Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CorelightForSecOps — Parser di Chronicle per CORELIGHT e informazioni correlate. | Kitploit
Strumenti/GitHubGitHub/corelight/corelightforsecops
Strumenti DifensiviSicurezza di ReteSicurezza CloudUtilità e FrameworkRilevamento IntrusioniAnalisi dei Log
GitHubcorelight/corelightforsecops

CorelightForSecOps

Parser di Chronicle per CORELIGHT e informazioni correlate.

Vedi Repository
542 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Raccolta dei log di Corelight Sensor

Questo documento descrive come raccogliere i log di Corelight Sensor configurando Corelight Sensor e un forwarder di Chronicle. Questo documento elenca anche i tipi di log supportati e le versioni di Corelight supportate.

Per maggiori informazioni, consulta Ingestione dei dati in Chronicle.

Prima di iniziare

  • Verifica la versione di Corelight Sensor. Il parser Corelight Google SecOps è stato progettato per la versione 27.13 e precedenti. Le versioni successive di Corelight Sensor potrebbero avere log aggiuntivi che il parser non riconosce e tali log potrebbero ricevere un parsing dei campi limitato o assente. Tuttavia, il contenuto dei log sarà comunque disponibile nel formato di log grezzo in Google SecOps.
  • Assicurati che tutti i sistemi nell'architettura di distribuzione siano configurati con il fuso orario UTC.

Metodi di distribuzione e di ingestione dei log

Il seguente diagramma dell'architettura di distribuzione illustra come Corelight Sensor è configurato per inviare log a Google Security Operations utilizzando due diverse architetture di ingestione. È importante notare che ogni distribuzione del cliente può differire da questa rappresentazione e potrebbe essere più complessa.

Un'etichetta di ingestione identifica il parser che normalizza i dati di log grezzi nel formato strutturato UDM. Le informazioni contenute in questo documento si applicano al parser con etichetta di ingestione CORELIGHT.

Ingestione dei log in Google SecOps utilizzando gli exporter di Corelight

Architettura di distribuzione

Il diagramma dell'architettura mostra i seguenti componenti:

  • Corelight Sensor: Il sistema che esegue Corelight Sensor .

  • Exporter di Corelight Sensor: L'exporter di Corelight Sensor raccoglie i dati di log dal Sensor e li inoltra a Google Security Operations.

  • Google Security Operations: Google Security Operations conserva e analizza i log provenienti da Corelight Sensor.

Configurare l'exporter Google SecOps in Corelight

Utilizza l'interfaccia web di Sensor o Fleet Manager per configurare l'exporter di Google SecOps. Questa configurazione utilizza le credenziali API della tua istanza di Google SecOps per stabilire la connessione sicura.

  1. Accedi all'interfaccia web di Fleet Manager o Sensor di Corelight Sensor come amministratore.

  2. Vai all'area di configurazione dell'exporter:

    • Fleet Manager: Vai su Policies, seleziona una policy e fai clic sulla scheda Export.
    • Standalone Sensor: Vai su Configuration | Export | Export Configuration.
  3. Nella sezione Create Exporter, fai clic su Google SecOps.

Architettura di distribuzione

  1. Configura i seguenti parametri di input:
  • Name*: Un nome univoco per questa istanza di exporter (ad esempio, SecOps).
  • Google SecOps Customer ID*: Il tuo identificatore cliente univoco fornito da Google.
  • Google SecOps Namespace: Il namespace logico per i log del tuo Sensor in Google SecOps.
  • Credentials*: Le credenziali del Service Account di Google SecOps (JSON). (Incolla l'intero contenuto JSON).
  • Google SecOps Labels: Etichette configurate dall'utente per identificare il dominio dei dati.
  • Region*: Il nome della regione GCP utilizzata da Google SecOps.
  • Batch Max Events: La dimensione massima del batch.
  • Batch Timeout Seconds: L'età massima di un batch.
  • Proxy URL: L'URL del proxy di rete, se necessario.
  • Exporter Log Filter: Seleziona un filtro da applicare a questa istanza di exporter.
  • Log Type Filter: Includi o escludi specifici file di log per nome.
    • Exclude: Rimuove i log specificati. I nuovi tipi di log (ad esempio, dai pacchetti) verranno comunque esportati.
    • Include: Esporta solo i log specificati. I nuovi tipi di log NON verranno esportati a meno che non vengano aggiunti manualmente.

Architettura di distribuzione Architettura di distribuzione

  1. Fai clic su Done.

Architettura di distribuzione

  1. Fai clic su Apply Changes.

Ingestione dei log in Google SecOps utilizzando un forwarder

Architettura di distribuzione

Il diagramma dell'architettura mostra i seguenti componenti:

  • Corelight Sensor: Il sistema che esegue Corelight Sensor .

  • Exporter di Corelight Sensor: L'exporter di Corelight Sensor raccoglie i dati di log dal Sensor e li inoltra al forwarder di Google Security Operations.

  • Forwarder di Google Security Operations: Il forwarder di Google Security Operations è un componente software leggero, distribuito nella rete del cliente, che supporta syslog. Il forwarder di Google Security Operations inoltra i log a Google Security Operations.

  • Google Security Operations: Google Security Operations conserva e analizza i log provenienti da Corelight Sensor.

Configurare il forwarder di Google Security Operations

Per configurare il forwarder di Google Security Operations, procedi come segue:

  1. Configura un forwarder di Google Security Operations. Consulta Installa e configura il forwarder su Linux.

  2. Configura il forwarder di Google Security Operations per inviare i log a Google Security Operations. ```none collectors:

    • syslog: common: enabled: true data_type: CORELIGHT data_hint: batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: tcp_buffer_size: 524288 udp_address: connection_timeout_sec: 60
root@kitploit:~
### Configura l'exporter di Corelight Sensor 

1. Accedi a Corelight Sensor come amministratore.
2. Seleziona la scheda **Export**.
3. Trova e abilita l'opzione **EXPORT TO SYSLOG**.
4. Nella sezione **EXPORT TO SYSLOG**, configura i seguenti campi:
* **SYSLOG SERVER**: Specifica l'indirizzo IP e la porta del listener syslog del forwarder di Google Security Operations.
* Vai a **Advanced Settings > SYSLOG FORMAT** e modifica l'impostazione su **Legacy**.

![Configurazione di Corelight Sensor](https://assets.kitploit.com/production/public/readmes/45240/98e9932cefa08d1f288a8a66675a4ae8398ad3d243bd14379054908875b0da03.jpg)

5. Fai clic su **Apply Changes**.

## Tipi di log Corelight supportati

Il parser Corelight supporta i seguenti tipi di log:
<div class="fixed" translate="no">
<h4>Log Type</h4>
<ul>
  <li>asset_classification</li>
  <li>conn</li>
  <li>conn_long</li>
  <li>conn_red</li>
  <li>conn_agg</li>
  <li>dce_rpc</li>
  <li>dns</li>
  <li>dns_red</li>
  <li>files</li>
  <li>files_red</li>
  <li>http</li>
  <li>http2</li>
  <li>http_red</li>
  <li>intel</li>
  <li>irc</li>
  <li>notice</li>
  <li>rdp</li>
  <li>sip</li>
  <li>smb_files</li>
  <li>smb_mapping</li>
  <li>smtp</li>
  <li>smtp_links</li>
  <li>ssh</li>
  <li>ssl</li>
  <li>ssl_red</li>
  <li>suricata_corelight</li>
  <li>bacnet</li>
  <li>cip</li>
  <li>corelight_burst</li>
  <li>corelight_metrics_bro</li>
  <li>corelight_metrics_disk</li>
  <li>corelight_metrics_iface</li>
  <li>corelight_metrics_memory</li>
  <li>corelight_metrics_system</li>
  <li>corelight_metrics_zeek_doctor</li>
  <li>corelight_overall_capture_loss</li>
  <li>corelight_profiling</li>
  <li>datared</li>
  <li>dga</li>
  <li>dhcp</li>
  <li>dnp3</li>
  <li>dpd</li>
  <li>encrypted_dns</li>
  <li>enip</li>
  <li>enip_debug</li>
  <li>enip_list_identity</li>
  <li>etc_viz</li>
  <li>ftp</li>
  <li>generic_dns_tunnels</li>
  <li>generic_icmp_tunnels</li>
  <li>icmp_specific_tunnels</li>
  <li>ipsec</li>
  <li>iso_cotp</li>
  <li>kerberos</li>
  <li>known_certs</li>
  <li>known_devices</li>
  <li>known_domains</li>
  <li>known_hosts</li>
  <li>known_names</li>
  <li>known_remotes</li>
  <li>known_services</li>
  <li>known_users</li>
  <li>ldap</li>
  <li>ldap_search</li>
  <li>local_subnets</li>
  <li>local_subnets_dj</li>
  <li>local_subnets_graphs</li>
  <li>log4shell</li>
  <li>modbus</li>
  <li>mqtt_connect</li>
  <li>mqtt_publish</li>
  <li>mqtt_subscribe</li>
  <li>mysql</li>
  <li>napatech_shunting</li>
  <li>ntlm</li>
  <li>ntp</li>
  <li>pe</li>
  <li>profinet</li>
  <li>profinet_dce_rpc</li>
  <li>profinet_debug</li>
  <li>radius</li>
  <li>reporter</li>
  <li>rfb</li>
  <li>s7comm</li>
  <li>smartpcap</li>
  <li>snmp</li>
  <li>socks</li>
  <li>software</li>
  <li>specific_dns_tunnels</li>
  <li>stepping</li>
  <li>stun</li>
  <li>stun_nat</li>
  <li>suricata_eve</li>
  <li>suricata_stats</li>
  <li>syslog</li>
  <li>tds</li>
  <li>tds_rpc</li>
  <li>tds_sql_batch</li>
  <li>traceroute</li>
  <li>tunnel</li>
  <li>unknown-smartpcap</li>
  <li>vpn</li>
  <li>weird</li>
  <li>weird_red</li>
  <li>wireguard</li>
  <li>x509</li>
  <li>x509_red</li>
  <li>dns_agg</li>
  <li>files_agg</li>
  <li>http_agg</li>
  <li>ssl_agg</li>
  <li>weird_agg</li>
  <li>analyzer</li>
  <li>anomaly</li>
  <li>ssdp</li>
  <li>telnet</li>
  <li>websocket</li>
  <li>first_seen</li>
</ul>
</div>

## Riferimento per il mapping dei campi

Questa sezione spiega come il parser di Google Security Operations mappa i campi di Google Security Operations sui campi del Unified Data Model (UDM) di Google Security Operations.

<h3>Riferimento per il mapping dei campi: CORELIGHT - Campi comuni </h3>

La tabella seguente elenca i campi comuni del log <code>CORELIGHT</code> e i corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.vendor_name</code></td>
<td>The <code>metadata.vendor_name</code> UDM field is set to <code>Corelight</code>.</td>
</tr>
<tr>
<td><code>_path (string)</code></td>
<td><code>metadata.product_event_type</code></td>
<td></td>
</tr>
<tr>
<td><code>_system_name (string)</code></td>
<td><code>observer.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>ts (time)</code></td>
<td><code>metadata.event_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>uid (string)</code></td>
<td><code>about.labels [uid], network.session_id</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_h (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_p (integer - port)</code></td>
<td><code>principal.port</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_h (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_p (integer - port)</code></td>
<td><code>target.port</code></td>
<td></td>
</tr>
<tr>
<td><code>_write_ts</code></td><code></code>
<td><code>metadata.collected_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan (integer - int)</code></td>
<td><code>additional.fields [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - int)</code></td>
<td><code>additional.fields [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_cid (string)</code></td>
<td><code>additional.fields [id_orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_source (string)</code></td>
<td><code>additional.fields [id_orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_status (string)</code></td>
<td><code>additional.fields [id_orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_uid (string)</code></td>
<td><code>additional.fields [id_orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_cid (string)</code></td>
<td><code>additional.fields [id_resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_source (string)</code></td>
<td><code>additional.fields [id_resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_status (string)</code></td>
<td><code>additional.fields [id_resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_uid (string)</code></td>
<td><code>additional.fields [id_resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>uids (array[string] - vector of string)</code></td>
<td><code>additional.fields [uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>count (integer - int)</code></td>
<td><code>additional.fields [count]</code></td>
<td></td>
</tr>
<tr>
<td><code>ts_last</code></td>
<td><code>additional.fields [ts_last]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - asset_classification</h3>

La tabella seguente elenca i campi del log di tipo <code>asset_classification</code> e i corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>STATUS_UPDATE</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>mac</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>vendor_mac (string)</code></td>
<td><code>about.asset.hardware.manufacturer</code></td>
<td></td>
</tr>
<tr>
<td><code>device_type (string)</code></td>
<td><code>about.asset.category</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.platform</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.asset.attribute.labels</code></td>
<td></td>
</tr>
<tr>
<td><code>type_group (string)</code></td>
<td><code>about.group.group_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>type_name (string)</code></td>
<td><code>about.resource.resource_subtype</code></td>
<td>The <code>about.resource.resource_type</code> UDM field is set to <code>DEVICE</code></td>
</tr>
<tr>
<td><code>brand (string)</code></td>
<td><code>about.user.company_name</code></td>
<td></td>
</tr>
<tr>
<td><code>model (string)</code></td>
<td><code>about.asset.hardware.model</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (integer)</code></td>
<td><code>about.security_result.confidence_score</code></td>
<td></td>
</tr>
<tr>
<td><code>os_ver (string)</code></td>
<td><code>about.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string])</code></td>
<td><code>about.ip_geo_artifact.tags</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - conn, conn_red, conn_long, conn_agg</h3>

La tabella seguente elenca i campi del log di tipo <code>conn, conn_red, conn_long, conn_agg</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_bytes (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_bytes (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_state (string)</code></td>
<td><code>metadata.description</code></td>
<td>Se il valore del campo di log <code>conn_state</code> è uguale a <code>S0</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S0: Connection attempt seen, no reply</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>S1</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S1: Connection established, not terminated</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>S2</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S2: Connection established and close attempt by originator seen (but no reply from responder)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>S3</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S3: Connection established and close attempt by responder seen (but no reply from originator)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>SF</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>SF: Normal SYN/FIN completion</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>REJ</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>REJ: Connection attempt rejected</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTO</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTO: Connection established, originator aborted (sent a RST)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTOS0</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTOSH</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTR</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTR: Established, responder aborted</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>SH</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>SH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>SHR</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>SHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>OTH</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>OTH: No SYN seen, just midstream traffic (a partial connection that was not later closed)</code>.</td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_resp (boolean - bool)</code></td>
<td><code>about.labels [local_resp]</code></td>
<td></td>
</tr>
<tr>
<td><code>missed_bytes (integer - count)</code></td>
<td><code>about.labels [missed_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>history (string)</code></td>
<td><code>about.labels [history]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_pkts (integer - count)</code></td>
<td><code>network.sent_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ip_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_pkts (integer - count)</code></td>
<td><code>network.received_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ip_bytes (integer - count)</code></td>
<td><code>target.labels [resp_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>tunnel_parents (array[string] - set[string])</code></td>
<td><code>intermediary.labels [tunnel_parent]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cc (string)</code></td>
<td><code>principal.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cc (string)</code></td>
<td><code>target.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_ids (array[string] - set[string])</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.url (string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.rule (integer - count)</code></td>
<td><code>security_result.rule_labels [spcap_rule]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.trigger (string)</code></td>
<td><code>security_result.detection_fields [spcap_trigger]</code></td>
<td></td>
</tr>
<tr>
<td><code>app (array[string] - vector of string)</code></td>
<td><code>about.application</code></td>
<td></td>
</tr>
<tr>
<td><code>corelight_shunted (boolean - bool)</code></td>
<td><code>about.labels [corelight_shunted]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_pkts (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_pkts (integer - count)</code></td>
<td><code>target.labels [resp_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_bytes (integer - count)</code></td>
<td><code>target.labels [resp_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_l2_addr (string)</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_l2_addr (string)</code></td>
<td><code>target.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.src (string)</code></td>
<td><code>principal.labels [id_orig_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.vals (array[string] - set[string])</code></td>
<td><code>principal.labels [id_orig_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.src (string)</code></td>
<td><code>target.labels [id_resp_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.vals (array[string] - set[string])</code></td>
<td><code>target.labels [id_resp_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>intermediary.labels [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>inner_vlan (integer - int)</code></td>
<td><code>intermediary.labels [inner_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> è impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_cid (string)</code></td>
<td><code>additional.fields [orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_source (string)</code></td>
<td><code>additional.fields [orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_status (string)</code></td>
<td><code>additional.fields [orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_uid (string)</code></td>
<td><code>additional.fields [orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_cid (string)</code></td>
<td><code>additional.fields [resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_source (string)</code></td>
<td><code>additional.fields [resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_status (string)</code></td>
<td><code>additional.fields [resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_uid (string)</code></td>
<td><code>additional.fields [resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>netskope_site_ids</code></td>
<td><code>additional.fields[netskope_site_ids]</code></td>
<td>Iterare sul campo di log <code>netskope_site_ids</code>; quindi <br>il campo di log <code>netskope_site_id_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo di log <code>netskope_site_id</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>netskope_user_ids</code></td>
<td><code>additional.fields[netskope_user_ids]</code></td>
<td>Iterare sul campo di log <code>netskope_user_ids</code>; quindi <br>il campo di log <code>netskope_user_id_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo di log <code>netskope_user_id</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>write_ts</code></td>
<td><code>additional.fields[write_ts]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.urls (array[string] - vector of string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td>Iterare sul campo di log <code>spcap.urls</code>; quindi <br>il campo di log <code>spcap.urls</code> viene mappato sul campo UDM <code>security_result.url_back_to_product</code>.<br></td>
</tr>
<tr>
<td><code>community_ids (array[string] - vector of string)</code></td>
<td><code>network.community_id</code></td>
<td>Iterare sul campo di log <code>community_ids</code>; quindi<br> se l'indice è uguale a <code>0</code>, il campo di log <code>community_id</code> viene mappato sul campo UDM <code>network.community_id</code>. <br> Altrimenti, il campo di log <code>community_id_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo di log <code>community_id</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.version</code></td>
<td><code>about.resource.attribute.labels[vpc_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.vpc_id</code></td>
<td><code>about.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>about.resource.resource_type</code></td>
<td>Se <code>capture_metadata.vpc.vpc_id</code> è presente, allora il campo UDM <code>about.resource.resource_type</code> viene impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>capture_source</code></td>
<td><code>about.resource.attribute.labels[capture_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.az</code></td>
<td><code>principal.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.id</code></td>
<td><code>principal.resource.product_object_id</code></td>
<td></td>
</tr>

<tr>
<td><code>orig_inst.name</code></td>
<td><code>principal.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.org_id</code></td>
<td><code>principal.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.sg_ids</code></td>
<td><code>principal.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.subnet_id</code></td>
<td><code>principal.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.vpc_id</code></td>
<td><code>principal.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>principal.resource.resource_type</code></td>
<td>Se <code>orig_inst.vpc_id</code> è presente, allora il campo UDM <code>principal.resource.resource_type</code> viene impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>orig_inst.profile</code></td>
<td><code>principal.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.az</code></td>
<td><code>target.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.id</code></td>
<td><code>target.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.name</code></td>
<td><code>target.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.org_id</code></td>
<td><code>target.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.sg_ids</code></td>
<td><code>target.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.subnet_id</code></td>
<td><code>target.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.vpc_id</code></td>
<td><code>target.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>target.resource.resource_type</code></td>
<td>Se <code>resp_inst.vpc_id</code> è presente, allora il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>resp_inst.profile</code></td>
<td><code>target.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig</code> and <code>local_resp</code></td>
<td><code>additional.fields[direction]</code></td>
<td>Se il valore del campo di log <code>local_orig</code> è uguale a <code>true</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>true</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>internal</code>.<br><br>Altrimenti, se il valore del campo di log <code>local_orig</code> è uguale a <code>true</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>false</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>outbound</code>.<br><br>Altrimenti, se il valore del campo di log <code>local_orig</code> è uguale a <code>false</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>false</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>external</code>.<br><br>Altrimenti, se il valore del campo di log <code>local_orig</code> è uguale a <code>false</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>true</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>inbound</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - dce_rpc</h3>

La tabella seguente elenca i campi di log del tipo di log <code>dce_rpc</code> e i corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>named_pipe (string)</code></td>
<td><code>intermediary.resource.name</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>intermediary.resource.resource_type</code></td>
<td>Se il valore del campo di log <code>named_pipe</code> <em>non</em> è vuoto, allora il campo UDM <code>intermediary.resource.resource_type</code> viene impostato su <code>PIPE</code>.</td>
</tr>
<tr>
<td><code>endpoint (string)</code></td>
<td><code>target.labels [endpoint]</code></td>
<td></td>
</tr>
<tr>
<td><code>operation (string)</code></td>
<td><code>target.labels [operation]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>DCERPC</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> è impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td><code>operation, endpoint, named_pipe (string)</code></td>
<td><code>metadata.description</code></td>
<td>Il campo UDM <code>metadata.description</code> viene impostato con i campi di log <code>operation</code>, <code>endpoint</code>, <code>named_pipe</code> come "operation <code>operation</code> on <code>endpoint</code> using named pipe <code>named_pipe</code>".</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> è impostato su <code>TCP</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - dns, dns_red, dns_agg</h3>

La tabella seguente elenca i campi di log del tipo di log <code>dns, dns_red, dns_agg</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_DNS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>DNS</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>trans_id (integer - count)</code></td>
<td><code>network.dns.id</code></td>
<td></td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>query (string)</code></td>
<td><code>network.dns.questions.name</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass (integer - count)</code></td>
<td><code>network.dns.questions.class</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass_name (string)</code></td>
<td><code>about.labels [qclass_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype (integer - count)</code></td>
<td><code>network.dns.questions.type</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype_name (string)</code></td>
<td><code>about.labels [qtype_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response</code></td>
<td>Se il valore del campo log <code>rcode</code> *non* è vuoto, allora il campo UDM <code>network.dns.response</code> è impostato su <code>true</code>.</td>
</tr>
<tr>
<td><code>rcode_name (string)</code></td>
<td><code>about.labels [rcode_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>AA (boolean - bool)</code></td>
<td><code>network.dns.authoritative</code></td>
<td></td>
</tr>
<tr>
<td><code>TC (boolean - bool)</code></td>
<td><code>network.dns.truncated</code></td>
<td></td>
</tr>
<tr>
<td><code>RD (boolean - bool)</code></td>
<td><code>network.dns.recursion_desired</code></td>
<td></td>
</tr>
<tr>
<td><code>RA (boolean - bool)</code></td>
<td><code>network.dns.recursion_available</code></td>
<td></td>
</tr>
<tr>
<td><code>Z (integer - count)</code></td>
<td><code>about.labels [Z]</code></td>
<td></td>
</tr>
<tr>
<td><code>answers (array[string] - vector of string)</code></td>
<td><code>network.dns.answers.name</code></td>
<td></td>
</tr>
<tr>
<td><code>TTLs (array[number] - vector of interval)</code></td>
<td><code>network.dns.answers.ttl</code></td>
<td></td>
</tr>
<tr>
<td><code>rejected (boolean - bool)</code></td>
<td><code>about.labels [rejected]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_trusted_domain (string)</code></td>
<td><code>about.labels [is_trusted_domain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_host_subdomain (string)</code></td>
<td><code>about.labels [icann_host_subdomain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_domain (string)</code></td>
<td><code>network.dns_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_tld (string)</code></td>
<td><code>about.labels [icann_tld]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>security_result.detection_fields [num]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - http, http_red, http2, http_agg</h3>

La seguente tabella elenca i campi log del tipo di log <code>http, http_red, http2, http_agg</code> e i relativi campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_HTTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>network.http.method</code></td>
<td></td>
</tr>
<tr>
<td><code>host (string)</code></td>
<td><code>target.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>referrer (string)</code></td>
<td><code>network.http.referral_url</code></td>
<td></td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.application_protocol_version</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>network.http.user_agent</code></td>
<td></td>
</tr>
<tr>
<td><code>origin (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>network.http.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>about.labels [status_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_code (integer - count)</code></td>
<td><code>about.labels [info_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_msg (string)</code></td>
<td><code>about.labels [info_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>tags (array[string] - set[enum])</code></td>
<td><code>about.labels [tags]</code></td>
<td></td>
</tr>
<tr>
<td><code>username (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>password (string)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td></td>
</tr>
<tr>
<td><code>proxied (array[string] - set[string])</code></td>
<td><code>intermediary.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [orig_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_filenames (array[string] - vector of string)</code></td>
<td><code>src.file.names</code></td>
<td>Il campo log <code>orig_filenames</code> viene mappato sul campo UDM <code>src.file.names</code> quando il valore dell'indice in <code>orig_filenames</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>orig_filenames</code> viene mappato su <code>about.file.names</code>.</td>
</tr>
<tr>
<td><code>orig_mime_types (array[string] - vector of string)</code></td>
<td><code>src.file.mime_type</code></td>
<td>Il campo log <code>orig_mime_types</code> viene mappato sul campo UDM <code>src.file.mime_type</code> quando il valore dell'indice in <code>orig_mime_types</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>orig_mime_types</code> viene mappato su <code>about.file.mime_type</code>.</td>
</tr>
<tr>
<td><code>resp_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [resp_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_filenames (array[string] - vector of string)</code></td>
<td><code>target.file.names</code></td>
<td>Il campo log <code>resp_filenames</code> viene mappato sul campo UDM <code>target.file.names</code> quando il valore dell'indice in <code>resp_filenames</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>resp_filenames</code> viene mappato su <code>about.file.names</code>.</td>
</tr>
<tr>
<td><code>resp_mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>Il campo log <code>resp_mime_types</code> viene mappato sul campo UDM <code>target.file.mime_type</code> quando il valore dell'indice in <code>resp_mime_types</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>resp_mime_types</code> viene mappato su <code>about.file.mime_type</code>.</td>
</tr>
<tr>
<td><code>post_body (string)</code></td>
<td><code>about.labels [post_body]</code></td>
<td></td>
</tr>
<tr>
<td><code>stream_id (integer - count)</code></td>
<td><code>about.labels [stream_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>encoding (string)</code></td>
<td><code>about.labels [encoding]</code></td>
<td></td>
</tr>
<tr>
<td><code>push (boolean - bool)</code></td>
<td><code>about.labels [push]</code></td>
<td></td>
</tr>
<tr>
<td><code>versions (array[float] - vector of float)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>Itera attraverso il campo log <code>versions</code>, quindi<br> se l'indice è uguale a <code>0</code>, il campo log <code>version</code> viene mappato sul campo UDM <code>network.application_protocol_version</code>. <br> Altrimenti, il campo log <code>version_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo log <code>version</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>user_agents (array[string] - vector of string)</code></td>
<td><code>network.http.user_agent</code></td>
<td>Itera attraverso il campo log <code>user_agents</code>, quindi<br> se l'indice è uguale a <code>0</code>, il campo log <code>user_agent</code> viene mappato sul campo UDM <code>network.http.user_agent</code>. <br> Altrimenti, il campo log <code>user_agent_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo log <code>user_agent</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - smtp_links</h3>

La seguente tabella elenca i campi log del tipo di log <code>smtp_links</code> e i relativi campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>link (string)</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domain (string)</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - irc</h3>

La seguente tabella elenca i campi log del tipo di log <code>irc</code> e i relativi campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>nick (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>user (string)</code></td>
<td><code>principal.user.userid</code></td>
<td>Se il valore del campo log <code>user</code> è minore o uguale a 255, allora il campo log <code>user</code> viene mappato sul campo UDM <code>principal.user.userid</code>.<br><br>Altrimenti, il campo log <code>user</code> viene mappato sul campo UDM <code>about.labels</code>.</td>
</tr>
<tr>
<td><code>command, value, addl</code></td>
<td><code>principal.process.command_line</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_size (integer - count)</code></td>
<td><code>src.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_mime_type (string)</code></td>
<td><code>src.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - files, files_red, files_agg</h3>

La seguente tabella elenca i campi log del tipo di log <code>files, files_red, files_agg</code> e i relativi campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mappatura UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_hosts (array[string] - set[addr])</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>rx_hosts (array[string] - set[addr])</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_uids (array[string] - set[string])</code></td>
<td><code>about.labels [conn_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>source (string)</code></td>
<td><code>about.labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>depth (integer - count)</code></td>
<td><code>about.labels [depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>analyzers (array[string] - set[string])</code></td>
<td><code>about.labels [analyzer]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_type (string)</code></td>
<td><code>about.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>filename (string)</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>about.labels [duration]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_orig (boolean - bool)</code></td>
<td><code>about.labels [is_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen_bytes (integer - count)</code></td>
<td><code>about.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>total_bytes (integer - count)</code></td>
<td><code>about.labels [total_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>missing_bytes (integer - count)</code></td>
<td><code>about.labels [missing_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>overflow_bytes (integer - count)</code></td>
<td><code>about.labels [overflow_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>timedout (boolean - bool)</code></td>
<td><code>about.labels [timedout]</code></td>
<td></td>
</tr>
<tr>
<td><code>parent_fuid (string)</code></td>
<td><code>about.labels [parent_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>about.file.md5</code></td>
<td></td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>about.file.sha1</code></td>
<td></td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>about.file.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.client.certificate.md5</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-user-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.client.certificate.md5</code> è impostato su <code>md5</code>.</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.client.certificate.sha1</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-user-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.client.certificate.sha1</code> è impostato su <code>sha1</code>.</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.client.certificate.sha256</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-user-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.client.certificate.sha256</code> è impostato su <code>sha256</code>.</td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.server.certificate.md5</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-ca-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.server.certificate.md5</code> è impostato su <code>md5</code>.</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.server.certificate.sha1</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-ca-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.server.certificate.sha1</code> è impostato su <code>sha1</code>.</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-ca-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.server.certificate.sha256</code> è impostato su <code>sha256</code>.</td>
</tr>
<tr>
<td><code>extracted (array[string] - set[string])</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_cutoff (boolean - bool)</code></td>
<td><code>about.labels [extracted_cutoff]</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_size (integer - count)</code></td>
<td><code>about.labels [extracted_size]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>about.labels [num]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>additional.fields [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan_inner (integer - int)</code></td>
<td><code>additional.fields [vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>Itera attraverso il campo di log <code>mime_type</code>, quindi<br> se l'indice è uguale a <code>0</code>, il campo di log <code>mime_type</code> viene mappato al campo UDM <code>target.file.mime_type</code>. <br> Altrimenti, il campo di log <code>mime_type_%{index}</code> viene mappato al campo UDM <code>additional.fields.key</code> e il campo di log <code>mime_type</code> viene mappato al campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>timedouts (array[boolean] - vector of bool)</code></td>
<td><code>additional.fields[timedouts]</code></td>
<td>Itera attraverso il campo di log <code>timedouts</code>, quindi <br>il campo di log <code>timedout_%{index}</code> viene mappato al campo UDM <code>additional.fields.key</code> e il campo di log <code>timedouts</code> viene mappato al campo UDM <code>additional.fields.value</code>.<br></td>
</tr>

</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mappatura dei campi: CORELIGHT - notice</h3>

La seguente tabella elenca i campi di log del tipo di log <code>notice</code> e i corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mappatura UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>target.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>about.labels [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>note (string - enum)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>msg (string)</code></td>
<td><code>metadata.description</code></td>
<td></td>
</tr>
<tr>
<td><code>sub (string)</code></td>
<td><code>about.labels [sub]</code></td>
<td></td>
</tr>
<tr>
<td><code>src (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>dst (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>p (integer - port)</code></td>
<td><code>about.port</code></td>
<td></td>
</tr>
<tr>
<td><code>n (integer - count)</code></td>
<td><code>about.labels [n]</code></td>
<td></td>
</tr>
<tr>
<td><code>peer_descr (string)</code></td>
<td><code>about.labels [peer_descr]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.action </code></td>
<td>Il campo UDM <code>security_result.action</code> è impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>actions (array[string] - set[enum])</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>suppress_for (number - interval)</code></td>
<td><code>about.labels [suppress_for]</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>Il campo UDM <code>about.location.country_or_region</code> viene impostato con i campi di log <code>remote_location.country_code</code>, <code>remote_location.region</code> come "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>Il campo UDM <code>about.location.country_or_region</code> viene impostato con i campi di log <code>remote_location.country_code</code>, <code>remote_location.region</code> come "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>about.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>about.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>about.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>severity.level</code> contiene uno dei seguenti valori<div style='margin-top: -0.8em;'></div><ul><li><code>0</code></li><li><code> 1</code></li></ul><div style='margin-top: -0.8em;'></div> il campo UDM <code>  security_result.severity </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> è uguale a <code> 2 </code>, il campo UDM <code>  security_result.severity </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> è uguale a <code> 3 </code>, il campo UDM <code>  security_result.severity </code> è impostato su <code>ERROR</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> contiene uno dei seguenti valori<div style='margin-top: -0.8em;'></div><ul><li><code>4</code></li><li><code>5</code></li><li><code>6</code></li></ul><div style='margin-top: -0.8em;'></div> il campo UDM <code>  security_result.severity </code> è impostato su <code>INFORMATIONAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> è uguale a <code> 7 </code>, il campo UDM <code>  security_result.severity </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, il campo UDM <code>  security_result.severity </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>severity.name</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>severity.level</code></td>
<td><code>security_result.detection_fields [severity_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "4 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "3 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "1 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "2 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" </code> oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "0 </code>", il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname (string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain (string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version (string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "4 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "3 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "1 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "2 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" </code> oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "0 </code>", il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname (string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain (string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version (string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source (string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mappatura dei campi: CORELIGHT - smb_files</h3>

La seguente tabella elenca i campi di log del tipo di log <code>smb_files</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_READ</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_READ</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_WRITE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_MODIFICATION</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_OPEN</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_OPEN</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_CLOSE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_UNCATEGORIZED</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_DELETE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_DELETION</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_RENAME</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_MOVE</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_SET_ATTRIBUTE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_UNCATEGORIZED</code>.<br><br>Altrimenti, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>SMB</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td><code>action, name</code></td>
<td><code>metadata.description</code></td>
<td>Il campo UDM <code>metadata.description</code> viene impostato con i campi di log <code>action</code>, <code>name</code> come "action: <code>action</code> on: <code>name</code>".</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>Il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>action (string - enum)</code></td>
<td><code>target.labels [action]</code></td>
<td></td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.file.full_path</code></td>
<td></td>
</tr>
<tr>
<td><code>name (string)</code></td>
<td><code>target.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>size (integer - count)</code></td>
<td><code>target.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>prev_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>times.modified (time)</code></td>
<td><code>target.file.last_modification_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.accessed (time)</code></td>
<td><code>target.file.last_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.created (time)</code></td>
<td><code>target.file.first_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.changed (time)</code></td>
<td><code>target.labels [times_changed]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_offset_req (integer - count)</code></td>
<td><code>target.labels [data_offset_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_req (integer - count)</code></td>
<td><code>target.labels [data_len_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_rsp (integer - count)</code></td>
<td><code>target.labels [data_len_rsp]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - smb_mapping</h3>

