Not a member of Pastebin yet?
                        Sign Up,
                        it unlocks many cool features!                    
                - {
 - "filebeat-2017.06.30" : {
 - "mappings" : {
 - "generic_log" : {
 - "_meta" : {
 - "version" : "5.4.2"
 - },
 - "_all" : {
 - "norms" : false
 - },
 - "dynamic_templates" : [
 - {
 - "strings_as_keyword" : {
 - "match_mapping_type" : "string",
 - "mapping" : {
 - "ignore_above" : 1024,
 - "type" : "keyword"
 - }
 - }
 - }
 - ],
 - "date_detection" : false,
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "@version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "apache2" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "client" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auditd" : {
 - "properties" : {
 - "log" : {
 - "properties" : {
 - "a0" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "acct" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "item" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "items" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ppid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "record_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "res" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "sequence" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "beat" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "fileset" : {
 - "properties" : {
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "input_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "meta" : {
 - "properties" : {
 - "cloud" : {
 - "properties" : {
 - "availability_zone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "instance_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "machine_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "project_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "provider" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "mysql" : {
 - "properties" : {
 - "error" : {
 - "properties" : {
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "thread_id" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "slowlog" : {
 - "properties" : {
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "id" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "lock_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "query" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "query_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "rows_examined" : {
 - "type" : "long"
 - },
 - "rows_sent" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "long"
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "nginx" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "connection_id" : {
 - "type" : "long"
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "offset" : {
 - "type" : "long"
 - },
 - "read_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "source" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "system" : {
 - "properties" : {
 - "auth" : {
 - "properties" : {
 - "groupadd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ssh" : {
 - "properties" : {
 - "dropped_ip" : {
 - "type" : "ip"
 - },
 - "event" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "ip" : {
 - "type" : "ip"
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "port" : {
 - "type" : "long"
 - },
 - "signature" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "sudo" : {
 - "properties" : {
 - "command" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pwd" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "tty" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "useradd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "home" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "shell" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "uid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "syslog" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "tags" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "nginx.access" : {
 - "_meta" : {
 - "version" : "5.4.2"
 - },
 - "_all" : {
 - "norms" : false
 - },
 - "dynamic_templates" : [
 - {
 - "strings_as_keyword" : {
 - "match_mapping_type" : "string",
 - "mapping" : {
 - "ignore_above" : 1024,
 - "type" : "keyword"
 - }
 - }
 - }
 - ],
 - "date_detection" : false,
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "@version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "agent" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "apache2" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "client" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auditd" : {
 - "properties" : {
 - "log" : {
 - "properties" : {
 - "a0" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "acct" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "item" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "items" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ppid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "record_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "res" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "sequence" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auth" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "beat" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "bytes" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "clientip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "fileset" : {
 - "properties" : {
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_code2" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_code3" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "dma_code" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "latitude" : {
 - "type" : "float"
 - },
 - "location" : {
 - "properties" : {
 - "lat" : {
 - "type" : "float"
 - },
 - "lon" : {
 - "type" : "float"
 - }
 - }
 - },
 - "longitude" : {
 - "type" : "float"
 - },
 - "postal_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timezone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "httpversion" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ident" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "input_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "meta" : {
 - "properties" : {
 - "cloud" : {
 - "properties" : {
 - "availability_zone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "instance_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "machine_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "project_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "provider" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "mysql" : {
 - "properties" : {
 - "error" : {
 - "properties" : {
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "thread_id" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "slowlog" : {
 - "properties" : {
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "id" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "lock_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "query" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "query_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "rows_examined" : {
 - "type" : "long"
 - },
 - "rows_sent" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "long"
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "nginx" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "connection_id" : {
 - "type" : "long"
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "offset" : {
 - "type" : "long"
 - },
 - "rawrequest" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "read_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "request" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "source" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "system" : {
 - "properties" : {
 - "auth" : {
 - "properties" : {
 - "groupadd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ssh" : {
 - "properties" : {
 - "dropped_ip" : {
 - "type" : "ip"
 - },
 - "event" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "ip" : {
 - "type" : "ip"
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "port" : {
 - "type" : "long"
 - },
 - "signature" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "sudo" : {
 - "properties" : {
 - "command" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pwd" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "tty" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "useradd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "home" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "shell" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "uid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "syslog" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "tags" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "verb" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "nginx.error" : {
 - "_meta" : {
 - "version" : "5.4.2"
 - },
 - "_all" : {
 - "norms" : false
 - },
 - "dynamic_templates" : [
 - {
 - "strings_as_keyword" : {
 - "match_mapping_type" : "string",
 - "mapping" : {
 - "ignore_above" : 1024,
 - "type" : "keyword"
 - }
 - }
 - }
 - ],
 - "date_detection" : false,
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "@version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "apache2" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "client" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auditd" : {
 - "properties" : {
 - "log" : {
 - "properties" : {
 - "a0" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "acct" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "item" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "items" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ppid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "record_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "res" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "sequence" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "beat" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "fileset" : {
 - "properties" : {
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "input_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "meta" : {
 - "properties" : {
 - "cloud" : {
 - "properties" : {
 - "availability_zone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "instance_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "machine_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "project_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "provider" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "mysql" : {
 - "properties" : {
 - "error" : {
 - "properties" : {
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "thread_id" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "slowlog" : {
 - "properties" : {
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "id" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "lock_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "query" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "query_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "rows_examined" : {
 - "type" : "long"
 - },
 - "rows_sent" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "long"
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "nginx" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "connection_id" : {
 - "type" : "long"
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "offset" : {
 - "type" : "long"
 - },
 - "read_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "source" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "system" : {
 - "properties" : {
 - "auth" : {
 - "properties" : {
 - "groupadd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ssh" : {
 - "properties" : {
 - "dropped_ip" : {
 - "type" : "ip"
 - },
 - "event" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "ip" : {
 - "type" : "ip"
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "port" : {
 - "type" : "long"
 - },
 - "signature" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "sudo" : {
 - "properties" : {
 - "command" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pwd" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "tty" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "useradd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "home" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "shell" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "uid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "syslog" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "tags" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "_default_" : {
 - "_meta" : {
 - "version" : "5.4.2"
 - },
 - "_all" : {
 - "norms" : false
 - },
 - "dynamic_templates" : [
 - {
 - "strings_as_keyword" : {
 - "match_mapping_type" : "string",
 - "mapping" : {
 - "ignore_above" : 1024,
 - "type" : "keyword"
 - }
 - }
 - }
 - ],
 - "date_detection" : false,
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "apache2" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "client" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auditd" : {
 - "properties" : {
 - "log" : {
 - "properties" : {
 - "a0" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "acct" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "item" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "items" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ppid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "record_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "res" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "sequence" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "beat" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "fileset" : {
 - "properties" : {
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "input_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "meta" : {
 - "properties" : {
 - "cloud" : {
 - "properties" : {
 - "availability_zone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "instance_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "machine_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "project_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "provider" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "mysql" : {
 - "properties" : {
 - "error" : {
 - "properties" : {
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "thread_id" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "slowlog" : {
 - "properties" : {
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "id" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "lock_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "query" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "query_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "rows_examined" : {
 - "type" : "long"
 - },
 - "rows_sent" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "long"
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "nginx" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "connection_id" : {
 - "type" : "long"
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "offset" : {
 - "type" : "long"
 - },
 - "read_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "source" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "system" : {
 - "properties" : {
 - "auth" : {
 - "properties" : {
 - "groupadd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ssh" : {
 - "properties" : {
 - "dropped_ip" : {
 - "type" : "ip"
 - },
 - "event" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "ip" : {
 - "type" : "ip"
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "port" : {
 - "type" : "long"
 - },
 - "signature" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "sudo" : {
 - "properties" : {
 - "command" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pwd" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "tty" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "useradd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "home" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "shell" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "uid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "syslog" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "tags" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "nginx" : {
 - "_meta" : {
 - "version" : "5.4.2"
 - },
 - "_all" : {
 - "norms" : false
 - },
 - "dynamic_templates" : [
 - {
 - "strings_as_keyword" : {
 - "match_mapping_type" : "string",
 - "mapping" : {
 - "ignore_above" : 1024,
 - "type" : "keyword"
 - }
 - }
 - }
 - ],
 - "date_detection" : false,
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "@version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "agent" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "apache2" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "client" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auditd" : {
 - "properties" : {
 - "log" : {
 - "properties" : {
 - "a0" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "acct" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "item" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "items" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ppid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "record_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "res" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "sequence" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auth" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "beat" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "bytes" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "clientip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "fileset" : {
 - "properties" : {
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_code2" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_code3" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "dma_code" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "latitude" : {
 - "type" : "float"
 - },
 - "location" : {
 - "properties" : {
 - "lat" : {
 - "type" : "float"
 - },
 - "lon" : {
 - "type" : "float"
 - }
 - }
 - },
 - "longitude" : {
 - "type" : "float"
 - },
 - "postal_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timezone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "httpversion" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ident" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "input_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "meta" : {
 - "properties" : {
 - "cloud" : {
 - "properties" : {
 - "availability_zone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "instance_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "machine_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "project_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "provider" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "mysql" : {
 - "properties" : {
 - "error" : {
 - "properties" : {
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "thread_id" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "slowlog" : {
 - "properties" : {
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "id" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "lock_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "query" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "query_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "rows_examined" : {
 - "type" : "long"
 - },
 - "rows_sent" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "long"
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "nginx" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "connection_id" : {
 - "type" : "long"
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "offset" : {
 - "type" : "long"
 - },
 - "rawrequest" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "read_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "request" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "source" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "system" : {
 - "properties" : {
 - "auth" : {
 - "properties" : {
 - "groupadd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ssh" : {
 - "properties" : {
 - "dropped_ip" : {
 - "type" : "ip"
 - },
 - "event" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "ip" : {
 - "type" : "ip"
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "port" : {
 - "type" : "long"
 - },
 - "signature" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "sudo" : {
 - "properties" : {
 - "command" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pwd" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "tty" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "useradd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "home" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "shell" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "uid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "syslog" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "tags" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "verb" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "syslog" : {
 - "_meta" : {
 - "version" : "5.4.2"
 - },
 - "_all" : {
 - "norms" : false
 - },
 - "dynamic_templates" : [
 - {
 - "strings_as_keyword" : {
 - "match_mapping_type" : "string",
 - "mapping" : {
 - "ignore_above" : 1024,
 - "type" : "keyword"
 - }
 - }
 - }
 - ],
 - "date_detection" : false,
 - "properties" : {
 - "@timestamp" : {
 - "type" : "date"
 - },
 - "@version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "apache2" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "client" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "auditd" : {
 - "properties" : {
 - "log" : {
 - "properties" : {
 - "a0" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "acct" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "item" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "items" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "new_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_auid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "old_ses" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ppid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "record_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "res" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "sequence" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "beat" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "fileset" : {
 - "properties" : {
 - "module" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "input_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "meta" : {
 - "properties" : {
 - "cloud" : {
 - "properties" : {
 - "availability_zone" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "instance_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "machine_type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "project_id" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "provider" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "region" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "mysql" : {
 - "properties" : {
 - "error" : {
 - "properties" : {
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "thread_id" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "slowlog" : {
 - "properties" : {
 - "host" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "id" : {
 - "type" : "long"
 - },
 - "ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "lock_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "query" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "query_time" : {
 - "properties" : {
 - "sec" : {
 - "type" : "float"
 - }
 - }
 - },
 - "rows_examined" : {
 - "type" : "long"
 - },
 - "rows_sent" : {
 - "type" : "long"
 - },
 - "timestamp" : {
 - "type" : "long"
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "nginx" : {
 - "properties" : {
 - "access" : {
 - "properties" : {
 - "agent" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "body_sent" : {
 - "properties" : {
 - "bytes" : {
 - "type" : "long"
 - }
 - }
 - },
 - "geoip" : {
 - "properties" : {
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - }
 - }
 - },
 - "http_version" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "referrer" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "remote_ip" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "response_code" : {
 - "type" : "long"
 - },
 - "url" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user_agent" : {
 - "properties" : {
 - "device" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "major" : {
 - "type" : "long"
 - },
 - "minor" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "os_major" : {
 - "type" : "long"
 - },
 - "os_minor" : {
 - "type" : "long"
 - },
 - "os_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "patch" : {
 - "type" : "long"
 - }
 - }
 - },
 - "user_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "error" : {
 - "properties" : {
 - "connection_id" : {
 - "type" : "long"
 - },
 - "level" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "text",
 - "norms" : false
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "tid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "offset" : {
 - "type" : "long"
 - },
 - "read_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "received_at" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "received_from" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "source" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_facility" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_facility_code" : {
 - "type" : "long"
 - },
 - "syslog_hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_severity" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "syslog_severity_code" : {
 - "type" : "long"
 - },
 - "syslog_timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "system" : {
 - "properties" : {
 - "auth" : {
 - "properties" : {
 - "groupadd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "long"
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "ssh" : {
 - "properties" : {
 - "dropped_ip" : {
 - "type" : "ip"
 - },
 - "event" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "geoip" : {
 - "properties" : {
 - "city_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "continent_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "country_iso_code" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "location" : {
 - "type" : "geo_point"
 - },
 - "region_name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "ip" : {
 - "type" : "ip"
 - },
 - "method" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "port" : {
 - "type" : "long"
 - },
 - "signature" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "sudo" : {
 - "properties" : {
 - "command" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "error" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pwd" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "tty" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "user" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "useradd" : {
 - "properties" : {
 - "gid" : {
 - "type" : "long"
 - },
 - "home" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "name" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "shell" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "uid" : {
 - "type" : "long"
 - }
 - }
 - }
 - }
 - },
 - "syslog" : {
 - "properties" : {
 - "hostname" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "message" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "pid" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "program" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "timestamp" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - },
 - "tags" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - },
 - "type" : {
 - "type" : "keyword",
 - "ignore_above" : 1024
 - }
 - }
 - }
 - }
 - }
 - }
 
Advertisement
 
                    Add Comment                
                
                        Please, Sign In to add comment