本文档介绍如何通过配置 Corelight Sensor 和 Chronicle 转发器来收集 Corelight Sensor 日志。本文档还列出了支持的日志类型和支持的 Corelight 版本。
有关更多信息,请参阅 将数据注入 Chronicle。
以下部署架构图说明了如何设置 Corelight Sensor,通过两种不同的摄取架构将日志发送到 Google Security Operations。需要注意的是,每个客户的部署可能与图示有所不同,并且可能更为复杂。
摄取标签用于标识将原始日志数据标准化为结构化 UDM 格式的解析器。本文档中的信息适用于带有 CORELIGHT 摄取标签的解析器。

架构图显示了以下组件:
Corelight Sensor:运行 Corelight Sensor 的系统。
Corelight Sensor 导出器:Corelight Sensor 导出器 从 Sensor 收集日志数据,并将其转发到 Google Security Operations。
Google Security Operations:Google Security Operations 保留并分析来自 Corelight Sensor 的日志。
使用 Sensor 或 Fleet Manager Web 界面配置 Google SecOps 导出器。此配置使用 Google SecOps 实例中的 API 凭据来建立安全连接。
以管理员身份登录 Corelight Sensor 的 Fleet Manager 或 Sensor Web 界面。
导航到导出器配置区域:
在 Create Exporter 部分,点击 Google SecOps。




架构图显示了以下组件:
Corelight Sensor:运行 Corelight Sensor 的系统。
Corelight Sensor 导出器:Corelight Sensor 导出器 从 Sensor 收集日志数据,并将其转发到 Google Security Operations 转发器。
Google Security Operations 转发器:Google Security Operations 转发器是一个轻量级软件组件,部署在客户网络中,支持 syslog。Google Security Operations 转发器将日志转发到 Google Security Operations。
Google Security Operations:Google Security Operations 保留并分析来自 Corelight Sensor 的日志。
要配置 Google Security Operations 转发器,请执行以下操作:
设置 Google Security Operations 转发器。请参阅 在 Linux 上安装和配置转发器。
配置 Google Security Operations 转发器,以将日志发送到 Google Security Operations。 ```none collectors:
### 配置 Corelight Sensor 导出器
1. 以管理员身份登录 Corelight Sensor。
2. 选择 **Export** 标签页。
3. 找到并启用 **EXPORT TO SYSLOG** 选项。
4. 在 **EXPORT TO SYSLOG** 下,配置以下字段:
* **SYSLOG SERVER**:指定 Google Security Operations 转发器 syslog 监听器的 IP 地址和端口。
* 导航到 **Advanced Settings > SYSLOG FORMAT**,并将设置更改为 **Legacy**。

5. 点击 **Apply Changes**。
## 支持的 Corelight 日志类型
Corelight 解析器支持以下日志类型:
<div class="fixed" translate="no">
<h4>Log Type</h4>
<ul>
<li>asset_classification</li>
<li>conn</li>
<li>conn_long</li>
<li>conn_red</li>
<li>conn_agg</li>
<li>dce_rpc</li>
<li>dns</li>
<li>dns_red</li>
<li>files</li>
<li>files_red</li>
<li>http</li>
<li>http2</li>
<li>http_red</li>
<li>intel</li>
<li>irc</li>
<li>notice</li>
<li>rdp</li>
<li>sip</li>
<li>smb_files</li>
<li>smb_mapping</li>
<li>smtp</li>
<li>smtp_links</li>
<li>ssh</li>
<li>ssl</li>
<li>ssl_red</li>
<li>suricata_corelight</li>
<li>bacnet</li>
<li>cip</li>
<li>corelight_burst</li>
<li>corelight_metrics_bro</li>
<li>corelight_metrics_disk</li>
<li>corelight_metrics_iface</li>
<li>corelight_metrics_memory</li>
<li>corelight_metrics_system</li>
<li>corelight_metrics_zeek_doctor</li>
<li>corelight_overall_capture_loss</li>
<li>corelight_profiling</li>
<li>datared</li>
<li>dga</li>
<li>dhcp</li>
<li>dnp3</li>
<li>dpd</li>
<li>encrypted_dns</li>
<li>enip</li>
<li>enip_debug</li>
<li>enip_list_identity</li>
<li>etc_viz</li>
<li>ftp</li>
<li>generic_dns_tunnels</li>
<li>generic_icmp_tunnels</li>
<li>icmp_specific_tunnels</li>
<li>ipsec</li>
<li>iso_cotp</li>
<li>kerberos</li>
<li>known_certs</li>
<li>known_devices</li>
<li>known_domains</li>
<li>known_hosts</li>
<li>known_names</li>
<li>known_remotes</li>
<li>known_services</li>
<li>known_users</li>
<li>ldap</li>
<li>ldap_search</li>
<li>local_subnets</li>
<li>local_subnets_dj</li>
<li>local_subnets_graphs</li>
<li>log4shell</li>
<li>modbus</li>
<li>mqtt_connect</li>
<li>mqtt_publish</li>
<li>mqtt_subscribe</li>
<li>mysql</li>
<li>napatech_shunting</li>
<li>ntlm</li>
<li>ntp</li>
<li>pe</li>
<li>profinet</li>
<li>profinet_dce_rpc</li>
<li>profinet_debug</li>
<li>radius</li>
<li>reporter</li>
<li>rfb</li>
<li>s7comm</li>
<li>smartpcap</li>
<li>snmp</li>
<li>socks</li>
<li>software</li>
<li>specific_dns_tunnels</li>
<li>stepping</li>
<li>stun</li>
<li>stun_nat</li>
<li>suricata_eve</li>
<li>suricata_stats</li>
<li>syslog</li>
<li>tds</li>
<li>tds_rpc</li>
<li>tds_sql_batch</li>
<li>traceroute</li>
<li>tunnel</li>
<li>unknown-smartpcap</li>
<li>vpn</li>
<li>weird</li>
<li>weird_red</li>
<li>wireguard</li>
<li>x509</li>
<li>x509_red</li>
<li>dns_agg</li>
<li>files_agg</li>
<li>http_agg</li>
<li>ssl_agg</li>
<li>weird_agg</li>
<li>analyzer</li>
<li>anomaly</li>
<li>ssdp</li>
<li>telnet</li>
<li>websocket</li>
<li>first_seen</li>
</ul>
</div>
## 字段映射参考
本节说明 Google Security Operations 解析器如何将 Google Security Operations 字段映射到 Google Security Operations 统一数据模型(UDM)字段。
<h3>字段映射参考:CORELIGHT - 通用字段 </h3>
下表列出了 <code>CORELIGHT</code> 日志的通用字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.vendor_name</code></td>
<td>The <code>metadata.vendor_name</code> UDM field is set to <code>Corelight</code>.</td>
</tr>
<tr>
<td><code>_path (string)</code></td>
<td><code>metadata.product_event_type</code></td>
<td></td>
</tr>
<tr>
<td><code>_system_name (string)</code></td>
<td><code>observer.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>ts (time)</code></td>
<td><code>metadata.event_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>uid (string)</code></td>
<td><code>about.labels [uid], network.session_id</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_h (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_p (integer - port)</code></td>
<td><code>principal.port</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_h (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_p (integer - port)</code></td>
<td><code>target.port</code></td>
<td></td>
</tr>
<tr>
<td><code>_write_ts</code></td><code></code>
<td><code>metadata.collected_timestamp</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan (integer - int)</code></td>
<td><code>additional.fields [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - int)</code></td>
<td><code>additional.fields [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_cid (string)</code></td>
<td><code>additional.fields [id_orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_source (string)</code></td>
<td><code>additional.fields [id_orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_status (string)</code></td>
<td><code>additional.fields [id_orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.orig_ep_uid (string)</code></td>
<td><code>additional.fields [id_orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_cid (string)</code></td>
<td><code>additional.fields [id_resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_source (string)</code></td>
<td><code>additional.fields [id_resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_status (string)</code></td>
<td><code>additional.fields [id_resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.resp_ep_uid (string)</code></td>
<td><code>additional.fields [id_resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>uids (array[string] - vector of string)</code></td>
<td><code>additional.fields [uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>count (integer - int)</code></td>
<td><code>additional.fields [count]</code></td>
<td></td>
</tr>
<tr>
<td><code>ts_last</code></td>
<td><code>additional.fields [ts_last]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - asset_classification</h3>
下表列出了 <code>asset_classification</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>Log field</th>
<th>UDM mapping</th>
<th>Logic</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>The <code>metadata.event_type</code> UDM field is set to <code>STATUS_UPDATE</code>.</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>The <code>metadata.product_name</code> UDM field is set to <code>Zeek</code>.</td>
</tr>
<tr>
<td><code>ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>mac</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>vendor_mac (string)</code></td>
<td><code>about.asset.hardware.manufacturer</code></td>
<td></td>
</tr>
<tr>
<td><code>device_type (string)</code></td>
<td><code>about.asset.category</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.platform</code></td>
<td></td>
</tr>
<tr>
<td><code>os_name (string)</code></td>
<td><code>about.asset.attribute.labels</code></td>
<td></td>
</tr>
<tr>
<td><code>type_group (string)</code></td>
<td><code>about.group.group_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>type_name (string)</code></td>
<td><code>about.resource.resource_subtype</code></td>
<td>The <code>about.resource.resource_type</code> UDM field is set to <code>DEVICE</code></td>
</tr>
<tr>
<td><code>brand (string)</code></td>
<td><code>about.user.company_name</code></td>
<td></td>
</tr>
<tr>
<td><code>model (string)</code></td>
<td><code>about.asset.hardware.model</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (integer)</code></td>
<td><code>about.security_result.confidence_score</code></td>
<td></td>
</tr>
<tr>
<td><code>os_ver (string)</code></td>
<td><code>about.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string])</code></td>
<td><code>about.ip_geo_artifact.tags</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - conn, conn_red, conn_long, conn_agg</h3>
下表列出了 <code>conn, conn_red, conn_long, conn_agg</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>将 <code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_CONNECTION</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>将 <code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_bytes (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_bytes (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_state (string)</code></td>
<td><code>metadata.description</code></td>
<td>如果 <code>conn_state</code> 日志字段值等于 <code>S0</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>S0: Connection attempt seen, no reply</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>S1</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>S1: Connection established, not terminated</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>S2</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>S2: Connection established and close attempt by originator seen (but no reply from responder)</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>S3</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>S3: Connection established and close attempt by responder seen (but no reply from originator)</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>SF</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>SF: Normal SYN/FIN completion</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>REJ</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>REJ: Connection attempt rejected</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>RSTO</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>RSTO: Connection established, originator aborted (sent a RST)</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>RSTOS0</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>RSTOS0: Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>RSTOSH</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>RSTOSH: Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>RSTR</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>RSTR: Established, responder aborted</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>SH</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>SH: Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was "half" open)</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>SHR</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>SHR: Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator</code>。<br><br>否则,如果 <code>conn_state</code> 日志字段值等于 <code>OTH</code>,则将 <code>metadata.description</code> UDM 字段设置为 <code>OTH: No SYN seen, just midstream traffic (a partial connection that was not later closed)</code>。</td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_resp (boolean - bool)</code></td>
<td><code>about.labels [local_resp]</code></td>
<td></td>
</tr>
<tr>
<td><code>missed_bytes (integer - count)</code></td>
<td><code>about.labels [missed_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>history (string)</code></td>
<td><code>about.labels [history]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_pkts (integer - count)</code></td>
<td><code>network.sent_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ip_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_pkts (integer - count)</code></td>
<td><code>network.received_packets</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ip_bytes (integer - count)</code></td>
<td><code>target.labels [resp_ip_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>tunnel_parents (array[string] - set[string])</code></td>
<td><code>intermediary.labels [tunnel_parent]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cc (string)</code></td>
<td><code>principal.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cc (string)</code></td>
<td><code>target.ip_geo_artifact.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_ids (array[string] - set[string])</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.url (string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.rule (integer - count)</code></td>
<td><code>security_result.rule_labels [spcap_rule]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.trigger (string)</code></td>
<td><code>security_result.detection_fields [spcap_trigger]</code></td>
<td></td>
</tr>
<tr>
<td><code>app (array[string] - vector of string)</code></td>
<td><code>about.application</code></td>
<td></td>
</tr>
<tr>
<td><code>corelight_shunted (boolean - bool)</code></td>
<td><code>about.labels [corelight_shunted]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_pkts (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_shunted_bytes (integer - count)</code></td>
<td><code>principal.labels [orig_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_pkts (integer - count)</code></td>
<td><code>target.labels [resp_shunted_pkts]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_shunted_bytes (integer - count)</code></td>
<td><code>target.labels [resp_shunted_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_l2_addr (string)</code></td>
<td><code>principal.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_l2_addr (string)</code></td>
<td><code>target.mac</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.src (string)</code></td>
<td><code>principal.labels [id_orig_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n.vals (array[string] - set[string])</code></td>
<td><code>principal.labels [id_orig_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.src (string)</code></td>
<td><code>target.labels [id_resp_h_n_src]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n.vals (array[string] - set[string])</code></td>
<td><code>target.labels [id_resp_h_n_val]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>intermediary.labels [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>inner_vlan (integer - int)</code></td>
<td><code>intermediary.labels [inner_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>将 <code>security_result.severity</code> UDM 字段设置为 <code>INFORMATIONAL</code>。</td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_cid (string)</code></td>
<td><code>additional.fields [orig_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_source (string)</code></td>
<td><code>additional.fields [orig_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_status (string)</code></td>
<td><code>additional.fields [orig_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_ep_uid (string)</code></td>
<td><code>additional.fields [orig_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_cid (string)</code></td>
<td><code>additional.fields [resp_ep_cid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_source (string)</code></td>
<td><code>additional.fields [resp_ep_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_status (string)</code></td>
<td><code>additional.fields [resp_ep_status]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_ep_uid (string)</code></td>
<td><code>additional.fields [resp_ep_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>id_orig_h_n</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>id_resp_h_n</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>netskope_site_ids</code></td>
<td><code>additional.fields[netskope_site_ids]</code></td>
<td>遍历日志字段 <code>netskope_site_ids</code>,然后 <br>将 <code>netskope_site_id_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>netskope_site_id</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>netskope_user_ids</code></td>
<td><code>additional.fields[netskope_user_ids]</code></td>
<td>遍历日志字段 <code>netskope_user_ids</code>,然后 <br>将 <code>netskope_user_id_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>netskope_user_id</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>write_ts</code></td>
<td><code>additional.fields[write_ts]</code></td>
<td></td>
</tr>
<tr>
<td><code>spcap.urls (array[string] - vector of string)</code></td>
<td><code>security_result.url_back_to_product</code></td>
<td>遍历日志字段 <code>spcap.urls</code>,然后 <br>将 <code>spcap.urls</code> 日志字段映射到 <code>security_result.url_back_to_product</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>community_ids (array[string] - vector of string)</code></td>
<td><code>network.community_id</code></td>
<td>遍历日志字段 <code>community_ids</code>,然后<br> 如果索引等于 <code>0</code>,则将 <code>community_id</code> 日志字段映射到 <code>network.community_id</code> UDM 字段。 <br> 否则,将 <code>community_id_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>community_id</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.version</code></td>
<td><code>about.resource.attribute.labels[vpc_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>capture_metadata.vpc.vpc_id</code></td>
<td><code>about.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>about.resource.resource_type</code></td>
<td>如果存在 <code>capture_metadata.vpc.vpc_id</code>,则将 <code>about.resource.resource_type</code> UDM 字段设置为 <code>VPC_NETWORK</code>。</td>
</tr>
<tr>
<td><code>capture_source</code></td>
<td><code>about.resource.attribute.labels[capture_source]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.az</code></td>
<td><code>principal.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.id</code></td>
<td><code>principal.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.name</code></td>
<td><code>principal.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.org_id</code></td>
<td><code>principal.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.sg_ids</code></td>
<td><code>principal.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.subnet_id</code></td>
<td><code>principal.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_inst.vpc_id</code></td>
<td><code>principal.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>principal.resource.resource_type</code></td>
<td>如果存在 <code>orig_inst.vpc_id</code>,则将 <code>principal.resource.resource_type</code> UDM 字段设置为 <code>VPC_NETWORK</code>。</td>
</tr>
<tr>
<td><code>orig_inst.profile</code></td>
<td><code>principal.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.az</code></td>
<td><code>target.location.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.id</code></td>
<td><code>target.resource.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.name</code></td>
<td><code>target.resource.name</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.org_id</code></td>
<td><code>target.resource.attribute.labels[org_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.sg_ids</code></td>
<td><code>target.resource.attribute.labels[sg_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.subnet_id</code></td>
<td><code>target.resource.attribute.labels[subnet_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_inst.vpc_id</code></td>
<td><code>target.resource.attribute.labels[vpc_id]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>target.resource.resource_type</code></td>
<td>如果存在 <code>resp_inst.vpc_id</code>,则将 <code>target.resource.resource_type</code> UDM 字段设置为 <code>VPC_NETWORK</code>。</td>
</tr>
<tr>
<td><code>resp_inst.profile</code></td>
<td><code>target.resource.attribute.labels[profile]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig</code> 和 <code>local_resp</code></td>
<td><code>additional.fields[direction]</code></td>
<td>如果 <code>local_orig</code> 日志字段值等于 <code>true</code> 且 <code>local_resp</code> 日志字段值等于 <code>true</code>,则将 <code>additional.fields[direction]</code> UDM 字段设置为 <code>internal</code>。<br><br>否则,如果 <code>local_orig</code> 日志字段值等于 <code>true</code> 且 <code>local_resp</code> 日志字段值等于 <code>false</code>,则将 <code>additional.fields[direction]</code> UDM 字段设置为 <code>outbound</code>。<br><br>否则,如果 <code>local_orig</code> 日志字段值等于 <code>false</code> 且 <code>local_resp</code> 日志字段值等于 <code>false</code>,则将 <code>additional.fields[direction]</code> UDM 字段设置为 <code>external</code>。<br><br>否则,如果 <code>local_orig</code> 日志字段值等于 <code>false</code> 且 <code>local_resp</code> 日志字段值等于 <code>true</code>,则将 <code>additional.fields[direction]</code> UDM 字段设置为 <code>inbound</code>。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - dce_rpc</h3>
下表列出了 <code>dce_rpc</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>将 <code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_CONNECTION</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td>将 <code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>named_pipe (string)</code></td>
<td><code>intermediary.resource.name</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>intermediary.resource.resource_type</code></td>
<td>如果 <code>named_pipe</code> 日志字段值<em>不</em>为空,则将 <code>intermediary.resource.resource_type</code> UDM 字段设置为 <code>PIPE</code>。</td>
</tr>
<tr>
<td><code>endpoint (string)</code></td>
<td><code>target.labels [endpoint]</code></td>
<td></td>
</tr>
<tr>
<td><code>operation (string)</code></td>
<td><code>target.labels [operation]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td>将 <code>network.application_protocol</code> UDM 字段设置为 <code>DCERPC</code>。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td>将 <code>security_result.severity</code> UDM 字段设置为 <code>INFORMATIONAL</code>。</td>
</tr>
<tr>
<td><code>operation, endpoint, named_pipe (string)</code></td>
<td><code>metadata.description</code></td>
<td>使用 <code>operation</code>、<code>endpoint</code>、<code>named_pipe</code> 日志字段将 <code>metadata.description</code> UDM 字段设置为 "operation <code>operation</code> on <code>endpoint</code> using named pipe <code>named_pipe</code>"。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td>将 <code>network.ip_protocol</code> UDM 字段设置为 <code>TCP</code>。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - dns, dns_red, dns_agg</h3>
