTP Server

var/log/nginx/access.log ‪192.0.2.1 - admin [05/May/2022:11:53:27 +0530] "GET /icons/ubuntu-logo.png HTTP/1.1" 404 209 "http://198.51.100.1/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/192.0.2.1 Safari/537.36" ‫{principal_ip} - (<optional_field>{principal_user_userid}?) [{timestamp}] {http_method} /(<optional_field>{resource_name}?|) {protocol}(<message_text>){response_code} {received_bytes}(<optional_field>{referer_url}) ({user_agent}|{user_agent})? NETWORK_HTTP

הזמן ממופה ל-metadata.timestamp

ה-IP ממופה ל-target.ip

‫principal_ip ממופה ל-principal.ip

‫principal_user_userid ממופה אל principal.user.userid

‫metadata_timestamp ממופה אל timestamp

‫http_method ממופה ל-network.http.method

‫resource_name ממופה אל principal.resource.name

הפרוטוקול ממופה ל-network.application_protocol = (HTTP)

המאפיין response_code ממופה למאפיין network.http.response_code

המאפיין received_bytes ממופה למאפיין network.sent_bytes

המאפיין referer_url ממופה אל network.http.referral_url

‫user_agent ממופה ל-network.http.user_agent

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא NGINX

הערך של metadata.product_name הוא NGINX

הערך של network.ip_protocol הוא TCP

הערך של network.direction הוא OUTBOUND

var/log/nginx/error.log ‪2022/01/29 13:51:48 [error] 593#593: *62432 open() \"/usr/share/nginx/html/nginx_status\" failed (2: No such file or directory), client: 192.0.2.1, server: localhost, request: \"GET /nginx_status HTTP/1.1\", host: \"192.0.2.1:8080\" "{year}\/{month}\/{day}{time}[{severity}]{pid}#{thread_id}:{inner_message2}"

‫inner_message2 ממופה אל '{security_result_description_2},client:{principal_ip},server:(<optional_field>{target_hostname}?),request:"{http_method} /(<optional_field>{resource_name}?) {protocol}/1.1",host:"({target_ip}:{target_port})?"

‪"bind() to ({target_ip}|[{target_ip}]):{target_port} failed ({security_description})",

‪"\*{cid}{security_description}",

"{security_description}"

NETWORK_HTTP

‫thread_id ממופה ל-principal.process.pid

מידת החומרה ממופה ל-security_result.severity

(debug is mapped to UNKNOWN_SEVERITY, info is mapped to INFORMATIONAL, notice is mapped to LOW, warn is mapped to MEDIUM, error is mapped to ERROR, crit is mapped to CRITICAL, alert is mapped to HIGH)

‫target_file_full_path ממופה אל target.file.full_path

‫principal_ip ממופה ל-principal.ip

‫target_hostname ממופה אל target.hostname

‫http_method ממופה ל-network.http.method

‫resource_name ממופה אל principal.resource.name

הפרוטוקול ממופה ל-TCP

‫target_ip ממופה אל target.ip

‫target_port ממופה אל target.port

‫security_description + security_result_description_2 ממופה ל-security_result.description

‫pid ממופה אל principal.process.parent_process.pid

ההגדרה של network.application_protocol היא HTTP

חותמת הזמן ממופה לפורמט {year}/{day}/{month} {time}

הערך של target.platform מוגדר כ-'LINUX'

הערך של metadata.vendor_name הוא NGINX

הערך של metadata.product_name הוא NGINX

הערך של network.ip_protocol הוא TCP

הערך של network.direction הוא OUTBOUND

var/log/rkhunter.log ‫[14:10:40] בדיקת הפקודות הנדרשות נכשלה [<message_text>]{security_description} עדכון סטטוס

השדה time ממופה אל metadata.timestamp

‫security_description ממופה ל-security_result.description

הערך של principal.platform הוא LINUX

‫metadata.vendor_name מוגדר כ-RootKit Hunter

ההגדרה של metadata.product_name היא RootKit Hunter

var/log/rkhunter.log ‫[14:09:52] בדיקה אם הקובץ '/dev/.oz/.nap/rkit/terror' קיים [ לא נמצא ] ‪[<message_text>] {security_description} {file_path}[\{metadata_description}] FILE_UNCATEGORIZED המאפיין metadata_description ממופה למאפיין metadata.description

‫file_path ממופה אל target.file.full_path

‫security_description ממופה ל-security_result.description

הערך של principal.platform הוא LINUX

‫metadata.vendor_name מוגדר כ-RootKit Hunter

ההגדרה של metadata.product_name היא RootKit Hunter

var/log/rkhunter.log ‫fluentd: גודל הקובץ הוקטן (מספר ה-inode נשאר זהה): ‎'/var/log/rkhunter.log'. (<optional_field><message_text>:){metadata_description}:'{file_path}' FILE_UNCATEGORIZED

הזמן ממופה ל-metadata.timestamp

המאפיין metadata_description ממופה אל metadata.description

‫file_path ממופה אל target.file.full_path

הערך של principal.platform הוא LINUX

‫metadata.vendor_name מוגדר כ-RootKit Hunter

ההגדרה של metadata.product_name היא RootKit Hunter

/var/log/kern.log Apr 28 12:41:35 localhost kernel: [ 5079.912215] ctnetlink v0.93: registering with nfnetlink. {timestamp}{principal_hostname}{metadata_product_event_type}:[<message_text>]{metadata_description} עדכון סטטוס

חותמת הזמן ממופה אל metadata.event_timestamp

principal_hostname ממופה ל-'principal.hostname'

‫metadata_product_event_type ממופה אל metadata.product_event_type

‫metadata_description ממופה אל metadata.description

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

הערך של principal.platform הוא LINUX

/var/log/kern.log ‪Jul 6 11:17:01 Ubuntu18 kernel: [ 0.030139] smpboot: CPU0: Intel(R) Xeon(R) Gold 5220R CPU @ 2.20GHz (family: 0x6, model: 0x55, stepping: 0x7) {timestamp}{principal_hostname}{metadata_product_event_type}:([<message_text>])<message_text>:\CPU0:{principal_asset_hardware_cpu_model}({metadata_description}) STATUS_UPDATE

חותמת הזמן ממופה אל metadata.event_timestamp

principal_hostname ממופה ל-'principal.hostname'

‫metadata_product_event_type ממופה אל metadata.product_event_type

המאפיין principal_asset_hardware_cpu_model ממופה אל principal.asset.hardware.cpu_model

‫metadata_description ממופה אל metadata.description

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

הערך של principal.platform הוא LINUX

‫cpu_model ממופה אל principal.asset.hardware.cpu_model

/var/log/syslog.log ‫24 במאי 10:30:42 Ubuntu18 systemd[1]: Started Session 112 of user kajal. {collected_timestamp}{hostname}{command_line}(<optional_field>[{pid}]):{message} STATUS_UPDATE

הפרמטר collected_time ממופה אל metadata.event_timestamp

שם המארח ממופה ל-principal.hostname

‫pid ממופה אל principal.process.pid

ההודעה ממופה ל-metadata.description

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

הערך של principal.platform הוא LINUX

‫command_line ממופה אל principal.process.command_line

/var/log/syslog.log ‫Jul 06 10:14:37 Ubuntu18 rsyslogd: rsyslogd's userid changed to 102 {collected_timestamp}{hostname}{command_line}:{message}to{user_id} STATUS_UPDATE

השדה collected_time ממופה אל metadata.collected_timestamp

שם המארח ממופה ל-principal.hostname

ההודעה ממופה ל-metadata.description

‫user_id ממופה אל principal.user.userid

‫command_line ממופה אל principal.process.command_line

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

הערך של principal.platform הוא LINUX

/var/log/syslog.log Jul 06 10:36:48 Ubuntu18 systemd[1]: Starting System Logging Service... {collected_timestamp}{hostname}{command_line}(<optional_field>|[{pid}]):{message} STATUS_UPDATE

הפרמטר collected_time ממופה אל metadata.event_timestamp

שם המארח ממופה ל-principal.hostname

‫pid ממופה אל principal.process.pid

ההודעה ממופה ל-metadata.description

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

הערך של principal.platform הוא LINUX

‫command_line ממופה אל principal.process.command_line

var/log/openvpnas.log ‪2022-04-29T10:51:22+0530 [stdout#info] [OVPN 4] OUT: '2022-04-29 05:21:22 mohit_AUTOLOGIN/198.51.100.1:16245 MULTI: Learn: 198.51.100.1 -> mohit_AUTOLOGIN/203.0.113.1:16245' ‫{timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>-<message_text>{user}\/{ip}:{port}MULTI:Learn:{local_ip}->{target_hostname}?{target_ip}:{port}(<optional_field>'|") NETWORK_HTTP

חותמת הזמן ממופה אל metadata.timestamp

‫log_level ממופה ל-security_result.severity

‫local_ip ממופה ל-principal.ip

‫target_ip ממופה אל target.ip

‫target_hostname ממופה אל principal.hostname

היציאה ממופה ל-target.port

המשתמש ממופה אל principal.user.user_display_name

‫metadata.vendor_name מוגדר כ-OpenVPN

‫metadata.product_name מוגדר כ-OpenVPN Access Server

הערך של principal.platform הוא LINUX

var/log/openvpnas.log ‪2022-04-28T16:14:13+0530 [stdout#info] [OVPN 6] OUT: '2022-04-28 16:14:13 library versions: OpenSSL 1.1.1 11 Sep 2018, LZO 2.08' {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>{msg}(<optional_field>'|") עדכון סטטוס

חותמת הזמן ממופה אל metadata.timestamp

‫log_level ממופה ל-security_result.severity

ההודעה ממופה ל-security_result.description

‫metadata.vendor_name מוגדר כ-OpenVPN

‫metadata.product_name מוגדר כ-OpenVPN Access Server

הערך של principal.platform הוא LINUX

var/log/openvpnas.log 2022-04-28T16:14:13+0530 [stdout#info] [OVPN 6] OUT: '2022-04-28 16:14:13 net_addr_v4_add: 198.51.100.1/23 dev as0t6'

{timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:<optional_field>'|"<message_text>-<message_text>-<message_text><message_text>{message}<optional_field>'|"

ההודעה ממופה אל (net_addr_v4_add|net_route_v4_best_gw):{target_ip}/{target_port}

עדכון סטטוס

הערך של principal.platform הוא LINUX

‫target_ip ממופה אל target.ip

‫target_port ממופה אל target.port

מידת החומרה ממופה ל-security_result.severity

חותמת הזמן ממופה אל metadata.timestamp

הערך של metadata.vendor_name הוא OpenVPN

‫metadata.product_name מוגדר ל-OpenVPN Access Server

var/log/openvpnas.log ‪2022-04-29T10:51:22+0530 [stdout#info] [OVPN 4] OUT: '2022-04-29 05:21:22 198.51.100.1:16245 [mohit_AUTOLOGIN] Peer Connection Initiated with [AF_INET]192.0.2.1:16245 (via [AF_INET]198.51.100.1%ens160)'

{timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>{message}(<optional_field>'|")

ההודעה ממופה אל <message_text>עם[<message_text>]<message_text>:{port}<message_text>

עדכון סטטוס

חותמת הזמן ממופה אל metadata.timestamp

‫log_level ממופה ל-security_result.severity

הערך של metadata.vendor_name הוא OpenVPN

‫metadata.product_name מוגדר ל-OpenVPN Access Server

הערך של principal.platform הוא Linux

‫target_ip ממופה אל target.ip

‫target_port ממופה אל target.port

‫target_hostname ממופה אל target.hostname

‫intermediary_ip ממופה אל intermediary.ip

var/log/openvpnas.log ‪2022-04-29T10:51:22+0530 [stdout#info] [OVPN 4] OUT: \"2022-04-29 05:21:22 mohit_AUTOLOGIN/198.51.100.1:16245 SENT CONTROL [mohit_AUTOLOGIN]: 'PUSH_REPLY,explicit-exit-notify,topology subnet,route-delay 5 30,dhcp-pre-release,dhcp-renew,dhcp-release,route-metric 101,ping 12,ping-restart 50,redirect-gateway def1,redirect-gateway bypass-dhcp,redirect-gateway autolocal,route-gateway 198.51.100.1,dhcp-option DNS 192.0.2.1,dhcp-option DNS 192.0.2.1,register-dns,block-ipv6,ifconfig 198.51.100.1 203.0.113.1,peer-id 0,auth-tokenSESS_ID,cipher AES-256-GCM,key-derivation tls-ekm' (status=1)\" {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>{user}\/{ip}:{message}(<optional_field>'|") עדכון סטטוס

חותמת הזמן ממופה אל metadata.timestamp

‫log_level ממופה ל-security_result.severity

ההודעה ממופה ל-metadata.description

המשתמש ממופה ל-target.hostname

ה-IP ממופה ל-target.ip

היציאה ממופה ל-target.port

הערך של metadata.vendor_name הוא OpenVPN

‫metadata.product_name מוגדר ל-OpenVPN Access Server

הערך של principal.platform הוא Linux

var/log/openvpnas.log 2022-04-29T10:51:22+0530 [stdout#info] AUTH SUCCESS {'status': 0, 'user': 'mohit', 'reason': 'AuthAutoLogin: autologin certificate auth succeeded', 'proplist': {'prop_autogenerate': 'true', 'prop_autologin': 'true', 'pvt_password_digest': '[redacted]', 'type': 'user_connect'}, 'common_name': 'mohit_AUTOLOGIN', 'serial': '3', 'serial_list': []} cli='win'/'3.git::d3f8b18b'/'OCWindows_3.3.6-2752' {timestamp}[stdout#{log_level}]{summary}{'<message_text>':({status})?'<message_text>':({user})?'<message_text>':({reason})?<message_text>}, 'common_name':'{user_name}'<message_text>}cli='{cli}' עדכון סטטוס

חותמת הזמן ממופה אל metadata.timestamp

‫log_level ממופה ל-security_result.severity

ההודעה ממופה ל-security_result.description

הסיכום ממופה ל-security_result.summary

‫user_name ממופה אל principal.user.user_display_name

‫cli ממופה אל principal.process.command_line

הסטטוס ממופה אל principal.user.user_authentication_status

‫metadata.vendor_name מוגדר כ-OpenVPN

‫metadata.product_name מוגדר כ-OpenVPN Access Server

הערך של principal.platform הוא LINUX

/var/log/rundeck/service.log ‫[2022-05-04T17:03:11,166] WARN config.NavigableMap - Accessing config key '[filterNames]' through dot notation is deprecated, and it will be removed in a future release. במקום זאת, צריך להשתמש ב-'config.getProperty(key, targetClass)'. ‫[{timestamp}]{severity}{summary}\-{security_description}

, בכתובת {command_line}\({file_path}:<message_text>\)

עדכון סטטוס ‫command_line ממופה אל target.process.command_line

file_path ממופה אל target.process.file.full_path

חותמת הזמן ממופה אל metadata.event_timestamp

מידת החומרה ממופה ל-security_result.severity

הסיכום ממופה ל-security_result.summary

‫security_description ממופה אל 'security_result.description'

הערך של metadata.product_name הוא FLUENTD

ההגדרה של metadata.vendor_name היא FLUENTD

/var/log/auth.log ‪Jul 4 19:26:19 Ubuntu18 systemd-logind[982]: Removed session 153. ‫{timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}]):{security_description}{network_session_id}?(of user{principal_user_userid})? USER_LOGOUT

חותמת הזמן ממופה אל metadata.timestamp

principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname

המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application

הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid.

‫security_description ממופה אל 'security_result.description'

‫network_session_id ממופה אל network.session_id

המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid.

הערך של 'principal.platform' הוא LINUX

אם event security_description הוא Removed session, ‏ event_type מוגדר כ-USER_LOGOUT.

ההגדרה extensions.auth.type מוגדרת כ-AUTHTYPE_UNSPECIFIED

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/auth.log ‫Jun 27 11:07:17 Ubuntu18 systemd-logind[804]: New session 564 of user root. ‫{timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}]):{security_description}{network_session_id}?(of user{principal_user_userid})? USER_LOGIN

חותמת הזמן ממופה אל metadata.timestamp

principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname

המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application

הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid.

‫security_description ממופה אל 'security_result.description'

‫network_session_id ממופה אל network.session_id

המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid.

הערך של 'principal.platform' הוא LINUX

‫network.application_protocol ממופה ל-SSH

‫if(new_session) event_type is set to USER_LOGIN

ההגדרה extensions.auth.type מוגדרת כ-AUTHTYPE_UNSPECIFIED

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/auth.log ‫Jun 27 11:07:17 Ubuntu18 sshd[9349]: Accepted password for root from 198.51.100.1 port 57619 ssh2 ‫{timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}])<optional_field> {security_description} for (invalid user )?{principal_user_userid} from {principal_ip} port {principal_port} ssh2(:{security_result_detection_fields_ssh_kv}SHA256:{security_result_detection_fields_kv})? USER_LOGIN

חותמת הזמן ממופה אל metadata.timestamp

principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname

המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application

הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid.

‫security_description ממופה אל 'security_result.description'

המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid.

המשתנה principal_ip ממופה ל-principal.ip

‫principal_port ממופה ל-principal.port

‫security_result_detection_fields_ssh_kv ממופה אל security_result.detection_fields.key/value

‫security_result_detection_fields_kv ממופה אל security_result.detection_fields.key/value

הערך של 'principal.platform' הוא LINUX

הערך של 'network.application_protocol' מוגדר כ-'SSH'

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/auth.log Apr 28 11:51:13 Ubuntu18 sudo[24149]: root : TTY=pts/5 ; PWD=/ ; USER=root ; COMMAND=/bin/ls {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}])<optional_field> {principal_user_userid} :( {security_description} ;)? TTY=<message_text> ; PWD={principal_process_command_line_1} ; USER={principal_user_attribute_labels_uid_kv} ; COMMAND={principal_process_command_line_2} עדכון סטטוס

חותמת הזמן ממופה אל metadata.timestamp

השדה principal_hostname ממופה לשדה principal.hostname

‫principal_application ממופה אל principal.application

‫pid ממופה אל principal.process.pid

‫principal_user_userid ממופה אל target.user.userid

‫security_description ממופה אל 'security_result.description'

‫principal_process_command_line_1 ממופה אל principal.process.command_line

‫principal_process_command_line_2 ממופה אל principal.process.command_line

‫principal_user_attribute_labels_uid_kv ממופה אל principal.user.attribute.labels.key/value

הערך של 'principal.platform' הוא LINUX

/var/log/auth.log ‫Jul 4 19:39:01 Ubuntu18 CRON[17217]: pam_unix(cron:session): session opened for user root by (uid=0) ‫{timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}])<optional_field> {security_description} for (invalid user|user)?{principal_user_userid}(by (uid={principal_user_attribute_labels_uid_kv}))?$ USER_LOGIN

חותמת הזמן ממופה אל metadata.timestamp

principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname

המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application

הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid.

‫security_description ממופה אל 'security_result.description'

המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid.

‫principal_user_attribute_labels_uid_kv ממופה אל principal.user.attribute.labels.key/value

הערך של 'principal.platform' הוא LINUX

הערך של 'network.application_protocol' מוגדר כ-'SSH'

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/auth.log ‫Jul 4 19:24:43 Ubuntu18 sshd[14731]: pam_unix(sshd:session): session closed for user root ‫{timestamp} {principal_hostname}{principal_application}<optional_filed>[{pid}]): {security_description} for (invalid user|user){principal_user_userid} USER_LOGOUT

חותמת הזמן ממופה אל metadata.timestamp

principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname

המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application

הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid.

‫security_description ממופה אל 'security_result.description'

המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid.

‫principal_user_attribute_labels_uid_kv ממופה אל principal.user.attribute.labels.key/value

הערך של 'principal.platform' הוא LINUX

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/auth.log Jun 30 11:32:26 Ubuntu18 sshd[29425]: Connection reset by authenticating user root 198.51.100.1 port 52518 [preauth] {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}]):{security_description}(from|{principal_user_userid}){target_ip}port{target_port}<optional_field>[preauth]|:<text_message>{security_summary}|) USER_LOGOUT

חותמת הזמן ממופה אל metadata.timestamp

principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname

המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application

הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid.

‫security_description ממופה ל-security_result.description

‫security_summary ממופה אל security_result.summary

המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid.

‫target_ip ממופה אל target.ip

‫target_port ממופה אל target.port"

הערך של principal.platform הוא LINUX

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

var/log/samba/log.winbindd ‪[2022/05/05 13:51:22.212484, 0] ../source3/winbindd/winbindd_cache.c:3170(initialize_winbindd_cache)initialize_winbindd_cache: clearing cache and re-creating with version number 2 {timestamp},{severity}(<optional_field>,pid={pid},effective({principal_user_attribute_labels_kv},{principal_group_attribute_labels_kv}),real({principal_user_userid},{principal_group_product_object_id}))?]<message_text>:{security_description} עדכון סטטוס

חותמת הזמן ממופה אל metadata.timestamp

ה-pid ממופה ל-principal.process.pid

‫principal_user_attribute_labels_kv ממופה אל principal.user.attribute.labels

‫principal_group_attribute_labels_kv ממופה ל-principal.group.attribute.labels

‫principal_user_userid ממופה אל 'principal.user.userid'

‫principal_group_product_object_id ממופה אל principal.group.product_object_id

‫security_description ממופה אל 'security_result.description'

‫metadata_description ממופה אל metadata.description

‫metadata.product_name מוגדר כ-FLUENTD

‫metadata.vendor_name" is set to "FLUENTD"

var/log/samba/log.winbindd messaging_dgm_init: bind failed: No space left on device {user_id}: {desc} עדכון סטטוס

‫metadata.product_name מוגדר כ-FLUENTD

‫metadata.vendor_name" is set to "FLUENTD"

‫user_id ממופה אל principal.user.userid

המאפיין desc ממופה אל metadata.description

/var/log/mail.log ‫16 ביולי 11:40:56 Ubuntu18 sendmail[9341]: 22G6AtwH009341: from=<fluentd@Ubuntu18>, size=377, class=0, nrcpts=1, metadata_descriptionid=<202203160610.22G6AtwH009341@Ubuntu18.cdsys.local>, proto=SMTP, daemon=MTA-v4, relay=localhost [192.0.2.1] {timestamp} {target_hostname} {application}[{pid}]: <message_text>:{KV} עדכון סטטוס

