mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
516 lines
15 KiB
JSON
516 lines
15 KiB
JSON
{
|
|
"modelName": "Network_Sessions",
|
|
"displayName": "Network Sessions",
|
|
"description": "Network Sessions Data Model",
|
|
"editable": false,
|
|
"objects": [
|
|
{
|
|
"comment": {
|
|
"tags": [
|
|
"network",
|
|
"session"
|
|
]
|
|
},
|
|
"objectName": "All_Sessions",
|
|
"displayName": "All Sessions",
|
|
"parentName": "BaseEvent",
|
|
"fields": [
|
|
{
|
|
"comment": {
|
|
"description": "The action taken by the reporting device."
|
|
},
|
|
"fieldName": "action",
|
|
"displayName": "action",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The business unit of the destination.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "dest_bunit",
|
|
"displayName": "dest_bunit",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The category of the destination.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "dest_category",
|
|
"displayName": "dest_category",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": true,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The priority of the destination.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "dest_priority",
|
|
"displayName": "dest_priority",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The amount of time for the completion of the network session event, in seconds."
|
|
},
|
|
"fieldName": "duration",
|
|
"displayName": "duration",
|
|
"type": "number",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The amount of time it took to receive a response in the network session event, in seconds."
|
|
},
|
|
"fieldName": "response_time",
|
|
"displayName": "response_time",
|
|
"type": "number",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "An indication of the type of network session event."
|
|
},
|
|
"fieldName": "signature",
|
|
"displayName": "signature",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The unique identifier or event code of the event signature."
|
|
},
|
|
"fieldName": "signature_id",
|
|
"displayName": "signature_id",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The business unit of the source.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "src_bunit",
|
|
"displayName": "src_bunit",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The category of the source.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "src_category",
|
|
"displayName": "src_category",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": true,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The external domain name of the client initializing a network session. Not applicable for DHCP events."
|
|
},
|
|
"fieldName": "src_dns",
|
|
"displayName": "src_dns",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The IP address of the client initializing a network session. Not applicable for DHCP events."
|
|
},
|
|
"fieldName": "src_ip",
|
|
"displayName": "src_ip",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The MAC address of the client initializing a network session. Not applicable for DHCP events."
|
|
},
|
|
"fieldName": "src_mac",
|
|
"displayName": "src_mac",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The NetBIOS name of the client initializing a network session. Not applicable for DHCP events."
|
|
},
|
|
"fieldName": "src_nt_host",
|
|
"displayName": "src_nt_host",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The priority of the source.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "src_priority",
|
|
"displayName": "src_priority",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "This automatically generated field is used to access tags from within data models. Add-on builders do not need to populate it.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "tag",
|
|
"displayName": "tag",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": true,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The business unit associated with the user.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "user_bunit",
|
|
"displayName": "user_bunit",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The category of the user.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "user_category",
|
|
"displayName": "user_category",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": true,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The priority of the user.",
|
|
"ta_relevant": false
|
|
},
|
|
"fieldName": "user_priority",
|
|
"displayName": "user_priority",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"calculations": [
|
|
{
|
|
"calculationID": "All_Sessions_fillnull_dest_ip",
|
|
"calculationType": "Eval",
|
|
"outputFields": [
|
|
{
|
|
"comment": {
|
|
"description": "The internal IP address allocated to the client initializing a network session. For DHCP and VPN events, this is the IP address leased to the client.",
|
|
"recommended": true
|
|
},
|
|
"fieldName": "dest_ip",
|
|
"displayName": "dest_ip",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"expression": "case(source LIKE \"stream%\" AND isnotnull(yiaddr) AND yiaddr!=\"\",yiaddr,isnull(dest_ip) OR dest_ip=\"\",\"unknown\",1=1,dest_ip)"
|
|
},
|
|
{
|
|
"calculationID": "All_Sessions_fillnull_dest_mac",
|
|
"calculationType": "Eval",
|
|
"outputFields": [
|
|
{
|
|
