Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Syslog data replication project #11480

Merged
merged 38 commits into from
Nov 28, 2024
Merged
Show file tree
Hide file tree
Changes from 32 commits
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
e630c5d
Adding utility CEFReplicator
anki-narravula Mar 24, 2022
a28805c
Latest version
anki-narravula Apr 20, 2022
ac75e0c
Rename readme.md to README.md
anki-narravula Apr 20, 2022
9c184e1
Update README.md
anki-narravula Apr 20, 2022
d45860e
Update README.md
anki-narravula Apr 20, 2022
e406750
Update README.md
anki-narravula Apr 20, 2022
01160b9
Update README.md
anki-narravula May 28, 2022
fecdc2e
Update README.md
anki-narravula May 28, 2022
bfe0705
Sample data upload
anki-narravula May 28, 2022
63326de
Merge branch 'SyslogDataReplication' of https://github.com/Azure/Azur…
anki-narravula May 28, 2022
f06428b
Test
anki-narravula May 28, 2022
5c7be8c
Code Change
anki-narravula May 28, 2022
8d248de
Add files via upload
anki-narravula May 28, 2022
6710fe2
Add files via upload
anki-narravula May 28, 2022
7366bf4
Delete Tools/Syslog-cef-data-replocator/syslog directory
anki-narravula May 28, 2022
165da46
Update README.md
anki-narravula May 28, 2022
6e3903e
Update README.md
anki-narravula May 28, 2022
1ca4abb
Update README.md
anki-narravula May 29, 2022
847e2a9
Change in Folder Name
anki-narravula May 29, 2022
541a19c
Update syslogfromraw.py
anki-narravula May 31, 2022
2be9087
Update README.md
anki-narravula May 31, 2022
ae51e0a
Update README.md
anki-narravula May 31, 2022
2202cb5
Update README.md
anki-narravula May 31, 2022
8d47982
Merge branch 'master' into SyslogDataReplication
anki-narravula Aug 12, 2022
971b3eb
Create syslog_cef_data_replicator.zip
anki-narravula Aug 12, 2022
413e5db
Update README.md
anki-narravula Aug 17, 2022
7680e3c
Update README.md
anki-narravula Aug 23, 2022
7ed0519
Update README.md
anki-narravula Aug 23, 2022
a07e95b
Update README.md
mkchiliveri Sep 14, 2022
b8c6dab
Merge branch 'master' into SyslogDataReplication
anki-narravula Jul 27, 2023
6146a5c
Merge branch 'master' into SyslogDataReplication
anki-narravula Jul 27, 2023
a1f443d
Merge branch 'master' into SyslogDataReplication
anki-narravula Sep 4, 2023
c5c81ef
Update README.md
anki-narravula Nov 26, 2024
f2be605
CodeQL issue fix
anki-narravula Nov 26, 2024
0741b41
CodeQL issue for FileOpen
anki-narravula Nov 26, 2024
f458bef
Update syslogfromcsv.py
anki-narravula Nov 26, 2024
8a1b5ea
Update syslogfromraw.py
anki-narravula Nov 26, 2024
6e666c9
Code cleanup
anki-narravula Nov 27, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
{
"fullSchema":{},
"customizations":{
"version":{"data_type":"Integer", "values": [0]},
"deviceVendor": {"data_type":"String", "values": ["CISCO","JUNIPER","Fortinet","MSFT"]},
"deviceProduct": {"data_type":"String", "values": ["Cortex","Vertex","Fortigate", "WSF"]},
"deviceVersion": {"data_type":"String", "values": ["2","19","34"]},
"signatureId": {"data_type":"String", "values": ["3.6.0.3","3.4.0.6","5.6.7.8","1.6.1.3","9.6.1.7","1.9.0.2","1.89.12.3","14.61.0.31","19.6.01.36"]},
"name": {"data_type":"String", "values": ["Phishing","TROJAN_GIPPERS.DC","services-health","Monitoring"]},
"severity": {"data_type":"Integer", "values": [1,2,3,4,5,6,7,8,9]},
"deviceExternalId": {"data_type":"String", "values": ["FGVMEV9XTHSMYCCF","FGVMEV9XPDFRYYCCF","FGVMEV9XPEPFOCFR"]},
"FTNTFGTlogid": {"data_type":"String", "values": ["0100026001","010004554","01566fjj56"]},
"cat": {"data_type":"String", "values": ["event","alert","traffic"]},
"direction": {"data_type":"String", "values": ["egress","ingress","in"]},
"FTNTFGTsubtype": {"data_type":"String", "values": ["system"]},
"origisationname": {"data_type":"String", "values": ["Fortigate","CISCO"]},
"origin": {"data_type":"String", "values": ["NA","NULL",""]},
"logid": {"data_type":"String", "values": ["562ed3w","dfdf564s","3455frs"]},
"dst_country": {"data_type":"String", "values": ["US","Canada","Bhutan"]},
"dst": {"data_type":"String", "values": ["67.21.32.78","201.32.13.56","76.62.201.10"]},
"src": {"data_type":"String", "values": ["101.21.21.1","67.23.21.90","82.78.9.87"]},
"ifname": {"data_type":"String", "values": ["eth0","eth1"]},
"product": {"data_type":"String", "values": ["FortiWeb","Prisma","Fortigate", "WAF"]},
"dpt": {"data_type":"Integer", "values": [1233, 3456, 6738]},
"spt": {"data_type":"Integer", "values": [7837,8929,7832,8729]},
"start1": {"data_type":"datetime", "values": ["current"], "format":"%Y-%m-%d %H:%M:%S"},
"end1": {"data_type":"datetime", "values": ["current"], "format":"%Y-%m-%d %H:%M:%S"},
"ISOTimeStamp": {"data_type":"datetime", "values": ["current"], "format":"%Y-%m-%d %H:%M:%S"}
},
"SyslogMessage":{
"headerTemplate": "DateTime HostName",
"syslog_message_template":{"values": "{hostName} {application} {pid} {messageId}: {structured_data} {message}"},
"syslog_header_fields": {"values": ["hostName", "application", "pid", "messageId"]},
"syslog_header_fields_dummy": {"values":"{\"priority\": \"139\", \"version\": \"1\",\"ISOTimeStamp\": \"2022-03-31 11:59:59\",\"hostName\": \"SYSLOG_Host\",\"application\": \"SYSLOG_App\", \"pid\": \"process\",\"messageId\": \"1234\"}"},
"KVDelimiter": {"values": "="},
"fieldDelimiter": {"values": " "},
"headerDelimiter": {"values": ":"}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
{
"fullSchema":{},
"customizations":{
"version":{"data_type":"Integer", "values": [0]},
"deviceVendor": {"data_type":"String", "values": ["CISCO","JUNIPER","Fortinet","MSFT"]},
"deviceProduct": {"data_type":"String", "values": ["Cortex","Vertex","Fortigate", "WSF"]},
"deviceVersion": {"data_type":"String", "values": ["2","19","34"]},
"signatureId": {"data_type":"String", "values": ["3.6.0.3","3.4.0.6","5.6.7.8","1.6.1.3","9.6.1.7","1.9.0.2","1.89.12.3","14.61.0.31","19.6.01.36"]},
"name": {"data_type":"String", "values": ["Phishing","TROJAN_GIPPERS.DC","services-health","Monitoring"]},
"severity": {"data_type":"Integer", "values": [1,2,3,4,5,6,7,8,9]},
"deviceExternalId": {"data_type":"String", "values": ["FGVMEV9XTHSMYCCF","FGVMEV9XPDFRYYCCF","FGVMEV9XPEPFOCFR"]},
"FTNTFGTlogid": {"data_type":"String", "values": ["0100026001","010004554","01566fjj56"]},
"cat": {"data_type":"String", "values": ["event","alert","traffic"]},
"direction": {"data_type":"String", "values": ["egress","ingress","in"]},
"FTNTFGTsubtype": {"data_type":"String", "values": ["system"]},
"origisationname": {"data_type":"String", "values": ["Fortigate","CISCO"]},
"origin": {"data_type":"String", "values": ["NA","NULL",""]},
"logid": {"data_type":"String", "values": ["562ed3w","dfdf564s","3455frs"]},
"dst_country": {"data_type":"String", "values": ["US","Canada","Bhutan"]},
"dst": {"data_type":"String", "values": ["67.21.32.78","201.32.13.56","76.62.201.10"]},
"src": {"data_type":"String", "values": ["101.21.21.1","67.23.21.90","82.78.9.87"]},
"ifname": {"data_type":"String", "values": ["eth0","eth1"]},
"product": {"data_type":"String", "values": ["FortiWeb","Prisma","Fortigate", "WAF"]},
"dpt": {"data_type":"Integer", "values": [1233, 3456, 6738]},
"spt": {"data_type":"Integer", "values": [7837,8929,7832,8729]},
"start1": {"data_type":"datetime", "values": ["current"], "format":"%Y-%m-%d %H:%M:%S"},
"end1": {"data_type":"datetime", "values": ["current"], "format":"%Y-%m-%d %H:%M:%S"},
"ISOTimeStamp": {"data_type":"datetime", "values": ["current"], "format":"%Y-%m-%d %H:%M:%S"}
},
"SyslogMessage":{
"headerTemplate": "DateTime HostName",
"syslog_message_template":{"values": "{hostName} {application} {pid} {messageId}: {structured_data} {message}"},
"syslog_header_fields": {"values": ["hostName", "application", "pid", "messageId"]},
"syslog_header_fields_dummy": {"values":"{\"priority\": \"139\", \"version\": \"1\",\"ISOTimeStamp\": \"2022-03-31 11:59:59\",\"hostName\": \"SYSLOG_Host\",\"application\": \"SYSLOG_App\", \"pid\": \"process\",\"messageId\": \"1234\"}"},
"KVDelimiter": {"values": "="},
"fieldDelimiter": {"values": " "},
"headerDelimiter": {"values": ":"}
}
}
Loading
Loading