Skip to content

Commit e65845c

Browse files
Mapping of Gigamon Metadata Attributes to ECS fields
1 parent 6caee3e commit e65845c

File tree

8 files changed

+3592
-156
lines changed

8 files changed

+3592
-156
lines changed

packages/gigamon/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.8.0"
3+
changes:
4+
- description: Mapping of Gigamon attributes to ECS fields
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/14692
27
- version: "1.7.0"
38
changes:
49
- description: Added child dashboards for ZT.

packages/gigamon/data_stream/ami/_dev/test/pipeline/test-ami.json

Lines changed: 225 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2201,6 +2201,231 @@
22012201
"id": "679408454713142279",
22022202
"seq_num": "724"
22032203
}
2204+
},
2205+
{
2206+
"json": {
2207+
"ts": "Wed Dec 13 15:25:54 2023",
2208+
"vendor": "Gigamon",
2209+
"version": "6.5.00",
2210+
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2211+
"dst_mac": "00:90:7f:3e:02:d0",
2212+
"src_mac": "e0:f8:47:21:c9:d6",
2213+
"src_ip": "172.16.133.96",
2214+
"dst_ip": "172.16.133.134",
2215+
"protocol": "6",
2216+
"src_port": "53512",
2217+
"dst_port": "80",
2218+
"device_inbound_interface": "0",
2219+
"http_rtt": "2",
2220+
"http_server": "g-pixel.invitemedia.com",
2221+
"http_referer": "http:\\/\\/pixel.invitemedia.com\\/data_sync?partner_id=419",
2222+
"http_uri": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999",
2223+
"http_uri_path": "\\/BurstingPipe\\/adServer.bs",
2224+
"http_host": "bs.serving-sys.com",
2225+
"http_uri_raw": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999",
2226+
"http_set_cookie": "S_6283423=1070476434893147863",
2227+
"http_server_agent": "Jetty(7.3.1.v20110307)",
2228+
"http_code": "200",
2229+
"http_content_encoding": "gzip",
2230+
"http_content_type": "image\\/gif",
2231+
"http_method": "GET",
2232+
"http_version": "1.1",
2233+
"http_user_agent": "Mozilla\\/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit\\/534.57.2 (KHTML, like Gecko) Version\\/5.1.7 Safari\\/534.57.2",
2234+
"http_file_type": "GIF (v89a)",
2235+
"app_id": "67",
2236+
"tcp_flags": "19",
2237+
"src_bytes": "702",
2238+
"dst_bytes": "1261",
2239+
"src_packets": "5",
2240+
"dst_packets": "4",
2241+
"start_time": "2025:01:27 21:31:31.807",
2242+
"end_time": "2025:01:27 21:31:31.863",
2243+
"flow_start_sec": "2025:01:27 21:31:30",
2244+
"flow_end_sec": "2025:01:27 21:31:30",
2245+
"intf_name": "0",
2246+
"egress_intf_id": "0",
2247+
"app_name": "http",
2248+
"id": "6470375316427636737",
2249+
"seq_num": "187452"
2250+
}
2251+
},
2252+
{
2253+
"json": {
2254+
"ts": "Wed Dec 13 15:25:54 2023",
2255+
"vendor": "Gigamon",
2256+
"version": "6.5.00",
2257+
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2258+
"dst_mac": "b4:0c:25:e0:40:11",
2259+
"src_mac": "4c:32:75:97:66:cf",
2260+
"src_ip": "10.155.24.73",
2261+
"dst_ip": "10.155.24.35",
2262+
"protocol": "6",
2263+
"src_port": "64631",
2264+
"dst_port": "443",
2265+
"device_inbound_interface": "0",
2266+
"ssl_common_name": "*.event.prod.bidr.io",
2267+
"ssl_issuer": "Amazon",
2268+
"ssl_validity_not_before": "2017-08-31 06:30:04",
2269+
"ssl_validity_not_after": "2020-08-31 06:30:04",
2270+
"ssl_cipher_suite_id": "49199",
2271+
"ssl_protocol_version": "771",
2272+
"ssl_certificate_subject_cn": "*.event.prod.bidr.io",
2273+
"ssl_ext_sig_algorithm_scheme": "1027",
2274+
"ssl_ext_sig_algorithm_hash": "4",
2275+
"ssl_ext_sig_algorithm_sig": "3",
2276+
"ip_wrong_crc": "5199",
2277+
"app_id": "1183",
2278+
"tcp_flags": "18",
2279+
"src_bytes": "2365",
2280+
"dst_bytes": "6387",
2281+
"src_packets": "11",
2282+
"dst_packets": "8",
2283+
"start_time": "2025:01:27 21:37:26.327",
2284+
"end_time": "2025:01:27 21:37:26.415",
2285+
"flow_start_sec": "2025:01:27 21:37:25",
2286+
"flow_end_sec": "2025:01:27 21:37:25",
2287+
"intf_name": "0",
2288+
"egress_intf_id": "0",
2289+
"app_name": "amazon-aws",
2290+
"id": "6470375590653329409",
2291+
"seq_num": "319260"
2292+
}
2293+
},
2294+
{
2295+
"json": {
2296+
"ts": "Wed Dec 13 15:25:54 2023",
2297+
"vendor": "Gigamon",
2298+
"version": "6.5.00",
2299+
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2300+
"dst_mac": "4c:32:75:97:66:cf",
2301+
"src_mac": "c0:94:35:1c:5e:1a",
2302+
"src_port": "443",
2303+
"dst_port": "63770",
2304+
"tcp_loss_count": "1380",
2305+
"tcp_rtt": "0.000015",
2306+
"tcp_rtt_app": "0.000026",
2307+
"tcp_retransmission_bytes": "155",
2308+
"tcp_flag_reset": "1",
2309+
"tcp_wrong_crc": "4296",
2310+
"app_id": "68",
2311+
"src_ipv6": "2a02:cf40:0000:0000:0000:0000:0000:0001",
2312+
"dst_ipv6": "2a02:cf47:ffff:ffff:ffff:ffff:ffff:0001",
2313+
"ip_version": "6",
2314+
"tcp_flags": "18",
2315+
"src_packets": "3301",
2316+
"dst_packets": "4205",
2317+
"flow_start_sec": "2025:07:28 03:12:22",
2318+
"end_reason": "2",
2319+
"app_name": "https",
2320+
"src_bytes": "307270",
2321+
"dst_bytes": "558827",
2322+
"id": "691388880983323651",
2323+
"seq_num": "52332271"
2324+
}
2325+
},
2326+
{
2327+
"json": {
2328+
"ts": "Wed Dec 13 15:25:54 2023",
2329+
"vendor": "Gigamon",
2330+
"version": "6.5.00",
2331+
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2332+
"dst_mac": "b4:0c:25:e0:40:53",
2333+
"src_mac": "00:08:e3:ff:fc:28",
2334+
"src_ip": "10.10.1.116",
2335+
"dst_ip": "10.120.10.218",
2336+
"protocol": "17",
2337+
"src_port": "61751",
2338+
"dst_port": "161",
2339+
"device_inbound_interface": "0",
2340+
"snmp_version": "2c",
2341+
"app_id": "190",
2342+
"tcp_flags": "0",
2343+
"src_bytes": "172",
2344+
"dst_bytes": "182",
2345+
"src_packets": "2",
2346+
"dst_packets": "2",
2347+
"start_time": "2025:01:27 21:33:58.759",
2348+
"end_time": "2025:01:27 21:33:58.759",
2349+
"flow_start_sec": "2025:01:27 21:33:57",
2350+
"flow_end_sec": "2025:01:27 21:33:57",
2351+
"intf_name": "0",
2352+
"egress_intf_id": "0",
2353+
"app_name": "snmp",
2354+
"id": "6470375508803584001",
2355+
"seq_num": "213751"
2356+
}
2357+
},
2358+
{
2359+
"json": {
2360+
"ts": "Wed Dec 13 15:25:54 2023",
2361+
"vendor": "Gigamon",
2362+
"version": "6.5.00",
2363+
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2364+
"dst_mac": "ff:ff:ff:ff:ff:ff",
2365+
"src_mac": "09:00:09:00:01:12",
2366+
"src_ip": "10.2.1.23",
2367+
"dst_ip": "10.2.1.255",
2368+
"protocol": "17",
2369+
"src_port": "138",
2370+
"dst_port": "138",
2371+
"device_inbound_interface": "0",
2372+
"smb_version": "1",
2373+
"smb_command_string": "negotiate",
2374+
"smb_path": "\\/\\/11.1.0.37:445\\/sharefile",
2375+
"smb_host": "user1",
2376+
"smb_filename": "testfile",
2377+
"app_id": "3855",
2378+
"tcp_flags": "0",
2379+
"src_bytes": "38376",
2380+
"dst_bytes": "0",
2381+
"src_packets": "162",
2382+
"dst_packets": "0",
2383+
"start_time": "2025:01:27 21:30:10.463",
2384+
"end_time": "2025:01:27 21:30:44.847",
2385+
"flow_start_sec": "2025:01:27 21:30:09",
2386+
"flow_end_sec": "2025:01:27 21:30:43",
2387+
"intf_name": "0",
2388+
"egress_intf_id": "0",
2389+
"app_name": "mailslot",
2390+
"id": "6470375254073016321",
2391+
"seq_num": "76099"
2392+
}
2393+
},
2394+
{
2395+
"json": {
2396+
"ts": "Wed Dec 13 15:25:54 2023",
2397+
"vendor": "Gigamon",
2398+
"version": "6.5.00",
2399+
"generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6",
2400+
"dst_mac": "02:01:93:9c:99:4d",
2401+
"src_mac": "02:01:93:9c:98:37",
2402+
"src_ip": "10.1.0.4",
2403+
"dst_ip": "10.1.0.4",
2404+
"protocol": "17",
2405+
"src_port": "57677",
2406+
"dst_port": "67",
2407+
"dns_qdcount": "1",
2408+
"dns_message_type": "QUERY",
2409+
"dns_tunneling": "1",
2410+
"dns_reverse_addr": "10.12.21.34",
2411+
"dns_flags": "256",
2412+
"dns_opcode": "0",
2413+
"dns_class": "1",
2414+
"dns_query": "34.21.12.61.in-addr.arpa",
2415+
"dns_query_type": "12",
2416+
"app_id": "32",
2417+
"ip_version": "4",
2418+
"src_packets": "2955",
2419+
"dst_packets": "2705",
2420+
"flow_start_sec": "2025:07:27 23:52:17",
2421+
"end_reason": "1",
2422+
"app_name": "dns",
2423+
"src_bytes": "326560",
2424+
"dst_bytes": "432901",
2425+
"id": "691388880109625347",
2426+
"seq_num": "52203185"
2427+
}
22042428
}
22052429
]
22062430
}
2431+

0 commit comments

Comments
 (0)