Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

standardize graylog schema field names #8061

Merged
merged 2 commits into from
May 7, 2020
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,12 @@
/**
* Field names used in the standard Graylog Schema.
*/



public class GraylogSchemaFields {

public static final String FIELD_USER_ID = "user_id";
public static final String FIELD_USER_TYPE = "user_type";
public static final String FIELD_ASSOCIATED_USER_REFERENCE = "associated_user_reference";
public static final String FIELD_USER_NAME = "user_name";
public static final String FIELD_HTTP_USER_AGENT = "http_user_agent";
Expand All @@ -33,20 +36,35 @@ public class GraylogSchemaFields {
public static final String FIELD_SOURCE_GEO_COUNTRY_NAME = "source_geo_country_name";
public static final String FIELD_SOURCE_GEO_COORDINATES = "source_geo_coordinates";
public static final String FIELD_SESSION_ID = "session_id";
public static final String FIELD_EVENT_VENDOR_DESCRIPTION = "event_vendor_description";
public static final String FIELD_EVENT_VENDOR_ACTION = "event_vendor_action";
public static final String FIELD_EVENT_ERROR_DESCRIPTION = "event_error_description";
public static final String FIELD_TIMESTAMP = "timestamp";
public static final String FIELD_SOURCE_AS_NUMBER = "source_as_number";
public static final String FIELD_SOURCE_AS_ORGANIZATION_NAME = "source_as_organization_name";
public static final String FIELD_SOURCE_AS_IP = "source_as_ip";
public static final String FIELD_SOURCE_AS_DOMAIN = "source_as_domain";
public static final String FIELD_EVENT_VENDOR_SEVERITY_DESCRIPTION = "event_vendor_severity_description";
public static final String FIELD_THREAT_DETECTED = "threat_detected";
public static final String FIELD_EVENT_UID = "event_uid";
public static final String FIELD_SERVICE_VERSION = "service_version";
public static final String FIELD_TARGET_USER_NAME = "target_user_name";
public static final String FIELD_TARGET_USER_ID = "target_user_id";
public static final String FIELD_ASSOCIATED_USER_NAME = "associated_user_name";
public static final String FIELD_ASSOCIATED_USER_ID = "associated_user_id";
public static final String FIELD_EVENT_UID = "event_uid";
public static final String FIELD_EVENT_SOURCE_PRODUCT = "event_source_product";

public static final String FIELD_APPLICATION_SSO_SIGNONMODE = "application_sso_signonmode";
public static final String FIELD_APPLICATION_SSO_TARGET_NAME = "application_sso_target_name";

public static final String FIELD_VENDOR_EVENT_ACTION = "vendor_event_action";
public static final String FIELD_VENDOR_EVENT_DESCRIPTION = "vendor_event_description";
public static final String FIELD_VENDOR_EVENT_SEVERITY = "vendor_event_severity";
public static final String FIELD_VENDOR_EVENT_OUTCOME = "vendor_event_outcome";
public static final String FIELD_VENDOR_EVENT_OUTCOME_REASON = "vendor_event_outcome_reason";
public static final String FIELD_VENDOR_SEVERITY_DESCRIPTION = "vendor_severity_description";
public static final String FIELD_VENDOR_THREAT_SUSPECTED = "vendor_threat_suspected";
public static final String FIELD_VENDOR_TRANSACTION_TYPE = "vendor_transaction_type";
public static final String FIELD_VENDOR_TRANSACTION_ID = "vendor_transaction_id";
public static final String FIELD_VENDOR_USER_TYPE = "vendor_user_type";



}