Advertisement
Guest User

Untitled

a guest
Feb 21st, 2020
158
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.56 KB | None | 0 0
  1. {
  2. "access-logs-2020.02.21_new": {
  3. "mappings": {
  4. "doc": {
  5. "properties": {
  6. "@timestamp": {
  7. "type": "date"
  8. },
  9. "@version": {
  10. "type": "text",
  11. "fields": {
  12. "keyword": {
  13. "type": "keyword",
  14. "ignore_above": 256
  15. }
  16. }
  17. },
  18. "agent": {
  19. "properties": {
  20. "ephemeral_id": {
  21. "type": "text",
  22. "fields": {
  23. "keyword": {
  24. "type": "keyword",
  25. "ignore_above": 256
  26. }
  27. }
  28. },
  29. "hostname": {
  30. "type": "text",
  31. "fields": {
  32. "keyword": {
  33. "type": "keyword",
  34. "ignore_above": 256
  35. }
  36. }
  37. },
  38. "id": {
  39. "type": "text",
  40. "fields": {
  41. "keyword": {
  42. "type": "keyword",
  43. "ignore_above": 256
  44. }
  45. }
  46. },
  47. "type": {
  48. "type": "text",
  49. "fields": {
  50. "keyword": {
  51. "type": "keyword",
  52. "ignore_above": 256
  53. }
  54. }
  55. },
  56. "version": {
  57. "type": "text",
  58. "fields": {
  59. "keyword": {
  60. "type": "keyword",
  61. "ignore_above": 256
  62. }
  63. }
  64. }
  65. }
  66. },
  67. "ecs": {
  68. "properties": {
  69. "version": {
  70. "type": "text",
  71. "fields": {
  72. "keyword": {
  73. "type": "keyword",
  74. "ignore_above": 256
  75. }
  76. }
  77. }
  78. }
  79. },
  80. "event": {
  81. "properties": {
  82. "action": {
  83. "type": "text",
  84. "fields": {
  85. "keyword": {
  86. "type": "keyword",
  87. "ignore_above": 256
  88. }
  89. }
  90. },
  91. "code": {
  92. "type": "long"
  93. },
  94. "created": {
  95. "type": "date"
  96. },
  97. "kind": {
  98. "type": "text",
  99. "fields": {
  100. "keyword": {
  101. "type": "keyword",
  102. "ignore_above": 256
  103. }
  104. }
  105. },
  106. "provider": {
  107. "type": "text",
  108. "fields": {
  109. "keyword": {
  110. "type": "keyword",
  111. "ignore_above": 256
  112. }
  113. }
  114. }
  115. }
  116. },
  117. "host": {
  118. "properties": {
  119. "architecture": {
  120. "type": "text",
  121. "fields": {
  122. "keyword": {
  123. "type": "keyword",
  124. "ignore_above": 256
  125. }
  126. }
  127. },
  128. "hostname": {
  129. "type": "text",
  130. "fields": {
  131. "keyword": {
  132. "type": "keyword",
  133. "ignore_above": 256
  134. }
  135. }
  136. },
  137. "id": {
  138. "type": "text",
  139. "fields": {
  140. "keyword": {
  141. "type": "keyword",
  142. "ignore_above": 256
  143. }
  144. }
  145. },
  146. "name": {
  147. "type": "text",
  148. "fields": {
  149. "keyword": {
  150. "type": "keyword",
  151. "ignore_above": 256
  152. }
  153. }
  154. },
  155. "os": {
  156. "properties": {
  157. "build": {
  158. "type": "text",
  159. "fields": {
  160. "keyword": {
  161. "type": "keyword",
  162. "ignore_above": 256
  163. }
  164. }
  165. },
  166. "family": {
  167. "type": "text",
  168. "fields": {
  169. "keyword": {
  170. "type": "keyword",
  171. "ignore_above": 256
  172. }
  173. }
  174. },
  175. "kernel": {
  176. "type": "text",
  177. "fields": {
  178. "keyword": {
  179. "type": "keyword",
  180. "ignore_above": 256
  181. }
  182. }
  183. },
  184. "name": {
  185. "type": "text",
  186. "fields": {
  187. "keyword": {
  188. "type": "keyword",
  189. "ignore_above": 256
  190. }
  191. }
  192. },
  193. "platform": {
  194. "type": "text",
  195. "fields": {
  196. "keyword": {
  197. "type": "keyword",
  198. "ignore_above": 256
  199. }
  200. }
  201. },
  202. "version": {
  203. "type": "text",
  204. "fields": {
  205. "keyword": {
  206. "type": "keyword",
  207. "ignore_above": 256
  208. }
  209. }
  210. }
  211. }
  212. }
  213. }
  214. },
  215. "log": {
  216. "properties": {
  217. "level": {
  218. "type": "text",
  219. "fields": {
  220. "keyword": {
  221. "type": "keyword",
