
CORELIGHT और संबंधित जानकारी के लिए Chronicle पार्सर
यह दस्तावेज़ बताता है कि आप Corelight सेंसर और Chronicle फॉरवर्डर को कॉन्फ़िगर करके Corelight सेंसर लॉग कैसे एकत्र कर सकते हैं। यह दस्तावेज़ समर्थित लॉग प्रकारों और समर्थित Corelight संस्करणों की सूची भी देता है।
अधिक जानकारी के लिए, देखें Chronicle में डेटा इन्जेशन।
निम्नलिखित डिप्लॉयमेंट आर्किटेक्चर आरेख दर्शाता है कि Corelight सेंसर को दो अलग-अलग इन्जेशन आर्किटेक्चर का उपयोग करके Google Security Operations को लॉग भेजने के लिए कैसे सेट किया जाता है। यह ध्यान रखना महत्वपूर्ण है कि प्रत्येक ग्राहक का डिप्लॉयमेंट इस प्रतिनिधित्व से भिन्न हो सकता है और अधिक जटिल हो सकता है।
एक इन्जेशन लेबल उस पार्सर की पहचान करता है जो रॉ लॉग डेटा को संरचित UDM प्रारूप में सामान्यीकृत करता है। इस दस्तावेज़ की जानकारी CORELIGHT इन्जेशन लेबल वाले पार्सर पर लागू होती है।

आर्किटेक्चर आरेख निम्नलिखित घटकों को दर्शाता है:
Corelight सेंसर: वह सिस्टम जो Corelight सेंसर चला रहा है।
Corelight सेंसर एक्सपोर्टर्स: Corelight सेंसर एक्सपोर्टर सेंसर से लॉग डेटा एकत्र करता है, और उसे Google Security Operations को अग्रेषित करता है।
Google Security Operations: Google Security Operations Corelight सेंसर से लॉग को बनाए रखता है और उनका विश्लेषण करता है।
Google SecOps एक्सपोर्टर को कॉन्फ़िगर करने के लिए Sensor या Fleet Manager वेब इंटरफ़ेस का उपयोग करें। यह कॉन्फ़िगरेशन सुरक्षित कनेक्शन स्थापित करने के लिए आपके Google SecOps इंस्टेंस की API क्रेडेंशियल्स का उपयोग करता है।
Corelight सेंसर के Fleet Manager या Sensor वेब इंटरफ़ेस में व्यवस्थापक के रूप में लॉग इन करें।
एक्सपोर्टर कॉन्फ़िगरेशन क्षेत्र पर नेविगेट करें:
Create Exporter अनुभाग में, Google SecOps पर क्लिक करें।




आर्किटेक्चर आरेख निम्नलिखित घटकों को दर्शाता है:
Corelight सेंसर: वह सिस्टम जो Corelight सेंसर चला रहा है।
Corelight सेंसर एक्सपोर्टर: Corelight सेंसर एक्सपोर्टर सेंसर से लॉग डेटा एकत्र करता है, और उसे Google Security Operations फॉरवर्डर को अग्रेषित करता है।
Google Security Operations फॉरवर्डर: Google Security Operations फॉरवर्डर एक हल्का सॉफ़्टवेयर घटक है, जो ग्राहक के नेटवर्क में तैनात किया जाता है, और जो syslog का समर्थन करता है। Google Security Operations फॉरवर्डर लॉग को Google Security Operations को अग्रेषित करता है।
Google Security Operations: Google Security Operations Corelight सेंसर से लॉग को बनाए रखता है और उनका विश्लेषण करता है। ```none collectors:
### Corelight सेंसर एक्सपोर्टर कॉन्फ़िगर करें
1. Corelight सेंसर में एक व्यवस्थापक के रूप में लॉग इन करें।
2. **Export** टैब चुनें।
3. **EXPORT TO SYSLOG** विकल्प खोजें और सक्षम करें।
4. **EXPORT TO SYSLOG** के अंतर्गत, निम्न फ़ील्ड कॉन्फ़िगर करें:
* **SYSLOG SERVER**: Google Security Operations फ़ॉरवर्डर syslog श्रोता का IP पता और पोर्ट निर्दिष्ट करें।
* **Advanced Settings > SYSLOG FORMAT** पर जाएं और सेटिंग को **Legacy** में बदलें।

5. **Apply Changes** पर क्लिक करें।
## समर्थित Corelight लॉग प्रकार
Corelight पार्सर निम्नलिखित लॉग प्रकारों का समर्थन करता है:
<div class="fixed" translate="no">
<h4>Log Type</h4>
<ul>
<li>asset_classification</li>
<li>conn</li>
<li>conn_long</li>
<li>conn_red</li>
<li>conn_agg</li>
<li>dce_rpc</li>
<li>dns</li>
<li>dns_red</li>
<li>files</li>
<li>files_red</li>
<li>http</li>
<li>http2</li>
<li>http_red</li>
<li>intel</li>
<li>irc</li>
<li>notice</li>
<li>rdp</li>
<li>sip</li>
<li>smb_files</li>
<li>smb_mapping</li>
<li>smtp</li>
<li>smtp_links</li>
<li>ssh</li>
<li>ssl</li>
<li>ssl_red</li>
<li>suricata_corelight</li>
<li>bacnet</li>
<li>cip</li>
<li>corelight_burst</li>
<li>corelight_metrics_bro</li>
<li>corelight_metrics_disk</li>
<li>corelight_metrics_iface</li>
<li>corelight_metrics_memory</li>
<li>corelight_metrics_system</li>
<li>corelight_metrics_zeek_doctor</li>
<li>corelight_overall_capture_loss</li>
<li>corelight_profiling</li>
<li>datared</li>
<li>dga</li>
<li>dhcp</li>
<li>dnp3</li>
<li>dpd</li>
<li>encrypted_dns</li>
<li>enip</li>
<li>enip_debug</li>
<li>enip_list_identity</li>
<li>etc_viz</li>
<li>ftp</li>
<li>generic_dns_tunnels</li>
<li>generic_icmp_tunnels</li>
<li>icmp_specific_tunnels</li>
<li>ipsec</li>
<li>iso_cotp</li>
<li>kerberos</li>
<li>known_certs</li>
<li>known_devices</li>
<li>known_domains</li>
<li>known_hosts</li>
<li>known_names</li>
<li>known_remotes</li>
<li>known_services</li>
<li>known_users</li>
<li>ldap</li>
<li>ldap_search</li>
<li>local_subnets</li>
<li>local_subnets_dj</li>
<li>local_subnets_graphs</li>
<li>log4shell</li>
<li>modbus</li>
<li>mqtt_connect</li>
<li>mqtt_publish</li>
<li>mqtt_subscribe</li>
<li>mysql</li>
<li>napatech_shunting</li>
<li>ntlm</li>
<li>ntp</li>
<li>pe</li>
<li>profinet</li>
<li>profinet_dce_rpc</li>
<li>profinet_debug</li>
<li>radius</li>
<li>reporter</li>
<li>rfb</li>
<li>s7comm</li>
<li>smartpcap</li>
<li>snmp</li>
<li>socks</li>
<li>software</li>
<li>specific_dns_tunnels</li>
<li>stepping</li>
<li>stun</li>
<li>stun_nat</li>
<li>suricata_eve</li>
<li>suricata_stats</li>
<li>syslog</li>
<li>tds</li>
<li>tds_rpc</li>
<li>tds_sql_batch</li>
<li>traceroute</li>
<li>tunnel</li>
<li>unknown-smartpcap</li>
<li>vpn</li>
<li>weird</li>
<li>weird_red</li>
<li>wireguard</li>
<li>x509</li>
<li>x509_red</li>
<li>dns_agg</li>
<li>files_agg</li>
<li>http_agg</li>
<li>ssl_agg</li>
<li>weird_agg</li>
<li>analyzer</li>
<li>anomaly</li>
<li>ssdp</li>
<li>telnet</li>
<li>websocket</li>
<li>first_seen</li>
</ul>
</div>
## फ़ील्ड मैपिंग संदर्भ
यह अनुभाग बताता है कि Google Security Operations पार्सर Google Security Operations फ़ील्ड को Google Security Operations यूनिफाइड डेटा मॉडल (UDM) फ़ील्ड में कैसे मैप करता है।
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - सामान्य फ़ील्ड </h3>
निम्न तालिका <code>CORELIGHT</code> लॉग के सामान्य फ़ील्ड और उनके संबंधित UDM फ़ील्ड को सूचीबद्ध करती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.vendor_name</code></td>
<td>The <code>metadata.vendor_name</code> UDM field is set to <code>Corelight</code>.</td>
</tr>
<tr>
<td><code>_path (string)</code></td>
<td><code>metadata.product_event_type</code></td>
<td></td>
</tr>
<tr>
<td><code>_system_name (string)</code></td>
<td><code>observer.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>ts (time)</code></td>
<td><code>metadata.event_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>uid (string)</code></td>
<td><code>about.labels [uid], network.session_id</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_h (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_p (integer - port)</code></td>
<td><code>principal.port</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_h (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_p (integer - port)</code></td>
<td><code>target.port</code></td>
<td></td>
</tr>
<tr>
<td><code>_write_ts</code></td><code></code>
<td><code>metadata.collected_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan (integer - int)</code></td>
<td><code>additional.fields [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - int)</code></td>
<td><code>additional.fields [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_cid (string)</code></td>
<td><code>additional.fields [id_orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_source (string)</code></td>
<td><code>additional.fields [id_orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_status (string)</code></td>
<td><code>additional.fields [id_orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_uid (string)</code></td>
<td><code>additional.fields [id_orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_cid (string)</code></td>
<td><code>additional.fields [id_resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_source (string)</code></td>
<td><code>additional.fields [id_resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_status (string)</code></td>
<td><code>additional.fields [id_resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_uid (string)</code></td>
<td><code>additional.fields [id_resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>uids (array[string] - vector of string)</code></td>
<td><code>additional.fields [uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>count (integer - int)</code></td>
<td><code>additional.fields [count]</code></td>
<td></td>
</tr>
<tr>
<td><code>ts_last</code></td>
<td><code>additional.fields [ts_last]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - asset_classification</h3>
निम्न तालिका <code>asset_classification</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड को सूचीबद्ध करती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>STATUS_UPDATE</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>mac</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>vendor_mac (string)</code></td>
<td><code>about.asset.hardware.manufacturer</code></td>
<td></td>
</tr>
<tr>
<td><code>device_type (string)</code></td>
<td><code>about.asset.category</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.platform</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.asset.attribute.labels</code></td>
<td></td>
</tr>
<tr>
<td><code>type_group (string)</code></td>
<td><code>about.group.group_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>type_name (string)</code></td>
<td><code>about.resource.resource_subtype</code></td>
<td>The <code>about.resource.resource_type</code> UDM field is set to <code>DEVICE</code></td>
</tr>
<tr>
<td><code>brand (string)</code></td>
<td><code>about.user.company_name</code></td>
<td></td>
</tr>
<tr>
<td><code>model (string)</code></td>
<td><code>about.asset.hardware.model</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (integer)</code></td>
<td><code>about.security_result.confidence_score</code></td>
<td></td>
</tr>
<tr>
<td><code>os_ver (string)</code></td>
<td><code>about.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string])</code></td>
<td><code>about.ip_geo_artifact.tags</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - conn, conn_red, conn_long, conn_agg</h3>
निम्न तालिका <code>conn, conn_red, conn_long, conn_agg</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड को सूचीबद्ध करती है।<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_CONNECTION</code> पर सेट है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट है।</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_bytes (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_bytes (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_state (string)</code></td>
<td><code>metadata.description</code></td>
<td>यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>S0</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>S0: Connection attempt seen, no reply</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>S1</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>S1: Connection established, not terminated</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>S2</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>S2: Connection established and close attempt by originator seen (but no reply from responder)</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>S3</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>S3: Connection established and close attempt by responder seen (but no reply from originator)</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>SF</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>SF: Normal SYN/FIN completion</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>REJ</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>REJ: Connection attempt rejected</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>RSTO</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>RSTO: Connection established, originator aborted (sent a RST)</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>RSTOS0</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>RSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>RSTOSH</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>RSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>RSTR</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>RSTR: Established, responder aborted</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>SH</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>SH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open)</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>SHR</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>SHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>conn_state</code> लॉग फ़ील्ड का मान <code>OTH</code> के बराबर है, तो <code>metadata.description</code> UDM फ़ील्ड <code>OTH: No SYN seen, just midstream traffic (a partial connection that was not later closed)</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_resp (boolean - bool)</code></td>
<td><code>about.labels [local_resp]</code></td>
<td></td>
</tr>
<tr>
<td><code>missed_bytes (integer - count)</code></td>
<td><code>about.labels [missed_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>history (string)</code></td>
<td><code>about.labels [history]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_pkts (integer - count)</code></td>
<td><code>network.sent_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ip_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_pkts (integer - count)</code></td>
<td><code>network.received_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ip_bytes (integer - count)</code></td>
<td><code>target.labels [resp_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>tunnel_parents (array[string] - set[string])</code></td>
<td><code>intermediary.labels [tunnel_parent]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cc (string)</code></td>
<td><code>principal.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cc (string)</code></td>
<td><code>target.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_ids (array[string] - set[string])</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.url (string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.rule (integer - count)</code></td>
<td><code>security_result.rule_labels [spcap_rule]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.trigger (string)</code></td>
<td><code>security_result.detection_fields [spcap_trigger]</code></td>
<td></td>
</tr>
<tr>
<td><code>app (array[string] - vector of string)</code></td>
<td><code>about.application</code></td>
<td></td>
</tr>
<tr>
<td><code>corelight_shunted (boolean - bool)</code></td>
<td><code>about.labels [corelight_shunted]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_pkts (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_pkts (integer - count)</code></td>
<td><code>target.labels [resp_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_bytes (integer - count)</code></td>
<td><code>target.labels [resp_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_l2_addr (string)</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_l2_addr (string)</code></td>
<td><code>target.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.src (string)</code></td>
<td><code>principal.labels [id_orig_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.vals (array[string] - set[string])</code></td>
<td><code>principal.labels [id_orig_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.src (string)</code></td>
<td><code>target.labels [id_resp_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.vals (array[string] - set[string])</code></td>
<td><code>target.labels [id_resp_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>intermediary.labels [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>inner_vlan (integer - int)</code></td>
<td><code>intermediary.labels [inner_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM फ़ील्ड <code>INFORMATIONAL</code> पर सेट है।</td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_cid (string)</code></td>
<td><code>additional.fields [orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_source (string)</code></td>
<td><code>additional.fields [orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_status (string)</code></td>
<td><code>additional.fields [orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_uid (string)</code></td>
<td><code>additional.fields [orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_cid (string)</code></td>
<td><code>additional.fields [resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_source (string)</code></td>
<td><code>additional.fields [resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_status (string)</code></td>
<td><code>additional.fields [resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_uid (string)</code></td>
<td><code>additional.fields [resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>netskope_site_ids</code></td>
<td><code>additional.fields[netskope_site_ids]</code></td>
<td>लॉग फ़ील्ड <code>netskope_site_ids</code> को पुनरावृत्त करें, फिर <br><code>netskope_site_id_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में मैप किया जाता है और <code>netskope_site_id</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>netskope_user_ids</code></td>
<td><code>additional.fields[netskope_user_ids]</code></td>
<td>लॉग फ़ील्ड <code>netskope_user_ids</code> को पुनरावृत्त करें, फिर <br><code>netskope_user_id_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में मैप किया जाता है और <code>netskope_user_id</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>write_ts</code></td>
<td><code>additional.fields[write_ts]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.urls (array[string] - vector of string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td>लॉग फ़ील्ड <code>spcap.urls</code> को पुनरावृत्त करें, फिर <br><code>spcap.urls</code> लॉग फ़ील्ड को <code>security_result.url_back_to_product</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>community_ids (array[string] - vector of string)</code></td>
<td><code>network.community_id</code></td>
<td>लॉग फ़ील्ड <code>community_ids</code> को पुनरावृत्त करें, फिर<br> यदि इंडेक्स <code>0</code> के बराबर है, तो <code>community_id</code> लॉग फ़ील्ड को <code>network.community_id</code> UDM फ़ील्ड में मैप किया जाता है। <br> अन्यथा, <code>community_id_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में मैप किया जाता है और <code>community_id</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.version</code></td>
<td><code>about.resource.attribute.labels[vpc_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.vpc_id</code></td>
<td><code>about.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>about.resource.resource_type</code></td>
<td>यदि <code>capture_metadata.vpc.vpc_id</code> मौजूद है, तो <code>about.resource.resource_type</code> UDM फ़ील्ड <code>VPC_NETWORK</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>capture_source</code></td>
<td><code>about.resource.attribute.labels[capture_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.az</code></td>
<td><code>principal.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.id</code></td>
<td><code>principal.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.name</code></td>
<td><code>principal.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.org_id</code></td>
<td><code>principal.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.sg_ids</code></td>
<td><code>principal.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.subnet_id</code></td>
<td><code>principal.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.vpc_id</code></td>
<td><code>principal.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>principal.resource.resource_type</code></td>
<td>यदि <code>orig_inst.vpc_id</code> मौजूद है, तो <code>principal.resource.resource_type</code> UDM फ़ील्ड <code>VPC_NETWORK</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>orig_inst.profile</code></td>
<td><code>principal.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.az</code></td>
<td><code>target.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.id</code></td>
<td><code>target.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.name</code></td>
<td><code>target.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.org_id</code></td>
<td><code>target.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.sg_ids</code></td>
<td><code>target.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.subnet_id</code></td>
<td><code>target.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.vpc_id</code></td>
<td><code>target.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>target.resource.resource_type</code></td>
<td>यदि <code>resp_inst.vpc_id</code> मौजूद है, तो <code>target.resource.resource_type</code> UDM फ़ील्ड <code>VPC_NETWORK</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>resp_inst.profile</code></td>
<td><code>target.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig</code> and <code>local_resp</code></td>
<td><code>additional.fields[direction]</code></td>
<td>यदि <code>local_orig</code> लॉग फ़ील्ड का मान <code>true</code> के बराबर है और <code>local_resp</code> लॉग फ़ील्ड का मान <code>true</code> के बराबर है, तो <code>additional.fields[direction]</code> UDM फ़ील्ड <code>internal</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>local_orig</code> लॉग फ़ील्ड का मान <code>true</code> के बराबर है और <code>local_resp</code> लॉग फ़ील्ड का मान <code>false</code> के बराबर है, तो <code>additional.fields[direction]</code> UDM फ़ील्ड <code>outbound</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>local_orig</code> लॉग फ़ील्ड का मान <code>false</code> के बराबर है और <code>local_resp</code> लॉग फ़ील्ड का मान <code>false</code> के बराबर है, तो <code>additional.fields[direction]</code> UDM फ़ील्ड <code>external</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>local_orig</code> लॉग फ़ील्ड का मान <code>false</code> के बराबर है और <code>local_resp</code> लॉग फ़ील्ड का मान <code>true</code> के बराबर है, तो <code>additional.fields[direction]</code> UDM फ़ील्ड <code>inbound</code> पर सेट होता है।</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - dce_rpc</h3>
निम्न तालिका <code>dce_rpc</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संगत UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_CONNECTION</code> पर सेट है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट है।</td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>named_pipe (string)</code></td>
<td><code>intermediary.resource.name</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>intermediary.resource.resource_type</code></td>
<td>यदि <code>named_pipe</code> लॉग फ़ील्ड का मान <em>नहीं</em> खाली है, तो <code>intermediary.resource.resource_type</code> UDM फ़ील्ड <code>PIPE</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>endpoint (string)</code></td>
<td><code>target.labels [endpoint]</code></td>
<td></td>
</tr>
<tr>
<td><code>operation (string)</code></td>
<td><code>target.labels [operation]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड <code>DCERPC</code> पर सेट है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM फ़ील्ड <code>INFORMATIONAL</code> पर सेट है।</td>
</tr>
<tr>
<td><code>operation, endpoint, named_pipe (string)</code></td>
<td><code>metadata.description</code></td>
<td><code>metadata.description</code> UDM फ़ील्ड को <code>operation</code>, <code>endpoint</code>, <code>named_pipe</code> लॉग फ़ील्ड के साथ "ऑपरेशन <code>operation</code> एन्डपॉइंट <code>endpoint</code> पर नेम्ड पाइप <code>named_pipe</code> का उपयोग करते हुए" के रूप में सेट किया जाता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM फ़ील्ड <code>TCP</code> पर सेट है।</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - dns, dns_red, dns_agg</h3>
निम्न तालिका <code>dns, dns_red, dns_agg</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संगत UDM फ़ील्ड की सूची देती है।<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>NETWORK_DNS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>The <code>network.application_protocol</code> UDM field is set to <code>DNS</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>trans_id (integer - count)</code></td>
<td><code>network.dns.id</code></td>
<td></td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>query (string)</code></td>
<td><code>network.dns.questions.name</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass (integer - count)</code></td>
<td><code>network.dns.questions.class</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass_name (string)</code></td>
<td><code>about.labels [qclass_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype (integer - count)</code></td>
<td><code>network.dns.questions.type</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype_name (string)</code></td>
<td><code>about.labels [qtype_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response</code></td>
<td>यदि <code>rcode</code> लॉग फ़ील्ड का मान <em>खाली नहीं</em> है, तो <code>network.dns.response</code> UDM फ़ील्ड को <code>true</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>rcode_name (string)</code></td>
<td><code>about.labels [rcode_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>AA (boolean - bool)</code></td>
<td><code>network.dns.authoritative</code></td>
<td></td>
</tr>
<tr>
<td><code>TC (boolean - bool)</code></td>
<td><code>network.dns.truncated</code></td>
<td></td>
</tr>
<tr>
<td><code>RD (boolean - bool)</code></td>
<td><code>network.dns.recursion_desired</code></td>
<td></td>
</tr>
<tr>
<td><code>RA (boolean - bool)</code></td>
<td><code>network.dns.recursion_available</code></td>
<td></td>
</tr>
<tr>
<td><code>Z (integer - count)</code></td>
<td><code>about.labels [Z]</code></td>
<td></td>
</tr>
<tr>
<td><code>answers (array[string] - vector of string)</code></td>
<td><code>network.dns.answers.name</code></td>
<td></td>
</tr>
<tr>
<td><code>TTLs (array[number] - vector of interval)</code></td>
<td><code>network.dns.answers.ttl</code></td>
<td></td>
</tr>
<tr>
<td><code>rejected (boolean - bool)</code></td>
<td><code>about.labels [rejected]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_trusted_domain (string)</code></td>
<td><code>about.labels [is_trusted_domain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_host_subdomain (string)</code></td>
<td><code>about.labels [icann_host_subdomain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_domain (string)</code></td>
<td><code>network.dns_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_tld (string)</code></td>
<td><code>about.labels [icann_tld]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>security_result.detection_fields [num]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - http, http_red, http2, http_agg</h3>
निम्न तालिका <code>http, http_red, http2, http_agg</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड को सूचीबद्ध करती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>NETWORK_HTTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>network.http.method</code></td>
<td></td>
</tr>
<tr>
<td><code>host (string)</code></td>
<td><code>target.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>referrer (string)</code></td>
<td><code>network.http.referral_url</code></td>
<td></td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.application_protocol_version</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>network.http.user_agent</code></td>
<td></td>
</tr>
<tr>
<td><code>origin (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>network.http.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>about.labels [status_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_code (integer - count)</code></td>
<td><code>about.labels [info_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_msg (string)</code></td>
<td><code>about.labels [info_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>tags (array[string] - set[enum])</code></td>
