Skip to content

Instantly share code, notes, and snippets.

@clay584
Created November 20, 2014 19:36
Show Gist options
  • Select an option

  • Save clay584/4e5e1896a2bda76e4158 to your computer and use it in GitHub Desktop.

Select an option

Save clay584/4e5e1896a2bda76e4158 to your computer and use it in GitHub Desktop.
logging into the future - corresponding elasticsearch document
{
"_index" : "logstash-2014.11.21",
"_type" : "syslog",
"_id" : "l9u2pNC4RjKlsweRhgalWA",
"_score" : 1.0,
"_source":{"@version":"1","@timestamp":"2014-11-21T00:00:57.000Z","type":"syslog","tags":["netsyslog","grok_ran"],"host":"orl-syslog","path":"/var/log/network.log","syslog_host":"10.0.0.34","device_host":"orl-asa-fp","device_module":"sf","pri_detection_engine":"6c462a00-43ae-11e4-954c-a4aa6fe94c69","sf_policy":"Presidio Lab - Internet Access Policy","connection_type":"End","user":"Unknown","client":"Chrome","app_protocol":"HTTP","webapp":"Unknown","acl_rule_name":"Malware Lookups | Monitor All","acl_rule_action":"Allow","acl_rule_reason":"Unknown","url_category":"Unknown","url_reputation":"Risk unknown","url":"http://sn-cc-nbox.presidiolab.local:3000/lua/get_flow_data.lua?flow_key=352531341&_=1416504188744","ingress_interface":"outside","egress_interface":"inside","ingress_sec_zone":"Outside","egress_sec_zone":"Inside","sec_intel_match_ip":"None","sec_intel_category":"None","client_version":"38.0.2125.111","num_file_events":0,"num_ips_events":0,"tcp_flags":"0x0","netbios_domain":"(null)","initiator_packets":5,"responder_packets":5,"initiator_bytes":778,"responder_bytes":451,"context":"unknown","protocol":"TCP","source_ip":"10.254.1.19","source_port":"50609","dest_ip":"10.4.4.15","dest_port":"3000"}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment