- Notifications
You must be signed in to change notification settings - Fork 513
Increase the ZT event coverage for Cloudflare Logpush #6132
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
P1llus merged 24 commits into elastic:main from chemamartinez:5867-cloudflare-new-datastreams Jun 20, 2023
Merged
Changes from all commits
Commits
Show all changes
24 commits Select commit Hold shift + click to select a range
1dab4ad Add gateway_dns data stream for Cloudflare Logpush
chemamartinez 1315647 Add gateway_http data stream for Cloudflare Logpush
chemamartinez 209c0c5 Add gateway_network data stream for Cloudflare Logpush
chemamartinez 13e7115 Add network_session data stream for Cloudflare Logpush
chemamartinez f8be673 Update new data streams with latest changes from #6164 and #6053
chemamartinez a1bfdbc Add casb_findings data stream for Cloudflare Logpush
chemamartinez 0654f0c Add access_request data stream for Cloudflare Logpush
chemamartinez 1f2913c Rename CASB sample log
chemamartinez c352d11 Add device_posture data stream for Cloudflare Logpush
chemamartinez ff9abcc Update new data streams with latest changes from #6199
chemamartinez 9d73af0 Add requested changes for data streams
chemamartinez daac3c0 Fix typo in network analytics pipeline
chemamartinez b303e62 Merge branch 'main' into 5867-cloudflare-new-datastreams
chemamartinez 267d28c Fix missing field in Device Posture pipeline
chemamartinez d54e37a Add dashboards for ZT events
chemamartinez a9e16e5 Fix the use of event.outcome and event.type
chemamartinez 7316263 Update Cloudflare Logpush dashboards
chemamartinez df9b6b7 Update pipeline and system tests
chemamartinez 6e1e53f Update Cloudflare Logpush screenshots
chemamartinez 5aee4c0 Add screenshots to manifest
chemamartinez 525cfca Update preference in timestamp formats
chemamartinez c60be29 Increase Kibana version to 8.7.0
chemamartinez 5e19f4f Merge branch 'main' into 5867-cloudflare-new-datastreams
chemamartinez c8ee8a2 Update some filters in cloudflare logpush dashboards
chemamartinez File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/access_request.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"Action":"login","Allowed":true,"AppDomain":"partner-zt-logs.cloudflareaccess.com/warp","AppUUID":"123e4567-e89b-12d3-a456-426614174000","Connection":"onetimepin","Country":"us","CreatedAt":1684862313000000000,"Email":"user@example.com","IPAddress":"67.43.156.93","PurposeJustificationPrompt":"Please provide your reason for accessing the application.","PurposeJustificationResponse":"I need to access the application for work purposes.","RayID":"00c0ffeeabc12345","TemporaryAccessApprovers":["approver1@example.com","approver2@example.com"],"TemporaryAccessDuration":7200,"UserUID":"166befbb-00e3-5e20-bd6e-27245333949f"} |
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/casb.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"AssetDisplayName":"John Doe","AssetExternalID":"0051N000004mG2LAAA","AssetLink":"https://example.com/resource","AssetMetadata":{"Id":"0051N000004mG2LAAA","Fax":null,"Name":"John Doe","Alias":"JDoe","Email":"user@example.com","Phone":"+3460000000","Title":"Customer Solutions Engineer","Address":{"city":"Singapore","state":null,"street":null,"country":"Singapore","latitude":null,"longitude":null,"stateCode":null,"postalCode":null,"countryCode":"SG","geocodeAccuracy":null},"Division":null,"IsActive":false,"LastName":"Doe","UserType":"Standard","AccountId":null,"BadgeText":"","ContactId":null,"Extension":null,"FirstName":"John","Signature":null,"Department":"521","SenderName":null,"UserRoleId":"00E2G000001E","attributes":{"url":"/services/data/userID","type":"User"},"CompanyName":"MyCompany","MobilePhone":null,"SenderEmail":"sender@example.com","CallCenterId":null,"FullPhotoUrl":"https://photos.com/profilephoto/001","LocaleSidKey":"en_SG","LastLoginDate":"2021-10-06T06:32:09.000+0000","SmallPhotoUrl":"https://photos.com/photo/001","BannerPhotoUrl":"/profilephoto/001","EmployeeNumber":"18124","LastViewedDate":null,"TimeZoneSidKey":"Asia/Singapore","DigestFrequency":"D","ForecastEnabled":false,"EmailEncodingKey":"UTF-8","CommunityNickname":"Doe.John","LanguageLocaleKey":"en_US","LastReferencedDate":null,"ReceivesInfoEmails":true,"SmallBannerPhotoUrl":"/profilephoto/001/D","FederationIdentifier":null,"IsProfilePhotoActive":false,"MediumBannerPhotoUrl":"/profilephoto/001/E","EmailPreferencesAutoBcc":true,"ReceivesAdminInfoEmails":true,"OfflineTrialExpirationDate":null,"UserPermissionsOfflineUser":false,"UserPermissionsSupportUser":false,"UserPermissionsMarketingUser":false,"UserPermissionsInteractionUser":true,"DefaultGroupNotificationFrequency":"N","UserPermissionsCallCenterAutoLogin":false},"DetectedTimestamp":"2023-05-16T10:00:00Z","FindingTypeDisplayName":"Salesforce User Sending Email with Different Email Address","FindingTypeID":"a2790c4f-03f5-449f-b209-5f4447f417aa","FindingTypeSeverity":"Medium","InstanceID":"6b187be4-2dd5-42c5-a37b-111111111111","IntegrationDisplayName":"Salesforce Testing","IntegrationID":"c772678d-5cf1-4c73-bf3f-111111111111","IntegrationPolicyVendor":"Salesforce Connection"} |
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/device_posture.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"ClientVersion":"2023.3.258","DeviceID":"083a8354-d56c-11ed-9771-111111111","DeviceManufacturer":"Google Compute Engine","DeviceModel":"Google Compute Engine","DeviceName":"zt-test-vm1","DeviceSerialNumber":"GoogleCloud-ABCD1234567890","DeviceType":"linux","Email":"user@example.com","OSVersion":"5.15.0","PolicyID":"policy-abcdefgh","PostureCheckName":"Ubuntu","PostureCheckType":"os_version","PostureEvaluatedResult":true,"PostureExpectedJSON":{"version":"5.15.0-1025-gcp","operator":"==","os_distro_name":"ubuntu","os_distro_revision":"20.04"},"PostureReceivedJSON":{"version":"5.15.0-1025-gcp","operator":"==","os_distro_name":"ubuntu","os_distro_revision":"20.04"},"Timestamp":"2023-05-17T12:00:00Z","UserUID":"user-abcdefgh"} |
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/gateway_dns.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"ApplicationID":0,"ColoCode":"ORD","ColoID":14,"Datetime":"2023-05-02T22:49:53Z","DeviceID":"083a8354-d56c-11ed-9771-6a842b111aaa","DeviceName":"zt-test-vm1","DstIP":"89.160.20.129","DstPort":443,"Email":"user@test.com","Location":"GCP default","LocationID":"f233bd67-78c7-4050-9aff-ad63cce25732","MatchedCategoryIDs":[7,163],"MatchedCategoryNames":["Photography","Weather"],"Policy":"7bdc7a9c-81d3-4816-8e56-de1acad3dec5","PolicyID":"1412","Protocol":"https","QueryCategoryIDs":[26,155],"QueryCategoryNames":["Technology","Technology"],"QueryName":"security.ubuntu.com","QueryNameReversed":"com.ubuntu.security","QuerySize":48,"QueryType":1,"QueryTypeName":"A","RCode":0,"RData":[{"type":"1","data":"CHNlY3VyaXR5BnVidW50dQMjb20AAAEAAQAAAAgABLl9vic="},{"type":"1","data":"CHNlY3VyaXR5BnVidW50dQNjb20AAAEAABAAAAgABLl9viQ="},{"type":"1","data":"CHNlT3VyaXR5BnVidW50dQNjb20AAAEAAQAAAAgABFu9Wyc="}],"ResolvedIPs":["67.43.156.1","67.43.156.2","67.43.156.3"],"ResolverDecision":"allowedOnNoPolicyMatch","SrcIP":"67.43.156.2","SrcPort":0,"TimeZone":"UTC","TimeZoneInferredMethod":"fromLocalTime","UserID":"166befbb-00e3-5e20-bd6e-27245000000"} |
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/gateway_http.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"AccountID":"e1836771179f98aabb828da5ea69a348","Action":"block","BlockedFileHash":"91dc1db739a705105e1c763bfdbdaa84c0de8","BlockedFileName":"downloaded_test","BlockedFileReason":"malware","BlockedFileSize":43,"BlockedFileType":"bin","Datetime":"2023-05-03T20:55:05Z","DestinationIP":"89.160.20.129","DestinationPort":443,"DeviceID":"083a8354-d56c-11ed-9771-6a842b100cff","DeviceName":"zt-test-vm1","DownloadedFileNames":["downloaded_file","downloaded_test"],"Email":"user@example.com","FileInfo":{"files":[{"name":"downloaded_file","size":43},{"name":"downloaded_test","size":341}]},"HTTPHost":"guce.yahoo.com","HTTPMethod":"GET","HTTPStatusCode":302,"HTTPVersion":"HTTP/2","IsIsolated":false,"PolicyID":"85063bec-74cb-4546-85a3-e0cde2cdfda2","PolicyName":"Block Yahoo","Referer":"https://www.example.com/","RequestID":"1884fec9b600007fb06a299400000001","SourceInternalIP":"192.168.1.123","SourceIP":"67.43.156.2","SourcePort":47924,"UntrustedCertificateAction":"none","UploadedFileNames":["uploaded_file","uploaded_test"],"URL":"https://test.com","UserAgent":"Mozilla/5.0 (X11; Ubuntu; Linux x86_64) Firefox/112.0","UserID":"166befbb-00e3-5e20-bd6e-27245723949f"} |
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/gateway_network.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"AccountID":"e1836771179f98aabb828da5ea69a111","Action":"allowedOnNoRuleMatch","Datetime":1684444377058000000,"DestinationIP":"89.160.20.129","DestinationPort":443,"DeviceID":"083a8354-d56c-11ed-9771-6a842b100cff","DeviceName":"zt-test-vm1","Email":"user@test.com","OverrideIP":"175.16.199.4","OverridePort":8080,"PolicyID":"85063bec-74cb-4546-85a3-e0cde2cdfda2","PolicyName":"My policy","SNI":"www.elastic.co","SessionID":"5f2d04be-3512-11e8-b467-0ed5f89f718b","SourceIP":"67.43.156.2","SourceInternalIP":"192.168.1.3","SourcePort":47924,"Transport":"tcp","UserID":"166befbb-00e3-5e20-bd6e-27245723949f"} |
1 change: 1 addition & 0 deletions 1 packages/cloudflare_logpush/_dev/deploy/docker/sample_logs/network_session.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"AccountID":"e1836771179f98aabb828da5ea69a111","BytesReceived":679,"BytesSent":2333,"ClientTCPHandshakeDurationMs":12,"ClientTLSCipher":"TLS_AES_128_GCM_SHA256","ClientTLSHandshakeDurationMs":125,"ClientTLSVersion":"TLS 1.3","ConnectionCloseReason":"CLIENT_CLOSED","ConnectionReuse":false,"DestinationTunnelID":"00000000-0000-0000-0000-000000000000","DeviceID":"083a8354-d56c-11ed-9771-6a842b100cff","DeviceName":"zt-test-vm1","EgressColoName":"ORD","EgressIP":"2a02:cf40::23","EgressPort":41052,"EgressRuleID":"00000000-0000-0000-0000-000000000000","EgressRuleName":"Egress Rule 1","Email":"user@test.com","IngressColoName":"ORD","Offramp":"INTERNET","OriginIP":"89.160.20.129","OriginPort":80,"OriginTLSCertificateIssuer":"DigiCert Inc","OriginTLSCertificateValidationResult":"VALID","OriginTLSCipher":"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384","OriginTLSHandshakeDurationMs":130,"OriginTLSVersion":"TLS 1.2","Protocol":"TCP","RuleEvaluationDurationMs":10,"SessionEndTime":"2023-05-04T11:29:14Z","SessionID":"18881f179300007fb0d06d6400000001","SessionStartTime":"2023-05-04T11:29:14Z","SourceInternalIP":"1.128.0.1","SourceIP":"67.43.156.2","SourcePort":52994,"UserID":"166befbb-00e3-5e20-bd6e-27245723949f","VirtualNetworkID":"0ce99869-63d3-4d5d-bdaf-d4f33df964aa"} |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
4 changes: 4 additions & 0 deletions 4 ...s/cloudflare_logpush/data_stream/access_request/_dev/test/pipeline/test-common-config.yml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,4 @@ | ||
| fields: | ||
| tags: | ||
| - preserve_original_event | ||
| - preserve_duplicate_custom_fields |
1 change: 1 addition & 0 deletions 1 ...re_logpush/data_stream/access_request/_dev/test/pipeline/test-pipeline-access-request.log
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {"Action":"login","Allowed":true,"AppDomain":"partner-zt-logs.cloudflareaccess.com/warp","AppUUID":"123e4567-e89b-12d3-a456-426614174000","Connection":"onetimepin","Country":"us","CreatedAt":1684862313000000000,"Email":"user@example.com","IPAddress":"67.43.156.93","PurposeJustificationPrompt":"Please provide your reason for accessing the application.","PurposeJustificationResponse":"I need to access the application for work purposes.","RayID":"00c0ffeeabc12345","TemporaryAccessApprovers":["approver1@example.com","approver2@example.com"],"TemporaryAccessDuration":7200,"UserUID":"166befbb-00e3-5e20-bd6e-27245333949f"} |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.