Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit79b03b4

Browse files
committed
gis-9284 add strict mapping to Anomali
1 parent7ec3852 commit79b03b4

File tree

3 files changed

+54
-3
lines changed

3 files changed

+54
-3
lines changed

‎uncoder-core/app/translator/mappings/platforms/anomali/common.yml‎renamed to ‎uncoder-core/app/translator/mappings/platforms/anomali/proxy.yml‎

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,19 @@
11
platform:Anomali
2-
description:Common field mapping
2+
source:proxy
33

44
field_mapping:
55
c-uri-query:url
66
c-useragent:user_agent
7+
c-uri:url
8+
cs-method:http_method
9+
cs-bytes:bytes_out
10+
cs-referrer:http_referrer
11+
sc-status:return_code
12+
13+
dns-query:query
14+
dns-answer:answer
15+
dns-record:record_type
16+
717
CommandLine:command_line
818
DestinationHostname:dest
919
DestinationIp:dest_ip
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
platform:Anomali
2+
source:webserver
3+
4+
field_mapping:
5+
c-uri-query:url
6+
c-useragent:user_agent
7+
c-uri:url
8+
cs-method:http_method
9+
cs-bytes:bytes_out
10+
cs-referrer:http_referrer
11+
sc-status:return_code
12+
13+
dns-query:query
14+
dns-answer:answer
15+
dns-record:record_type
16+
17+
CommandLine:command_line
18+
DestinationHostname:dest
19+
DestinationIp:dest_ip
20+
DestinationPort:dest_port
21+
Details:reg_value_data
22+
dst_ip:dest_ip
23+
dst_port:dest_port
24+
EventID:event_id
25+
EventName:event_name
26+
FileName:file_name
27+
FilePath:file_path
28+
Image:image
29+
NewProcessName:image
30+
OriginalFileName:original_file_name
31+
ParentCommandLine:parent_command_line
32+
ParentImage:parent_image
33+
ParentProcessID:parent_process_id
34+
Platform:platform
35+
ProcessCommandLine:command_line
36+
ProcessID:process_id
37+
SourceImage:parent_image
38+
SourcePort:src_port
39+
TargetFilename:file_name
40+
TargetObject:reg_key
41+
UserAgent:user_agent

‎uncoder-core/app/translator/platforms/anomali/mapping.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
fromapp.translator.core.mappingimportBaseCommonPlatformMappings,LogSourceSignature
1+
fromapp.translator.core.mappingimportBaseStrictLogSourcesPlatformMappings,LogSourceSignature
22
fromapp.translator.platforms.anomali.constimportanomali_query_details
33

44

@@ -10,7 +10,7 @@ def __str__(self) -> str:
1010
return""
1111

1212

13-
classAnomaliMappings(BaseCommonPlatformMappings):
13+
classAnomaliMappings(BaseStrictLogSourcesPlatformMappings):
1414
defprepare_log_source_signature(self,mapping:dict)->AnomaliLogSourceSignature:# noqa: ARG002
1515
returnAnomaliLogSourceSignature()
1616

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp