Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "api": "search",
- "ver": "v0.3",
- "devices": {
- "hits": [{
- "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
- "profileid": "Device Behind Router",
- "user_profile_type": "Non_IoT",
- "profile_date": "2016-11-30T21:56:40.570Z",
- "risk_level": "low",
- "baseline": {
- "progress": 100,
- "state": "unstable",
- "pi": 0
- },
- "profile_confidence": 80,
- "display_osGroup": "Others",
- "connect_evtContent": {
- "username": "unknown",
- "hostname": "unknown",
- "monitored": true,
- "osSource": null,
- "roles": "",
- "osGroup": "Others",
- "ip": "192.168.10.164",
- "vlan": 0,
- "osVer": null,
- "UserAgent": "unknown",
- "os": null
- },
- "display_osVer": null,
- "subnets": "192.168.10.0/24",
- "profile_type": "Non_IoT",
- "profile_type_score": 0,
- "vlan": 1003,
- "display_os": null,
- "date": "2016-11-30T21:56:28.007000",
- "profile_type_factors": [],
- "profile_classifier": "RoutedHostsClassifier",
- "profile_type_source": "baseline",
- "profile_category": "Devices Behind Router",
- "profile_type_date": "2016-12-27T10:09:24.362331Z",
- "routed": true,
- "siteid": "111",
- "deviceid": "74:df:bf:bf:79:72:192.168.10.164",
- "profile_vertical": "IT Devices",
- "applianceid": "564D29485CF37A7869FCF2090864B53F"
- }, {
- "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
- "profileid": "Device Behind Router",
- "user_profile_type": "Non_IoT",
- "profile_date": "2016-12-02T23:27:57.153Z",
- "risk_level": "low",
- "profile_confidence": 80,
- "display_osGroup": "Others",
- "connect_evtContent": {
- "username": "unknown",
- "hostname": "unknown",
- "monitored": true,
- "osSource": null,
- "roles": "",
- "osGroup": "Others",
- "ip": "192.168.10.138",
- "vlan": 0,
- "osVer": null,
- "UserAgent": "unknown",
- "os": null
- },
- "display_osVer": null,
- "subnets": "192.168.10.0/24",
- "profile_type": "Non_IoT",
- "vlan": 1003,
- "display_os": null,
- "date": "2017-01-05T21:05:08.783000",
- "profile_classifier": "RoutedHostsClassifier",
- "profile_type_source": "profiler",
- "profile_category": "Devices Behind Router",
- "routed": true,
- "siteid": "0",
- "deviceid": "5c:83:8f:31:a7:84:192.168.10.138",
- "profile_vertical": "IT Devices",
- "applianceid": "295994E09DAF11E6BB23000EC4CCD0A5"
- }, {
- "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
- "profileid": "Device Behind Router",
- "user_profile_type": "Non_IoT",
- "profile_date": "2016-11-17T00:29:32.804Z",
- "risk_level": "low",
- "baseline": {
- "progress": 100,
- "state": "unstable",
- "pi": 0
- },
- "profile_confidence": 80,
- "display_osGroup": "Others",
- "connect_evtContent": {
- "username": "unknown",
- "hostname": "unknown",
- "monitored": true,
- "osSource": null,
- "roles": "",
- "osGroup": "Others",
- "ip": "192.168.10.159",
- "vlan": 0,
- "osVer": null,
- "UserAgent": "unknown",
- "os": null
- },
- "display_osVer": null,
- "subnets": "192.168.10.0/24",
- "profile_type": "Non_IoT",
- "profile_type_score": 0,
- "vlan": 1003,
- "display_os": null,
- "date": "2016-11-16T00:29:23.106000",
- "profile_type_factors": [],
- "profile_classifier": "RoutedHostsClassifier",
- "profile_type_source": "baseline",
- "profile_category": "Devices Behind Router",
- "profile_type_date": "2016-12-07T10:13:39.203476Z",
- "routed": true,
- "siteid": "111",
- "deviceid": "00:01:5c:62:4e:46:192.168.10.159",
- "profile_vertical": "IT Devices",
- "applianceid": "564D29485CF37A7869FCF2090864B53F"
- }],
- "highlights": {
- "connect_evtContent.ip": ["<em>192.168.10.159</em>"],
