|
6 | 6 | "version": "1.12.0" |
7 | 7 | }, |
8 | 8 | "event": { |
9 | | - "ingested": "2021-12-09T13:41:22.171223700Z", |
10 | 9 | "original": "01,04/19/20,13:11:13,Stopped,,,", |
11 | 10 | "code": "01", |
12 | 11 | "kind": "event", |
|
31 | 30 | "version": "1.12.0" |
32 | 31 | }, |
33 | 32 | "event": { |
34 | | - "ingested": "2021-12-09T13:41:22.171228300Z", |
35 | 33 | "original": "00,04/19/20,12:43:06,Started,,,", |
36 | 34 | "code": "00", |
37 | 35 | "kind": "event", |
|
60 | 58 | "domain": "057182593757.test.com" |
61 | 59 | }, |
62 | 60 | "event": { |
63 | | - "ingested": "2021-12-09T13:41:22.171233100Z", |
64 | 61 | "original": "30,09/20/21,09:16:15,DNS Update Request,172.28.43.169,057182593757.test.com,,,0,6,,,,,,,,,0", |
65 | 62 | "code": "30", |
66 | 63 | "kind": "event", |
67 | 64 | "timezone": "America/New_York", |
| 65 | + "action": "dhcp-dns-update", |
68 | 66 | "category": [ |
69 | 67 | "network" |
70 | 68 | ], |
|
95 | 93 | "domain": "1-07.test.com" |
96 | 94 | }, |
97 | 95 | "event": { |
98 | | - "ingested": "2021-12-09T13:41:22.171238100Z", |
99 | 96 | "original": "30,09/20/21,09:16:09,DNS Update Request,172.28.53.173,1-07.test.com,,,0,6,,,,,,,,,0", |
100 | 97 | "code": "30", |
101 | 98 | "kind": "event", |
102 | 99 | "timezone": "America/New_York", |
| 100 | + "action": "dhcp-dns-update", |
103 | 101 | "category": [ |
104 | 102 | "network" |
105 | 103 | ], |
|
130 | 128 | "domain": "3-07.test.com" |
131 | 129 | }, |
132 | 130 | "event": { |
133 | | - "ingested": "2021-12-09T13:41:22.171242700Z", |
134 | 131 | "original": "32,09/20/21,09:16:03,DNS Update Successful,172.28.53.36,3-07.test.com,,,0,6,,,,,,,,,0", |
135 | 132 | "code": "32", |
136 | 133 | "kind": "event", |
137 | 134 | "timezone": "America/New_York", |
| 135 | + "action": "dhcp-dns-update", |
138 | 136 | "category": [ |
139 | 137 | "network" |
140 | 138 | ], |
|
165 | 163 | "ip": "172.28.52.0" |
166 | 164 | }, |
167 | 165 | "event": { |
168 | | - "ingested": "2021-12-09T13:41:22.171249400Z", |
169 | 166 | "original": "36,09/20/21,09:18:01,Packet dropped because of Client ID hash mismatch or standby server.,172.28.52.0,,76691ED45C90,,0,6,,,,,,,,,0", |
170 | 167 | "code": "36", |
171 | 168 | "kind": "event", |
|
174 | 171 | "network" |
175 | 172 | ], |
176 | 173 | "type": [ |
177 | | - "connection" |
| 174 | + "connection", |
| 175 | + "denied" |
178 | 176 | ], |
179 | | - "outcome": "success" |
| 177 | + "outcome": "failure" |
180 | 178 | }, |
181 | 179 | "message": "Packet dropped because of Client ID hash mismatch or standby server.", |
182 | 180 | "microsoft": { |
|
200 | 198 | "domain": "035856103966.test.com" |
201 | 199 | }, |
202 | 200 | "event": { |
203 | | - "ingested": "2021-12-09T13:41:22.171254600Z", |
204 | 201 | "original": "31,09/20/21,09:18:00,DNS Update Failed,172.28.43.159,035856103966.test.com,,,0,6,,,,,,,,,10054", |
205 | 202 | "code": "31", |
206 | 203 | "kind": "event", |
207 | 204 | "timezone": "America/New_York", |
| 205 | + "action": "dhcp-dns-update", |
208 | 206 | "category": [ |
209 | 207 | "network" |
210 | 208 | ], |
211 | 209 | "type": [ |
212 | 210 | "connection" |
213 | 211 | ], |
214 | | - "outcome": "success" |
| 212 | + "outcome": "failure" |
215 | 213 | }, |
216 | 214 | "message": "DNS Update Failed", |
217 | 215 | "microsoft": { |
|
235 | 233 | "domain": "001100581357.test.com" |
236 | 234 | }, |
237 | 235 | "event": { |
238 | | - "ingested": "2021-12-09T13:41:22.171260Z", |
239 | 236 | "original": "31,09/20/21,09:18:01,DNS Update Failed,172.28.40.35,001100581357.test.com,,,0,6,,,,,,,,,10054", |
240 | 237 | "code": "31", |
241 | 238 | "kind": "event", |
242 | 239 | "timezone": "America/New_York", |
| 240 | + "action": "dhcp-dns-update", |
243 | 241 | "category": [ |
244 | 242 | "network" |
245 | 243 | ], |
246 | 244 | "type": [ |
247 | 245 | "connection" |
248 | 246 | ], |
249 | | - "outcome": "success" |
| 247 | + "outcome": "failure" |
250 | 248 | }, |
251 | 249 | "message": "DNS Update Failed", |
252 | 250 | "microsoft": { |
|
271 | 269 | "domain": "host.test.com" |
272 | 270 | }, |
273 | 271 | "event": { |
274 | | - "ingested": "2021-12-09T13:41:22.171266400Z", |
275 | 272 | "original": "35,01/01/01,01:01:01,DNS update request failed,192.168.2.1,host.test.com,000000000000,", |
276 | 273 | "code": "35", |
277 | 274 | "kind": "event", |
278 | 275 | "timezone": "America/New_York", |
| 276 | + "action": "dhcp-dns-update", |
279 | 277 | "category": [ |
280 | 278 | "network" |
281 | 279 | ], |
282 | 280 | "type": [ |
283 | | - "connection" |
| 281 | + "connection", |
| 282 | + "denied" |
284 | 283 | ], |
285 | | - "outcome": "success" |
| 284 | + "outcome": "failure" |
286 | 285 | }, |
287 | 286 | "message": "DNS update request failed", |
288 | 287 | "tags": [ |
|
300 | 299 | "domain": "host.test.com" |
301 | 300 | }, |
302 | 301 | "event": { |
303 | | - "ingested": "2021-12-09T13:41:22.171271800Z", |
304 | 302 | "original": "10,01/01/01,01:01:01,Assign,192.168.2.10,host.test.com,000000000000,,17739,0,,,", |
305 | 303 | "code": "10", |
306 | 304 | "kind": "event", |
|
310 | 308 | "network" |
311 | 309 | ], |
312 | 310 | "type": [ |
313 | | - "connection" |
| 311 | + "connection", |
| 312 | + "allowed" |
314 | 313 | ], |
315 | 314 | "outcome": "success" |
316 | 315 | }, |
|
336 | 335 | "domain": "host.test.com" |
337 | 336 | }, |
338 | 337 | "event": { |
339 | | - "ingested": "2021-12-09T13:41:22.171277Z", |
340 | 338 | "original": "10,01/01/01,01:01:01,Assign,192.168.2.20,host.test.com,000000000000,,3096562285,0,,,,0x4D53465420352E30,MSFT 5.0,,,,0", |
341 | 339 | "code": "10", |
342 | 340 | "kind": "event", |
|
346 | 344 | "network" |
347 | 345 | ], |
348 | 346 | "type": [ |
349 | | - "connection" |