La tabella seguente elenca i campi di log del tipo di log <code>smb_mapping</code> e i loro corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>SMB</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>Il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.resource.attribute.labels [path]</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>target.application</code></td>
<td></td>
</tr>
<tr>
<td><code>native_file_system (string)</code></td>
<td><code>target.resource.attribute.labels [native_file_system]</code></td>
<td></td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_type</code></td>
<td>Se il valore del campo di log <code>share_type</code> è uguale a <code>DISK</code>, il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>STORAGE_OBJECT</code>.<br><br>Altrimenti, se il valore del campo di log <code>share_type</code> è uguale a <code>PIPE</code>, il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>PIPE</code>.<br><br>Altrimenti, il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>UNSPECIFIED</code>.</td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_subtype</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - ssl, ssl_red, ssl_agg</h3>

La tabella seguente elenca i campi di log del tipo di log <code>ssl, ssl_red, ssl_agg</code> e i loro corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>HTTPS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>Il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.tls.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>curve (string)</code></td>
<td><code>network.tls.curve</code></td>
<td></td>
</tr>
<tr>
<td><code>server_name (string)</code></td>
<td><code>network.tls.client.server_name</code></td>
<td></td>
</tr>
<tr>
<td><code>resumed (boolean - bool)</code></td>
<td><code>network.tls.resumed</code></td>
<td></td>
</tr>
<tr>
<td><code>last_alert (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>next_protocol (string)</code></td>
<td><code>network.tls.next_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>established (boolean - bool)</code></td>
<td><code>network.tls.established</code></td>
<td></td>
</tr>
<tr>
<td><code>ssl_history (string)</code></td>
<td><code>about.labels [ssl_history]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>target.labels [cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>principal.labels [client_cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>sni_matches_cert (boolean - bool)</code></td>
<td><code>about.labels [sni_matches_cert]</code></td>
<td></td>
</tr>
<tr>
<td><code>validation_status (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3 (string)</code></td>
<td><code>network.tls.client.ja3</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3s (string)</code></td>
<td><code>network.tls.server.ja3s</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - rdp</h3>

La tabella seguente elenca i campi di log del tipo di log <code>rdp</code> e i loro corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>cookie (string)</code></td>
<td><code>principal.user.userid</code></td>
<td></td>
</tr>
<tr>
<td><code>result (string)</code></td>
<td><code>about.labels [result]</code></td>
<td></td>
</tr>
<tr>
<td><code>security_protocol (string)</code></td>
<td><code>target.labels [security_protocol]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_channels (array[string] - vector of string)</code></td>
<td><code>intermediary.labels [client_channels]</code></td>
<td></td>
</tr>
<tr>
<td><code>keyboard_layout (string)</code></td>
<td><code>principal.labels [keyboard_layout]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_build (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>client_name (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>client_dig_product_id (string)</code></td>
<td><code>principal.asset.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_width (integer - count)</code></td>
<td><code>principal.labels [desktop_width]</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_height (integer - count)</code></td>
<td><code>principal.labels [desktop_height]</code></td>
<td></td>
</tr>
<tr>
<td><code>requested_color_depth (string)</code></td>
<td><code>principal.labels [requested_color_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_type (string)</code></td>
<td><code>about.labels [cert_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_count (integer - count)</code></td>
<td><code>about.labels [cert_count]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_permanent (boolean - bool)</code></td>
<td><code>about.labels [cert_permanent ]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_level (string)</code></td>
<td><code>about.labels [encryption_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_method (string)</code></td>
<td><code>about.labels [encryption_method]</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>Se il valore del campo di log <code>auth_success</code> è uguale a <code>true</code>, il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>. <br> Altrimenti, il campo UDM <code>security_result.action</code> viene impostato su <code>FAIL</code>.</td>
</tr>
<tr>
<td><code>channels_joined (integer - int)</code></td>
<td><code>intermediary.labels [channels_joined]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>about.labels [inferences]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdpeudp_uid (string)</code></td>
<td><code>about.labels [rdpeudp_uid]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td><code>rdfp_string (string)</code></td>
<td><code>principal.labels [rdfp_string]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdfp_hash (string)</code></td>
<td><code>principal.labels [rdfp_hash]</code></td>
<td></td>
</tr>
<tr>
<td><code>result, security_protocol</code></td>
<td><code>security_result.description</code></td>
<td>Il campo UDM <code>security_result.description</code> viene impostato con i campi di log <code>result</code>, <code>security_protocol</code> come "<code>result</code> connection with security protocol <code>security_protocol</code>".</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - sip</h3>

La tabella seguente elenca i campi di log del tipo di log <code>sip</code> e i loro corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>SIP</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>about.labels [method]</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_from (string)</code></td>
<td><code>principal.labels [request_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_to (string)</code></td>
<td><code>target.labels [request_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_from</code></td>
<td><code>principal.labels [response_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_to (string)</code></td>
<td><code>target.labels [response_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>about.labels [reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>call_id (string)</code></td>
<td><code>about.labels[call_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>seq (string)</code></td>
<td><code>about.labels [seq]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>about.labels [subject]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_path (array[string] - vector of string)</code></td>
<td><code>about.labels [request_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_path (array[string] - vector of string)</code></td>
<td><code>about.labels [response_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>about.labels [user_agent]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>about.labels [status_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>warning (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>content_type (string)</code></td>
<td><code>about.labels [content_type]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - intel</h3>

La tabella seguente elenca i campi di log del tipo di log <code>intel</code> e i loro corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>SCAN_NETWORK</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.metadata.entity_type</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::ADDR</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>IP_ADDRESS</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::SUBNET</code> o <code>Intel::SOFTWARE</code> o <code>Intel::CERT_HASH</code> o <code>Intel::PUBKEY_HASH</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>RESOURCE</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::URL</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>URL</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::EMAIL</code> o <code>Intel::USER_NAME</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>USER</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::DOMAIN</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>DOMAIN_NAME</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::FILE_HASH</code> o <code>Intel::FILE_NAME</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>FILE</code>.<br><br>Altrimenti, il campo UDM <code>metadata.entity_type</code> è impostato su <code>RESOURCE</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.ip</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::ADDR</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.ip</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.url</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::URL</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.url</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.domain.name</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::DOMAIN</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.domain.name</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.user.email_address</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::USER_NAME</code> o <code>Intel::EMAIL</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.user.email_address</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.file.names</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::FILE_HASH</code> o <code>Intel::FILE_NAME</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.file.full_path</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.resource.name</code></td>
<td>Se il valore del campo di log <code>metadata.entity_type</code> è uguale a <code>RESOURCE</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.resource.name</code>.</td>
</tr>
<tr>
<td></td>
<td><code>entity.resource.resource_type</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::SUBNET</code>, allora il campo UDM <code>entity.resource.resource_name</code> è impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.resource.resource_sub_type</code></td>
<td>Se il valore del campo di log <code>metadata.entity_type</code> è uguale a <code>RESOURCE</code>, allora il campo di log <code>seen.indicator_type</code> è mappato sul campo UDM <code>entity.resource.resource_sub_type</code>.</td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>entity.metadata.source_labels [seen_where]</code></td>
<td></td>
</tr>
<tr>
<td><code>matched (array[string] - set[enum])</code></td>
<td><code>entity.labels [matched]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>entity.metadata.source_labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>entity.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>metadata.threat.detection_fields [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>desc (array[string] - set[string])</code></td>
<td><code>ioc.description</code></td>
<td>Il campo di log <code>desc</code> è mappato sul campo UDM <code>ioc.description</code> quando il valore dell'indice in <code>desc</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>desc</code> e  il campo di log <code>desc</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>url (array[string] - set[string])</code></td>
<td><code>metadata.threat.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>ioc.confidence_score</code></td>
<td>Il campo di log <code>confidence</code> è mappato sul campo UDM <code>ioc.confidence_score</code> quando il valore dell'indice in <code>confidence</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>confidence</code> e  il campo di log <code>confidence</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>firstseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.start</code></td>
<td>Il campo di log <code>firstseen</code> è mappato sul campo UDM <code>ioc.active_timerange.start</code> quando il valore dell'indice in <code>firstseen</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>firstseen</code> e  il campo di log <code>firstseen</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>lastseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.end</code></td>
<td>Il campo di log <code>lastseen</code> è mappato sul campo UDM <code>ioc.active_timerange.end</code> quando il valore dell'indice in <code>lastseen</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>lastseen</code> e  il campo di log <code>lastseen</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>associated (array[string] - set[string])</code></td>
<td><code>entity.labels [associated]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>ioc.categorization</code></td>
<td>Il campo di log <code>category</code> è mappato sul campo UDM <code>ioc.categorization</code> quando il valore dell'indice in <code>category</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>category</code> e  il campo di log <code>category</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>campaigns (array[string] - set[string])</code></td>
<td><code>entity.labels [campaign]</code></td>
<td></td>
</tr>
<tr>
<td><code>reports (array[string] - set[string])</code></td>
<td><code>entity.labels [report]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>about.labels [indicator]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>about.labels [indicator_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>about.labels [where]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>about.labels [sources]</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>about.labels [confidence]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>about.labels [category]</code></td>
<td></td>
</tr>
<tr>
<td><code>threat_score (array[number] - set[double])</code></td>
<td><code>entity.security_result.detection_fields[threat_score]</code></td>
<td></td>
</tr>
<tr>
<td><code>verdict (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.verdict_response</code></td>
<td>Itera attraverso <code>verdict</code>,<div style='margin-bottom: 0.5em;'></div><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>verdict</code> corrisponde al pattern di espressione regolare <code> "(?i)Malicious" or the <code>verdict</code> log field value is equal to <code> "1" </code> </code> allora, il campo UDM <code>        "entity.security_result.verdict_info.verdict_response" </code> è impostato su <code>MALICIOUS</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>verdict</code> corrisponde al pattern di espressione regolare <code> "(?i)Benign" or the <code>verdict</code> log field value is equal to <code> "2" </code> </code> allora, il campo UDM <code>        "entity.security_result.verdict_info.verdict_response" </code> è impostato su <code>BENIGN</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti il campo UDM <code>        "entity.security_result.verdict_info.verdict_response" </code> è impostato su <code>VERDICT_RESPONSE_UNSPECIFIED</code>. <br></td>
</tr>
<tr>
<td><code>verdict_source (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.source_provider</code></td>
<td>Itera attraverso <code>verdict_source</code>,<div style='margin-bottom: 0.5em;'></div>Il campo di log <code>verdict_source</code> è mappato sul campo UDM <code>    entity.security_result.VerdictInfo.source_provider </code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento mapping dei campi: CORELIGHT - smtp</h3>

La seguente tabella elenca i campi di log del tipo di log <code>smtp</code> e i corrispondenti campi UDM.

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>helo (string)</code></td>
<td><code>network.smtp.helo</code></td>
<td></td>
</tr>
<tr>
<td><code>mailfrom (string)</code></td>
<td><code>network.smtp.mail_from</code></td>
<td></td>
</tr>
<tr>
<td><code>rcptto (array[string] - set[string])</code></td>
<td><code>network.smtp.rcpt_to</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>from (string)</code></td>
<td><code>network.email.from</code></td>
<td></td>
</tr>
<tr>
<td><code>to (array[string] - set[string])</code></td>
<td><code>network.email.to</code></td>
<td></td>
</tr>
<tr>
<td><code>cc (array[string] - set[string])</code></td>
<td><code>network.email.cc</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>network.email.reply_to</code></td>
<td></td>
</tr>
<tr>
<td><code>msg_id (string)</code></td>
<td><code>network.email.mail_id</code></td>
<td></td>
</tr>
<tr>
<td><code>in_reply_to (string)</code></td>
<td><code>about.labels [in_reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>network.email.subject</code></td>
<td></td>
</tr>
<tr>
<td><code>x_originating_ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>first_received (string)</code></td>
<td><code>about.labels [first_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>second_received (string)</code></td>
<td><code>about.labels [second_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>last_reply (string)</code></td>
<td><code>network.smtp.server_response</code></td>
<td></td>
</tr>
<tr>
<td><code>path (array[string] - vector of addr)</code></td>
<td><code>network.smtp.message_path</code></td>
<td>Itera attraverso il campo di log <code>path</code>, quindi<br> se il valore di <code>index</code> è uguale a <code>0</code> allora, il campo di log <code>path</code> è mappato sul campo UDM <code>network.smtp.message_path</code>. <br> Altrimenti, il campo di log <code>path</code> è mappato sul campo UDM <code>intermediary.ip</code>.<br></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>principal.application</code></td>
<td></td>
</tr>
<tr>
<td><code>tls (boolean - bool)</code></td>
<td><code>network.smtp.is_tls</code></td>
<td></td>
</tr>
<tr>
<td><code>fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_webmail (boolean - bool)</code></td>
<td><code>network.smtp.is_webmail</code></td>
<td></td>
</tr>
<tr>
<td><code>urls (array[string] - set[string])</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domains (array[string] - set[string])</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento mapping dei campi: CORELIGHT - ssh</h3>

La seguente tabella elenca i campi di log del tipo di log <code>ssh</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mappatura UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>SSH</code>.</td>
</tr>
<tr>
<td><code>version (integer - count)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>Il campo UDM <code>network.application_protocol_version</code> viene impostato con il campo di log <code>version</code> come "SSH <code>version</code>".</td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>Se il valore del campo di log <code>auth_success</code> <em>non</em> è uguale a <code>true</code>, il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.<br><br>Altrimenti, il campo UDM <code>security_result.action</code> viene impostato su <code>BLOCK</code>.</td>
</tr>
<tr>
<td><code>auth_attempts (integer - count)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td>Il campo UDM <code>extensions.auth.auth_details</code> viene impostato con il campo di log <code>auth_attempts</code> come "auth_attempts: <code>auth_attempts</code>".</td>
</tr>
<tr>
<td><code>direction (string - enum)</code></td>
<td><code>network.direction</code></td>
<td>Se il valore del campo di log <code>direction</code> è uguale a <code>INBOUND</code>, il campo UDM <code>network.direction</code> viene impostato su <code>INBOUND</code>.<br><br>Altrimenti, se il valore del campo di log <code>direction</code> è uguale a <code>OUTBOUND</code>, il campo UDM <code>network.direction</code> viene impostato su <code>OUTBOUND</code>.</td>
</tr>
<tr>
<td><code>client (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>server (string)</code></td>
<td><code>target.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher_alg (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>mac_alg (string)</code></td>
<td><code>security_result.detection_fields [mac_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>compression_alg (string)</code></td>
<td><code>security_result.detection_fields [compression_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>kex_alg (string)</code></td>
<td><code>security_result.detection_fields [kex_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key_alg (string)</code></td>
<td><code>network.tls.server.certificate.version</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>target.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>target.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>target.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshVersion (string)</code></td>
<td><code>about.labels [hassh_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>hassh (string)</code></td>
<td><code>principal.labels [hassh]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServer (string)</code></td>
<td><code>target.labels [hassh_server]</code></td>
<td></td>
</tr>
<tr>
<td><code>cshka (string)</code></td>
<td><code>about.labels [cshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshAlgorithms (string)</code></td>
<td><code>about.labels [hassh_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>sshka (string)</code></td>
<td><code>about.labels [sshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServerAlgorithms (string)</code></td>
<td><code>about.labels [hassh_server_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>security_result.summary, security_result.description, security_result.detection_fields[inferences]</code></td>
<td>Se il valore del campo di log <code>inferences</code> è uguale a <code>ABP</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Authentication Bypass</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client wasn't adhering to expectations of SSH either through server exploit or by the client and server switching to a protocol other than SSH after encryption begins</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>AFR</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>SSH Agent Forwarding Requested</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>Agent Forwarding is requested by the Client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>APWA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Automated Password Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client authenticated with an automated password tool (like sshpass)</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>AUTO</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Automated Interaction</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client is a script automated utility and not driven by a user</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>BAN</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Server Banner</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The server sent the client a pre-authentication banner, likely for legal reasons</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>BF</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Brute Force Guessing</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>BFS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Brute Force Success</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>CTS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Trusted Server</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client already has an entry in its known_hosts file for this server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>CUS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Untrusted Server</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client did not have an entry in its known_hosts file for this server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>IPWA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Interactive Password Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client interactively typed their password to authenticate</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>KS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Keystrokes</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>An interactive session occurred in which the client set user-driven keystrokes to the server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>LFD</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Large Client File Download</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>LFU</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Large Client File Upload</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the client sent a sequence of bytes to the server. Large file are identified dynamically based on trains of MTU-sized packets</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>MFA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Multifactor Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The server required a second form of authentication (a code) after password or public key was accepted, and the client successfully provided it</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>NA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>None Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client successfully authenticated using the None method</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>NRC</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>No Remote Command</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The -N flag was used in SSH authentication</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>PKA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Public Key Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client automatically authenticated using pubkey authentication</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSI</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Initiated</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The Reverse session is initiated from the server back to the client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSIA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Initiated Automated</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The inititation of the Reverse session happened very early in the packet stream, indicating automation</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSK</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Keystrokes</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>Keystrokes are detected within the Reverse tunnel</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSL</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Logged In</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The Reverse Tunnel login has succeeded</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSP</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Provisioned</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client connected with -R flag, which provisions the port to be used for a Reverse Session set up at any future time</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Authentication Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client scanned authentication method with the server and then disconnected</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SC</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Capabilities Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client exchanged capabilities with the server and then disconnected</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SFD</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Small Client File Download</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SFU</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Small Client File Upload</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the client sent a sequence of bytes to the server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SP</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Other Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client and server didn't exchange encrypted packets but the client wasn't a version or capabilities scanner</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SV</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Version Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client exchanged version strings with the server and than disconnected</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>UA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Unknown Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The authentication method is not determinated or is unknown</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mappatura dei campi: CORELIGHT - suricata_corelight</h3>

La tabella seguente elenca i campi di log del tipo di log <code>suricata_corelight</code> e i relativi campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>SCAN_NETWORK</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Suricata</code>.</td>
</tr>
<tr>
<td><code>id.vlan (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_type (integer - count)</code></td>
<td><code>about.labels [icmp_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_code (integer - count)</code></td>
<td><code>about.labels [icmp_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_id (string)</code></td>
<td><code>metadata.product_log_id</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>flow_id (integer - count)</code></td>
<td><code>about.labels[flow_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_id (integer - count)</code></td>
<td><code>about.labels [tx_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>pcap_cnt (integer - count)</code></td>
<td><code>about.labels [pcap_cnt]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.action (string)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.gid (integer - count)</code></td>
<td><code>security_result.detection_fields [alert_gid]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature_id (integer - count)</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rev (integer - count)</code></td>
<td><code>security_result.rule_version</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.rule_name</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.category (string)</code></td>
<td><code>security_result.category_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.severity (integer - count)</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[alert_metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload]</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>signature_severity</code></td>
<td><code>security_result.severity</code></td>
<td>Se il valore del campo di log <code>alert.rule</code> corrisponde al pattern grok <code>signature_severity (?<signature_severity>Critical|Major|Minor|Informational)</code> allora <div style='margin-bottom: 0.0em;'></div>Se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Critical</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>CRITICAL</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code>security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Major</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>MEDIUM</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code> security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Minor</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>LOW</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code>security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Informational</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>INFORMATIONAL</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code>security_result.severity_details</code>.<br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname(string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain(string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version(string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source(string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname(string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain(string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version(string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rule (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.references (array[string] - vector of string)</code></td>
<td><code>security_result.detection_fields[alert_references]</code></td>
<td>itera attraverso alert.references,<div style='margin-bottom: 0.5em;'></div>il campo di log <code>alert.references</code> viene mappato al campo UDM <code> security_result.detection_fields.alert_references </code>.</td>
</tr>
<tr>
<td><code>payload_printable (string)</code></td>
<td><code>security_result.detection_fields[payload_printable]</code></td>
<td></td>
</tr>
<tr>
<td><code>references (array[string] - vector of string)</code></td>
<td><code>security_result.detection_fields[references]</code></td>
<td>itera attraverso references,<div style='margin-bottom: 0.5em;'></div>il campo di log <code>references</code> viene mappato al campo UDM <code> security_result.detection_fields.references </code>.</td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "4" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "3" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "1" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "2" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "0" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "4 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "3 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "1 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "2 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "0 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>rule_content</code></td>
<td><code>security_result.detection_fields[alert_rule_content]</code></td>

Read more

Scarica lo strumento