"comment": {
|
|
"description": "The internal MAC address of the network session client. For DHCP events, this is the MAC address of the client acquiring an IP address lease. For VPN events, this is the MAC address of the client initializing a network session.",
|
|
"recommended": true
|
|
},
|
|
"fieldName": "dest_mac",
|
|
"displayName": "dest_mac",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"expression": "case(source LIKE \"stream%\" AND isnotnull(chaddr) AND chaddr!=\"\",chaddr,isnull(dest_mac) OR dest_mac=\"\",\"unknown\",1=1,dest_mac)"
|
|
},
|
|
{
|
|
"calculationID": "All_Sessions_fillnull_dest_nt_host",
|
|
"calculationType": "Eval",
|
|
"outputFields": [
|
|
{
|
|
"comment": {
|
|
"description": "The NetBIOS name of the client initializing a network session.",
|
|
"recommended": true
|
|
},
|
|
"fieldName": "dest_nt_host",
|
|
"displayName": "dest_nt_host",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"expression": "if(isnull(dest_nt_host) OR dest_nt_host=\"\",\"unknown\",dest_nt_host)"
|
|
},
|
|
{
|
|
"calculationID": "All_Sessions_fillnull_dest_dns",
|
|
"calculationType": "Eval",
|
|
"outputFields": [
|
|
{
|
|
"comment": {
|
|
"description": "The domain name system address of the destination for a network session event.",
|
|
"recommended": true
|
|
},
|
|
"fieldName": "dest_dns",
|
|
"displayName": "dest_dns",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"expression": "if(isnull(dest_dns) OR dest_dns=\"\",\"unknown\",dest_dns)"
|
|
},
|
|
{
|
|
"calculationID": "All_Sessions_fillnull_user",
|
|
"calculationType": "Eval",
|
|
"outputFields": [
|
|
{
|
|
"comment": {
|
|
"description": "The user in a network session event, where applicable. For example, a VPN session or an authenticated DHCP event.",
|
|
"recommended": true
|
|
},
|
|
"fieldName": "user",
|
|
"displayName": "user",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"expression": "if(isnull(user) OR user=\"\",\"unknown\",user)"
|
|
},
|
|
{
|
|
"calculationID": "All_Sessions_vendor_product",
|
|
"calculationType": "Eval",
|
|
"outputFields": [
|
|
{
|
|
"comment": {
|
|
"description": "The full name of the Dynamic Host Configuration Protocol (DHCP) or DNS server involved in this event including vendor and product name, such as Microsoft DHCP or ISC BIND. This field is generated by combining the values of the vendor and product fields.",
|
|
"recommended": true
|
|
},
|
|
"fieldName": "vendor_product",
|
|
"displayName": "vendor_product",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"expression": "case(isnotnull(vendor_product),vendor_product,isnotnull(vendor) AND vendor!=\"unknown\" AND isnotnull(product) AND product!=\"unknown\",vendor.\" \".product,isnotnull(vendor) AND vendor!=\"unknown\" AND (isnull(product) OR product=\"unknown\"),vendor.\" unknown\",(isnull(vendor) OR vendor=\"unknown\") AND isnotnull(product) AND product!=\"unknown\",\"unknown \".product,isnotnull(sourcetype),sourcetype,1=1,\"unknown\")"
|
|
}
|
|
],
|
|
"constraints": [
|
|
{
|
|
"search": "(`cim_Network_Sessions_indexes`) tag=network tag=session"
|
|
}
|
|
],
|
|
"children": [
|
|
|
|
]
|
|
},
|
|
{
|
|
"comment": {
|
|
"tags": [
|
|
"network",
|
|
"session",
|
|
"start"
|
|
]
|
|
},
|
|
"objectName": "Session_Start",
|
|
"displayName": "Session Start",
|
|
"parentName": "All_Sessions",
|
|
"fields": [
|
|
|
|
],
|
|
"calculations": [
|
|
|
|
],
|
|
"constraints": [
|
|
{
|
|
"search": "tag=start"
|
|
}
|
|
],
|
|
"children": [
|
|
|
|
]
|
|
},
|
|
{
|
|
"comment": {
|
|
"tags": [
|
|
"network",
|
|
"session",
|
|
"end"
|
|
]
|
|
},
|
|
"objectName": "Session_End",
|
|
"displayName": "Session End",
|
|
"parentName": "All_Sessions",
|
|
"fields": [
|
|
|
|
],
|
|
"calculations": [
|
|
|
|
],
|
|
"constraints": [
|
|
{
|
|
"search": "tag=end"
|
|
}
|
|
],
|
|
"children": [
|
|
|
|
]
|
|
},
|
|
{
|
|
"comment": {
|
|
"tags": [
|
|
"network",
|
|
"session",
|
|
"dhcp"
|
|
]
|
|
},
|
|
"objectName": "DHCP",
|
|
"displayName": "DHCP",
|
|
"parentName": "All_Sessions",
|
|
"fields": [
|
|
{
|
|
"comment": {
|
|
"description": "The duration of the Dynamic Host Configuration Protocol (DHCP) lease, in seconds."
|
|
},
|
|
"fieldName": "lease_duration",
|
|
"displayName": "lease_duration",
|
|
"type": "number",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
},
|
|
{
|
|
"comment": {
|
|
"description": "The consecutive range of possible IP addresses that the Dynamic Host Configuration Protocol (DHCP) server can lease to clients on a subnet. A lease_scope typically defines a single physical subnet on your network to which DHCP services are offered."
|
|
},
|
|
"fieldName": "lease_scope",
|
|
"displayName": "lease_scope",
|
|
"type": "string",
|
|
"fieldSearch": "",
|
|
"required": false,
|
|
"multivalue": false,
|
|
"hidden": false
|
|
}
|
|
],
|
|
"calculations": [
|
|
|
|
],
|
|
"constraints": [
|
|
{
|
|
"search": "tag=dhcp"
|
|
}
|
|
],
|
|
"children": [
|
|
|
|
]
|
|
},
|
|
{
|
|
"comment": {
|
|
"tags": [
|
|
"network",
|
|
"session",
|
|
"vpn"
|
|
]
|
|
},
|
|
"objectName": "VPN",
|
|
"displayName": "VPN",
|
|
"parentName": "All_Sessions",
|
|
"fields": [
|
|
|
|
],
|
|
"calculations": [
|
|
|
|
],
|
|
"constraints": [
|
|
{
|
|
"search": "tag=vpn"
|
|
}
|
|
],
|
|
"children": [
|
|
|
|
]
|
|
}
|
|
]
|
|
} |