|
38 | 38 | }, |
39 | 39 | "event": { |
40 | 40 | "duration": 76967000, |
41 | | - "ingested": "2021-12-14T14:59:07.719052684Z", |
42 | 41 | "original": "{\"ts\":1547188415.857497,\"uid\":\"CAcJw21BbVedgFnYH3\",\"id.orig_h\":\"192.168.86.167\",\"id.orig_p\":38339,\"id.resp_h\":\"192.168.86.1\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.076967,\"orig_bytes\":75,\"resp_bytes\":178,\"conn_state\":\"SF\",\"local_orig\":true,\"local_resp\":true,\"missed_bytes\":0,\"history\":\"Dd\",\"orig_pkts\":1,\"orig_ip_bytes\":103,\"resp_pkts\":1,\"resp_ip_bytes\":206,\"tunnel_parents\":[]}", |
43 | 42 | "created": "2020-04-28T11:07:58.223Z", |
44 | 43 | "kind": "event", |
|
120 | 119 | }, |
121 | 120 | "event": { |
122 | 121 | "duration": 76967000, |
123 | | - "ingested": "2021-12-14T14:59:07.719086167Z", |
124 | 122 | "original": "{\"ts\":1547188416.857497,\"uid\":\"CAcJw21BbVedgFnYH4\",\"id.orig_h\":\"192.168.86.167\",\"id.orig_p\":38340,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.076967,\"orig_bytes\":75,\"resp_bytes\":178,\"conn_state\":\"SF\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Dd\",\"orig_pkts\":1,\"orig_ip_bytes\":103,\"resp_pkts\":1,\"resp_ip_bytes\":206,\"tunnel_parents\":[]}", |
125 | 123 | "created": "2020-04-28T11:07:58.223Z", |
126 | 124 | "kind": "event", |
|
219 | 217 | }, |
220 | 218 | "event": { |
221 | 219 | "duration": 76967000, |
222 | | - "ingested": "2021-12-14T14:59:07.719086748Z", |
223 | 220 | "original": "{\"ts\":1547188417.857497,\"uid\":\"CAcJw21BbVedgFnYH5\",\"id.orig_h\":\"89.160.20.156\",\"id.orig_p\":38334,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.076967,\"orig_bytes\":75,\"resp_bytes\":178,\"conn_state\":\"SF\",\"local_orig\":false,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Dd\",\"orig_pkts\":1,\"orig_ip_bytes\":103,\"resp_pkts\":1,\"resp_ip_bytes\":206,\"tunnel_parents\":[]}", |
224 | 221 | "created": "2020-04-28T11:07:58.223Z", |
225 | 222 | "kind": "event", |
|
301 | 298 | "ip": "192.168.2.205" |
302 | 299 | }, |
303 | 300 | "event": { |
304 | | - "ingested": "2021-12-14T14:59:07.719087140Z", |
305 | 301 | "original": "{\"ts\":1551399000.57855,\"uid\":\"Cc6NJ3GRlfjE44I3h\",\"id.orig_h\":\"192.168.2.205\",\"id.orig_p\":3,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":3,\"proto\":\"icmp\",\"conn_state\":\"OTH\",\"local_orig\":false,\"local_resp\":false,\"missed_bytes\":0,\"orig_pkts\":1,\"orig_ip_bytes\":107,\"resp_pkts\":0,\"resp_ip_bytes\":0,\"tunnel_parents\":[]}", |
306 | | - "created": "2020-04-28T11:07:58.223Z", |
307 | | - "kind": "event", |
308 | 302 | "id": "Cc6NJ3GRlfjE44I3h", |
309 | 303 | "category": "network", |
310 | 304 | "type": [ |
311 | 305 | "connection", |
312 | 306 | "info" |
313 | | - ] |
| 307 | + ], |
| 308 | + "created": "2020-04-28T11:07:58.223Z", |
| 309 | + "kind": "event" |
314 | 310 | }, |
315 | 311 | "tags": [ |
316 | 312 | "preserve_original_event", |
|
380 | 376 | "ip": "10.156.0.2" |
381 | 377 | }, |
382 | 378 | "event": { |
383 | | - "ingested": "2021-12-14T14:59:07.719087516Z", |
384 | 379 | "original": "{\"ts\":1617062400.404645,\"uid\":\"CCicIg43lOtCQOxXnb\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":56190,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":443,\"proto\":\"tcp\",\"conn_state\":\"OTH\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"C\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":0,\"resp_ip_bytes\":0}", |