下表列出了 <code>dns, dns_red, dns_agg</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_DNS</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>DNS</code>。</td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>trans_id (integer - count)</code></td>
<td><code>network.dns.id</code></td>
<td></td>
</tr>
<tr>
<td><code>rtt (number - interval)</code></td>
<td><code>network.session_duration</code></td>
<td></td>
</tr>
<tr>
<td><code>query (string)</code></td>
<td><code>network.dns.questions.name</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass (integer - count)</code></td>
<td><code>network.dns.questions.class</code></td>
<td></td>
</tr>
<tr>
<td><code>qclass_name (string)</code></td>
<td><code>about.labels [qclass_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype (integer - count)</code></td>
<td><code>network.dns.questions.type</code></td>
<td></td>
</tr>
<tr>
<td><code>qtype_name (string)</code></td>
<td><code>about.labels [qtype_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>rcode (integer - count)</code></td>
<td><code>network.dns.response</code></td>
<td>如果 <code>rcode</code> 日志字段值<em>不</em>为空,则将 <code>network.dns.response</code> UDM 字段设置为 <code>true</code>。</td>
</tr>
<tr>
<td><code>rcode_name (string)</code></td>
<td><code>about.labels [rcode_name]</code></td>
<td></td>
</tr>
<tr>
<td><code>AA (boolean - bool)</code></td>
<td><code>network.dns.authoritative</code></td>
<td></td>
</tr>
<tr>
<td><code>TC (boolean - bool)</code></td>
<td><code>network.dns.truncated</code></td>
<td></td>
</tr>
<tr>
<td><code>RD (boolean - bool)</code></td>
<td><code>network.dns.recursion_desired</code></td>
<td></td>
</tr>
<tr>
<td><code>RA (boolean - bool)</code></td>
<td><code>network.dns.recursion_available</code></td>
<td></td>
</tr>
<tr>
<td><code>Z (integer - count)</code></td>
<td><code>about.labels [Z]</code></td>
<td></td>
</tr>
<tr>
<td><code>answers (array[string] - vector of string)</code></td>
<td><code>network.dns.answers.name</code></td>
<td></td>
</tr>
<tr>
<td><code>TTLs (array[number] - vector of interval)</code></td>
<td><code>network.dns.answers.ttl</code></td>
<td></td>
</tr>
<tr>
<td><code>rejected (boolean - bool)</code></td>
<td><code>about.labels [rejected]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_trusted_domain (string)</code></td>
<td><code>about.labels [is_trusted_domain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_host_subdomain (string)</code></td>
<td><code>about.labels [icann_host_subdomain]</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_domain (string)</code></td>
<td><code>network.dns_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>icann_tld (string)</code></td>
<td><code>about.labels [icann_tld]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>security_result.detection_fields [num]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - http, http_red, http2, http_agg</h3>
下表列出了 <code>http, http_red, http2, http_agg</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_HTTP</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>network.http.method</code></td>
<td></td>
</tr>
<tr>
<td><code>host (string)</code></td>
<td><code>target.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>referrer (string)</code></td>
<td><code>network.http.referral_url</code></td>
<td></td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.application_protocol_version</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>network.http.user_agent</code></td>
<td></td>
</tr>
<tr>
<td><code>origin (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>network.http.response_code</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>about.labels [status_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_code (integer - count)</code></td>
<td><code>about.labels [info_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>info_msg (string)</code></td>
<td><code>about.labels [info_msg]</code></td>
<td></td>
</tr>
<tr>
<td><code>tags (array[string] - set[enum])</code></td>
<td><code>about.labels [tags]</code></td>
<td></td>
</tr>
<tr>
<td><code>username (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>password (string)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td></td>
</tr>
<tr>
<td><code>proxied (array[string] - set[string])</code></td>
<td><code>intermediary.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [orig_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_filenames (array[string] - vector of string)</code></td>
<td><code>src.file.names</code></td>
<td>当 <code>orig_filenames</code> 中的索引值等于 <code>0</code> 时,将 <code>orig_filenames</code> 日志字段映射到 <code>src.file.names</code> UDM 字段。<br><br>对于其他所有索引值,将 <code>orig_filenames</code> 日志字段映射到 <code>about.file.names</code>。</td>
</tr>
<tr>
<td><code>orig_mime_types (array[string] - vector of string)</code></td>
<td><code>src.file.mime_type</code></td>
<td>当 <code>orig_mime_types</code> 中的索引值等于 <code>0</code> 时,将 <code>orig_mime_types</code> 日志字段映射到 <code>src.file.mime_type</code> UDM 字段。<br><br>对于其他所有索引值,将 <code>orig_mime_types</code> 日志字段映射到 <code>about.file.mime_type</code>。</td>
</tr>
<tr>
<td><code>resp_fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [resp_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_filenames (array[string] - vector of string)</code></td>
<td><code>target.file.names</code></td>
<td>当 <code>resp_filenames</code> 中的索引值等于 <code>0</code> 时,将 <code>resp_filenames</code> 日志字段映射到 <code>target.file.names</code> UDM 字段。<br><br>对于其他所有索引值,将 <code>resp_filenames</code> 日志字段映射到 <code>about.file.names</code>。</td>
</tr>
<tr>
<td><code>resp_mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>当 <code>resp_mime_types</code> 中的索引值等于 <code>0</code> 时,将 <code>resp_mime_types</code> 日志字段映射到 <code>target.file.mime_type</code> UDM 字段。<br><br>对于其他所有索引值,将 <code>resp_mime_types</code> 日志字段映射到 <code>about.file.mime_type</code>。</td>
</tr>
<tr>
<td><code>post_body (string)</code></td>
<td><code>about.labels [post_body]</code></td>
<td></td>
</tr>
<tr>
<td><code>stream_id (integer - count)</code></td>
<td><code>about.labels [stream_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>encoding (string)</code></td>
<td><code>about.labels [encoding]</code></td>
<td></td>
</tr>
<tr>
<td><code>push (boolean - bool)</code></td>
<td><code>about.labels [push]</code></td>
<td></td>
</tr>
<tr>
<td><code>versions (array[float] - vector of float)</code></td>
<td><code>network.application_protocol_version</code></td>
<td>遍历 <code>versions</code> 日志字段,然后<br> 如果索引等于 <code>0</code>,则将 <code>version</code> 日志字段映射到 <code>network.application_protocol_version</code> UDM 字段。<br> 否则,将 <code>version_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>version</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>user_agents (array[string] - vector of string)</code></td>
<td><code>network.http.user_agent</code></td>
<td>遍历 <code>user_agents</code> 日志字段,然后<br> 如果索引等于 <code>0</code>,则将 <code>user_agent</code> 日志字段映射到 <code>network.http.user_agent</code> UDM 字段。<br> 否则,将 <code>user_agent_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>user_agent</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - smtp_links</h3>
下表列出了 <code>smtp_links</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_SMTP</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>SMTP</code>。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>link (string)</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domain (string)</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - irc</h3>
下表列出了 <code>irc</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_UNCATEGORIZED</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>nick (string)</code></td>
<td><code>principal.user.user_display_name</code></td>
<td></td>
</tr>
<tr>
<td><code>user (string)</code></td>
<td><code>principal.user.userid</code></td>
<td>如果 <code>user</code> 日志字段值小于或等于 255,则将 <code>user</code> 日志字段映射到 <code>principal.user.userid</code> UDM 字段。<br><br>否则,将 <code>user</code> 日志字段映射到 <code>about.labels</code> UDM 字段。</td>
</tr>
<tr>
<td><code>command, value, addl</code></td>
<td><code>principal.process.command_line</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_file_size (integer - count)</code></td>
<td><code>src.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>dcc_mime_type (string)</code></td>
<td><code>src.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - files, files_red, files_agg</h3>
下表列出了 <code>files, files_red, files_agg</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_UNCATEGORIZED</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_hosts (array[string] - set[addr])</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>rx_hosts (array[string] - set[addr])</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>conn_uids (array[string] - set[string])</code></td>
<td><code>about.labels [conn_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>source (string)</code></td>
<td><code>about.labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>depth (integer - count)</code></td>
<td><code>about.labels [depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>analyzers (array[string] - set[string])</code></td>
<td><code>about.labels [analyzer]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_type (string)</code></td>
<td><code>about.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>filename (string)</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>duration (number - interval)</code></td>
<td><code>about.labels [duration]</code></td>
<td></td>
</tr>
<tr>
<td><code>local_orig (boolean - bool)</code></td>
<td><code>about.labels [local_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_orig (boolean - bool)</code></td>
<td><code>about.labels [is_orig]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen_bytes (integer - count)</code></td>
<td><code>about.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>total_bytes (integer - count)</code></td>
<td><code>about.labels [total_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>missing_bytes (integer - count)</code></td>
<td><code>about.labels [missing_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>overflow_bytes (integer - count)</code></td>
<td><code>about.labels [overflow_bytes]</code></td>
<td></td>
</tr>
<tr>
<td><code>timedout (boolean - bool)</code></td>
<td><code>about.labels [timedout]</code></td>
<td></td>
</tr>
<tr>
<td><code>parent_fuid (string)</code></td>
<td><code>about.labels [parent_fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>about.file.md5</code></td>
<td></td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>about.file.sha1</code></td>
<td></td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>about.file.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.client.certificate.md5</code></td>
<td>如果 <code>source</code> 日志字段值等于 <code>ssl</code>,且 <code>mime_type</code> 日志字段值等于 <code>application/x-x509-user-cert</code>,且 <code>_path</code> 日志字段值等于 <code>files</code>,则将 <code>network.tls.client.certificate.md5</code> UDM 字段设置为 <code>md5</code>。</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.client.certificate.sha1</code></td>
<td>如果 <code>source</code> 日志字段值等于 <code>ssl</code>,且 <code>mime_type</code> 日志字段值等于 <code>application/x-x509-user-cert</code>,且 <code>_path</code> 日志字段值等于 <code>files</code>,则将 <code>network.tls.client.certificate.sha1</code> UDM 字段设置为 <code>sha1</code>。</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.client.certificate.sha256</code></td>
<td>如果 <code>source</code> 日志字段值等于 <code>ssl</code>,且 <code>mime_type</code> 日志字段值等于 <code>application/x-x509-user-cert</code>,且 <code>_path</code> 日志字段值等于 <code>files</code>,则将 <code>network.tls.client.certificate.sha256</code> UDM 字段设置为 <code>sha256</code>。</td>
</tr>
<tr>
<td><code>md5 (string)</code></td>
<td><code>network.tls.server.certificate.md5</code></td>
<td>如果 <code>source</code> 日志字段值等于 <code>ssl</code>,且 <code>mime_type</code> 日志字段值等于 <code>application/x-x509-ca-cert</code>,且 <code>_path</code> 日志字段值等于 <code>files</code>,则将 <code>network.tls.server.certificate.md5</code> UDM 字段设置为 <code>md5</code>。</td>
</tr>
<tr>
<td><code>sha1 (string)</code></td>
<td><code>network.tls.server.certificate.sha1</code></td>
<td>如果 <code>source</code> 日志字段值等于 <code>ssl</code>,且 <code>mime_type</code> 日志字段值等于 <code>application/x-x509-ca-cert</code>,且 <code>_path</code> 日志字段值等于 <code>files</code>,则将 <code>network.tls.server.certificate.sha1</code> UDM 字段设置为 <code>sha1</code>。</td>
</tr>
<tr>
<td><code>sha256 (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td>如果 <code>source</code> 日志字段值等于 <code>ssl</code>,且 <code>mime_type</code> 日志字段值等于 <code>application/x-x509-ca-cert</code>,且 <code>_path</code> 日志字段值等于 <code>files</code>,则将 <code>network.tls.server.certificate.sha256</code> UDM 字段设置为 <code>sha256</code>。</td>
</tr>
<tr>
<td><code>extracted (array[string] - set[string])</code></td>
<td><code>about.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_cutoff (boolean - bool)</code></td>
<td><code>about.labels [extracted_cutoff]</code></td>
<td></td>
</tr>
<tr>
<td><code>extracted_size (integer - count)</code></td>
<td><code>about.labels [extracted_size]</code></td>
<td></td>
</tr>
<tr>
<td><code>num (integer - count)</code></td>
<td><code>about.labels [num]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan (integer - int)</code></td>
<td><code>additional.fields [vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>vlan_inner (integer - int)</code></td>
<td><code>additional.fields [vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>mime_types (array[string] - vector of string)</code></td>
<td><code>target.file.mime_type</code></td>
<td>遍历日志字段 <code>mime_type</code>,然后<br> 如果索引等于 <code>0</code>,则将 <code>mime_type</code> 日志字段映射到 <code>target.file.mime_type</code> UDM 字段。 <br> 否则,将 <code>mime_type_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>mime_type</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>timedouts (array[boolean] - vector of bool)</code></td>
<td><code>additional.fields[timedouts]</code></td>
<td>遍历日志字段 <code>timedouts</code>,然后 <br>将 <code>timedout_%{index}</code> 日志字段映射到 <code>additional.fields.key</code> UDM 字段,并将 <code>timedouts</code> 日志字段映射到 <code>additional.fields.value</code> UDM 字段。<br></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - notice</h3>
下表列出了 <code>notice</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="Type a keyword to find a value.">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_UNCATEGORIZED</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>target.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>about.labels [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>proto (string - enum)</code></td>
<td><code>network.ip_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>note (string - enum)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>msg (string)</code></td>
<td><code>metadata.description</code></td>
<td></td>
</tr>
<tr>
<td><code>sub (string)</code></td>
<td><code>about.labels [sub]</code></td>
<td></td>
</tr>
<tr>
<td><code>src (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>dst (string - addr)</code></td>
<td><code>target.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>p (integer - port)</code></td>
<td><code>about.port</code></td>
<td></td>
</tr>
<tr>
<td><code>n (integer - count)</code></td>
<td><code>about.labels [n]</code></td>
<td></td>
</tr>
<tr>
<td><code>peer_descr (string)</code></td>
<td><code>about.labels [peer_descr]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.action </code></td>
<td><code>security_result.action</code> UDM 字段设置为 <code>ALLOW</code>。</td>
</tr>
<tr>
<td><code>actions (array[string] - set[enum])</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>suppress_for (number - interval)</code></td>
<td><code>about.labels [suppress_for]</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td><code>about.location.country_or_region</code> UDM 字段使用 <code>remote_location.country_code</code>、<code>remote_location.region</code> 日志字段设置为 "<code>remote_location.country_code</code>: <code>remote_location.region</code>"。</td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>about.location.country_or_region</code></td>
<td><code>about.location.country_or_region</code> UDM 字段使用 <code>remote_location.country_code</code>、<code>remote_location.region</code> 日志字段设置为 "<code>remote_location.country_code</code>: <code>remote_location.region</code>"。</td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>about.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>about.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>about.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>如果 <code>severity.level</code> 日志字段值包含以下任一值<div style='margin-top: -0.8em;'></div><ul><li><code>0</code></li><li><code> 1</code></li></ul><div style='margin-top: -0.8em;'></div>,则将 <code> security_result.severity </code> UDM 字段设置为 <code>HIGH</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>severity.level</code> 日志字段值等于 <code> 2 </code>,则将 <code> security_result.severity </code> UDM 字段设置为 <code>CRITICAL</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>severity.level</code> 日志字段值等于 <code> 3 </code>,则将 <code> security_result.severity </code> UDM 字段设置为 <code>ERROR</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>severity.level</code> 日志字段值包含以下任一值<div style='margin-top: -0.8em;'></div><ul><li><code>4</code></li><li><code>5</code></li><li><code>6</code></li></ul><div style='margin-top: -0.8em;'></div>,则将 <code> security_result.severity </code> UDM 字段设置为 <code>INFORMATIONAL</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>severity.level</code> 日志字段值等于 <code> 7 </code>,则将 <code> security_result.severity </code> UDM 字段设置为 <code>LOW</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,将 <code> security_result.severity </code> UDM 字段设置为 <code>UNKNOWN_SEVERITY</code>。 <br></td>
</tr>
<tr>
<td><code>severity.name</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>severity.level</code></td>
<td><code>security_result.detection_fields [severity_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>如果 <code>resp_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Critical" or the <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "4 </code>" </code>,则将 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>CRITICAL</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)High" or the <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "3 </code>" </code>,则将 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>HIGH</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Low" or the <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "1 </code>" </code>,则将 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>LOW</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Medium" or the <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "2 </code>" </code>,则将 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>MEDIUM</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Unknown_Severity" </code> 匹配,或 <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "0 </code>",则将 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>UNKNOWN_SEVERITY</code>。 <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname (string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain (string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version (string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source (string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>如果 <code>orig_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Critical" or the <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "4 </code>" </code>,则将 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>CRITICAL</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)High" or the <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "3 </code>" </code>,则将 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>HIGH</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Low" or the <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "1 </code>" </code>,则将 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>LOW</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Medium" or the <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "2 </code>" </code>,则将 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>MEDIUM</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值与正则表达式模式 <code> "(?i)Unknown_Severity" </code> 匹配,或 <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "0 </code>",则将 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段设置为 <code>UNKNOWN_SEVERITY</code>。 <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid (string)</code></td>
<td><code>additional.fields [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname (string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain (string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version (string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source (string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - smb_files</h3>
下表列出了 <code>smb_files</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td>如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_READ</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_READ</code>。<br><br>否则,如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_WRITE</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_MODIFICATION</code>。<br><br>否则,如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_OPEN</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_OPEN</code>。<br><br>否则,如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_CLOSE</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_UNCATEGORIZED</code>。<br><br>否则,如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_DELETE</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_DELETION</code>。<br><br>否则,如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_RENAME</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_MOVE</code>。<br><br>否则,如果 <code>action</code> 日志字段值等于 <code>SMB::FILE_SET_ATTRIBUTE</code>,则 <code>metadata.event_type</code> UDM 字段设置为 <code>FILE_UNCATEGORIZED</code>。<br><br>否则,<code>metadata.event_type</code> UDM 字段设置为 <code>FILE_UNCATEGORIZED</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>SMB</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM 字段设置为 <code>TCP</code>。</td>
</tr>
<tr>
<td><code>action, name</code></td>
<td><code>metadata.description</code></td>
<td><code>metadata.description</code> UDM 字段使用 <code>action</code>、<code>name</code> 日志字段设置,格式为 "action: <code>action</code> on: <code>name</code>"。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM 字段设置为 <code>INFORMATIONAL</code>。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM 字段设置为 <code>ALLOW</code>。</td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>action (string - enum)</code></td>
<td><code>target.labels [action]</code></td>
<td></td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.file.full_path</code></td>
<td></td>
</tr>
<tr>
<td><code>name (string)</code></td>
<td><code>target.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>size (integer - count)</code></td>
<td><code>target.file.size</code></td>
<td></td>
</tr>
<tr>
<td><code>prev_name (string)</code></td>
<td><code>src.file.names</code></td>
<td></td>
</tr>
<tr>
<td><code>times.modified (time)</code></td>
<td><code>target.file.last_modification_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.accessed (time)</code></td>
<td><code>target.file.last_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.created (time)</code></td>
<td><code>target.file.first_seen_time</code></td>
<td></td>
</tr>
<tr>
<td><code>times.changed (time)</code></td>
<td><code>target.labels [times_changed]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_offset_req (integer - count)</code></td>
<td><code>target.labels [data_offset_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_req (integer - count)</code></td>
<td><code>target.labels [data_len_req]</code></td>
<td></td>
</tr>
<tr>
<td><code>data_len_rsp (integer - count)</code></td>
<td><code>target.labels [data_len_rsp]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - smb_mapping</h3>
下表列出了 <code>smb_mapping</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_CONNECTION</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>SMB</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM 字段设置为 <code>TCP</code>。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM 字段设置为 <code>INFORMATIONAL</code>。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM 字段设置为 <code>ALLOW</code>。</td>
</tr>
<tr>
<td><code>path (string)</code></td>
<td><code>target.resource.attribute.labels [path]</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>target.application</code></td>
<td></td>
</tr>
<tr>
<td><code>native_file_system (string)</code></td>
<td><code>target.resource.attribute.labels [native_file_system]</code></td>
<td></td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_type</code></td>
<td>如果 <code>share_type</code> 日志字段值等于 <code>DISK</code>,则 <code>target.resource.resource_type</code> UDM 字段设置为 <code>STORAGE_OBJECT</code>。<br><br>否则,如果 <code>share_type</code> 日志字段值等于 <code>PIPE</code>,则 <code>target.resource.resource_type</code> UDM 字段设置为 <code>PIPE</code>。<br><br>否则,<code>target.resource.resource_type</code> UDM 字段设置为 <code>UNSPECIFIED</code>。</td>
</tr>
<tr>
<td><code>share_type (string)</code></td>
<td><code>target.resource.resource_subtype</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - ssl, ssl_red, ssl_agg</h3>
下表列出了 <code>ssl, ssl_red, ssl_agg</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_CONNECTION</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>HTTPS</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM 字段设置为 <code>TCP</code>。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM 字段设置为 <code>INFORMATIONAL</code>。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.action</code></td>
<td><code>security_result.action</code> UDM 字段设置为 <code>ALLOW</code>。</td>
</tr>
<tr>
<td><code>version (string)</code></td>
<td><code>network.tls.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>curve (string)</code></td>
<td><code>network.tls.curve</code></td>
<td></td>
</tr>
<tr>
<td><code>server_name (string)</code></td>
<td><code>network.tls.client.server_name</code></td>
<td></td>
</tr>
<tr>
<td><code>resumed (boolean - bool)</code></td>
<td><code>network.tls.resumed</code></td>
<td></td>
</tr>
<tr>
<td><code>last_alert (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>next_protocol (string)</code></td>
<td><code>network.tls.next_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>established (boolean - bool)</code></td>
<td><code>network.tls.established</code></td>
<td></td>
</tr>
<tr>
<td><code>ssl_history (string)</code></td>
<td><code>about.labels [ssl_history]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>target.labels [cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_cert_chain_fps (array[string] - vector of string)</code></td>
<td><code>principal.labels [client_cert_chain_fps]</code></td>
<td></td>
</tr>
<tr>
<td><code>sni_matches_cert (boolean - bool)</code></td>
<td><code>about.labels [sni_matches_cert]</code></td>
<td></td>
</tr>
<tr>
<td><code>validation_status (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3 (string)</code></td>
<td><code>network.tls.client.ja3</code></td>
<td></td>
</tr>
<tr>
<td><code>ja3s (string)</code></td>
<td><code>network.tls.server.ja3s</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - rdp</h3>
下表列出了 <code>rdp</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_CONNECTION</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>cookie (string)</code></td>
<td><code>principal.user.userid</code></td>
<td></td>
</tr>
<tr>
<td><code>result (string)</code></td>
<td><code>about.labels [result]</code></td>
<td></td>
</tr>
<tr>
<td><code>security_protocol (string)</code></td>
<td><code>target.labels [security_protocol]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_channels (array[string] - vector of string)</code></td>
<td><code>intermediary.labels [client_channels]</code></td>
<td></td>
</tr>
<tr>
<td><code>keyboard_layout (string)</code></td>
<td><code>principal.labels [keyboard_layout]</code></td>
<td></td>
</tr>
<tr>
<td><code>client_build (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>client_name (string)</code></td>
<td><code>principal.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>client_dig_product_id (string)</code></td>
<td><code>principal.asset.product_object_id</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_width (integer - count)</code></td>
<td><code>principal.labels [desktop_width]</code></td>
<td></td>
</tr>
<tr>
<td><code>desktop_height (integer - count)</code></td>
<td><code>principal.labels [desktop_height]</code></td>
<td></td>
</tr>
<tr>
<td><code>requested_color_depth (string)</code></td>
<td><code>principal.labels [requested_color_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_type (string)</code></td>
<td><code>about.labels [cert_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_count (integer - count)</code></td>
<td><code>about.labels [cert_count]</code></td>
<td></td>
</tr>
<tr>
<td><code>cert_permanent (boolean - bool)</code></td>
<td><code>about.labels [cert_permanent ]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_level (string)</code></td>
<td><code>about.labels [encryption_level]</code></td>
<td></td>
</tr>
<tr>
<td><code>encryption_method (string)</code></td>
<td><code>about.labels [encryption_method]</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>如果 <code>auth_success</code> 日志字段值等于 <code>true</code>,则 <code>security_result.action</code> UDM 字段设置为 <code>ALLOW</code>。<br>否则,<code>security_result.action</code> UDM 字段设置为 <code>FAIL</code>。</td>
</tr>
<tr>
<td><code>channels_joined (integer - int)</code></td>
<td><code>intermediary.labels [channels_joined]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>about.labels [inferences]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdpeudp_uid (string)</code></td>
<td><code>about.labels [rdpeudp_uid]</code></td>
<td></td>
</tr>
<tr>
<td></td>
<td><code>network.ip_protocol</code></td>
<td><code>network.ip_protocol</code> UDM 字段设置为 <code>TCP</code>。</td>
</tr>
<tr>
<td><code>rdfp_string (string)</code></td>
<td><code>principal.labels [rdfp_string]</code></td>
<td></td>
</tr>
<tr>
<td><code>rdfp_hash (string)</code></td>
<td><code>principal.labels [rdfp_hash]</code></td>
<td></td>
</tr>
<tr>
<td><code>result, security_protocol</code></td>
<td><code>security_result.description</code></td>
<td><code>security_result.description</code> UDM 字段使用 <code>result</code>、<code>security_protocol</code> 日志字段设置,格式为 "<code>result</code> connection with security protocol <code>security_protocol</code>"。</td>
</tr>
<tr>
<td></td>
<td><code>security_result.severity</code></td>
<td><code>security_result.severity</code> UDM 字段设置为 <code>INFORMATIONAL</code>。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - sip</h3>
下表列出了 <code>sip</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_UNCATEGORIZED</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>SIP</code>。</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>method (string)</code></td>
<td><code>about.labels [method]</code></td>
<td></td>
</tr>
<tr>
<td><code>uri (string)</code></td>
<td><code>target.url</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_from (string)</code></td>
<td><code>principal.labels [request_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_to (string)</code></td>
<td><code>target.labels [request_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_from</code></td>
<td><code>principal.labels [response_from]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_to (string)</code></td>
<td><code>target.labels [response_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>about.labels [reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>call_id (string)</code></td>
<td><code>about.labels[call_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>seq (string)</code></td>
<td><code>about.labels [seq]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>about.labels [subject]</code></td>
<td></td>
</tr>
<tr>
<td><code>request_path (array[string] - vector of string)</code></td>
<td><code>about.labels [request_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>response_path (array[string] - vector of string)</code></td>
<td><code>about.labels [response_path]</code></td>
<td></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>about.labels [user_agent]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_code (integer - count)</code></td>
<td><code>about.labels [status_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>status_msg (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>warning (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>request_body_len (integer - count)</code></td>
<td><code>network.sent_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>response_body_len (integer - count)</code></td>
<td><code>network.received_bytes</code></td>
<td></td>
</tr>
<tr>
<td><code>content_type (string)</code></td>
<td><code>about.labels [content_type]</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - intel</h3>
下表列出了 <code>intel</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>SCAN_NETWORK</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.metadata.entity_type</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::ADDR</code>,则将 <code>metadata.entity_type</code> UDM 字段设置为 <code>IP_ADDRESS</code>。<br><br>否则,如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::SUBNET</code>、<code>Intel::SOFTWARE</code>、<code>Intel::CERT_HASH</code> 或 <code>Intel::PUBKEY_HASH</code>,则将 <code>metadata.entity_type</code> UDM 字段设置为 <code>RESOURCE</code>。<br><br>否则,如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::URL</code>,则将 <code>metadata.entity_type</code> UDM 字段设置为 <code>URL</code>。<br><br>否则,如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::EMAIL</code> 或 <code>Intel::USER_NAME</code>,则将 <code>metadata.entity_type</code> UDM 字段设置为 <code>USER</code>。<br><br>否则,如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::DOMAIN</code>,则将 <code>metadata.entity_type</code> UDM 字段设置为 <code>DOMAIN_NAME</code>。<br><br>否则,如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::FILE_HASH</code> 或 <code>Intel::FILE_NAME</code>,则将 <code>metadata.entity_type</code> UDM 字段设置为 <code>FILE</code>。<br><br>否则,将 <code>metadata.entity_type</code> UDM 字段设置为 <code>RESOURCE</code>。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.ip</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::ADDR</code>,则将 <code>seen.indicator</code> 日志字段映射到 <code>entity.ip</code> UDM 字段。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.url</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::URL</code>,则将 <code>seen.indicator</code> 日志字段映射到 <code>entity.url</code> UDM 字段。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.domain.name</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::DOMAIN</code>,则将 <code>seen.indicator</code> 日志字段映射到 <code>entity.domain.name</code> UDM 字段。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.user.email_address</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::USER_NAME</code> 或 <code>Intel::EMAIL</code>,则将 <code>seen.indicator</code> 日志字段映射到 <code>entity.user.email_address</code> UDM 字段。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.file.names</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::FILE_HASH</code> 或 <code>Intel::FILE_NAME</code>,则将 <code>seen.indicator</code> 日志字段映射到 <code>entity.file.full_path</code> UDM 字段。</td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>entity.resource.name</code></td>
<td>如果 <code>metadata.entity_type</code> 日志字段值等于 <code>RESOURCE</code>,则将 <code>seen.indicator</code> 日志字段映射到 <code>entity.resource.name</code> UDM 字段。</td>
</tr>
<tr>
<td></td>
<td><code>entity.resource.resource_type</code></td>
<td>如果 <code>indicator.type</code> 日志字段值等于 <code>Intel::SUBNET</code>,则将 <code>entity.resource.resource_name</code> UDM 字段设置为 <code>VPC_NETWORK</code>。</td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>entity.resource.resource_sub_type</code></td>
<td>如果 <code>metadata.entity_type</code> 日志字段值等于 <code>RESOURCE</code>,则将 <code>seen.indicator_type</code> 日志字段映射到 <code>entity.resource.resource_sub_type</code> UDM 字段。</td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>entity.metadata.source_labels [seen_where]</code></td>
<td></td>
</tr>
<tr>
<td><code>matched (array[string] - set[enum])</code></td>
<td><code>entity.labels [matched]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>entity.metadata.source_labels [source]</code></td>
<td></td>
</tr>
<tr>
<td><code>fuid (string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>file_mime_type (string)</code></td>
<td><code>entity.file.mime_type</code></td>
<td></td>
</tr>
<tr>
<td><code>file_desc (string)</code></td>
<td><code>metadata.threat.detection_fields [file_desc]</code></td>
<td></td>
</tr>
<tr>
<td><code>desc (array[string] - set[string])</code></td>
<td><code>ioc.description</code></td>
<td>当 <code>desc</code> 中的索引值等于 <code>0</code> 时,将 <code>desc</code> 日志字段映射到 <code>ioc.description</code> UDM 字段。<br><br>对于其他索引值,<code>entity.labels.key</code> UDM 字段设置为 <code>desc</code>, <code>desc</code> 日志字段映射到 <code>entity.labels.value</code>。</td>
</tr>
<tr>
<td><code>url (array[string] - set[string])</code></td>
<td><code>metadata.threat.url_back_to_product</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>ioc.confidence_score</code></td>
<td>当 <code>confidence</code> 中的索引值等于 <code>0</code> 时,将 <code>confidence</code> 日志字段映射到 <code>ioc.confidence_score</code> UDM 字段。<br><br>对于其他索引值,<code>entity.labels.key</code> UDM 字段设置为 <code>confidence</code>, <code>confidence</code> 日志字段映射到 <code>entity.labels.value</code>。</td>
</tr>
<tr>
<td><code>firstseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.start</code></td>
<td>当 <code>firstseen</code> 中的索引值等于 <code>0</code> 时,将 <code>firstseen</code> 日志字段映射到 <code>ioc.active_timerange.start</code> UDM 字段。<br><br>对于其他索引值,<code>entity.labels.key</code> UDM 字段设置为 <code>firstseen</code>, <code>firstseen</code> 日志字段映射到 <code>entity.labels.value</code>。</td>
</tr>
<tr>
<td><code>lastseen (array[string] - set[string])</code></td>
<td><code>ioc.active_timerange.end</code></td>
<td>当 <code>lastseen</code> 中的索引值等于 <code>0</code> 时,将 <code>lastseen</code> 日志字段映射到 <code>ioc.active_timerange.end</code> UDM 字段。<br><br>对于其他索引值,<code>entity.labels.key</code> UDM 字段设置为 <code>lastseen</code>, <code>lastseen</code> 日志字段映射到 <code>entity.labels.value</code>。</td>
</tr>
<tr>
<td><code>associated (array[string] - set[string])</code></td>
<td><code>entity.labels [associated]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>ioc.categorization</code></td>
<td>当 <code>category</code> 中的索引值等于 <code>0</code> 时,将 <code>category</code> 日志字段映射到 <code>ioc.categorization</code> UDM 字段。<br><br>对于其他索引值,<code>entity.labels.key</code> UDM 字段设置为 <code>category</code>, <code>category</code> 日志字段映射到 <code>entity.labels.value</code>。</td>
</tr>
<tr>
<td><code>campaigns (array[string] - set[string])</code></td>
<td><code>entity.labels [campaign]</code></td>
<td></td>
</tr>
<tr>
<td><code>reports (array[string] - set[string])</code></td>
<td><code>entity.labels [report]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator (string)</code></td>
<td><code>about.labels [indicator]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.indicator_type (string - enum)</code></td>
<td><code>about.labels [indicator_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>seen.where (string - enum)</code></td>
<td><code>about.labels [where]</code></td>
<td></td>
</tr>
<tr>
<td><code>sources (array[string] - set[string])</code></td>
<td><code>about.labels [sources]</code></td>
<td></td>
</tr>
<tr>
<td><code>confidence (array[number] - set[double])</code></td>
<td><code>about.labels [confidence]</code></td>
<td></td>
</tr>
<tr>
<td><code>category (array[string] - set[string])</code></td>
<td><code>about.labels [category]</code></td>
<td></td>
</tr>
<tr>
<td><code>threat_score (array[number] - set[double])</code></td>
<td><code>entity.security_result.detection_fields[threat_score]</code></td>
<td></td>
</tr>
<tr>
<td><code>verdict (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.verdict_response</code></td>
<td>遍历 <code>verdict</code>,<div style='margin-bottom: 0.5em;'></div><div style='margin-bottom: 0.0em;'></div>如果 <code>verdict</code> 日志字段值与正则表达式模式 <code> "(?i)Malicious" 匹配,或 <code>verdict</code> 日志字段值等于 <code> "1" </code> </code>,则将 <code> "entity.security_result.verdict_info.verdict_response" </code> UDM 字段设置为 <code>MALICIOUS</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>verdict</code> 日志字段值与正则表达式模式 <code> "(?i)Benign" 匹配,或 <code>verdict</code> 日志字段值等于 <code> "2" </code> </code>,则将 <code> "entity.security_result.verdict_info.verdict_response" </code> UDM 字段设置为 <code>BENIGN</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,将 <code> "entity.security_result.verdict_info.verdict_response" </code> UDM 字段设置为 <code>VERDICT_RESPONSE_UNSPECIFIED</code>。 <br></td>
</tr>
<tr>
<td><code>verdict_source (array[string] - set[string])</code></td>
<td><code>entity.security_result.verdict_info.source_provider</code></td>
<td>遍历 <code>verdict_source</code>,<div style='margin-bottom: 0.5em;'></div><code>verdict_source</code> 日志字段映射到 <code> entity.security_result.VerdictInfo.source_provider </code> UDM 字段。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - smtp</h3>
下表列出了 <code>smtp</code> 日志类型的日志字段及其对应的 UDM 字段。
<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段设置为 <code>NETWORK_SMTP</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段设置为 <code>SMTP</code>。</td>
</tr>
<tr>
<td><code>trans_depth (integer - count)</code></td>
<td><code>about.labels [trans_depth]</code></td>
<td></td>
</tr>
<tr>
<td><code>helo (string)</code></td>
<td><code>network.smtp.helo</code></td>
<td></td>
</tr>
<tr>
<td><code>mailfrom (string)</code></td>
<td><code>network.smtp.mail_from</code></td>
<td></td>
</tr>
<tr>
<td><code>rcptto (array[string] - set[string])</code></td>
<td><code>network.smtp.rcpt_to</code></td>
<td></td>
</tr>
<tr>
<td><code>date (string)</code></td>
<td><code>about.labels [date]</code></td>
<td></td>
</tr>
<tr>
<td><code>from (string)</code></td>
<td><code>network.email.from</code></td>
<td></td>
</tr>
<tr>
<td><code>to (array[string] - set[string])</code></td>
<td><code>network.email.to</code></td>
<td></td>
</tr>
<tr>
<td><code>cc (array[string] - set[string])</code></td>
<td><code>network.email.cc</code></td>
<td></td>
</tr>
<tr>
<td><code>reply_to (string)</code></td>
<td><code>network.email.reply_to</code></td>
<td></td>
</tr>
<tr>
<td><code>msg_id (string)</code></td>
<td><code>network.email.mail_id</code></td>
<td></td>
</tr>
<tr>
<td><code>in_reply_to (string)</code></td>
<td><code>about.labels [in_reply_to]</code></td>
<td></td>
</tr>
<tr>
<td><code>subject (string)</code></td>
<td><code>network.email.subject</code></td>
<td></td>
</tr>
<tr>
<td><code>x_originating_ip (string - addr)</code></td>
<td><code>principal.ip</code></td>
<td></td>
</tr>
<tr>
<td><code>first_received (string)</code></td>
<td><code>about.labels [first_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>second_received (string)</code></td>
<td><code>about.labels [second_received]</code></td>
<td></td>
</tr>
<tr>
<td><code>last_reply (string)</code></td>
<td><code>network.smtp.server_response</code></td>
<td></td>
</tr>
<tr>
<td><code>path (array[string] - vector of addr)</code></td>
<td><code>network.smtp.message_path</code></td>
<td>遍历日志字段 <code>path</code>,然后<br> 如果 <code>index</code> 值等于 <code>0</code>,则将 <code>path</code> 日志字段映射到 <code>network.smtp.message_path</code> UDM 字段。 <br> 否则,将 <code>path</code> 日志字段映射到 <code>intermediary.ip</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>user_agent (string)</code></td>
<td><code>principal.application</code></td>
<td></td>
</tr>
<tr>
<td><code>tls (boolean - bool)</code></td>
<td><code>network.smtp.is_tls</code></td>
<td></td>
</tr>
<tr>
<td><code>fuids (array[string] - vector of string)</code></td>
<td><code>about.labels [fuid]</code></td>
<td></td>
</tr>
<tr>
<td><code>is_webmail (boolean - bool)</code></td>
<td><code>network.smtp.is_webmail</code></td>
<td></td>
</tr>
<tr>
<td><code>urls (array[string] - set[string])</code></td>
<td><code>about.url</code></td>
<td></td>
</tr>
<tr>
<td><code>domains (array[string] - set[string])</code></td>
<td><code>about.domain.name</code></td>
<td></td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - ssh</h3>
下表列出了 <code>ssh</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段被设置为 <code>NETWORK_UNCATEGORIZED</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段被设置为 <code>Zeek</code>。</td>
</tr>
<tr>
<td></td>
<td><code>network.application_protocol</code></td>
<td><code>network.application_protocol</code> UDM 字段被设置为 <code>SSH</code>。</td>
</tr>
<tr>
<td><code>version (integer - count)</code></td>
<td><code>network.application_protocol_version</code></td>
<td><code>network.application_protocol_version</code> UDM 字段使用 <code>version</code> 日志字段设置,格式为 "SSH <code>version</code>"。</td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>auth_success (boolean - bool)</code></td>
<td><code>security_result.action</code></td>
<td>如果 <code>auth_success</code> 日志字段的值<em>不</em>等于 <code>true</code>,则 <code>security_result.action</code> UDM 字段被设置为 <code>ALLOW</code>。<br><br>否则,<code>security_result.action</code> UDM 字段被设置为 <code>BLOCK</code>。</td>
</tr>
<tr>
<td><code>auth_attempts (integer - count)</code></td>
<td><code>extensions.auth.auth_details</code></td>
<td><code>extensions.auth.auth_details</code> UDM 字段使用 <code>auth_attempts</code> 日志字段设置,格式为 "auth_attempts: <code>auth_attempts</code>"。</td>
</tr>
<tr>
<td><code>direction (string - enum)</code></td>
<td><code>network.direction</code></td>
<td>如果 <code>direction</code> 日志字段的值等于 <code>INBOUND</code>,则 <code>network.direction</code> UDM 字段被设置为 <code>INBOUND</code>。<br><br>否则,如果 <code>direction</code> 日志字段的值等于 <code>OUTBOUND</code>,则 <code>network.direction</code> UDM 字段被设置为 <code>OUTBOUND</code>。</td>
</tr>
<tr>
<td><code>client (string)</code></td>
<td><code>principal.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>server (string)</code></td>
<td><code>target.asset.software.version</code></td>
<td></td>
</tr>
<tr>
<td><code>cipher_alg (string)</code></td>
<td><code>network.tls.cipher</code></td>
<td></td>
</tr>
<tr>
<td><code>mac_alg (string)</code></td>
<td><code>security_result.detection_fields [mac_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>compression_alg (string)</code></td>
<td><code>security_result.detection_fields [compression_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>kex_alg (string)</code></td>
<td><code>security_result.detection_fields [kex_alg]</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key_alg (string)</code></td>
<td><code>network.tls.server.certificate.version</code></td>
<td></td>
</tr>
<tr>
<td><code>host_key (string)</code></td>
<td><code>network.tls.server.certificate.sha256</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.country_code (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.region (string)</code></td>
<td><code>target.location.country_or_region</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.city (string)</code></td>
<td><code>target.location.city</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.latitude (number - double)</code></td>
<td><code>target.location.region_coordinates.latitude</code></td>
<td></td>
</tr>
<tr>
<td><code>remote_location.longitude (number - double)</code></td>
<td><code>target.location.region_coordinates.longitude</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshVersion (string)</code></td>
<td><code>about.labels [hassh_version]</code></td>
<td></td>
</tr>
<tr>
<td><code>hassh (string)</code></td>
<td><code>principal.labels [hassh]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServer (string)</code></td>
<td><code>target.labels [hassh_server]</code></td>
<td></td>
</tr>
<tr>
<td><code>cshka (string)</code></td>
<td><code>about.labels [cshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshAlgorithms (string)</code></td>
<td><code>about.labels [hassh_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>sshka (string)</code></td>
<td><code>about.labels [sshka]</code></td>
<td></td>
</tr>
<tr>
<td><code>hasshServerAlgorithms (string)</code></td>
<td><code>about.labels [hassh_server_algorithms]</code></td>
<td></td>
</tr>
<tr>
<td><code>inferences (array[string] - set[string])</code></td>
<td><code>security_result.summary, security_result.description, security_result.detection_fields[inferences]</code></td>
<td>如果 <code>inferences</code> 日志字段的值等于 <code>ABP</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Client Authentication Bypass</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A client wasn't adhering to expectations of SSH either through server exploit or by the client and server switching to a protocol other than SSH after encryption begins</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>AFR</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>SSH Agent Forwarding Requested</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>Agent Forwarding is requested by the Client</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>APWA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Automated Password Authentication</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client authenticated with an automated password tool (like sshpass)</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>AUTO</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Automated Interaction</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client is a script automated utility and not driven by a user</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>BAN</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Server Banner</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The server sent the client a pre-authentication banner, likely for legal reasons</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>BF</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Client Brute Force Guessing</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>BFS</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Client Brute Force Success</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A client made a number of authentication attempts that exceeded some configured, pre-connection threshold</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>CTS</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Client Trusted Server</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client already has an entry in its known_hosts file for this server</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>CUS</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Client Untrusted Server</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client did not have an entry in its known_hosts file for this server</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>IPWA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Interactive Password Authentication</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client interactively typed their password to authenticate</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>KS</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Keystrokes</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>An interactive session occurred in which the client set user-driven keystrokes to the server</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>LFD</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Large Client File Download</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>LFU</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Large Client File Upload</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A file transfer occurred in which the client sent a sequence of bytes to the server. Large file are identified dynamically based on trains of MTU-sized packets</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>MFA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Multifactor Authentication</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The server required a second form of authentication (a code) after password or public key was accepted, and the client successfully provided it</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>NA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>None Authentication</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client successfully authenticated using the None method</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>NRC</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>No Remote Command</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The -N flag was used in SSH authentication</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>PKA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Public Key Authentication</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client automatically authenticated using pubkey authentication</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>RSI</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Reverse SSH Initiated</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The Reverse session is initiated from the server back to the client</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>RSIA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Reverse SSH Initiated Automated</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The inititation of the Reverse session happened very early in the packet stream, indicating automation</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>RSK</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Reverse SSH Keystrokes</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>Keystrokes are detected within the Reverse tunnel</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>RSL</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Reverse SSH Logged In</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The Reverse Tunnel login has succeeded</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>RSP</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Reverse SSH Provisioned</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client connected with -R flag, which provisions the port to be used for a Reverse Session set up at any future time</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>SA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Authentication Scanning</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client scanned authentication method with the server and then disconnected</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>SC</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Capabilities Scanning</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The client exchanged capabilities with the server and then disconnected</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>SFD</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Small Client File Download</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A file transfer occurred in which the server sent a sequence of bytes to the client</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>SFU</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Small Client File Upload</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A file transfer occurred in which the client sent a sequence of bytes to the server</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>SP</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Other Scanning</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A client and server didn't exchange encrypted packets but the client wasn't a version or capabilities scanner</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>SV</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Version Scanning</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>A client exchanged version strings with the server and than disconnected</code>。<br><br>
如果 <code>inferences</code> 日志字段的值等于 <code>UA</code>,则 <code>security_result.summary</code> UDM 字段被设置为 <code>Unknown Authentication</code>,并且 <code>security_result.description</code> UDM 字段被设置为 <code>The authentication method is not determinated or is unknown</code>。</td>
</tr>
</tbody>
</table>
</devsite-filter>
</div>
<h3>字段映射参考:CORELIGHT - suricata_corelight</h3>
下表列出了 <code>suricata_corelight</code> 日志类型的日志字段及其对应的 UDM 字段。<div translate="no">
<devsite-filter sortable="0">
<input type="text" placeholder="输入关键字以查找值。">
<table class="fixed">
<thead>
<tr>
<th>日志字段</th>
<th>UDM 映射</th>
<th>逻辑</th>
</tr>
</thead>
<tbody class="list">
<tr>
<td></td>
<td><code>metadata.event_type</code></td>
<td><code>metadata.event_type</code> UDM 字段被设置为 <code>SCAN_NETWORK</code>。</td>
</tr>
<tr>
<td></td>
<td><code>metadata.product_name</code></td>
<td><code>metadata.product_name</code> UDM 字段被设置为 <code>Suricata</code>。</td>
</tr>
<tr>
<td><code>id.vlan (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan]</code></td>
<td></td>
</tr>
<tr>
<td><code>id.vlan_inner (integer - count)</code></td>
<td><code>intermediary.labels [id_vlan_inner]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_type (integer - count)</code></td>
<td><code>about.labels [icmp_type]</code></td>
<td></td>
</tr>
<tr>
<td><code>icmp_code (integer - count)</code></td>
<td><code>about.labels [icmp_code]</code></td>
<td></td>
</tr>
<tr>
<td><code>suri_id (string)</code></td>
<td><code>metadata.product_log_id</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>network.application_protocol</code></td>
<td></td>
</tr>
<tr>
<td><code>flow_id (integer - count)</code></td>
<td><code>about.labels[flow_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>tx_id (integer - count)</code></td>
<td><code>about.labels [tx_id]</code></td>
<td></td>
</tr>
<tr>
<td><code>pcap_cnt (integer - count)</code></td>
<td><code>about.labels [pcap_cnt]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.action (string)</code></td>
<td><code>security_result.action_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.gid (integer - count)</code></td>
<td><code>security_result.detection_fields [alert_gid]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature_id (integer - count)</code></td>
<td><code>security_result.rule_id</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rev (integer - count)</code></td>
<td><code>security_result.rule_version</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.summary</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.signature (string)</code></td>
<td><code>security_result.rule_name</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.category (string)</code></td>
<td><code>security_result.category_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.severity (integer - count)</code></td>
<td><code>security_result.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[alert_metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>community_id (string)</code></td>
<td><code>network.community_id</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload]</code></td>
<td></td>
</tr>
<tr>
<td><code>payload (string)</code></td>
<td><code>about.labels [payload_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet]</code></td>
<td></td>
</tr>
<tr>
<td><code>packet (string)</code></td>
<td><code>about.labels [packet_decoded]</code></td>
<td></td>
</tr>
<tr>
<td><code>metadata (array[string] - vector of string)</code></td>
<td><code>security_result.rule_labels[metadata]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_cve (string)</code></td>
<td><code>extensions.vulns.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>signature_severity</code></td>
<td><code>security_result.severity</code></td>
<td>如果 <code>alert.rule</code> 日志字段值匹配 grok 模式 <code>signature_severity (?<signature_severity>Critical|Major|Minor|Informational)</code>,则 <div style='margin-bottom: 0.0em;'></div>如果提取的 <code>signature_severity</code> 字段值等于 <code>Critical</code>,则 <code>security_result.severity</code> UDM 字段被设置为 <code>CRITICAL</code>,并将提取的 <code>signature_severity</code> 字段映射到 <code>security_result.severity_details</code> UDM 字段。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果提取的 <code>signature_severity</code> 字段值等于 <code>Major</code>,则 <code>security_result.severity</code> UDM 字段被设置为 <code>MEDIUM</code>,并将提取的 <code>signature_severity</code> 字段映射到 <code> security_result.severity_details</code> UDM 字段。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果提取的 <code>signature_severity</code> 字段值等于 <code>Minor</code>,则 <code>security_result.severity</code> UDM 字段被设置为 <code>LOW</code>,并将提取的 <code>signature_severity</code> 字段映射到 <code>security_result.severity_details</code> UDM 字段。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果提取的 <code>signature_severity</code> 字段值等于 <code>Informational</code>,则 <code>security_result.severity</code> UDM 字段被设置为 <code>INFORMATIONAL</code>,并将提取的 <code>signature_severity</code> 字段映射到 <code>security_result.severity_details</code> UDM 字段。<br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.cve (array[string] - vector of string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.hostname(string)</code></td>
<td><code>principal.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [orig_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.machine_domain(string)</code></td>
<td><code>principal.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.os_version(string)</code></td>
<td><code>principal.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.source(string)</code></td>
<td><code>principal.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.cve(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_id</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.hostname(string)</code></td>
<td><code>target.asset.hostname</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.host_uid(string)</code></td>
<td><code>about.labels [resp_vulnerable_host_uid]</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.machine_domain(string)</code></td>
<td><code>target.asset.network_domain</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.os_version(string)</code></td>
<td><code>target.asset.platform_software.platform_version</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.source(string)</code></td>
<td><code>target.asset.vulnerabilities.cve_description</code></td>
<td></td>
</tr>
<tr>
<td><code>service (string)</code></td>
<td><code>about.labels [service]</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.rule (string)</code></td>
<td><code>security_result.description</code></td>
<td></td>
</tr>
<tr>
<td><code>alert.references (array[string] - vector of string)</code></td>
<td><code>security_result.detection_fields[alert_references]</code></td>
<td>遍历 alert.references,<div style='margin-bottom: 0.5em;'></div><code>alert.references</code> 日志字段被映射到 <code> security_result.detection_fields.alert_references </code> UDM 字段。</td>
</tr>
<tr>
<td><code>payload_printable (string)</code></td>
<td><code>security_result.detection_fields[payload_printable]</code></td>
<td></td>
</tr>
<tr>
<td><code>references (array[string] - vector of string)</code></td>
<td><code>security_result.detection_fields[references]</code></td>
<td>遍历 references,<div style='margin-bottom: 0.5em;'></div><code>references</code> 日志字段被映射到 <code> security_result.detection_fields.references </code> UDM 字段。</td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>如果 <code>orig_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Critical" 或 <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "4" </code> </code>,则 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>CRITICAL</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)High" 或 <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "3" </code> </code>,则 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>HIGH</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Low" 或 <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "1" </code> </code>,则 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>LOW</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Medium" 或 <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "2" </code> </code>,则 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>MEDIUM</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>orig_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Unknown_Severity" 或 <code>orig_vulnerable_host.criticality</code> 日志字段值等于 <code> "0" </code> </code>,则 <code> "principal.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>UNKNOWN_SEVERITY</code>。 <br></td>
</tr>
<tr>
<td><code>orig_vulnerable_host.criticality (string)</code></td>
<td><code>principal.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity</code></td>
<td><div style='margin-bottom: 0.0em;'></div>如果 <code>resp_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Critical" 或 <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "4 </code>" </code>,则 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>CRITICAL</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)High" 或 <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "3 </code>" </code>,则 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>HIGH</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Low" 或 <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "1 </code>" </code>,则 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>LOW</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Medium" 或 <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "2 </code>" </code>,则 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>MEDIUM</code>。 <br> <div style='margin-bottom: 0.5em;'></div>否则,如果 <code>resp_vulnerable_host.criticality</code> 日志字段值匹配正则表达式模式 <code> "(?i)Unknown_Severity" 或 <code>resp_vulnerable_host.criticality</code> 日志字段值等于 <code> "0 </code>" </code>,则 <code> "target.asset.vulnerabilities.severity" </code> UDM 字段被设置为 <code>UNKNOWN_SEVERITY</code>。 <br></td>
</tr>
<tr>
<td><code>resp_vulnerable_host.criticality (string)</code></td>
<td><code>target.asset.vulnerabilities.severity_details</code></td>
<td></td>
</tr>
<tr>
<td><code>rule_content</code></td>
<td><code>security_result.detection_fields[alert_rule_content]</code></td>
<td>如果 <code>alert.rule</code> 日志字段值匹配 grok 模式 <code>%{GREEDYDATA:_}content:\\"%{GREEDYDATA:rule_content}\\"</code>,则将提取的 <code>rule_content</code> 字段映射到 <code>security_result.detection_fields [alert_rule_content]</code> UDM 字段。</td>
</tr>
<tr>
<td><code>rule_classtype</code></td>
<td><code>security_result.detection_fields [alert_rule_classtype]</code></td>
<td>如果 <code>alert.rule</code> 日志字段值匹配 grok 模式 <code>%{GREEDYDATA:_}classtype:%{DATA:rule_classtype};</code>,则将提取的 <code>rule_classtype</code> 字段映射到 <code>security_result.detection_fields [alert_rule_classtype]</code> UDM 字段。</td>
</tr>
<tr>
<td><code>reference_url</code></td>
<td><code>security_result.detection_fields[alert_rule_reference_url]</code></td>
---
[了解更多](https://github.com/corelight/corelightforsecops)