‫target_hostname ממופה אל target.hostname

האפליקציה ממופה אל target.application

‫pid ממופה אל target.process.pid

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/mail.log July 7 13:44:01 prod postfix/pickup[22580]: AE4271627DB: uid=0 from=<root> {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} EMAIL_UNCATEGORIZED

‫target_hostname ממופה אל target.hostname

האפליקציה ממופה אל target.application

‫pid ממופה אל target.process.pid

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/mail.log ‪July 7 13:44:01 prod postfix/cleanup[23434]: AE4271627DB: message-id=<20150207184401.AE4271627DB@server.hostname.01> {timestamp} {target_hostname} {application}[{pid}]: <message_text> message-id=<{resource_name}> עדכון סטטוס

‫target_hostname ממופה אל target.hostname

האפליקציה ממופה אל target.application

‫pid ממופה אל target.process.pid

‫resource_name ממופה אל target.resource.name

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/mail.log July 7 13:44:01 prod postfix/qmgr[3539]: AE4271627DB: from=<root@server.hostname.01>, size=565, nrcpt=1 (queue active) {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} EMAIL_UNCATEGORIZED

‫target_hostname ממופה אל target.hostname

האפליקציה ממופה אל target.application

‫pid ממופה אל target.process.pid

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/mail.log ‫July 7 13:44:01 prod postfix/smtp[23436]: connect to gmail-smtp-in.l.example.com[2607:xxxx:xxxx:xxx::xx]:25: Network is unreachable {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} עדכון סטטוס

‫target_hostname ממופה אל target.hostname

האפליקציה ממופה אל target.application

‫pid ממופה אל target.process.pid

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

/var/log/mail.log ‫July 7 13:44:02 prod postfix/local[23439]: E62521627DC: to=<root@server.hostname.01>, relay=local, delay=0.01, delays=0/0.01/0/0, dsn=2.0.0, status=sent (delivered to mailbox) {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} EMAIL_UNCATEGORIZED

‫target_hostname ממופה אל target.hostname

האפליקציה ממופה אל target.application

‫pid ממופה אל target.process.pid

ההגדרה של metadata.vendor_name היא FLUENTD

הערך של metadata.product_name הוא FLUENTD

ביקורת

שדות ביומן ביקורת לשדות ב-UDM

בטבלה הבאה מפורטים השדות ביומן הביקורת לפי סוג, והשדות התואמים ב-UDM.

שדה ביומן שדה UDM
acct target.user.user_display_name
addr principal.ip
קשת about.labels.key/value
auid target.user.userid
cgroup principal.process.file.full_path
cmd target.process.command_line
comm target.application
cwd target.file.full_path
נתונים about.labels.key/value
devmajor about.labels.key/value
devminor about.labels.key/value
egid target.group.product_object_id
euid target.user.userid
exe target.process.file.full_path
יציאה target.labels.key/value
משפחה הערך של network.ip_protocol הוא IP6IN4 אם ip_protocol == 2, אחרת הערך הוא UNKNOWN_IP_PROTOCOL
filetype target.file.mime_type
fsgid target.group.product_object_id
fsuid target.user.userid
gid target.group.product_object_id
hostname target.hostname
icmptype הערך של network.ip_protocol הוא ICMP
id אם [audit_log_type] == "ADD_USER", הערך של target.user.userid מוגדר כ-"%{id}"

‫If [audit_log_type] == "ADD_GROUP", target.group.product_object_id is set to "%{id}"

אחרת, הערך של target.user.attribute.labels.key/value מוגדר כ-id

inode target.resource.product_object_id
key security_result.detection_fields.key/value
list security_result.about.labels.key/value
מצב target.resource.attribute.permissions.name

target.resource.attribute.permissions.type

name target.file.full_path
new-disk target.resource.name
new-mem target.resource.attribute.labels.key/value
new-vcpu target.resource.attribute.labels.key/value
new-net pincipal.mac
new_gid target.group.product_object_id
oauid target.user.userid
ocomm target.process.command_line
opid target.process.pid
oses network.session_id
ouid target.user.userid
obj_gid target.group.product_object_id
obj_role target.user.attribute.role.name
obj_uid target.user.userid
obj_user target.user.user_display_name
ogid target.group.product_object_id
ouid target.user.userid
נתיב target.file.full_path
פרמננט target.asset.attribute.permissions.name
pid target.process.pid
ppid target.parent_process.pid
proto אם [ip_protocol] == 2, ‏ network.ip_protocol מוגדר כ-"IP6IN4"

