Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CorelightForSecOps — CORELIGHTおよび関連情報のためのChronicleパーサー | Kitploit
ツール/GitHubGitHub/corelight/corelightforsecops
防御ツールネットワークセキュリティクラウドセキュリティユーティリティとフレームワーク侵入検知ログ分析
GitHubcorelight/corelightforsecops

CorelightForSecOps

CORELIGHTおよび関連情報のためのChronicleパーサー

リポジトリを見る
542ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Corelight Sensor ログの収集

このドキュメントでは、Corelight Sensor と Chronicle フォワーダーを構成して Corelight Sensor ログを収集する方法について説明します。このドキュメントでは、サポートされているログタイプとサポートされている Corelight のバージョンについても一覧表示します。

詳細については、Data ingestion to Chronicle をご覧ください。

始める前に

  • Corelight Sensor のバージョンを確認してください。Corelight Google SecOps パーサーはバージョン 27.13 以前向けに設計されています。それ以降のバージョンの Corelight Sensor には、パーサーが認識しない追加のログが含まれている場合があり、そのようなログはフィールド解析が制限されるか、まったく行われない可能性があります。ただし、ログコンテンツは、Google SecOps で raw ログ形式のまま引き続き利用できます。
  • デプロイメントアーキテクチャ内のすべてのシステムが UTC タイムゾーンで構成されていることを確認します。

デプロイメントとログの取り込み方法

次のデプロイメントアーキテクチャ図は、2 つの異なる取り込みアーキテクチャを使用して Corelight Sensor が Google Security Operations にログを送信するように設定される仕組みを示しています。各顧客のデプロイメントはこの図とは異なる場合があり、より複雑になる可能性があることに注意してください。

取り込みラベルは、raw ログデータを構造化された UDM 形式に正規化するパーサーを識別します。このドキュメントの情報は、CORELIGHT 取り込みラベルが付いたパーサーに適用されます。

Corelight エクスポーターを使用した Google SecOps へのログの取り込み

デプロイメントアーキテクチャ

このアーキテクチャ図は、次のコンポーネントを示しています。

  • Corelight Sensor: Corelight Sensor を実行しているシステム。

  • Corelight Sensor エクスポーター: Corelight Sensor exporter が Sensor からログデータを収集し、Google Security Operations に転送します。

  • Google Security Operations: Google Security Operations は、Corelight Sensor からのログを保持および分析します。

Corelight で Google SecOps エクスポーターを構成する

Sensor または Fleet Manager の Web インターフェースを使用して、Google SecOps エクスポーターを構成します。この構成では、Google SecOps インスタンスの API 認証情報を使用して安全な接続を確立します。

  1. 管理者として Corelight Sensor の Fleet Manager または Sensor の Web インターフェースにログインします。

  2. エクスポーターの構成領域に移動します。

    • Fleet Manager: [Policies] に移動し、ポリシーを選択して、[Export] タブをクリックします。
    • Standalone Sensor: [Configuration] | [Export] | [Export Configuration] の順に移動します。
  3. Create Exporter セクションで、Google SecOps をクリックします。

デプロイメントアーキテクチャ

  1. 次の入力パラメータを構成します。
  • Name*: このエクスポーターインスタンスの一意の名前(例: SecOps)。
  • Google SecOps Customer ID*: Google から提供される一意の顧客 ID。
  • Google SecOps Namespace: Google SecOps 内の Sensor ログの論理名前空間。
  • Credentials*: Google SecOps サービス アカウントの認証情報(JSON)。(JSON コンテンツ全体を貼り付けます)。
  • Google SecOps Labels: データドメインを識別するためのユーザー構成ラベル。
  • Region*: Google SecOps で使用される GCP リージョン名。
  • Batch Max Events: 最大バッチサイズ。
  • Batch Timeout Seconds: バッチの最大経過時間。
  • Proxy URL: 必要な場合のネットワークプロキシ URL。
  • Exporter Log Filter: このエクスポーターインスタンスに適用するフィルタを選択します。
  • Log Type Filter: 特定のログファイルを名前で含めるか除外します。
    • Exclude: 指定されたログを削除します。新しいログタイプ(パッケージからのものなど)は引き続きエクスポートされます。
    • Include: 指定されたログのみをエクスポートします。新しいログタイプは、手動で追加しない限りエクスポートされません。

デプロイメントアーキテクチャ デプロイメントアーキテクチャ

  1. Done をクリックします。

デプロイメントアーキテクチャ

  1. Apply Changes をクリックします。

フォワーダーを使用した Google SecOps へのログの取り込み

デプロイメントアーキテクチャ

このアーキテクチャ図は、次のコンポーネントを示しています。

  • Corelight Sensor: Corelight Sensor を実行しているシステム。

  • Corelight Sensor エクスポーター: Corelight Sensor exporter が Sensor からログデータを収集し、Google Security Operations フォワーダーに転送します。

  • Google Security Operations フォワーダー: Google Security Operations フォワーダーは、顧客のネットワークにデプロイされ、syslog をサポートする軽量のソフトウェアコンポーネントです。Google Security Operations フォワーダーは、ログを Google Security Operations に転送します。

  • Google Security Operations: Google Security Operations は、Corelight Sensor からのログを保持および分析します。

Google Security Operations フォワーダーを構成する

Google Security Operations フォワーダーを構成するには、次の操作を行います。

  1. Google Security Operations フォワーダーをセットアップします。Linux でのフォワーダーのインストールと構成 をご覧ください。

  2. Google Security Operations フォワーダーが Google Security Operations にログを送信するよう構成します。 ```none collectors:

    • syslog: common: enabled: true data_type: CORELIGHT data_hint: batch_n_seconds: 10 batch_n_bytes: 1048576 tcp_address: tcp_buffer_size: 524288 udp_address: connection_timeout_sec: 60
root@kitploit:~
### Corelight Sensor エクスポーターの設定 

1. Corelight Sensor に管理者としてログインします。
2. **Export** タブを選択します。
3. **EXPORT TO SYSLOG** オプションを見つけて有効にします。
4. **EXPORT TO SYSLOG** で、以下のフィールドを設定します:
* **SYSLOG SERVER**: Google Security Operations フォワーダーの syslog リスナーの IP アドレスとポートを指定します。
* **Advanced Settings > SYSLOG FORMAT** に移動し、設定を **Legacy** に変更します。

![Corelight Sensor の設定](https://assets.kitploit.com/production/public/readmes/45240/98e9932cefa08d1f288a8a66675a4ae8398ad3d243bd14379054908875b0da03.jpg)

5. **Apply Changes** をクリックします。

## サポートされている Corelight ログタイプ

Corelight パーサーは、以下のログタイプをサポートしています:
<div class="fixed" translate="no">
<h4>Log Type</h4>
<ul>
  <li>asset_classification</li>
  <li>conn</li>
  <li>conn_long</li>
  <li>conn_red</li>
  <li>conn_agg</li>
  <li>dce_rpc</li>
  <li>dns</li>
  <li>dns_red</li>
  <li>files</li>
  <li>files_red</li>
  <li>http</li>
  <li>http2</li>
  <li>http_red</li>
  <li>intel</li>
  <li>irc</li>
  <li>notice</li>
  <li>rdp</li>
  <li>sip</li>
  <li>smb_files</li>
  <li>smb_mapping</li>
  <li>smtp</li>
  <li>smtp_links</li>
  <li>ssh</li>
  <li>ssl</li>
  <li>ssl_red</li>
  <li>suricata_corelight</li>
  <li>bacnet</li>
  <li>cip</li>
  <li>corelight_burst</li>
  <li>corelight_metrics_bro</li>
  <li>corelight_metrics_disk</li>
  <li>corelight_metrics_iface</li>
  <li>corelight_metrics_memory</li>
  <li>corelight_metrics_system</li>
  <li>corelight_metrics_zeek_doctor</li>
  <li>corelight_overall_capture_loss</li>
  <li>corelight_profiling</li>
  <li>datared</li>
  <li>dga</li>
  <li>dhcp</li>
  <li>dnp3</li>
  <li>dpd</li>
  <li>encrypted_dns</li>
  <li>enip</li>
  <li>enip_debug</li>
  <li>enip_list_identity</li>
  <li>etc_viz</li>
  <li>ftp</li>
  <li>generic_dns_tunnels</li>
  <li>generic_icmp_tunnels</li>
  <li>icmp_specific_tunnels</li>
  <li>ipsec</li>
  <li>iso_cotp</li>
  <li>kerberos</li>
  <li>known_certs</li>
  <li>known_devices</li>
  <li>known_domains</li>
  <li>known_hosts</li>
  <li>known_names</li>
  <li>known_remotes</li>
  <li>known_services</li>
  <li>known_users</li>
  <li>ldap</li>
  <li>ldap_search</li>
  <li>local_subnets</li>
  <li>local_subnets_dj</li>
  <li>local_subnets_graphs</li>
  <li>log4shell</li>
  <li>modbus</li>
  <li>mqtt_connect</li>
  <li>mqtt_publish</li>
  <li>mqtt_subscribe</li>
  <li>mysql</li>
  <li>napatech_shunting</li>
  <li>ntlm</li>
  <li>ntp</li>
  <li>pe</li>
  <li>profinet</li>
  <li>profinet_dce_rpc</li>
  <li>profinet_debug</li>
  <li>radius</li>
  <li>reporter</li>
  <li>rfb</li>
  <li>s7comm</li>
  <li>smartpcap</li>
  <li>snmp</li>
  <li>socks</li>
  <li>software</li>
  <li>specific_dns_tunnels</li>
  <li>stepping</li>
  <li>stun</li>
  <li>stun_nat</li>
  <li>suricata_eve</li>
  <li>suricata_stats</li>
  <li>syslog</li>
  <li>tds</li>
  <li>tds_rpc</li>
  <li>tds_sql_batch</li>
  <li>traceroute</li>
  <li>tunnel</li>
  <li>unknown-smartpcap</li>
  <li>vpn</li>
  <li>weird</li>
  <li>weird_red</li>
  <li>wireguard</li>
  <li>x509</li>
  <li>x509_red</li>
  <li>dns_agg</li>
  <li>files_agg</li>
  <li>http_agg</li>
  <li>ssl_agg</li>
  <li>weird_agg</li>
  <li>analyzer</li>
  <li>anomaly</li>
  <li>ssdp</li>
  <li>telnet</li>
  <li>websocket</li>
  <li>first_seen</li>
</ul>
</div>

## フィールドマッピングリファレンス

このセクションでは、Google Security Operations パーサーが Google Security Operations のフィールドを Google Security Operations Unified Data Model (UDM) のフィールドにどのようにマッピングするかについて説明します。

<h3>フィールドマッピングリファレンス: CORELIGHT - 共通フィールド </h3>

以下の表は、<code>CORELIGHT</code> ログの共通フィールドと、対応する UDM フィールドを示しています。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.vendor_name</code></td>
<td>The <code>metadata.vendor_name</code> UDM field is set to <code>Corelight</code>.</td>
</tr>
<tr>
<td><code>_path (string)</code></td>
<td><code>metadata.product_event_type</code></td>
<td></td>
</tr>
<tr>
<td><code>_system_name (string)</code></td>
<td><code>observer.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>ts (time)</code></td>
<td><code>metadata.event_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>uid (string)</code></td>
<td><code>about.labels [uid], network.session_id</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_h (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_p (integer - port)</code></td>
<td><code>principal.port</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_h (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_p (integer - port)</code></td>
<td><code>target.port</code></td>
<td></td>
</tr>
<tr>
<td><code>_write_ts</code></td><code></code>
<td><code>metadata.collected_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan (integer - int)</code></td>
<td><code>additional.fields [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - int)</code></td>
<td><code>additional.fields [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_cid (string)</code></td>
<td><code>additional.fields [id_orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_source (string)</code></td>
<td><code>additional.fields [id_orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_status (string)</code></td>
<td><code>additional.fields [id_orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_uid (string)</code></td>
<td><code>additional.fields [id_orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_cid (string)</code></td>
<td><code>additional.fields [id_resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_source (string)</code></td>
<td><code>additional.fields [id_resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_status (string)</code></td>
<td><code>additional.fields [id_resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_uid (string)</code></td>
<td><code>additional.fields [id_resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>uids (array[string] - vector of string)</code></td>
<td><code>additional.fields [uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>count (integer - int)</code></td>
<td><code>additional.fields [count]</code></td>
<td></td>
</tr>
<tr>
<td><code>ts_last</code></td>
<td><code>additional.fields [ts_last]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - asset_classification</h3>

以下の表は、<code>asset_classification</code> ログタイプのログフィールドと、対応する UDM フィールドを示しています。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>STATUS_UPDATE</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>mac</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>vendor_mac (string)</code></td>
<td><code>about.asset.hardware.manufacturer</code></td>
<td></td>
</tr>
<tr>
<td><code>device_type (string)</code></td>
<td><code>about.asset.category</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.platform</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.asset.attribute.labels</code></td>
<td></td>
</tr>
<tr>
<td><code>type_group (string)</code></td>
<td><code>about.group.group_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>type_name (string)</code></td>
<td><code>about.resource.resource_subtype</code></td>
<td>The <code>about.resource.resource_type</code> UDM field is set to <code>DEVICE</code></td>
</tr>
<tr>
<td><code>brand (string)</code></td>
<td><code>about.user.company_name</code></td>
<td></td>
</tr>
<tr>
<td><code>model (string)</code></td>
<td><code>about.asset.hardware.model</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (integer)</code></td>
<td><code>about.security_result.confidence_score</code></td>
<td></td>
</tr>
<tr>
<td><code>os_ver (string)</code></td>
<td><code>about.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string])</code></td>
<td><code>about.ip_geo_artifact.tags</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - conn, conn_red, conn_long, conn_agg</h3>

以下の表は、<code>conn, conn_red, conn_long, conn_agg</code> ログタイプのログフィールドと、対応する UDM フィールドを示しています。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="キーワードを入力して値を検索します。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDMマッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDMフィールドは <code>NETWORK_CONNECTION</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDMフィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_bytes (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_bytes (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_state (string)</code></td>
<td><code>metadata.description</code></td>
<td><code>conn_state</code> ログフィールドの値が <code>S0</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>S0: Connection attempt seen, no reply</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>S1</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>S1: Connection established, not terminated</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>S2</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>S2: Connection established and close attempt by originator seen (but no reply from responder)</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>S3</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>S3: Connection established and close attempt by responder seen (but no reply from originator)</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>SF</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>SF: Normal SYN/FIN completion</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>REJ</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>REJ: Connection attempt rejected</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>RSTO</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>RSTO: Connection established, originator aborted (sent a RST)</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>RSTOS0</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>RSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>RSTOSH</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>RSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>RSTR</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>RSTR: Established, responder aborted</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>SH</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>SH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open)</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>SHR</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>SHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator</code> に設定されます。<br><br>それ以外の場合、<code>conn_state</code> ログフィールドの値が <code>OTH</code> と等しい場合、<code>metadata.description</code> UDMフィールドは <code>OTH: No SYN seen, just midstream traffic (a partial connection that was not later closed)</code> に設定されます。</td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_resp (boolean - bool)</code></td>
<td><code>about.labels [local_resp]</code></td>
<td></td>
</tr>
<tr>
<td><code>missed_bytes (integer - count)</code></td>
<td><code>about.labels [missed_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>history (string)</code></td>
<td><code>about.labels [history]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_pkts (integer - count)</code></td>
<td><code>network.sent_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ip_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_pkts (integer - count)</code></td>
<td><code>network.received_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ip_bytes (integer - count)</code></td>
<td><code>target.labels [resp_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>tunnel_parents (array[string] - set[string])</code></td>
<td><code>intermediary.labels [tunnel_parent]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cc (string)</code></td>
<td><code>principal.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cc (string)</code></td>
<td><code>target.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_ids (array[string] - set[string])</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.url (string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.rule (integer - count)</code></td>
<td><code>security_result.rule_labels [spcap_rule]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.trigger (string)</code></td>
<td><code>security_result.detection_fields [spcap_trigger]</code></td>
<td></td>
</tr>
<tr>
<td><code>app (array[string] - vector of string)</code></td>
<td><code>about.application</code></td>
<td></td>
</tr>
<tr>
<td><code>corelight_shunted (boolean - bool)</code></td>
<td><code>about.labels [corelight_shunted]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_pkts (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_pkts (integer - count)</code></td>
<td><code>target.labels [resp_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_bytes (integer - count)</code></td>
<td><code>target.labels [resp_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_l2_addr (string)</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_l2_addr (string)</code></td>
<td><code>target.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.src (string)</code></td>
<td><code>principal.labels [id_orig_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.vals (array[string] - set[string])</code></td>
<td><code>principal.labels [id_orig_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.src (string)</code></td>
<td><code>target.labels [id_resp_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.vals (array[string] - set[string])</code></td>
<td><code>target.labels [id_resp_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>intermediary.labels [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>inner_vlan (integer - int)</code></td>
<td><code>intermediary.labels [inner_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDMフィールドは <code>INFORMATIONAL</code> に設定されます。</td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_cid (string)</code></td>
<td><code>additional.fields [orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_source (string)</code></td>
<td><code>additional.fields [orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_status (string)</code></td>
<td><code>additional.fields [orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_uid (string)</code></td>
<td><code>additional.fields [orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_cid (string)</code></td>
<td><code>additional.fields [resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_source (string)</code></td>
<td><code>additional.fields [resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_status (string)</code></td>
<td><code>additional.fields [resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_uid (string)</code></td>
<td><code>additional.fields [resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>netskope_site_ids</code></td>
<td><code>additional.fields[netskope_site_ids]</code></td>
<td><code>netskope_site_ids</code> ログフィールドを反復処理し、<br><code>netskope_site_id_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDMフィールドにマッピングされ、<code>netskope_site_id</code> ログフィールドは <code>additional.fields.value</code> UDMフィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>netskope_user_ids</code></td>
<td><code>additional.fields[netskope_user_ids]</code></td>
<td><code>netskope_user_ids</code> ログフィールドを反復処理し、<br><code>netskope_user_id_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDMフィールドにマッピングされ、<code>netskope_user_id</code> ログフィールドは <code>additional.fields.value</code> UDMフィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>write_ts</code></td>
<td><code>additional.fields[write_ts]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.urls (array[string] - vector of string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td><code>spcap.urls</code> ログフィールドを反復処理し、<br><code>spcap.urls</code> ログフィールドは <code>security_result.url_back_to_product</code> UDMフィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>community_ids (array[string] - vector of string)</code></td>
<td><code>network.community_id</code></td>
<td><code>community_ids</code> ログフィールドを反復処理し、<br>インデックスが <code>0</code> と等しい場合、<code>community_id</code> ログフィールドは <code>network.community_id</code> UDMフィールドにマッピングされます。<br>それ以外の場合、<code>community_id_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDMフィールドにマッピングされ、<code>community_id</code> ログフィールドは <code>additional.fields.value</code> UDMフィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.version</code></td>
<td><code>about.resource.attribute.labels[vpc_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.vpc_id</code></td>
<td><code>about.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>about.resource.resource_type</code></td>
<td><code>capture_metadata.vpc.vpc_id</code> が存在する場合、<code>about.resource.resource_type</code> UDMフィールドは <code>VPC_NETWORK</code> に設定されます。</td>
</tr>
<tr>
<td><code>capture_source</code></td>
<td><code>about.resource.attribute.labels[capture_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.az</code></td>
<td><code>principal.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.id</code></td>
<td><code>principal.resource.product_object_id</code></td>
<td></td>
</tr>

<tr>
<td><code>orig_inst.name</code></td>
<td><code>principal.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.org_id</code></td>
<td><code>principal.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.sg_ids</code></td>
<td><code>principal.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.subnet_id</code></td>
<td><code>principal.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.vpc_id</code></td>
<td><code>principal.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>principal.resource.resource_type</code></td>
<td><code>orig_inst.vpc_id</code> が存在する場合、<code>principal.resource.resource_type</code> UDMフィールドは <code>VPC_NETWORK</code> に設定されます。</td>
</tr>
<tr>
<td><code>orig_inst.profile</code></td>
<td><code>principal.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.az</code></td>
<td><code>target.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.id</code></td>
<td><code>target.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.name</code></td>
<td><code>target.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.org_id</code></td>
<td><code>target.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.sg_ids</code></td>
<td><code>target.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.subnet_id</code></td>
<td><code>target.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.vpc_id</code></td>
<td><code>target.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>target.resource.resource_type</code></td>
<td><code>resp_inst.vpc_id</code> が存在する場合、<code>target.resource.resource_type</code> UDMフィールドは <code>VPC_NETWORK</code> に設定されます。</td>
</tr>
<tr>
<td><code>resp_inst.profile</code></td>
<td><code>target.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig</code> および <code>local_resp</code></td>
<td><code>additional.fields[direction]</code></td>
<td><code>local_orig</code> ログフィールドの値が <code>true</code> かつ <code>local_resp</code> ログフィールドの値が <code>true</code> の場合、<code>additional.fields[direction]</code> UDMフィールドは <code>internal</code> に設定されます。<br><br>それ以外の場合、<code>local_orig</code> ログフィールドの値が <code>true</code> かつ <code>local_resp</code> ログフィールドの値が <code>false</code> の場合、<code>additional.fields[direction]</code> UDMフィールドは <code>outbound</code> に設定されます。<br><br>それ以外の場合、<code>local_orig</code> ログフィールドの値が <code>false</code> かつ <code>local_resp</code> ログフィールドの値が <code>false</code> の場合、<code>additional.fields[direction]</code> UDMフィールドは <code>external</code> に設定されます。<br><br>それ以外の場合、<code>local_orig</code> ログフィールドの値が <code>false</code> かつ <code>local_resp</code> ログフィールドの値が <code>true</code> の場合、<code>additional.fields[direction]</code> UDMフィールドは <code>inbound</code> に設定されます。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - dce_rpc</h3>

次の表は、<code>dce_rpc</code> ログタイプのログフィールドと、対応する UDMフィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="キーワードを入力して値を検索します。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDMマッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDMフィールドは <code>NETWORK_CONNECTION</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDMフィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>named_pipe (string)</code></td>
<td><code>intermediary.resource.name</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>intermediary.resource.resource_type</code></td>
<td><code>named_pipe</code> ログフィールドの値が <em>空でない</em> 場合、<code>intermediary.resource.resource_type</code> UDMフィールドは <code>PIPE</code> に設定されます。</td>
</tr>
<tr>
<td><code>endpoint (string)</code></td>
<td><code>target.labels [endpoint]</code></td>
<td></td>
</tr>
<tr>
<td><code>operation (string)</code></td>
<td><code>target.labels [operation]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDMフィールドは <code>DCERPC</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDMフィールドは <code>INFORMATIONAL</code> に設定されます。</td>
</tr>
<tr>
<td><code>operation, endpoint, named_pipe (string)</code></td>
<td><code>metadata.description</code></td>
<td><code>metadata.description</code> UDMフィールドは、<code>operation</code>、<code>endpoint</code>、<code>named_pipe</code> ログフィールドを "operation <code>operation</code> on <code>endpoint</code> using named pipe <code>named_pipe</code>" として設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDMフィールドは <code>TCP</code> に設定されます。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - dns, dns_red, dns_agg</h3>

次の表は、<code>dns, dns_red, dns_agg</code> ログタイプのログフィールドと、対応する UDMフィールドの一覧です。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_DNS</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM フィールドは <code>DNS</code> に設定されます。</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>trans_id (integer - count)</code></td>
<td><code>network.dns.id</code></td>
<td></td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>query (string)</code></td>
<td><code>network.dns.questions.name</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass (integer - count)</code></td>
<td><code>network.dns.questions.class</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass_name (string)</code></td>
<td><code>about.labels [qclass_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype (integer - count)</code></td>
<td><code>network.dns.questions.type</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype_name (string)</code></td>
<td><code>about.labels [qtype_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response</code></td>
<td><code>rcode</code> ログフィールドの値が *空でない* 場合、<code>network.dns.response</code> UDM フィールドは <code>true</code> に設定されます。</td>
</tr>
<tr>
<td><code>rcode_name (string)</code></td>
<td><code>about.labels [rcode_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>AA (boolean - bool)</code></td>
<td><code>network.dns.authoritative</code></td>
<td></td>
</tr>
<tr>
<td><code>TC (boolean - bool)</code></td>
<td><code>network.dns.truncated</code></td>
<td></td>
</tr>
<tr>
<td><code>RD (boolean - bool)</code></td>
<td><code>network.dns.recursion_desired</code></td>
<td></td>
</tr>
<tr>
<td><code>RA (boolean - bool)</code></td>
<td><code>network.dns.recursion_available</code></td>
<td></td>
</tr>
<tr>
<td><code>Z (integer - count)</code></td>
<td><code>about.labels [Z]</code></td>
<td></td>
</tr>
<tr>
<td><code>answers (array[string] - vector of string)</code></td>
<td><code>network.dns.answers.name</code></td>
<td></td>
</tr>
<tr>
<td><code>TTLs (array[number] - vector of interval)</code></td>
<td><code>network.dns.answers.ttl</code></td>
<td></td>
</tr>
<tr>
<td><code>rejected (boolean - bool)</code></td>
<td><code>about.labels [rejected]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_trusted_domain (string)</code></td>
<td><code>about.labels [is_trusted_domain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_host_subdomain (string)</code></td>
<td><code>about.labels [icann_host_subdomain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_domain (string)</code></td>
<td><code>network.dns_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_tld (string)</code></td>
<td><code>about.labels [icann_tld]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>security_result.detection_fields [num]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピング リファレンス: CORELIGHT - http, http_red, http2, http_agg</h3>

次の表は、<code>http, http_red, http2, http_agg</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_HTTP</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>network.http.method</code></td>
<td></td>
</tr>
<tr>
<td><code>host (string)</code></td>
<td><code>target.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>referrer (string)</code></td>
<td><code>network.http.referral_url</code></td>
<td></td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.application_protocol_version</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>network.http.user_agent</code></td>
<td></td>
</tr>
<tr>
<td><code>origin (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>network.http.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>about.labels [status_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_code (integer - count)</code></td>
<td><code>about.labels [info_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_msg (string)</code></td>
<td><code>about.labels [info_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>tags (array[string] - set[enum])</code></td>
<td><code>about.labels [tags]</code></td>
<td></td>
</tr>
<tr>
<td><code>username (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>password (string)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td></td>
</tr>
<tr>
<td><code>proxied (array[string] - set[string])</code></td>
<td><code>intermediary.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [orig_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_filenames (array[string] - vector of string)</code></td>
<td><code>src.file.names</code></td>
<td><code>orig_filenames</code> ログフィールドは、<code>orig_filenames</code> 内のインデックス値が <code>0</code> の場合、<code>src.file.names</code> UDM フィールドにマッピングされます。<br><br>それ以外のインデックス値の場合、<code>orig_filenames</code> ログフィールドは <code>about.file.names</code> にマッピングされます。</td>
</tr>
<tr>
<td><code>orig_mime_types (array[string] - vector of string)</code></td>
<td><code>src.file.mime_type</code></td>
<td><code>orig_mime_types</code> ログフィールドは、<code>orig_mime_types</code> 内のインデックス値が <code>0</code> の場合、<code>src.file.mime_type</code> UDM フィールドにマッピングされます。<br><br>それ以外のインデックス値の場合、<code>orig_mime_types</code> ログフィールドは <code>about.file.mime_type</code> にマッピングされます。</td>
</tr>
<tr>
<td><code>resp_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [resp_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_filenames (array[string] - vector of string)</code></td>
<td><code>target.file.names</code></td>
<td><code>resp_filenames</code> ログフィールドは、<code>resp_filenames</code> 内のインデックス値が <code>0</code> の場合、<code>target.file.names</code> UDM フィールドにマッピングされます。<br><br>それ以外のインデックス値の場合、<code>resp_filenames</code> ログフィールドは <code>about.file.names</code> にマッピングされます。</td>
</tr>
<tr>
<td><code>resp_mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td><code>resp_mime_types</code> ログフィールドは、<code>resp_mime_types</code> 内のインデックス値が <code>0</code> の場合、<code>target.file.mime_type</code> UDM フィールドにマッピングされます。<br><br>それ以外のインデックス値の場合、<code>resp_mime_types</code> ログフィールドは <code>about.file.mime_type</code> にマッピングされます。</td>
</tr>
<tr>
<td><code>post_body (string)</code></td>
<td><code>about.labels [post_body]</code></td>
<td></td>
</tr>
<tr>
<td><code>stream_id (integer - count)</code></td>
<td><code>about.labels [stream_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>encoding (string)</code></td>
<td><code>about.labels [encoding]</code></td>
<td></td>
</tr>
<tr>
<td><code>push (boolean - bool)</code></td>
<td><code>about.labels [push]</code></td>
<td></td>
</tr>
<tr>
<td><code>versions (array[float] - vector of float)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>ログフィールド <code>versions</code> を反復処理し、<br> インデックスが <code>0</code> の場合、<code>version</code> ログフィールドは <code>network.application_protocol_version</code> UDM フィールドにマッピングされます。<br> それ以外の場合、<code>version_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDM フィールドに、<code>version</code> ログフィールドは <code>additional.fields.value</code> UDM フィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>user_agents (array[string] - vector of string)</code></td>
<td><code>network.http.user_agent</code></td>
<td>ログフィールド <code>user_agents</code> を反復処理し、<br> インデックスが <code>0</code> の場合、<code>user_agent</code> ログフィールドは <code>network.http.user_agent</code> UDM フィールドにマッピングされます。<br> それ以外の場合、<code>user_agent_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDM フィールドに、<code>user_agent</code> ログフィールドは <code>additional.fields.value</code> UDM フィールドにマッピングされます。<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピング リファレンス: CORELIGHT - smtp_links</h3>

次の表は、<code>smtp_links</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_SMTP</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM フィールドは <code>SMTP</code> に設定されます。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>link (string)</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domain (string)</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピング リファレンス: CORELIGHT - irc</h3>

次の表は、<code>irc</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_UNCATEGORIZED</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>nick (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>user (string)</code></td>
<td><code>principal.user.userid</code></td>
<td><code>user</code> ログフィールドの値が 255 以下の場合、<code>user</code> ログフィールドは <code>principal.user.userid</code> UDM フィールドにマッピングされます。<br><br>それ以外の場合、<code>user</code> ログフィールドは <code>about.labels</code> UDM フィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>command, value, addl</code></td>
<td><code>principal.process.command_line</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_size (integer - count)</code></td>
<td><code>src.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_mime_type (string)</code></td>
<td><code>src.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピング リファレンス: CORELIGHT - files, files_red, files_agg</h3>

次の表は、<code>files, files_red, files_agg</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="キーワードを入力して値を検索します。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM フィールドは <code>NETWORK_UNCATEGORIZED</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_hosts (array[string] - set[addr])</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>rx_hosts (array[string] - set[addr])</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_uids (array[string] - set[string])</code></td>
<td><code>about.labels [conn_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>source (string)</code></td>
<td><code>about.labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>depth (integer - count)</code></td>
<td><code>about.labels [depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>analyzers (array[string] - set[string])</code></td>
<td><code>about.labels [analyzer]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_type (string)</code></td>
<td><code>about.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>filename (string)</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>about.labels [duration]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_orig (boolean - bool)</code></td>
<td><code>about.labels [is_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen_bytes (integer - count)</code></td>
<td><code>about.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>total_bytes (integer - count)</code></td>
<td><code>about.labels [total_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>missing_bytes (integer - count)</code></td>
<td><code>about.labels [missing_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>overflow_bytes (integer - count)</code></td>
<td><code>about.labels [overflow_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>timedout (boolean - bool)</code></td>
<td><code>about.labels [timedout]</code></td>
<td></td>
</tr>
<tr>
<td><code>parent_fuid (string)</code></td>
<td><code>about.labels [parent_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>about.file.md5</code></td>
<td></td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>about.file.sha1</code></td>
<td></td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>about.file.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.client.certificate.md5</code></td>
<td>もし <code>source</code> ログフィールドの値が <code>ssl</code> に等しく、<code>mime_type</code> ログフィールドの値が <code>application/x-x509-user-cert</code> に等しく、<code>_path</code> ログフィールドの値が <code>files</code> に等しい場合、<code>network.tls.client.certificate.md5</code> UDM フィールドは <code>md5</code> に設定されます。</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.client.certificate.sha1</code></td>
<td>もし <code>source</code> ログフィールドの値が <code>ssl</code> に等しく、<code>mime_type</code> ログフィールドの値が <code>application/x-x509-user-cert</code> に等しく、<code>_path</code> ログフィールドの値が <code>files</code> に等しい場合、<code>network.tls.client.certificate.sha1</code> UDM フィールドは <code>sha1</code> に設定されます。</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.client.certificate.sha256</code></td>
<td>もし <code>source</code> ログフィールドの値が <code>ssl</code> に等しく、<code>mime_type</code> ログフィールドの値が <code>application/x-x509-user-cert</code> に等しく、<code>_path</code> ログフィールドの値が <code>files</code> に等しい場合、<code>network.tls.client.certificate.sha256</code> UDM フィールドは <code>sha256</code> に設定されます。</td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.server.certificate.md5</code></td>
<td>もし <code>source</code> ログフィールドの値が <code>ssl</code> に等しく、<code>mime_type</code> ログフィールドの値が <code>application/x-x509-ca-cert</code> に等しく、<code>_path</code> ログフィールドの値が <code>files</code> に等しい場合、<code>network.tls.server.certificate.md5</code> UDM フィールドは <code>md5</code> に設定されます。</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.server.certificate.sha1</code></td>
<td>もし <code>source</code> ログフィールドの値が <code>ssl</code> に等しく、<code>mime_type</code> ログフィールドの値が <code>application/x-x509-ca-cert</code> に等しく、<code>_path</code> ログフィールドの値が <code>files</code> に等しい場合、<code>network.tls.server.certificate.sha1</code> UDM フィールドは <code>sha1</code> に設定されます。</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td>もし <code>source</code> ログフィールドの値が <code>ssl</code> に等しく、<code>mime_type</code> ログフィールドの値が <code>application/x-x509-ca-cert</code> に等しく、<code>_path</code> ログフィールドの値が <code>files</code> に等しい場合、<code>network.tls.server.certificate.sha256</code> UDM フィールドは <code>sha256</code> に設定されます。</td>
</tr>
<tr>
<td><code>extracted (array[string] - set[string])</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_cutoff (boolean - bool)</code></td>
<td><code>about.labels [extracted_cutoff]</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_size (integer - count)</code></td>
<td><code>about.labels [extracted_size]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>about.labels [num]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>additional.fields [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan_inner (integer - int)</code></td>
<td><code>additional.fields [vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td><code>mime_type</code> ログフィールドを反復処理し、<br> インデックスが <code>0</code> に等しい場合、<code>mime_type</code> ログフィールドは <code>target.file.mime_type</code> UDM フィールドにマッピングされます。 <br> それ以外の場合、<code>mime_type_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDM フィールドに、<code>mime_type</code> ログフィールドは <code>additional.fields.value</code> UDM フィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>timedouts (array[boolean] - vector of bool)</code></td>
<td><code>additional.fields[timedouts]</code></td>
<td><code>timedouts</code> ログフィールドを反復処理し、<br><code>timedout_%{index}</code> ログフィールドは <code>additional.fields.key</code> UDM フィールドに、<code>timedouts</code> ログフィールドは <code>additional.fields.value</code> UDM フィールドにマッピングされます。<br></td>
</tr>

</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - notice</h3>

次の表は、<code>notice</code> ログタイプのログフィールドと、対応する UDM フィールドを示しています。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="キーワードを入力して値を検索します。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM フィールドは <code>NETWORK_UNCATEGORIZED</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>target.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>about.labels [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>note (string - enum)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>msg (string)</code></td>
<td><code>metadata.description</code></td>
<td></td>
</tr>
<tr>
<td><code>sub (string)</code></td>
<td><code>about.labels [sub]</code></td>
<td></td>
</tr>
<tr>
<td><code>src (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>dst (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>p (integer - port)</code></td>
<td><code>about.port</code></td>
<td></td>
</tr>
<tr>
<td><code>n (integer - count)</code></td>
<td><code>about.labels [n]</code></td>
<td></td>
</tr>
<tr>
<td><code>peer_descr (string)</code></td>
<td><code>about.labels [peer_descr]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.action </code></td>
<td>The <code>security_result.action</code> UDM フィールドは <code>ALLOW</code> に設定されます。</td>
</tr>
<tr>
<td><code>actions (array[string] - set[enum])</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>suppress_for (number - interval)</code></td>
<td><code>about.labels [suppress_for]</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>The <code>about.location.country_or_region</code> UDM フィールドは、<code>remote_location.country_code</code> ログフィールドと <code>remote_location.region</code> ログフィールドを使用して "<code>remote_location.country_code</code>: <code>remote_location.region</code>" として設定されます。</td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td>The <code>about.location.country_or_region</code> UDM フィールドは、<code>remote_location.country_code</code> ログフィールドと <code>remote_location.region</code> ログフィールドを使用して "<code>remote_location.country_code</code>: <code>remote_location.region</code>" として設定されます。</td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>about.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>about.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>about.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>もし <code>severity.level</code> ログフィールドの値が次のいずれかの値を含む場合<div style='margin-top: -0.8em;'></div><ul><li><code>0</code></li><li><code> 1</code></li></ul><div style='margin-top: -0.8em;'></div> の場合、<code>  security_result.severity </code> UDM フィールドは <code>HIGH</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>severity.level</code> ログフィールドの値が <code> 2 </code> に等しい場合、<code>  security_result.severity </code> UDM フィールドは <code>CRITICAL</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>severity.level</code> ログフィールドの値が <code> 3 </code> に等しい場合、<code>  security_result.severity </code> UDM フィールドは <code>ERROR</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>severity.level</code> ログフィールドの値が次のいずれかの値を含む場合<div style='margin-top: -0.8em;'></div><ul><li><code>4</code></li><li><code>5</code></li><li><code>6</code></li></ul><div style='margin-top: -0.8em;'></div> の場合、<code>  security_result.severity </code> UDM フィールドは <code>INFORMATIONAL</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>severity.level</code> ログフィールドの値が <code> 7 </code> に等しい場合、<code>  security_result.severity </code> UDM フィールドは <code>LOW</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>  security_result.severity </code> UDM フィールドは <code>UNKNOWN_SEVERITY</code> に設定されます。 <br></td>
</tr>
<tr>
<td><code>severity.name</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>severity.level</code></td>
<td><code>security_result.detection_fields [severity_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>もし <code>resp_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Critical" or the <code>resp_vulnerable_host.criticality</code> log field value is equal to <code> "4 </code>" </code> に一致する場合、<code> "target.asset.vulnerabilities.severity" </code> UDM フィールドは <code>CRITICAL</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>resp_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)High" or the <code>resp_vulnerable_host.criticality</code> log field value is equal to <code> "3 </code>" </code> に一致する場合、<code> "target.asset.vulnerabilities.severity" </code> UDM フィールドは <code>HIGH</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>resp_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Low" or the <code>resp_vulnerable_host.criticality</code> log field value is equal to <code> "1 </code>" </code> に一致する場合、<code> "target.asset.vulnerabilities.severity" </code> UDM フィールドは <code>LOW</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>resp_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Medium" or the <code>resp_vulnerable_host.criticality</code> log field value is equal to <code> "2 </code>" </code> に一致する場合、<code> "target.asset.vulnerabilities.severity" </code> UDM フィールドは <code>MEDIUM</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>resp_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Unknown_Severity" </code> または <code>resp_vulnerable_host.criticality</code> ログフィールドの値が <code> "0 </code>" に等しい場合、<code> "target.asset.vulnerabilities.severity" </code> UDM フィールドは <code>UNKNOWN_SEVERITY</code> に設定されます。 <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname (string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain (string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version (string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>もし <code>orig_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Critical" or the <code>orig_vulnerable_host.criticality</code> log field value is equal to <code> "4 </code>" </code> に一致する場合、<code> "principal.asset.vulnerabilities.severity" </code> UDM フィールドは <code>CRITICAL</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>orig_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)High" or the <code>orig_vulnerable_host.criticality</code> log field value is equal to <code> "3 </code>" </code> に一致する場合、<code> "principal.asset.vulnerabilities.severity" </code> UDM フィールドは <code>HIGH</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>orig_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Low" or the <code>orig_vulnerable_host.criticality</code> log field value is equal to <code> "1 </code>" </code> に一致する場合、<code> "principal.asset.vulnerabilities.severity" </code> UDM フィールドは <code>LOW</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>orig_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Medium" or the <code>orig_vulnerable_host.criticality</code> log field value is equal to <code> "2 </code>" </code> に一致する場合、<code> "principal.asset.vulnerabilities.severity" </code> UDM フィールドは <code>MEDIUM</code> に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>orig_vulnerable_host.criticality</code> ログフィールドの値が正規表現パターン <code> "(?i)Unknown_Severity" </code> または <code>orig_vulnerable_host.criticality</code> ログフィールドの値が <code> "0 </code>" に等しい場合、<code> "principal.asset.vulnerabilities.severity" </code> UDM フィールドは <code>UNKNOWN_SEVERITY</code> に設定されます。 <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname (string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain (string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version (string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source (string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - smb_files</h3>

次の表は、<code>smb_files</code> ログタイプのログフィールドと、対応する UDM フィールドを示しています。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="値を検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>action</code> ログフィールドの値が <code>SMB::FILE_READ</code> と等しい場合、<code>metadata.event_type</code> UDM フィールドは <code>FILE_READ</code> に設定されます。<br><br>それ以外の場合、<code>action</code> ログフィールドの値が <code>SMB::FILE_WRITE</code> と等しければ、<code>metadata.event_type</code> UDM フィールドは <code>FILE_MODIFICATION</code> に設定されます。<br><br>それ以外の場合、<code>action</code> ログフィールドの値が <code>SMB::FILE_OPEN</code> と等しければ、<code>metadata.event_type</code> UDM フィールドは <code>FILE_OPEN</code> に設定されます。<br><br>それ以外の場合、<code>action</code> ログフィールドの値が <code>SMB::FILE_CLOSE</code> と等しければ、<code>metadata.event_type</code> UDM フィールドは <code>FILE_UNCATEGORIZED</code> に設定されます。<br><br>それ以外の場合、<code>action</code> ログフィールドの値が <code>SMB::FILE_DELETE</code> と等しければ、<code>metadata.event_type</code> UDM フィールドは <code>FILE_DELETION</code> に設定されます。<br><br>それ以外の場合、<code>action</code> ログフィールドの値が <code>SMB::FILE_RENAME</code> と等しければ、<code>metadata.event_type</code> UDM フィールドは <code>FILE_MOVE</code> に設定されます。<br><br>それ以外の場合、<code>action</code> ログフィールドの値が <code>SMB::FILE_SET_ATTRIBUTE</code> と等しければ、<code>metadata.event_type</code> UDM フィールドは <code>FILE_UNCATEGORIZED</code> に設定されます。<br><br>それ以外の場合、<code>metadata.event_type</code> UDM フィールドは <code>FILE_UNCATEGORIZED</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM フィールドは <code>SMB</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM フィールドは <code>TCP</code> に設定されます。</td>
</tr>
<tr>
<td><code>action, name</code></td>
<td><code>metadata.description</code></td>
<td><code>metadata.description</code> UDM フィールドには、<code>action</code> および <code>name</code> ログフィールドが "action: <code>action</code> on: <code>name</code>" として設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM フィールドは <code>INFORMATIONAL</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM フィールドは <code>ALLOW</code> に設定されます。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>action (string - enum)</code></td>
<td><code>target.labels [action]</code></td>
<td></td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.file.full_path</code></td>
<td></td>
</tr>
<tr>
<td><code>name (string)</code></td>
<td><code>target.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>size (integer - count)</code></td>
<td><code>target.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>prev_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>times.modified (time)</code></td>
<td><code>target.file.last_modification_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.accessed (time)</code></td>
<td><code>target.file.last_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.created (time)</code></td>
<td><code>target.file.first_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.changed (time)</code></td>
<td><code>target.labels [times_changed]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_offset_req (integer - count)</code></td>
<td><code>target.labels [data_offset_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_req (integer - count)</code></td>
<td><code>target.labels [data_len_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_rsp (integer - count)</code></td>
<td><code>target.labels [data_len_rsp]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - smb_mapping</h3>

次の表は、<code>smb_mapping</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="値を検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_CONNECTION</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM フィールドは <code>SMB</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM フィールドは <code>TCP</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM フィールドは <code>INFORMATIONAL</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM フィールドは <code>ALLOW</code> に設定されます。</td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.resource.attribute.labels [path]</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>target.application</code></td>
<td></td>
</tr>
<tr>
<td><code>native_file_system (string)</code></td>
<td><code>target.resource.attribute.labels [native_file_system]</code></td>
<td></td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_type</code></td>
<td><code>share_type</code> ログフィールドの値が <code>DISK</code> と等しい場合、<code>target.resource.resource_type</code> UDM フィールドは <code>STORAGE_OBJECT</code> に設定されます。<br><br>それ以外の場合、<code>share_type</code> ログフィールドの値が <code>PIPE</code> と等しければ、<code>target.resource.resource_type</code> UDM フィールドは <code>PIPE</code> に設定されます。<br><br>それ以外の場合、<code>target.resource.resource_type</code> UDM フィールドは <code>UNSPECIFIED</code> に設定されます。</td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_subtype</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - ssl, ssl_red, ssl_agg</h3>

次の表は、<code>ssl, ssl_red, ssl_agg</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="値を検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_CONNECTION</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM フィールドは <code>HTTPS</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM フィールドは <code>TCP</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM フィールドは <code>INFORMATIONAL</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM フィールドは <code>ALLOW</code> に設定されます。</td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.tls.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>curve (string)</code></td>
<td><code>network.tls.curve</code></td>
<td></td>
</tr>
<tr>
<td><code>server_name (string)</code></td>
<td><code>network.tls.client.server_name</code></td>
<td></td>
</tr>
<tr>
<td><code>resumed (boolean - bool)</code></td>
<td><code>network.tls.resumed</code></td>
<td></td>
</tr>
<tr>
<td><code>last_alert (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>next_protocol (string)</code></td>
<td><code>network.tls.next_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>established (boolean - bool)</code></td>
<td><code>network.tls.established</code></td>
<td></td>
</tr>
<tr>
<td><code>ssl_history (string)</code></td>
<td><code>about.labels [ssl_history]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>target.labels [cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>principal.labels [client_cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>sni_matches_cert (boolean - bool)</code></td>
<td><code>about.labels [sni_matches_cert]</code></td>
<td></td>
</tr>
<tr>
<td><code>validation_status (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3 (string)</code></td>
<td><code>network.tls.client.ja3</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3s (string)</code></td>
<td><code>network.tls.server.ja3s</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - rdp</h3>

次の表は、<code>rdp</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="値を検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_CONNECTION</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td><code>cookie (string)</code></td>
<td><code>principal.user.userid</code></td>
<td></td>
</tr>
<tr>
<td><code>result (string)</code></td>
<td><code>about.labels [result]</code></td>
<td></td>
</tr>
<tr>
<td><code>security_protocol (string)</code></td>
<td><code>target.labels [security_protocol]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_channels (array[string] - vector of string)</code></td>
<td><code>intermediary.labels [client_channels]</code></td>
<td></td>
</tr>
<tr>
<td><code>keyboard_layout (string)</code></td>
<td><code>principal.labels [keyboard_layout]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_build (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>client_name (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>client_dig_product_id (string)</code></td>
<td><code>principal.asset.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_width (integer - count)</code></td>
<td><code>principal.labels [desktop_width]</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_height (integer - count)</code></td>
<td><code>principal.labels [desktop_height]</code></td>
<td></td>
</tr>
<tr>
<td><code>requested_color_depth (string)</code></td>
<td><code>principal.labels [requested_color_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_type (string)</code></td>
<td><code>about.labels [cert_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_count (integer - count)</code></td>
<td><code>about.labels [cert_count]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_permanent (boolean - bool)</code></td>
<td><code>about.labels [cert_permanent ]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_level (string)</code></td>
<td><code>about.labels [encryption_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_method (string)</code></td>
<td><code>about.labels [encryption_method]</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td><code>auth_success</code> ログフィールドの値が <code>true</code> と等しい場合、<code>security_result.action</code> UDM フィールドは <code>ALLOW</code> に設定されます。<br> それ以外の場合、<code>security_result.action</code> UDM フィールドは <code>FAIL</code> に設定されます。</td>
</tr>
<tr>
<td><code>channels_joined (integer - int)</code></td>
<td><code>intermediary.labels [channels_joined]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>about.labels [inferences]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdpeudp_uid (string)</code></td>
<td><code>about.labels [rdpeudp_uid]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM フィールドは <code>TCP</code> に設定されます。</td>
</tr>
<tr>
<td><code>rdfp_string (string)</code></td>
<td><code>principal.labels [rdfp_string]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdfp_hash (string)</code></td>
<td><code>principal.labels [rdfp_hash]</code></td>
<td></td>
</tr>
<tr>
<td><code>result, security_protocol</code></td>
<td><code>security_result.description</code></td>
<td><code>security_result.description</code> UDM フィールドには、<code>result</code> および <code>security_protocol</code> ログフィールドが "<code>result</code> connection with security protocol <code>security_protocol</code>" として設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM フィールドは <code>INFORMATIONAL</code> に設定されます。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - sip</h3>

次の表は、<code>sip</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="値を検索するキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDM マッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM フィールドは <code>NETWORK_UNCATEGORIZED</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM フィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM フィールドは <code>SIP</code> に設定されます。</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>about.labels [method]</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_from (string)</code></td>
<td><code>principal.labels [request_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_to (string)</code></td>
<td><code>target.labels [request_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_from</code></td>
<td><code>principal.labels [response_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_to (string)</code></td>
<td><code>target.labels [response_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>about.labels [reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>call_id (string)</code></td>
<td><code>about.labels[call_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>seq (string)</code></td>
<td><code>about.labels [seq]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>about.labels [subject]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_path (array[string] - vector of string)</code></td>
<td><code>about.labels [request_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_path (array[string] - vector of string)</code></td>
<td><code>about.labels [response_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>about.labels [user_agent]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>about.labels [status_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>warning (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>content_type (string)</code></td>
<td><code>about.labels [content_type]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - intel</h3>