| 347 | + "connection", |
| 348 | + "allowed" |
350 | 349 | ], |
351 | 350 | "outcome": "success" |
352 | 351 | }, |
|
372 | 371 | "version": "1.12.0" |
373 | 372 | }, |
374 | 373 | "event": { |
375 | | - "ingested": "2021-12-09T13:41:22.171281100Z", |
376 | 374 | "original": "24,11/20/20,00:00:05,Database Cleanup Begin,,,,,0,6,,,,,,,,,0", |
377 | 375 | "code": "24", |
378 | 376 | "kind": "event", |
379 | 377 | "timezone": "America/New_York", |
| 378 | + "action": "ip-cleanup-start", |
380 | 379 | "category": [ |
381 | 380 | "network" |
382 | 381 | ], |
|
407 | 406 | "domain": "hostname.test.com" |
408 | 407 | }, |
409 | 408 | "event": { |
410 | | - "ingested": "2021-12-09T13:41:22.171285200Z", |
411 | 409 | "original": "30,11/20/20,00:00:05,DNS Update Request,10.10.10.10,hostname.test.com,,,0,6,,,,,,,,,0", |
412 | 410 | "code": "30", |
413 | 411 | "kind": "event", |
414 | 412 | "timezone": "America/New_York", |
| 413 | + "action": "dhcp-dns-update", |
415 | 414 | "category": [ |
416 | 415 | "network" |
417 | 416 | ], |
|
438 | 437 | "version": "1.12.0" |
439 | 438 | }, |
440 | 439 | "event": { |
441 | | - "ingested": "2021-12-09T13:41:22.171289600Z", |
442 | 440 | "original": "17,11/20/20,00:00:05,DNS record not deleted67.43.156.15,,,,0,6,,,,,,,,,0", |
443 | 441 | "code": "17", |
444 | 442 | "kind": "event", |
445 | 443 | "timezone": "America/New_York", |
| 444 | + "action": "dhcp-expire", |
446 | 445 | "category": [ |
447 | 446 | "network" |
448 | 447 | ], |
|
474 | 473 | "domain": "domain.local" |
475 | 474 | }, |
476 | 475 | "event": { |
477 | | - "ingested": "2021-12-09T13:41:22.171294600Z", |
478 | 476 | "original": "55,04/19/20,12:43:54,Authorized(servicing),,domain.local,", |
479 | 477 | "code": "55", |
480 | 478 | "kind": "event", |
481 | 479 | "timezone": "America/New_York", |
| 480 | + "action": "rogue-server-detection", |
482 | 481 | "category": [ |
483 | 482 | "network" |
484 | 483 | ], |
|
501 | 500 | "domain": "domain.local" |
502 | 501 | }, |
503 | 502 | "event": { |
504 | | - "ingested": "2021-12-09T13:41:22.171299500Z", |
505 | 503 | "original": "60,04/19/20,12:43:21,No DC is DS Enabled,,domain.local,", |
506 | 504 | "code": "60", |
507 | 505 | "kind": "event", |
508 | 506 | "timezone": "America/New_York", |
| 507 | + "action": "rogue-server-detection", |
509 | 508 | "category": [ |
510 | 509 | "network", |
511 | 510 | "authentication" |
|
527 | 526 | "version": "1.12.0" |
528 | 527 | }, |
529 | 528 | "event": { |
530 | | - "ingested": "2021-12-09T13:41:22.171305200Z", |
531 | 529 | "original": "63,04/19/20,12:43:28,Restarting rogue detection,,,", |
532 | 530 | "code": "63", |
533 | 531 | "kind": "event", |
534 | 532 | "timezone": "America/New_York", |
| 533 | + "action": "rogue-server-detection", |
535 | 534 | "category": [ |
536 | 535 | "network", |
537 | 536 | "authentication" |
|
0 commit comments