איסוף יומנים של Fluentd
גרסת מנתח הנתונים: 16.0
במאמר הזה מוסבר איך לאסוף יומנים של Fluentd באמצעות הגדרה של Fluentd ושל מעביר נתונים של Google Security Operations. במסמך הזה מפורטים גם סוגי היומנים הנתמכים וגרסת Fluentd הנתמכת.
מידע נוסף זמין במאמר בנושא העברת נתונים אל Google Security Operations.
סקירה כללית
בתרשים דיאגרמת ארכיטקטורת הפריסה הבא מוצג אופן ההתקנה של Fluentd בשרת ה-Forwarder ובשרת ה-Aggregator כדי לשלוח יומנים אל Google Security Operations. הפריסה של כל לקוח עשויה להיות שונה מהייצוג הזה, ואולי מורכבת יותר.
דיאגרמת הארכיטקטורה מציגה את הרכיבים הבאים:
מערכת Linux. מערכת Linux שרוצים לנטר. מערכת Linux מורכבת מהקבצים למעקב ומשרת Fluentd forwarder.
מערכת Microsoft Windows. מערכת Microsoft Windows שרוצים לעקוב אחריה, שבה מותקן שרת Fluentd forwarder.
Fluentd forwarder. הכלי להעברת נתונים Fluentd אוסף מידע ממערכת Microsoft Windows או Linux ומעביר את המידע לאגרגטור Fluentd.
אגרגטור Fluentd. האגרגטור Fluentd מקבל יומנים מה-forwarder של Fluentd ומעביר אותם ל-forwarder של Google Security Operations.
Bindplane agent. הסוכן של Bindplane מאחזר יומנים מ-Zscaler ZPA ושולח אותם ל-Google SecOps.
Google Security Operations forwarder. הכלי להעברת נתונים של Google Security Operations הוא רכיב תוכנה קל משקל שמוטמע ברשת של הלקוח ותומך ב-syslog. הכלי להעברת נתונים של Google Security Operations מעביר את היומנים אל Google Security Operations.
Google Security Operations. Google Security Operations שומרת את היומנים מהאגרגטור Fluentd ומנתחת אותם.
תווית הטמעה מזהה את מנתח הנתונים שמנרמל נתוני יומן גולמיים לפורמט UDM מובנה. המידע במסמך הזה רלוונטי למנתח התוכן עם תווית ההטמעה FLUENTD.
לפני שמתחילים
מוודאים ש-Fluentd forwarder מותקן במערכות Microsoft Windows או Linux שאתם מתכננים לעקוב אחריהן. מידע נוסף על התקנת Fluentd forwarder
משתמשים בגרסת Fluentd שהכלי לניתוח של Google Security Operations תומך בה. הכלי לניתוח נתונים של Google Security Operations תומך בגרסה 1.0 של Fluentd.
מוודאים שהצבירה של Fluentd מותקנת ומוגדרת בשרת Linux המרכזי.
מוודאים שכל המערכות בארכיטקטורת הפריסה מוגדרות לאזור הזמן UTC.
בודקים את סוגי היומנים שכלי הניתוח של Google Security Operations תומך בהם. בטבלה הבאה מפורטים המוצרים ונתיבי קובצי היומן שהכלי לניתוח של Google Security Operations תומך בהם:
מערכת ההפעלה מוצר נתיב קובץ היומן Microsoft Windows Microsoft Windows יומני אירועים Linux Linux /var/log/audit/audit.log Linux Linux /var/log/syslog Linux apache2 /var/log/apache2/access.log Linux apache2 /var/log/apache2/error.log Linux apache2 /var/log/apache2/other_vhosts_access.log Linux apache2 /var/log/apache2/novnc-server-access.log Linux OpenVpn /var/log/openvpnas.log Linux Nginx /var/log/nginx/access.log Linux Nginx /var/log/nginx/error.log Linux rkhunter /var/log/rkhunter.log Linux Linux /var/log/auth.log Linux Linux /var/log/kern.log Linux rundeck /var/log/rundeck/service.log Linux Samba /var/log/samba/log.winbindd Linux Linux /var/log/mail.log
הגדרת המעביר והמצבר של Fluentd, והמעביר של Google Security Operations
כדי לעקוב אחרי היומנים שמערכות Linux יוצרות, יוצרים קובץ
td-agent.confכדי לציין את הגדרות המעקב אחרי היומנים עבור Fluentd forwarder. זוהי דוגמה לקובץ הגדרה של Fluentd forwarder במערכת Linux:<source> @type tail path /var/log/nginx/access.log pos_file /var/log/td-agent/nginx-access.log.pos tag mytag.nginx.access <parse> @type none </parse> </source> <source> @type tail path /var/log/nginx/error.log pos_file /var/log/td-agent/nginx-error.log.pos tag mytag.nginx.error <parse> @type none </parse> </source> <source> @type tail path /var/log/apache2/access.log pos_file /var/log/td-agent/apache-access.log.pos tag mytag.apache.access <parse> @type none </parse> </source> <source> @type tail path /var/log/apache2/error.log pos_file /var/log/td-agent/apache-error.log.pos tag mytag.apache.error <parse> @type none </parse> </source> <source> @type tail path /var/log/audit/audit.log pos_file /var/log/td-agent/audit.log.pos tag mytag.audit <parse> @type none </parse> </source> <source> @type tail path /var/log/syslog/syslog.log pos_file /var/log/td-agent/syslog.log.pos tag mytag.syslog <parse> @type none </parse> </source> <source> @type tail path /var/log/apache2/other_vhosts_access.log pos_file /var/log/td-agent/vhost.log.pos tag mytag.apache.other_vhosts_access <parse> @type none </parse> </source> <source> @type tail path /var/log/apache2/novnc-server-access.log pos_file /var/log/td-agent/novnc.log.pos tag mytag.apache.novnc-server-access <parse> @type none </parse> </source> <source> @type tail path /var/log/openvpnas.log pos_file /var/log/td-agent/openvpnas.log.pos tag mytag.openvpnas <parse> @type none </parse> </source> <source> @type tail path /var/log/auth.log pos_file /var/log/td-agent/auth.log.pos tag mytag.auth <parse> @type none </parse> </source> <source> @type tail path /var/log/kern.log pos_file /var/log/td-agent/kern.log.pos tag mytag.kern <parse> @type none </parse> </source> <source> @type tail path /var/log/rundeck/service.log pos_file /var/log/td-agent/rundeck.log.pos tag mytag.rundeck <parse> @type none </parse> </source> <source> @type tail path /var/log/mail.log pos_file /var/log/td-agent/mail.log.pos tag mytag.mail <parse> @type none </parse> </source> <source> @type tail path /var/log/rkhunter.log pos_file /var/log/td-agent/rkhunter.log.pos tag mytag.rkhunter <parse> @type none </parse> </source> <source> @type tail Path /var/log/samba/log.winbindd pos_file /var/log/td-agent/winbindd.log.pos tag mytag.winbindd <parse> @type none </parse> </source> <filter mytag.**> @type record_transformer <record> forwarder_hostname "#{Socket.gethostname}" </record> </filter> <filter mytag.nginx.access.**> @type record_transformer <record> path "/var/log/nginx/access.log" </record> </filter> <filter mytag.nginx.error.**> @type record_transformer <record> path "/var/log/nginx/error.log" </record> </filter> <filter mytag.apache.access.**> @type record_transformer <record> path "/var/log/apache2/access.log" </record> </filter> <filter mytag.apache.error.**> @type record_transformer <record> path "/var/log/apache2/error.log" </record> </filter> <filter mytag.audit.**> @type record_transformer <record> path "/var/log/audit/audit.log" </record> </filter> <filter mytag.syslog.**> @type record_transformer <record> path "/var/log/syslog/syslog.log" </record> </filter> <filter mytag.apache.other_vhosts_access.**> @type record_transformer <record> path "/var/log/apache2/other_vhosts_access.log" </record> </filter> <filter mytag.apache.novnc-server-access.**> @type record_transformer <record> path "/var/log/apache2/novnc-server-access.log" </record> </filter> <filter mytag.openvpnas.**> @type record_transformer <record> path "/var/log/openvpnas.log" </record> </filter> <filter mytag.auth.**> @type record_transformer <record> path "/var/log/auth.log" </record> </filter> <filter mytag.kern.**> @type record_transformer <record> path "/var/log/kern.log" </record> </filter> <filter mytag.rundeck.**> @type record_transformer <record> path "/var/log/rundeck/service.log" </record> </filter> <filter mytag.mail.**> @type record_transformer <record> path "/var/log/mail.log" </record> </filter> <filter mytag.rkhunter.**> @type record_transformer <record> path "/var/log/rkhunter.log" </record> </filter> <filter mytag.winbindd.**> @type record_transformer <record> path "/var/log/samba/log.winbindd" </record> </filter> <match mytag.**> @type forward # primary host <server> host <AGGREGATOR_HOSTNAME> port <AGGREGATOR_PORT> </server> </match>כדי לעקוב אחרי היומנים שמערכות Microsoft Windows יוצרות, צריך ליצור קובץ
td-agent.confכדי לציין את הגדרות המעקב אחרי היומנים עבור Fluentd forwarder. דוגמה לקובץ תצורה של Fluentd forwarder במערכת Microsoft Windows:<source> @type windows_eventlog @id windows_eventlog channels application,security,system read_existing_events true read_interval 2 tag windows.raw render_as_xml true <storage> @type local persistent true path E:\windows.pos </storage> </source> <match windowslog> @type forward <server> host <AGGREGATOR_HOSTNAME> port <AGGREGATOR_PORT> username <AGGREGATOR_USERNAME> password <AGGREGATOR_PASSWORD> </server> </match>כדי להעביר את היומנים מהצובר Fluentd למעביר של Google Security Operations, צריך ליצור קובץ תצורה בפורמט הבא:
<source> @type forward port <AGGREGATOR_PORT> </source> ## Forwarding <match mytag.**> @id output_system_forward @type forward # IP and port of the forwarder <server> host <CHRONICLE_FORWARDER_HOSTNAME> port <CHRONICLE_FORWARDER_PORT> </server> </match>מגדירים את מעביר היומנים של Google Security Operations לשליחת יומנים אל Google Security Operations. מידע נוסף זמין במאמר התקנה והגדרה של המעביר ב-Linux. הנה דוגמה להגדרת מעביר ב-Google Security Operations:
common: enabled: true data_type: FLUENTD batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: 0.0.0.0:10514 connection_timeout_sec: 60
העברת יומנים ל-Google SecOps באמצעות סוכן Bindplane
- מתקינים ומגדירים מכונה וירטואלית של Linux.
- איך מתקינים ומגדירים את סוכן Bindplane ב-Linux כדי להעביר יומנים ל-Google SecOps. מידע נוסף על התקנה והגדרה של סוכן Bindplane זמין בהוראות להתקנה ולהגדרה של סוכן Bindplane.
אם נתקלתם בבעיות ביצירת פידים, פנו לתמיכה של Google SecOps.
פורמטים נתמכים של יומנים ב-Fluentd
מנתח הנתונים של Fluentd תומך ביומנים בפורמט SYSLOG+JSON.
יומנים לדוגמה של Fluentd שנתמכים
SYSLOG + JSON
"2022-06-30T17:10:10+05:30 mytag.apache.error {\"message\":\"[Sat Jun 02 00:30:55 2022] New connection: [connection: gTxkX8Z6tjk] [client 172.17.0.1:50786]\",\"forwarder_hostname\":\"Ubuntu18\",\"path\":\"/var/log/apache2/error.log\"}"
הפניה למיפוי שדות
בקטע הזה מוסבר איך מנתח התוכן משתמש בתבניות grok במערכות Linux ו-Microsoft Windows, ואיך הוא ממפה שדות של יומן Fluentd לשדות של מודל הנתונים המאוחד (UDM) של Google Security Operations לכל סוג יומן.
מידע על מיפוי הפניה של שדות נפוצים זמין במאמר שדות נפוצים
למידע על נתיבי יומנים, דפוסי grok ליומנים לדוגמה, סוגי אירועים ושדות UDM במערכות Linux, אפשר לעיין בקטעים הבאים:
מידע על אירועים נתמכים ב-Microsoft Windows ושדות UDM תואמים זמין במאמר נתונים של אירועים ב-Microsoft Windows
שדות נפוצים
בטבלה הבאה מפורטים שדות נפוצים ביומן והשדות התואמים להם ב-UDM.
| שדה יומן נפוץ | שדה UDM |
|---|---|
| collected_time | metadata.collected_timestamp |
| inner_message.message | inner_message |
| inner_message.forwarder_hostname | target.hostname או principal.hostname |
| inner_message.path | event_source |
מערכת Linux
בטבלה הבאה מפורטים נתיבי היומן של מערכת Linux, דפוס grok לדוגמאות של יומנים, סוג האירוע ומיפויים של UDM:
| נתיב היומן | יומן לדוגמה | תבנית Grok | סוג אירוע | מיפוי UDM |
|---|---|---|---|---|
| /var/log/apache2/error.log | [Thu Apr 28 16:13:01.283342 2022] [core:notice] [pid 18394:tid 140188660751296] [client 1.200.32.47:59840] failed to make connection | [{timestamp}][{log_module}:{log_level}][pid{pid}(<optional_field>:tid{tid}|)](<optional_field> [client {client_ip}:{client_port}]|) (?<error_message>.*) | NETWORK_UNCATEGORIZED | חותמת הזמן ממופה אל metadata.event_timestamp log_module ממופה ל-target.resource.name log_level ממופה ל-security_result.severity pid ממופה אל target.process.parent_process.pid tid ממופה ל-target.process.pid client_ip ממופה אל principal.ip client_port ממופה ל-principal.port error_message ממופה ל-security_result.description ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/error.log | [Thu Apr 28 16:13:01.283342 2022] [core:notice] [pid 18394:tid 140188660751296] failed to make connection | [{timestamp}][{log_module}:{severity}][pid{pid}(<optional_field>:tid{tid}|)]{error_message} | NETWORK_UNCATEGORIZED | חותמת הזמן ממופה אל metadata.event_timestamp log_module ממופה ל-target.resource.name log_level ממופה ל-security_result.severity pid ממופה אל target.process.parent_process.pid tid ממופה ל-target.process.pid error_message ממופה ל-security_result.description ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/error.log | [Thu Apr 28 16:13:01.283342 2022] [core:notice] [pid 18394:tid 140188660751296] AH00094: שורת פקודה: '/usr/sbin/apache2' | [{timestamp}][{log_module}:{log_level}][pid{pid}(<optional_field>:tid{tid}|)](<optional_field> [client {client_ip}:{client_port}]|) (?<error_message>.*),referer{referer_url} | NETWORK_UNCATEGORIZED | הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server חותמת הזמן ממופה אל metadata.event_timestamp log_module ממופה ל-target.resource.name log_level ממופה ל-security_result.severity pid ממופה אל target.process.parent_process.pid tid ממופה ל-target.process.pid client_ip ממופה אל principal.ip client_port ממופה ל-principal.port error_message ממופה ל-security_result.description הערך של target.platform מוגדר כ-'LINUX' המאפיין referer_url ממופה אל network.http.referral_url |
| /var/log/apache2/error.log | [Sun Jan 30 15:14:47.260309 2022] [proxy_http:error] [pid 12515:tid 140035781285632] [client 1.200.32.47:59840] AH01114: HTTP: failed to make connection to backend: 192.0.2.1 , referer http:// | [{timestamp}] [{log_module}:{log_level}] [pid {pid}(<optional_field>:tid{tid}|)] [client {client_ip}:{client_port}]( <message_text>HTTP: )?{error_message}:( {target_ip})(<optional_field>,referer{referer_url})?" | NETWORK_HTTP | חותמת הזמן ממופה אל metadata.event_timestamp log_module ממופה ל-target.resource.name log_level ממופה ל-security_result.severity pid ממופה אל target.process.parent_process.pid tid ממופה ל-target.process.pid client_ip ממופה אל principal.ip client_port ממופה ל-principal.port error_message ממופה ל-security_result.description target_ip ממופה אל target.ip המאפיין referer_url ממופה למאפיין network.http.referral_url ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/error.log | [Sat Feb 02 00:30:55 2019] New connection: [connection: gTxkX8Z6tjk] [client 192.0.2.1:50786] | [{timestamp}]<message_text>connection:[connection:{connection_id}][client{client_ip}:{client_port}] | NETWORK_UNCATEGORIZED | חותמת הזמן ממופה אל metadata.event_timestamp client_ip ממופה אל principal.ip client_port ממופה ל-principal.port connection_id ממופה אל network.session_id ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/error.log | [Sat Feb 02 00:30:55 2019] New request: [connection: j8BjX4Z5tjk] [request: ACtkX1Z5tjk] [pid 8] [client 192.0.2.1:50784] | [{timestamp}]<message_text>request:[connection:{connection_id}][request:{request_id}][pid{pid}][client{client_ip}:{client_port}] | NETWORK_UNCATEGORIZED | חותמת הזמן ממופה אל metadata.event_timestamp request_id ממופה ל-security_result.detection_fields.(key/value) client_ip ממופה אל principal.ip client_port ממופה ל-principal.port pid ממופה אל target.process.parent_process.pid connection_id ממופה אל network.session_id ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/error.log | [Sat Feb 02 00:30:55 2019] [info] [C: j8BjX4Z5tjk] [R: p7pjX4Z5tjk] [pid 8] core.c(4739): [client 192.0.2.1:50784] AH00128: File does not exist: /usr/local/apache2/htdocs/favicon.ico | [{timestamp}] [{log_level}][C:{connection_id}][R:{request_id}][pid {pid}(<optional_field>:tid{tid}|)]<message_text>[client {client_ip}:{client_port}]{error_message}:{file_path} | NETWORK_UNCATEGORIZED | חותמת הזמן ממופה אל metadata.event_timestamp log_level ממופה ל-security_result.severity request_id ממופה ל-security_result.detection_fields.(key/value) client_ip ממופה אל principal.ip client_port ממופה ל-principal.port pid ממופה אל target.process.parent_process.pid connection_id ממופה אל network.session_id error_message ממופה ל-security_result.description file_path ממופה אל target.file.full_path ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/access.log | 192.0.2.1 - - [28/Apr/2022:17:35:52 +0530] "GET / HTTP/1.1" 200 3476 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/192.0.2.1 Safari/537.36" | ({client_ip})?<message_text>{userid}[{timestamp}](<optional_field>{method}/(<optional_field>{resource}?) {client_protocol}?){result_status}{object_size}(<optional_field>(<optional_field>{referer_url}?)(<optional_field>{user_agent}?)? | NETWORK_HTTP | client_ip ממופה אל principal.ip userid ממופה אל principal.user.userid המארח ממופה אל principal.hostname חותמת הזמן ממופה אל metadata.event_timestamp השיטה ממופה ל-network.http.method המשאב ממופה אל principal.resource.name client_protocol ממופה ל-network.application_protocol result_status ממופה ל-network.http.response_code object_size ממופה ל-network.sent_bytes המאפיין referer_url ממופה אל network.http.referral_url user_agent ממופה ל-network.http.user_agent הערך של network.ip_protocol הוא TCP הערך של network.direction הוא OUTBOUND ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| var/log/apache2/other_vhosts_access.log | wintest.example.com:80 ::1 - - [14/Jan/2022:14:08:16 -0700] \"GET /server-status?auto HTTP/1.1\" 200 1415 \"-\" \"Python-urllib/2.7\" | {target_host}:{NUMBER:target_port} {client_ip} - (<optional_field>{host}?) [{timestamp}](<optional_field>{method}/(<optional_field>{resource}?){client_protocol}?){result_status}{object_size}(<optional_field>{referer_url}?)(<optional_field>{user_agent}?) | NETWORK_HTTP | target_host ממופה אל target.hostname
target_port ממופה אל target.port client_ip ממופה אל principal.ip userid ממופה אל principal.user.userid המארח ממופה אל principal.hostname חותמת הזמן ממופה אל metadata.event_timestamp השיטה ממופה ל-network.http.method המשאב ממופה אל principal.resource.name result_status ממופה ל-network.http.response_code object_size ממופה ל-network.sent_bytes המאפיין referer_url ממופה אל network.http.referral_url user_agent ממופה ל-network.http.user_agent הערך של network.ip_protocol הוא TCP הערך של network.direction הוא OUTBOUND הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server ההגדרה של network.application_protocol היא HTTP |
| var/log/apache2/novnc-server-access.log | wintest.example.com:80 ::1 - - [14/Jan/2022:14:08:16 -0700] \"GET /server-status?auto HTTP/1.1\" 200 1415 \"-\" \"http://\" | {target_host}:{NUMBER:target_port} {client_ip} - (<optional_field>{host}?) [{timestamp}](<optional_field>{method}/(<optional_field>{resource}?){client_protocol}?){result_status}{object_size}(<optional_field>{referer_url}?)(<optional_field>{user_agent}?) | NETWORK_HTTP | client_ip ממופה אל principal.ip userid ממופה אל principal.user.userid השיטה ממופה ל-network.http.method הנתיב ממופה אל target.url result_status ממופה ל-network.http.response_code object_size ממופה ל-network.sent_bytes המאפיין referer_url ממופה אל network.http.referral_url user_agent ממופה ל-network.http.user_agent הערך של network.ip_protocol הוא TCP הערך של network.direction הוא OUTBOUND הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server ההגדרה של network.application_protocol היא HTTP |
| /var/log/apache2/access.log | "http://192.0.2.1/test/first.html" -> /google.com | (<optional_field>{referer_url}?)->(<optional_field>{path}?) | GENERIC_EVENT | הנתיב ממופה אל target.url המאפיין referer_url ממופה למאפיין network.http.referral_url הערך של network.direction הוא OUTBOUND הערך של target.platform מוגדר כ-'LINUX' ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| /var/log/apache2/access.log | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Code/1.67.0 Chrome/98.0.4758.141 Electron/17.4.1 Safari/537.36 | (<optional_field>{user_agent}) | GENERIC_EVENT | user_agent ממופה ל-network.http.user_agent הערך של network.direction הוא OUTBOUND הערך של target.platform מוגדר כ-'LINUX' ההגדרה של network.application_protocol היא HTTP הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא Apache הערך של metadata.product_name הוא Apache HTTP Server |
