Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CorelightForSecOps — محلل Chronicle لـ CORELIGHT والمعلومات ذات الصلة. | Kitploit
أدوات/GitHubGitHub/corelight/corelightforsecops
أدوات دفاعيةأمن الشبكاتأمن السحابةالأدوات والمكوناتكشف التسللتحليل السجلات
GitHubcorelight/corelightforsecops

CorelightForSecOps

محلل Chronicle لـ CORELIGHT والمعلومات ذات الصلة.

عرض المستودع
54منذ 2 أشهرلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

جمع سجلات Corelight Sensor

يصف هذا المستند كيفية جمع سجلات Corelight Sensor عن طريق تكوين Corelight Sensor وChronicle forwarder. كما يسرد هذا المستند أنواع السجلات المدعومة وإصدارات Corelight المدعومة.

لمزيد من المعلومات، راجع إدخال البيانات إلى Chronicle.

قبل البدء

  • تحقق من إصدار Corelight Sensor. تم تصميم محلل Google SecOps التابع لـ Corelight للإصدار 27.13 والإصدارات الأقدم. قد تحتوي الإصدارات الأحدث من Corelight Sensor على سجلات إضافية لن يتعرف عليها المحلل، وقد تتلقى تلك السجلات تحليلاً محدودًا أو بدون تحليل للحقول. ومع ذلك، سيظل محتوى السجل متاحًا بتنسيق السجل الخام في Google SecOps.
  • تأكد من تكوين جميع الأنظمة في بنية النشر على المنطقة الزمنية UTC.

طرق النشر وإدخال السجلات

يوضح مخطط بنية النشر التالي كيفية إعداد Corelight Sensor لإرسال السجلات إلى Google Security Operations باستخدام بنيتين مختلفتين لإدخال السجلات. من المهم ملاحظة أن كل نشر لدى العميل قد يختلف عن هذا التمثيل وقد يكون أكثر تعقيدًا.

تُعرّف تسمية الإدخال المحلل الذي يعيد تشكيل بيانات السجل الخام إلى تنسيق UDM منظم. تنطبق المعلومات الواردة في هذا المستند على المحلل ذي تسمية الإدخال CORELIGHT.

إدخال السجلات إلى Google SecOps باستخدام مُصدِّرات Corelight

بنية النشر

يوضح مخطط البنية المكونات التالية:

  • Corelight Sensor: النظام الذي يقوم بتشغيل Corelight Sensor .

  • مُصدِّرات Corelight Sensor: يجمع مُصدِّر Corelight Sensor بيانات السجل من Sensor ويعيد توجيهها إلى Google Security Operations.

  • Google Security Operations: تحتفظ Google Security Operations بسجلات Corelight Sensor وتحللها.

تكوين مُصدِّر Google SecOps في Corelight

استخدم واجهة الويب الخاصة بـ Sensor أو Fleet Manager لتكوين مُصدِّر Google SecOps. يستخدم هذا التكوين بيانات اعتماد API من مثيل Google SecOps الخاص بك لإنشاء الاتصال الآمن.

  1. سجّل الدخول إلى واجهة ويب Fleet Manager أو Sensor الخاصة بـ Corelight Sensor بصفة مسؤول.

  2. انتقل إلى منطقة تكوين المُصدِّر:

    • Fleet Manager: انتقل إلى Policies، وحدد سياسة، ثم انقر فوق علامة التبويب Export.
    • Standalone Sensor: انتقل إلى Configuration | Export | Export Configuration.
  3. في قسم إنشاء المُصدِّر، انقر فوق Google SecOps.

بنية النشر

  1. قم بتكوين معلمات الإدخال التالية:
  • Name*: اسم فريد لمثيل المُصدِّر هذا (على سبيل المثال، SecOps).
  • Google SecOps Customer ID*: معرّف العميل الفريد الخاص بك الذي توفره Google.
  • Google SecOps Namespace: مساحة الاسم المنطقية لسجلات Sensor الخاصة بك في Google SecOps.
  • Credentials*: بيانات اعتماد حساب الخدمة في Google SecOps (JSON). (الصق محتوى JSON الكامل).
  • Google SecOps Labels: تسميات يكوّنها المستخدم لتحديد نطاق البيانات.
  • Region*: اسم منطقة GCP المستخدمة بواسطة Google SecOps.
  • Batch Max Events: الحد الأقصى لحجم الدفعة.
  • Batch Timeout Seconds: الحد الأقصى لعمر الدفعة.
  • Proxy URL: عنوان URL للوكيل الشبكي، إذا لزم الأمر.
  • Exporter Log Filter: حدد عامل تصفية لتطبيقه على مثيل المُصدِّر هذا.
  • Log Type Filter: تضمين أو استبعاد ملفات سجلات معينة بالاسم.
    • Exclude: يزيل السجلات المحددة. سيستمر تصدير أنواع السجلات الجديدة (على سبيل المثال، من الحزم).
    • Include: يصدّر السجلات المحددة فقط. لن يتم تصدير أنواع السجلات الجديدة ما لم تُضاف يدويًا.

بنية النشر بنية النشر

  1. انقر فوق Done.

بنية النشر

  1. انقر فوق Apply Changes.

إدخال السجلات إلى Google SecOps باستخدام Forwarder

بنية النشر

يوضح مخطط البنية المكونات التالية:

  • Corelight Sensor: النظام الذي يقوم بتشغيل Corelight Sensor .

  • مُصدِّر Corelight Sensor: يجمع مُصدِّر Corelight Sensor بيانات السجل من Sensor ويعيد توجيهها إلى forwarder الخاص بـ Google Security Operations.

  • forwarder الخاص بـ Google Security Operations: مكوّن برمجي خفيف الوزن يُنشر في شبكة العميل ويدعم syslog. يقوم forwarder الخاص بـ Google Security Operations بإعادة توجيه السجلات إلى Google Security Operations.

  • Google Security Operations: تحتفظ Google Security Operations بسجلات Corelight Sensor وتحللها.

تكوين forwarder الخاص بـ Google Security Operations

لتكوين forwarder الخاص بـ Google Security Operations، نفّذ ما يلي:

  1. قم بإعداد forwarder خاص بـ Google Security Operations. راجع تثبيت وتكوين forwarder على Linux.

  2. قم بتكوين forwarder الخاص بـ Google Security Operations لإرسال السجلات إلى Google Security Operations. ```none collectors:

    • syslog: common: enabled: true data_type: CORELIGHT data_hint: batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: tcp_buffer_size: 524288 udp_address: connection_timeout_sec: 60
root@kitploit:~
### تكوين مُصدِّر Corelight Sensor 

1. سجّل الدخول إلى Corelight Sensor كمسؤول.
2. حدّد علامة التبويب **Export**.
3. ابحث عن خيار **EXPORT TO SYSLOG** وفعّله.
4. ضمن **EXPORT TO SYSLOG**، قم بتكوين الحقول التالية:
* **SYSLOG SERVER**: حدّد عنوان IP ورقم منفذ مستمع syslog الخاص بموجّه Google Security Operations.
* انتقل إلى **Advanced Settings > SYSLOG FORMAT**، وغيّر الإعداد إلى **Legacy**.

![تكوين Corelight Sensor](https://assets.kitploit.com/production/public/readmes/45240/98e9932cefa08d1f288a8a66675a4ae8398ad3d243bd14379054908875b0da03.jpg)

5. انقر على **Apply Changes**.

## أنواع سجلات Corelight المدعومة

يدعم محلّل Corelight أنواع السجلات التالية:
<div class="fixed" translate="no">
<h4>Log Type</h4>
<ul>
  <li>asset_classification</li>
  <li>conn</li>
  <li>conn_long</li>
  <li>conn_red</li>
  <li>conn_agg</li>
  <li>dce_rpc</li>
  <li>dns</li>
  <li>dns_red</li>
  <li>files</li>
  <li>files_red</li>
  <li>http</li>
  <li>http2</li>
  <li>http_red</li>
  <li>intel</li>
  <li>irc</li>
  <li>notice</li>
  <li>rdp</li>
  <li>sip</li>
  <li>smb_files</li>
  <li>smb_mapping</li>
  <li>smtp</li>
  <li>smtp_links</li>
  <li>ssh</li>
  <li>ssl</li>
  <li>ssl_red</li>
  <li>suricata_corelight</li>
  <li>bacnet</li>
  <li>cip</li>
  <li>corelight_burst</li>
  <li>corelight_metrics_bro</li>
  <li>corelight_metrics_disk</li>
  <li>corelight_metrics_iface</li>
  <li>corelight_metrics_memory</li>
  <li>corelight_metrics_system</li>
  <li>corelight_metrics_zeek_doctor</li>
  <li>corelight_overall_capture_loss</li>
  <li>corelight_profiling</li>
  <li>datared</li>
  <li>dga</li>
  <li>dhcp</li>
  <li>dnp3</li>
  <li>dpd</li>
  <li>encrypted_dns</li>
  <li>enip</li>
  <li>enip_debug</li>
  <li>enip_list_identity</li>
  <li>etc_viz</li>
  <li>ftp</li>
  <li>generic_dns_tunnels</li>
  <li>generic_icmp_tunnels</li>
  <li>icmp_specific_tunnels</li>
  <li>ipsec</li>
  <li>iso_cotp</li>
  <li>kerberos</li>
  <li>known_certs</li>
  <li>known_devices</li>
  <li>known_domains</li>
  <li>known_hosts</li>
  <li>known_names</li>
  <li>known_remotes</li>
  <li>known_services</li>
  <li>known_users</li>
  <li>ldap</li>
  <li>ldap_search</li>
  <li>local_subnets</li>
  <li>local_subnets_dj</li>
  <li>local_subnets_graphs</li>
  <li>log4shell</li>
  <li>modbus</li>
  <li>mqtt_connect</li>
  <li>mqtt_publish</li>
  <li>mqtt_subscribe</li>
  <li>mysql</li>
  <li>napatech_shunting</li>
  <li>ntlm</li>
  <li>ntp</li>
  <li>pe</li>
  <li>profinet</li>
  <li>profinet_dce_rpc</li>
  <li>profinet_debug</li>
  <li>radius</li>
  <li>reporter</li>
  <li>rfb</li>
  <li>s7comm</li>
  <li>smartpcap</li>
  <li>snmp</li>
  <li>socks</li>
  <li>software</li>
  <li>specific_dns_tunnels</li>
  <li>stepping</li>
  <li>stun</li>
  <li>stun_nat</li>
  <li>suricata_eve</li>
  <li>suricata_stats</li>
  <li>syslog</li>
  <li>tds</li>
  <li>tds_rpc</li>
  <li>tds_sql_batch</li>
  <li>traceroute</li>
  <li>tunnel</li>
  <li>unknown-smartpcap</li>
  <li>vpn</li>
  <li>weird</li>
  <li>weird_red</li>
  <li>wireguard</li>
  <li>x509</li>
  <li>x509_red</li>
  <li>dns_agg</li>
  <li>files_agg</li>
  <li>http_agg</li>
  <li>ssl_agg</li>
  <li>weird_agg</li>
  <li>analyzer</li>
  <li>anomaly</li>
  <li>ssdp</li>
  <li>telnet</li>
  <li>websocket</li>
  <li>first_seen</li>
</ul>
</div>

## مرجع تعيين الحقول

يشرح هذا القسم كيفية تعيين محلّل Google Security Operations لحقول Google Security Operations إلى حقول نموذج البيانات الموحّد (UDM) الخاص بها.

<h3>مرجع تعيين الحقول: CORELIGHT - الحقول الشائعة </h3>

يسرد الجدول التالي الحقول الشائعة لسجل <code>CORELIGHT</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.vendor_name</code></td>
<td>The <code>metadata.vendor_name</code> UDM field is set to <code>Corelight</code>.</td>
</tr>
<tr>
<td><code>_path (string)</code></td>
<td><code>metadata.product_event_type</code></td>
<td></td>
</tr>
<tr>
<td><code>_system_name (string)</code></td>
<td><code>observer.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>ts (time)</code></td>
<td><code>metadata.event_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>uid (string)</code></td>
<td><code>about.labels [uid], network.session_id</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_h (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_p (integer - port)</code></td>
<td><code>principal.port</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_h (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_p (integer - port)</code></td>
<td><code>target.port</code></td>
<td></td>
</tr>
<tr>
<td><code>_write_ts</code></td><code></code>
<td><code>metadata.collected_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan (integer - int)</code></td>
<td><code>additional.fields [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - int)</code></td>
<td><code>additional.fields [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_cid (string)</code></td>
<td><code>additional.fields [id_orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_source (string)</code></td>
<td><code>additional.fields [id_orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_status (string)</code></td>
<td><code>additional.fields [id_orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_uid (string)</code></td>
<td><code>additional.fields [id_orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_cid (string)</code></td>
<td><code>additional.fields [id_resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_source (string)</code></td>
<td><code>additional.fields [id_resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_status (string)</code></td>
<td><code>additional.fields [id_resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_uid (string)</code></td>
<td><code>additional.fields [id_resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>uids (array[string] - vector of string)</code></td>
<td><code>additional.fields [uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>count (integer - int)</code></td>
<td><code>additional.fields [count]</code></td>
<td></td>
</tr>
<tr>
<td><code>ts_last</code></td>
<td><code>additional.fields [ts_last]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - asset_classification</h3>

يسرد الجدول التالي حقول نوع السجل <code>asset_classification</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>STATUS_UPDATE</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>mac</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>vendor_mac (string)</code></td>
<td><code>about.asset.hardware.manufacturer</code></td>
<td></td>
</tr>
<tr>
<td><code>device_type (string)</code></td>
<td><code>about.asset.category</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.platform</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.asset.attribute.labels</code></td>
<td></td>
</tr>
<tr>
<td><code>type_group (string)</code></td>
<td><code>about.group.group_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>type_name (string)</code></td>
<td><code>about.resource.resource_subtype</code></td>
<td>The <code>about.resource.resource_type</code> UDM field is set to <code>DEVICE</code></td>
</tr>
<tr>
<td><code>brand (string)</code></td>
<td><code>about.user.company_name</code></td>
<td></td>
</tr>
<tr>
<td><code>model (string)</code></td>
<td><code>about.asset.hardware.model</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (integer)</code></td>
<td><code>about.security_result.confidence_score</code></td>
<td></td>
</tr>
<tr>
<td><code>os_ver (string)</code></td>
<td><code>about.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string])</code></td>
<td><code>about.ip_geo_artifact.tags</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - conn, conn_red, conn_long, conn_agg</h3>

يسرد الجدول التالي حقول نوع السجل <code>conn, conn_red, conn_long, conn_agg</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_bytes (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_bytes (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_state (string)</code></td>
<td><code>metadata.description</code></td>
<td>إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>S0</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>S0: Connection attempt seen, no reply</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>S1</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>S1: Connection established, not terminated</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>S2</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>S2: Connection established and close attempt by originator seen (but no reply from responder)</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>S3</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>S3: Connection established and close attempt by responder seen (but no reply from originator)</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>SF</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>SF: Normal SYN/FIN completion</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>REJ</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>REJ: Connection attempt rejected</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>RSTO</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>RSTO: Connection established, originator aborted (sent a RST)</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>RSTOS0</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>RSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>RSTOSH</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>RSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>RSTR</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>RSTR: Established, responder aborted</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>SH</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>SH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open)</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>SHR</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>SHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>conn_state</code> تساوي <code>OTH</code>، فسيتم تعيين حقل UDM <code>metadata.description</code> إلى <code>OTH: No SYN seen, just midstream traffic (a partial connection that was not later closed)</code>.</td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_resp (boolean - bool)</code></td>
<td><code>about.labels [local_resp]</code></td>
<td></td>
</tr>
<tr>
<td><code>missed_bytes (integer - count)</code></td>
<td><code>about.labels [missed_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>history (string)</code></td>
<td><code>about.labels [history]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_pkts (integer - count)</code></td>
<td><code>network.sent_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ip_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_pkts (integer - count)</code></td>
<td><code>network.received_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ip_bytes (integer - count)</code></td>
<td><code>target.labels [resp_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>tunnel_parents (array[string] - set[string])</code></td>
<td><code>intermediary.labels [tunnel_parent]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cc (string)</code></td>
<td><code>principal.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cc (string)</code></td>
<td><code>target.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_ids (array[string] - set[string])</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.url (string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.rule (integer - count)</code></td>
<td><code>security_result.rule_labels [spcap_rule]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.trigger (string)</code></td>
<td><code>security_result.detection_fields [spcap_trigger]</code></td>
<td></td>
</tr>
<tr>
<td><code>app (array[string] - vector of string)</code></td>
<td><code>about.application</code></td>
<td></td>
</tr>
<tr>
<td><code>corelight_shunted (boolean - bool)</code></td>
<td><code>about.labels [corelight_shunted]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_pkts (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_pkts (integer - count)</code></td>
<td><code>target.labels [resp_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_bytes (integer - count)</code></td>
<td><code>target.labels [resp_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_l2_addr (string)</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_l2_addr (string)</code></td>
<td><code>target.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.src (string)</code></td>
<td><code>principal.labels [id_orig_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.vals (array[string] - set[string])</code></td>
<td><code>principal.labels [id_orig_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.src (string)</code></td>
<td><code>target.labels [id_resp_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.vals (array[string] - set[string])</code></td>
<td><code>target.labels [id_resp_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>intermediary.labels [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>inner_vlan (integer - int)</code></td>
<td><code>intermediary.labels [inner_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_cid (string)</code></td>
<td><code>additional.fields [orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_source (string)</code></td>
<td><code>additional.fields [orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_status (string)</code></td>
<td><code>additional.fields [orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_uid (string)</code></td>
<td><code>additional.fields [orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_cid (string)</code></td>
<td><code>additional.fields [resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_source (string)</code></td>
<td><code>additional.fields [resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_status (string)</code></td>
<td><code>additional.fields [resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_uid (string)</code></td>
<td><code>additional.fields [resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>netskope_site_ids</code></td>
<td><code>additional.fields[netskope_site_ids]</code></td>
<td>قم بالتكرار عبر حقل السجل <code>netskope_site_ids</code>، ثم <br>يتم تعيين حقل السجل <code>netskope_site_id_%{index}</code> إلى حقل UDM <code>additional.fields.key</code> ويتم تعيين حقل السجل <code>netskope_site_id</code> إلى حقل UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>netskope_user_ids</code></td>
<td><code>additional.fields[netskope_user_ids]</code></td>
<td>قم بالتكرار عبر حقل السجل <code>netskope_user_ids</code>، ثم <br>يتم تعيين حقل السجل <code>netskope_user_id_%{index}</code> إلى حقل UDM <code>additional.fields.key</code> ويتم تعيين حقل السجل <code>netskope_user_id</code> إلى حقل UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>write_ts</code></td>
<td><code>additional.fields[write_ts]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.urls (array[string] - vector of string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td>قم بالتكرار عبر حقل السجل <code>spcap.urls</code>، ثم <br>يتم تعيين حقل السجل <code>spcap.urls</code> إلى حقل UDM <code>security_result.url_back_to_product</code>.<br></td>
</tr>
<tr>
<td><code>community_ids (array[string] - vector of string)</code></td>
<td><code>network.community_id</code></td>
<td>قم بالتكرار عبر حقل السجل <code>community_ids</code>، ثم<br> إذا كان الفهرس يساوي <code>0</code>، فسيتم تعيين حقل السجل <code>community_id</code> إلى حقل UDM <code>network.community_id</code>. <br> وإلا، فسيتم تعيين حقل السجل <code>community_id_%{index}</code> إلى حقل UDM <code>additional.fields.key</code> ويتم تعيين حقل السجل <code>community_id</code> إلى حقل UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.version</code></td>
<td><code>about.resource.attribute.labels[vpc_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.vpc_id</code></td>
<td><code>about.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>about.resource.resource_type</code></td>
<td>إذا كان <code>capture_metadata.vpc.vpc_id</code> موجودًا، فسيتم تعيين حقل UDM <code>about.resource.resource_type</code> إلى <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>capture_source</code></td>
<td><code>about.resource.attribute.labels[capture_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.az</code></td>
<td><code>principal.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.id</code></td>
<td><code>principal.resource.product_object_id</code></td>
<td></td>
</tr>

<tr>
<td><code>orig_inst.name</code></td>
<td><code>principal.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.org_id</code></td>
<td><code>principal.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.sg_ids</code></td>
<td><code>principal.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.subnet_id</code></td>
<td><code>principal.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.vpc_id</code></td>
<td><code>principal.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>principal.resource.resource_type</code></td>
<td>إذا كان <code>orig_inst.vpc_id</code> موجودًا، فسيتم تعيين حقل UDM <code>principal.resource.resource_type</code> إلى <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>orig_inst.profile</code></td>
<td><code>principal.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.az</code></td>
<td><code>target.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.id</code></td>
<td><code>target.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.name</code></td>
<td><code>target.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.org_id</code></td>
<td><code>target.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.sg_ids</code></td>
<td><code>target.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.subnet_id</code></td>
<td><code>target.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.vpc_id</code></td>
<td><code>target.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>target.resource.resource_type</code></td>
<td>إذا كان <code>resp_inst.vpc_id</code> موجودًا، فسيتم تعيين حقل UDM <code>target.resource.resource_type</code> إلى <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>resp_inst.profile</code></td>
<td><code>target.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig</code> و<code>local_resp</code></td>
<td><code>additional.fields[direction]</code></td>
<td>إذا كانت قيمة حقل السجل <code>local_orig</code> تساوي <code>true</code> وقيمة حقل السجل <code>local_resp</code> تساوي <code>true</code>، فسيتم تعيين حقل UDM <code>additional.fields[direction]</code> إلى <code>internal</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>local_orig</code> تساوي <code>true</code> وقيمة حقل السجل <code>local_resp</code> تساوي <code>false</code>، فسيتم تعيين حقل UDM <code>additional.fields[direction]</code> إلى <code>outbound</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>local_orig</code> تساوي <code>false</code> وقيمة حقل السجل <code>local_resp</code> تساوي <code>false</code>، فسيتم تعيين حقل UDM <code>additional.fields[direction]</code> إلى <code>external</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>local_orig</code> تساوي <code>false</code> وقيمة حقل السجل <code>local_resp</code> تساوي <code>true</code>، فسيتم تعيين حقل UDM <code>additional.fields[direction]</code> إلى <code>inbound</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - dce_rpc</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>dce_rpc</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>named_pipe (string)</code></td>
<td><code>intermediary.resource.name</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>intermediary.resource.resource_type</code></td>
<td>إذا كانت قيمة حقل السجل <code>named_pipe</code> <em>غير</em> فارغة، فسيتم تعيين حقل UDM <code>intermediary.resource.resource_type</code> إلى <code>PIPE</code>.</td>
</tr>
<tr>
<td><code>endpoint (string)</code></td>
<td><code>target.labels [endpoint]</code></td>
<td></td>
</tr>
<tr>
<td><code>operation (string)</code></td>
<td><code>target.labels [operation]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>DCERPC</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td><code>operation, endpoint, named_pipe (string)</code></td>
<td><code>metadata.description</code></td>
<td>يتم تعيين حقل UDM <code>metadata.description</code> باستخدام حقول السجل <code>operation</code> و<code>endpoint</code> و<code>named_pipe</code> بتنسيق "operation <code>operation</code> on <code>endpoint</code> using named pipe <code>named_pipe</code>".</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.ip_protocol</code> إلى <code>TCP</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - dns, dns_red, dns_agg</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>dns, dns_red, dns_agg</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_DNS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>DNS</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>trans_id (integer - count)</code></td>
<td><code>network.dns.id</code></td>
<td></td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>query (string)</code></td>
<td><code>network.dns.questions.name</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass (integer - count)</code></td>
<td><code>network.dns.questions.class</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass_name (string)</code></td>
<td><code>about.labels [qclass_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype (integer - count)</code></td>
<td><code>network.dns.questions.type</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype_name (string)</code></td>
<td><code>about.labels [qtype_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response</code></td>
<td>إذا كانت قيمة حقل السجل <code>rcode</code> *غير* فارغة، فسيتم تعيين حقل UDM <code>network.dns.response</code> إلى <code>true</code>.</td>
</tr>
<tr>
<td><code>rcode_name (string)</code></td>
<td><code>about.labels [rcode_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>AA (boolean - bool)</code></td>
<td><code>network.dns.authoritative</code></td>
<td></td>
</tr>
<tr>
<td><code>TC (boolean - bool)</code></td>
<td><code>network.dns.truncated</code></td>
<td></td>
</tr>
<tr>
<td><code>RD (boolean - bool)</code></td>
<td><code>network.dns.recursion_desired</code></td>
<td></td>
</tr>
<tr>
<td><code>RA (boolean - bool)</code></td>
<td><code>network.dns.recursion_available</code></td>
<td></td>
</tr>
<tr>
<td><code>Z (integer - count)</code></td>
<td><code>about.labels [Z]</code></td>
<td></td>
</tr>
<tr>
<td><code>answers (array[string] - vector of string)</code></td>
<td><code>network.dns.answers.name</code></td>
<td></td>
</tr>
<tr>
<td><code>TTLs (array[number] - vector of interval)</code></td>
<td><code>network.dns.answers.ttl</code></td>
<td></td>
</tr>
<tr>
<td><code>rejected (boolean - bool)</code></td>
<td><code>about.labels [rejected]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_trusted_domain (string)</code></td>
<td><code>about.labels [is_trusted_domain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_host_subdomain (string)</code></td>
<td><code>about.labels [icann_host_subdomain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_domain (string)</code></td>
<td><code>network.dns_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_tld (string)</code></td>
<td><code>about.labels [icann_tld]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>security_result.detection_fields [num]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - http, http_red, http2, http_agg</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>http, http_red, http2, http_agg</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_HTTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>network.http.method</code></td>
<td></td>
</tr>
<tr>
<td><code>host (string)</code></td>
<td><code>target.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>referrer (string)</code></td>
<td><code>network.http.referral_url</code></td>
<td></td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.application_protocol_version</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>network.http.user_agent</code></td>
<td></td>
</tr>
<tr>
<td><code>origin (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>network.http.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>about.labels [status_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_code (integer - count)</code></td>
<td><code>about.labels [info_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_msg (string)</code></td>
<td><code>about.labels [info_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>tags (array[string] - set[enum])</code></td>
<td><code>about.labels [tags]</code></td>
<td></td>
</tr>
<tr>
<td><code>username (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>password (string)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td></td>
</tr>
<tr>
<td><code>proxied (array[string] - set[string])</code></td>
<td><code>intermediary.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [orig_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_filenames (array[string] - vector of string)</code></td>
<td><code>src.file.names</code></td>
<td>يتم ربط حقل السجل <code>orig_filenames</code> بحقل UDM <code>src.file.names</code> عندما تكون قيمة الفهرس في <code>orig_filenames</code> مساوية لـ <code>0</code>. <br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ربط حقل السجل <code>orig_filenames</code> بـ <code>about.file.names</code>.
</td>
</tr>
<tr>
<td><code>orig_mime_types (array[string] - vector of string)</code></td>
<td><code>src.file.mime_type</code></td>
<td>يتم ربط حقل السجل <code>orig_mime_types</code> بحقل UDM <code>src.file.mime_type</code> عندما تكون قيمة الفهرس في <code>orig_mime_types</code> مساوية لـ <code>0</code>. <br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ربط حقل السجل <code>orig_mime_types</code> بـ <code>about.file.mime_type</code>.
</td>
</tr>
<tr>
<td><code>resp_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [resp_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_filenames (array[string] - vector of string)</code></td>
<td><code>target.file.names</code></td>
<td>يتم ربط حقل السجل <code>resp_filenames</code> بحقل UDM <code>target.file.names</code> عندما تكون قيمة الفهرس في <code>resp_filenames</code> مساوية لـ <code>0</code>. <br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ربط حقل السجل <code>resp_filenames</code> بـ <code>about.file.names</code>.
</td>
</tr>
<tr>
<td><code>resp_mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>يتم ربط حقل السجل <code>resp_mime_types</code> بحقل UDM <code>target.file.mime_type</code> عندما تكون قيمة الفهرس في <code>resp_mime_types</code> مساوية لـ <code>0</code>. <br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ربط حقل السجل <code>resp_mime_types</code> بـ <code>about.file.mime_type</code>.
</td>
</tr>
<tr>
<td><code>post_body (string)</code></td>
<td><code>about.labels [post_body]</code></td>
<td></td>
</tr>
<tr>
<td><code>stream_id (integer - count)</code></td>
<td><code>about.labels [stream_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>encoding (string)</code></td>
<td><code>about.labels [encoding]</code></td>
<td></td>
</tr>
<tr>
<td><code>push (boolean - bool)</code></td>
<td><code>about.labels [push]</code></td>
<td></td>
</tr>
<tr>
<td><code>versions (array[float] - vector of float)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>قم بالتكرار عبر حقل السجل <code>versions</code>، ثم<br> إذا كان الفهرس مساويًا لـ <code>0</code>، فسيتم ربط حقل السجل <code>version</code> بحقل UDM <code>network.application_protocol_version</code>. <br> وإلا، يتم ربط حقل السجل <code>version_%{index}</code> بحقل UDM <code>additional.fields.key</code> ويتم ربط حقل السجل <code>version</code> بحقل UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>user_agents (array[string] - vector of string)</code></td>
<td><code>network.http.user_agent</code></td>
<td>قم بالتكرار عبر حقل السجل <code>user_agents</code>، ثم<br> إذا كان الفهرس مساويًا لـ <code>0</code>، فسيتم ربط حقل السجل <code>user_agent</code> بحقل UDM <code>network.http.user_agent</code>. <br> وإلا، يتم ربط حقل السجل <code>user_agent_%{index}</code> بحقل UDM <code>additional.fields.key</code> ويتم ربط حقل السجل <code>user_agent</code> بحقل UDM <code>additional.fields.value</code>.<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - smtp_links</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>smtp_links</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>link (string)</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domain (string)</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - irc</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>irc</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>nick (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>user (string)</code></td>
<td><code>principal.user.userid</code></td>
<td>إذا كانت قيمة حقل السجل <code>user</code> أقل من أو تساوي 255، فسيتم ربط حقل السجل <code>user</code> بحقل UDM <code>principal.user.userid</code>.<br><br>وإلا، يتم ربط حقل السجل <code>user</code> بحقل UDM <code>about.labels</code>.</td>
</tr>
<tr>
<td><code>command, value, addl</code></td>
<td><code>principal.process.command_line</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_size (integer - count)</code></td>
<td><code>src.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_mime_type (string)</code></td>
<td><code>src.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - files, files_red, files_agg</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>files, files_red, files_agg</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_hosts (array[string] - set[addr])</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>rx_hosts (array[string] - set[addr])</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_uids (array[string] - set[string])</code></td>
<td><code>about.labels [conn_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>source (string)</code></td>
<td><code>about.labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>depth (integer - count)</code></td>
<td><code>about.labels [depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>analyzers (array[string] - set[string])</code></td>
<td><code>about.labels [analyzer]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_type (string)</code></td>
<td><code>about.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>filename (string)</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>about.labels [duration]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_orig (boolean - bool)</code></td>
<td><code>about.labels [is_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen_bytes (integer - count)</code></td>
<td><code>about.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>total_bytes (integer - count)</code></td>
<td><code>about.labels [total_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>missing_bytes (integer - count)</code></td>
<td><code>about.labels [missing_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>overflow_bytes (integer - count)</code></td>
<td><code>about.labels [overflow_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>timedout (boolean - bool)</code></td>
<td><code>about.labels [timedout]</code></td>
<td></td>
</tr>
<tr>
<td><code>parent_fuid (string)</code></td>
<td><code>about.labels [parent_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>about.file.md5</code></td>
<td></td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>about.file.sha1</code></td>
<td></td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>about.file.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.client.certificate.md5</code></td>
<td>إذا كانت قيمة حقل السجل <code>source</code> تساوي <code>ssl</code> وقيمة حقل السجل <code>mime_type</code> تساوي <code>application/x-x509-user-cert</code> وقيمة حقل السجل <code>_path</code> تساوي <code>files</code>، فسيتم تعيين حقل UDM <code>network.tls.client.certificate.md5</code> إلى <code>md5</code>.</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.client.certificate.sha1</code></td>
<td>إذا كانت قيمة حقل السجل <code>source</code> تساوي <code>ssl</code> وقيمة حقل السجل <code>mime_type</code> تساوي <code>application/x-x509-user-cert</code> وقيمة حقل السجل <code>_path</code> تساوي <code>files</code>، فسيتم تعيين حقل UDM <code>network.tls.client.certificate.sha1</code> إلى <code>sha1</code>.</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.client.certificate.sha256</code></td>
<td>إذا كانت قيمة حقل السجل <code>source</code> تساوي <code>ssl</code> وقيمة حقل السجل <code>mime_type</code> تساوي <code>application/x-x509-user-cert</code> وقيمة حقل السجل <code>_path</code> تساوي <code>files</code>، فسيتم تعيين حقل UDM <code>network.tls.client.certificate.sha256</code> إلى <code>sha256</code>.</td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.server.certificate.md5</code></td>
<td>إذا كانت قيمة حقل السجل <code>source</code> تساوي <code>ssl</code> وقيمة حقل السجل <code>mime_type</code> تساوي <code>application/x-x509-ca-cert</code> وقيمة حقل السجل <code>_path</code> تساوي <code>files</code>، فسيتم تعيين حقل UDM <code>network.tls.server.certificate.md5</code> إلى <code>md5</code>.</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.server.certificate.sha1</code></td>
<td>إذا كانت قيمة حقل السجل <code>source</code> تساوي <code>ssl</code> وقيمة حقل السجل <code>mime_type</code> تساوي <code>application/x-x509-ca-cert</code> وقيمة حقل السجل <code>_path</code> تساوي <code>files</code>، فسيتم تعيين حقل UDM <code>network.tls.server.certificate.sha1</code> إلى <code>sha1</code>.</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td>إذا كانت قيمة حقل السجل <code>source</code> تساوي <code>ssl</code> وقيمة حقل السجل <code>mime_type</code> تساوي <code>application/x-x509-ca-cert</code> وقيمة حقل السجل <code>_path</code> تساوي <code>files</code>، فسيتم تعيين حقل UDM <code>network.tls.server.certificate.sha256</code> إلى <code>sha256</code>.</td>
</tr>
<tr>
<td><code>extracted (array[string] - set[string])</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_cutoff (boolean - bool)</code></td>
<td><code>about.labels [extracted_cutoff]</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_size (integer - count)</code></td>
<td><code>about.labels [extracted_size]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>about.labels [num]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>additional.fields [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan_inner (integer - int)</code></td>
<td><code>additional.fields [vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>قم بالتكرار عبر حقل السجل <code>mime_type</code>، ثم<br> إذا كان الفهرس يساوي <code>0</code>، فسيتم تعيين حقل السجل <code>mime_type</code> إلى حقل UDM <code>target.file.mime_type</code>. <br> وإلا، يتم تعيين حقل السجل <code>mime_type_%{index}</code> إلى حقل UDM <code>additional.fields.key</code> ويتم تعيين حقل السجل <code>mime_type</code> إلى حقل UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>timedouts (array[boolean] - vector of bool)</code></td>
<td><code>additional.fields[timedouts]</code></td>
<td>قم بالتكرار عبر حقل السجل <code>timedouts</code>، ثم <br>يتم تعيين حقل السجل <code>timedout_%{index}</code> إلى حقل UDM <code>additional.fields.key</code> ويتم تعيين حقل السجل <code>timedouts</code> إلى حقل UDM <code>additional.fields.value</code>.<br></td>
</tr>

</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - notice</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>notice</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>target.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>about.labels [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>note (string - enum)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>msg (string)</code></td>
<td><code>metadata.description</code></td>
<td></td>
</tr>
<tr>
<td><code>sub (string)</code></td>
<td><code>about.labels [sub]</code></td>
<td></td>
</tr>
<tr>
<td><code>src (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>dst (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>p (integer - port)</code></td>
<td><code>about.port</code></td>
<td></td>
</tr>
<tr>
<td><code>n (integer - count)</code></td>
<td><code>about.labels [n]</code></td>
<td></td>
</tr>
<tr>
<td><code>peer_descr (string)</code></td>
<td><code>about.labels [peer_descr]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.action </code></td>
<td>يتم تعيين حقل UDM <code>security_result.action</code> إلى <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>actions (array[string] - set[enum])</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>suppress_for (number - interval)</code></td>
<td><code>about.labels [suppress_for]</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>يتم تعيين حقل UDM <code>about.location.country_or_region</code> باستخدام حقلي السجل <code>remote_location.country_code</code> و<code>remote_location.region</code> بالشكل "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>يتم تعيين حقل UDM <code>about.location.country_or_region</code> باستخدام حقلي السجل <code>remote_location.country_code</code> و<code>remote_location.region</code> بالشكل "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>about.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>about.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>about.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>إذا كانت قيمة حقل السجل <code>severity.level</code> تحتوي إحدى القيم التالية<div style='margin-top: -0.8em;'></div><ul><li><code>0</code></li><li><code> 1</code></li></ul><div style='margin-top: -0.8em;'></div>، فسيتم تعيين حقل UDM <code>  security_result.severity </code> إلى <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة حقل السجل <code>severity.level</code> تساوي <code> 2 </code>، فسيتم تعيين حقل UDM <code>  security_result.severity </code> إلى <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة حقل السجل <code>severity.level</code> تساوي <code> 3 </code>، فسيتم تعيين حقل UDM <code>  security_result.severity </code> إلى <code>ERROR</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة حقل السجل <code>severity.level</code> تحتوي إحدى القيم التالية<div style='margin-top: -0.8em;'></div><ul><li><code>4</code></li><li><code>5</code></li><li><code>6</code></li></ul><div style='margin-top: -0.8em;'></div>، فسيتم تعيين حقل UDM <code>  security_result.severity </code> إلى <code>INFORMATIONAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة حقل السجل <code>severity.level</code> تساوي <code> 7 </code>، فسيتم تعيين حقل UDM <code>  security_result.severity </code> إلى <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا يتم تعيين حقل UDM <code>  security_result.severity </code> إلى <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>severity.name</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>severity.level</code></td>
<td><code>security_result.detection_fields [severity_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>إذا كانت <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Critical" or the <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "4 </code>" </code>، فسيتم تعيين <code> "target.asset.vulnerabilities.severity" </code> إلى <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)High" or the <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "3 </code>" </code>، فسيتم تعيين <code> "target.asset.vulnerabilities.severity" </code> إلى <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Low" or the <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "1 </code>" </code>، فسيتم تعيين <code> "target.asset.vulnerabilities.severity" </code> إلى <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Medium" or the <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "2 </code>" </code>، فسيتم تعيين <code> "target.asset.vulnerabilities.severity" </code> إلى <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Unknown_Severity" </code> أو كانت <code>resp_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "0 </code>"، فسيتم تعيين <code> "target.asset.vulnerabilities.severity" </code> إلى <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname (string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain (string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version (string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>إذا كانت <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Critical" or the <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "4 </code>" </code>، فسيتم تعيين <code> "principal.asset.vulnerabilities.severity" </code> إلى <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)High" or the <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "3 </code>" </code>، فسيتم تعيين <code> "principal.asset.vulnerabilities.severity" </code> إلى <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Low" or the <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "1 </code>" </code>، فسيتم تعيين <code> "principal.asset.vulnerabilities.severity" </code> إلى <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Medium" or the <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "2 </code>" </code>، فسيتم تعيين <code> "principal.asset.vulnerabilities.severity" </code> إلى <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تطابق نمط التعبير النمطي <code> "(?i)Unknown_Severity" </code> أو كانت <code>orig_vulnerable_host.criticality</code> قيمة حقل السجل تساوي <code> "0 </code>"، فسيتم تعيين <code> "principal.asset.vulnerabilities.severity" </code> إلى <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname (string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain (string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version (string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source (string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - smb_files</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>smb_files</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_READ</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_READ</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_WRITE</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_MODIFICATION</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_OPEN</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_OPEN</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_CLOSE</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_UNCATEGORIZED</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_DELETE</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_DELETION</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_RENAME</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_MOVE</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>action</code> تساوي <code>SMB::FILE_SET_ATTRIBUTE</code>، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_UNCATEGORIZED</code>.<br><br>وإلا، فسيتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>FILE_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>SMB</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.ip_protocol</code> إلى <code>TCP</code>.</td>
</tr>
<tr>
<td><code>action, name</code></td>
<td><code>metadata.description</code></td>
<td>يتم تعيين حقل UDM <code>metadata.description</code> باستخدام حقلي السجل <code>action</code> و<code>name</code> بصيغة "action: <code>action</code> on: <code>name</code>".</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>يتم تعيين حقل UDM <code>security_result.action</code> إلى <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>action (string - enum)</code></td>
<td><code>target.labels [action]</code></td>
<td></td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.file.full_path</code></td>
<td></td>
</tr>
<tr>
<td><code>name (string)</code></td>
<td><code>target.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>size (integer - count)</code></td>
<td><code>target.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>prev_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>times.modified (time)</code></td>
<td><code>target.file.last_modification_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.accessed (time)</code></td>
<td><code>target.file.last_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.created (time)</code></td>
<td><code>target.file.first_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.changed (time)</code></td>
<td><code>target.labels [times_changed]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_offset_req (integer - count)</code></td>
<td><code>target.labels [data_offset_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_req (integer - count)</code></td>
<td><code>target.labels [data_len_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_rsp (integer - count)</code></td>
<td><code>target.labels [data_len_rsp]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - smb_mapping</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>smb_mapping</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>SMB</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.ip_protocol</code> إلى <code>TCP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>يتم تعيين حقل UDM <code>security_result.action</code> إلى <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.resource.attribute.labels [path]</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>target.application</code></td>
<td></td>
</tr>
<tr>
<td><code>native_file_system (string)</code></td>
<td><code>target.resource.attribute.labels [native_file_system]</code></td>
<td></td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_type</code></td>
<td>إذا كانت قيمة حقل السجل <code>share_type</code> تساوي <code>DISK</code>، فسيتم تعيين حقل UDM <code>target.resource.resource_type</code> إلى <code>STORAGE_OBJECT</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>share_type</code> تساوي <code>PIPE</code>، فسيتم تعيين حقل UDM <code>target.resource.resource_type</code> إلى <code>PIPE</code>.<br><br>وإلا، فسيتم تعيين حقل UDM <code>target.resource.resource_type</code> إلى <code>UNSPECIFIED</code>.</td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_subtype</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - ssl, ssl_red, ssl_agg</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>ssl, ssl_red, ssl_agg</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>HTTPS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.ip_protocol</code> إلى <code>TCP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>يتم تعيين حقل UDM <code>security_result.action</code> إلى <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.tls.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>curve (string)</code></td>
<td><code>network.tls.curve</code></td>
<td></td>
</tr>
<tr>
<td><code>server_name (string)</code></td>
<td><code>network.tls.client.server_name</code></td>
<td></td>
</tr>
<tr>
<td><code>resumed (boolean - bool)</code></td>
<td><code>network.tls.resumed</code></td>
<td></td>
</tr>
<tr>
<td><code>last_alert (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>next_protocol (string)</code></td>
<td><code>network.tls.next_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>established (boolean - bool)</code></td>
<td><code>network.tls.established</code></td>
<td></td>
</tr>
<tr>
<td><code>ssl_history (string)</code></td>
<td><code>about.labels [ssl_history]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>target.labels [cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>principal.labels [client_cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>sni_matches_cert (boolean - bool)</code></td>
<td><code>about.labels [sni_matches_cert]</code></td>
<td></td>
</tr>
<tr>
<td><code>validation_status (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3 (string)</code></td>
<td><code>network.tls.client.ja3</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3s (string)</code></td>
<td><code>network.tls.server.ja3s</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - rdp</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>rdp</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>cookie (string)</code></td>
<td><code>principal.user.userid</code></td>
<td></td>
</tr>
<tr>
<td><code>result (string)</code></td>
<td><code>about.labels [result]</code></td>
<td></td>
</tr>
<tr>
<td><code>security_protocol (string)</code></td>
<td><code>target.labels [security_protocol]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_channels (array[string] - vector of string)</code></td>
<td><code>intermediary.labels [client_channels]</code></td>
<td></td>
</tr>
<tr>
<td><code>keyboard_layout (string)</code></td>
<td><code>principal.labels [keyboard_layout]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_build (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>client_name (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>client_dig_product_id (string)</code></td>
<td><code>principal.asset.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_width (integer - count)</code></td>
<td><code>principal.labels [desktop_width]</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_height (integer - count)</code></td>
<td><code>principal.labels [desktop_height]</code></td>
<td></td>
</tr>
<tr>
<td><code>requested_color_depth (string)</code></td>
<td><code>principal.labels [requested_color_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_type (string)</code></td>
<td><code>about.labels [cert_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_count (integer - count)</code></td>
<td><code>about.labels [cert_count]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_permanent (boolean - bool)</code></td>
<td><code>about.labels [cert_permanent ]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_level (string)</code></td>
<td><code>about.labels [encryption_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_method (string)</code></td>
<td><code>about.labels [encryption_method]</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>إذا كانت قيمة حقل السجل <code>auth_success</code> تساوي <code>true</code>، فسيتم تعيين حقل UDM <code>security_result.action</code> إلى <code>ALLOW</code>. <br> وإلا، فسيتم تعيين حقل UDM <code>security_result.action</code> إلى <code>FAIL</code>.</td>
</tr>
<tr>
<td><code>channels_joined (integer - int)</code></td>
<td><code>intermediary.labels [channels_joined]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>about.labels [inferences]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdpeudp_uid (string)</code></td>
<td><code>about.labels [rdpeudp_uid]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.ip_protocol</code> إلى <code>TCP</code>.</td>
</tr>
<tr>
<td><code>rdfp_string (string)</code></td>
<td><code>principal.labels [rdfp_string]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdfp_hash (string)</code></td>
<td><code>principal.labels [rdfp_hash]</code></td>
<td></td>
</tr>
<tr>
<td><code>result, security_protocol</code></td>
<td><code>security_result.description</code></td>
<td>يتم تعيين حقل UDM <code>security_result.description</code> باستخدام حقلي السجل <code>result</code> و<code>security_protocol</code> بصيغة "<code>result</code> connection with security protocol <code>security_protocol</code>".</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - sip</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>sip</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>SIP</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>about.labels [method]</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_from (string)</code></td>
<td><code>principal.labels [request_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_to (string)</code></td>
<td><code>target.labels [request_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_from</code></td>
<td><code>principal.labels [response_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_to (string)</code></td>
<td><code>target.labels [response_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>about.labels [reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>call_id (string)</code></td>
<td><code>about.labels[call_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>seq (string)</code></td>
<td><code>about.labels [seq]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>about.labels [subject]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_path (array[string] - vector of string)</code></td>
<td><code>about.labels [request_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_path (array[string] - vector of string)</code></td>
<td><code>about.labels [response_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>about.labels [user_agent]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>about.labels [status_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>warning (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>content_type (string)</code></td>
<td><code>about.labels [content_type]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - intel</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>intel</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>حقل <code>metadata.event_type</code> في UDM مضبوط على <code>SCAN_NETWORK</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>حقل <code>metadata.product_name</code> في UDM مضبوط على <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.metadata.entity_type</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::ADDR</code>، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>IP_ADDRESS</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::SUBNET</code> أو <code>Intel::SOFTWARE</code> أو <code>Intel::CERT_HASH</code> أو <code>Intel::PUBKEY_HASH</code>، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>RESOURCE</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::URL</code>، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>URL</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::EMAIL</code> أو <code>Intel::USER_NAME</code>، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>USER</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::DOMAIN</code>، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>DOMAIN_NAME</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::FILE_HASH</code> أو <code>Intel::FILE_NAME</code>، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>FILE</code>.<br><br>وإلا، فسيتم ضبط حقل <code>metadata.entity_type</code> في UDM على <code>RESOURCE</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.ip</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::ADDR</code>، فسيتم تعيين حقل السجل <code>seen.indicator</code> إلى حقل UDM <code>entity.ip</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.url</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::URL</code>، فسيتم تعيين حقل السجل <code>seen.indicator</code> إلى حقل UDM <code>entity.url</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.domain.name</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::DOMAIN</code>، فسيتم تعيين حقل السجل <code>seen.indicator</code> إلى حقل UDM <code>entity.domain.name</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.user.email_address</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::USER_NAME</code> أو <code>Intel::EMAIL</code>، فسيتم تعيين حقل السجل <code>seen.indicator</code> إلى حقل UDM <code>entity.user.email_address</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.file.names</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::FILE_HASH</code> أو <code>Intel::FILE_NAME</code>، فسيتم تعيين حقل السجل <code>seen.indicator</code> إلى حقل UDM <code>entity.file.full_path</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.resource.name</code></td>
<td>إذا كانت قيمة حقل السجل <code>metadata.entity_type</code> تساوي <code>RESOURCE</code>، فسيتم تعيين حقل السجل <code>seen.indicator</code> إلى حقل UDM <code>entity.resource.name</code>.</td>
</tr>
<tr>
<td></td>
<td><code>entity.resource.resource_type</code></td>
<td>إذا كانت قيمة حقل السجل <code>indicator.type</code> تساوي <code>Intel::SUBNET</code>، فسيتم ضبط حقل UDM <code>entity.resource.resource_name</code> على <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.resource.resource_sub_type</code></td>
<td>إذا كانت قيمة حقل السجل <code>metadata.entity_type</code> تساوي <code>RESOURCE</code>، فسيتم تعيين حقل السجل <code>seen.indicator_type</code> إلى حقل UDM <code>entity.resource.resource_sub_type</code>.</td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>entity.metadata.source_labels [seen_where]</code></td>
<td></td>
</tr>
<tr>
<td><code>matched (array[string] - set[enum])</code></td>
<td><code>entity.labels [matched]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>entity.metadata.source_labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>entity.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>metadata.threat.detection_fields [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>desc (array[string] - set[string])</code></td>
<td><code>ioc.description</code></td>
<td>يتم تعيين حقل السجل <code>desc</code> إلى حقل UDM <code>ioc.description</code> عندما تكون قيمة الفهرس في <code>desc</code> تساوي <code>0</code>.
<br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ضبط حقل UDM <code>entity.labels.key</code> على <code>desc</code> ويتم تعيين حقل السجل <code>desc</code> إلى <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>url (array[string] - set[string])</code></td>
<td><code>metadata.threat.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>ioc.confidence_score</code></td>
<td>يتم تعيين حقل السجل <code>confidence</code> إلى حقل UDM <code>ioc.confidence_score</code> عندما تكون قيمة الفهرس في <code>confidence</code> تساوي <code>0</code>.
<br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ضبط حقل UDM <code>entity.labels.key</code> على <code>confidence</code> ويتم تعيين حقل السجل <code>confidence</code> إلى <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>firstseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.start</code></td>
<td>يتم تعيين حقل السجل <code>firstseen</code> إلى حقل UDM <code>ioc.active_timerange.start</code> عندما تكون قيمة الفهرس في <code>firstseen</code> تساوي <code>0</code>.
<br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ضبط حقل UDM <code>entity.labels.key</code> على <code>firstseen</code> ويتم تعيين حقل السجل <code>firstseen</code> إلى <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>lastseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.end</code></td>
<td>يتم تعيين حقل السجل <code>lastseen</code> إلى حقل UDM <code>ioc.active_timerange.end</code> عندما تكون قيمة الفهرس في <code>lastseen</code> تساوي <code>0</code>.
<br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ضبط حقل UDM <code>entity.labels.key</code> على <code>lastseen</code> ويتم تعيين حقل السجل <code>lastseen</code> إلى <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>associated (array[string] - set[string])</code></td>
<td><code>entity.labels [associated]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>ioc.categorization</code></td>
<td>يتم تعيين حقل السجل <code>category</code> إلى حقل UDM <code>ioc.categorization</code> عندما تكون قيمة الفهرس في <code>category</code> تساوي <code>0</code>.
<br><br>بالنسبة لأي قيمة فهرس أخرى، يتم ضبط حقل UDM <code>entity.labels.key</code> على <code>category</code> ويتم تعيين حقل السجل <code>category</code> إلى <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>campaigns (array[string] - set[string])</code></td>
<td><code>entity.labels [campaign]</code></td>
<td></td>
</tr>
<tr>
<td><code>reports (array[string] - set[string])</code></td>
<td><code>entity.labels [report]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>about.labels [indicator]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>about.labels [indicator_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>about.labels [where]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>about.labels [sources]</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>about.labels [confidence]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>about.labels [category]</code></td>
<td></td>
</tr>
<tr>
<td><code>threat_score (array[number] - set[double])</code></td>
<td><code>entity.security_result.detection_fields[threat_score]</code></td>
<td></td>
</tr>
<tr>
<td><code>verdict (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.verdict_response</code></td>
<td>قم بالتكرار عبر <code>verdict</code>,<div style='margin-bottom: 0.5em;'></div><div style='margin-bottom: 0.0em;'></div>إذا كانت قيمة حقل السجل <code>verdict</code> تطابق نمط التعبير النمطي <code> "(?i)Malicious" أو كانت قيمة حقل السجل <code>verdict</code> تساوي <code> "1" </code> </code>، فسيتم ضبط حقل UDM <code>        "entity.security_result.verdict_info.verdict_response" </code> على <code>MALICIOUS</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة حقل السجل <code>verdict</code> تطابق نمط التعبير النمطي <code> "(?i)Benign" أو كانت قيمة حقل السجل <code>verdict</code> تساوي <code> "2" </code> </code>، فسيتم ضبط حقل UDM <code>        "entity.security_result.verdict_info.verdict_response" </code> على <code>BENIGN</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، فسيتم ضبط حقل UDM <code>        "entity.security_result.verdict_info.verdict_response" </code> على <code>VERDICT_RESPONSE_UNSPECIFIED</code>. <br></td>
</tr>
<tr>
<td><code>verdict_source (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.source_provider</code></td>
<td>قم بالتكرار عبر <code>verdict_source</code>,<div style='margin-bottom: 0.5em;'></div>يتم تعيين حقل السجل <code>verdict_source</code> إلى حقل UDM <code>    entity.security_result.VerdictInfo.source_provider </code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - smtp</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>smtp</code> وحقول UDM المقابلة لها.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>حقل <code>metadata.event_type</code> في UDM مضبوط على <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>حقل <code>metadata.product_name</code> في UDM مضبوط على <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>حقل <code>network.application_protocol</code> في UDM مضبوط على <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>helo (string)</code></td>
<td><code>network.smtp.helo</code></td>
<td></td>
</tr>
<tr>
<td><code>mailfrom (string)</code></td>
<td><code>network.smtp.mail_from</code></td>
<td></td>
</tr>
<tr>
<td><code>rcptto (array[string] - set[string])</code></td>
<td><code>network.smtp.rcpt_to</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>from (string)</code></td>
<td><code>network.email.from</code></td>
<td></td>
</tr>
<tr>
<td><code>to (array[string] - set[string])</code></td>
<td><code>network.email.to</code></td>
<td></td>
</tr>
<tr>
<td><code>cc (array[string] - set[string])</code></td>
<td><code>network.email.cc</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>network.email.reply_to</code></td>
<td></td>
</tr>
<tr>
<td><code>msg_id (string)</code></td>
<td><code>network.email.mail_id</code></td>
<td></td>
</tr>
<tr>
<td><code>in_reply_to (string)</code></td>
<td><code>about.labels [in_reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>network.email.subject</code></td>
<td></td>
</tr>
<tr>
<td><code>x_originating_ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>first_received (string)</code></td>
<td><code>about.labels [first_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>second_received (string)</code></td>
<td><code>about.labels [second_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>last_reply (string)</code></td>
<td><code>network.smtp.server_response</code></td>
<td></td>
</tr>
<tr>
<td><code>path (array[string] - vector of addr)</code></td>
<td><code>network.smtp.message_path</code></td>
<td>قم بالتكرار عبر حقل السجل <code>path</code>, ثم<br> إذا كانت قيمة <code>index</code> تساوي <code>0</code>، فسيتم تعيين حقل السجل <code>path</code> إلى حقل UDM <code>network.smtp.message_path</code>. <br> وإلا، فسيتم تعيين حقل السجل <code>path</code> إلى حقل UDM <code>intermediary.ip</code>.<br></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>principal.application</code></td>
<td></td>
</tr>
<tr>
<td><code>tls (boolean - bool)</code></td>
<td><code>network.smtp.is_tls</code></td>
<td></td>
</tr>
<tr>
<td><code>fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_webmail (boolean - bool)</code></td>
<td><code>network.smtp.is_webmail</code></td>
<td></td>
</tr>
<tr>
<td><code>urls (array[string] - set[string])</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domains (array[string] - set[string])</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - ssh</h3>

يسرد الجدول التالي حقول السجل لنوع السجل <code>ssh</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة رئيسية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol</code> إلى <code>SSH</code>.</td>
</tr>
<tr>
<td><code>version (integer - count)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>يتم تعيين حقل UDM <code>network.application_protocol_version</code> باستخدام حقل السجل <code>version</code> بصيغة "SSH <code>version</code>".</td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>إذا كانت قيمة حقل السجل <code>auth_success</code> <em>لا</em> تساوي <code>true</code>، فسيتم تعيين حقل UDM <code>security_result.action</code> إلى <code>ALLOW</code>.<br><br>وإلا، فسيتم تعيين حقل UDM <code>security_result.action</code> إلى <code>BLOCK</code>.</td>
</tr>
<tr>
<td><code>auth_attempts (integer - count)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td>يتم تعيين حقل UDM <code>extensions.auth.auth_details</code> باستخدام حقل السجل <code>auth_attempts</code> بصيغة "auth_attempts: <code>auth_attempts</code>".</td>
</tr>
<tr>
<td><code>direction (string - enum)</code></td>
<td><code>network.direction</code></td>
<td>إذا كانت قيمة حقل السجل <code>direction</code> تساوي <code>INBOUND</code>، فسيتم تعيين حقل UDM <code>network.direction</code> إلى <code>INBOUND</code>.<br><br>وإلا، إذا كانت قيمة حقل السجل <code>direction</code> تساوي <code>OUTBOUND</code>، فسيتم تعيين حقل UDM <code>network.direction</code> إلى <code>OUTBOUND</code>.</td>
</tr>
<tr>
<td><code>client (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>server (string)</code></td>
<td><code>target.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher_alg (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>mac_alg (string)</code></td>
<td><code>security_result.detection_fields [mac_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>compression_alg (string)</code></td>
<td><code>security_result.detection_fields [compression_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>kex_alg (string)</code></td>
<td><code>security_result.detection_fields [kex_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key_alg (string)</code></td>
<td><code>network.tls.server.certificate.version</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>target.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>target.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>target.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshVersion (string)</code></td>
<td><code>about.labels [hassh_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>hassh (string)</code></td>
<td><code>principal.labels [hassh]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServer (string)</code></td>
<td><code>target.labels [hassh_server]</code></td>
<td></td>
</tr>
<tr>
<td><code>cshka (string)</code></td>
<td><code>about.labels [cshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshAlgorithms (string)</code></td>
<td><code>about.labels [hassh_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>sshka (string)</code></td>
<td><code>about.labels [sshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServerAlgorithms (string)</code></td>
<td><code>about.labels [hassh_server_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>security_result.summary, security_result.description, security_result.detection_fields[inferences]</code></td>
<td>إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>ABP</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Client Authentication Bypass</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A client wasn't adhering to expectations of SSH either through server exploit or by the client and server switching to a protocol other than SSH after encryption begins</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>AFR</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>SSH Agent Forwarding Requested</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>Agent Forwarding is requested by the Client</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>APWA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Automated Password Authentication</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client authenticated with an automated password tool (like sshpass)</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>AUTO</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Automated Interaction</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client is a script automated utility and not driven by a user</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>BAN</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Server Banner</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The server sent the client a pre-authentication banner, likely for legal reasons</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>BF</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Client Brute Force Guessing</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>BFS</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Client Brute Force Success</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>CTS</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Client Trusted Server</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client already has an entry in its known_hosts file for this server</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>CUS</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Client Untrusted Server</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client did not have an entry in its known_hosts file for this server</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>IPWA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Interactive Password Authentication</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client interactively typed their password to authenticate</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>KS</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Keystrokes</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>An interactive session occurred in which the client set user-driven keystrokes to the server</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>LFD</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Large Client File Download</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>LFU</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Large Client File Upload</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A file transfer occurred in which the client sent a sequence of bytes to the server. Large file are identified dynamically based on trains of MTU-sized packets</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>MFA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Multifactor Authentication</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The server required a second form of authentication (a code) after password or public key was accepted, and the client successfully provided it</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>NA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>None Authentication</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client successfully authenticated using the None method</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>NRC</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>No Remote Command</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The -N flag was used in SSH authentication</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>PKA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Public Key Authentication</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client automatically authenticated using pubkey authentication</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>RSI</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Reverse SSH Initiated</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The Reverse session is initiated from the server back to the client</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>RSIA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Reverse SSH Initiated Automated</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The inititation of the Reverse session happened very early in the packet stream, indicating automation</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>RSK</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Reverse SSH Keystrokes</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>Keystrokes are detected within the Reverse tunnel</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>RSL</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Reverse SSH Logged In</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The Reverse Tunnel login has succeeded</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>RSP</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Reverse SSH Provisioned</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client connected with -R flag, which provisions the port to be used for a Reverse Session set up at any future time</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>SA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Authentication Scanning</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client scanned authentication method with the server and then disconnected</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>SC</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Capabilities Scanning</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The client exchanged capabilities with the server and then disconnected</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>SFD</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Small Client File Download</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>SFU</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Small Client File Upload</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A file transfer occurred in which the client sent a sequence of bytes to the server</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>SP</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Other Scanning</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A client and server didn't exchange encrypted packets but the client wasn't a version or capabilities scanner</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>SV</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Version Scanning</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>A client exchanged version strings with the server and than disconnected</code>.<br><br>
إذا كانت قيمة حقل السجل <code>inferences</code> تساوي <code>UA</code>، فسيتم تعيين حقل UDM <code>security_result.summary</code> إلى <code>Unknown Authentication</code>، وسيتم تعيين حقل UDM <code>security_result.description</code> إلى <code>The authentication method is not determinated or is unknown</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>مرجع تعيين الحقول: CORELIGHT - suricata_corelight</h3>

يسرد الجدول التالي حقول السجل الخاصة بنوع السجل <code>suricata_corelight</code> وحقول UDM المقابلة لها.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="اكتب كلمة مفتاحية للعثور على قيمة.">
<table class="fixed">
<thead>
<tr>
<th>حقل السجل</th>
<th>تعيين UDM</th>
<th>المنطق</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td> يتم تعيين حقل UDM <code>metadata.event_type</code> إلى <code>SCAN_NETWORK</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td> يتم تعيين حقل UDM <code>metadata.product_name</code> إلى <code>Suricata</code>.</td>
</tr>
<tr>
<td><code>id.vlan (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_type (integer - count)</code></td>
<td><code>about.labels [icmp_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_code (integer - count)</code></td>
<td><code>about.labels [icmp_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_id (string)</code></td>
<td><code>metadata.product_log_id</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>flow_id (integer - count)</code></td>
<td><code>about.labels[flow_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_id (integer - count)</code></td>
<td><code>about.labels [tx_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>pcap_cnt (integer - count)</code></td>
<td><code>about.labels [pcap_cnt]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.action (string)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.gid (integer - count)</code></td>
<td><code>security_result.detection_fields [alert_gid]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature_id (integer - count)</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rev (integer - count)</code></td>
<td><code>security_result.rule_version</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.rule_name</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.category (string)</code></td>
<td><code>security_result.category_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.severity (integer - count)</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[alert_metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload]</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>signature_severity</code></td>
<td><code>security_result.severity</code></td>
<td> إذا تطابقت قيمة حقل السجل <code>alert.rule</code> مع نمط grok <code>signature_severity (?<signature_severity>Critical|Major|Minor|Informational)</code> عندها <div style='margin-bottom: 0.0em;'></div>إذا كانت قيمة الحقل المستخرج <code>signature_severity</code> مساوية لـ <code>Critical</code> عندها، يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>CRITICAL</code> ويتم تعيين الحقل المستخرج <code>signature_severity</code> إلى حقل UDM <code>security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة الحقل المستخرج <code>signature_severity</code> مساوية لـ <code>Major</code> عندها، يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>MEDIUM</code> ويتم تعيين الحقل المستخرج <code>signature_severity</code> إلى حقل UDM <code> security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة الحقل المستخرج <code>signature_severity</code> مساوية لـ <code>Minor</code> عندها، يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>LOW</code> ويتم تعيين الحقل المستخرج <code>signature_severity</code> إلى حقل UDM <code>security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>وإلا، إذا كانت قيمة الحقل المستخرج <code>signature_severity</code> مساوية لـ <code>Informational</code> عندها، يتم تعيين حقل UDM <code>security_result.severity</code> إلى <code>INFORMATIONAL</code> ويتم تعيين الحقل المستخرج <code>signature_severity</code> إلى حقل UDM <code>security_result.severity_details</code>.<br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname(string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain(string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version(string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source(string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname(string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain(string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version(string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rule (string)</code></td>

Read more

تنزيل الأداة