אחרת, הערך של network.ip_protocol הוא UNKNOWN_IP_PROTOCOL

res security_result.summary
result security_result.summary
saddr security_result.detection_fields.key/value
sauid target.user.attribute.labels.key/value
ses network.session_id
sgid target.group.product_object_id
sig security_result.detection_fields.key/value
subj_user target.user.user_display_name
הפעולה בוצעה אם success=='yes',‏ security_result.summary מוגדר כ-'system call was successful' אחרת, security_result.summary מוגדר כ-'systemcall was failed'
suid target.user.userid
קריאת מערכת about.labels.key/value
טרמינל target.labels.key/value
TTY target.labels.key/value
uid ‫If [audit_log_type] in [SYSCALL, SERVICE_START, ADD_GROUP, ADD_USER, MAC_IPSEC_EVENT, MAC_UNLBL_STCADD, OBJ_PID, CONFIG_CHANGE, SECCOMP, USER_CHAUTHTOK, USYS_CONFIG, DEL_GROUP, DEL_USER, USER_CMD, USER_MAC_POLICY_LOAD] uid is set to principal.user.userid

else uid is set to target.user.userid

vm target.resource.name

סוגים של יומני ביקורת לסוג אירוע ב-UDM

בטבלה הבאה מפורטים סוגי יומני הביקורת וסוגי האירועים התואמים ב-UDM.

סוג יומן הביקורת סוג אירוע UDM תיאור
ADD_GROUP GROUP_CREATION מופעל כשמוסיפים קבוצה במרחב המשתמש.
ADD_USER USER_CREATION מופעל כשמוסיפים חשבון משתמש במרחב המשתמש.
ANOM_ABEND GENERIC_EVENT / PROCESS_TERMINATION מופעל כאשר תהליך מסתיים בצורה לא תקינה (עם אות שיכול לגרום ליצירת קובץ ליבה, אם האפשרות הזו מופעלת).
AVC GENERIC_EVENT מופעל כדי להקליט בדיקת הרשאות של SELinux.
CONFIG_CHANGE USER_RESOURCE_UPDATE_CONTENT מופעל כשמשנים את ההגדרה של מערכת הביקורת.
CRED_ACQ USER_LOGIN מופעל כשמשתמש מקבל הרשאות במרחב המשתמש.
CRED_DISP USER_LOGOUT מופעל כשמשתמש משליך נתוני כניסה במרחב המשתמש.
CRED_REFR USER_LOGIN מופעל כשמשתמש מרענן את פרטי הכניסה שלו למרחב המשתמש.
CRYPTO_KEY_USER USER_RESOURCE_ACCESS מופעל כדי לתעד את מזהה המפתח הקריפטוגרפי שמשמש למטרות קריפטוגרפיות.
CRYPTO_SESSION PROCESS_TERMINATION מופעל כדי לתעד פרמטרים שמוגדרים במהלך יצירת סשן TLS.
CWD SYSTEM_AUDIT_LOG_UNCATEGORIZED הופעלה הקלטה של ספריית העבודה הנוכחית.
DAEMON_ABORT PROCESS_TERMINATION מופעל כשדמון מופסק בגלל שגיאה.
DAEMON_END PROCESS_TERMINATION מופעל כששירות (daemon) מופסק.
DAEMON_RESUME PROCESS_UNCATEGORIZED מופעל כששירות ה-daemon של auditd ממשיך את הרישום ביומן.
DAEMON_ROTATE PROCESS_UNCATEGORIZED מופעל כשדמון auditd מבצע רוטציה של קובצי יומן הביקורת.
DAEMON_START PROCESS_LAUNCH מופעל כשמתחילים את ה-daemon של auditd.
DEL_GROUP GROUP_DELETION מופעל כשמוחקים קבוצה במרחב המשתמשים
בהמתנה USER_DELETION מופעל כשמשתמש במרחב המשתמשים נמחק
EXECVE PROCESS_LAUNCH מופעל כדי להקליט את הארגומנטים של קריאת המערכת execve(2).
MAC_CONFIG_CHANGE GENERIC_EVENT מופעל כשערך בוליאני של SELinux משתנה.
MAC_IPSEC_EVENT SYSTEM_AUDIT_LOG_UNCATEGORIZED מופעל כדי לתעד מידע על אירוע IPSec, כשמתגלה אירוע כזה או כשמתבצע שינוי בהגדרת IPSec.
MAC_POLICY_LOAD GENERIC_EVENT מופעל כשקובץ מדיניות SELinux נטען.
MAC_STATUS GENERIC_EVENT מופעל כשמצב SELinux (אכיפה, הרשאה, השבתה) משתנה.
MAC_UNLBL_STCADD SYSTEM_AUDIT_LOG_UNCATEGORIZED מופעל כשמוסיפים תווית סטטית כשמשתמשים ביכולות התיוג של מנות המידע של ליבת המערכת שסופקו על ידי NetLabel.
NETFILTER_CFG GENERIC_EVENT מופעל כשמזוהים שינויים בשרשרת Netfilter.
OBJ_PID SYSTEM_AUDIT_LOG_UNCATEGORIZED מופעל כדי לתעד מידע על תהליך שאליו נשלח אות.
נתיב FILE_OPEN/GENERIC_EVENT מופעל כדי לתעד את פרטי הנתיב של שם הקובץ.
SELINUX_ERR GENERIC_EVENT מופעלת כשמזוהה שגיאת SELinux פנימית.
SERVICE_START SERVICE_START מופעל כשמתחילים להשתמש בשירות.
SERVICE_STOP SERVICE_STOP מופעל כששירות מופסק.
SYSCALL GENERIC_EVENT מופעלת הקלטה של שיחה למערכת לליבת המערכת.
SYSTEM_BOOT STATUS_STARTUP מופעל כשמפעילים את המערכת.
SYSTEM_RUNLEVEL STATUS_UPDATE מופעל כשמשנים את רמת ההרצה של המערכת.
SYSTEM_SHUTDOWN STATUS_SHUTDOWN מופעל כשהמערכת מושבתת.
USER_ACCT SETTING_MODIFICATION מופעל כשמשנים חשבון משתמש במרחב המשתמש.
USER_AUTH USER_LOGIN מופעל כשמזוהה ניסיון אימות של משתמש במרחב.
USER_AVC USER_UNCATEGORIZED מופעל כשנוצרת הודעת AVC במרחב משתמש.
USER_CHAUTHTOK USER_RESOURCE_UPDATE_CONTENT מופעל כשמשנים מאפיין של חשבון משתמש.
USER_CMD USER_COMMUNICATION מופעלת כשפקודת מעטפת של מרחב משתמש מופעלת.
USER_END USER_LOGOUT מופעל כשסשן במרחב המשתמשים מסתיים.
USER_ERR USER_UNCATEGORIZED מופעל כשמזוהה שגיאה במצב של חשבון משתמש.
USER_LOGIN USER_LOGIN מופעל כשמשתמש מתחבר לחשבון.
USER_LOGOUT USER_LOGOUT מופעל כשמשתמש מתנתק מהחשבון.
USER_MAC_POLICY_LOAD RESOURCE_READ מופעל כשדמון במרחב המשתמש טוען מדיניות SELinux.
USER_MGMT USER_UNCATEGORIZED מופעל כדי לתעד נתוני ניהול של מרחב המשתמש.
USER_ROLE_CHANGE USER_CHANGE_PERMISSIONS מופעל כשמשנים את תפקיד SELinux של משתמש.
USER_START USER_LOGIN מופעל כשמתחיל סשן במרחב המשתמש.
USYS_CONFIG USER_RESOURCE_UPDATE_CONTENT מופעל כשמזוהה שינוי בהגדרת המערכת במרחב המשתמש.
VIRT_CONTROL STATUS_UPDATE מופעל כשמכונה וירטואלית מופעלת, מושהית או מופסקת.
VIRT_MACHINE_ID USER_RESOURCE_ACCESS מופעל כדי לתעד את הקישור של תווית למכונה וירטואלית.
VIRT_RESOURCE USER_RESOURCE_ACCESS מופעלת כדי לתעד הקצאת משאבים של מכונה וירטואלית.