| var/log/nginx/access.log | 192.0.2.1 - admin [05/May/2022:11:53:27 +0530] "GET /icons/ubuntu-logo.png HTTP/1.1" 404 209 "http://198.51.100.1/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/192.0.2.1 Safari/537.36" | {principal_ip} - (<optional_field>{principal_user_userid}?) [{timestamp}] {http_method} /(<optional_field>{resource_name}?|) {protocol}(<message_text>){response_code} {received_bytes}(<optional_field>{referer_url}) ({user_agent}|{user_agent})? | NETWORK_HTTP | הזמן ממופה ל-metadata.timestamp ה-IP ממופה ל-target.ip principal_ip ממופה ל-principal.ip principal_user_userid ממופה אל principal.user.userid metadata_timestamp ממופה אל timestamp http_method ממופה ל-network.http.method resource_name ממופה אל principal.resource.name הפרוטוקול ממופה ל-network.application_protocol = (HTTP) המאפיין response_code ממופה למאפיין network.http.response_code המאפיין received_bytes ממופה למאפיין network.sent_bytes המאפיין referer_url ממופה אל network.http.referral_url user_agent ממופה ל-network.http.user_agent הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא NGINX הערך של metadata.product_name הוא NGINX הערך של network.ip_protocol הוא TCP הערך של network.direction הוא OUTBOUND |
| var/log/nginx/error.log | 2022/01/29 13:51:48 [error] 593#593: *62432 open() \"/usr/share/nginx/html/nginx_status\" failed (2: No such file or directory), client: 192.0.2.1, server: localhost, request: \"GET /nginx_status HTTP/1.1\", host: \"192.0.2.1:8080\" | "{year}\/{month}\/{day}{time}[{severity}]{pid}#{thread_id}:{inner_message2}"
inner_message2 ממופה אל '{security_result_description_2},client:{principal_ip},server:(<optional_field>{target_hostname}?),request:"{http_method} /(<optional_field>{resource_name}?) {protocol}/1.1",host:"({target_ip}:{target_port})?" "bind() to ({target_ip}|[{target_ip}]):{target_port} failed ({security_description})", "\*{cid}{security_description}", "{security_description}" |
NETWORK_HTTP | thread_id ממופה ל-principal.process.pid מידת החומרה ממופה ל-security_result.severity (debug is mapped to UNKNOWN_SEVERITY, info is mapped to INFORMATIONAL, notice is mapped to LOW, warn is mapped to MEDIUM, error is mapped to ERROR, crit is mapped to CRITICAL, alert is mapped to HIGH) target_file_full_path ממופה אל target.file.full_path principal_ip ממופה ל-principal.ip target_hostname ממופה אל target.hostname http_method ממופה ל-network.http.method resource_name ממופה אל principal.resource.name הפרוטוקול ממופה ל-TCP target_ip ממופה אל target.ip target_port ממופה אל target.port security_description + security_result_description_2 ממופה ל-security_result.description pid ממופה אל principal.process.parent_process.pid ההגדרה של network.application_protocol היא HTTP חותמת הזמן ממופה לפורמט {year}/{day}/{month} {time} הערך של target.platform מוגדר כ-'LINUX' הערך של metadata.vendor_name הוא NGINX הערך של metadata.product_name הוא NGINX הערך של network.ip_protocol הוא TCP הערך של network.direction הוא OUTBOUND |
| var/log/rkhunter.log | [14:10:40] בדיקת הפקודות הנדרשות נכשלה | [<message_text>]{security_description} | עדכון סטטוס | השדה time ממופה אל metadata.timestamp security_description ממופה ל-security_result.description הערך של principal.platform הוא LINUX metadata.vendor_name מוגדר כ-RootKit Hunter ההגדרה של metadata.product_name היא RootKit Hunter |
| var/log/rkhunter.log | [14:09:52] בדיקה אם הקובץ '/dev/.oz/.nap/rkit/terror' קיים [ לא נמצא ] | [<message_text>] {security_description} {file_path}[\{metadata_description}] | FILE_UNCATEGORIZED | המאפיין metadata_description ממופה למאפיין metadata.description
file_path ממופה אל target.file.full_path security_description ממופה ל-security_result.description הערך של principal.platform הוא LINUX metadata.vendor_name מוגדר כ-RootKit Hunter ההגדרה של metadata.product_name היא RootKit Hunter |
| var/log/rkhunter.log | fluentd: גודל הקובץ הוקטן (מספר ה-inode נשאר זהה): '/var/log/rkhunter.log'. | (<optional_field><message_text>:){metadata_description}:'{file_path}' | FILE_UNCATEGORIZED | הזמן ממופה ל-metadata.timestamp המאפיין metadata_description ממופה אל metadata.description file_path ממופה אל target.file.full_path הערך של principal.platform הוא LINUX metadata.vendor_name מוגדר כ-RootKit Hunter ההגדרה של metadata.product_name היא RootKit Hunter |
| /var/log/kern.log | Apr 28 12:41:35 localhost kernel: [ 5079.912215] ctnetlink v0.93: registering with nfnetlink. | {timestamp}{principal_hostname}{metadata_product_event_type}:[<message_text>]{metadata_description} | עדכון סטטוס | חותמת הזמן ממופה אל metadata.event_timestamp principal_hostname ממופה ל-'principal.hostname' metadata_product_event_type ממופה אל metadata.product_event_type metadata_description ממופה אל metadata.description ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD הערך של principal.platform הוא LINUX |
| /var/log/kern.log | Jul 6 11:17:01 Ubuntu18 kernel: [ 0.030139] smpboot: CPU0: Intel(R) Xeon(R) Gold 5220R CPU @ 2.20GHz (family: 0x6, model: 0x55, stepping: 0x7) | {timestamp}{principal_hostname}{metadata_product_event_type}:([<message_text>])<message_text>:\CPU0:{principal_asset_hardware_cpu_model}({metadata_description}) | STATUS_UPDATE | חותמת הזמן ממופה אל metadata.event_timestamp principal_hostname ממופה ל-'principal.hostname' metadata_product_event_type ממופה אל metadata.product_event_type המאפיין principal_asset_hardware_cpu_model ממופה אל principal.asset.hardware.cpu_model metadata_description ממופה אל metadata.description ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD הערך של principal.platform הוא LINUX cpu_model ממופה אל principal.asset.hardware.cpu_model |
| /var/log/syslog.log | 24 במאי 10:30:42 Ubuntu18 systemd[1]: Started Session 112 of user kajal. | {collected_timestamp}{hostname}{command_line}(<optional_field>[{pid}]):{message} | STATUS_UPDATE | הפרמטר collected_time ממופה אל metadata.event_timestamp שם המארח ממופה ל-principal.hostname pid ממופה אל principal.process.pid ההודעה ממופה ל-metadata.description ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD הערך של principal.platform הוא LINUX command_line ממופה אל principal.process.command_line |
| /var/log/syslog.log | Jul 06 10:14:37 Ubuntu18 rsyslogd: rsyslogd's userid changed to 102 | {collected_timestamp}{hostname}{command_line}:{message}to{user_id} | STATUS_UPDATE | השדה collected_time ממופה אל metadata.collected_timestamp שם המארח ממופה ל-principal.hostname ההודעה ממופה ל-metadata.description user_id ממופה אל principal.user.userid command_line ממופה אל principal.process.command_line ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD הערך של principal.platform הוא LINUX |
| /var/log/syslog.log | Jul 06 10:36:48 Ubuntu18 systemd[1]: Starting System Logging Service... | {collected_timestamp}{hostname}{command_line}(<optional_field>|[{pid}]):{message} | STATUS_UPDATE | הפרמטר collected_time ממופה אל metadata.event_timestamp שם המארח ממופה ל-principal.hostname pid ממופה אל principal.process.pid ההודעה ממופה ל-metadata.description ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD הערך של principal.platform הוא LINUX command_line ממופה אל principal.process.command_line |
| var/log/openvpnas.log | 2022-04-29T10:51:22+0530 [stdout#info] [OVPN 4] OUT: '2022-04-29 05:21:22 mohit_AUTOLOGIN/198.51.100.1:16245 MULTI: Learn: 198.51.100.1 -> mohit_AUTOLOGIN/203.0.113.1:16245' | {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>-<message_text>{user}\/{ip}:{port}MULTI:Learn:{local_ip}->{target_hostname}?{target_ip}:{port}(<optional_field>'|") | NETWORK_HTTP | חותמת הזמן ממופה אל metadata.timestamp log_level ממופה ל-security_result.severity local_ip ממופה ל-principal.ip target_ip ממופה אל target.ip target_hostname ממופה אל principal.hostname היציאה ממופה ל-target.port המשתמש ממופה אל principal.user.user_display_name metadata.vendor_name מוגדר כ-OpenVPN metadata.product_name מוגדר כ-OpenVPN Access Server הערך של principal.platform הוא LINUX |
| var/log/openvpnas.log | 2022-04-28T16:14:13+0530 [stdout#info] [OVPN 6] OUT: '2022-04-28 16:14:13 library versions: OpenSSL 1.1.1 11 Sep 2018, LZO 2.08' | {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>{msg}(<optional_field>'|") | עדכון סטטוס | חותמת הזמן ממופה אל metadata.timestamp log_level ממופה ל-security_result.severity ההודעה ממופה ל-security_result.description metadata.vendor_name מוגדר כ-OpenVPN metadata.product_name מוגדר כ-OpenVPN Access Server הערך של principal.platform הוא LINUX |
| var/log/openvpnas.log | 2022-04-28T16:14:13+0530 [stdout#info] [OVPN 6] OUT: '2022-04-28 16:14:13 net_addr_v4_add: 198.51.100.1/23 dev as0t6' | {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:<optional_field>'|"<message_text>-<message_text>-<message_text><message_text>{message}<optional_field>'|" ההודעה ממופה אל (net_addr_v4_add|net_route_v4_best_gw):{target_ip}/{target_port} |
עדכון סטטוס | הערך של principal.platform הוא LINUX target_ip ממופה אל target.ip target_port ממופה אל target.port מידת החומרה ממופה ל-security_result.severity חותמת הזמן ממופה אל metadata.timestamp הערך של metadata.vendor_name הוא OpenVPN metadata.product_name מוגדר ל-OpenVPN Access Server |
| var/log/openvpnas.log | 2022-04-29T10:51:22+0530 [stdout#info] [OVPN 4] OUT: '2022-04-29 05:21:22 198.51.100.1:16245 [mohit_AUTOLOGIN] Peer Connection Initiated with [AF_INET]192.0.2.1:16245 (via [AF_INET]198.51.100.1%ens160)' | {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>{message}(<optional_field>'|") ההודעה ממופה אל <message_text>עם[<message_text>]<message_text>:{port}<message_text> |
עדכון סטטוס | חותמת הזמן ממופה אל metadata.timestamp log_level ממופה ל-security_result.severity הערך של metadata.vendor_name הוא OpenVPN metadata.product_name מוגדר ל-OpenVPN Access Server הערך של principal.platform הוא Linux target_ip ממופה אל target.ip target_port ממופה אל target.port target_hostname ממופה אל target.hostname intermediary_ip ממופה אל intermediary.ip |
| var/log/openvpnas.log | 2022-04-29T10:51:22+0530 [stdout#info] [OVPN 4] OUT: \"2022-04-29 05:21:22 mohit_AUTOLOGIN/198.51.100.1:16245 SENT CONTROL [mohit_AUTOLOGIN]: 'PUSH_REPLY,explicit-exit-notify,topology subnet,route-delay 5 30,dhcp-pre-release,dhcp-renew,dhcp-release,route-metric 101,ping 12,ping-restart 50,redirect-gateway def1,redirect-gateway bypass-dhcp,redirect-gateway autolocal,route-gateway 198.51.100.1,dhcp-option DNS 192.0.2.1,dhcp-option DNS 192.0.2.1,register-dns,block-ipv6,ifconfig 198.51.100.1 203.0.113.1,peer-id 0,auth-tokenSESS_ID,cipher AES-256-GCM,key-derivation tls-ekm' (status=1)\" | {timestamp}[stdout#{log_level}][OVPN <message_text>]OUT:(<optional_field>'|")<message_text>{user}\/{ip}:{message}(<optional_field>'|") | עדכון סטטוס | חותמת הזמן ממופה אל metadata.timestamp log_level ממופה ל-security_result.severity ההודעה ממופה ל-metadata.description המשתמש ממופה ל-target.hostname ה-IP ממופה ל-target.ip היציאה ממופה ל-target.port הערך של metadata.vendor_name הוא OpenVPN metadata.product_name מוגדר ל-OpenVPN Access Server הערך של principal.platform הוא Linux |
| var/log/openvpnas.log | 2022-04-29T10:51:22+0530 [stdout#info] AUTH SUCCESS {'status': 0, 'user': 'mohit', 'reason': 'AuthAutoLogin: autologin certificate auth succeeded', 'proplist': {'prop_autogenerate': 'true', 'prop_autologin': 'true', 'pvt_password_digest': '[redacted]', 'type': 'user_connect'}, 'common_name': 'mohit_AUTOLOGIN', 'serial': '3', 'serial_list': []} cli='win'/'3.git::d3f8b18b'/'OCWindows_3.3.6-2752' | {timestamp}[stdout#{log_level}]{summary}{'<message_text>':({status})?'<message_text>':({user})?'<message_text>':({reason})?<message_text>}, 'common_name':'{user_name}'<message_text>}cli='{cli}' | עדכון סטטוס | חותמת הזמן ממופה אל metadata.timestamp log_level ממופה ל-security_result.severity ההודעה ממופה ל-security_result.description הסיכום ממופה ל-security_result.summary user_name ממופה אל principal.user.user_display_name cli ממופה אל principal.process.command_line הסטטוס ממופה אל principal.user.user_authentication_status metadata.vendor_name מוגדר כ-OpenVPN metadata.product_name מוגדר כ-OpenVPN Access Server הערך של principal.platform הוא LINUX |
| /var/log/rundeck/service.log | [2022-05-04T17:03:11,166] WARN config.NavigableMap - Accessing config key '[filterNames]' through dot notation is deprecated, and it will be removed in a future release. במקום זאת, צריך להשתמש ב-'config.getProperty(key, targetClass)'. | [{timestamp}]{severity}{summary}\-{security_description}
, בכתובת {command_line}\({file_path}:<message_text>\) |
עדכון סטטוס | command_line ממופה אל target.process.command_line
file_path ממופה אל target.process.file.full_path חותמת הזמן ממופה אל metadata.event_timestamp מידת החומרה ממופה ל-security_result.severity הסיכום ממופה ל-security_result.summary security_description ממופה אל 'security_result.description' הערך של metadata.product_name הוא FLUENTD ההגדרה של metadata.vendor_name היא FLUENTD |
| /var/log/auth.log | Jul 4 19:26:19 Ubuntu18 systemd-logind[982]: Removed session 153. | {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}]):{security_description}{network_session_id}?(of user{principal_user_userid})? | USER_LOGOUT | חותמת הזמן ממופה אל metadata.timestamp principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid. security_description ממופה אל 'security_result.description' network_session_id ממופה אל network.session_id המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid. הערך של 'principal.platform' הוא LINUX אם event security_description הוא Removed session, event_type מוגדר כ-USER_LOGOUT. ההגדרה extensions.auth.type מוגדרת כ-AUTHTYPE_UNSPECIFIED ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/auth.log | Jun 27 11:07:17 Ubuntu18 systemd-logind[804]: New session 564 of user root. | {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}]):{security_description}{network_session_id}?(of user{principal_user_userid})? | USER_LOGIN | חותמת הזמן ממופה אל metadata.timestamp principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid. security_description ממופה אל 'security_result.description' network_session_id ממופה אל network.session_id המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid. הערך של 'principal.platform' הוא LINUX network.application_protocol ממופה ל-SSH if(new_session) event_type is set to USER_LOGIN ההגדרה extensions.auth.type מוגדרת כ-AUTHTYPE_UNSPECIFIED ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/auth.log | Jun 27 11:07:17 Ubuntu18 sshd[9349]: Accepted password for root from 198.51.100.1 port 57619 ssh2 | {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}])<optional_field> {security_description} for (invalid user )?{principal_user_userid} from {principal_ip} port {principal_port} ssh2(:{security_result_detection_fields_ssh_kv}SHA256:{security_result_detection_fields_kv})? | USER_LOGIN | חותמת הזמן ממופה אל metadata.timestamp principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid. security_description ממופה אל 'security_result.description' המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid. המשתנה principal_ip ממופה ל-principal.ip principal_port ממופה ל-principal.port security_result_detection_fields_ssh_kv ממופה אל security_result.detection_fields.key/value security_result_detection_fields_kv ממופה אל security_result.detection_fields.key/value הערך של 'principal.platform' הוא LINUX הערך של 'network.application_protocol' מוגדר כ-'SSH' ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/auth.log | Apr 28 11:51:13 Ubuntu18 sudo[24149]: root : TTY=pts/5 ; PWD=/ ; USER=root ; COMMAND=/bin/ls | {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}])<optional_field> {principal_user_userid} :( {security_description} ;)? TTY=<message_text> ; PWD={principal_process_command_line_1} ; USER={principal_user_attribute_labels_uid_kv} ; COMMAND={principal_process_command_line_2} | עדכון סטטוס | חותמת הזמן ממופה אל metadata.timestamp השדה principal_hostname ממופה לשדה principal.hostname principal_application ממופה אל principal.application pid ממופה אל principal.process.pid principal_user_userid ממופה אל target.user.userid security_description ממופה אל 'security_result.description' principal_process_command_line_1 ממופה אל principal.process.command_line principal_process_command_line_2 ממופה אל principal.process.command_line principal_user_attribute_labels_uid_kv ממופה אל principal.user.attribute.labels.key/value הערך של 'principal.platform' הוא LINUX |
| /var/log/auth.log | Jul 4 19:39:01 Ubuntu18 CRON[17217]: pam_unix(cron:session): session opened for user root by (uid=0) | {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}])<optional_field> {security_description} for (invalid user|user)?{principal_user_userid}(by (uid={principal_user_attribute_labels_uid_kv}))?$ | USER_LOGIN | חותמת הזמן ממופה אל metadata.timestamp principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid. security_description ממופה אל 'security_result.description' המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid. principal_user_attribute_labels_uid_kv ממופה אל principal.user.attribute.labels.key/value הערך של 'principal.platform' הוא LINUX הערך של 'network.application_protocol' מוגדר כ-'SSH' ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/auth.log | Jul 4 19:24:43 Ubuntu18 sshd[14731]: pam_unix(sshd:session): session closed for user root | {timestamp} {principal_hostname}{principal_application}<optional_filed>[{pid}]): {security_description} for (invalid user|user){principal_user_userid} | USER_LOGOUT | חותמת הזמן ממופה אל metadata.timestamp principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid. security_description ממופה אל 'security_result.description' המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid. principal_user_attribute_labels_uid_kv ממופה אל principal.user.attribute.labels.key/value הערך של 'principal.platform' הוא LINUX ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/auth.log | Jun 30 11:32:26 Ubuntu18 sshd[29425]: Connection reset by authenticating user root 198.51.100.1 port 52518 [preauth] | {timestamp} {principal_hostname}{principal_application}(<optional_field>[{pid}]):{security_description}(from|{principal_user_userid}){target_ip}port{target_port}<optional_field>[preauth]|:<text_message>{security_summary}|) | USER_LOGOUT | חותמת הזמן ממופה אל metadata.timestamp principal_hostname ממופה ל-target.hostname אם הערך הוא USER_LOGOUT, אחרת הוא ממופה ל-principal.hostname המשתנה principal_application ממופה אל target.application אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.application הפרמטר pid ממופה אל target.process.pid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה אל principal.process.pid. security_description ממופה ל-security_result.description security_summary ממופה אל security_result.summary המשתנה principal_user_userid ממופה למשתנה principal.user.userid אם הערך הוא USER_LOGOUT, אחרת הוא ממופה למשתנה target.user.userid. target_ip ממופה אל target.ip target_port ממופה אל target.port" הערך של principal.platform הוא LINUX ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| var/log/samba/log.winbindd | [2022/05/05 13:51:22.212484, 0] ../source3/winbindd/winbindd_cache.c:3170(initialize_winbindd_cache)initialize_winbindd_cache: clearing cache and re-creating with version number 2 | {timestamp},{severity}(<optional_field>,pid={pid},effective({principal_user_attribute_labels_kv},{principal_group_attribute_labels_kv}),real({principal_user_userid},{principal_group_product_object_id}))?]<message_text>:{security_description} | עדכון סטטוס | חותמת הזמן ממופה אל metadata.timestamp ה-pid ממופה ל-principal.process.pid principal_user_attribute_labels_kv ממופה אל principal.user.attribute.labels principal_group_attribute_labels_kv ממופה ל-principal.group.attribute.labels principal_user_userid ממופה אל 'principal.user.userid' principal_group_product_object_id ממופה אל principal.group.product_object_id security_description ממופה אל 'security_result.description' metadata_description ממופה אל metadata.description metadata.product_name מוגדר כ-FLUENTD metadata.vendor_name" is set to "FLUENTD" |