<td><code>about.labels [tags]</code></td>
<td></td>
</tr>
<tr>
<td><code>username (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>password (string)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td></td>
</tr>
<tr>
<td><code>proxied (array[string] - set[string])</code></td>
<td><code>intermediary.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [orig_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_filenames (array[string] - vector of string)</code></td>
<td><code>src.file.names</code></td>
<td><code>orig_filenames</code> लॉग फ़ील्ड को <code>src.file.names</code> UDM फ़ील्ड में मैप किया जाता है, जब <code>orig_filenames</code> में इंडेक्स मान <code>0</code> के बराबर होता है। <br><br>अन्य प्रत्येक इंडेक्स मान के लिए, <code>orig_filenames</code> लॉग फ़ील्ड को <code>about.file.names</code> में मैप किया जाता है।
</td>
</tr>
<tr>
<td><code>orig_mime_types (array[string] - vector of string)</code></td>
<td><code>src.file.mime_type</code></td>
<td><code>orig_mime_types</code> लॉग फ़ील्ड को <code>src.file.mime_type</code> UDM फ़ील्ड में मैप किया जाता है, जब <code>orig_mime_types</code> में इंडेक्स मान <code>0</code> के बराबर होता है। <br><br>अन्य प्रत्येक इंडेक्स मान के लिए, <code>orig_mime_types</code> लॉग फ़ील्ड को <code>about.file.mime_type</code> में मैप किया जाता है।
</td>
</tr>
<tr>
<td><code>resp_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [resp_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_filenames (array[string] - vector of string)</code></td>
<td><code>target.file.names</code></td>
<td><code>resp_filenames</code> लॉग फ़ील्ड को <code>target.file.names</code> UDM फ़ील्ड में मैप किया जाता है, जब <code>resp_filenames</code> में इंडेक्स मान <code>0</code> के बराबर होता है। <br><br>अन्य प्रत्येक इंडेक्स मान के लिए, <code>resp_filenames</code> लॉग फ़ील्ड को <code>about.file.names</code> में मैप किया जाता है।
</td>
</tr>
<tr>
<td><code>resp_mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td><code>resp_mime_types</code> लॉग फ़ील्ड को <code>target.file.mime_type</code> UDM फ़ील्ड में मैप किया जाता है, जब <code>resp_mime_types</code> में इंडेक्स मान <code>0</code> के बराबर होता है। <br><br>अन्य प्रत्येक इंडेक्स मान के लिए, <code>resp_mime_types</code> लॉग फ़ील्ड को <code>about.file.mime_type</code> में मैप किया जाता है।
</td>
</tr>
<tr>
<td><code>post_body (string)</code></td>
<td><code>about.labels [post_body]</code></td>
<td></td>
</tr>
<tr>
<td><code>stream_id (integer - count)</code></td>
<td><code>about.labels [stream_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>encoding (string)</code></td>
<td><code>about.labels [encoding]</code></td>
<td></td>
</tr>
<tr>
<td><code>push (boolean - bool)</code></td>
<td><code>about.labels [push]</code></td>
<td></td>
</tr>
<tr>
<td><code>versions (array[float] - vector of float)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>लॉग फ़ील्ड <code>versions</code> में पुनरावृत्ति करें, फिर<br> यदि index <code>0</code> के बराबर है, तो <code>version</code> लॉग फ़ील्ड को <code>network.application_protocol_version</code> UDM फ़ील्ड में मैप किया जाता है। <br> अन्यथा, <code>version_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में और <code>version</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>user_agents (array[string] - vector of string)</code></td>
<td><code>network.http.user_agent</code></td>
<td>लॉग फ़ील्ड <code>user_agents</code> में पुनरावृत्ति करें, फिर<br> यदि index <code>0</code> के बराबर है, तो <code>user_agent</code> लॉग फ़ील्ड को <code>network.http.user_agent</code> UDM फ़ील्ड में मैप किया जाता है। <br> अन्यथा, <code>user_agent_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में और <code>user_agent</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - smtp_links</h3>
निम्न तालिका <code>smtp_links</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड को सूचीबद्ध करती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>The <code>network.application_protocol</code> UDM field is set to <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>link (string)</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domain (string)</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - irc</h3>
निम्न तालिका <code>irc</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड को सूचीबद्ध करती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>nick (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>user (string)</code></td>
<td><code>principal.user.userid</code></td>
<td>यदि <code>user</code> लॉग फ़ील्ड का मान 255 से कम या उसके बराबर है, तो <code>user</code> लॉग फ़ील्ड को <code>principal.user.userid</code> UDM फ़ील्ड में मैप किया जाता है।<br><br>अन्यथा, <code>user</code> लॉग फ़ील्ड को <code>about.labels</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>command, value, addl</code></td>
<td><code>principal.process.command_line</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_size (integer - count)</code></td>
<td><code>src.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_mime_type (string)</code></td>
<td><code>src.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - files, files_red, files_agg</h3><div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="मान खोजने के लिए कोई कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_hosts (array[string] - set[addr])</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>rx_hosts (array[string] - set[addr])</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_uids (array[string] - set[string])</code></td>
<td><code>about.labels [conn_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>source (string)</code></td>
<td><code>about.labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>depth (integer - count)</code></td>
<td><code>about.labels [depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>analyzers (array[string] - set[string])</code></td>
<td><code>about.labels [analyzer]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_type (string)</code></td>
<td><code>about.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>filename (string)</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>about.labels [duration]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_orig (boolean - bool)</code></td>
<td><code>about.labels [is_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen_bytes (integer - count)</code></td>
<td><code>about.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>total_bytes (integer - count)</code></td>
<td><code>about.labels [total_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>missing_bytes (integer - count)</code></td>
<td><code>about.labels [missing_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>overflow_bytes (integer - count)</code></td>
<td><code>about.labels [overflow_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>timedout (boolean - bool)</code></td>
<td><code>about.labels [timedout]</code></td>
<td></td>
</tr>
<tr>
<td><code>parent_fuid (string)</code></td>
<td><code>about.labels [parent_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>about.file.md5</code></td>
<td></td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>about.file.sha1</code></td>
<td></td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>about.file.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.client.certificate.md5</code></td>
<td>यदि <code>source</code> लॉग फ़ील्ड का मान <code>ssl</code> के बराबर है और <code>mime_type</code> लॉग फ़ील्ड का मान <code>application/x-x509-user-cert</code> के बराबर है और <code>_path</code> लॉग फ़ील्ड का मान <code>files</code> के बराबर है, तो <code>network.tls.client.certificate.md5</code> UDM फ़ील्ड को <code>md5</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.client.certificate.sha1</code></td>
<td>यदि <code>source</code> लॉग फ़ील्ड का मान <code>ssl</code> के बराबर है और <code>mime_type</code> लॉग फ़ील्ड का मान <code>application/x-x509-user-cert</code> के बराबर है और <code>_path</code> लॉग फ़ील्ड का मान <code>files</code> के बराबर है, तो <code>network.tls.client.certificate.sha1</code> UDM फ़ील्ड को <code>sha1</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.client.certificate.sha256</code></td>
<td>यदि <code>source</code> लॉग फ़ील्ड का मान <code>ssl</code> के बराबर है और <code>mime_type</code> लॉग फ़ील्ड का मान <code>application/x-x509-user-cert</code> के बराबर है और <code>_path</code> लॉग फ़ील्ड का मान <code>files</code> के बराबर है, तो <code>network.tls.client.certificate.sha256</code> UDM फ़ील्ड को <code>sha256</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.server.certificate.md5</code></td>
<td>यदि <code>source</code> लॉग फ़ील्ड का मान <code>ssl</code> के बराबर है और <code>mime_type</code> लॉग फ़ील्ड का मान <code>application/x-x509-ca-cert</code> के बराबर है और <code>_path</code> लॉग फ़ील्ड का मान <code>files</code> के बराबर है, तो <code>network.tls.server.certificate.md5</code> UDM फ़ील्ड को <code>md5</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.server.certificate.sha1</code></td>
<td>यदि <code>source</code> लॉग फ़ील्ड का मान <code>ssl</code> के बराबर है और <code>mime_type</code> लॉग फ़ील्ड का मान <code>application/x-x509-ca-cert</code> के बराबर है और <code>_path</code> लॉग फ़ील्ड का मान <code>files</code> के बराबर है, तो <code>network.tls.server.certificate.sha1</code> UDM फ़ील्ड को <code>sha1</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td>यदि <code>source</code> लॉग फ़ील्ड का मान <code>ssl</code> के बराबर है और <code>mime_type</code> लॉग फ़ील्ड का मान <code>application/x-x509-ca-cert</code> के बराबर है और <code>_path</code> लॉग फ़ील्ड का मान <code>files</code> के बराबर है, तो <code>network.tls.server.certificate.sha256</code> UDM फ़ील्ड को <code>sha256</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>extracted (array[string] - set[string])</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_cutoff (boolean - bool)</code></td>
<td><code>about.labels [extracted_cutoff]</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_size (integer - count)</code></td>
<td><code>about.labels [extracted_size]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>about.labels [num]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>additional.fields [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan_inner (integer - int)</code></td>
<td><code>additional.fields [vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td><code>mime_type</code> लॉग फ़ील्ड में पुनरावृत्ति करें, फिर<br> यदि इंडेक्स <code>0</code> के बराबर है, तो <code>mime_type</code> लॉग फ़ील्ड को <code>target.file.mime_type</code> UDM फ़ील्ड में मैप किया जाता है। <br> अन्यथा, <code>mime_type_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में और <code>mime_type</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>timedouts (array[boolean] - vector of bool)</code></td>
<td><code>additional.fields[timedouts]</code></td>
<td><code>timedouts</code> लॉग फ़ील्ड में पुनरावृत्ति करें, फिर <br><code>timedout_%{index}</code> लॉग फ़ील्ड को <code>additional.fields.key</code> UDM फ़ील्ड में और <code>timedouts</code> लॉग फ़ील्ड को <code>additional.fields.value</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - notice</h3>
निम्न तालिका <code>notice</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="मान खोजने के लिए कोई कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>target.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>about.labels [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>note (string - enum)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>msg (string)</code></td>
<td><code>metadata.description</code></td>
<td></td>
</tr>
<tr>
<td><code>sub (string)</code></td>
<td><code>about.labels [sub]</code></td>
<td></td>
</tr>
<tr>
<td><code>src (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>dst (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>p (integer - port)</code></td>
<td><code>about.port</code></td>
<td></td>
</tr>
<tr>
<td><code>n (integer - count)</code></td>
<td><code>about.labels [n]</code></td>
<td></td>
</tr>
<tr>
<td><code>peer_descr (string)</code></td>
<td><code>about.labels [peer_descr]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.action </code></td>
<td>The <code>security_result.action</code> UDM field is set to <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>actions (array[string] - set[enum])</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>suppress_for (number - interval)</code></td>
<td><code>about.labels [suppress_for]</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>The <code>about.location.country_or_region</code> UDM field is set with <code>remote_location.country_code</code>, <code>remote_location.region</code> log fields as "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>The <code>about.location.country_or_region</code> UDM field is set with <code>remote_location.country_code</code>, <code>remote_location.region</code> log fields as "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>about.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>about.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>about.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>यदि <code>severity.level</code> लॉग फ़ील्ड का मान निम्न मानों में से एक रखता है<div style='margin-top: -0.8em;'></div><ul><li><code>0</code></li><li><code> 1</code></li></ul><div style='margin-top: -0.8em;'></div> तो, <code> security_result.severity </code> UDM फ़ील्ड को <code>HIGH</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>severity.level</code> लॉग फ़ील्ड का मान <code> 2 </code> के बराबर है तो, <code> security_result.severity </code> UDM फ़ील्ड को <code>CRITICAL</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>severity.level</code> लॉग फ़ील्ड का मान <code> 3 </code> के बराबर है तो, <code> security_result.severity </code> UDM फ़ील्ड को <code>ERROR</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>severity.level</code> लॉग फ़ील्ड का मान निम्न मानों में से एक रखता है<div style='margin-top: -0.8em;'></div><ul><li><code>4</code></li><li><code>5</code></li><li><code>6</code></li></ul><div style='margin-top: -0.8em;'></div> तो, <code> security_result.severity </code> UDM फ़ील्ड को <code>INFORMATIONAL</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>severity.level</code> लॉग फ़ील्ड का मान <code> 7 </code> के बराबर है तो, <code> security_result.severity </code> UDM फ़ील्ड को <code>LOW</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा <code> security_result.severity </code> UDM फ़ील्ड को <code>UNKNOWN_SEVERITY</code> पर सेट किया जाता है। <br></td>
</tr>
<tr>
<td><code>severity.name</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>severity.level</code></td>
<td><code>security_result.detection_fields [severity_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>यदि <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Critical" या <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "4 </code>" </code> के बराबर है तो, <code> "target.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>CRITICAL</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)High" या <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "3 </code>" </code> के बराबर है तो, <code> "target.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>HIGH</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Low" या <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "1 </code>" </code> के बराबर है तो, <code> "target.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>LOW</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Medium" या <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "2 </code>" </code> के बराबर है तो, <code> "target.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>MEDIUM</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Unknown_Severity" </code> या <code>resp_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "0 </code>" के बराबर है तो, <code> "target.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>UNKNOWN_SEVERITY</code> पर सेट किया जाता है। <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname (string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain (string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version (string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>यदि <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Critical" या <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "4 </code>" </code> के बराबर है तो, <code> "principal.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>CRITICAL</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)High" या <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "3 </code>" </code> के बराबर है तो, <code> "principal.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>HIGH</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Low" या <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "1 </code>" </code> के बराबर है तो, <code> "principal.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>LOW</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Medium" या <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "2 </code>" </code> के बराबर है तो, <code> "principal.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>MEDIUM</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान नियमित अभिव्यक्ति पैटर्न से मेल खाता है <code> "(?i)Unknown_Severity" </code> या <code>orig_vulnerable_host.criticality</code> लॉग फ़ील्ड का मान <code> "0 </code>" के बराबर है तो, <code> "principal.asset.vulnerabilities.severity" </code> UDM फ़ील्ड को <code>UNKNOWN_SEVERITY</code> पर सेट किया जाता है। <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname (string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain (string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version (string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source (string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - smb_files</h3>
निम्न तालिका <code>smb_files</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_READ</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_READ</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_WRITE</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_MODIFICATION</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_OPEN</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_OPEN</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_CLOSE</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_UNCATEGORIZED</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_DELETE</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_DELETION</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_RENAME</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_MOVE</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>action</code> लॉग फ़ील्ड का मान <code>SMB::FILE_SET_ATTRIBUTE</code> के बराबर है, तो <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_UNCATEGORIZED</code> पर सेट होता है।<br><br>अन्यथा, <code>metadata.event_type</code> UDM फ़ील्ड <code>FILE_UNCATEGORIZED</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड <code>SMB</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM फ़ील्ड <code>TCP</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>action, name</code></td>
<td><code>metadata.description</code></td>
<td><code>metadata.description</code> UDM फ़ील्ड <code>action</code> और <code>name</code> लॉग फ़ील्ड के साथ "action: <code>action</code> on: <code>name</code>" के रूप में सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM फ़ील्ड <code>INFORMATIONAL</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM फ़ील्ड <code>ALLOW</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>action (string - enum)</code></td>
<td><code>target.labels [action]</code></td>
<td></td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.file.full_path</code></td>
<td></td>
</tr>
<tr>
<td><code>name (string)</code></td>
<td><code>target.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>size (integer - count)</code></td>
<td><code>target.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>prev_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>times.modified (time)</code></td>
<td><code>target.file.last_modification_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.accessed (time)</code></td>
<td><code>target.file.last_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.created (time)</code></td>
<td><code>target.file.first_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.changed (time)</code></td>
<td><code>target.labels [times_changed]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_offset_req (integer - count)</code></td>
<td><code>target.labels [data_offset_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_req (integer - count)</code></td>
<td><code>target.labels [data_len_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_rsp (integer - count)</code></td>
<td><code>target.labels [data_len_rsp]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - smb_mapping</h3>
निम्न तालिका <code>smb_mapping</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_CONNECTION</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड <code>SMB</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM फ़ील्ड <code>TCP</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM फ़ील्ड <code>INFORMATIONAL</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM फ़ील्ड <code>ALLOW</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.resource.attribute.labels [path]</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>target.application</code></td>
<td></td>
</tr>
<tr>
<td><code>native_file_system (string)</code></td>
<td><code>target.resource.attribute.labels [native_file_system]</code></td>
<td></td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_type</code></td>
<td>यदि <code>share_type</code> लॉग फ़ील्ड का मान <code>DISK</code> के बराबर है, तो <code>target.resource.resource_type</code> UDM फ़ील्ड <code>STORAGE_OBJECT</code> पर सेट होता है।<br><br>अन्यथा, यदि <code>share_type</code> लॉग फ़ील्ड का मान <code>PIPE</code> के बराबर है, तो <code>target.resource.resource_type</code> UDM फ़ील्ड <code>PIPE</code> पर सेट होता है।<br><br>अन्यथा, <code>target.resource.resource_type</code> UDM फ़ील्ड <code>UNSPECIFIED</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_subtype</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - ssl, ssl_red, ssl_agg</h3>
निम्न तालिका <code>ssl, ssl_red, ssl_agg</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_CONNECTION</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड <code>HTTPS</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM फ़ील्ड <code>TCP</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM फ़ील्ड <code>INFORMATIONAL</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM फ़ील्ड <code>ALLOW</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.tls.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>curve (string)</code></td>
<td><code>network.tls.curve</code></td>
<td></td>
</tr>
<tr>
<td><code>server_name (string)</code></td>
<td><code>network.tls.client.server_name</code></td>
<td></td>
</tr>
<tr>
<td><code>resumed (boolean - bool)</code></td>
<td><code>network.tls.resumed</code></td>
<td></td>
</tr>
<tr>
<td><code>last_alert (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>next_protocol (string)</code></td>
<td><code>network.tls.next_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>established (boolean - bool)</code></td>
<td><code>network.tls.established</code></td>
<td></td>
</tr>
<tr>
<td><code>ssl_history (string)</code></td>
<td><code>about.labels [ssl_history]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>target.labels [cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>principal.labels [client_cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>sni_matches_cert (boolean - bool)</code></td>
<td><code>about.labels [sni_matches_cert]</code></td>
<td></td>
</tr>
<tr>
<td><code>validation_status (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3 (string)</code></td>
<td><code>network.tls.client.ja3</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3s (string)</code></td>
<td><code>network.tls.server.ja3s</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - rdp</h3>
निम्न तालिका <code>rdp</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_CONNECTION</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>cookie (string)</code></td>
<td><code>principal.user.userid</code></td>
<td></td>
</tr>
<tr>
<td><code>result (string)</code></td>
<td><code>about.labels [result]</code></td>
<td></td>
</tr>
<tr>
<td><code>security_protocol (string)</code></td>
<td><code>target.labels [security_protocol]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_channels (array[string] - vector of string)</code></td>
<td><code>intermediary.labels [client_channels]</code></td>
<td></td>
</tr>
<tr>
<td><code>keyboard_layout (string)</code></td>
<td><code>principal.labels [keyboard_layout]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_build (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>client_name (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>client_dig_product_id (string)</code></td>
<td><code>principal.asset.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_width (integer - count)</code></td>
<td><code>principal.labels [desktop_width]</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_height (integer - count)</code></td>
<td><code>principal.labels [desktop_height]</code></td>
<td></td>
</tr>
<tr>
<td><code>requested_color_depth (string)</code></td>
<td><code>principal.labels [requested_color_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_type (string)</code></td>
<td><code>about.labels [cert_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_count (integer - count)</code></td>
<td><code>about.labels [cert_count]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_permanent (boolean - bool)</code></td>
<td><code>about.labels [cert_permanent ]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_level (string)</code></td>
<td><code>about.labels [encryption_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_method (string)</code></td>
<td><code>about.labels [encryption_method]</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>यदि <code>auth_success</code> लॉग फ़ील्ड का मान <code>true</code> के बराबर है, तो <code>security_result.action</code> UDM फ़ील्ड <code>ALLOW</code> पर सेट होता है। <br> अन्यथा, <code>security_result.action</code> UDM फ़ील्ड <code>FAIL</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>channels_joined (integer - int)</code></td>
<td><code>intermediary.labels [channels_joined]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>about.labels [inferences]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdpeudp_uid (string)</code></td>
<td><code>about.labels [rdpeudp_uid]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM फ़ील्ड <code>TCP</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>rdfp_string (string)</code></td>
<td><code>principal.labels [rdfp_string]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdfp_hash (string)</code></td>
<td><code>principal.labels [rdfp_hash]</code></td>
<td></td>
</tr>
<tr>
<td><code>result, security_protocol</code></td>
<td><code>security_result.description</code></td>
<td><code>security_result.description</code> UDM फ़ील्ड <code>result</code> और <code>security_protocol</code> लॉग फ़ील्ड के साथ "<code>result</code> connection with security protocol <code>security_protocol</code>" के रूप में सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM फ़ील्ड <code>INFORMATIONAL</code> पर सेट होता है।</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - sip</h3>
