Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "index_templates" : [
- {
- "name" : "metrics-system.process",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.process-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "process" : {
- "properties" : {
- "pgid" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "process" : {
- "properties" : {
- "cmdline" : {
- "ignore_above" : 2048,
- "type" : "keyword"
- },
- "memory" : {
- "properties" : {
- "rss" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "size" : {
- "type" : "long"
- },
- "share" : {
- "type" : "long"
- }
- }
- },
- "cpu" : {
- "properties" : {
- "start_time" : {
- "type" : "date"
- },
- "total" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "value" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "system" : {
- "properties" : {
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "user" : {
- "properties" : {
- "ticks" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "state" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "env" : {
- "type" : "object"
- },
- "cgroup" : {
- "properties" : {
- "blkio" : {
- "properties" : {
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "total" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "ios" : {
- "type" : "long"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "memory" : {
- "properties" : {
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mem" : {
- "properties" : {
- "failures" : {
- "type" : "long"
- },
- "usage" : {
- "properties" : {
- "max" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "limit" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "stats" : {
- "properties" : {
- "inactive_anon" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "cache" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "rss_huge" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "mapped_file" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "swap" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "unevictable" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "active_anon" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "pages_in" : {
- "type" : "long"
- },
- "hierarchical_memory_limit" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "page_faults" : {
- "type" : "long"
- },
- "pages_out" : {
- "type" : "long"
- },
- "inactive_file" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "hierarchical_memsw_limit" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "rss" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "major_page_faults" : {
- "type" : "long"
- },
- "active_file" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "memsw" : {
- "properties" : {
- "failures" : {
- "type" : "long"
- },
- "usage" : {
- "properties" : {
- "max" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "limit" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "kmem_tcp" : {
- "properties" : {
- "failures" : {
- "type" : "long"
- },
- "usage" : {
- "properties" : {
- "max" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "limit" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "kmem" : {
- "properties" : {
- "failures" : {
- "type" : "long"
- },
- "usage" : {
- "properties" : {
- "max" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "limit" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "cpu" : {
- "properties" : {
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "cfs" : {
- "properties" : {
- "shares" : {
- "type" : "long"
- },
- "period" : {
- "properties" : {
- "us" : {
- "type" : "long"
- }
- }
- },
- "quota" : {
- "properties" : {
- "us" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "rt" : {
- "properties" : {
- "period" : {
- "properties" : {
- "us" : {
- "type" : "long"
- }
- }
- },
- "runtime" : {
- "properties" : {
- "us" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "stats" : {
- "properties" : {
- "periods" : {
- "type" : "long"
- },
- "throttled" : {
- "properties" : {
- "ns" : {
- "type" : "long"
- },
- "periods" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "cpuacct" : {
- "properties" : {
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "total" : {
- "properties" : {
- "ns" : {
- "type" : "long"
- }
- }
- },
- "stats" : {
- "properties" : {
- "system" : {
- "properties" : {
- "ns" : {
- "type" : "long"
- }
- }
- },
- "user" : {
- "properties" : {
- "ns" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "percpu" : {
- "type" : "object"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "fd" : {
- "properties" : {
- "limit" : {
- "properties" : {
- "hard" : {
- "type" : "long"
- },
- "soft" : {
- "type" : "long"
- }
- }
- },
- "open" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : ".triggered_watches",
- "index_template" : {
- "index_patterns" : [
- ".triggered_watches*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "format" : "6",
- "refresh_interval" : "-1",
- "number_of_shards" : "1",
- "priority" : "900",
- "auto_expand_replicas" : "0-1"
- }
- },
- "mappings" : {
- "dynamic" : "strict",
- "properties" : {
- "state" : {
- "type" : "keyword"
- },
- "trigger_event" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false,
- "properties" : {
- "schedule" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "triggered_time" : {
- "type" : "date"
- },
- "scheduled_time" : {
- "type" : "date"
- }
- }
- }
- }
- }
- }
- }
- },
- "composed_of" : [ ],
- "priority" : 2147483647,
- "version" : 12,
- "_meta" : {
- "managed" : true,
- "description" : "index template for triggered watches indices"
- }
- }
- },
- {
- "name" : "metrics-system.fsstat",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.fsstat-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "fsstat" : {
- "properties" : {
- "total_files" : {
- "type" : "long"
- },
- "count" : {
- "type" : "long"
- },
- "total_size" : {
- "properties" : {
- "total" : {
- "type" : "long"
- },
- "used" : {
- "type" : "long"
- },
- "free" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-endpoint.metadata",
- "index_template" : {
- "index_patterns" : [
- "metrics-endpoint.metadata-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "metrics-endpoint.metadata-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "Endpoint" : {
- "properties" : {
- "policy" : {
- "properties" : {
- "applied" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "elastic" : {
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "event" : {
- "properties" : {
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "metrics-endpoint.metadata-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.memory",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.memory-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "memory" : {
- "properties" : {
- "hugepages" : {
- "properties" : {
- "total" : {
- "type" : "long"
- },
- "default_size" : {
- "type" : "long"
- },
- "surplus" : {
- "type" : "long"
- },
- "reserved" : {
- "type" : "long"
- },
- "swap" : {
- "properties" : {
- "out" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- },
- "fallback" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "used" : {
- "properties" : {
- "pct" : {
- "type" : "long"
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "free" : {
- "type" : "long"
- }
- }
- },
- "actual" : {
- "properties" : {
- "used" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "free" : {
- "type" : "long"
- }
- }
- },
- "total" : {
- "type" : "long"
- },
- "swap" : {
- "properties" : {
- "total" : {
- "type" : "long"
- },
- "readahead" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- },
- "cached" : {
- "type" : "long"
- }
- }
- },
- "in" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- },
- "used" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "free" : {
- "type" : "long"
- },
- "out" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "page_stats" : {
- "properties" : {
- "pgscan_kswapd" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- },
- "pgscan_direct" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- },
- "pgsteal_direct" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- },
- "direct_efficiency" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- },
- "pgfree" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- },
- "pgsteal_kswapd" : {
- "properties" : {
- "pages" : {
- "type" : "long"
- }
- }
- },
- "kswapd_efficiency" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "used" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "free" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.socket_summary",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.socket_summary-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "process" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "socket" : {
- "properties" : {
- "summary" : {
- "properties" : {
- "all" : {
- "properties" : {
- "listening" : {
- "type" : "long"
- },
- "count" : {
- "type" : "long"
- }
- }
- },
- "tcp" : {
- "properties" : {
- "all" : {
- "properties" : {
- "listening" : {
- "type" : "long"
- },
- "established" : {
- "type" : "long"
- },
- "syn_sent" : {
- "type" : "long"
- },
- "syn_recv" : {
- "type" : "long"
- },
- "closing" : {
- "type" : "long"
- },
- "time_wait" : {
- "type" : "long"
- },
- "last_ack" : {
- "type" : "long"
- },
- "count" : {
- "type" : "long"
- },
- "orphan" : {
- "type" : "long"
- },
- "close_wait" : {
- "type" : "long"
- },
- "fin_wait1" : {
- "type" : "long"
- },
- "fin_wait2" : {
- "type" : "long"
- }
- }
- },
- "memory" : {
- "type" : "long"
- }
- }
- },
- "udp" : {
- "properties" : {
- "all" : {
- "properties" : {
- "count" : {
- "type" : "long"
- }
- }
- },
- "memory" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "port" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "user" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "group" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-metadata-current",
- "index_template" : {
- "index_patterns" : [
- "metrics-endpoint.metadata_current_*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "codec" : "best_compression",
- "refresh_interval" : "5s",
- "number_of_routing_shards" : "30",
- "number_of_shards" : "1"
- }
- },
- "mappings" : {
- "_meta" : { },
- "dynamic" : "false",
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "type" : "keyword"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "HostDetails" : {
- "properties" : {
- "agent" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "Endpoint" : {
- "properties" : {
- "policy" : {
- "properties" : {
- "applied" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "elastic" : {
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "event" : {
- "properties" : {
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200
- }
- },
- {
- "name" : "metrics-endpoint.metrics",
- "index_template" : {
- "index_patterns" : [
- "metrics-endpoint.metrics-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "metrics-endpoint.metrics-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "Endpoint" : {
- "properties" : {
- "metrics" : {
- "properties" : {
- "memory" : {
- "properties" : {
- "endpoint" : {
- "properties" : {
- "private" : {
- "properties" : {
- "mean" : {
- "type" : "long"
- },
- "latest" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "disks" : {
- "properties" : {
- "endpoint_drive" : {
- "type" : "boolean"
- },
- "total" : {
- "type" : "long"
- },
- "free" : {
- "type" : "long"
- },
- "device" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mount" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "fstype" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- },
- "enabled" : false
- },
- "cpu" : {
- "properties" : {
- "endpoint" : {
- "properties" : {
- "histogram" : {
- "type" : "histogram"
- },
- "mean" : {
- "type" : "half_float"
- },
- "latest" : {
- "type" : "half_float"
- }
- }
- }
- }
- },
- "threads" : {
- "type" : "object",
- "enabled" : false
- },
- "uptime" : {
- "properties" : {
- "endpoint" : {
- "type" : "long"
- },
- "system" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "start" : {
- "type" : "date"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "end" : {
- "type" : "date"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "metrics-endpoint.metrics-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.load",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.load-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "load" : {
- "properties" : {
- "1" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "cores" : {
- "type" : "long"
- },
- "15" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "5" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "norm" : {
- "properties" : {
- "1" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "15" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "5" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.core",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.core-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "core" : {
- "properties" : {
- "system" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "softirq" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "idle" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "steal" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "irq" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "iowait" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "user" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- },
- "nice" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : ".slm-history",
- "index_template" : {
- "index_patterns" : [
- ".slm-history-3*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "format" : "1",
- "lifecycle" : {
- "name" : "slm-history-ilm-policy",
- "rollover_alias" : ".slm-history-3"
- },
- "hidden" : "true",
- "number_of_shards" : "1",
- "auto_expand_replicas" : "0-1",
- "number_of_replicas" : "0"
- }
- },
- "mappings" : {
- "dynamic" : false,
- "properties" : {
- "snapshot_name" : {
- "type" : "keyword"
- },
- "@timestamp" : {
- "format" : "epoch_millis",
- "type" : "date"
- },
- "configuration" : {
- "dynamic" : false,
- "type" : "object",
- "properties" : {
- "indices" : {
- "type" : "keyword"
- },
- "include_global_state" : {
- "type" : "boolean"
- },
- "partial" : {
- "type" : "boolean"
- }
- }
- },
- "error_details" : {
- "index" : false,
- "type" : "text"
- },
- "success" : {
- "type" : "boolean"
- },
- "repository" : {
- "type" : "keyword"
- },
- "operation" : {
- "type" : "keyword"
- },
- "policy" : {
- "type" : "keyword"
- }
- }
- }
- },
- "composed_of" : [ ],
- "priority" : 2147483647,
- "version" : 3,
- "_meta" : {
- "managed" : true,
- "description" : "index template for SLM history indices"
- }
- }
- },
- {
- "name" : "logs-endpoint.events.security",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.events.security-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.events.security-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- },
- "thread" : {
- "properties" : {
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.events.security-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-endpoint.events.registry",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.events.registry-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.events.registry-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "registry" : {
- "properties" : {
- "hive" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "data" : {
- "properties" : {
- "strings" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "bytes" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "value" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "key" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- },
- "thread" : {
- "properties" : {
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "@timestamp" : {
- "type" : "date"
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.events.registry-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : ".watches",
- "index_template" : {
- "index_patterns" : [
- ".watches*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "format" : "6",
- "number_of_shards" : "1",
- "priority" : "800",
- "auto_expand_replicas" : "0-1",
- "number_of_replicas" : "0"
- }
- },
- "mappings" : {
- "dynamic" : "strict",
- "properties" : {
- "throttle_period" : {
- "index" : false,
- "type" : "keyword",
- "doc_values" : false
- },
- "input" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- },
- "condition" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- },
- "transform" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- },
- "metadata" : {
- "dynamic" : true,
- "type" : "object"
- },
- "throttle_period_in_millis" : {
- "index" : false,
- "type" : "long",
- "doc_values" : false
- },
- "trigger" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- },
- "actions" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- },
- "status" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- }
- }
- }
- },
- "composed_of" : [ ],
- "priority" : 2147483647,
- "version" : 12,
- "_meta" : {
- "managed" : true,
- "description" : "index template for watches indices"
- }
- }
- },
- {
- "name" : "logs",
- "index_template" : {
- "index_patterns" : [
- "logs-*-*"
- ],
- "composed_of" : [
- "logs-mappings",
- "logs-settings"
- ],
- "priority" : 100,
- "version" : 0,
- "_meta" : {
- "managed" : true,
- "description" : "default logs template installed by x-pack"
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-endpoint.events.network",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.events.network-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.events.network-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- },
- "thread" : {
- "properties" : {
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "registered_domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "port" : {
- "type" : "long"
- },
- "top_level_domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "bytes" : {
- "type" : "long"
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "packets" : {
- "type" : "long"
- }
- }
- },
- "dns" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "options" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "type" : "long"
- }
- }
- },
- "resolved_ip" : {
- "type" : "ip"
- },
- "question" : {
- "properties" : {
- "registered_domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "top_level_domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "subdomain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "registered_domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "port" : {
- "type" : "long"
- },
- "top_level_domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "bytes" : {
- "type" : "long"
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "packets" : {
- "type" : "long"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "network" : {
- "properties" : {
- "community_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "protocol" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "bytes" : {
- "type" : "long"
- },
- "transport" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "iana_number" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "packets" : {
- "type" : "long"
- },
- "direction" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "http" : {
- "properties" : {
- "request" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "body" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "content" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- }
- }
- },
- "response" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "status_code" : {
- "type" : "long"
- },
- "bytes" : {
- "type" : "long"
- },
- "body" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "content" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.events.network-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.uptime",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.uptime-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "uptime" : {
- "properties" : {
- "duration" : {
- "properties" : {
- "ms" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-endpoint.events.process",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.events.process-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.events.process-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "session" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "authentication_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "token" : {
- "properties" : {
- "elevation" : {
- "type" : "boolean"
- },
- "integrity_level_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "elevation_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "parent" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "real" : {
- "properties" : {
- "pid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "pgid" : {
- "type" : "long"
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "thread" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "title" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- },
- "uptime" : {
- "type" : "long"
- },
- "args" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "code_signature" : {
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "exit_code" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "args_count" : {
- "type" : "long"
- },
- "command_line" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "pgid" : {
- "type" : "long"
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "thread" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "title" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- },
- "uptime" : {
- "type" : "long"
- },
- "args" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "code_signature" : {
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "exit_code" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "args_count" : {
- "type" : "long"
- },
- "command_line" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "package" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "@timestamp" : {
- "type" : "date"
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.events.process-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.cpu",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.cpu-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "cpu" : {
- "properties" : {
- "total" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "cores" : {
- "type" : "long"
- },
- "system" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "softirq" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "idle" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "steal" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "irq" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "iowait" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "user" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "nice" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "ticks" : {
- "type" : "long"
- },
- "norm" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "cpu" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "synthetics",
- "index_template" : {
- "index_patterns" : [
- "synthetics-*-*"
- ],
- "composed_of" : [
- "synthetics-mappings",
- "synthetics-settings"
- ],
- "priority" : 100,
- "version" : 0,
- "_meta" : {
- "managed" : true,
- "description" : "default synthetics template installed by x-pack"
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.diskio",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.diskio-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "diskio" : {
- "properties" : {
- "read" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "count" : {
- "type" : "long"
- },
- "time" : {
- "type" : "long"
- }
- }
- },
- "iostat" : {
- "properties" : {
- "request" : {
- "properties" : {
- "avg_size" : {
- "type" : "float"
- }
- }
- },
- "service_time" : {
- "type" : "float"
- },
- "read" : {
- "properties" : {
- "request" : {
- "properties" : {
- "merges_per_sec" : {
- "type" : "float"
- },
- "per_sec" : {
- "type" : "float"
- }
- }
- },
- "await" : {
- "type" : "float"
- },
- "per_sec" : {
- "properties" : {
- "bytes" : {
- "type" : "float"
- }
- }
- }
- }
- },
- "busy" : {
- "type" : "float"
- },
- "await" : {
- "type" : "float"
- },
- "write" : {
- "properties" : {
- "request" : {
- "properties" : {
- "merges_per_sec" : {
- "type" : "float"
- },
- "per_sec" : {
- "type" : "float"
- }
- }
- },
- "await" : {
- "type" : "float"
- },
- "per_sec" : {
- "properties" : {
- "bytes" : {
- "type" : "float"
- }
- }
- }
- }
- },
- "queue" : {
- "properties" : {
- "avg_size" : {
- "type" : "float"
- }
- }
- }
- }
- },
- "io" : {
- "properties" : {
- "time" : {
- "type" : "long"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "serial_number" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "write" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "count" : {
- "type" : "long"
- },
- "time" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "disk" : {
- "properties" : {
- "read" : {
- "properties" : {
- "bytes" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- },
- "write" : {
- "properties" : {
- "bytes" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.process_summary",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.process_summary-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "process" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "process" : {
- "properties" : {
- "summary" : {
- "properties" : {
- "running" : {
- "type" : "long"
- },
- "total" : {
- "type" : "long"
- },
- "stopped" : {
- "type" : "long"
- },
- "idle" : {
- "type" : "long"
- },
- "zombie" : {
- "type" : "long"
- },
- "dead" : {
- "type" : "long"
- },
- "sleeping" : {
- "type" : "long"
- },
- "unknown" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "port" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "user" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "group" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-system.auth",
- "index_template" : {
- "index_patterns" : [
- "logs-system.auth-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-system.auth-0.9.3",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "process" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "auth" : {
- "properties" : {
- "ssh" : {
- "properties" : {
- "geoip" : {
- "properties" : { }
- },
- "method" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dropped_ip" : {
- "type" : "ip"
- },
- "signature" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "event" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "sudo" : {
- "properties" : {
- "tty" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "error" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pwd" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "command" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "useradd" : {
- "properties" : {
- "shell" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "home" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "groupadd" : {
- "properties" : { }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "port" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "user" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-endpoint.policy",
- "index_template" : {
- "index_patterns" : [
- "metrics-endpoint.policy-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "metrics-endpoint.policy-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "Endpoint" : {
- "properties" : {
- "policy" : {
- "properties" : {
- "applied" : {
- "properties" : {
- "configurations" : {
- "properties" : {
- "streaming" : {
- "properties" : {
- "concerned_actions" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "malware" : {
- "properties" : {
- "concerned_actions" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "logging" : {
- "properties" : {
- "concerned_actions" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "events" : {
- "properties" : {
- "concerned_actions" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "response" : {
- "type" : "object",
- "enabled" : false
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "actions" : {
- "type" : "nested",
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "message" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- },
- "enabled" : false
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "artifacts" : {
- "properties" : {
- "global" : {
- "properties" : {
- "identifiers" : {
- "type" : "nested",
- "properties" : {
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "identifiers" : {
- "type" : "nested",
- "properties" : {
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "metrics-endpoint.policy-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : ".watch-history-12",
- "index_template" : {
- "index_patterns" : [
- ".watcher-history-12*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "format" : "6",
- "lifecycle" : {
- "name" : "watch-history-ilm-policy"
- },
- "hidden" : "true",
- "number_of_shards" : "1",
- "auto_expand_replicas" : "0-1",
- "number_of_replicas" : "0"
- }
- },
- "mappings" : {
- "_meta" : {
- "watcher-history-version" : "12"
- },
- "dynamic" : false,
- "dynamic_templates" : [
- {
- "disabled_payload_fields" : {
- "match_pattern" : "regex",
- "path_match" : """result\.(input(\..+)*|(transform(\..+)*)|(actions\.transform(\..+)*))\.payload""",
- "mapping" : {
- "type" : "object",
- "enabled" : false
- }
- }
- },
- {
- "disabled_search_request_body_fields" : {
- "match_pattern" : "regex",
- "path_match" : """result\.(input(\..+)*|(transform(\..+)*)|(actions\.transform(\..+)*))\.search\.request\.(body|template)""",
- "mapping" : {
- "type" : "object",
- "enabled" : false
- }
- }
- },
- {
- "disabled_exception_fields" : {
- "match_pattern" : "regex",
- "path_match" : """result\.(input(\..+)*|(transform(\..+)*)|(actions\.transform(\..+)*)|actions)\.error""",
- "mapping" : {
- "type" : "object",
- "enabled" : false
- }
- }
- },
- {
- "disabled_jira_custom_fields" : {
- "path_match" : "result.actions.jira.fields.customfield_*",
- "mapping" : {
- "type" : "object",
- "enabled" : false
- }
- }
- }
- ],
- "properties" : {
- "exception" : {
- "type" : "object",
- "enabled" : false
- },
- "metadata" : {
- "dynamic" : true,
- "type" : "object"
- },
- "trigger_event" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "schedule" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "scheduled_time" : {
- "type" : "date"
- }
- }
- },
- "triggered_time" : {
- "type" : "date"
- },
- "type" : {
- "type" : "keyword"
- },
- "manual" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "schedule" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "scheduled_time" : {
- "type" : "date"
- }
- }
- }
- }
- }
- }
- },
- "result" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "input" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "search" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "request" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "indices" : {
- "type" : "keyword"
- },
- "types" : {
- "type" : "keyword"
- },
- "search_type" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "payload" : {
- "type" : "object",
- "enabled" : false
- },
- "http" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "request" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "path" : {
- "type" : "keyword"
- },
- "host" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "type" : {
- "type" : "keyword"
- },
- "status" : {
- "type" : "keyword"
- }
- }
- },
- "condition" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "compare" : {
- "type" : "object",
- "enabled" : false
- },
- "array_compare" : {
- "type" : "object",
- "enabled" : false
- },
- "type" : {
- "type" : "keyword"
- },
- "met" : {
- "type" : "boolean"
- },
- "script" : {
- "type" : "object",
- "enabled" : false
- },
- "status" : {
- "type" : "keyword"
- }
- }
- },
- "transform" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "search" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "request" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "indices" : {
- "type" : "keyword"
- },
- "types" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "type" : {
- "type" : "keyword"
- }
- }
- },
- "execution_duration" : {
- "type" : "long"
- },
- "actions" : {
- "include_in_parent" : true,
- "dynamic" : true,
- "type" : "nested",
- "properties" : {
- "reason" : {
- "type" : "keyword"
- },
- "foreach" : {
- "type" : "object",
- "enabled" : false
- },
- "webhook" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "request" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "path" : {
- "type" : "keyword"
- },
- "host" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "number_of_actions_executed" : {
- "type" : "integer"
- },
- "slack" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "sent_messages" : {
- "include_in_parent" : true,
- "dynamic" : true,
- "type" : "nested",
- "properties" : {
- "reason" : {
- "type" : "text"
- },
- "request" : {
- "type" : "object",
- "enabled" : false
- },
- "response" : {
- "type" : "object",
- "enabled" : false
- },
- "to" : {
- "type" : "keyword"
- },
- "message" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "attachments" : {
- "include_in_parent" : true,
- "dynamic" : true,
- "type" : "nested",
- "properties" : {
- "color" : {
- "type" : "keyword"
- },
- "fields" : {
- "properties" : {
- "value" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "icon" : {
- "type" : "keyword"
- },
- "from" : {
- "type" : "text"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "status" : {
- "type" : "keyword"
- }
- }
- },
- "account" : {
- "type" : "keyword"
- }
- }
- },
- "index" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "response" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "index" : {
- "type" : "keyword"
- },
- "id" : {
- "type" : "keyword"
- },
- "type" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "pagerduty" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "sent_event" : {
- "include_in_parent" : true,
- "dynamic" : true,
- "type" : "nested",
- "properties" : {
- "reason" : {
- "type" : "text"
- },
- "request" : {
- "type" : "object",
- "enabled" : false
- },
- "response" : {
- "type" : "object",
- "enabled" : false
- },
- "event" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "client_url" : {
- "type" : "keyword"
- },
- "context" : {
- "include_in_parent" : true,
- "dynamic" : true,
- "type" : "nested",
- "properties" : {
- "src" : {
- "type" : "keyword"
- },
- "alt" : {
- "type" : "text"
- },
- "href" : {
- "type" : "keyword"
- },
- "type" : {
- "type" : "keyword"
- }
- }
- },
- "client" : {
- "type" : "text"
- },
- "description" : {
- "type" : "text"
- },
- "attach_payload" : {
- "type" : "boolean"
- },
- "incident_key" : {
- "type" : "keyword"
- },
- "type" : {
- "type" : "keyword"
- },
- "account" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "account" : {
- "type" : "keyword"
- }
- }
- },
- "id" : {
- "type" : "keyword"
- },
- "type" : {
- "type" : "keyword"
- },
- "email" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "message" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "cc" : {
- "type" : "keyword"
- },
- "bcc" : {
- "type" : "keyword"
- },
- "reply_to" : {
- "type" : "keyword"
- },
- "from" : {
- "type" : "keyword"
- },
- "id" : {
- "type" : "keyword"
- },
- "to" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "status" : {
- "type" : "keyword"
- },
- "jira" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "result" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "self" : {
- "type" : "keyword"
- },
- "id" : {
- "type" : "keyword"
- },
- "key" : {
- "type" : "keyword"
- }
- }
- },
- "reason" : {
- "type" : "text"
- },
- "request" : {
- "type" : "object",
- "enabled" : false
- },
- "response" : {
- "type" : "object",
- "enabled" : false
- },
- "fields" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "summary" : {
- "type" : "text"
- },
- "issuetype" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "name" : {
- "type" : "keyword"
- },
- "id" : {
- "type" : "keyword"
- }
- }
- },
- "description" : {
- "type" : "text"
- },
- "project" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "id" : {
- "type" : "keyword"
- },
- "key" : {
- "type" : "keyword"
- }
- }
- },
- "labels" : {
- "type" : "text"
- }
- }
- },
- "account" : {
- "type" : "keyword"
- }
- }
- }
- }
- },
- "execution_time" : {
- "type" : "date"
- }
- }
- },
- "node" : {
- "type" : "keyword"
- },
- "input" : {
- "type" : "object",
- "enabled" : false
- },
- "condition" : {
- "type" : "object",
- "enabled" : false
- },
- "watch_id" : {
- "type" : "keyword"
- },
- "messages" : {
- "type" : "text"
- },
- "vars" : {
- "type" : "object",
- "enabled" : false
- },
- "state" : {
- "type" : "keyword"
- },
- "user" : {
- "type" : "text"
- },
- "status" : {
- "dynamic" : true,
- "type" : "object",
- "enabled" : false
- }
- }
- }
- },
- "composed_of" : [ ],
- "priority" : 2147483647,
- "version" : 12,
- "_meta" : {
- "managed" : true,
- "description" : "index template for watcher history indices"
- }
- }
- },
- {
- "name" : "ilm-history",
- "index_template" : {
- "index_patterns" : [
- "ilm-history-3*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "format" : "1",
- "lifecycle" : {
- "name" : "ilm-history-ilm-policy",
- "rollover_alias" : "ilm-history-3"
- },
- "hidden" : "true",
- "number_of_shards" : "1",
- "auto_expand_replicas" : "0-1",
- "number_of_replicas" : "0"
- }
- },
- "mappings" : {
- "dynamic" : false,
- "properties" : {
- "index_age" : {
- "type" : "long"
- },
- "@timestamp" : {
- "format" : "epoch_millis",
- "type" : "date"
- },
- "error_details" : {
- "type" : "text"
- },
- "success" : {
- "type" : "boolean"
- },
- "index" : {
- "type" : "keyword"
- },
- "state" : {
- "dynamic" : true,
- "type" : "object",
- "properties" : {
- "phase" : {
- "type" : "keyword"
- },
- "failed_step" : {
- "type" : "keyword"
- },
- "phase_definition" : {
- "type" : "text"
- },
- "action_time" : {
- "format" : "epoch_millis",
- "type" : "date"
- },
- "phase_time" : {
- "format" : "epoch_millis",
- "type" : "date"
- },
- "step_info" : {
- "type" : "text"
- },
- "action" : {
- "type" : "keyword"
- },
- "step" : {
- "type" : "keyword"
- },
- "is_auto-retryable_error" : {
- "type" : "keyword"
- },
- "creation_date" : {
- "format" : "epoch_millis",
- "type" : "date"
- },
- "step_time" : {
- "format" : "epoch_millis",
- "type" : "date"
- }
- }
- },
- "policy" : {
- "type" : "keyword"
- }
- }
- }
- },
- "composed_of" : [ ],
- "priority" : 2147483647,
- "version" : 3,
- "_meta" : {
- "managed" : true,
- "description" : "index template for ILM history indices"
- }
- }
- },
- {
- "name" : "logs-endpoint.events.library",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.events.library-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.events.library-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- },
- "thread" : {
- "properties" : {
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "dll" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "@timestamp" : {
- "type" : "date"
- },
- "file" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.events.library-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.network",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.network-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "process" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "network" : {
- "properties" : {
- "in" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "dropped" : {
- "type" : "long"
- },
- "packets" : {
- "type" : "long"
- },
- "errors" : {
- "type" : "long"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "out" : {
- "properties" : {
- "bytes" : {
- "type" : "long"
- },
- "dropped" : {
- "type" : "long"
- },
- "packets" : {
- "type" : "long"
- },
- "errors" : {
- "type" : "long"
- }
- }
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "network" : {
- "properties" : {
- "in" : {
- "properties" : {
- "bytes" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "packets" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- },
- "out" : {
- "properties" : {
- "bytes" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "packets" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- }
- }
- }
- }
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "port" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "user" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "group" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics-system.filesystem",
- "index_template" : {
- "index_patterns" : [
- "metrics-system.filesystem-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "metrics"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "filesystem" : {
- "properties" : {
- "device_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "total" : {
- "type" : "long"
- },
- "mount_point" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "free_files" : {
- "type" : "long"
- },
- "available" : {
- "type" : "long"
- },
- "files" : {
- "type" : "long"
- },
- "used" : {
- "properties" : {
- "pct" : {
- "scaling_factor" : 1000,
- "type" : "scaled_float"
- },
- "bytes" : {
- "type" : "long"
- }
- }
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "free" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-system.syslog",
- "index_template" : {
- "index_patterns" : [
- "logs-system.syslog-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-system.syslog-0.9.3",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "cloud" : {
- "properties" : {
- "availability_zone" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "image" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "instance" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "machine" : {
- "properties" : {
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "project" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "region" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "account" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "container" : {
- "properties" : {
- "image" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "labels" : {
- "type" : "object"
- }
- }
- },
- "process" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "system" : {
- "properties" : {
- "syslog" : {
- "properties" : { }
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "build" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "codename" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "containerized" : {
- "type" : "boolean"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [ ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "system"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "metrics",
- "index_template" : {
- "index_patterns" : [
- "metrics-*-*"
- ],
- "composed_of" : [
- "metrics-mappings",
- "metrics-settings"
- ],
- "priority" : 100,
- "version" : 0,
- "_meta" : {
- "managed" : true,
- "description" : "default metrics template installed by x-pack"
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-endpoint.alerts",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.alerts-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.alerts-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ephemeral_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "session" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "services" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "authentication_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "malware_classification" : {
- "properties" : {
- "features" : {
- "properties" : {
- "data" : {
- "properties" : {
- "decompressed_size" : {
- "type" : "long"
- },
- "buffer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "encoding" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "score" : {
- "type" : "double"
- },
- "upx_packed" : {
- "type" : "boolean"
- },
- "threshold" : {
- "type" : "double"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "token" : {
- "properties" : {
- "elevation" : {
- "type" : "boolean"
- },
- "integrity_level" : {
- "type" : "long"
- },
- "privileges" : {
- "type" : "nested",
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "enabled" : {
- "type" : "boolean"
- }
- }
- },
- "integrity_level_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "is_appcontainer" : {
- "type" : "boolean"
- },
- "impersonation_level" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "elevation_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "parent" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "real" : {
- "properties" : {
- "pid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "pgid" : {
- "type" : "long"
- },
- "start" : {
- "type" : "date"
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "thread" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "title" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- },
- "uptime" : {
- "type" : "long"
- },
- "args" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exit_code" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "args_count" : {
- "type" : "long"
- },
- "command_line" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "pgid" : {
- "type" : "long"
- },
- "start" : {
- "type" : "date"
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "thread" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "start_address_module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "service" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "start_address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "start" : {
- "type" : "date"
- },
- "call_stack" : {
- "properties" : {
- "symbol_info" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "rva" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "instruction_pointer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "memory_section" : {
- "properties" : {
- "address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "size" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "protection" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "module_path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- },
- "enabled" : false
- },
- "token" : {
- "properties" : {
- "elevation" : {
- "type" : "boolean"
- },
- "integrity_level" : {
- "type" : "long"
- },
- "privileges" : {
- "type" : "nested",
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "enabled" : {
- "type" : "boolean"
- }
- }
- },
- "integrity_level_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "is_appcontainer" : {
- "type" : "boolean"
- },
- "impersonation_level" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "elevation_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "title" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- },
- "uptime" : {
- "type" : "long"
- },
- "args" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "exit_code" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "args_count" : {
- "type" : "long"
- },
- "command_line" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "dll" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "compile_time" : {
- "type" : "date"
- },
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "malware_classification" : {
- "properties" : {
- "features" : {
- "properties" : {
- "data" : {
- "properties" : {
- "decompressed_size" : {
- "type" : "long"
- },
- "buffer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "encoding" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "score" : {
- "type" : "double"
- },
- "upx_packed" : {
- "type" : "boolean"
- },
- "threshold" : {
- "type" : "double"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "mapped_address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mapped_size" : {
- "type" : "long"
- }
- }
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "rule" : {
- "properties" : {
- "reference" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "license" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "author" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ruleset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uuid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "Target" : {
- "properties" : {
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "session" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "services" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "authentication_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "malware_classification" : {
- "properties" : {
- "features" : {
- "properties" : {
- "data" : {
- "properties" : {
- "decompressed_size" : {
- "type" : "long"
- },
- "buffer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "encoding" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "score" : {
- "type" : "double"
- },
- "upx_packed" : {
- "type" : "boolean"
- },
- "threshold" : {
- "type" : "double"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "token" : {
- "properties" : {
- "elevation" : {
- "type" : "boolean"
- },
- "integrity_level" : {
- "type" : "long"
- },
- "privileges" : {
- "type" : "nested",
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "enabled" : {
- "type" : "boolean"
- }
- }
- },
- "integrity_level_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "is_appcontainer" : {
- "type" : "boolean"
- },
- "impersonation_level" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "elevation_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "parent" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "real" : {
- "properties" : {
- "pid" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "pgid" : {
- "type" : "long"
- },
- "start" : {
- "type" : "date"
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "thread" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "title" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- },
- "uptime" : {
- "type" : "long"
- },
- "args" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exit_code" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "args_count" : {
- "type" : "long"
- },
- "command_line" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "pgid" : {
- "type" : "long"
- },
- "start" : {
- "type" : "date"
- },
- "pid" : {
- "type" : "long"
- },
- "working_directory" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "thread" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "start_address_module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "service" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "start_address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "start" : {
- "type" : "date"
- },
- "call_stack" : {
- "properties" : {
- "symbol_info" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "rva" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "instruction_pointer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "memory_section" : {
- "properties" : {
- "address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "size" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "protection" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "module_path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- },
- "enabled" : false
- },
- "token" : {
- "properties" : {
- "elevation" : {
- "type" : "boolean"
- },
- "integrity_level" : {
- "type" : "long"
- },
- "privileges" : {
- "type" : "nested",
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "enabled" : {
- "type" : "boolean"
- }
- }
- },
- "integrity_level_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "is_appcontainer" : {
- "type" : "boolean"
- },
- "impersonation_level" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "elevation_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "title" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "ppid" : {
- "type" : "long"
- },
- "uptime" : {
- "type" : "long"
- },
- "args" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "exit_code" : {
- "type" : "long"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "args_count" : {
- "type" : "long"
- },
- "command_line" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "dll" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "compile_time" : {
- "type" : "date"
- },
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "malware_classification" : {
- "properties" : {
- "features" : {
- "properties" : {
- "data" : {
- "properties" : {
- "decompressed_size" : {
- "type" : "long"
- },
- "buffer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "encoding" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "score" : {
- "type" : "double"
- },
- "upx_packed" : {
- "type" : "boolean"
- },
- "threshold" : {
- "type" : "double"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "mapped_address" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mapped_size" : {
- "type" : "long"
- }
- }
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- }
- }
- },
- "@timestamp" : {
- "type" : "date"
- },
- "file" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "macro" : {
- "properties" : {
- "code_page" : {
- "type" : "long"
- },
- "stream" : {
- "type" : "nested",
- "properties" : {
- "raw_code_size" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "raw_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "project_file" : {
- "properties" : {
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "file_extension" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "collection" : {
- "properties" : {
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "errors" : {
- "type" : "nested",
- "properties" : {
- "error_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "count" : {
- "type" : "long"
- }
- }
- }
- }
- },
- "temp_file_path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original" : {
- "properties" : {
- "mode" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "owner" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "gid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "code_signature" : {
- "type" : "nested",
- "properties" : {
- "valid" : {
- "type" : "boolean"
- },
- "trusted" : {
- "type" : "boolean"
- },
- "subject_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "exists" : {
- "type" : "boolean"
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "quarantine_path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "entry_modified" : {
- "type" : "double"
- },
- "windows" : {
- "properties" : {
- "zone_identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "quarantine_result" : {
- "type" : "boolean"
- },
- "malware_classification" : {
- "properties" : {
- "features" : {
- "properties" : {
- "data" : {
- "properties" : {
- "decompressed_size" : {
- "type" : "long"
- },
- "buffer" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "encoding" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "score" : {
- "type" : "double"
- },
- "upx_packed" : {
- "type" : "boolean"
- },
- "threshold" : {
- "type" : "double"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "owner" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "extension" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "gid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "drive_letter" : {
- "ignore_above" : 1,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "accessed" : {
- "type" : "date"
- },
- "mtime" : {
- "type" : "date"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "directory" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "target_path" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "inode" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mode" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "uid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "size" : {
- "type" : "long"
- },
- "mime_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ctime" : {
- "type" : "date"
- },
- "attributes" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "device" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "group" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "Endpoint" : {
- "properties" : {
- "policy" : {
- "properties" : {
- "applied" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "artifacts" : {
- "properties" : {
- "global" : {
- "properties" : {
- "identifiers" : {
- "type" : "nested",
- "properties" : {
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "identifiers" : {
- "type" : "nested",
- "properties" : {
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- },
- "enabled" : false
- },
- "status" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "elastic" : {
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "host" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "threat" : {
- "properties" : {
- "framework" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "technique" : {
- "properties" : {
- "reference" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "tactic" : {
- "properties" : {
- "reference" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "event" : {
- "properties" : {
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.alerts-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- },
- {
- "name" : "logs-endpoint.events.file",
- "index_template" : {
- "index_patterns" : [
- "logs-endpoint.events.file-*"
- ],
- "template" : {
- "settings" : {
- "index" : {
- "lifecycle" : {
- "name" : "logs"
- },
- "codec" : "best_compression",
- "mapping" : {
- "total_fields" : {
- "limit" : "10000"
- }
- },
- "refresh_interval" : "5s",
- "number_of_shards" : "1",
- "query" : {
- "default_field" : [
- "message"
- ]
- },
- "default_pipeline" : "logs-endpoint.events.file-0.16.2",
- "number_of_routing_shards" : "30"
- }
- },
- "mappings" : {
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "dynamic_templates" : [
- {
- "strings_as_keyword" : {
- "mapping" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "match_mapping_type" : "string"
- }
- }
- ],
- "date_detection" : false,
- "properties" : {
- "agent" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "process" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "ancestry" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "pid" : {
- "type" : "long"
- },
- "args_count" : {
- "type" : "long"
- },
- "thread" : {
- "properties" : {
- "id" : {
- "type" : "long"
- }
- }
- },
- "entity_id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "executable" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "destination" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "source" : {
- "properties" : {
- "geo" : {
- "properties" : {
- "continent_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "region_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "city_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_iso_code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "country_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "location" : {
- "type" : "geo_point"
- },
- "region_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "message" : {
- "type" : "text"
- },
- "@timestamp" : {
- "type" : "date"
- },
- "file" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "original" : {
- "properties" : {
- "mode" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "owner" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "gid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "windows" : {
- "properties" : {
- "zone_identifier" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "owner" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "extension" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "gid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "drive_letter" : {
- "ignore_above" : 1,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "accessed" : {
- "type" : "date"
- },
- "mtime" : {
- "type" : "date"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "directory" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "target_path" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "inode" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mode" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "path" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "uid" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "size" : {
- "type" : "long"
- },
- "mime_type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "pe" : {
- "properties" : {
- "file_version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "product" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "imphash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "description" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "company" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "original_file_name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ctime" : {
- "type" : "date"
- },
- "attributes" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "device" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "properties" : {
- "sha1" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha256" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sha512" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "md5" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "group" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "ecs" : {
- "properties" : {
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "data_stream" : {
- "properties" : {
- "namespace" : {
- "type" : "constant_keyword"
- },
- "type" : {
- "type" : "constant_keyword"
- },
- "dataset" : {
- "type" : "constant_keyword"
- }
- }
- },
- "host" : {
- "properties" : {
- "hostname" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "os" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "variant" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "kernel" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- },
- "family" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "version" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "platform" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "full" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "caseless" : {
- "normalizer" : "lowercase",
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "text" : {
- "type" : "text"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "ip" : {
- "type" : "ip"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "mac" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "architecture" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "uptime" : {
- "type" : "long"
- }
- }
- },
- "event" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "correlation" : {
- "properties" : {
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "severity" : {
- "type" : "long"
- },
- "code" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "created" : {
- "type" : "date"
- },
- "kind" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "module" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "type" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "sequence" : {
- "type" : "long"
- },
- "ingested" : {
- "type" : "date"
- },
- "provider" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "action" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "category" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "dataset" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "outcome" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- },
- "user" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "full_name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword",
- "fields" : {
- "text" : {
- "type" : "text"
- }
- }
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "email" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "hash" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "group" : {
- "properties" : {
- "Ext" : {
- "properties" : {
- "real" : {
- "properties" : {
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "domain" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "name" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- },
- "id" : {
- "ignore_above" : 1024,
- "type" : "keyword"
- }
- }
- }
- }
- },
- "aliases" : { }
- },
- "composed_of" : [
- "logs-endpoint.events.file-mappings"
- ],
- "priority" : 200,
- "_meta" : {
- "package" : {
- "name" : "endpoint"
- },
- "managed_by" : "ingest-manager",
- "managed" : true
- },
- "data_stream" : { }
- }
- }
- ]
- }
Advertisement
Add Comment
Please, Sign In to add comment