Files
splunk-security_content/data_sources/web/Splunk_Stream_HTTP.yml
T
2024-06-05 21:05:06 +00:00

41 lines
685 B
YAML

name: Splunk Stream HTTP
id: b0070a33-92ed-49e5-8f38-576cdf300710
author: Patrick Bareiss, Splunk
source: stream:http
sourcetype: stream:http
supported_TA:
name: Splunk App for Stream
version: 8.1.1
url: https://splunkbase.splunk.com/app/1809
event_names: []
fields:
- _time
- count
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- endtime
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- src_ip
- sum(bytes)
- sum(packets_in)
- sum(packets_out)
- timeendpos
- timestamp
- timestartpos
- values(flow_id){}
- vxlan_id
example_log: ""