Advertisement
Guest User

Untitled

a guest
Jan 20th, 2017
99
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.05 KB | None | 0 0
  1. {
  2. "api": "search",
  3. "ver": "v0.3",
  4. "devices": {
  5. "hits": [{
  6. "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
  7. "profileid": "Device Behind Router",
  8. "user_profile_type": "Non_IoT",
  9. "profile_date": "2016-11-30T21:56:40.570Z",
  10. "risk_level": "low",
  11. "baseline": {
  12. "progress": 100,
  13. "state": "unstable",
  14. "pi": 0
  15. },
  16. "profile_confidence": 80,
  17. "display_osGroup": "Others",
  18. "connect_evtContent": {
  19. "username": "unknown",
  20. "hostname": "unknown",
  21. "monitored": true,
  22. "osSource": null,
  23. "roles": "",
  24. "osGroup": "Others",
  25. "ip": "192.168.10.164",
  26. "vlan": 0,
  27. "osVer": null,
  28. "UserAgent": "unknown",
  29. "os": null
  30. },
  31. "display_osVer": null,
  32. "subnets": "192.168.10.0/24",
  33. "profile_type": "Non_IoT",
  34. "profile_type_score": 0,
  35. "vlan": 1003,
  36. "display_os": null,
  37. "date": "2016-11-30T21:56:28.007000",
  38. "profile_type_factors": [],
  39. "profile_classifier": "RoutedHostsClassifier",
  40. "profile_type_source": "baseline",
  41. "profile_category": "Devices Behind Router",
  42. "profile_type_date": "2016-12-27T10:09:24.362331Z",
  43. "routed": true,
  44. "siteid": "111",
  45. "deviceid": "74:df:bf:bf:79:72:192.168.10.164",
  46. "profile_vertical": "IT Devices",
  47. "applianceid": "564D29485CF37A7869FCF2090864B53F"
  48. }, {
  49. "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
  50. "profileid": "Device Behind Router",
  51. "user_profile_type": "Non_IoT",
  52. "profile_date": "2016-12-02T23:27:57.153Z",
  53. "risk_level": "low",
  54. "profile_confidence": 80,
  55. "display_osGroup": "Others",
  56. "connect_evtContent": {
  57. "username": "unknown",
  58. "hostname": "unknown",
  59. "monitored": true,
  60. "osSource": null,
  61. "roles": "",
  62. "osGroup": "Others",
  63. "ip": "192.168.10.138",
  64. "vlan": 0,
  65. "osVer": null,
  66. "UserAgent": "unknown",
  67. "os": null
  68. },
  69. "display_osVer": null,
  70. "subnets": "192.168.10.0/24",
  71. "profile_type": "Non_IoT",
  72. "vlan": 1003,
  73. "display_os": null,
  74. "date": "2017-01-05T21:05:08.783000",
  75. "profile_classifier": "RoutedHostsClassifier",
  76. "profile_type_source": "profiler",
  77. "profile_category": "Devices Behind Router",
  78. "routed": true,
  79. "siteid": "0",
  80. "deviceid": "5c:83:8f:31:a7:84:192.168.10.138",
  81. "profile_vertical": "IT Devices",
  82. "applianceid": "295994E09DAF11E6BB23000EC4CCD0A5"
  83. }, {
  84. "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
  85. "profileid": "Device Behind Router",
  86. "user_profile_type": "Non_IoT",
  87. "profile_date": "2016-11-17T00:29:32.804Z",
  88. "risk_level": "low",
  89. "baseline": {
  90. "progress": 100,
  91. "state": "unstable",
  92. "pi": 0
  93. },
  94. "profile_confidence": 80,
  95. "display_osGroup": "Others",
  96. "connect_evtContent": {
  97. "username": "unknown",
  98. "hostname": "unknown",
  99. "monitored": true,
  100. "osSource": null,
  101. "roles": "",
  102. "osGroup": "Others",
  103. "ip": "192.168.10.159",
  104. "vlan": 0,
  105. "osVer": null,
  106. "UserAgent": "unknown",
  107. "os": null
  108. },
  109. "display_osVer": null,
  110. "subnets": "192.168.10.0/24",
  111. "profile_type": "Non_IoT",
  112. "profile_type_score": 0,
  113. "vlan": 1003,
  114. "display_os": null,
  115. "date": "2016-11-16T00:29:23.106000",
  116. "profile_type_factors": [],
  117. "profile_classifier": "RoutedHostsClassifier",
  118. "profile_type_source": "baseline",
  119. "profile_category": "Devices Behind Router",
  120. "profile_type_date": "2016-12-07T10:13:39.203476Z",
  121. "routed": true,
  122. "siteid": "111",
  123. "deviceid": "00:01:5c:62:4e:46:192.168.10.159",
  124. "profile_vertical": "IT Devices",
  125. "applianceid": "564D29485CF37A7869FCF2090864B53F"
  126. }],
  127. "highlights": {
  128. "connect_evtContent.ip": ["<em>192.168.10.159</em>"],
