Skip to content

Commit 9adc056

Browse files
Mapping of Gigamon Metadata Attributes to ECS fields
1 parent 6caee3e commit 9adc056

File tree

7 files changed

+2941
-183
lines changed

7 files changed

+2941
-183
lines changed

packages/gigamon/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.7.0"
3+
changes:
4+
- description: Mapping of Gigamon Attributes to ECS fields
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/14692
27
- version: "1.7.0"
38
changes:
49
- description: Added child dashboards for ZT.

packages/gigamon/data_stream/ami/_dev/test/pipeline/test-ami.json

Lines changed: 55 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@
88
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
99
"dst_mac": "01:00:5e:00:00:fb",
1010
"src_mac": "00:50:56:8d:89:41",
11-
"src_ip": "10.114.82.101",
12-
"dst_ip": "224.0.0.251",
11+
"src_ip": "89.160.20.112",
12+
"dst_ip": "89.160.20.113",
1313
"protocol": "17",
1414
"src_port": "5353",
1515
"dst_port": "5353",
@@ -1044,6 +1044,8 @@
10441044
"dns_qdcount": "4",
10451045
"dns_transaction_id": "0",
10461046
"dns_name": "3.a.2.3.7.1.5.5.e.2.1.6.e.4.7.e.0.8.0.2.1.0.0.0.0.0.0.0.b.a.c.f. ip6.arpa",
1047+
"dns_message_type": "QUERY",
1048+
"dns_tunneling": "1",
10471049
"dns_host": "pnstrex-83631.local",
10481050
"dns_host_addr": "10.114.82.162",
10491051
"dns_host_type": "PTR",
@@ -1099,6 +1101,22 @@
10991101
"egress_intf_id": "0",
11001102
"sys_up_time_first": "1890478091",
11011103
"sys_up_time_last": "2158913547",
1104+
"http_rtt": "2",
1105+
"http_server": "g-pixel.invitemedia.com",
1106+
"http_referer": "http:\\/\\/pixel.invitemedia.com\\/data_sync?partner_id=419",
1107+
"http_uri": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999",
1108+
"http_uri_path": "\\/BurstingPipe\\/adServer.bs",
1109+
"http_host": "bs.serving-sys.com",
1110+
"http_uri_raw": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999",
1111+
"http_set_cookie": "S_6283423=1070476434893147863",
1112+
"http_server_agent": "Jetty(7.3.1.v20110307)",
1113+
"http_code": "200",
1114+
"http_content_encoding": "gzip",
1115+
"http_content_type": "image\\/gif",
1116+
"http_method": "GET",
1117+
"http_version": "1.1",
1118+
"http_user_agent": "Mozilla\\/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit\\/534.57.2 (KHTML, like Gecko) Version\\/5.1.7 Safari\\/534.57.2",
1119+
"http_file_type": "GIF (v89a)",
11021120
"end_reason": "1",
11031121
"app_name": "https",
11041122
"id": "679408454713104391",
@@ -2081,6 +2099,8 @@
20812099
"dst_packets": "3",
20822100
"start_time": "2023:12:13 15:25:36.669",
20832101
"end_time": "2023:12:13 15:25:38.253",
2102+
"flow_start_sec": "2023:12:13 15:25:21",
2103+
"flow_end_sec": "2023:12:13 15:25:40",
20842104
"intf_name": "0",
20852105
"egress_intf_id": "0",
20862106
"sys_up_time_first": "1624860683",
@@ -2097,10 +2117,18 @@
20972117
"vendor": "Gigamon",
20982118
"version": "6.5.00",
20992119
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2100-
"dns_qdcount": "0",
2101-
"dns_ancount": "27",
2102-
"dns_transaction_id": "0",
2103-
"dns_name": "sys"
2120+
"smb_version": "1",
2121+
"smb_command_string": "negotiate",
2122+
"smb_path": "\\/\\/11.1.0.37:445\\/sharefile",
2123+
"smb_host": "user1",
2124+
"smb_filename": "testfile",
2125+
"app_id": "3855",
2126+
"tcp_flags": "0",
2127+
"src_bytes": "1036",
2128+
"dst_bytes": "0",
2129+
"src_packets": "4",
2130+
"dst_packets": "0",
2131+
"app_name": "mailslot"
21042132
}
21052133
},
21062134
{
@@ -2117,7 +2145,16 @@
21172145
"src_port": "41529",
21182146
"dst_port": "9080",
21192147
"device_inbound_interface": "0",
2120-
"ssl_cipher_suite_id": "49200",
2148+
"ssl_common_name": "*.zoom.us",
2149+
"ssl_issuer": "Go Daddy Secure Certificate Authority - G2",
2150+
"ssl_cipher_suite_id": "49199",
2151+
"ssl_protocol_version": "771",
2152+
"ssl_certificate_subject_cn": "*.zoom.us",
2153+
"ssl_ext_sig_algorithm_scheme": "1537",
2154+
"ssl_ext_sig_algorithm_hash": "6",
2155+
"ssl_ext_sig_algorithm_sig": "1",
2156+
"ssl_validity_not_before": "2025-05-26 04:32:14",
2157+
"ssl_validity_not_after": "2026-05-26 04:32:14",
21212158
"app_id": "4962",
21222159
"ip_version": "4",
21232160
"src_bytes": "1533",
@@ -2142,12 +2179,14 @@
21422179
"vendor": "Gigamon",
21432180
"version": "6.5.00",
21442181
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2145-
"dns_qdcount": "1",
2146-
"dns_ancount": "30",
2147-
"dns_transaction_id": "0",
2148-
"dns_name": "_tms_cluster._tcp.local",
2149-
"dns_host": "duo-test-cluster._tms_cluster._tcp.local",
2150-
"dns_host_type": "PTR"
2182+
"tcp_loss_count": "1380",
2183+
"tcp_rtt": "0.000015",
2184+
"tcp_rtt_app": "0.000026",
2185+
"tcp_retransmission_bytes": "155",
2186+
"tcp_flag_reset": "1",
2187+
"tcp_wrong_crc": "4296",
2188+
"ip_wrong_crc": "5199",
2189+
"app_id": "15"
21512190
}
21522191
},
21532192
{
@@ -2156,11 +2195,8 @@
21562195
"vendor": "Gigamon",
21572196
"version": "6.5.00",
21582197
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2159-
"dns_qdcount": "2",
2160-
"dns_ancount": "40",
2161-
"dns_transaction_id": "0",
2162-
"dns_name": "_tcn_Suki-Cluster._tcp.local",
2163-
"dns_host": "eqaHCT._tms"
2198+
"snmp_version": "2c",
2199+
"app_id": "190"
21642200
}
21652201
},
21662202
{
@@ -2204,3 +2240,4 @@
22042240
}
22052241
]
22062242
}
2243+

0 commit comments

Comments
 (0)