
Parser di Chronicle per CORELIGHT e informazioni correlate.
Questo documento descrive come raccogliere i log di Corelight Sensor configurando Corelight Sensor e un forwarder di Chronicle. Questo documento elenca anche i tipi di log supportati e le versioni di Corelight supportate.
Per maggiori informazioni, consulta Ingestione dei dati in Chronicle.
Il seguente diagramma dell'architettura di distribuzione illustra come Corelight Sensor è configurato per inviare log a Google Security Operations utilizzando due diverse architetture di ingestione. È importante notare che ogni distribuzione del cliente può differire da questa rappresentazione e potrebbe essere più complessa.
Un'etichetta di ingestione identifica il parser che normalizza i dati di log grezzi nel formato strutturato UDM. Le informazioni contenute in questo documento si applicano al parser con etichetta di ingestione CORELIGHT.

Il diagramma dell'architettura mostra i seguenti componenti:
Corelight Sensor: Il sistema che esegue Corelight Sensor .
Exporter di Corelight Sensor: L'exporter di Corelight Sensor raccoglie i dati di log dal Sensor e li inoltra a Google Security Operations.
Google Security Operations: Google Security Operations conserva e analizza i log provenienti da Corelight Sensor.
Utilizza l'interfaccia web di Sensor o Fleet Manager per configurare l'exporter di Google SecOps. Questa configurazione utilizza le credenziali API della tua istanza di Google SecOps per stabilire la connessione sicura.
Accedi all'interfaccia web di Fleet Manager o Sensor di Corelight Sensor come amministratore.
Vai all'area di configurazione dell'exporter:
Nella sezione Create Exporter, fai clic su Google SecOps.




Il diagramma dell'architettura mostra i seguenti componenti:
Corelight Sensor: Il sistema che esegue Corelight Sensor .
Exporter di Corelight Sensor: L'exporter di Corelight Sensor raccoglie i dati di log dal Sensor e li inoltra al forwarder di Google Security Operations.
Forwarder di Google Security Operations: Il forwarder di Google Security Operations è un componente software leggero, distribuito nella rete del cliente, che supporta syslog. Il forwarder di Google Security Operations inoltra i log a Google Security Operations.
Google Security Operations: Google Security Operations conserva e analizza i log provenienti da Corelight Sensor.
Per configurare il forwarder di Google Security Operations, procedi come segue:
Configura un forwarder di Google Security Operations. Consulta Installa e configura il forwarder su Linux.
Configura il forwarder di Google Security Operations per inviare i log a Google Security Operations. ```none collectors:
### Configura l'exporter di Corelight Sensor
1. Accedi a Corelight Sensor come amministratore.
2. Seleziona la scheda **Export**.
3. Trova e abilita l'opzione **EXPORT TO SYSLOG**.
4. Nella sezione **EXPORT TO SYSLOG**, configura i seguenti campi:
* **SYSLOG SERVER**: Specifica l'indirizzo IP e la porta del listener syslog del forwarder di Google Security Operations.
* Vai a **Advanced Settings > SYSLOG FORMAT** e modifica l'impostazione su **Legacy**.

5. Fai clic su **Apply Changes**.
## Tipi di log Corelight supportati
Il parser Corelight supporta i seguenti tipi di log:
<div class="fixed" translate="no">
<h4>Log Type</h4>
<ul>
<li>asset_classification</li>
<li>conn</li>
<li>conn_long</li>
<li>conn_red</li>
<li>conn_agg</li>
<li>dce_rpc</li>
<li>dns</li>
<li>dns_red</li>
<li>files</li>
<li>files_red</li>
<li>http</li>
<li>http2</li>
<li>http_red</li>
<li>intel</li>
<li>irc</li>
<li>notice</li>
<li>rdp</li>
<li>sip</li>
<li>smb_files</li>
<li>smb_mapping</li>
<li>smtp</li>
<li>smtp_links</li>
<li>ssh</li>
<li>ssl</li>
<li>ssl_red</li>
<li>suricata_corelight</li>
<li>bacnet</li>
<li>cip</li>
<li>corelight_burst</li>
<li>corelight_metrics_bro</li>
<li>corelight_metrics_disk</li>
<li>corelight_metrics_iface</li>
<li>corelight_metrics_memory</li>
<li>corelight_metrics_system</li>
<li>corelight_metrics_zeek_doctor</li>
<li>corelight_overall_capture_loss</li>
<li>corelight_profiling</li>
<li>datared</li>
<li>dga</li>
<li>dhcp</li>
<li>dnp3</li>
<li>dpd</li>
<li>encrypted_dns</li>
<li>enip</li>
<li>enip_debug</li>
<li>enip_list_identity</li>
<li>etc_viz</li>
<li>ftp</li>
<li>generic_dns_tunnels</li>
<li>generic_icmp_tunnels</li>
<li>icmp_specific_tunnels</li>
<li>ipsec</li>
<li>iso_cotp</li>
<li>kerberos</li>
<li>known_certs</li>
<li>known_devices</li>
<li>known_domains</li>
<li>known_hosts</li>
<li>known_names</li>
<li>known_remotes</li>
<li>known_services</li>
<li>known_users</li>
<li>ldap</li>
<li>ldap_search</li>
<li>local_subnets</li>
<li>local_subnets_dj</li>
<li>local_subnets_graphs</li>
<li>log4shell</li>
<li>modbus</li>
<li>mqtt_connect</li>
<li>mqtt_publish</li>
<li>mqtt_subscribe</li>
<li>mysql</li>
<li>napatech_shunting</li>
<li>ntlm</li>
<li>ntp</li>
<li>pe</li>
<li>profinet</li>
<li>profinet_dce_rpc</li>
<li>profinet_debug</li>
<li>radius</li>
<li>reporter</li>
<li>rfb</li>
<li>s7comm</li>
<li>smartpcap</li>
<li>snmp</li>
<li>socks</li>
<li>software</li>
<li>specific_dns_tunnels</li>
<li>stepping</li>
<li>stun</li>
<li>stun_nat</li>
<li>suricata_eve</li>
<li>suricata_stats</li>
<li>syslog</li>
<li>tds</li>
<li>tds_rpc</li>
<li>tds_sql_batch</li>
<li>traceroute</li>
<li>tunnel</li>
<li>unknown-smartpcap</li>
<li>vpn</li>
<li>weird</li>
<li>weird_red</li>
<li>wireguard</li>
<li>x509</li>
<li>x509_red</li>
<li>dns_agg</li>
<li>files_agg</li>
<li>http_agg</li>
<li>ssl_agg</li>
<li>weird_agg</li>
<li>analyzer</li>
<li>anomaly</li>
<li>ssdp</li>
<li>telnet</li>
<li>websocket</li>
<li>first_seen</li>
</ul>
</div>
## Riferimento per il mapping dei campi
Questa sezione spiega come il parser di Google Security Operations mappa i campi di Google Security Operations sui campi del Unified Data Model (UDM) di Google Security Operations.
<h3>Riferimento per il mapping dei campi: CORELIGHT - Campi comuni </h3>
La tabella seguente elenca i campi comuni del log <code>CORELIGHT</code> e i corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.vendor_name</code></td>
<td>The <code>metadata.vendor_name</code> UDM field is set to <code>Corelight</code>.</td>
</tr>
<tr>
<td><code>_path (string)</code></td>
<td><code>metadata.product_event_type</code></td>
<td></td>
</tr>
<tr>
<td><code>_system_name (string)</code></td>
<td><code>observer.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>ts (time)</code></td>
<td><code>metadata.event_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>uid (string)</code></td>
<td><code>about.labels [uid], network.session_id</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_h (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_p (integer - port)</code></td>
<td><code>principal.port</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_h (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_p (integer - port)</code></td>
<td><code>target.port</code></td>
<td></td>
</tr>
<tr>
<td><code>_write_ts</code></td><code></code>
<td><code>metadata.collected_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan (integer - int)</code></td>
<td><code>additional.fields [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - int)</code></td>
<td><code>additional.fields [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_cid (string)</code></td>
<td><code>additional.fields [id_orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_source (string)</code></td>
<td><code>additional.fields [id_orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_status (string)</code></td>
<td><code>additional.fields [id_orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_uid (string)</code></td>
<td><code>additional.fields [id_orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_cid (string)</code></td>
<td><code>additional.fields [id_resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_source (string)</code></td>
<td><code>additional.fields [id_resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_status (string)</code></td>
<td><code>additional.fields [id_resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_uid (string)</code></td>
<td><code>additional.fields [id_resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>uids (array[string] - vector of string)</code></td>
<td><code>additional.fields [uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>count (integer - int)</code></td>
<td><code>additional.fields [count]</code></td>
<td></td>
</tr>
<tr>
<td><code>ts_last</code></td>
<td><code>additional.fields [ts_last]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - asset_classification</h3>
La tabella seguente elenca i campi del log di tipo <code>asset_classification</code> e i corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>STATUS_UPDATE</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>mac</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>vendor_mac (string)</code></td>
<td><code>about.asset.hardware.manufacturer</code></td>
<td></td>
</tr>
<tr>
<td><code>device_type (string)</code></td>
<td><code>about.asset.category</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.platform</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.asset.attribute.labels</code></td>
<td></td>
</tr>
<tr>
<td><code>type_group (string)</code></td>
<td><code>about.group.group_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>type_name (string)</code></td>
<td><code>about.resource.resource_subtype</code></td>
<td>The <code>about.resource.resource_type</code> UDM field is set to <code>DEVICE</code></td>
</tr>
<tr>
<td><code>brand (string)</code></td>
<td><code>about.user.company_name</code></td>
<td></td>
</tr>
<tr>
<td><code>model (string)</code></td>
<td><code>about.asset.hardware.model</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (integer)</code></td>
<td><code>about.security_result.confidence_score</code></td>
<td></td>
</tr>
<tr>
<td><code>os_ver (string)</code></td>
<td><code>about.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string])</code></td>
<td><code>about.ip_geo_artifact.tags</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - conn, conn_red, conn_long, conn_agg</h3>
La tabella seguente elenca i campi del log di tipo <code>conn, conn_red, conn_long, conn_agg</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_bytes (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_bytes (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_state (string)</code></td>
<td><code>metadata.description</code></td>
<td>Se il valore del campo di log <code>conn_state</code> è uguale a <code>S0</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S0: Connection attempt seen, no reply</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>S1</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S1: Connection established, not terminated</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>S2</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S2: Connection established and close attempt by originator seen (but no reply from responder)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>S3</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>S3: Connection established and close attempt by responder seen (but no reply from originator)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>SF</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>SF: Normal SYN/FIN completion</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>REJ</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>REJ: Connection attempt rejected</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTO</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTO: Connection established, originator aborted (sent a RST)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTOS0</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTOSH</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>RSTR</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>RSTR: Established, responder aborted</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>SH</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>SH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open)</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>SHR</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>SHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator</code>.<br><br>Altrimenti, se il valore del campo di log <code>conn_state</code> è uguale a <code>OTH</code>, allora il campo UDM <code>metadata.description</code> viene impostato su <code>OTH: No SYN seen, just midstream traffic (a partial connection that was not later closed)</code>.</td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_resp (boolean - bool)</code></td>
<td><code>about.labels [local_resp]</code></td>
<td></td>
</tr>
<tr>
<td><code>missed_bytes (integer - count)</code></td>
<td><code>about.labels [missed_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>history (string)</code></td>
<td><code>about.labels [history]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_pkts (integer - count)</code></td>
<td><code>network.sent_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ip_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_pkts (integer - count)</code></td>
<td><code>network.received_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ip_bytes (integer - count)</code></td>
<td><code>target.labels [resp_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>tunnel_parents (array[string] - set[string])</code></td>
<td><code>intermediary.labels [tunnel_parent]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cc (string)</code></td>
<td><code>principal.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cc (string)</code></td>
<td><code>target.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_ids (array[string] - set[string])</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.url (string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.rule (integer - count)</code></td>
<td><code>security_result.rule_labels [spcap_rule]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.trigger (string)</code></td>
<td><code>security_result.detection_fields [spcap_trigger]</code></td>
<td></td>
</tr>
<tr>
<td><code>app (array[string] - vector of string)</code></td>
<td><code>about.application</code></td>
<td></td>
</tr>
<tr>
<td><code>corelight_shunted (boolean - bool)</code></td>
<td><code>about.labels [corelight_shunted]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_pkts (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_pkts (integer - count)</code></td>
<td><code>target.labels [resp_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_bytes (integer - count)</code></td>
<td><code>target.labels [resp_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_l2_addr (string)</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_l2_addr (string)</code></td>
<td><code>target.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.src (string)</code></td>
<td><code>principal.labels [id_orig_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.vals (array[string] - set[string])</code></td>
<td><code>principal.labels [id_orig_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.src (string)</code></td>
<td><code>target.labels [id_resp_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.vals (array[string] - set[string])</code></td>
<td><code>target.labels [id_resp_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>intermediary.labels [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>inner_vlan (integer - int)</code></td>
<td><code>intermediary.labels [inner_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> è impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_cid (string)</code></td>
<td><code>additional.fields [orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_source (string)</code></td>
<td><code>additional.fields [orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_status (string)</code></td>
<td><code>additional.fields [orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_uid (string)</code></td>
<td><code>additional.fields [orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_cid (string)</code></td>
<td><code>additional.fields [resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_source (string)</code></td>
<td><code>additional.fields [resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_status (string)</code></td>
<td><code>additional.fields [resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_uid (string)</code></td>
<td><code>additional.fields [resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>netskope_site_ids</code></td>
<td><code>additional.fields[netskope_site_ids]</code></td>
<td>Iterare sul campo di log <code>netskope_site_ids</code>; quindi <br>il campo di log <code>netskope_site_id_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo di log <code>netskope_site_id</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>netskope_user_ids</code></td>
<td><code>additional.fields[netskope_user_ids]</code></td>
<td>Iterare sul campo di log <code>netskope_user_ids</code>; quindi <br>il campo di log <code>netskope_user_id_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo di log <code>netskope_user_id</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>write_ts</code></td>
<td><code>additional.fields[write_ts]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.urls (array[string] - vector of string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td>Iterare sul campo di log <code>spcap.urls</code>; quindi <br>il campo di log <code>spcap.urls</code> viene mappato sul campo UDM <code>security_result.url_back_to_product</code>.<br></td>
</tr>
<tr>
<td><code>community_ids (array[string] - vector of string)</code></td>
<td><code>network.community_id</code></td>
<td>Iterare sul campo di log <code>community_ids</code>; quindi<br> se l'indice è uguale a <code>0</code>, il campo di log <code>community_id</code> viene mappato sul campo UDM <code>network.community_id</code>. <br> Altrimenti, il campo di log <code>community_id_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo di log <code>community_id</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.version</code></td>
<td><code>about.resource.attribute.labels[vpc_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.vpc_id</code></td>
<td><code>about.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>about.resource.resource_type</code></td>
<td>Se <code>capture_metadata.vpc.vpc_id</code> è presente, allora il campo UDM <code>about.resource.resource_type</code> viene impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>capture_source</code></td>
<td><code>about.resource.attribute.labels[capture_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.az</code></td>
<td><code>principal.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.id</code></td>
<td><code>principal.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.name</code></td>
<td><code>principal.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.org_id</code></td>
<td><code>principal.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.sg_ids</code></td>
<td><code>principal.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.subnet_id</code></td>
<td><code>principal.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.vpc_id</code></td>
<td><code>principal.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>principal.resource.resource_type</code></td>
<td>Se <code>orig_inst.vpc_id</code> è presente, allora il campo UDM <code>principal.resource.resource_type</code> viene impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>orig_inst.profile</code></td>
<td><code>principal.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.az</code></td>
<td><code>target.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.id</code></td>
<td><code>target.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.name</code></td>
<td><code>target.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.org_id</code></td>
<td><code>target.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.sg_ids</code></td>
<td><code>target.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.subnet_id</code></td>
<td><code>target.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.vpc_id</code></td>
<td><code>target.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>target.resource.resource_type</code></td>
<td>Se <code>resp_inst.vpc_id</code> è presente, allora il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>resp_inst.profile</code></td>
<td><code>target.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig</code> and <code>local_resp</code></td>
<td><code>additional.fields[direction]</code></td>
<td>Se il valore del campo di log <code>local_orig</code> è uguale a <code>true</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>true</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>internal</code>.<br><br>Altrimenti, se il valore del campo di log <code>local_orig</code> è uguale a <code>true</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>false</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>outbound</code>.<br><br>Altrimenti, se il valore del campo di log <code>local_orig</code> è uguale a <code>false</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>false</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>external</code>.<br><br>Altrimenti, se il valore del campo di log <code>local_orig</code> è uguale a <code>false</code> e il valore del campo di log <code>local_resp</code> è uguale a <code>true</code>, allora il campo UDM <code>additional.fields[direction]</code> viene impostato su <code>inbound</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - dce_rpc</h3>
La tabella seguente elenca i campi di log del tipo di log <code>dce_rpc</code> e i corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>named_pipe (string)</code></td>
<td><code>intermediary.resource.name</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>intermediary.resource.resource_type</code></td>
<td>Se il valore del campo di log <code>named_pipe</code> <em>non</em> è vuoto, allora il campo UDM <code>intermediary.resource.resource_type</code> viene impostato su <code>PIPE</code>.</td>
</tr>
<tr>
<td><code>endpoint (string)</code></td>
<td><code>target.labels [endpoint]</code></td>
<td></td>
</tr>
<tr>
<td><code>operation (string)</code></td>
<td><code>target.labels [operation]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>DCERPC</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> è impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td><code>operation, endpoint, named_pipe (string)</code></td>
<td><code>metadata.description</code></td>
<td>Il campo UDM <code>metadata.description</code> viene impostato con i campi di log <code>operation</code>, <code>endpoint</code>, <code>named_pipe</code> come "operation <code>operation</code> on <code>endpoint</code> using named pipe <code>named_pipe</code>".</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> è impostato su <code>TCP</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento per il mapping dei campi: CORELIGHT - dns, dns_red, dns_agg</h3>
La tabella seguente elenca i campi di log del tipo di log <code>dns, dns_red, dns_agg</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_DNS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>DNS</code>.</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>trans_id (integer - count)</code></td>
<td><code>network.dns.id</code></td>
<td></td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>query (string)</code></td>
<td><code>network.dns.questions.name</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass (integer - count)</code></td>
<td><code>network.dns.questions.class</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass_name (string)</code></td>
<td><code>about.labels [qclass_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype (integer - count)</code></td>
<td><code>network.dns.questions.type</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype_name (string)</code></td>
<td><code>about.labels [qtype_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response</code></td>
<td>Se il valore del campo log <code>rcode</code> *non* è vuoto, allora il campo UDM <code>network.dns.response</code> è impostato su <code>true</code>.</td>
</tr>
<tr>
<td><code>rcode_name (string)</code></td>
<td><code>about.labels [rcode_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>AA (boolean - bool)</code></td>
<td><code>network.dns.authoritative</code></td>
<td></td>
</tr>
<tr>
<td><code>TC (boolean - bool)</code></td>
<td><code>network.dns.truncated</code></td>
<td></td>
</tr>
<tr>
<td><code>RD (boolean - bool)</code></td>
<td><code>network.dns.recursion_desired</code></td>
<td></td>
</tr>
<tr>
<td><code>RA (boolean - bool)</code></td>
<td><code>network.dns.recursion_available</code></td>
<td></td>
</tr>
<tr>
<td><code>Z (integer - count)</code></td>
<td><code>about.labels [Z]</code></td>
<td></td>
</tr>
<tr>
<td><code>answers (array[string] - vector of string)</code></td>
<td><code>network.dns.answers.name</code></td>
<td></td>
</tr>
<tr>
<td><code>TTLs (array[number] - vector of interval)</code></td>
<td><code>network.dns.answers.ttl</code></td>
<td></td>
</tr>
<tr>
<td><code>rejected (boolean - bool)</code></td>
<td><code>about.labels [rejected]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_trusted_domain (string)</code></td>
<td><code>about.labels [is_trusted_domain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_host_subdomain (string)</code></td>
<td><code>about.labels [icann_host_subdomain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_domain (string)</code></td>
<td><code>network.dns_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_tld (string)</code></td>
<td><code>about.labels [icann_tld]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>security_result.detection_fields [num]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - http, http_red, http2, http_agg</h3>
La seguente tabella elenca i campi log del tipo di log <code>http, http_red, http2, http_agg</code> e i relativi campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_HTTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>network.http.method</code></td>
<td></td>
</tr>
<tr>
<td><code>host (string)</code></td>
<td><code>target.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>referrer (string)</code></td>
<td><code>network.http.referral_url</code></td>
<td></td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.application_protocol_version</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>network.http.user_agent</code></td>
<td></td>
</tr>
<tr>
<td><code>origin (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>network.http.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>about.labels [status_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_code (integer - count)</code></td>
<td><code>about.labels [info_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_msg (string)</code></td>
<td><code>about.labels [info_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>tags (array[string] - set[enum])</code></td>
<td><code>about.labels [tags]</code></td>
<td></td>
</tr>
<tr>
<td><code>username (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>password (string)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td></td>
</tr>
<tr>
<td><code>proxied (array[string] - set[string])</code></td>
<td><code>intermediary.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [orig_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_filenames (array[string] - vector of string)</code></td>
<td><code>src.file.names</code></td>
<td>Il campo log <code>orig_filenames</code> viene mappato sul campo UDM <code>src.file.names</code> quando il valore dell'indice in <code>orig_filenames</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>orig_filenames</code> viene mappato su <code>about.file.names</code>.</td>
</tr>
<tr>
<td><code>orig_mime_types (array[string] - vector of string)</code></td>
<td><code>src.file.mime_type</code></td>
<td>Il campo log <code>orig_mime_types</code> viene mappato sul campo UDM <code>src.file.mime_type</code> quando il valore dell'indice in <code>orig_mime_types</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>orig_mime_types</code> viene mappato su <code>about.file.mime_type</code>.</td>
</tr>
<tr>
<td><code>resp_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [resp_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_filenames (array[string] - vector of string)</code></td>
<td><code>target.file.names</code></td>
<td>Il campo log <code>resp_filenames</code> viene mappato sul campo UDM <code>target.file.names</code> quando il valore dell'indice in <code>resp_filenames</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>resp_filenames</code> viene mappato su <code>about.file.names</code>.</td>
</tr>
<tr>
<td><code>resp_mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>Il campo log <code>resp_mime_types</code> viene mappato sul campo UDM <code>target.file.mime_type</code> quando il valore dell'indice in <code>resp_mime_types</code> è uguale a <code>0</code>. <br><br>Per ogni altro valore di indice, il campo log <code>resp_mime_types</code> viene mappato su <code>about.file.mime_type</code>.</td>
</tr>
<tr>
<td><code>post_body (string)</code></td>
<td><code>about.labels [post_body]</code></td>
<td></td>
</tr>
<tr>
<td><code>stream_id (integer - count)</code></td>
<td><code>about.labels [stream_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>encoding (string)</code></td>
<td><code>about.labels [encoding]</code></td>
<td></td>
</tr>
<tr>
<td><code>push (boolean - bool)</code></td>
<td><code>about.labels [push]</code></td>
<td></td>
</tr>
<tr>
<td><code>versions (array[float] - vector of float)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>Itera attraverso il campo log <code>versions</code>, quindi<br> se l'indice è uguale a <code>0</code>, il campo log <code>version</code> viene mappato sul campo UDM <code>network.application_protocol_version</code>. <br> Altrimenti, il campo log <code>version_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo log <code>version</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>user_agents (array[string] - vector of string)</code></td>
<td><code>network.http.user_agent</code></td>
<td>Itera attraverso il campo log <code>user_agents</code>, quindi<br> se l'indice è uguale a <code>0</code>, il campo log <code>user_agent</code> viene mappato sul campo UDM <code>network.http.user_agent</code>. <br> Altrimenti, il campo log <code>user_agent_%{index}</code> viene mappato sul campo UDM <code>additional.fields.key</code> e il campo log <code>user_agent</code> viene mappato sul campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - smtp_links</h3>
La seguente tabella elenca i campi log del tipo di log <code>smtp_links</code> e i relativi campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>link (string)</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domain (string)</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - irc</h3>
La seguente tabella elenca i campi log del tipo di log <code>irc</code> e i relativi campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>nick (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>user (string)</code></td>
<td><code>principal.user.userid</code></td>
<td>Se il valore del campo log <code>user</code> è minore o uguale a 255, allora il campo log <code>user</code> viene mappato sul campo UDM <code>principal.user.userid</code>.<br><br>Altrimenti, il campo log <code>user</code> viene mappato sul campo UDM <code>about.labels</code>.</td>
</tr>
<tr>
<td><code>command, value, addl</code></td>
<td><code>principal.process.command_line</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_size (integer - count)</code></td>
<td><code>src.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_mime_type (string)</code></td>
<td><code>src.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mapping dei campi: CORELIGHT - files, files_red, files_agg</h3>
La seguente tabella elenca i campi log del tipo di log <code>files, files_red, files_agg</code> e i relativi campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mappatura UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_hosts (array[string] - set[addr])</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>rx_hosts (array[string] - set[addr])</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_uids (array[string] - set[string])</code></td>
<td><code>about.labels [conn_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>source (string)</code></td>
<td><code>about.labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>depth (integer - count)</code></td>
<td><code>about.labels [depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>analyzers (array[string] - set[string])</code></td>
<td><code>about.labels [analyzer]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_type (string)</code></td>
<td><code>about.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>filename (string)</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>about.labels [duration]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_orig (boolean - bool)</code></td>
<td><code>about.labels [is_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen_bytes (integer - count)</code></td>
<td><code>about.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>total_bytes (integer - count)</code></td>
<td><code>about.labels [total_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>missing_bytes (integer - count)</code></td>
<td><code>about.labels [missing_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>overflow_bytes (integer - count)</code></td>
<td><code>about.labels [overflow_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>timedout (boolean - bool)</code></td>
<td><code>about.labels [timedout]</code></td>
<td></td>
</tr>
<tr>
<td><code>parent_fuid (string)</code></td>
<td><code>about.labels [parent_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>about.file.md5</code></td>
<td></td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>about.file.sha1</code></td>
<td></td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>about.file.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.client.certificate.md5</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-user-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.client.certificate.md5</code> è impostato su <code>md5</code>.</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.client.certificate.sha1</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-user-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.client.certificate.sha1</code> è impostato su <code>sha1</code>.</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.client.certificate.sha256</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-user-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.client.certificate.sha256</code> è impostato su <code>sha256</code>.</td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.server.certificate.md5</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-ca-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.server.certificate.md5</code> è impostato su <code>md5</code>.</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.server.certificate.sha1</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-ca-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.server.certificate.sha1</code> è impostato su <code>sha1</code>.</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td>Se il valore del campo di log <code>source</code> è uguale a <code>ssl</code> e il valore del campo di log <code>mime_type</code> è uguale a <code>application/x-x509-ca-cert</code> e il valore del campo di log <code>_path</code> è uguale a <code>files</code>, il campo UDM <code>network.tls.server.certificate.sha256</code> è impostato su <code>sha256</code>.</td>
</tr>
<tr>
<td><code>extracted (array[string] - set[string])</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_cutoff (boolean - bool)</code></td>
<td><code>about.labels [extracted_cutoff]</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_size (integer - count)</code></td>
<td><code>about.labels [extracted_size]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>about.labels [num]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>additional.fields [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan_inner (integer - int)</code></td>
<td><code>additional.fields [vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>Itera attraverso il campo di log <code>mime_type</code>, quindi<br> se l'indice è uguale a <code>0</code>, il campo di log <code>mime_type</code> viene mappato al campo UDM <code>target.file.mime_type</code>. <br> Altrimenti, il campo di log <code>mime_type_%{index}</code> viene mappato al campo UDM <code>additional.fields.key</code> e il campo di log <code>mime_type</code> viene mappato al campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
<tr>
<td><code>timedouts (array[boolean] - vector of bool)</code></td>
<td><code>additional.fields[timedouts]</code></td>
<td>Itera attraverso il campo di log <code>timedouts</code>, quindi <br>il campo di log <code>timedout_%{index}</code> viene mappato al campo UDM <code>additional.fields.key</code> e il campo di log <code>timedouts</code> viene mappato al campo UDM <code>additional.fields.value</code>.<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mappatura dei campi: CORELIGHT - notice</h3>
La seguente tabella elenca i campi di log del tipo di log <code>notice</code> e i corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mappatura UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>target.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>about.labels [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>note (string - enum)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>msg (string)</code></td>
<td><code>metadata.description</code></td>
<td></td>
</tr>
<tr>
<td><code>sub (string)</code></td>
<td><code>about.labels [sub]</code></td>
<td></td>
</tr>
<tr>
<td><code>src (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>dst (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>p (integer - port)</code></td>
<td><code>about.port</code></td>
<td></td>
</tr>
<tr>
<td><code>n (integer - count)</code></td>
<td><code>about.labels [n]</code></td>
<td></td>
</tr>
<tr>
<td><code>peer_descr (string)</code></td>
<td><code>about.labels [peer_descr]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.action </code></td>
<td>Il campo UDM <code>security_result.action</code> è impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>actions (array[string] - set[enum])</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>suppress_for (number - interval)</code></td>
<td><code>about.labels [suppress_for]</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>Il campo UDM <code>about.location.country_or_region</code> viene impostato con i campi di log <code>remote_location.country_code</code>, <code>remote_location.region</code> come "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>Il campo UDM <code>about.location.country_or_region</code> viene impostato con i campi di log <code>remote_location.country_code</code>, <code>remote_location.region</code> come "<code>remote_location.country_code</code>: <code>remote_location.region</code>".</td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>about.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>about.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>about.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>severity.level</code> contiene uno dei seguenti valori<div style='margin-top: -0.8em;'></div><ul><li><code>0</code></li><li><code> 1</code></li></ul><div style='margin-top: -0.8em;'></div> il campo UDM <code> security_result.severity </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> è uguale a <code> 2 </code>, il campo UDM <code> security_result.severity </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> è uguale a <code> 3 </code>, il campo UDM <code> security_result.severity </code> è impostato su <code>ERROR</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> contiene uno dei seguenti valori<div style='margin-top: -0.8em;'></div><ul><li><code>4</code></li><li><code>5</code></li><li><code>6</code></li></ul><div style='margin-top: -0.8em;'></div> il campo UDM <code> security_result.severity </code> è impostato su <code>INFORMATIONAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>severity.level</code> è uguale a <code> 7 </code>, il campo UDM <code> security_result.severity </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, il campo UDM <code> security_result.severity </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>severity.name</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>severity.level</code></td>
<td><code>security_result.detection_fields [severity_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "4 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "3 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "1 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "2 </code>" </code>, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" </code> oppure il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "0 </code>", il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname (string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain (string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version (string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "4 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "3 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "1 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "2 </code>" </code>, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" </code> oppure il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "0 </code>", il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname (string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain (string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version (string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source (string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mappatura dei campi: CORELIGHT - smb_files</h3>
La seguente tabella elenca i campi di log del tipo di log <code>smb_files</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_READ</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_READ</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_WRITE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_MODIFICATION</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_OPEN</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_OPEN</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_CLOSE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_UNCATEGORIZED</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_DELETE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_DELETION</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_RENAME</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_MOVE</code>.<br><br>Altrimenti, se il valore del campo di log <code>action</code> è uguale a <code>SMB::FILE_SET_ATTRIBUTE</code>, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_UNCATEGORIZED</code>.<br><br>Altrimenti, il campo UDM <code>metadata.event_type</code> viene impostato su <code>FILE_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>SMB</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td><code>action, name</code></td>
<td><code>metadata.description</code></td>
<td>Il campo UDM <code>metadata.description</code> viene impostato con i campi di log <code>action</code>, <code>name</code> come "action: <code>action</code> on: <code>name</code>".</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>Il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>action (string - enum)</code></td>
<td><code>target.labels [action]</code></td>
<td></td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.file.full_path</code></td>
<td></td>
</tr>
<tr>
<td><code>name (string)</code></td>
<td><code>target.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>size (integer - count)</code></td>
<td><code>target.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>prev_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>times.modified (time)</code></td>
<td><code>target.file.last_modification_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.accessed (time)</code></td>
<td><code>target.file.last_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.created (time)</code></td>
<td><code>target.file.first_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.changed (time)</code></td>
<td><code>target.labels [times_changed]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_offset_req (integer - count)</code></td>
<td><code>target.labels [data_offset_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_req (integer - count)</code></td>
<td><code>target.labels [data_len_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_rsp (integer - count)</code></td>
<td><code>target.labels [data_len_rsp]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - smb_mapping</h3>
La tabella seguente elenca i campi di log del tipo di log <code>smb_mapping</code> e i loro corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>SMB</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>Il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.resource.attribute.labels [path]</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>target.application</code></td>
<td></td>
</tr>
<tr>
<td><code>native_file_system (string)</code></td>
<td><code>target.resource.attribute.labels [native_file_system]</code></td>
<td></td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_type</code></td>
<td>Se il valore del campo di log <code>share_type</code> è uguale a <code>DISK</code>, il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>STORAGE_OBJECT</code>.<br><br>Altrimenti, se il valore del campo di log <code>share_type</code> è uguale a <code>PIPE</code>, il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>PIPE</code>.<br><br>Altrimenti, il campo UDM <code>target.resource.resource_type</code> viene impostato su <code>UNSPECIFIED</code>.</td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_subtype</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - ssl, ssl_red, ssl_agg</h3>
La tabella seguente elenca i campi di log del tipo di log <code>ssl, ssl_red, ssl_agg</code> e i loro corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>HTTPS</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td>Il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.</td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.tls.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>curve (string)</code></td>
<td><code>network.tls.curve</code></td>
<td></td>
</tr>
<tr>
<td><code>server_name (string)</code></td>
<td><code>network.tls.client.server_name</code></td>
<td></td>
</tr>
<tr>
<td><code>resumed (boolean - bool)</code></td>
<td><code>network.tls.resumed</code></td>
<td></td>
</tr>
<tr>
<td><code>last_alert (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>next_protocol (string)</code></td>
<td><code>network.tls.next_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>established (boolean - bool)</code></td>
<td><code>network.tls.established</code></td>
<td></td>
</tr>
<tr>
<td><code>ssl_history (string)</code></td>
<td><code>about.labels [ssl_history]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>target.labels [cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>principal.labels [client_cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>sni_matches_cert (boolean - bool)</code></td>
<td><code>about.labels [sni_matches_cert]</code></td>
<td></td>
</tr>
<tr>
<td><code>validation_status (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3 (string)</code></td>
<td><code>network.tls.client.ja3</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3s (string)</code></td>
<td><code>network.tls.server.ja3s</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - rdp</h3>
La tabella seguente elenca i campi di log del tipo di log <code>rdp</code> e i loro corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_CONNECTION</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>cookie (string)</code></td>
<td><code>principal.user.userid</code></td>
<td></td>
</tr>
<tr>
<td><code>result (string)</code></td>
<td><code>about.labels [result]</code></td>
<td></td>
</tr>
<tr>
<td><code>security_protocol (string)</code></td>
<td><code>target.labels [security_protocol]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_channels (array[string] - vector of string)</code></td>
<td><code>intermediary.labels [client_channels]</code></td>
<td></td>
</tr>
<tr>
<td><code>keyboard_layout (string)</code></td>
<td><code>principal.labels [keyboard_layout]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_build (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>client_name (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>client_dig_product_id (string)</code></td>
<td><code>principal.asset.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_width (integer - count)</code></td>
<td><code>principal.labels [desktop_width]</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_height (integer - count)</code></td>
<td><code>principal.labels [desktop_height]</code></td>
<td></td>
</tr>
<tr>
<td><code>requested_color_depth (string)</code></td>
<td><code>principal.labels [requested_color_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_type (string)</code></td>
<td><code>about.labels [cert_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_count (integer - count)</code></td>
<td><code>about.labels [cert_count]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_permanent (boolean - bool)</code></td>
<td><code>about.labels [cert_permanent ]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_level (string)</code></td>
<td><code>about.labels [encryption_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_method (string)</code></td>
<td><code>about.labels [encryption_method]</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>Se il valore del campo di log <code>auth_success</code> è uguale a <code>true</code>, il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>. <br> Altrimenti, il campo UDM <code>security_result.action</code> viene impostato su <code>FAIL</code>.</td>
</tr>
<tr>
<td><code>channels_joined (integer - int)</code></td>
<td><code>intermediary.labels [channels_joined]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>about.labels [inferences]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdpeudp_uid (string)</code></td>
<td><code>about.labels [rdpeudp_uid]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>Il campo UDM <code>network.ip_protocol</code> viene impostato su <code>TCP</code>.</td>
</tr>
<tr>
<td><code>rdfp_string (string)</code></td>
<td><code>principal.labels [rdfp_string]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdfp_hash (string)</code></td>
<td><code>principal.labels [rdfp_hash]</code></td>
<td></td>
</tr>
<tr>
<td><code>result, security_protocol</code></td>
<td><code>security_result.description</code></td>
<td>Il campo UDM <code>security_result.description</code> viene impostato con i campi di log <code>result</code>, <code>security_protocol</code> come "<code>result</code> connection with security protocol <code>security_protocol</code>".</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>Il campo UDM <code>security_result.severity</code> viene impostato su <code>INFORMATIONAL</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - sip</h3>
La tabella seguente elenca i campi di log del tipo di log <code>sip</code> e i loro corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> viene impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> viene impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> viene impostato su <code>SIP</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>about.labels [method]</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_from (string)</code></td>
<td><code>principal.labels [request_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_to (string)</code></td>
<td><code>target.labels [request_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_from</code></td>
<td><code>principal.labels [response_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_to (string)</code></td>
<td><code>target.labels [response_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>about.labels [reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>call_id (string)</code></td>
<td><code>about.labels[call_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>seq (string)</code></td>
<td><code>about.labels [seq]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>about.labels [subject]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_path (array[string] - vector of string)</code></td>
<td><code>about.labels [request_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_path (array[string] - vector of string)</code></td>
<td><code>about.labels [response_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>about.labels [user_agent]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>about.labels [status_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>warning (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>content_type (string)</code></td>
<td><code>about.labels [content_type]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento al mapping dei campi: CORELIGHT - intel</h3>
La tabella seguente elenca i campi di log del tipo di log <code>intel</code> e i loro corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>SCAN_NETWORK</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.metadata.entity_type</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::ADDR</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>IP_ADDRESS</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::SUBNET</code> o <code>Intel::SOFTWARE</code> o <code>Intel::CERT_HASH</code> o <code>Intel::PUBKEY_HASH</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>RESOURCE</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::URL</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>URL</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::EMAIL</code> o <code>Intel::USER_NAME</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>USER</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::DOMAIN</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>DOMAIN_NAME</code>.<br><br>Altrimenti, se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::FILE_HASH</code> o <code>Intel::FILE_NAME</code>, allora il campo UDM <code>metadata.entity_type</code> è impostato su <code>FILE</code>.<br><br>Altrimenti, il campo UDM <code>metadata.entity_type</code> è impostato su <code>RESOURCE</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.ip</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::ADDR</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.ip</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.url</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::URL</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.url</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.domain.name</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::DOMAIN</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.domain.name</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.user.email_address</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::USER_NAME</code> o <code>Intel::EMAIL</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.user.email_address</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.file.names</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::FILE_HASH</code> o <code>Intel::FILE_NAME</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.file.full_path</code>.</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.resource.name</code></td>
<td>Se il valore del campo di log <code>metadata.entity_type</code> è uguale a <code>RESOURCE</code>, allora il campo di log <code>seen.indicator</code> è mappato sul campo UDM <code>entity.resource.name</code>.</td>
</tr>
<tr>
<td></td>
<td><code>entity.resource.resource_type</code></td>
<td>Se il valore del campo di log <code>indicator.type</code> è uguale a <code>Intel::SUBNET</code>, allora il campo UDM <code>entity.resource.resource_name</code> è impostato su <code>VPC_NETWORK</code>.</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.resource.resource_sub_type</code></td>
<td>Se il valore del campo di log <code>metadata.entity_type</code> è uguale a <code>RESOURCE</code>, allora il campo di log <code>seen.indicator_type</code> è mappato sul campo UDM <code>entity.resource.resource_sub_type</code>.</td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>entity.metadata.source_labels [seen_where]</code></td>
<td></td>
</tr>
<tr>
<td><code>matched (array[string] - set[enum])</code></td>
<td><code>entity.labels [matched]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>entity.metadata.source_labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>entity.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>metadata.threat.detection_fields [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>desc (array[string] - set[string])</code></td>
<td><code>ioc.description</code></td>
<td>Il campo di log <code>desc</code> è mappato sul campo UDM <code>ioc.description</code> quando il valore dell'indice in <code>desc</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>desc</code> e il campo di log <code>desc</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>url (array[string] - set[string])</code></td>
<td><code>metadata.threat.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>ioc.confidence_score</code></td>
<td>Il campo di log <code>confidence</code> è mappato sul campo UDM <code>ioc.confidence_score</code> quando il valore dell'indice in <code>confidence</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>confidence</code> e il campo di log <code>confidence</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>firstseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.start</code></td>
<td>Il campo di log <code>firstseen</code> è mappato sul campo UDM <code>ioc.active_timerange.start</code> quando il valore dell'indice in <code>firstseen</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>firstseen</code> e il campo di log <code>firstseen</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>lastseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.end</code></td>
<td>Il campo di log <code>lastseen</code> è mappato sul campo UDM <code>ioc.active_timerange.end</code> quando il valore dell'indice in <code>lastseen</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>lastseen</code> e il campo di log <code>lastseen</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>associated (array[string] - set[string])</code></td>
<td><code>entity.labels [associated]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>ioc.categorization</code></td>
<td>Il campo di log <code>category</code> è mappato sul campo UDM <code>ioc.categorization</code> quando il valore dell'indice in <code>category</code> è uguale a <code>0</code>.
<br><br>Per ogni altro valore di indice, il campo UDM <code>entity.labels.key</code> è impostato su <code>category</code> e il campo di log <code>category</code> è mappato su <code>entity.labels.value</code>.</td>
</tr>
<tr>
<td><code>campaigns (array[string] - set[string])</code></td>
<td><code>entity.labels [campaign]</code></td>
<td></td>
</tr>
<tr>
<td><code>reports (array[string] - set[string])</code></td>
<td><code>entity.labels [report]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>about.labels [indicator]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>about.labels [indicator_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>about.labels [where]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>about.labels [sources]</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>about.labels [confidence]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>about.labels [category]</code></td>
<td></td>
</tr>
<tr>
<td><code>threat_score (array[number] - set[double])</code></td>
<td><code>entity.security_result.detection_fields[threat_score]</code></td>
<td></td>
</tr>
<tr>
<td><code>verdict (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.verdict_response</code></td>
<td>Itera attraverso <code>verdict</code>,<div style='margin-bottom: 0.5em;'></div><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>verdict</code> corrisponde al pattern di espressione regolare <code> "(?i)Malicious" or the <code>verdict</code> log field value is equal to <code> "1" </code> </code> allora, il campo UDM <code> "entity.security_result.verdict_info.verdict_response" </code> è impostato su <code>MALICIOUS</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>verdict</code> corrisponde al pattern di espressione regolare <code> "(?i)Benign" or the <code>verdict</code> log field value is equal to <code> "2" </code> </code> allora, il campo UDM <code> "entity.security_result.verdict_info.verdict_response" </code> è impostato su <code>BENIGN</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti il campo UDM <code> "entity.security_result.verdict_info.verdict_response" </code> è impostato su <code>VERDICT_RESPONSE_UNSPECIFIED</code>. <br></td>
</tr>
<tr>
<td><code>verdict_source (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.source_provider</code></td>
<td>Itera attraverso <code>verdict_source</code>,<div style='margin-bottom: 0.5em;'></div>Il campo di log <code>verdict_source</code> è mappato sul campo UDM <code> entity.security_result.VerdictInfo.source_provider </code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento mapping dei campi: CORELIGHT - smtp</h3>
La seguente tabella elenca i campi di log del tipo di log <code>smtp</code> e i corrispondenti campi UDM.
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_SMTP</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>SMTP</code>.</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>helo (string)</code></td>
<td><code>network.smtp.helo</code></td>
<td></td>
</tr>
<tr>
<td><code>mailfrom (string)</code></td>
<td><code>network.smtp.mail_from</code></td>
<td></td>
</tr>
<tr>
<td><code>rcptto (array[string] - set[string])</code></td>
<td><code>network.smtp.rcpt_to</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>from (string)</code></td>
<td><code>network.email.from</code></td>
<td></td>
</tr>
<tr>
<td><code>to (array[string] - set[string])</code></td>
<td><code>network.email.to</code></td>
<td></td>
</tr>
<tr>
<td><code>cc (array[string] - set[string])</code></td>
<td><code>network.email.cc</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>network.email.reply_to</code></td>
<td></td>
</tr>
<tr>
<td><code>msg_id (string)</code></td>
<td><code>network.email.mail_id</code></td>
<td></td>
</tr>
<tr>
<td><code>in_reply_to (string)</code></td>
<td><code>about.labels [in_reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>network.email.subject</code></td>
<td></td>
</tr>
<tr>
<td><code>x_originating_ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>first_received (string)</code></td>
<td><code>about.labels [first_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>second_received (string)</code></td>
<td><code>about.labels [second_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>last_reply (string)</code></td>
<td><code>network.smtp.server_response</code></td>
<td></td>
</tr>
<tr>
<td><code>path (array[string] - vector of addr)</code></td>
<td><code>network.smtp.message_path</code></td>
<td>Itera attraverso il campo di log <code>path</code>, quindi<br> se il valore di <code>index</code> è uguale a <code>0</code> allora, il campo di log <code>path</code> è mappato sul campo UDM <code>network.smtp.message_path</code>. <br> Altrimenti, il campo di log <code>path</code> è mappato sul campo UDM <code>intermediary.ip</code>.<br></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>principal.application</code></td>
<td></td>
</tr>
<tr>
<td><code>tls (boolean - bool)</code></td>
<td><code>network.smtp.is_tls</code></td>
<td></td>
</tr>
<tr>
<td><code>fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_webmail (boolean - bool)</code></td>
<td><code>network.smtp.is_webmail</code></td>
<td></td>
</tr>
<tr>
<td><code>urls (array[string] - set[string])</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domains (array[string] - set[string])</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento mapping dei campi: CORELIGHT - ssh</h3>
La seguente tabella elenca i campi di log del tipo di log <code>ssh</code> e i corrispondenti campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mappatura UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>NETWORK_UNCATEGORIZED</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Zeek</code>.</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>Il campo UDM <code>network.application_protocol</code> è impostato su <code>SSH</code>.</td>
</tr>
<tr>
<td><code>version (integer - count)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>Il campo UDM <code>network.application_protocol_version</code> viene impostato con il campo di log <code>version</code> come "SSH <code>version</code>".</td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>Se il valore del campo di log <code>auth_success</code> <em>non</em> è uguale a <code>true</code>, il campo UDM <code>security_result.action</code> viene impostato su <code>ALLOW</code>.<br><br>Altrimenti, il campo UDM <code>security_result.action</code> viene impostato su <code>BLOCK</code>.</td>
</tr>
<tr>
<td><code>auth_attempts (integer - count)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td>Il campo UDM <code>extensions.auth.auth_details</code> viene impostato con il campo di log <code>auth_attempts</code> come "auth_attempts: <code>auth_attempts</code>".</td>
</tr>
<tr>
<td><code>direction (string - enum)</code></td>
<td><code>network.direction</code></td>
<td>Se il valore del campo di log <code>direction</code> è uguale a <code>INBOUND</code>, il campo UDM <code>network.direction</code> viene impostato su <code>INBOUND</code>.<br><br>Altrimenti, se il valore del campo di log <code>direction</code> è uguale a <code>OUTBOUND</code>, il campo UDM <code>network.direction</code> viene impostato su <code>OUTBOUND</code>.</td>
</tr>
<tr>
<td><code>client (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>server (string)</code></td>
<td><code>target.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher_alg (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>mac_alg (string)</code></td>
<td><code>security_result.detection_fields [mac_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>compression_alg (string)</code></td>
<td><code>security_result.detection_fields [compression_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>kex_alg (string)</code></td>
<td><code>security_result.detection_fields [kex_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key_alg (string)</code></td>
<td><code>network.tls.server.certificate.version</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>target.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>target.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>target.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshVersion (string)</code></td>
<td><code>about.labels [hassh_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>hassh (string)</code></td>
<td><code>principal.labels [hassh]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServer (string)</code></td>
<td><code>target.labels [hassh_server]</code></td>
<td></td>
</tr>
<tr>
<td><code>cshka (string)</code></td>
<td><code>about.labels [cshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshAlgorithms (string)</code></td>
<td><code>about.labels [hassh_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>sshka (string)</code></td>
<td><code>about.labels [sshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServerAlgorithms (string)</code></td>
<td><code>about.labels [hassh_server_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>security_result.summary, security_result.description, security_result.detection_fields[inferences]</code></td>
<td>Se il valore del campo di log <code>inferences</code> è uguale a <code>ABP</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Authentication Bypass</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client wasn't adhering to expectations of SSH either through server exploit or by the client and server switching to a protocol other than SSH after encryption begins</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>AFR</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>SSH Agent Forwarding Requested</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>Agent Forwarding is requested by the Client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>APWA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Automated Password Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client authenticated with an automated password tool (like sshpass)</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>AUTO</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Automated Interaction</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client is a script automated utility and not driven by a user</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>BAN</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Server Banner</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The server sent the client a pre-authentication banner, likely for legal reasons</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>BF</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Brute Force Guessing</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>BFS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Brute Force Success</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>CTS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Trusted Server</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client already has an entry in its known_hosts file for this server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>CUS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Client Untrusted Server</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client did not have an entry in its known_hosts file for this server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>IPWA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Interactive Password Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client interactively typed their password to authenticate</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>KS</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Keystrokes</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>An interactive session occurred in which the client set user-driven keystrokes to the server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>LFD</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Large Client File Download</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>LFU</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Large Client File Upload</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the client sent a sequence of bytes to the server. Large file are identified dynamically based on trains of MTU-sized packets</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>MFA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Multifactor Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The server required a second form of authentication (a code) after password or public key was accepted, and the client successfully provided it</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>NA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>None Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client successfully authenticated using the None method</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>NRC</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>No Remote Command</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The -N flag was used in SSH authentication</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>PKA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Public Key Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client automatically authenticated using pubkey authentication</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSI</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Initiated</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The Reverse session is initiated from the server back to the client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSIA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Initiated Automated</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The inititation of the Reverse session happened very early in the packet stream, indicating automation</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSK</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Keystrokes</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>Keystrokes are detected within the Reverse tunnel</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSL</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Logged In</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The Reverse Tunnel login has succeeded</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>RSP</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Reverse SSH Provisioned</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client connected with -R flag, which provisions the port to be used for a Reverse Session set up at any future time</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Authentication Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client scanned authentication method with the server and then disconnected</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SC</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Capabilities Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The client exchanged capabilities with the server and then disconnected</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SFD</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Small Client File Download</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SFU</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Small Client File Upload</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A file transfer occurred in which the client sent a sequence of bytes to the server</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SP</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Other Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client and server didn't exchange encrypted packets but the client wasn't a version or capabilities scanner</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>SV</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Version Scanning</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>A client exchanged version strings with the server and than disconnected</code>.<br><br>
Se il valore del campo di log <code>inferences</code> è uguale a <code>UA</code>, il campo UDM <code>security_result.summary</code> viene impostato su <code>Unknown Authentication</code> e il campo UDM <code>security_result.description</code> viene impostato su <code>The authentication method is not determinated or is unknown</code>.</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>Riferimento di mappatura dei campi: CORELIGHT - suricata_corelight</h3>
La tabella seguente elenca i campi di log del tipo di log <code>suricata_corelight</code> e i relativi campi UDM.<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Digita una parola chiave per trovare un valore.">
<table class="fixed">
<thead>
<tr>
<th>Campo di log</th>
<th>Mapping UDM</th>
<th>Logica</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>Il campo UDM <code>metadata.event_type</code> è impostato su <code>SCAN_NETWORK</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>Il campo UDM <code>metadata.product_name</code> è impostato su <code>Suricata</code>.</td>
</tr>
<tr>
<td><code>id.vlan (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_type (integer - count)</code></td>
<td><code>about.labels [icmp_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_code (integer - count)</code></td>
<td><code>about.labels [icmp_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_id (string)</code></td>
<td><code>metadata.product_log_id</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>flow_id (integer - count)</code></td>
<td><code>about.labels[flow_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_id (integer - count)</code></td>
<td><code>about.labels [tx_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>pcap_cnt (integer - count)</code></td>
<td><code>about.labels [pcap_cnt]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.action (string)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.gid (integer - count)</code></td>
<td><code>security_result.detection_fields [alert_gid]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature_id (integer - count)</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rev (integer - count)</code></td>
<td><code>security_result.rule_version</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.rule_name</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.category (string)</code></td>
<td><code>security_result.category_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.severity (integer - count)</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[alert_metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload]</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>signature_severity</code></td>
<td><code>security_result.severity</code></td>
<td>Se il valore del campo di log <code>alert.rule</code> corrisponde al pattern grok <code>signature_severity (?<signature_severity>Critical|Major|Minor|Informational)</code> allora <div style='margin-bottom: 0.0em;'></div>Se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Critical</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>CRITICAL</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code>security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Major</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>MEDIUM</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code> security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Minor</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>LOW</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code>security_result.severity_details</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo estratto <code>signature_severity</code> è uguale a <code>Informational</code> allora, il campo UDM <code>security_result.severity</code> è impostato su <code>INFORMATIONAL</code> e il campo estratto <code>signature_severity</code> viene mappato al campo UDM <code>security_result.severity_details</code>.<br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname(string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain(string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version(string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source(string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname(string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain(string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version(string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rule (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.references (array[string] - vector of string)</code></td>
<td><code>security_result.detection_fields[alert_references]</code></td>
<td>itera attraverso alert.references,<div style='margin-bottom: 0.5em;'></div>il campo di log <code>alert.references</code> viene mappato al campo UDM <code> security_result.detection_fields.alert_references </code>.</td>
</tr>
<tr>
<td><code>payload_printable (string)</code></td>
<td><code>security_result.detection_fields[payload_printable]</code></td>
<td></td>
</tr>
<tr>
<td><code>references (array[string] - vector of string)</code></td>
<td><code>security_result.detection_fields[references]</code></td>
<td>itera attraverso references,<div style='margin-bottom: 0.5em;'></div>il campo di log <code>references</code> viene mappato al campo UDM <code> security_result.detection_fields.references </code>.</td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "4" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "3" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "1" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "2" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>orig_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" o il valore del campo di log <code>orig_vulnerable_host.criticality</code> è uguale a <code> "0" </code> </code> allora, il campo UDM <code> "principal.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>Se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Critical" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "4 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>CRITICAL</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)High" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "3 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>HIGH</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Low" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "1 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>LOW</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Medium" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "2 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>MEDIUM</code>. <br> <div style='margin-bottom: 0.5em;'></div>Altrimenti, se il valore del campo di log <code>resp_vulnerable_host.criticality</code> corrisponde al pattern di espressione regolare <code> "(?i)Unknown_Severity" o il valore del campo di log <code>resp_vulnerable_host.criticality</code> è uguale a <code> "0 </code>" </code> allora, il campo UDM <code> "target.asset.vulnerabilities.severity" </code> è impostato su <code>UNKNOWN_SEVERITY</code>. <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>rule_content</code></td>
<td><code>security_result.detection_fields[alert_rule_content]</code></td>