  129. "deviceid": ["00:01:5c:62:4e:46:<em>192.168.10.159</em>"]
  130. }
  131. },
  132. "alerts": {
  133. "hits": [{
  134. "resolved": "yes",
  135. "severity": "low",
  136. "name": "Unprofiled new application",
  137. "description": "Detected established connections to multicast",
  138. "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
  139. "date": "2016-10-12T20:40:28.129000",
  140. "deviceid": "58:b6:33:15:85:40",
  141. "msg": {
  142. "status": "reject",
  143. "toURL": "multicast",
  144. "toip": "192.168.10.255",
  145. "severity": "low",
  146. "appName": "UDP",
  147. "proto": 17,
  148. "description": "Detected established connections to multicast",
  149. "hostname": "unknown",
  150. "ruleid": "analytics-whitelist-app",
  151. "acl": true,
  152. "values": [{
  153. "value": "UDP",
  154. "label": "appName"
  155. }],
  156. "fromip": "192.168.10.203",
  157. "toPort": 12223,
  158. "taggedBy": "PolicyAlert",
  159. "id": "9bCzM",
  160. "name": "Unprofiled new application"
  161. },
  162. "type": "policy_alert",
  163. "inspectorid": "564D29485CF37A7869FCF2090864B53F"
  164. }, {
  165. "resolved": "yes",
  166. "severity": "low",
  167. "name": "Unprofiled new URL connection",
  168. "description": "Detected established connections to 192.168.10.165",
  169. "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
  170. "date": "2016-10-12T23:53:17.997000",
  171. "deviceid": "d0:4f:7e:2b:d5:ee",
  172. "msg": {
  173. "status": "publish",
  174. "toURL": "192.168.10.165",
  175. "toip": "192.168.10.165",
  176. "severity": "low",
  177. "appName": "mdns",
  178. "proto": 17,
  179. "description": "Detected established connections to 192.168.10.165",
  180. "hostname": "ConfRooAppleTV2",
  181. "ruleid": "analytics-whitelist-remote-URL",
  182. "acl": true,
  183. "values": [{
  184. "value": "192.168.10.165",
  185. "label": "remoteURL"
  186. }],
  187. "fromip": "192.168.10.85",
  188. "toPort": 5353,
  189. "taggedBy": "PolicyAlert",
  190. "id": "BGfXq",
  191. "name": "Unprofiled new URL connection"
  192. },
  193. "ACLRule": {
  194. "client_ip": "192.168.10.85",
  195. "opType": "pushACL",
  196. "alertid": "57feccfa7b71120b0054ae33",
  197. "acl_name": "ZB_57feccfa7b71120b0054ae33",
  198. "ruleid": "analytics-whitelist-remote-URL",
  199. "service_port": 5353,
  200. "firewall_name": "zingbox-fw",
  201. "from_zone": "any",
  202. "application": "mdns",
  203. "to_zone": "any",
  204. "ip_proto_num": 17,
  205. "server_ip": "192.168.10.165",
  206. "date": "2016-10-17T21:23:00.166000",
  207. "firewall_ip": "192.168.10.140",
  208. "action": "BLOCKED",
  209. "firewall_id": "58053bc12ddbc30b0030a1e0",
  210. "inspectorid": "564D29485CF37A7869FCF2090864B53F"
  211. },
  212. "type": "policy_alert",
  213. "action": "BLOCKED",
  214. "inspectorid": "564D29485CF37A7869FCF2090864B53F"
  215. }, {
  216. "resolved": "yes",
  217. "severity": "low",
  218. "name": "Unprofiled new application",
  219. "description": "Detected established connections to 192.168.10.181",
  220. "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
  221. "date": "2016-10-12T23:12:42.100000",
  222. "deviceid": "30:05:5c:5b:1b:4c",
  223. "msg": {
  224. "status": "publish",
  225. "toURL": "192.168.10.181",
  226. "toip": "192.168.10.181",
  227. "severity": "low",
  228. "appName": "snmp",
  229. "proto": 17,
  230. "description": "Detected established connections to 192.168.10.181",
  231. "hostname": "unknown",
  232. "ruleid": "analytics-whitelist-app",
  233. "acl": true,
  234. "values": [{
  235. "value": "snmp",
  236. "label": "appName"
  237. }],
  238. "fromip": "192.168.10.228",
  239. "toPort": 50324,
  240. "taggedBy": "PolicyAlert",
  241. "id": "X2fGAM",
  242. "name": "Unprofiled new application"
  243. },
  244. "type": "policy_alert",
  245. "inspectorid": "564D29485CF37A7869FCF2090864B53F"
  246. }],
  247. "highlights": {
  248. "msg.toip": ["<em>192.168.10.181</em>"],
  249. "msg.fromip": ["<em>192.168.10.228</em>"]
  250. }
  251. }
  252. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement