Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "logstash-fortigate-2017.10.27" : {
- "aliases" : { },
- "mappings" : {
- "_default_" : {
- "_all" : {
- "enabled" : true,
- "omit_norms" : true
- },
- "dynamic_templates" : [ {
- "message_field" : {
- "mapping" : {
- "fielddata" : {
- "format" : "disabled"
- },
- "index" : "analyzed",
- "omit_norms" : true,
- "type" : "string"
- },
- "match" : "message",
- "match_mapping_type" : "string"
- }
- }, {
- "string_fields" : {
- "mapping" : {
- "fielddata" : {
- "format" : "disabled"
- },
- "index" : "analyzed",
- "omit_norms" : true,
- "type" : "string",
- "fields" : {
- "raw" : {
- "ignore_above" : 256,
- "index" : "not_analyzed",
- "type" : "string"
- }
- }
- },
- "match" : "*",
- "match_mapping_type" : "string"
- }
- } ],
- "properties" : {
- "@timestamp" : {
- "type" : "date",
- "format" : "strict_date_optional_time||epoch_millis"
- },
- "@version" : {
- "type" : "string",
- "index" : "not_analyzed"
- },
- "DestinationGeo" : {
- "dynamic" : "true",
- "properties" : {
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "float"
- }
- }
- },
- "SourceGeo" : {
- "dynamic" : "true",
- "properties" : {
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "float"
- }
- }
- },
- "geoip" : {
- "dynamic" : "true",
- "properties" : {
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "float"
- }
- }
- }
- }
- },
- "syslog" : {
- "_all" : {
- "enabled" : true,
- "omit_norms" : true
- },
- "dynamic_templates" : [ {
- "message_field" : {
- "mapping" : {
- "fielddata" : {
- "format" : "disabled"
- },
- "index" : "analyzed",
- "omit_norms" : true,
- "type" : "string"
- },
- "match" : "message",
- "match_mapping_type" : "string"
- }
- }, {
- "string_fields" : {
- "mapping" : {
- "fielddata" : {
- "format" : "disabled"
- },
- "index" : "analyzed",
- "omit_norms" : true,
- "type" : "string",
- "fields" : {
- "raw" : {
- "ignore_above" : 256,
- "index" : "not_analyzed",
- "type" : "string"
- }
- }
- },
- "match" : "*",
- "match_mapping_type" : "string"
- }
- } ],
- "properties" : {
- "@timestamp" : {
- "type" : "date",
- "format" : "strict_date_optional_time||epoch_millis"
- },
- "@version" : {
- "type" : "string",
- "index" : "not_analyzed"
- },
- "DestinationGeo" : {
- "dynamic" : "true",
- "properties" : {
- "area_code" : {
- "type" : "long"
- },
- "city_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "continent_code" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "country_code2" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "country_code3" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "country_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dma_code" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "float"
- },
- "postal_code" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "real_region_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "region_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "timezone" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- }
- }
- },
- "SourceGeo" : {
- "dynamic" : "true",
- "properties" : {
- "area_code" : {
- "type" : "long"
- },
- "city_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "continent_code" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "country_code2" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "country_code3" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "country_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dma_code" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "float"
- },
- "postal_code" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "real_region_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "region_name" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "timezone" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- }
- }
- },
- "action" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "agent" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "alert" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "ap" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "app" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "appact" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "appcat" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "appid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "applist" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "apprisk" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "apsn" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "authproto" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "cat" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "catdesc" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "category" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "channel" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "countapp" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "countdlp" : {
- "type" : "long"
- },
- "countweb" : {
- "type" : "long"
- },
- "craction" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "crlevel" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "crscore" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "date" : {
- "type" : "date",
- "format" : "strict_date_optional_time||epoch_millis"
- },
- "desc" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "devid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "devname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "devtype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "direction" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dlpextra" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dstcountry" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dstintf" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dstip" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "dstport" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "duration" : {
- "type" : "long"
- },
- "epoch" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "error" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "eventid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "eventtype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "expiry" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "filename" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "filesize" : {
- "type" : "long"
- },
- "filetype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "filtercat" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "filteridx" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "filtertype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "fingerprint" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "geoip" : {
- "dynamic" : "true",
- "properties" : {
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "float"
- }
- }
- },
- "group" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "host" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "hostname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "initiator" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "kv" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "lanin" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "lanout" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "level" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "logdesc" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "logid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "mastersrcmac" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "method" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "msg" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "oldwprof" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "osname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "osversion" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "policyid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "policytype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "poluuid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "port" : {
- "type" : "long"
- },
- "profile" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "profiletype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "proto" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "radioband" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "rcvdbyte" : {
- "type" : "long"
- },
- "rcvdpkt" : {
- "type" : "long"
- },
- "reason" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "referralurl" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "reqtype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "scope" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "sentbyte" : {
- "type" : "long"
- },
- "sentpkt" : {
- "type" : "long"
- },
- "service" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "session_id" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "sessionid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "severity" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "shaperdroprcvdbyte" : {
- "type" : "long"
- },
- "shaperdropsentbyte" : {
- "type" : "long"
- },
- "shaperperipdropbyte" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "shaperperipname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "shaperrcvdname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "shapersentname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "shapingpolicyid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srccountry" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srcintf" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srcip" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srcmac" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srcname" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srcport" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "srcssid" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "sslexempt" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "status" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "syslog5424_pri" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "syslog_facility" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "syslog_facility_code" : {
- "type" : "long"
- },
- "syslog_host" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "syslog_severity" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "syslog_severity_code" : {
- "type" : "long"
- },
- "tags" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "time" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "trandisp" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "transip" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "transport" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "type" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "unauthuser" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "unauthusersource" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "url" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "urlfilteridx" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "user" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "utmaction" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "vd" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "wanin" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "wanoptapptype" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- },
- "wanout" : {
- "type" : "string",
- "norms" : {
- "enabled" : false
- },
- "fielddata" : {
- "format" : "disabled"
- },
- "fields" : {
- "raw" : {
- "type" : "string",
- "index" : "not_analyzed",
- "ignore_above" : 256
- }
- }
- }
- }
- }
- },
- "settings" : {
- "index" : {
- "creation_date" : "1509062400226",
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "number_of_replicas" : "1",
- "uuid" : "qQ6fCr-PSu28H9F1w6j8tg",
- "version" : {
- "created" : "2040299"
- }
- }
- },
- "warmers" : { }
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement