|
19 | 19 | "region_name": "England" |
20 | 20 | }, |
21 | 21 | "ip": "81.2.69.145", |
| 22 | + "nat": { |
| 23 | + "port": 34294 |
| 24 | + }, |
22 | 25 | "port": 80 |
23 | 26 | }, |
24 | 27 | "ecs": { |
|
41 | 44 | "hostname": "MX100" |
42 | 45 | }, |
43 | 46 | "source": { |
44 | | - "as": { |
45 | | - "number": 1221, |
46 | | - "organization": { |
47 | | - "name": "Telstra Pty Ltd" |
48 | | - } |
| 47 | + "ip": "10.0.0.234", |
| 48 | + "nat": { |
| 49 | + "ip": "1.128.3.4", |
| 50 | + "port": 34294 |
49 | 51 | }, |
50 | | - "ip": "1.128.3.4", |
51 | 52 | "port": 34294 |
52 | 53 | }, |
53 | 54 | "tags": [ |
|
74 | 75 | "region_name": "England" |
75 | 76 | }, |
76 | 77 | "ip": "81.2.69.143", |
| 78 | + "nat": { |
| 79 | + "port": 45061 |
| 80 | + }, |
77 | 81 | "port": 53 |
78 | 82 | }, |
79 | 83 | "ecs": { |
|
96 | 100 | "hostname": "MX100" |
97 | 101 | }, |
98 | 102 | "source": { |
99 | | - "as": { |
100 | | - "number": 1221, |
101 | | - "organization": { |
102 | | - "name": "Telstra Pty Ltd" |
103 | | - } |
| 103 | + "ip": "10.0.0.234", |
| 104 | + "nat": { |
| 105 | + "ip": "1.128.3.4", |
| 106 | + "port": 45061 |
104 | 107 | }, |
105 | | - "ip": "1.128.3.4", |
106 | 108 | "port": 45061 |
107 | 109 | }, |
108 | 110 | "tags": [ |
|
129 | 131 | "region_name": "England" |
130 | 132 | }, |
131 | 133 | "ip": "81.2.69.143", |
| 134 | + "nat": { |
| 135 | + "port": 37401 |
| 136 | + }, |
132 | 137 | "port": 53 |
133 | 138 | }, |
134 | 139 | "ecs": { |
|
151 | 156 | "hostname": "MX100" |
152 | 157 | }, |
153 | 158 | "source": { |
154 | | - "as": { |
155 | | - "number": 1221, |
156 | | - "organization": { |
157 | | - "name": "Telstra Pty Ltd" |
158 | | - } |
| 159 | + "ip": "10.0.0.234", |
| 160 | + "nat": { |
| 161 | + "ip": "1.128.3.4", |
| 162 | + "port": 37401 |
159 | 163 | }, |
160 | | - "ip": "1.128.3.4", |
161 | 164 | "port": 37401 |
162 | 165 | }, |
163 | 166 | "tags": [ |
|
190 | 193 | "region_name": "Östergötland County" |
191 | 194 | }, |
192 | 195 | "ip": "89.160.20.156", |
| 196 | + "nat": { |
| 197 | + "port": 61272 |
| 198 | + }, |
193 | 199 | "port": 443 |
194 | 200 | }, |
195 | 201 | "ecs": { |
|
212 | 218 | "hostname": "MX84" |
213 | 219 | }, |
214 | 220 | "source": { |
215 | | - "as": { |
216 | | - "number": 209 |
| 221 | + "ip": "10.0.3.138", |
| 222 | + "nat": { |
| 223 | + "ip": "216.160.83.61", |
| 224 | + "port": 61272 |
217 | 225 | }, |
218 | | - "geo": { |
219 | | - "city_name": "Milton", |
220 | | - "continent_name": "North America", |
221 | | - "country_iso_code": "US", |
222 | | - "country_name": "United States", |
223 | | - "location": { |
224 | | - "lat": 47.2513, |
225 | | - "lon": -122.3149 |
226 | | - }, |
227 | | - "region_iso_code": "US-WA", |
228 | | - "region_name": "Washington" |
229 | | - }, |
230 | | - "ip": "216.160.83.61", |
231 | 226 | "port": 61272 |
232 | 227 | }, |
233 | 228 | "tags": [ |
|
241 | 236 | "event_type": "ip_flow_end" |
242 | 237 | }, |
243 | 238 | "destination": { |
244 | | - "as": { |
245 | | - "number": 29518, |
246 | | - "organization": { |
247 | | - "name": "Bredband2 AB" |
248 | | - } |
249 | | - }, |
250 | | - "geo": { |
251 | | - "city_name": "Linköping", |
252 | | - "continent_name": "Europe", |