- "deviceid": ["00:01:5c:62:4e:46:<em>192.168.10.159</em>"]
- }
- },
- "alerts": {
- "hits": [{
- "resolved": "yes",
- "severity": "low",
- "name": "Unprofiled new application",
- "description": "Detected established connections to multicast",
- "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
- "date": "2016-10-12T20:40:28.129000",
- "deviceid": "58:b6:33:15:85:40",
- "msg": {
- "status": "reject",
- "toURL": "multicast",
- "toip": "192.168.10.255",
- "severity": "low",
- "appName": "UDP",
- "proto": 17,
- "description": "Detected established connections to multicast",
- "hostname": "unknown",
- "ruleid": "analytics-whitelist-app",
- "acl": true,
- "values": [{
- "value": "UDP",
- "label": "appName"
- }],
- "fromip": "192.168.10.203",
- "toPort": 12223,
- "taggedBy": "PolicyAlert",
- "id": "9bCzM",
- "name": "Unprofiled new application"
- },
- "type": "policy_alert",
- "inspectorid": "564D29485CF37A7869FCF2090864B53F"
- }, {
- "resolved": "yes",
- "severity": "low",
- "name": "Unprofiled new URL connection",
- "description": "Detected established connections to 192.168.10.165",
- "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
- "date": "2016-10-12T23:53:17.997000",
- "deviceid": "d0:4f:7e:2b:d5:ee",
- "msg": {
- "status": "publish",
- "toURL": "192.168.10.165",
- "toip": "192.168.10.165",
- "severity": "low",
- "appName": "mdns",
- "proto": 17,
- "description": "Detected established connections to 192.168.10.165",
- "hostname": "ConfRooAppleTV2",
- "ruleid": "analytics-whitelist-remote-URL",
- "acl": true,
- "values": [{
- "value": "192.168.10.165",
- "label": "remoteURL"
- }],
- "fromip": "192.168.10.85",
- "toPort": 5353,
- "taggedBy": "PolicyAlert",
- "id": "BGfXq",
- "name": "Unprofiled new URL connection"
- },
- "ACLRule": {
- "client_ip": "192.168.10.85",
- "opType": "pushACL",
- "alertid": "57feccfa7b71120b0054ae33",
- "acl_name": "ZB_57feccfa7b71120b0054ae33",
- "ruleid": "analytics-whitelist-remote-URL",
- "service_port": 5353,
- "firewall_name": "zingbox-fw",
- "from_zone": "any",
- "application": "mdns",
- "to_zone": "any",
- "ip_proto_num": 17,
- "server_ip": "192.168.10.165",
- "date": "2016-10-17T21:23:00.166000",
- "firewall_ip": "192.168.10.140",
- "action": "BLOCKED",
- "firewall_id": "58053bc12ddbc30b0030a1e0",
- "inspectorid": "564D29485CF37A7869FCF2090864B53F"
- },
- "type": "policy_alert",
- "action": "BLOCKED",
- "inspectorid": "564D29485CF37A7869FCF2090864B53F"
- }, {
- "resolved": "yes",
- "severity": "low",
- "name": "Unprofiled new application",
- "description": "Detected established connections to 192.168.10.181",
- "tenantid": "KTKdJPQheZ2a_d_Dkgbv8r7kqKHQnoVb",
- "date": "2016-10-12T23:12:42.100000",
- "deviceid": "30:05:5c:5b:1b:4c",
- "msg": {
- "status": "publish",
- "toURL": "192.168.10.181",
- "toip": "192.168.10.181",
- "severity": "low",
- "appName": "snmp",
- "proto": 17,
- "description": "Detected established connections to 192.168.10.181",
- "hostname": "unknown",
- "ruleid": "analytics-whitelist-app",
- "acl": true,
- "values": [{
- "value": "snmp",
- "label": "appName"
- }],
- "fromip": "192.168.10.228",
- "toPort": 50324,
- "taggedBy": "PolicyAlert",
- "id": "X2fGAM",
- "name": "Unprofiled new application"
- },
- "type": "policy_alert",
- "inspectorid": "564D29485CF37A7869FCF2090864B53F"
- }],
- "highlights": {
- "msg.toip": ["<em>192.168.10.181</em>"],
- "msg.fromip": ["<em>192.168.10.228</em>"]
- }
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement