forked from logrhythm/kibana
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request elastic#360 from Shweta-Bhandare/addInternalFields
Added static fields.
- Loading branch information
Showing
5 changed files
with
108 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,50 @@ | ||
Internal, Internal, session, Session, string, "Session UUID." | ||
Internal, Internal, srcmac, SrcMAC, uint64, "Source MAC address." | ||
Internal, Internal, destmac, DestMAC, uint64, "Destination MAC address." | ||
Internal, Internal, srcip, SrcIP, uint32, "Source IP address." | ||
Internal, Internal, destip, DestIP, uint32, "Destination IP address." | ||
Internal, Internal, packetpath, PacketPath, string, "Packet path." | ||
Internal, Internal, flowsessioncount, FlowSessionCount, uint32, "Flow Session Count." | ||
Internal, Internal, srcport, SrcPort, uint32, "Source Port." | ||
Internal, Internal, destport, DestPort, uint32, "Destination Port." | ||
Internal, Internal, flowcompleted, FlowCompleted, bool, "Flow Completed flag." | ||
Internal, Internal, delay, Delay, string, "Delay." | ||
Internal, Internal, protocol, Protocol, uint32, "Protocol." | ||
Internal, Internal, totalpackets, TotalPackets, uint32, "Total packets in the session." | ||
Internal, Internal, timestart, TimeStart, uint64, "Start time of the flow." | ||
Internal, Internal, timeupdated, TimeUpdated, uint64, "Time updated." | ||
Internal, Internal, destbytes, DestBytes, uint64, "Destination bytes." | ||
Internal, Internal, srcbytes, SrcBytes, uint64, "Source bytes." | ||
Internal, Internal, flowtype, FlowType, FlowType, "Flow type." | ||
Internal, Internal, packetsdelta, PacketsDelta, uint64, "Packets delta between update." | ||
Internal, Internal, timedelta, TimeDelta, uint64, "Time delta between update." | ||
Internal, Internal, destbytesdelta, DestBytesDelta, uint64, "Destination byte delta between update." | ||
Internal, Internal, srcbytesdelta, SrcBytesDelta, uint64, "Source byte delta between update." | ||
Internal, Internal, customapplication, CustomApplication, bytes, "Custom Application." | ||
Internal, Internal, flowstate, FlowState, FlowState, "Flow State type." | ||
Internal, Internal, captured, Captured, bool, "Captured flag." | ||
Internal, Internal, childflownumber, ChildFlowNumber, uint32, "Child Flow number." | ||
Internal, Internal, totalbytes, TotalBytes, uint64, "Total bytes of the session." | ||
Internal, Internal, totalbytesdelta, TotalBytesDelta, uint64, "Total bytes delta between update." | ||
Internal, Internal, application, Application, string, "Application." | ||
Internal, Internal, applicationpath, ApplicationPath, string, "Application Path." | ||
Internal, Internal, duration, Duration, uint64, "Duration of the flow." | ||
Internal, Internal, messagesize, MessageSize, uint64, "Size of the DPI message." | ||
Internal, Internal, threadid, ThreadID, uint32, "Thread ID." | ||
Internal, Internal, fieldcount, FieldCount, uint64, "Total fields in DPI message." | ||
Internal, Internal, debugmessage, DebugMessage, string, "Debug message." | ||
Internal, Internal, applicationid, ApplicationID, uint32, "Application ID." | ||
Internal, Internal, latestupdate, LatestUpdate, bool, "Latest update flag." | ||
Internal, Internal, timeprevious, TimePrevious, uint64, "Time Previous." | ||
Internal, Internal, written, Written, bool, "Capture written flag." | ||
Internal, Internal, captureremoved, CaptureRemoved, bool, "Capture removed flag." | ||
Internal, Internal, srcip6, SrcIP6, uint32, "Source IP6 address." | ||
Internal, Internal, destip6, DestIP6, uint32, "Destination IP6 address." | ||
Internal, Internal, normalizedsyslogdata, NormalizedSyslogData, string, "Normalized Syslog data." | ||
Internal, Internal, timeend, TimeEnd, uint64, "Time End." | ||
Internal, Internal, headerwritten, HeaderWritten, bool, "Header written flag." | ||
Internal, Internal, connectionestablished, ConnectionEstablished, bool, "Connection Established flag." | ||
Internal, Internal, maxrepeatedfieldcount, MaxRepeatedFieldCount, uint32, "Maximum number of fields indexed by ElasticSearch." | ||
Internal, Internal, fieldcountindexed, FieldCountIndexed, uint32, "Field count indexed by ElasticSearch." | ||
Internal, Internal, emailAttachments, EmailAttachments, EmailAttach, "Email attachment structure." | ||
Internal, Internal, customfields, CustomFields, CustomField, "Custom Fields." |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters