|
84 | 84 | "rule.name": "iatisu", |
85 | 85 | "service.type": "snort", |
86 | 86 | "source.bytes": 4512, |
87 | | - "source.ip": "10.38.77.13", |
| 87 | + "source.ip": [ |
| 88 | + "10.38.77.13" |
| 89 | + ], |
88 | 90 | "source.port": 3971, |
89 | 91 | "tags": [ |
90 | 92 | "forwarded", |
|
233 | 235 | "rule.name": "doloremi", |
234 | 236 | "service.type": "snort", |
235 | 237 | "source.bytes": 651, |
236 | | - "source.ip": "10.182.199.231", |
| 238 | + "source.ip": [ |
| 239 | + "10.182.199.231" |
| 240 | + ], |
237 | 241 | "source.port": 4478, |
238 | 242 | "tags": [ |
239 | 243 | "forwarded", |
|
353 | 357 | "rsa.time.event_time_str": "May 22 14:30:33 2016 UTC", |
354 | 358 | "rsa.time.month": "May", |
355 | 359 | "service.type": "snort", |
356 | | - "source.ip": "10.110.31.190", |
| 360 | + "source.ip": [ |
| 361 | + "10.110.31.190" |
| 362 | + ], |
357 | 363 | "tags": [ |
358 | 364 | "forwarded", |
359 | 365 | "snort.log" |
|
845 | 851 | "rsa.time.month": "Dec", |
846 | 852 | "service.type": "snort", |
847 | 853 | "source.geo.country_name": "tur", |
848 | | - "source.ip": "10.182.213.195", |
| 854 | + "source.ip": [ |
| 855 | + "10.182.213.195" |
| 856 | + ], |
849 | 857 | "source.port": 7119, |
850 | 858 | "tags": [ |
851 | 859 | "forwarded", |
|
900 | 908 | "rule.name": "eriam", |
901 | 909 | "service.type": "snort", |
902 | 910 | "source.bytes": 3465, |
903 | | - "source.ip": "10.210.180.142", |
| 911 | + "source.ip": [ |
| 912 | + "10.210.180.142" |
| 913 | + ], |
904 | 914 | "source.port": 3015, |
905 | 915 | "tags": [ |
906 | 916 | "forwarded", |
|
969 | 979 | "rsa.time.day": "20", |
970 | 980 | "rsa.time.month": "Jan", |
971 | 981 | "service.type": "snort", |
972 | | - "source.ip": "10.165.33.19", |
| 982 | + "source.ip": [ |
| 983 | + "10.165.33.19" |
| 984 | + ], |
973 | 985 | "tags": [ |
974 | 986 | "forwarded", |
975 | 987 | "snort.log" |
|
1018 | 1030 | "rsa.time.event_time_str": "Feb 3 21:16:50 2017 UTC", |
1019 | 1031 | "rsa.time.month": "Feb", |
1020 | 1032 | "service.type": "snort", |
1021 | | - "source.ip": "10.52.190.18", |
| 1033 | + "source.ip": [ |
| 1034 | + "10.52.190.18" |
| 1035 | + ], |
1022 | 1036 | "source.port": 4411, |
1023 | 1037 | "tags": [ |
1024 | 1038 | "forwarded", |
|
1070 | 1084 | "rsa.time.event_time_str": "Feb 18 04:19:24 2017 UTC", |
1071 | 1085 | "rsa.time.month": "Feb", |
1072 | 1086 | "service.type": "snort", |
1073 | | - "source.ip": "10.68.233.163", |
| 1087 | + "source.ip": [ |
| 1088 | + "10.68.233.163" |
| 1089 | + ], |
1074 | 1090 | "tags": [ |
1075 | 1091 | "forwarded", |
1076 | 1092 | "snort.log" |
|
1219 | 1235 | "rsa.time.event_time_str": "Apr 16 08:29:41 2017 UTC", |
1220 | 1236 | "rsa.time.month": "Apr", |
1221 | 1237 | "service.type": "snort", |
1222 | | - "source.ip": "10.116.175.84", |
| 1238 | + "source.ip": [ |
| 1239 | + "10.116.175.84" |
| 1240 | + ], |
1223 | 1241 | "tags": [ |
1224 | 1242 | "forwarded", |
1225 | 1243 | "snort.log" |
|
1504 | 1522 | "rule.name": "emagnam", |
1505 | 1523 | "service.type": "snort", |
1506 | 1524 | "source.bytes": 1580, |
1507 | | - "source.ip": "10.240.144.78", |
| 1525 | + "source.ip": [ |
| 1526 | + "10.240.144.78" |
| 1527 | + ], |
1508 | 1528 | "source.port": 2998, |
1509 | 1529 | "tags": [ |
1510 | 1530 | "forwarded", |
|
1649 | 1669 | "rule.name": "temse", |
1650 | 1670 | "service.type": "snort", |
1651 | 1671 | "source.bytes": 470, |
1652 | | - "source.ip": "10.140.209.249", |
| 1672 | + "source.ip": [ |
| 1673 | + "10.140.209.249" |
| 1674 | + ], |
1653 | 1675 | "source.port": 1801, |
1654 | 1676 | "tags": [ |
1655 | 1677 | "forwarded", |
|
1734 | 1756 | "rsa.time.event_time_str": "Nov 2 11:05:41 2017 UTC", |
1735 | 1757 | "rsa.time.month": "Nov", |
1736 | 1758 | "service.type": "snort", |
1737 | | - "source.ip": "10.198.44.231", |
| 1759 | + "source.ip": [ |
| 1760 | + "10.198.44.231" |
| 1761 | + ], |
1738 | 1762 | "tags": [ |
1739 | 1763 | "forwarded", |
1740 | 1764 | "snort.log" |
|
1788 | 1812 | "rule.name": "ffici", |
1789 | 1813 | "service.type": "snort", |
1790 | 1814 | "source.bytes": 3273, |
1791 | | - "source.ip": "10.77.86.215", |
| 1815 | + "source.ip": [ |
| 1816 | + "10.77.86.215" |
| 1817 | + ], |
1792 | 1818 | "source.port": 5913, |
1793 | 1819 | "tags": [ |
1794 | 1820 | "forwarded", |
|
2113 | 2139 | "rsa.time.event_time_str": "Mar 25 09:31:24 2018 UTC", |
2114 | 2140 | "rsa.time.month": "Mar", |
2115 | 2141 | "service.type": "snort", |
2116 | | - "source.ip": "10.28.105.106", |
| 2142 | + "source.ip": [ |
| 2143 | + "10.28.105.106" |
| 2144 | + ], |
2117 | 2145 | "tags": [ |
2118 | 2146 | "forwarded", |
2119 | 2147 | "snort.log" |
|
2223 | 2251 | "rsa.time.day": "7", |
2224 | 2252 | "rsa.time.month": "May", |
2225 | 2253 | "service.type": "snort", |
2226 | | - "source.ip": "10.166.40.137", |
| 2254 | + "source.ip": [ |
| 2255 | + "10.166.40.137" |
| 2256 | + ], |
2227 | 2257 | "source.nat.ip": "10.65.144.119", |
2228 | 2258 | "source.nat.port": 6233, |
2229 | 2259 | "source.port": 5279, |
|
2264 | 2294 | "rsa.time.day": "21", |
2265 | 2295 | "rsa.time.month": "May", |
2266 | 2296 | "service.type": "snort", |
2267 | | - "source.ip": "10.104.78.147", |
| 2297 | + "source.ip": [ |
| 2298 | + "10.104.78.147" |
| 2299 | + ], |
2268 | 2300 | "tags": [ |
2269 | 2301 | "forwarded", |
2270 | 2302 | "snort.log" |
|
2302 | 2334 | "rsa.time.day": "4", |
2303 | 2335 | "rsa.time.month": "Jun", |
2304 | 2336 | "service.type": "snort", |
2305 | | - "source.ip": "10.237.43.87", |
| 2337 | + "source.ip": [ |
| 2338 | + "10.237.43.87" |
| 2339 | + ], |
2306 | 2340 | "tags": [ |
2307 | 2341 | "forwarded", |
2308 | 2342 | "snort.log" |
|
2355 | 2389 | "rsa.time.month": "Jun", |
2356 | 2390 | "service.type": "snort", |
2357 | 2391 | "source.geo.country_name": "eos", |
2358 | | - "source.ip": "10.234.234.205", |
| 2392 | + "source.ip": [ |
| 2393 | + "10.234.234.205" |
| 2394 | + ], |
2359 | 2395 | "source.port": 5714, |
2360 | 2396 | "tags": [ |
2361 | 2397 | "forwarded", |
|
2440 | 2476 | "rule.name": "iconseq", |
2441 | 2477 | "service.type": "snort", |
2442 | 2478 | "source.bytes": 1259, |
2443 | | - "source.ip": "10.40.250.209", |
| 2479 | + "source.ip": [ |
| 2480 | + "10.40.250.209" |
| 2481 | + ], |
2444 | 2482 | "source.port": 3941, |
2445 | 2483 | "tags": [ |
2446 | 2484 | "forwarded", |
|
2512 | 2550 | "rsa.time.day": "15", |
2513 | 2551 | "rsa.time.month": "Aug", |
2514 | 2552 | "service.type": "snort", |
2515 | | - "source.ip": "10.198.202.72", |
| 2553 | + "source.ip": [ |
| 2554 | + "10.198.202.72" |
| 2555 | + ], |
2516 | 2556 | "tags": [ |
2517 | 2557 | "forwarded", |
2518 | 2558 | "snort.log" |
|
2566 | 2606 | "rsa.time.event_time_str": "Aug 29 14:59:40 2018 UTC", |
2567 | 2607 | "rsa.time.month": "Aug", |
2568 | 2608 | "service.type": "snort", |
2569 | | - "source.ip": "10.147.155.100", |
| 2609 | + "source.ip": [ |
| 2610 | + "10.147.155.100" |
| 2611 | + ], |
2570 | 2612 | "tags": [ |
2571 | 2613 | "forwarded", |
2572 | 2614 | "snort.log" |
|
2617 | 2659 | "rsa.time.event_time_str": "Sep 12 22:02:15 2018 UTC", |
2618 | 2660 | "rsa.time.month": "Sep", |
2619 | 2661 | "service.type": "snort", |
2620 | | - "source.ip": "10.4.147.70", |
| 2662 | + "source.ip": [ |
| 2663 | + "10.4.147.70" |
| 2664 | + ], |
2621 | 2665 | "source.port": 3210, |
2622 | 2666 | "tags": [ |
2623 | 2667 | "forwarded", |
|
2759 | 2803 | "rsa.time.day": "9", |
2760 | 2804 | "rsa.time.month": "Nov", |
2761 | 2805 | "service.type": "snort", |
2762 | | - "source.ip": "10.224.250.83", |
| 2806 | + "source.ip": [ |
| 2807 | + "10.224.250.83" |
| 2808 | + ], |
2763 | 2809 | "tags": [ |
2764 | 2810 | "forwarded", |
2765 | 2811 | "snort.log" |
|
2810 | 2856 | "rsa.time.month": "Nov", |
2811 | 2857 | "service.type": "snort", |
2812 | 2858 | "source.geo.country_name": "ipi", |
2813 | | - "source.ip": "10.38.22.60", |
| 2859 | + "source.ip": [ |
| 2860 | + "10.38.22.60" |
| 2861 | + ], |
2814 | 2862 | "source.port": 653, |
2815 | 2863 | "tags": [ |
2816 | 2864 | "forwarded", |
|
2865 | 2913 | "rule.name": "tlab", |
2866 | 2914 | "service.type": "snort", |
2867 | 2915 | "source.bytes": 42, |
2868 | | - "source.ip": "10.46.57.181", |
| 2916 | + "source.ip": [ |
| 2917 | + "10.46.57.181" |
| 2918 | + ], |
2869 | 2919 | "source.port": 3760, |
2870 | 2920 | "tags": [ |
2871 | 2921 | "forwarded", |
|
3020 | 3070 | "rule.name": "Secti", |
3021 | 3071 | "service.type": "snort", |
3022 | 3072 | "source.bytes": 4673, |
3023 | | - "source.ip": "10.107.144.80", |
| 3073 | + "source.ip": [ |
| 3074 | + "10.107.144.80" |
| 3075 | + ], |
3024 | 3076 | "source.port": 703, |
3025 | 3077 | "tags": [ |
3026 | 3078 | "forwarded", |
|
3126 | 3178 | "rsa.time.day": "17", |
3127 | 3179 | "rsa.time.month": "Mar", |
3128 | 3180 | "service.type": "snort", |
3129 | | - "source.ip": "10.198.207.31", |
| 3181 | + "source.ip": [ |
| 3182 | + "10.198.207.31" |
| 3183 | + ], |
3130 | 3184 | "source.port": 579, |
3131 | 3185 | "tags": [ |
3132 | 3186 | "forwarded", |
|
3388 | 3442 | "rule.name": "itsed", |
3389 | 3443 | "service.type": "snort", |
3390 | 3444 | "source.bytes": 2005, |
3391 | | - "source.ip": "10.154.87.98", |
| 3445 | + "source.ip": [ |
| 3446 | + "10.154.87.98" |
| 3447 | + ], |
3392 | 3448 | "source.port": 2632, |
3393 | 3449 | "tags": [ |
3394 | 3450 | "forwarded", |
|
3443 | 3499 | "rule.name": "dantiu", |
3444 | 3500 | "service.type": "snort", |
3445 | 3501 | "source.bytes": 4338, |
3446 | | - "source.ip": "10.35.59.140", |
| 3502 | + "source.ip": [ |
| 3503 | + "10.35.59.140" |
| 3504 | + ], |
3447 | 3505 | "source.port": 1832, |
3448 | 3506 | "tags": [ |
3449 | 3507 | "forwarded", |
|
3613 | 3671 | "rsa.time.day": "19", |
3614 | 3672 | "rsa.time.month": "Sep", |
3615 | 3673 | "service.type": "snort", |
3616 | | - "source.ip": "10.14.46.141", |
| 3674 | + "source.ip": [ |
| 3675 | + "10.14.46.141" |
| 3676 | + ], |
3617 | 3677 | "tags": [ |
3618 | 3678 | "forwarded", |
3619 | 3679 | "snort.log" |
|
3798 | 3858 | "rsa.time.day": "30", |
3799 | 3859 | "rsa.time.month": "Nov", |
3800 | 3860 | "service.type": "snort", |
3801 | | - "source.ip": "10.125.130.61", |
| 3861 | + "source.ip": [ |
| 3862 | + "10.125.130.61" |
| 3863 | + ], |
3802 | 3864 | "source.nat.ip": "10.32.195.34", |
3803 | 3865 | "source.nat.port": 135, |
3804 | 3866 | "source.port": 6154, |
|
3839 | 3901 | "rsa.time.day": "14", |
3840 | 3902 | "rsa.time.month": "Dec", |
3841 | 3903 | "service.type": "snort", |
3842 | | - "source.ip": "10.188.88.133", |
| 3904 | + "source.ip": [ |
| 3905 | + "10.188.88.133" |
| 3906 | + ], |
3843 | 3907 | "tags": [ |
3844 | 3908 | "forwarded", |
3845 | 3909 | "snort.log" |
|
0 commit comments