Guest User

FortiAnalyzer API JSON Import

a guest
Apr 27th, 2022
467
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
JSON 5.73 KB | None | 0 0
  1. {
  2.   "id": 1,
  3.   "jsonrpc": "1.0",
  4.   "method": "add",
  5.   "params": [
  6.     {
  7.       "data": {
  8.         "address-filter": null,
  9.         "creation-time": 1645793716,
  10.         "description": "COMPANY-Botnet-Communication-Detection-By-Threat",
  11.         "device": [
  12.           {
  13.             "id": 1,
  14.             "name": "All_Devices",
  15.             "type": 2,
  16.             "vdom": null
  17.           }
  18.         ],
  19.         "device-specify": 0,
  20.         "email-from": "[email protected]",
  21.         "email-html-format": 0,
  22.         "email-subject": "COMPANY-Botnet-Communication-Detection-By-Threat",
  23.         "email-svr": "smtp.office365.com",
  24.         "email-to": "[email protected]",
  25.         "enable": 1,
  26.         "enable-time": 0,
  27.         "fabric-connector": null,
  28.         "filter": [
  29.           {
  30.             "aggregate-expr": "",
  31.             "dev-type": 0,
  32.             "enable": 1,
  33.             "eventstatus": "open",
  34.             "eventtype": "",
  35.             "extrainfo": "Traffic to Botnet C&C ${virus}, Reference: ${ref}, Traffic path: PolicyID ${policyid}\\${dstintf}\\${dstip}:${dstport}",
  36.             "extrainfo-type": 1,
  37.             "filter-expr": "logid==0202009249",
  38.             "groupby1": "virus",
  39.             "groupby2": "endpoint",
  40.             "groupby3": "",
  41.             "id": 2,
  42.             "indicator": null,
  43.             "logtype": "virus",
  44.             "rule": null,
  45.             "rule-relation": 0,
  46.             "severity": 0,
  47.             "subject": "Traffic to Botnet C&C from $groupby2 detected",
  48.             "tag": "Botnet,IP,C&C",
  49.             "thres-count": 1,
  50.             "thres-duration": 1440,
  51.             "utmevent": ""
  52.           },
  53.           {
  54.             "aggregate-expr": "",
  55.             "dev-type": 0,
  56.             "enable": 1,
  57.             "eventstatus": "open",
  58.             "eventtype": "",
  59.             "extrainfo": "Traffic to Botnet C&C ${attack}, Reference: ${ref}, Traffic path: PolicyID ${policyid}\\${dstintf}\\${dstip}:${dstport}",
  60.             "extrainfo-type": 1,
  61.             "filter-expr": "attack ~ Botnet and direction=incoming and (action=='detected' or action=='pass session')",
  62.             "groupby1": "attack",
  63.             "groupby2": "endpoint",
  64.             "groupby3": "",
  65.             "id": 4,
  66.             "indicator": null,
  67.             "logtype": "ips",
  68.             "rule": null,
  69.             "rule-relation": 0,
  70.             "severity": 0,
  71.             "subject": "Traffic to Botnet C&C from $groupby2 detected",
  72.             "tag": "Botnet,Signature,C&C",
  73.             "thres-count": 1,
  74.             "thres-duration": 1440,
  75.             "utmevent": ""
  76.           },
  77.           {
  78.             "aggregate-expr": "",
  79.             "dev-type": 0,
  80.             "enable": 1,
  81.             "eventstatus": "open",
  82.             "eventtype": "",
  83.             "extrainfo": "Traffic from Botnet C&C ${attack}, Reference: ${ref}, Traffic path: PolicyID ${policyid}\\${srcintf}\\${srcip}:${srcport}",
  84.             "extrainfo-type": 1,
  85.             "filter-expr": "attack ~ Botnet and direction=outgoing and (action=='detected' or action=='pass session')",
  86.             "groupby1": "attack",
  87.             "groupby2": "dstendpoint",
  88.             "groupby3": "",
  89.             "id": 6,
  90.             "indicator": null,
  91.             "logtype": "ips",
  92.             "rule": null,
  93.             "rule-relation": 0,
  94.             "severity": 0,
  95.             "subject": "Traffic from Botnet C&C to $groupby2 detected",
  96.             "tag": "Botnet,Signature,C&C",
  97.             "thres-count": 1,
  98.             "thres-duration": 1440,
  99.             "utmevent": ""
  100.           },
  101.           {
  102.             "aggregate-expr": "",
  103.             "dev-type": 0,
  104.             "enable": 1,
  105.             "eventstatus": "open",
  106.             "eventtype": "",
  107.             "extrainfo": "Traffic to C&C:${dstip}, Reference: ${ref}, Traffic path: PolicyID:${policyid}\\${dstintf}",
  108.             "extrainfo-type": 1,
  109.             "filter-expr": "logid==0422016400",
  110.             "groupby1": "attack",
  111.             "groupby2": "endpoint",
  112.             "groupby3": "",
  113.             "id": 8,
  114.             "indicator": null,
  115.             "logtype": "ips",
  116.             "rule": null,
  117.             "rule-relation": 1,
  118.             "severity": 1,
  119.             "subject": "Traffic to Botnet $groupby1 from $groupby2 blocked",
  120.             "tag": "Botnet,IP,C&C",
  121.             "thres-count": 1,
  122.             "thres-duration": 1440,
  123.             "utmevent": ""
  124.           },
  125.           {
  126.             "aggregate-expr": "",
  127.             "dev-type": 0,
  128.             "enable": 1,
  129.             "eventstatus": "open",
  130.             "eventtype": "",
  131.             "extrainfo": "Traffic to C&C:${dstip}, Reference: ${ref}, Traffic path: PolicyID:${policyid}\\${dstintf}",
  132.             "extrainfo-type": 1,
  133.             "filter-expr": "logid==0422016401",
  134.             "groupby1": "attack",
  135.             "groupby2": "endpoint",
  136.             "groupby3": "",
  137.             "id": 9,
  138.             "indicator": null,
  139.             "logtype": "ips",
  140.             "rule": null,
  141.             "rule-relation": 0,
  142.             "severity": 0,
  143.             "subject": "Traffic to Botnet $groupby1 from $groupby2 detected",
  144.             "tag": "Botnet,IP,C&C",
  145.             "thres-count": 1,
  146.             "thres-duration": 1440,
  147.             "utmevent": ""
  148.           }
  149.         ],
  150.         "filter-relation": 1,
  151.         "handlertype": 0,
  152.         "id": 10,
  153.         "name": "COMPANY-Botnet-Communication-Detection-By-Threat",
  154.         "pre-filter": null,
  155.         "pre-filter-option": 0,
  156.         "protected": 0,
  157.         "target-enable": 1,
  158.         "template-url": "",
  159.         "update-time": 1645793768,
  160.         "uuid": "",
  161.         "version": 2
  162.       },
  163.       "url": "config/adom/root/log-alert/trigger"
  164.     }
  165.   ],
  166.   "session": "",
  167.   "verbose": 1
  168. }
Advertisement
Add Comment
Please, Sign In to add comment