  222. "ignore_above": 256
  223. }
  224. }
  225. }
  226. }
  227. },
  228. "message": {
  229. "type": "text",
  230. "fields": {
  231. "keyword": {
  232. "type": "keyword",
  233. "ignore_above": 2000
  234. }
  235. }
  236. },
  237. "tags": {
  238. "type": "text",
  239. "fields": {
  240. "keyword": {
  241. "type": "keyword",
  242. "ignore_above": 256
  243. }
  244. }
  245. },
  246. "winlog": {
  247. "properties": {
  248. "activity_id": {
  249. "type": "text",
  250. "fields": {
  251. "keyword": {
  252. "type": "keyword",
  253. "ignore_above": 256
  254. }
  255. }
  256. },
  257. "api": {
  258. "type": "text",
  259. "fields": {
  260. "keyword": {
  261. "type": "keyword",
  262. "ignore_above": 256
  263. }
  264. }
  265. },
  266. "channel": {
  267. "type": "text",
  268. "fields": {
  269. "keyword": {
  270. "type": "keyword",
  271. "ignore_above": 256
  272. }
  273. }
  274. },
  275. "computer_name": {
  276. "type": "text",
  277. "fields": {
  278. "keyword": {
  279. "type": "keyword",
  280. "ignore_above": 256
  281. }
  282. }
  283. },
  284. "event_data": {
  285. "properties": {
  286. "ContextInfo": {
  287. "type": "text",
  288. "fields": {
  289. "keyword": {
  290. "type": "keyword",
  291. "ignore_above": 256
  292. }
  293. }
  294. },
  295. "Payload": {
  296. "type": "text",
  297. "fields": {
  298. "keyword": {
  299. "type": "keyword",
  300. "ignore_above": 256
  301. }
  302. }
  303. },
  304. "param1": {
  305. "type": "text",
  306. "fields": {
  307. "keyword": {
  308. "type": "keyword",
  309. "ignore_above": 256
  310. }
  311. }
  312. },
  313. "param2": {
  314. "type": "text",
  315. "fields": {
  316. "keyword": {
  317. "type": "keyword",
  318. "ignore_above": 256
  319. }
  320. }
  321. },
  322. "param3": {
  323. "type": "text",
  324. "fields": {
  325. "keyword": {
  326. "type": "keyword",
  327. "ignore_above": 256
  328. }
  329. }
  330. }
  331. }
  332. },
  333. "event_id": {
  334. "type": "long"
  335. },
  336. "keywords": {
  337. "type": "text",
  338. "fields": {
  339. "keyword": {
  340. "type": "keyword",
  341. "ignore_above": 256
  342. }
  343. }
  344. },
  345. "opcode": {
  346. "type": "text",
  347. "fields": {
  348. "keyword": {
  349. "type": "keyword",
  350. "ignore_above": 256
  351. }
  352. }
  353. },
  354. "process": {
  355. "properties": {
  356. "pid": {
  357. "type": "long"
  358. },
  359. "thread": {
  360. "properties": {
  361. "id": {
  362. "type": "long"
  363. }
  364. }
  365. }
  366. }
  367. },
  368. "provider_guid": {
  369. "type": "text",
  370. "fields": {
  371. "keyword": {
  372. "type": "keyword",
  373. "ignore_above": 256
  374. }
  375. }
  376. },
  377. "provider_name": {
  378. "type": "text",
  379. "fields": {
  380. "keyword": {
  381. "type": "keyword",
  382. "ignore_above": 256
  383. }
  384. }
  385. },
  386. "record_id": {
  387. "type": "long"
  388. },
  389. "task": {
  390. "type": "text",
  391. "fields": {
  392. "keyword": {
  393. "type": "keyword",
  394. "ignore_above": 256
  395. }
  396. }
  397. },
  398. "user": {
  399. "properties": {
  400. "domain": {
  401. "type": "text",
  402. "fields": {
  403. "keyword": {
  404. "type": "keyword",
  405. "ignore_above": 256
  406. }
  407. }
  408. },
  409. "identifier": {
  410. "type": "text",
  411. "fields": {
  412. "keyword": {
  413. "type": "keyword",
  414. "ignore_above": 256
  415. }
  416. }
  417. },
  418. "name": {
  419. "type": "text",
  420. "fields": {
  421. "keyword": {
  422. "type": "keyword",
  423. "ignore_above": 256
  424. }
  425. }
  426. },
  427. "type": {
  428. "type": "text",
  429. "fields": {
  430. "keyword": {
  431. "type": "keyword",
  432. "ignore_above": 256
  433. }
  434. }
  435. }
  436. }
  437. },
  438. "version": {
  439. "type": "long"
  440. }
  441. }
  442. }
  443. }
  444. }
  445. }
  446. }
  447. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement