Not a member of Pastebin yet?
                        Sign Up,
                        it unlocks many cool features!                    
                - {
 - "auditbeat-7.9.1" : {
 - "mappings" : {
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "agent" : {
 - "properties" : {
 - "ephemeral_id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "type" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "version" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "ecs" : {
 - "properties" : {
 - "version" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "event" : {
 - "properties" : {
 - "action" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "category" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "dataset" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "kind" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "module" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "type" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "host" : {
 - "properties" : {
 - "architecture" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "ip" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "mac" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "os" : {
 - "properties" : {
 - "build" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "family" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "kernel" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "platform" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "version" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - }
 - }
 - },
 - "message" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "process" : {
 - "properties" : {
 - "args" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "entity_id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "executable" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "hash" : {
 - "properties" : {
 - "sha1" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "ppid" : {
 - "type" : "long"
 - },
 - "start" : {
 - "type" : "date"
 - },
 - "working_directory" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "service" : {
 - "properties" : {
 - "type" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "system" : {
 - "properties" : {
 - "audit" : {
 - "properties" : {
 - "host" : {
 - "properties" : {
 - "architecture" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "boottime" : {
 - "type" : "date"
 - },
 - "hostname" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "ip" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "mac" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "os" : {
 - "properties" : {
 - "family" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "kernel" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "platform" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "version" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "timezone" : {
 - "properties" : {
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "offset" : {
 - "properties" : {
 - "sec" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "uptime" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - }
 - }
 - },
 - "user" : {
 - "properties" : {
 - "group" : {
 - "properties" : {
 - "id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - },
 - "id" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - },
 - "name" : {
 - "type" : "text",
 - "fields" : {
 - "keyword" : {
 - "type" : "keyword",
 - "ignore_above" : 256
 - }
 - }
 - }
 - }
 - }
 - }
 - }
 - }
 - }
 
Advertisement
 
                    Add Comment                
                
                        Please, Sign In to add comment