निम्न तालिका <code>sip</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="किसी मान को खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>तर्क</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_UNCATEGORIZED</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट होता है।</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड <code>SIP</code> पर सेट होता है।</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>about.labels [method]</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_from (string)</code></td>
<td><code>principal.labels [request_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_to (string)</code></td>
<td><code>target.labels [request_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_from</code></td>
<td><code>principal.labels [response_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_to (string)</code></td>
<td><code>target.labels [response_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>about.labels [reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>call_id (string)</code></td>
<td><code>about.labels[call_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>seq (string)</code></td>
<td><code>about.labels [seq]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>about.labels [subject]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_path (array[string] - vector of string)</code></td>
<td><code>about.labels [request_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_path (array[string] - vector of string)</code></td>
<td><code>about.labels [response_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>about.labels [user_agent]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>about.labels [status_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>warning (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>content_type (string)</code></td>
<td><code>about.labels [content_type]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - intel</h3>
निम्न तालिका <code>intel</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संबंधित UDM फ़ील्ड की सूची देती है।<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="मान खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>लॉजिक</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड को <code>SCAN_NETWORK</code> पर सेट किया गया है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड को <code>Zeek</code> पर सेट किया गया है।</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.metadata.entity_type</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::ADDR</code> के बराबर है, तो <code>metadata.entity_type</code> UDM फ़ील्ड को <code>IP_ADDRESS</code> पर सेट किया जाता है।<br><br>अन्यथा, यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::SUBNET</code> या <code>Intel::SOFTWARE</code> या <code>Intel::CERT_HASH</code> या <code>Intel::PUBKEY_HASH</code> के बराबर है, तो <code>metadata.entity_type</code> UDM फ़ील्ड को <code>RESOURCE</code> पर सेट किया जाता है।<br><br>अन्यथा, यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::URL</code> के बराबर है, तो <code>metadata.entity_type</code> UDM फ़ील्ड को <code>URL</code> पर सेट किया जाता है।<br><br>अन्यथा, यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::EMAIL</code> या <code>Intel::USER_NAME</code> के बराबर है, तो <code>metadata.entity_type</code> UDM फ़ील्ड को <code>USER</code> पर सेट किया जाता है।<br><br>अन्यथा, यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::DOMAIN</code> के बराबर है, तो <code>metadata.entity_type</code> UDM फ़ील्ड को <code>DOMAIN_NAME</code> पर सेट किया जाता है।<br><br>अन्यथा, यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::FILE_HASH</code> या <code>Intel::FILE_NAME</code> के बराबर है, तो <code>metadata.entity_type</code> UDM फ़ील्ड को <code>FILE</code> पर सेट किया जाता है।<br><br>अन्यथा, <code>metadata.entity_type</code> UDM फ़ील्ड को <code>RESOURCE</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.ip</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::ADDR</code> के बराबर है, तो <code>seen.indicator</code> लॉग फ़ील्ड को <code>entity.ip</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.url</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::URL</code> के बराबर है, तो <code>seen.indicator</code> लॉग फ़ील्ड को <code>entity.url</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.domain.name</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::DOMAIN</code> के बराबर है, तो <code>seen.indicator</code> लॉग फ़ील्ड को <code>entity.domain.name</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.user.email_address</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::USER_NAME</code> या <code>Intel::EMAIL</code> के बराबर है, तो <code>seen.indicator</code> लॉग फ़ील्ड को <code>entity.user.email_address</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.file.names</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::FILE_HASH</code> या <code>Intel::FILE_NAME</code> के बराबर है, तो <code>seen.indicator</code> लॉग फ़ील्ड को <code>entity.file.full_path</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.resource.name</code></td>
<td>यदि <code>metadata.entity_type</code> लॉग फ़ील्ड मान <code>RESOURCE</code> के बराबर है, तो <code>seen.indicator</code> लॉग फ़ील्ड को <code>entity.resource.name</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td></td>
<td><code>entity.resource.resource_type</code></td>
<td>यदि <code>indicator.type</code> लॉग फ़ील्ड मान <code>Intel::SUBNET</code> के बराबर है, तो <code>entity.resource.resource_name</code> UDM फ़ील्ड को <code>VPC_NETWORK</code> पर सेट किया जाता है।</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.resource.resource_sub_type</code></td>
<td>यदि <code>metadata.entity_type</code> लॉग फ़ील्ड मान <code>RESOURCE</code> के बराबर है, तो <code>seen.indicator_type</code> लॉग फ़ील्ड को <code>entity.resource.resource_sub_type</code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>entity.metadata.source_labels [seen_where]</code></td>
<td></td>
</tr>
<tr>
<td><code>matched (array[string] - set[enum])</code></td>
<td><code>entity.labels [matched]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>entity.metadata.source_labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>entity.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>metadata.threat.detection_fields [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>desc (array[string] - set[string])</code></td>
<td><code>ioc.description</code></td>
<td>जब <code>desc</code> में इंडेक्स मान <code>0</code> के बराबर होता है, तो <code>desc</code> लॉग फ़ील्ड को <code>ioc.description</code> UDM फ़ील्ड में मैप किया जाता है।
<br><br>अन्य सभी इंडेक्स मानों के लिए, <code>entity.labels.key</code> UDM फ़ील्ड को <code>desc</code> पर सेट किया जाता है और <code>desc</code> लॉग फ़ील्ड को <code>entity.labels.value</code> में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>url (array[string] - set[string])</code></td>
<td><code>metadata.threat.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>ioc.confidence_score</code></td>
<td>जब <code>confidence</code> में इंडेक्स मान <code>0</code> के बराबर होता है, तो <code>confidence</code> लॉग फ़ील्ड को <code>ioc.confidence_score</code> UDM फ़ील्ड में मैप किया जाता है।
<br><br>अन्य सभी इंडेक्स मानों के लिए, <code>entity.labels.key</code> UDM फ़ील्ड को <code>confidence</code> पर सेट किया जाता है और <code>confidence</code> लॉग फ़ील्ड को <code>entity.labels.value</code> में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>firstseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.start</code></td>
<td>जब <code>firstseen</code> में इंडेक्स मान <code>0</code> के बराबर होता है, तो <code>firstseen</code> लॉग फ़ील्ड को <code>ioc.active_timerange.start</code> UDM फ़ील्ड में मैप किया जाता है।
<br><br>अन्य सभी इंडेक्स मानों के लिए, <code>entity.labels.key</code> UDM फ़ील्ड को <code>firstseen</code> पर सेट किया जाता है और <code>firstseen</code> लॉग फ़ील्ड को <code>entity.labels.value</code> में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>lastseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.end</code></td>
<td>जब <code>lastseen</code> में इंडेक्स मान <code>0</code> के बराबर होता है, तो <code>lastseen</code> लॉग फ़ील्ड को <code>ioc.active_timerange.end</code> UDM फ़ील्ड में मैप किया जाता है।
<br><br>अन्य सभी इंडेक्स मानों के लिए, <code>entity.labels.key</code> UDM फ़ील्ड को <code>lastseen</code> पर सेट किया जाता है और <code>lastseen</code> लॉग फ़ील्ड को <code>entity.labels.value</code> में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>associated (array[string] - set[string])</code></td>
<td><code>entity.labels [associated]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>ioc.categorization</code></td>
<td>जब <code>category</code> में इंडेक्स मान <code>0</code> के बराबर होता है, तो <code>category</code> लॉग फ़ील्ड को <code>ioc.categorization</code> UDM फ़ील्ड में मैप किया जाता है।
<br><br>अन्य सभी इंडेक्स मानों के लिए, <code>entity.labels.key</code> UDM फ़ील्ड को <code>category</code> पर सेट किया जाता है और <code>category</code> लॉग फ़ील्ड को <code>entity.labels.value</code> में मैप किया जाता है।</td>
</tr>
<tr>
<td><code>campaigns (array[string] - set[string])</code></td>