253 | | - "country_iso_code": "SE", |
254 | | - "country_name": "Sweden", |
255 | | - "location": { |
256 | | - "lat": 58.4167, |
257 | | - "lon": 15.6167 |
258 | | - }, |
259 | | - "region_iso_code": "SE-E", |
260 | | - "region_name": "Östergötland County" |
| 239 | + "ip": "10.0.0.1", |
| 240 | + "nat": { |
| 241 | + "ip": "89.160.20.112", |
| 242 | + "port": 53 |
261 | 243 | }, |
262 | | - "ip": "89.160.20.112", |
263 | 244 | "port": 53 |
264 | 245 | }, |
265 | 246 | "ecs": { |
|
283 | 264 | }, |
284 | 265 | "source": { |
285 | 266 | "ip": "10.0.2.249", |
| 267 | + "nat": { |
| 268 | + "port": 53 |
| 269 | + }, |
286 | 270 | "port": 7421 |
287 | 271 | }, |
288 | 272 | "tags": [ |
|
309 | 293 | } |
310 | 294 | }, |
311 | 295 | "ip": "67.43.156.14", |
| 296 | + "nat": { |
| 297 | + "port": 38422 |
| 298 | + }, |
312 | 299 | "port": 443 |
313 | 300 | }, |
314 | 301 | "ecs": { |
|
331 | 318 | "hostname": "MX84" |
332 | 319 | }, |
333 | 320 | "source": { |
334 | | - "as": { |
335 | | - "number": 209 |
336 | | - }, |
337 | | - "geo": { |
338 | | - "city_name": "Milton", |
339 | | - "continent_name": "North America", |
340 | | - "country_iso_code": "US", |
341 | | - "country_name": "United States", |
342 | | - "location": { |
343 | | - "lat": 47.2513, |
344 | | - "lon": -122.3149 |
345 | | - }, |
346 | | - "region_iso_code": "US-WA", |
347 | | - "region_name": "Washington" |
| 321 | + "ip": "10.0.3.116", |
| 322 | + "nat": { |
| 323 | + "ip": "216.160.83.61", |
| 324 | + "port": 38422 |
348 | 325 | }, |
349 | | - "ip": "216.160.83.61", |
350 | 326 | "port": 38422 |
351 | 327 | }, |
352 | 328 | "tags": [ |
|
360 | 336 | "event_type": "ip_flow_end" |
361 | 337 | }, |
362 | 338 | "destination": { |
363 | | - "as": { |
364 | | - "number": 29518, |
365 | | - "organization": { |
366 | | - "name": "Bredband2 AB" |
367 | | - } |
| 339 | + "ip": "10.0.0.1", |
| 340 | + "nat": { |
| 341 | + "ip": "89.160.20.112", |
| 342 | + "port": 53 |
368 | 343 | }, |
369 | | - "geo": { |
370 | | - "city_name": "Linköping", |
371 | | - "continent_name": "Europe", |
372 | | - "country_iso_code": "SE", |
373 | | - "country_name": "Sweden", |
374 | | - "location": { |
375 | | - "lat": 58.4167, |
376 | | - "lon": 15.6167 |
377 | | - }, |
378 | | - "region_iso_code": "SE-E", |
379 | | - "region_name": "Östergötland County" |
380 | | - }, |
381 | | - "ip": "89.160.20.112", |
382 | 344 | "port": 53 |
383 | 345 | }, |
384 | 346 | "ecs": { |
|
402 | 364 | }, |
403 | 365 | "source": { |
404 | 366 | "ip": "10.0.2.99", |
| 367 | + "nat": { |
| 368 | + "port": 53 |
| 369 | + }, |
405 | 370 | "port": 29534 |
406 | 371 | }, |
407 | 372 | "tags": [ |
|
428 | 393 | "region_name": "England" |
429 | 394 | }, |
430 | 395 | "ip": "81.2.69.144", |
| 396 | + "nat": { |
| 397 | + "port": 36498 |
| 398 | + }, |
431 | 399 | "port": 80 |
432 | 400 | }, |
433 | 401 | "ecs": { |
|
450 | 418 | "hostname": "MX100" |
451 | 419 | }, |
452 | 420 | "source": { |
453 | | - "as": { |
454 | | - "number": 1221, |
455 | | - "organization": { |
456 | | - "name": "Telstra Pty Ltd" |
457 | | - } |
| 421 | + "ip": "10.0.0.234", |
| 422 | + "nat": { |
| 423 | + "ip": "1.128.3.4", |
| 424 | + "port": 36498 |
458 | 425 | }, |
459 | | - "ip": "1.128.3.4", |
460 | 426 | "port": 36498 |
461 | 427 | }, |
462 | 428 | "tags": [ |
|
504 | 470 | "hostname": "MX100" |
505 | 471 | }, |
506 | 472 | "source": { |
507 | | - "as": { |
508 | | - "number": 1221, |
509 | | - "organization": { |
510 | | - "name": "Telstra Pty Ltd" |
511 | | - } |
512 | | - }, |
513 | | - "ip": "1.128.3.4" |
| 473 | + "ip": "10.0.0.234", |
| 474 | + "nat": { |
| 475 | + "ip": "1.128.3.4" |
| 476 | + } |
514 | 477 | }, |
515 | 478 | "tags": [ |
516 | 479 | "forwarded", |
|
523 | 486 | "event_type": "ip_flow_end" |
524 | 487 | }, |
525 | 488 | "destination": { |
526 | | - "as": { |
527 | | - "number": 29518, |
528 | | - "organization": { |
529 | | - "name": "Bredband2 AB" |
530 | | - } |
531 | | - }, |
532 | | - "geo": { |
533 | | - "city_name": "Linköping", |
534 | | - "continent_name": "Europe", |
535 | | - "country_iso_code": "SE", |
536 | | - "country_name": "Sweden", |
537 | | - "location": { |
538 | | - "lat": 58.4167, |
539 | | - "lon": 15.6167 |
540 | | - }, |
541 | | - "region_iso_code": "SE-E", |
542 | | - "region_name": "Östergötland County" |
543 | | - }, |
544 | | - "ip": "89.160.20.112" |
| 489 | + "ip": "10.0.0.1", |
| 490 | + "nat": { |
| 491 | + "ip": "89.160.20.112" |
| 492 | + } |
545 | 493 | }, |
546 | 494 | "ecs": { |
547 | 495 | "version": "8.11.0" |
|
569 | 517 | "forwarded", |
570 | 518 | "preserve_original_event" |
571 | 519 | ] |
| 520 | + }, |
| 521 | + { |
| 522 | + "@timestamp": "2025-07-01T14:14:44.245Z", |
| 523 | + "cisco_meraki": { |
| 524 | + "event_type": "ip_flow_start" |
| 525 | + }, |
| 526 | + "destination": { |
| 527 | + "geo": { |
| 528 | + "city_name": "London", |
| 529 | + "continent_name": "Europe", |
| 530 | + "country_iso_code": "GB", |
| 531 | + "country_name": "United Kingdom", |
| 532 | + "location": { |
| 533 | + "lat": 51.5142, |
| 534 | + "lon": -0.0931 |
| 535 | + }, |
| 536 | + "region_iso_code": "GB-ENG", |
| 537 | + "region_name": "England" |
| 538 | + }, |
| 539 | + "ip": "81.2.69.144", |
| 540 | + "nat": { |
| 541 | + "port": 13710 |
| 542 | + }, |
| 543 | + "port": 53 |
| 544 | + }, |
| 545 | + "ecs": { |
| 546 | + "version": "8.11.0" |
| 547 | + }, |
| 548 | + "event": { |
| 549 | + "category": [ |
| 550 | + "network" |
| 551 | + ], |
| 552 | + "original": "<134>1 1751379284.245040794 FW_01 ip_flow_start src=10.140.40.72 dst=81.2.69.144 protocol=udp sport=18212 dport=53 translated_src_ip=1.128.3.4 translated_port=13710", |
| 553 | + "type": [ |
| 554 | + "info" |
| 555 | + ] |
| 556 | + }, |
| 557 | + "message": "src=10.140.40.72 dst=81.2.69.144 protocol=udp sport=18212 dport=53 translated_src_ip=1.128.3.4 translated_port=13710", |
| 558 | + "network": { |
| 559 | + "protocol": "udp" |
| 560 | + }, |
| 561 | + "observer": { |
| 562 | + "hostname": "FW_01" |
| 563 | + }, |
| 564 | + "source": { |
| 565 | + "ip": "10.140.40.72", |
| 566 | + "nat": { |
| 567 | + "ip": "1.128.3.4", |
| 568 | + "port": 13710 |
| 569 | + }, |
| 570 | + "port": 18212 |
| 571 | + }, |
| 572 | + "tags": [ |
| 573 | + "forwarded", |
| 574 | + "preserve_original_event" |
| 575 | + ] |
572 | 576 | } |
573 | 577 | ] |
574 | 578 | } |
0 commit comments