שליחת אימייל

שדות ביומן הדואר לשדות ב-UDM

בטבלה הבאה מפורטים שדות היומן של סוג יומן הדואר והשדות התואמים ב-UDM.

שדה ביומן שדה UDM
מחלקה about.labels.key/value
כתובת הבקרה principal.user.user_display_name
מאת network.email.from
Msgid network.email.mail_id
Proto network.application_protocol
שרת ממסר intermediary.hostname

intermediary.ip

גודל network.received_bytes
נתון סטטיסטי security_result.summary
הם במצב network.email.to

סוגי יומנים של אימייל למיפוי לסוג אירוע ב-UDM

בטבלה הבאה מפורטים סוגי יומני הדואר וסוגי האירועים המתאימים להם ב-UDM.

סוג יומן הדואר סוג אירוע UDM
sendmail עדכון סטטוס
איסוף EMAIL_UNCATEGORIZED
ניקוי נתונים עדכון סטטוס
qmgr EMAIL_UNCATEGORIZED
smtp עדכון סטטוס
מקומי EMAIL_UNCATEGORIZED

המאמרים הבאים

שנה רישום

צפייה ביומן השינויים של כלי הניתוח הזה

הבעיה עדיין לא נפתרה? קבלת תשובות מחברי הקהילה וממומחי Google SecOps.