385 | | - "created": "2020-04-28T11:07:58.223Z", |
386 | | - "kind": "event", |
387 | 380 | "id": "CCicIg43lOtCQOxXnb", |
388 | 381 | "category": "network", |
389 | 382 | "type": [ |
390 | 383 | "connection", |
391 | 384 | "info" |
392 | | - ] |
| 385 | + ], |
| 386 | + "created": "2020-04-28T11:07:58.223Z", |
| 387 | + "kind": "event" |
393 | 388 | }, |
394 | 389 | "tags": [ |
395 | 390 | "preserve_original_event", |
|
460 | 455 | }, |
461 | 456 | "event": { |
462 | 457 | "duration": 103708982, |
463 | | - "ingested": "2021-12-14T14:59:07.719087917Z", |
464 | 458 | "original": "{\"ts\":1617062100.419397,\"uid\":\"C52mXBCPJ4pPGkhr1\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":60810,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":443,\"proto\":\"tcp\",\"duration\":0.10370898246765137,\"orig_bytes\":0,\"resp_bytes\":5854,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"^hCcdafA\",\"orig_pkts\":1,\"orig_ip_bytes\":52,\"resp_pkts\":4,\"resp_ip_bytes\":267}", |
465 | 459 | "created": "2020-04-28T11:07:58.223Z", |
466 | 460 | "kind": "event", |
|
540 | 534 | }, |
541 | 535 | "event": { |
542 | 536 | "duration": 104128838, |
543 | | - "ingested": "2021-12-14T14:59:07.719090564Z", |
544 | 537 | "original": "{\"ts\":1617062100.419603,\"uid\":\"CTzCky2CyLT5JJvHck\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":60804,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":443,\"proto\":\"tcp\",\"duration\":0.10412883758544922,\"orig_bytes\":0,\"resp_bytes\":5854,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"^hCcdafA\",\"orig_pkts\":1,\"orig_ip_bytes\":52,\"resp_pkts\":4,\"resp_ip_bytes\":267}", |
545 | 538 | "created": "2020-04-28T11:07:58.223Z", |
546 | 539 | "kind": "event", |
|
620 | 613 | }, |
621 | 614 | "event": { |
622 | 615 | "duration": 104333878, |
623 | | - "ingested": "2021-12-14T14:59:07.719090943Z", |
624 | 616 | "original": "{\"ts\":1617062100.419826,\"uid\":\"CIkS28PDxqQnN49m2\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":60802,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":443,\"proto\":\"tcp\",\"duration\":0.10433387756347656,\"orig_bytes\":0,\"resp_bytes\":5854,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"^hCcdafA\",\"orig_pkts\":1,\"orig_ip_bytes\":52,\"resp_pkts\":4,\"resp_ip_bytes\":267}", |
625 | 617 | "created": "2020-04-28T11:07:58.223Z", |
626 | 618 | "kind": "event", |
|
682 | 674 | }, |
683 | 675 | "event": { |
684 | 676 | "duration": 26802063, |
685 | | - "ingested": "2021-12-14T14:59:07.719091294Z", |
686 | 677 | "original": "{\"ts\":1617062390.563187,\"uid\":\"CezEGe4jeLNkayV976\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":38948,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.02680206298828125,\"orig_bytes\":0,\"resp_bytes\":241,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Cd\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":1,\"resp_ip_bytes\":269}", |
687 | 678 | "created": "2020-04-28T11:07:58.223Z", |
688 | 679 | "kind": "event", |
|
745 | 736 | }, |
746 | 737 | "event": { |
747 | 738 | "duration": 25056124, |
748 | | - "ingested": "2021-12-14T14:59:07.719091659Z", |
749 | 739 | "original": "{\"ts\":1617062390.563442,\"uid\":\"CKSr3w18mmW6t7bXC4\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":40080,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.025056123733520509,\"orig_bytes\":0,\"resp_bytes\":276,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Cd\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":1,\"resp_ip_bytes\":304}", |
750 | 740 | "created": "2020-04-28T11:07:58.223Z", |
751 | 741 | "kind": "event", |
|
808 | 798 | }, |
809 | 799 | "event": { |
810 | 800 | "duration": 3319979, |
811 | | - "ingested": "2021-12-14T14:59:07.719092014Z", |
812 | 801 | "original": "{\"ts\":1617062390.667048,\"uid\":\"CGUiHy4kLIF2ml95eg\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":41407,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.003319978713989258,\"orig_bytes\":0,\"resp_bytes\":133,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Cd\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":1,\"resp_ip_bytes\":161}", |
813 | 802 | "created": "2020-04-28T11:07:58.223Z", |
814 | 803 | "kind": "event", |
|
871 | 860 | }, |
872 | 861 | "event": { |
873 | 862 | "duration": 1111984, |
874 | | - "ingested": "2021-12-14T14:59:07.719092573Z", |
875 | 863 | "original": "{\"ts\":1617062390.698943,\"uid\":\"CAOZZi4Qrio7gUVgVc\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":50487,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.0011119842529296876,\"orig_bytes\":0,\"resp_bytes\":202,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Cd\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":1,\"resp_ip_bytes\":230}", |
876 | 864 | "created": "2020-04-28T11:07:58.223Z", |
877 | 865 | "kind": "event", |
|
934 | 922 | }, |
935 | 923 | "event": { |
936 | 924 | "duration": 908852, |
937 | | - "ingested": "2021-12-14T14:59:07.719092936Z", |
938 | 925 | "original": "{\"ts\":1617062390.699227,\"uid\":\"Chx5fs3xQ5ALB72i4e\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":49647,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.0009088516235351563,\"orig_bytes\":0,\"resp_bytes\":145,\"conn_state\":\"SHR\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Cd\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":1,\"resp_ip_bytes\":173}", |
939 | 926 | "created": "2020-04-28T11:07:58.223Z", |
940 | 927 | "kind": "event", |
|
996 | 983 | "ip": "10.156.0.2" |
997 | 984 | }, |
998 | 985 | "event": { |
999 | | - "ingested": "2021-12-14T14:59:07.719093278Z", |
1000 | 986 | "original": "{\"ts\":1617062400.703865,\"uid\":\"C3pPjh1YRYcVDiZD3\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":44944,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":80,\"proto\":\"tcp\",\"conn_state\":\"OTH\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"C\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":0,\"resp_ip_bytes\":0}", |
1001 | | - "created": "2020-04-28T11:07:58.223Z", |
1002 | | - "kind": "event", |
1003 | 987 | "id": "C3pPjh1YRYcVDiZD3", |
1004 | 988 | "category": "network", |
1005 | 989 | "type": [ |
1006 | 990 | "connection", |
1007 | 991 | "info" |
1008 | | - ] |
| 992 | + ], |
| 993 | + "created": "2020-04-28T11:07:58.223Z", |
| 994 | + "kind": "event" |
1009 | 995 | }, |
1010 | 996 | "tags": [ |
1011 | 997 | "preserve_original_event", |
|
1057 | 1043 | "ip": "10.156.0.2" |
1058 | 1044 | }, |
1059 | 1045 | "event": { |
1060 | | - "ingested": "2021-12-14T14:59:07.719093624Z", |
1061 | 1046 | "original": "{\"ts\":1617062400.703851,\"uid\":\"ChUxTmYLG37oO5qUb\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":44942,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":80,\"proto\":\"tcp\",\"conn_state\":\"OTH\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"C\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":0,\"resp_ip_bytes\":0}", |
1062 | | - "created": "2020-04-28T11:07:58.223Z", |
1063 | | - "kind": "event", |
1064 | 1047 | "id": "ChUxTmYLG37oO5qUb", |
1065 | 1048 | "category": "network", |
1066 | 1049 | "type": [ |
1067 | 1050 | "connection", |
1068 | 1051 | "info" |
1069 | | - ] |
| 1052 | + ], |
| 1053 | + "created": "2020-04-28T11:07:58.223Z", |
| 1054 | + "kind": "event" |
1070 | 1055 | }, |
1071 | 1056 | "tags": [ |
1072 | 1057 | "preserve_original_event", |
|
1118 | 1103 | "ip": "10.156.0.2" |
1119 | 1104 | }, |
1120 | 1105 | "event": { |
1121 | | - "ingested": "2021-12-14T14:59:07.719093964Z", |
1122 | 1106 | "original": "{\"ts\":1617062400.704467,\"uid\":\"CpeAOT3B11CTXJgzw2\",\"id.orig_h\":\"10.156.0.2\",\"id.orig_p\":44946,\"id.resp_h\":\"169.254.169.254\",\"id.resp_p\":80,\"proto\":\"tcp\",\"conn_state\":\"OTH\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"C\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":0,\"resp_ip_bytes\":0}", |
1123 | | - "created": "2020-04-28T11:07:58.223Z", |
1124 | | - "kind": "event", |
1125 | 1107 | "id": "CpeAOT3B11CTXJgzw2", |
1126 | 1108 | "category": "network", |
1127 | 1109 | "type": [ |
1128 | 1110 | "connection", |
1129 | 1111 | "info" |
1130 | | - ] |
| 1112 | + ], |
| 1113 | + "created": "2020-04-28T11:07:58.223Z", |
| 1114 | + "kind": "event" |
1131 | 1115 | }, |
1132 | 1116 | "tags": [ |
1133 | 1117 | "preserve_original_event", |
|
1236 | 1220 | }, |
1237 | 1221 | "event": { |
1238 | 1222 | "duration": 76967000, |
1239 | | - "ingested": "2021-12-14T14:59:07.719094441Z", |
1240 | 1223 | "original": "{\"ts\":1547188417.857497,\"uid\":\"CAcJw21BbVedgFnYH5\",\"id.orig_h\":\"89.160.20.156\",\"id.orig_p\":38334,\"id.resp_h\":\"89.160.20.156\",\"id.resp_p\":53,\"proto\":\"udp\",\"service\":\"dns\",\"duration\":0.076967,\"orig_bytes\":75,\"resp_bytes\":178,\"conn_state\":\"SF\",\"local_orig\":false,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"Dd\",\"orig_pkts\":1,\"orig_ip_bytes\":103,\"resp_pkts\":1,\"resp_ip_bytes\":206,\"tunnel_parents\":[]}", |
1241 | 1224 | "created": "2020-04-28T11:07:58.223Z", |
1242 | 1225 | "kind": "event", |
|
1286 | 1269 | "ip": "10.0.2.15" |
1287 | 1270 | }, |
1288 | 1271 | "event": { |
1289 | | - "ingested": "2021-12-14T14:59:07.719094822Z", |
1290 | 1272 | "original": "{\"ts\":\"2021-06-09T20:55:13.160328Z\",\"uid\":\"C2KP1V3alRLoxl4JB9\",\"id.orig_h\":\"10.0.2.15\",\"id.orig_p\":46408,\"id.resp_h\":\"172.16.9.68\",\"id.resp_p\":80,\"proto\":\"tcp\",\"conn_state\":\"OTH\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"C\",\"orig_pkts\":0,\"orig_ip_bytes\":0,\"resp_pkts\":0,\"resp_ip_bytes\":0}", |
1291 | | - "created": "2020-04-28T11:07:58.223Z", |
1292 | | - "kind": "event", |
1293 | 1273 | "id": "C2KP1V3alRLoxl4JB9", |
1294 | 1274 | "category": "network", |
1295 | 1275 | "type": [ |
1296 | 1276 | "connection", |
1297 | 1277 | "info" |
1298 | | - ] |
| 1278 | + ], |
| 1279 | + "created": "2020-04-28T11:07:58.223Z", |
| 1280 | + "kind": "event" |
1299 | 1281 | }, |
1300 | 1282 | "tags": [ |
1301 | 1283 | "preserve_original_event", |
|
0 commit comments