Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "extractors": [
- {
- "title": "System - Hostname",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "hostname",
- "source_field": "message",
- "extractor_config": {
- "index": 1,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "System - Receive Date",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "receive_date_time",
- "source_field": "message",
- "extractor_config": {
- "index": 2,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "System - Serial Number",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "serial_number",
- "source_field": "message",
- "extractor_config": {
- "index": 3,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "System - Log Type",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "log_type",
- "source_field": "message",
- "extractor_config": {
- "index": 4,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "System - Log Subtype",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "log_subtype",
- "source_field": "message",
- "extractor_config": {
- "index": 5,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "System - Log Time Generated",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "time_generated",
- "source_field": "message",
- "extractor_config": {
- "index": 7,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Destination IP",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_dst_ip",
- "source_field": "message",
- "extractor_config": {
- "index": 9,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - NAT Source IP",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_nat_src_ip",
- "source_field": "message",
- "extractor_config": {
- "index": 10,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Source IP",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_src_ip",
- "source_field": "message",
- "extractor_config": {
- "index": 8,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - FIrewall Rule",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "firewall_rule",
- "source_field": "message",
- "extractor_config": {
- "index": 12,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Application",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "application",
- "source_field": "message",
- "extractor_config": {
- "index": 15,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Source Zone",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_src_zone",
- "source_field": "message",
- "extractor_config": {
- "index": 17,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Destination Zone",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_dst_zone",
- "source_field": "message",
- "extractor_config": {
- "index": 18,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Ingress Interface",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "ingress_interface",
- "source_field": "message",
- "extractor_config": {
- "index": 19,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Egress Interface",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "egress_interface",
- "source_field": "message",
- "extractor_config": {
- "index": 20,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Session ID",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_id",
- "source_field": "message",
- "extractor_config": {
- "index": 23,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Repeat Count (5 seconds)",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "repeat_count",
- "source_field": "message",
- "extractor_config": {
- "index": 24,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Source Port",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_src_port",
- "source_field": "message",
- "extractor_config": {
- "index": 25,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Destination Port",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_dst_port",
- "source_field": "message",
- "extractor_config": {
- "index": 26,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - NAT Source Port",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_nat_src_port",
- "source_field": "message",
- "extractor_config": {
- "index": 27,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - NAT Destination Port",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_nat_dst_port",
- "source_field": "message",
- "extractor_config": {
- "index": 28,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Flags",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_flags",
- "source_field": "message",
- "extractor_config": {
- "index": 29,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - IP Protocol",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_ip_proto",
- "source_field": "message",
- "extractor_config": {
- "index": 30,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Action",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "action",
- "source_field": "message",
- "extractor_config": {
- "index": 31,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Total Bytes",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_total_bytes",
- "source_field": "message",
- "extractor_config": {
- "index": 32,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Bytes Sent",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_bytes_sent",
- "source_field": "message",
- "extractor_config": {
- "index": 33,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Bytes Received",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_bytes_received",
- "source_field": "message",
- "extractor_config": {
- "index": 34,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Total Packets",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_total_packets",
- "source_field": "message",
- "extractor_config": {
- "index": 35,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Start Time",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_start_time",
- "source_field": "message",
- "extractor_config": {
- "index": 36,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Elapsed Time (Seconds)",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_elapsed_time_sec",
- "source_field": "message",
- "extractor_config": {
- "index": 37,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - URL Category",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "url_category",
- "source_field": "message",
- "extractor_config": {
- "index": 38,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Source Country",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "source_country",
- "source_field": "message",
- "extractor_config": {
- "index": 42,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Destination Country",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "destination_country",
- "source_field": "message",
- "extractor_config": {
- "index": 43,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Packets Sent",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "pkts_sent",
- "source_field": "message",
- "extractor_config": {
- "index": 45,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Packets Received",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "pkts_received",
- "source_field": "message",
- "extractor_config": {
- "index": 46,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - End Reason",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "session_end_reason",
- "source_field": "message",
- "extractor_config": {
- "index": 47,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- },
- {
- "title": "Session - Action Source",
- "extractor_type": "SPLIT_AND_INDEX",
- "cursor_strategy": "COPY",
- "target_field": "action_source",
- "source_field": "message",
- "extractor_config": {
- "index": 54,
- "split_by": ","
- },
- "converters": [],
- "condition_type": "NONE",
- "condition_value": "",
- "order": 0
- }
- ],
- "version": "3.2.1"
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement