30 lines
672 B
YAML
30 lines
672 B
YAML
|
|
title: Devo sourcetype mappings for web sources
|
||
|
|
order: 20
|
||
|
|
backends:
|
||
|
|
- devo
|
||
|
|
logsources:
|
||
|
|
web:
|
||
|
|
category: webserver
|
||
|
|
index: web.all.access
|
||
|
|
proxy:
|
||
|
|
category: proxy
|
||
|
|
index: proxy.all.access
|
||
|
|
apache:
|
||
|
|
product: apache
|
||
|
|
index: web.all.access
|
||
|
|
fieldmappings:
|
||
|
|
c-uri: url
|
||
|
|
c-useragent: userAgent
|
||
|
|
sc-status: statusCode
|
||
|
|
useragent: userAgent
|
||
|
|
cs-method: method
|
||
|
|
clientip: srcIp
|
||
|
|
uri_query: select uriquery(url) as url_query
|
||
|
|
r-dns: select urihost(url) as url_dns
|
||
|
|
cs-host: srcHost
|
||
|
|
c-uri-query: select uriquery(url) as url_query
|
||
|
|
c-uri-stem: url
|
||
|
|
c-uri-extension: select uripath(url) as uri_path
|
||
|
|
cs-uri-query: select uriquery(url) as url_query
|
||
|
|
|