Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "filebeat-2017.10.298" : {
- "mappings" : {
- "_default_" : {
- "_meta" : {
- "version" : "5.6.3"
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "match_mapping_type" : "string",
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "@timestamp" : {
- "type" : "date"
- },
- "apache2" : {
- "properties" : {
- "access" : {
- "properties" : {
- "agent" : {
- "type" : "text",
- "norms" : false
- },
- "body_sent" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "http_version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "referrer" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "remote_ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "response_code" : {
- "type" : "long"
- },
- "url" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user_agent" : {
- "properties" : {
- "device" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "major" : {
- "type" : "long"
- },
- "minor" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os_major" : {
- "type" : "long"
- },
- "os_minor" : {
- "type" : "long"
- },
- "os_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "patch" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "user_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "properties" : {
- "client" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "module" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "long"
- },
- "tid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "auditd" : {
- "properties" : {
- "log" : {
- "properties" : {
- "a0" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "acct" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "item" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "items" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "new_auid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "new_ses" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "old_auid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "old_ses" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "ppid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "record_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "res" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "sequence" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "beat" : {
- "properties" : {
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "fileset" : {
- "properties" : {
- "module" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "input_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "meta" : {
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "instance_id" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "machine_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "project_id" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "provider" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "region" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "mysql" : {
- "properties" : {
- "error" : {
- "properties" : {
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "thread_id" : {
- "type" : "long"
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "slowlog" : {
- "properties" : {
- "host" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "id" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "lock_time" : {
- "properties" : {
- "sec" : {
- "type" : "float"
- }
- }
- },
- "query" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "query_time" : {
- "properties" : {
- "sec" : {
- "type" : "float"
- }
- }
- },
- "rows_examined" : {
- "type" : "long"
- },
- "rows_sent" : {
- "type" : "long"
- },
- "timestamp" : {
- "type" : "long"
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "nginx" : {
- "properties" : {
- "access" : {
- "properties" : {
- "agent" : {
- "type" : "text",
- "norms" : false
- },
- "body_sent" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "http_version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "referrer" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "remote_ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "response_code" : {
- "type" : "long"
- },
- "url" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user_agent" : {
- "properties" : {
- "device" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "major" : {
- "type" : "long"
- },
- "minor" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os_major" : {
- "type" : "long"
- },
- "os_minor" : {
- "type" : "long"
- },
- "os_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "patch" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "user_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "properties" : {
- "connection_id" : {
- "type" : "long"
- },
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "pid" : {
- "type" : "long"
- },
- "tid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "offset" : {
- "type" : "long"
- },
- "read_timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "source" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "system" : {
- "properties" : {
- "auth" : {
- "properties" : {
- "groupadd" : {
- "properties" : {
- "gid" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "long"
- },
- "program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "ssh" : {
- "properties" : {
- "dropped_ip" : {
- "type" : "ip"
- },
- "event" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "ip" : {
- "type" : "ip"
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "port" : {
- "type" : "long"
- },
- "signature" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "sudo" : {
- "properties" : {
- "command" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "error" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pwd" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "tty" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "useradd" : {
- "properties" : {
- "gid" : {
- "type" : "long"
- },
- "home" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "shell" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "uid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "syslog" : {
- "properties" : {
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "tags" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "log" : {
- "_meta" : {
- "version" : "5.6.3"
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "match_mapping_type" : "string",
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "@timestamp" : {
- "type" : "date"
- },
- "@version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "apache2" : {
- "properties" : {
- "access" : {
- "properties" : {
- "agent" : {
- "type" : "text",
- "norms" : false
- },
- "body_sent" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "http_version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "referrer" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "remote_ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "response_code" : {
- "type" : "long"
- },
- "url" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user_agent" : {
- "properties" : {
- "device" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "major" : {
- "type" : "long"
- },
- "minor" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os_major" : {
- "type" : "long"
- },
- "os_minor" : {
- "type" : "long"
- },
- "os_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "patch" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "user_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "properties" : {
- "client" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "module" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "long"
- },
- "tid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "auditd" : {
- "properties" : {
- "log" : {
- "properties" : {
- "a0" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "acct" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "item" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "items" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "new_auid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "new_ses" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "old_auid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "old_ses" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "ppid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "record_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "res" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "sequence" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "beat" : {
- "properties" : {
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "fields" : {
- "properties" : {
- "company_env" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "fileset" : {
- "properties" : {
- "module" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "host" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "input_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "meta" : {
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "instance_id" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "machine_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "project_id" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "provider" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "region" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "mysql" : {
- "properties" : {
- "error" : {
- "properties" : {
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "thread_id" : {
- "type" : "long"
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "slowlog" : {
- "properties" : {
- "host" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "id" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "lock_time" : {
- "properties" : {
- "sec" : {
- "type" : "float"
- }
- }
- },
- "query" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "query_time" : {
- "properties" : {
- "sec" : {
- "type" : "float"
- }
- }
- },
- "rows_examined" : {
- "type" : "long"
- },
- "rows_sent" : {
- "type" : "long"
- },
- "timestamp" : {
- "type" : "long"
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "nginx" : {
- "properties" : {
- "access" : {
- "properties" : {
- "agent" : {
- "type" : "text",
- "norms" : false
- },
- "body_sent" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "http_version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "referrer" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "remote_ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "response_code" : {
- "type" : "long"
- },
- "url" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user_agent" : {
- "properties" : {
- "device" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "major" : {
- "type" : "long"
- },
- "minor" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os_major" : {
- "type" : "long"
- },
- "os_minor" : {
- "type" : "long"
- },
- "os_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "patch" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "user_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "properties" : {
- "connection_id" : {
- "type" : "long"
- },
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "pid" : {
- "type" : "long"
- },
- "tid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "offset" : {
- "type" : "long"
- },
- "read_timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "source" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "system" : {
- "properties" : {
- "auth" : {
- "properties" : {
- "groupadd" : {
- "properties" : {
- "gid" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "long"
- },
- "program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "ssh" : {
- "properties" : {
- "dropped_ip" : {
- "type" : "ip"
- },
- "event" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "ip" : {
- "type" : "ip"
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "port" : {
- "type" : "long"
- },
- "signature" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "sudo" : {
- "properties" : {
- "command" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "error" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pwd" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "tty" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "useradd" : {
- "properties" : {
- "gid" : {
- "type" : "long"
- },
- "home" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "shell" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "uid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "syslog" : {
- "properties" : {
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "tags" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "syslog" : {
- "_meta" : {
- "version" : "5.6.3"
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "match_mapping_type" : "string",
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "@timestamp" : {
- "type" : "date"
- },
- "@version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "apache2" : {
- "properties" : {
- "access" : {
- "properties" : {
- "agent" : {
- "type" : "text",
- "norms" : false
- },
- "body_sent" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "http_version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "referrer" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "remote_ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "response_code" : {
- "type" : "long"
- },
- "url" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user_agent" : {
- "properties" : {
- "device" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "major" : {
- "type" : "long"
- },
- "minor" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os_major" : {
- "type" : "long"
- },
- "os_minor" : {
- "type" : "long"
- },
- "os_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "patch" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "user_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "properties" : {
- "client" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "module" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "long"
- },
- "tid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "auditd" : {
- "properties" : {
- "log" : {
- "properties" : {
- "a0" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "acct" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "item" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "items" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "new_auid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "new_ses" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "old_auid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "old_ses" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "ppid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "record_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "res" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "sequence" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "beat" : {
- "properties" : {
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "fields" : {
- "properties" : {
- "hosts" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "company_env" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "fileset" : {
- "properties" : {
- "module" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "host" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "input_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "meta" : {
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "instance_id" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "machine_type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "project_id" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "provider" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "region" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "mysql" : {
- "properties" : {
- "error" : {
- "properties" : {
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "thread_id" : {
- "type" : "long"
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "slowlog" : {
- "properties" : {
- "host" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "id" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "lock_time" : {
- "properties" : {
- "sec" : {
- "type" : "float"
- }
- }
- },
- "query" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "query_time" : {
- "properties" : {
- "sec" : {
- "type" : "float"
- }
- }
- },
- "rows_examined" : {
- "type" : "long"
- },
- "rows_sent" : {
- "type" : "long"
- },
- "timestamp" : {
- "type" : "long"
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "nginx" : {
- "properties" : {
- "access" : {
- "properties" : {
- "agent" : {
- "type" : "text",
- "norms" : false
- },
- "body_sent" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "http_version" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "referrer" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "remote_ip" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "response_code" : {
- "type" : "long"
- },
- "url" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user_agent" : {
- "properties" : {
- "device" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "major" : {
- "type" : "long"
- },
- "minor" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "os_major" : {
- "type" : "long"
- },
- "os_minor" : {
- "type" : "long"
- },
- "os_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "patch" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "user_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "error" : {
- "properties" : {
- "connection_id" : {
- "type" : "long"
- },
- "level" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "text",
- "norms" : false
- },
- "pid" : {
- "type" : "long"
- },
- "tid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "offset" : {
- "type" : "long"
- },
- "read_timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "source" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "syslog_hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "syslog_message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "syslog_pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "syslog_program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "syslog_timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "system" : {
- "properties" : {
- "auth" : {
- "properties" : {
- "groupadd" : {
- "properties" : {
- "gid" : {
- "type" : "long"
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "long"
- },
- "program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "ssh" : {
- "properties" : {
- "dropped_ip" : {
- "type" : "ip"
- },
- "event" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "geoip" : {
- "properties" : {
- "city_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "continent_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "country_iso_code" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "ip" : {
- "type" : "ip"
- },
- "method" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "port" : {
- "type" : "long"
- },
- "signature" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "sudo" : {
- "properties" : {
- "command" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "error" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pwd" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "tty" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "user" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "useradd" : {
- "properties" : {
- "gid" : {
- "type" : "long"
- },
- "home" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "name" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "shell" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "uid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "syslog" : {
- "properties" : {
- "hostname" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "message" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "pid" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "program" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "timestamp" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- },
- "tags" : {
- "type" : "keyword",
- "ignore_above" : 1024
- },
- "type" : {
- "type" : "keyword",
- "ignore_above" : 1024
- }
- }
- }
- }
- }
- }
Add Comment
Please, Sign In to add comment