summaryrefslogtreecommitdiff
path: root/testSchemaFiles/security_event_hits_log.json
blob: d8a6b89b9198e1d8c4426ab6604309dfcc25326d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
{
  "type": "record",
  "name": "security_event_hits_log",
  "namespace": "druid",
  "doc": {
    "partition_key": "__time",
    "functions": {
      "$ref": "public_schema_info.json#/functions"
    },
    "schema_query": {
      "references": {
        "$ref": "public_schema_info.json#/schema_query/references"
      }
    }
  },
  "fields": [
    {
      "name": "__time",
      "label": "Time",
      "type": "string",
      "doc": {
        "constraints": {
          "type": "timestamp"
        },
        "visibility": "enabled"
      }
    },
    {
      "name": "isp",
      "label": "ISP",
      "type": "string",
      "doc": {
        "visibility": "disabled"
      }
    },
    {
      "name": "entrance_id",
      "label": "Entrance ID",
      "type": "long",
      "doc": {
        "visibility": "disabled"
      }
    },
    {
      "name": "policy_id",
      "label": "Policy ID",
      "type": "long",
      "doc": {
        "constraints": {
          "operator_functions": "=,in"
        },
        "visibility": "enabled"
      }
    },
    {
      "name": "action",
      "label": "Action",
      "type": "long",
      "doc": {
        "constraints": {
          "operator_functions": "=,in"
        },
        "data": [
          {
            "code": "1",
            "value": "Monitor"
          },
          {
            "code": "2",
            "value": "Intercept"
          },
          {
            "code": "16",
            "value": "Deny"
          },
          {
            "code": "128",
            "value": "Allow"
          }
        ],
        "visibility": "enabled"
      }
    },
    {
      "name": "hits",
      "label": "Hits",
      "doc": {
        "visibility": "enabled"
      },
      "type": "long"
    },
    {
      "name": "c2s_byte_num",
      "label": "Bytes Sent",
      "doc": {
        "visibility": "enabled"
      },
      "type": "long"
    },
    {
      "name": "s2c_byte_num",
      "label": "Bytes Received",
      "doc": {
        "visibility": "enabled"
      },
      "type": "long"
    }
  ]
}