<td><code>entity.labels [campaign]</code></td>
<td></td>
</tr>
<tr>
<td><code>reports (array[string] - set[string])</code></td>
<td><code>entity.labels [report]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>about.labels [indicator]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>about.labels [indicator_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>about.labels [where]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>about.labels [sources]</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>about.labels [confidence]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>about.labels [category]</code></td>
<td></td>
</tr>
<tr>
<td><code>threat_score (array[number] - set[double])</code></td>
<td><code>entity.security_result.detection_fields[threat_score]</code></td>
<td></td>
</tr>
<tr>
<td><code>verdict (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.verdict_response</code></td>
<td><code>verdict</code> के माध्यम से पुनरावृत्ति करें,<div style='margin-bottom: 0.5em;'></div><div style='margin-bottom: 0.0em;'></div>यदि <code>verdict</code> लॉग फ़ील्ड मान रेगुलर एक्सप्रेशन पैटर्न <code> "(?i)Malicious" or the <code>verdict</code> log field value is equal to <code> "1" </code> </code> से मेल खाता है, तो <code> "entity.security_result.verdict_info.verdict_response" </code> UDM फ़ील्ड को <code>MALICIOUS</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा, यदि <code>verdict</code> लॉग फ़ील्ड मान रेगुलर एक्सप्रेशन पैटर्न <code> "(?i)Benign" or the <code>verdict</code> log field value is equal to <code> "2" </code> </code> से मेल खाता है, तो <code> "entity.security_result.verdict_info.verdict_response" </code> UDM फ़ील्ड को <code>BENIGN</code> पर सेट किया जाता है। <br> <div style='margin-bottom: 0.5em;'></div>अन्यथा <code> "entity.security_result.verdict_info.verdict_response" </code> UDM फ़ील्ड को <code>VERDICT_RESPONSE_UNSPECIFIED</code> पर सेट किया जाता है। <br></td>
</tr>
<tr>
<td><code>verdict_source (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.source_provider</code></td>
<td><code>verdict_source</code> के माध्यम से पुनरावृत्ति करें,<div style='margin-bottom: 0.5em;'></div><code>verdict_source</code> लॉग फ़ील्ड को <code> entity.security_result.VerdictInfo.source_provider </code> UDM फ़ील्ड में मैप किया जाता है।</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - smtp</h3>
निम्न तालिका <code>smtp</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संगत UDM फ़ील्ड की सूची देती है।
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="मान खोजने के लिए एक कीवर्ड टाइप करें।">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>लॉजिक</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड को <code>NETWORK_SMTP</code> पर सेट किया गया है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड को <code>Zeek</code> पर सेट किया गया है।</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड को <code>SMTP</code> पर सेट किया गया है।</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>helo (string)</code></td>
<td><code>network.smtp.helo</code></td>
<td></td>
</tr>
<tr>
<td><code>mailfrom (string)</code></td>
<td><code>network.smtp.mail_from</code></td>
<td></td>
</tr>
<tr>
<td><code>rcptto (array[string] - set[string])</code></td>
<td><code>network.smtp.rcpt_to</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>from (string)</code></td>
<td><code>network.email.from</code></td>
<td></td>
</tr>
<tr>
<td><code>to (array[string] - set[string])</code></td>
<td><code>network.email.to</code></td>
<td></td>
</tr>
<tr>
<td><code>cc (array[string] - set[string])</code></td>
<td><code>network.email.cc</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>network.email.reply_to</code></td>
<td></td>
</tr>
<tr>
<td><code>msg_id (string)</code></td>
<td><code>network.email.mail_id</code></td>
<td></td>
</tr>
<tr>
<td><code>in_reply_to (string)</code></td>
<td><code>about.labels [in_reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>network.email.subject</code></td>
<td></td>
</tr>
<tr>
<td><code>x_originating_ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>first_received (string)</code></td>
<td><code>about.labels [first_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>second_received (string)</code></td>
<td><code>about.labels [second_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>last_reply (string)</code></td>
<td><code>network.smtp.server_response</code></td>
<td></td>
</tr>
<tr>
<td><code>path (array[string] - vector of addr)</code></td>
<td><code>network.smtp.message_path</code></td>
<td>लॉग फ़ील्ड <code>path</code> के माध्यम से पुनरावृत्ति करें, फिर<br> यदि <code>index</code> मान <code>0</code> के बराबर है, तो <code>path</code> लॉग फ़ील्ड को <code>network.smtp.message_path</code> UDM फ़ील्ड में मैप किया जाता है। <br> अन्यथा, <code>path</code> लॉग फ़ील्ड को <code>intermediary.ip</code> UDM फ़ील्ड में मैप किया जाता है।<br></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>principal.application</code></td>
<td></td>
</tr>
<tr>
<td><code>tls (boolean - bool)</code></td>
<td><code>network.smtp.is_tls</code></td>
<td></td>
</tr>
<tr>
<td><code>fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_webmail (boolean - bool)</code></td>
<td><code>network.smtp.is_webmail</code></td>
<td></td>
</tr>
<tr>
<td><code>urls (array[string] - set[string])</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domains (array[string] - set[string])</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>फ़ील्ड मैपिंग संदर्भ: CORELIGHT - ssh</h3>
निम्न तालिका <code>ssh</code> लॉग प्रकार के लॉग फ़ील्ड और उनके संगत UDM फ़ील्ड की सूची देती है।<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>लॉग फ़ील्ड</th>
<th>UDM मैपिंग</th>
<th>लॉजिक</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM फ़ील्ड <code>NETWORK_UNCATEGORIZED</code> पर सेट है।</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM फ़ील्ड <code>Zeek</code> पर सेट है।</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM फ़ील्ड <code>SSH</code> पर सेट है।</td>
</tr>
<tr>
<td><code>version (integer - count)</code></td>
<td><code>network.application_protocol_version</code></td>
<td><code>network.application_protocol_version</code> UDM फ़ील्ड को <code>version</code> लॉग फ़ील्ड के साथ "SSH <code>version</code>" के रूप में सेट किया गया है।</td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>यदि <code>auth_success</code> लॉग फ़ील्ड मान <code>true</code> के <em>बराबर नहीं</em> है, तो <code>security_result.action</code> UDM फ़ील्ड <code>ALLOW</code> पर सेट है।<br><br>अन्यथा, <code>security_result.action</code> UDM फ़ील्ड <code>BLOCK</code> पर सेट है।</td>
</tr>
<tr>
<td><code>auth_attempts (integer - count)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td><code>extensions.auth.auth_details</code> UDM फ़ील्ड को <code>auth_attempts</code> लॉग फ़ील्ड के साथ "auth_attempts: <code>auth_attempts</code>" के रूप में सेट किया गया है।</td>
</tr>
<tr>
<td><code>direction (string - enum)</code></td>
<td><code>network.direction</code></td>
<td>यदि <code>direction</code> लॉग फ़ील्ड मान <code>INBOUND</code> के बराबर है, तो <code>network.direction</code> UDM फ़ील्ड <code>INBOUND</code> पर सेट है।<br><br>अन्यथा, यदि <code>direction</code> लॉग फ़ील्ड मान <code>OUTBOUND</code> के बराबर है, तो <code>network.direction</code> UDM फ़ील्ड <code>OUTBOUND</code> पर सेट है।</td>
</tr>
<tr>
<td><code>client (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>server (string)</code></td>
<td><code>target.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher_alg (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>mac_alg (string)</code></td>
<td><code>security_result.detection_fields [mac_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>compression_alg (string)</code></td>
<td><code>security_result.detection_fields [compression_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>kex_alg (string)</code></td>
<td><code>security_result.detection_fields [kex_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key_alg (string)</code></td>
<td><code>network.tls.server.certificate.version</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>target.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>target.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>target.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshVersion (string)</code></td>
<td><code>about.labels [hassh_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>hassh (string)</code></td>
<td><code>principal.labels [hassh]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServer (string)</code></td>
<td><code>target.labels [hassh_server]</code></td>
<td></td>
</tr>
<tr>
<td><code>cshka (string)</code></td>
<td><code>about.labels [cshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshAlgorithms (string)</code></td>
<td><code>about.labels [hassh_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>sshka (string)</code></td>
<td><code>about.labels [sshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServerAlgorithms (string)</code></td>
<td><code>about.labels [hassh_server_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>security_result.summary, security_result.description, security_result.detection_fields[inferences]</code></td>