| var/log/samba/log.winbindd | messaging_dgm_init: bind failed: No space left on device | {user_id}: {desc} | עדכון סטטוס | metadata.product_name מוגדר כ-FLUENTD metadata.vendor_name" is set to "FLUENTD" user_id ממופה אל principal.user.userid המאפיין desc ממופה אל metadata.description |
| /var/log/mail.log | 16 ביולי 11:40:56 Ubuntu18 sendmail[9341]: 22G6AtwH009341: from=<fluentd@Ubuntu18>, size=377, class=0, nrcpts=1, metadata_descriptionid=<202203160610.22G6AtwH009341@Ubuntu18.cdsys.local>, proto=SMTP, daemon=MTA-v4, relay=localhost [192.0.2.1] | {timestamp} {target_hostname} {application}[{pid}]: <message_text>:{KV} | עדכון סטטוס | target_hostname ממופה אל target.hostname האפליקציה ממופה אל target.application pid ממופה אל target.process.pid ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/mail.log | July 7 13:44:01 prod postfix/pickup[22580]: AE4271627DB: uid=0 from=<root> | {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} | EMAIL_UNCATEGORIZED | target_hostname ממופה אל target.hostname האפליקציה ממופה אל target.application pid ממופה אל target.process.pid ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/mail.log | July 7 13:44:01 prod postfix/cleanup[23434]: AE4271627DB: message-id=<20150207184401.AE4271627DB@server.hostname.01> | {timestamp} {target_hostname} {application}[{pid}]: <message_text> message-id=<{resource_name}> | עדכון סטטוס | target_hostname ממופה אל target.hostname האפליקציה ממופה אל target.application pid ממופה אל target.process.pid resource_name ממופה אל target.resource.name ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/mail.log | July 7 13:44:01 prod postfix/qmgr[3539]: AE4271627DB: from=<root@server.hostname.01>, size=565, nrcpt=1 (queue active) | {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} | EMAIL_UNCATEGORIZED | target_hostname ממופה אל target.hostname האפליקציה ממופה אל target.application pid ממופה אל target.process.pid ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/mail.log | July 7 13:44:01 prod postfix/smtp[23436]: connect to gmail-smtp-in.l.example.com[2607:xxxx:xxxx:xxx::xx]:25: Network is unreachable | {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} | עדכון סטטוס | target_hostname ממופה אל target.hostname האפליקציה ממופה אל target.application pid ממופה אל target.process.pid ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
| /var/log/mail.log | July 7 13:44:02 prod postfix/local[23439]: E62521627DC: to=<root@server.hostname.01>, relay=local, delay=0.01, delays=0/0.01/0/0, dsn=2.0.0, status=sent (delivered to mailbox) | {timestamp} {target_hostname} {application}[{pid}]: <message_text>{KV} | EMAIL_UNCATEGORIZED | target_hostname ממופה אל target.hostname האפליקציה ממופה אל target.application pid ממופה אל target.process.pid ההגדרה של metadata.vendor_name היא FLUENTD הערך של metadata.product_name הוא FLUENTD |
ביקורת
שדות ביומן ביקורת לשדות ב-UDM
בטבלה הבאה מפורטים השדות ביומן הביקורת לפי סוג, והשדות התואמים ב-UDM.
| שדה ביומן | שדה UDM |
|---|---|
| acct | target.user.user_display_name |
| addr | principal.ip |
| קשת | about.labels.key/value |
| auid | target.user.userid |
| cgroup | principal.process.file.full_path |
| cmd | target.process.command_line |
| comm | target.application |
| cwd | target.file.full_path |
| נתונים | about.labels.key/value |
| devmajor | about.labels.key/value |
| devminor | about.labels.key/value |
| egid | target.group.product_object_id |
| euid | target.user.userid |
| exe | target.process.file.full_path |
| יציאה | target.labels.key/value |
| משפחה | הערך של network.ip_protocol הוא IP6IN4 אם ip_protocol == 2, אחרת הערך הוא UNKNOWN_IP_PROTOCOL |
| filetype | target.file.mime_type |
| fsgid | target.group.product_object_id |
| fsuid | target.user.userid |
| gid | target.group.product_object_id |
| hostname | target.hostname |
| icmptype | הערך של network.ip_protocol הוא ICMP |
| id | אם [audit_log_type] == "ADD_USER", הערך של target.user.userid מוגדר כ-"%{id}"
If [audit_log_type] == "ADD_GROUP", target.group.product_object_id is set to "%{id}" אחרת, הערך של target.user.attribute.labels.key/value מוגדר כ-id |
| inode | target.resource.product_object_id |
| key | security_result.detection_fields.key/value |
| list | security_result.about.labels.key/value |
| מצב | target.resource.attribute.permissions.name
target.resource.attribute.permissions.type |
| name | target.file.full_path |
| new-disk | target.resource.name |
| new-mem | target.resource.attribute.labels.key/value |
| new-vcpu | target.resource.attribute.labels.key/value |
| new-net | pincipal.mac |
| new_gid | target.group.product_object_id |
| oauid | target.user.userid |
| ocomm | target.process.command_line |
| opid | target.process.pid |
| oses | network.session_id |
| ouid | target.user.userid |
| obj_gid | target.group.product_object_id |
| obj_role | target.user.attribute.role.name |
| obj_uid | target.user.userid |
| obj_user | target.user.user_display_name |
| ogid | target.group.product_object_id |
| ouid | target.user.userid |
| נתיב | target.file.full_path |
| פרמננט | target.asset.attribute.permissions.name |
| pid | target.process.pid |
| ppid | target.parent_process.pid |
| proto | אם [ip_protocol] == 2, network.ip_protocol מוגדר כ-"IP6IN4"
אחרת, הערך של network.ip_protocol הוא UNKNOWN_IP_PROTOCOL |
| res | security_result.summary |
| result | security_result.summary |
| saddr | security_result.detection_fields.key/value |
| sauid | target.user.attribute.labels.key/value |
| ses | network.session_id |
| sgid | target.group.product_object_id |
| sig | security_result.detection_fields.key/value |
| subj_user | target.user.user_display_name |
| הפעולה בוצעה | אם success=='yes', security_result.summary מוגדר כ-'system call was successful' אחרת, security_result.summary מוגדר כ-'systemcall was failed' |
| suid | target.user.userid |
| קריאת מערכת | about.labels.key/value |
| טרמינל | target.labels.key/value |
| TTY | target.labels.key/value |
| uid | If [audit_log_type] in [SYSCALL, SERVICE_START, ADD_GROUP, ADD_USER, MAC_IPSEC_EVENT, MAC_UNLBL_STCADD, OBJ_PID, CONFIG_CHANGE, SECCOMP, USER_CHAUTHTOK, USYS_CONFIG, DEL_GROUP, DEL_USER, USER_CMD, USER_MAC_POLICY_LOAD] uid is set to principal.user.userid
else uid is set to target.user.userid |
| vm | target.resource.name |
סוגים של יומני ביקורת לסוג אירוע ב-UDM
בטבלה הבאה מפורטים סוגי יומני הביקורת וסוגי האירועים התואמים ב-UDM.