次の表は、<code>intel</code> ログタイプのログフィールドと、対応する UDM フィールドの一覧です。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="キーワードを入力して値を検索してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDMマッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDMフィールドは<code>SCAN_NETWORK</code>に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDMフィールドは<code>Zeek</code>に設定されます。</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.metadata.entity_type</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::ADDR</code>と等しい場合、<code>metadata.entity_type</code> UDMフィールドは<code>IP_ADDRESS</code>に設定されます。<br><br>それ以外で、<code>indicator.type</code>ログフィールドの値が<code>Intel::SUBNET</code>、<code>Intel::SOFTWARE</code>、<code>Intel::CERT_HASH</code>、<code>Intel::PUBKEY_HASH</code>のいずれかと等しい場合、<code>metadata.entity_type</code> UDMフィールドは<code>RESOURCE</code>に設定されます。<br><br>それ以外で、<code>indicator.type</code>ログフィールドの値が<code>Intel::URL</code>と等しい場合、<code>metadata.entity_type</code> UDMフィールドは<code>URL</code>に設定されます。<br><br>それ以外で、<code>indicator.type</code>ログフィールドの値が<code>Intel::EMAIL</code>または<code>Intel::USER_NAME</code>と等しい場合、<code>metadata.entity_type</code> UDMフィールドは<code>USER</code>に設定されます。<br><br>それ以外で、<code>indicator.type</code>ログフィールドの値が<code>Intel::DOMAIN</code>と等しい場合、<code>metadata.entity_type</code> UDMフィールドは<code>DOMAIN_NAME</code>に設定されます。<br><br>それ以外で、<code>indicator.type</code>ログフィールドの値が<code>Intel::FILE_HASH</code>または<code>Intel::FILE_NAME</code>と等しい場合、<code>metadata.entity_type</code> UDMフィールドは<code>FILE</code>に設定されます。<br><br>それ以外の場合、<code>metadata.entity_type</code> UDMフィールドは<code>RESOURCE</code>に設定されます。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.ip</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::ADDR</code>と等しい場合、<code>seen.indicator</code>ログフィールドは<code>entity.ip</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.url</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::URL</code>と等しい場合、<code>seen.indicator</code>ログフィールドは<code>entity.url</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.domain.name</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::DOMAIN</code>と等しい場合、<code>seen.indicator</code>ログフィールドは<code>entity.domain.name</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.user.email_address</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::USER_NAME</code>または<code>Intel::EMAIL</code>と等しい場合、<code>seen.indicator</code>ログフィールドは<code>entity.user.email_address</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.file.names</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::FILE_HASH</code>または<code>Intel::FILE_NAME</code>と等しい場合、<code>seen.indicator</code>ログフィールドは<code>entity.file.full_path</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.resource.name</code></td>
<td><code>metadata.entity_type</code>ログフィールドの値が<code>RESOURCE</code>と等しい場合、<code>seen.indicator</code>ログフィールドは<code>entity.resource.name</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td></td>
<td><code>entity.resource.resource_type</code></td>
<td><code>indicator.type</code>ログフィールドの値が<code>Intel::SUBNET</code>と等しい場合、<code>entity.resource.resource_name</code> UDMフィールドは<code>VPC_NETWORK</code>に設定されます。</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.resource.resource_sub_type</code></td>
<td><code>metadata.entity_type</code>ログフィールドの値が<code>RESOURCE</code>と等しい場合、<code>seen.indicator_type</code>ログフィールドは<code>entity.resource.resource_sub_type</code> UDMフィールドにマッピングされます。</td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>entity.metadata.source_labels [seen_where]</code></td>
<td></td>
</tr>
<tr>
<td><code>matched (array[string] - set[enum])</code></td>
<td><code>entity.labels [matched]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>entity.metadata.source_labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>entity.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>metadata.threat.detection_fields [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>desc (array[string] - set[string])</code></td>
<td><code>ioc.description</code></td>
<td><code>desc</code>ログフィールドは、<code>desc</code>内のインデックス値が<code>0</code>の場合、<code>ioc.description</code> UDMフィールドにマッピングされます。<br><br>その他のインデックス値の場合、<code>entity.labels.key</code> UDMフィールドは<code>desc</code>に設定され、  <code>desc</code>ログフィールドは<code>entity.labels.value</code>にマッピングされます。</td>
</tr>
<tr>
<td><code>url (array[string] - set[string])</code></td>
<td><code>metadata.threat.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>ioc.confidence_score</code></td>
<td><code>confidence</code>ログフィールドは、<code>confidence</code>内のインデックス値が<code>0</code>の場合、<code>ioc.confidence_score</code> UDMフィールドにマッピングされます。<br><br>その他のインデックス値の場合、<code>entity.labels.key</code> UDMフィールドは<code>confidence</code>に設定され、  <code>confidence</code>ログフィールドは<code>entity.labels.value</code>にマッピングされます。</td>
</tr>
<tr>
<td><code>firstseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.start</code></td>
<td><code>firstseen</code>ログフィールドは、<code>firstseen</code>内のインデックス値が<code>0</code>の場合、<code>ioc.active_timerange.start</code> UDMフィールドにマッピングされます。<br><br>その他のインデックス値の場合、<code>entity.labels.key</code> UDMフィールドは<code>firstseen</code>に設定され、  <code>firstseen</code>ログフィールドは<code>entity.labels.value</code>にマッピングされます。</td>
</tr>
<tr>
<td><code>lastseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.end</code></td>
<td><code>lastseen</code>ログフィールドは、<code>lastseen</code>内のインデックス値が<code>0</code>の場合、<code>ioc.active_timerange.end</code> UDMフィールドにマッピングされます。<br><br>その他のインデックス値の場合、<code>entity.labels.key</code> UDMフィールドは<code>lastseen</code>に設定され、  <code>lastseen</code>ログフィールドは<code>entity.labels.value</code>にマッピングされます。</td>
</tr>
<tr>
<td><code>associated (array[string] - set[string])</code></td>
<td><code>entity.labels [associated]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>ioc.categorization</code></td>
<td><code>category</code>ログフィールドは、<code>category</code>内のインデックス値が<code>0</code>の場合、<code>ioc.categorization</code> UDMフィールドにマッピングされます。<br><br>その他のインデックス値の場合、<code>entity.labels.key</code> UDMフィールドは<code>category</code>に設定され、  <code>category</code>ログフィールドは<code>entity.labels.value</code>にマッピングされます。</td>
</tr>
<tr>
<td><code>campaigns (array[string] - set[string])</code></td>
<td><code>entity.labels [campaign]</code></td>
<td></td>
</tr>
<tr>
<td><code>reports (array[string] - set[string])</code></td>
<td><code>entity.labels [report]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>about.labels [indicator]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>about.labels [indicator_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>about.labels [where]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>about.labels [sources]</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>about.labels [confidence]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>about.labels [category]</code></td>
<td></td>
</tr>
<tr>
<td><code>threat_score (array[number] - set[double])</code></td>
<td><code>entity.security_result.detection_fields[threat_score]</code></td>
<td></td>
</tr>
<tr>
<td><code>verdict (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.verdict_response</code></td>
<td><code>verdict</code>を反復処理します。<div style='margin-bottom: 0.5em;'></div><div style='margin-bottom: 0.0em;'></div><code>verdict</code>ログフィールドの値が正規表現パターン<code> "(?i)Malicious" または <code>verdict</code> ログフィールドの値が <code> "1" </code> と等しい </code>に一致する場合、<code>        "entity.security_result.verdict_info.verdict_response" </code> UDMフィールドは<code>MALICIOUS</code>に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>そうでない場合、<code>verdict</code>ログフィールドの値が正規表現パターン<code> "(?i)Benign" または <code>verdict</code> ログフィールドの値が <code> "2" </code> と等しい </code>に一致する場合、<code>        "entity.security_result.verdict_info.verdict_response" </code> UDMフィールドは<code>BENIGN</code>に設定されます。 <br> <div style='margin-bottom: 0.5em;'></div>それ以外の場合、<code>        "entity.security_result.verdict_info.verdict_response" </code> UDMフィールドは<code>VERDICT_RESPONSE_UNSPECIFIED</code>に設定されます。 <br></td>
</tr>
<tr>
<td><code>verdict_source (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.source_provider</code></td>
<td><code>verdict_source</code>を反復処理します。<div style='margin-bottom: 0.5em;'></div><code>verdict_source</code>ログフィールドは<code>    entity.security_result.VerdictInfo.source_provider </code> UDMフィールドにマッピングされます。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - smtp</h3>

次の表は、<code>smtp</code>ログタイプのログフィールドと、それに対応するUDMフィールドを示しています。

<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="キーワードを入力して値を検索してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDMマッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDMフィールドは<code>NETWORK_SMTP</code>に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDMフィールドは<code>Zeek</code>に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDMフィールドは<code>SMTP</code>に設定されます。</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>helo (string)</code></td>
<td><code>network.smtp.helo</code></td>
<td></td>
</tr>
<tr>
<td><code>mailfrom (string)</code></td>
<td><code>network.smtp.mail_from</code></td>
<td></td>
</tr>
<tr>
<td><code>rcptto (array[string] - set[string])</code></td>
<td><code>network.smtp.rcpt_to</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>from (string)</code></td>
<td><code>network.email.from</code></td>
<td></td>
</tr>
<tr>
<td><code>to (array[string] - set[string])</code></td>
<td><code>network.email.to</code></td>
<td></td>
</tr>
<tr>
<td><code>cc (array[string] - set[string])</code></td>
<td><code>network.email.cc</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>network.email.reply_to</code></td>
<td></td>
</tr>
<tr>
<td><code>msg_id (string)</code></td>
<td><code>network.email.mail_id</code></td>
<td></td>
</tr>
<tr>
<td><code>in_reply_to (string)</code></td>
<td><code>about.labels [in_reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>network.email.subject</code></td>
<td></td>
</tr>
<tr>
<td><code>x_originating_ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>first_received (string)</code></td>
<td><code>about.labels [first_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>second_received (string)</code></td>
<td><code>about.labels [second_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>last_reply (string)</code></td>
<td><code>network.smtp.server_response</code></td>
<td></td>
</tr>
<tr>
<td><code>path (array[string] - vector of addr)</code></td>
<td><code>network.smtp.message_path</code></td>
<td>ログフィールド<code>path</code>を反復処理し、<br> <code>index</code>の値が<code>0</code>の場合、<code>path</code>ログフィールドは<code>network.smtp.message_path</code> UDMフィールドにマッピングされます。 <br> それ以外の場合、<code>path</code>ログフィールドは<code>intermediary.ip</code> UDMフィールドにマッピングされます。<br></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>principal.application</code></td>
<td></td>
</tr>
<tr>
<td><code>tls (boolean - bool)</code></td>
<td><code>network.smtp.is_tls</code></td>
<td></td>
</tr>
<tr>
<td><code>fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_webmail (boolean - bool)</code></td>
<td><code>network.smtp.is_webmail</code></td>
<td></td>
</tr>
<tr>
<td><code>urls (array[string] - set[string])</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domains (array[string] - set[string])</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - ssh</h3>

次の表は、<code>ssh</code>ログタイプのログフィールドと、それに対応するUDMフィールドを示しています。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="値を見つけるにはキーワードを入力してください。">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDMマッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDMフィールドは <code>NETWORK_UNCATEGORIZED</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDMフィールドは <code>Zeek</code> に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDMフィールドは <code>SSH</code> に設定されます。</td>
</tr>
<tr>
<td><code>version (整数 - カウント)</code></td>
<td><code>network.application_protocol_version</code></td>
<td><code>network.application_protocol_version</code> UDMフィールドは、<code>version</code> ログフィールドを "SSH <code>version</code>" として設定します。</td>
</tr>
<tr>
<td><code>auth_success (ブール値 - bool)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (ブール値 - bool)</code></td>
<td><code>security_result.action</code></td>
<td><code>auth_success</code> ログフィールドの値が <code>true</code> と<em>等しくない</em>場合、<code>security_result.action</code> UDMフィールドは <code>ALLOW</code> に設定されます。<br><br>それ以外の場合、<code>security_result.action</code> UDMフィールドは <code>BLOCK</code> に設定されます。</td>
</tr>
<tr>
<td><code>auth_attempts (整数 - カウント)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td><code>extensions.auth.auth_details</code> UDMフィールドは、<code>auth_attempts</code> ログフィールドを "auth_attempts: <code>auth_attempts</code>" として設定します。</td>
</tr>
<tr>
<td><code>direction (文字列 - 列挙型)</code></td>
<td><code>network.direction</code></td>
<td><code>direction</code> ログフィールドの値が <code>INBOUND</code> と等しい場合、<code>network.direction</code> UDMフィールドは <code>INBOUND</code> に設定されます。<br><br>それ以外で、<code>direction</code> ログフィールドの値が <code>OUTBOUND</code> と等しい場合、<code>network.direction</code> UDMフィールドは <code>OUTBOUND</code> に設定されます。</td>
</tr>
<tr>
<td><code>client (文字列)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>server (文字列)</code></td>
<td><code>target.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher_alg (文字列)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>mac_alg (文字列)</code></td>
<td><code>security_result.detection_fields [mac_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>compression_alg (文字列)</code></td>
<td><code>security_result.detection_fields [compression_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>kex_alg (文字列)</code></td>
<td><code>security_result.detection_fields [kex_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key_alg (文字列)</code></td>
<td><code>network.tls.server.certificate.version</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key (文字列)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (文字列)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.region (文字列)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.city (文字列)</code></td>
<td><code>target.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (数値 - 倍精度)</code></td>
<td><code>target.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (数値 - 倍精度)</code></td>
<td><code>target.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshVersion (文字列)</code></td>
<td><code>about.labels [hassh_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>hassh (文字列)</code></td>
<td><code>principal.labels [hassh]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServer (文字列)</code></td>
<td><code>target.labels [hassh_server]</code></td>
<td></td>
</tr>
<tr>
<td><code>cshka (文字列)</code></td>
<td><code>about.labels [cshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshAlgorithms (文字列)</code></td>
<td><code>about.labels [hassh_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>sshka (文字列)</code></td>
<td><code>about.labels [sshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServerAlgorithms (文字列)</code></td>
<td><code>about.labels [hassh_server_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (配列[文字列] - セット[文字列])</code></td>
<td><code>security_result.summary, security_result.description, security_result.detection_fields[inferences]</code></td>
<td><code>inferences</code> ログフィールドの値が <code>ABP</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Client Authentication Bypass</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A client wasn't adhering to expectations of SSH either through server exploit or by the client and server switching to a protocol other than SSH after encryption begins</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>AFR</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>SSH Agent Forwarding Requested</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>Agent Forwarding is requested by the Client</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>APWA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Automated Password Authentication</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client authenticated with an automated password tool (like sshpass)</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>AUTO</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Automated Interaction</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client is a script automated utility and not driven by a user</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>BAN</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Server Banner</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The server sent the client a pre-authentication banner, likely for legal reasons</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>BF</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Client Brute Force Guessing</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>BFS</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Client Brute Force Success</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>CTS</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Client Trusted Server</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client already has an entry in its known_hosts file for this server</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>CUS</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Client Untrusted Server</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client did not have an entry in its known_hosts file for this server</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>IPWA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Interactive Password Authentication</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client interactively typed their password to authenticate</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>KS</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Keystrokes</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>An interactive session occurred in which the client set user-driven keystrokes to the server</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>LFD</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Large Client File Download</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>LFU</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Large Client File Upload</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A file transfer occurred in which the client sent a sequence of bytes to the server. Large file are identified dynamically based on trains of MTU-sized packets</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>MFA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Multifactor Authentication</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The server required a second form of authentication (a code) after password or public key was accepted, and the client successfully provided it</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>NA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>None Authentication</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client successfully authenticated using the None method</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>NRC</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>No Remote Command</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The -N flag was used in SSH authentication</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>PKA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Public Key Authentication</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client automatically authenticated using pubkey authentication</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>RSI</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Reverse SSH Initiated</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The Reverse session is initiated from the server back to the client</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>RSIA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Reverse SSH Initiated Automated</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The inititation of the Reverse session happened very early in the packet stream, indicating automation</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>RSK</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Reverse SSH Keystrokes</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>Keystrokes are detected within the Reverse tunnel</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>RSL</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Reverse SSH Logged In</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The Reverse Tunnel login has succeeded</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>RSP</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Reverse SSH Provisioned</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client connected with -R flag, which provisions the port to be used for a Reverse Session set up at any future time</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>SA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Authentication Scanning</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client scanned authentication method with the server and then disconnected</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>SC</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Capabilities Scanning</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The client exchanged capabilities with the server and then disconnected</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>SFD</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Small Client File Download</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>SFU</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Small Client File Upload</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A file transfer occurred in which the client sent a sequence of bytes to the server</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>SP</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Other Scanning</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A client and server didn't exchange encrypted packets but the client wasn't a version or capabilities scanner</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>SV</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Version Scanning</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>A client exchanged version strings with the server and than disconnected</code> に設定されます。<br><br>
<code>inferences</code> ログフィールドの値が <code>UA</code> と等しい場合、<code>security_result.summary</code> UDMフィールドは <code>Unknown Authentication</code> に設定され、<code>security_result.description</code> UDMフィールドは <code>The authentication method is not determinated or is unknown</code> に設定されます。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>フィールドマッピングリファレンス: CORELIGHT - suricata_corelight</h3>

次の表は、<code>suricata_corelight</code> ログタイプのログフィールドと、対応するUDMフィールドを示しています。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>ログフィールド</th>
<th>UDMマッピング</th>
<th>ロジック</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDMフィールドは<code>SCAN_NETWORK</code>に設定されます。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDMフィールドは<code>Suricata</code>に設定されます。</td>
</tr>
<tr>
<td><code>id.vlan (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_type (integer - count)</code></td>
<td><code>about.labels [icmp_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_code (integer - count)</code></td>
<td><code>about.labels [icmp_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_id (string)</code></td>
<td><code>metadata.product_log_id</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>flow_id (integer - count)</code></td>
<td><code>about.labels[flow_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_id (integer - count)</code></td>
<td><code>about.labels [tx_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>pcap_cnt (integer - count)</code></td>
<td><code>about.labels [pcap_cnt]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.action (string)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.gid (integer - count)</code></td>
<td><code>security_result.detection_fields [alert_gid]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature_id (integer - count)</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rev (integer - count)</code></td>
<td><code>security_result.rule_version</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.rule_name</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.category (string)</code></td>
<td><code>security_result.category_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.severity (integer - count)</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[alert_metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload]</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>signature_severity</code></td>
<td><code>security_result.severity</code></td>

Read more

ツールをダウンロード