diff options
| author | 尹姜谊 <[email protected]> | 2024-01-16 19:50:02 +0800 |
|---|---|---|
| committer | 尹姜谊 <[email protected]> | 2024-01-16 19:50:02 +0800 |
| commit | f52946b95c58e3d7fcf082ddb0ba350ae514b328 (patch) | |
| tree | 12d757f77188e62caa0ce97ddcaa12436584ae38 /config.yaml | |
| parent | 7170fefc0b4feeb00a3968b53f198411a3511ac6 (diff) | |
提取common_recv_time字段名配置
Diffstat (limited to 'config.yaml')
| -rw-r--r-- | config.yaml | 30 |
1 files changed, 29 insertions, 1 deletions
diff --git a/config.yaml b/config.yaml index 14c1731..2ec0a21 100644 --- a/config.yaml +++ b/config.yaml @@ -1,6 +1,8 @@ common: output_path: data/ time_zone: Asia/Shanghai + recv_time_columnname: common_recv_time + time_filter_pattern: (recv_time_columnname> toDateTime('{$start_time}', '{$time_zone}')) AND(recv_time_columnname <= toDateTime('{$end_time}', '{$time_zone}')) clickhouse: host: 192.168.40.194 @@ -58,4 +60,30 @@ ipvanishvpn_serverip: plugin_name: ipvanishvpn_serverip object_type: ip confidence: confirmed - kb_sql: SELECT distinct domain FROM {$mariadb_dbname}.{$mariadb_domain_tablename} where vpn_service_name = 'ipvanishvpn'
\ No newline at end of file + kb_sql: SELECT distinct domain FROM {$mariadb_dbname}.{$mariadb_domain_tablename} where vpn_service_name = 'ipvanishvpn' + + +psiphon3vpn_serverip: + vpn_service_name: psiphon3vpn + plugin_id: 4 + plugin_name: psiphon3vpn_serverip + object_type: ip + confidence: + + +cyberghostvpn_servername: + vpn_service_name: cyberghostvpn + plugin_id: 5 + plugin_name: cyberghostvpn_servername + object_type: domain + confidence: confirmed + sql: SELECT DISTINCT dns_qname FROM {$db_name}.{$table_name} WHERE {$time_filter} AND dns_qname LIKE '%.nodes.gen4.ninja' + + +cyberghostvpn_serverip: + vpn_service_name: cyberghostvpn + plugin_id: 6 + plugin_name: cyberghostvpn_serverip + object_type: ip + confidence: confirmed + kb_sql: SELECT distinct domain FROM {$mariadb_dbname}.{$mariadb_domain_tablename} where vpn_service_name = 'cyberghostvpn'
\ No newline at end of file |