| סוג יומן הביקורת | סוג אירוע UDM | תיאור |
|---|---|---|
| ADD_GROUP | GROUP_CREATION | מופעל כשמוסיפים קבוצה במרחב המשתמש. |
| ADD_USER | USER_CREATION | מופעל כשמוסיפים חשבון משתמש במרחב המשתמש. |
| ANOM_ABEND | GENERIC_EVENT / PROCESS_TERMINATION | מופעל כאשר תהליך מסתיים בצורה לא תקינה (עם אות שיכול לגרום ליצירת קובץ ליבה, אם האפשרות הזו מופעלת). |
| AVC | GENERIC_EVENT | מופעל כדי להקליט בדיקת הרשאות של SELinux. |
| CONFIG_CHANGE | USER_RESOURCE_UPDATE_CONTENT | מופעל כשמשנים את ההגדרה של מערכת הביקורת. |
| CRED_ACQ | USER_LOGIN | מופעל כשמשתמש מקבל הרשאות במרחב המשתמש. |
| CRED_DISP | USER_LOGOUT | מופעל כשמשתמש משליך נתוני כניסה במרחב המשתמש. |
| CRED_REFR | USER_LOGIN | מופעל כשמשתמש מרענן את פרטי הכניסה שלו למרחב המשתמש. |
| CRYPTO_KEY_USER | USER_RESOURCE_ACCESS | מופעל כדי לתעד את מזהה המפתח הקריפטוגרפי שמשמש למטרות קריפטוגרפיות. |
| CRYPTO_SESSION | PROCESS_TERMINATION | מופעל כדי לתעד פרמטרים שמוגדרים במהלך יצירת סשן TLS. |
| CWD | SYSTEM_AUDIT_LOG_UNCATEGORIZED | הופעלה הקלטה של ספריית העבודה הנוכחית. |
| DAEMON_ABORT | PROCESS_TERMINATION | מופעל כשדמון מופסק בגלל שגיאה. |
| DAEMON_END | PROCESS_TERMINATION | מופעל כששירות (daemon) מופסק. |
| DAEMON_RESUME | PROCESS_UNCATEGORIZED | מופעל כששירות ה-daemon של auditd ממשיך את הרישום ביומן. |
| DAEMON_ROTATE | PROCESS_UNCATEGORIZED | מופעל כשדמון auditd מבצע רוטציה של קובצי יומן הביקורת. |
| DAEMON_START | PROCESS_LAUNCH | מופעל כשמתחילים את ה-daemon של auditd. |
| DEL_GROUP | GROUP_DELETION | מופעל כשמוחקים קבוצה במרחב המשתמשים |
| בהמתנה | USER_DELETION | מופעל כשמשתמש במרחב המשתמשים נמחק |
| EXECVE | PROCESS_LAUNCH | מופעל כדי להקליט את הארגומנטים של קריאת המערכת execve(2). |
| MAC_CONFIG_CHANGE | GENERIC_EVENT | מופעל כשערך בוליאני של SELinux משתנה. |
| MAC_IPSEC_EVENT | SYSTEM_AUDIT_LOG_UNCATEGORIZED | מופעל כדי לתעד מידע על אירוע IPSec, כשמתגלה אירוע כזה או כשמתבצע שינוי בהגדרת IPSec. |
| MAC_POLICY_LOAD | GENERIC_EVENT | מופעל כשקובץ מדיניות SELinux נטען. |
| MAC_STATUS | GENERIC_EVENT | מופעל כשמצב SELinux (אכיפה, הרשאה, השבתה) משתנה. |
| MAC_UNLBL_STCADD | SYSTEM_AUDIT_LOG_UNCATEGORIZED | מופעל כשמוסיפים תווית סטטית כשמשתמשים ביכולות התיוג של מנות המידע של ליבת המערכת שסופקו על ידי NetLabel. |
| NETFILTER_CFG | GENERIC_EVENT | מופעל כשמזוהים שינויים בשרשרת Netfilter. |
| OBJ_PID | SYSTEM_AUDIT_LOG_UNCATEGORIZED | מופעל כדי לתעד מידע על תהליך שאליו נשלח אות. |
| נתיב | FILE_OPEN/GENERIC_EVENT | מופעל כדי לתעד את פרטי הנתיב של שם הקובץ. |
| SELINUX_ERR | GENERIC_EVENT | מופעלת כשמזוהה שגיאת SELinux פנימית. |
| SERVICE_START | SERVICE_START | מופעל כשמתחילים להשתמש בשירות. |
| SERVICE_STOP | SERVICE_STOP | מופעל כששירות מופסק. |
| SYSCALL | GENERIC_EVENT | מופעלת הקלטה של שיחה למערכת לליבת המערכת. |
| SYSTEM_BOOT | STATUS_STARTUP | מופעל כשמפעילים את המערכת. |
| SYSTEM_RUNLEVEL | STATUS_UPDATE | מופעל כשמשנים את רמת ההרצה של המערכת. |
| SYSTEM_SHUTDOWN | STATUS_SHUTDOWN | מופעל כשהמערכת מושבתת. |
| USER_ACCT | SETTING_MODIFICATION | מופעל כשמשנים חשבון משתמש במרחב המשתמש. |
| USER_AUTH | USER_LOGIN | מופעל כשמזוהה ניסיון אימות של משתמש במרחב. |
| USER_AVC | USER_UNCATEGORIZED | מופעל כשנוצרת הודעת AVC במרחב משתמש. |
| USER_CHAUTHTOK | USER_RESOURCE_UPDATE_CONTENT | מופעל כשמשנים מאפיין של חשבון משתמש. |
| USER_CMD | USER_COMMUNICATION | מופעלת כשפקודת מעטפת של מרחב משתמש מופעלת. |
| USER_END | USER_LOGOUT | מופעל כשסשן במרחב המשתמשים מסתיים. |
| USER_ERR | USER_UNCATEGORIZED | מופעל כשמזוהה שגיאה במצב של חשבון משתמש. |
| USER_LOGIN | USER_LOGIN | מופעל כשמשתמש מתחבר לחשבון. |
| USER_LOGOUT | USER_LOGOUT | מופעל כשמשתמש מתנתק מהחשבון. |
| USER_MAC_POLICY_LOAD | RESOURCE_READ | מופעל כשדמון במרחב המשתמש טוען מדיניות SELinux. |
| USER_MGMT | USER_UNCATEGORIZED | מופעל כדי לתעד נתוני ניהול של מרחב המשתמש. |
| USER_ROLE_CHANGE | USER_CHANGE_PERMISSIONS | מופעל כשמשנים את תפקיד SELinux של משתמש. |
| USER_START | USER_LOGIN | מופעל כשמתחיל סשן במרחב המשתמש. |
| USYS_CONFIG | USER_RESOURCE_UPDATE_CONTENT | מופעל כשמזוהה שינוי בהגדרת המערכת במרחב המשתמש. |
| VIRT_CONTROL | STATUS_UPDATE | מופעל כשמכונה וירטואלית מופעלת, מושהית או מופסקת. |
| VIRT_MACHINE_ID | USER_RESOURCE_ACCESS | מופעל כדי לתעד את הקישור של תווית למכונה וירטואלית. |
| VIRT_RESOURCE | USER_RESOURCE_ACCESS | מופעלת כדי לתעד הקצאת משאבים של מכונה וירטואלית. |
שליחת אימייל
שדות ביומן הדואר לשדות ב-UDM
בטבלה הבאה מפורטים שדות היומן של סוג יומן הדואר והשדות התואמים ב-UDM.
| שדה ביומן | שדה UDM |
|---|---|
| מחלקה | about.labels.key/value |
| כתובת הבקרה | principal.user.user_display_name |
| מאת | network.email.from |
| Msgid | network.email.mail_id |
| Proto | network.application_protocol |
| שרת ממסר | intermediary.hostname
intermediary.ip |
| גודל | network.received_bytes |
| נתון סטטיסטי | security_result.summary |
| הם במצב | network.email.to |
סוגי יומנים של אימייל למיפוי לסוג אירוע ב-UDM
בטבלה הבאה מפורטים סוגי יומני הדואר וסוגי האירועים המתאימים להם ב-UDM.
| סוג יומן הדואר | סוג אירוע UDM |
|---|---|
| sendmail | עדכון סטטוס |
| איסוף | EMAIL_UNCATEGORIZED |
| ניקוי נתונים | עדכון סטטוס |
| qmgr | EMAIL_UNCATEGORIZED |
| smtp | עדכון סטטוס |
| מקומי | EMAIL_UNCATEGORIZED |
המאמרים הבאים
שנה רישום
צפייה ביומן השינויים של כלי הניתוח הזה
הבעיה עדיין לא נפתרה? קבלת תשובות מחברי הקהילה וממומחי Google SecOps.