diff --git a/content/parsers/third_party/community/AWARE_AUDIT_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/AWARE_AUDIT_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..cf58480bfb --- /dev/null +++ b/content/parsers/third_party/community/AWARE_AUDIT_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,173 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "additional": { + "betweenParticipants_query_type": "user", + "completedOn": "2024-10-12T10:05:00Z", + "contentDateRange_query_type": "range", + "contentDateRange_query_value_endDate": "2024-10-12", + "contentDateRange_query_value_startDate": "2024-10-01", + "dataAccessSetId": "das-101", + "discoveryRequestModelId": "req-101", + "expectedSearchResultCount": "25", + "format": "JSON", + "includeAiSummaries": "false", + "isDeleted": "false", + "keywordQueryExpression": "confidential_project", + "name": "Audit Search 1", + "participants_query_type": "user", + "platformModelId_0": "pm-101", + "platformTarget_0": "cloud_storage", + "reportType": "AUDIT_SUMMARY", + "requestedOn": "2024-10-12T10:00:00Z", + "requestor": "dummy_requestor_01", + "requestorEmail": "dummy_requestor_01@dummy.net", + "type": "chat_messages" + }, + "metadata": { + "description": "DiscoveryAudit", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "AWARE_AUDIT", + "productDeploymentId": "tenant-001", + "productEventType": "DISCOVERY_SEARCH", + "productName": "AWARE_AUDIT", + "vendorName": "AWARE_AUDIT" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.1" + ] + }, + "ip": [ + "1.1.1.1" + ], + "user": { + "emailAddresses": [ + "dummy_analyst_01@dummy.net" + ], + "userid": "dummy_analyst_01" + } + }, + "securityResult": [ + { + "detectionFields": [ + { + "key": "scope_0", + "value": "internal" + }, + { + "key": "includedDataInsightTypes_0", + "value": "chat_messages" + } + ], + "summary": "User executed discovery keyword search" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "additional": { + "completedOn": "2024-10-12T11:02:00Z", + "format": "CSV", + "includeAiSummaries": "false", + "isDeleted": "false", + "name": "Export Audit 2", + "requestedOn": "2024-10-12T11:00:00Z", + "type": "EXPORT" + }, + "metadata": { + "description": "ExportAudit", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "AWARE_AUDIT", + "productDeploymentId": "tenant-002", + "productEventType": "DATA_EXPORT", + "productName": "AWARE_AUDIT", + "vendorName": "AWARE_AUDIT" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.2" + ] + }, + "ip": [ + "1.1.1.2" + ], + "user": { + "emailAddresses": [ + "dummy_admin_02@dummy.net" + ], + "userid": "dummy_admin_02" + } + }, + "securityResult": [ + { + "summary": "Exported compliance report archive" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "additional": { + "completedOn": "2024-10-12T12:01:00Z", + "isDeleted": "false", + "name": "Policy Update 3", + "requestedOn": "2024-10-12T12:00:00Z", + "type": "ADMIN_ACTION" + }, + "metadata": { + "description": "PolicyUpdateAudit", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "AWARE_AUDIT", + "productDeploymentId": "tenant-003", + "productEventType": "POLICY_UPDATE", + "productName": "AWARE_AUDIT", + "vendorName": "AWARE_AUDIT" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.3" + ] + }, + "ip": [ + "1.1.1.3" + ], + "user": { + "emailAddresses": [ + "dummy_secops_03@dummy.net" + ], + "userid": "dummy_secops_03" + } + }, + "securityResult": [ + { + "summary": "Updated retention policy settings" + } + ] + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/AWARE_AUDIT_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/AWARE_AUDIT_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..ac29d831c3 --- /dev/null +++ b/content/parsers/third_party/community/AWARE_AUDIT_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,17 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "{\"id\": \"usr-101\", \"tenantId\": \"tenant-001\", \"userName\": \"dummy_analyst_01\", \"emailAddress\": \"dummy_analyst_01@dummy.net\", \"sourceIp\": \"1.1.1.1\", \"auditName\": \"DiscoveryAudit\", \"actionName\": \"DISCOVERY_SEARCH\", \"actionSummary\": \"User executed discovery keyword search\", \"discoveryRequestModelId\": \"req-101\", \"requestor\": \"dummy_requestor_01\", \"requestorEmail\": \"dummy_requestor_01@dummy.net\", \"criteria\": {\"keywordQueryExpression\": \"confidential_project\", \"groupCriteria\": {\"groups\": \"SecOps_Team\"}, \"platformCriteria\": {\"platforms\": [{\"platformModelId\": \"pm-101\", \"platformTarget\": \"cloud_storage\", \"scope\": [\"internal\"]}]}, \"participants\": {\"query\": {\"type\": \"user\", \"value\": {\"userIds\": \"dummy_user_02\", \"emailAddresses\": \"dummy_user_02@dummy.net\"}}}, \"betweenParticipants\": {\"query\": {\"type\": \"user\", \"value\": {\"userIds\": \"dummy_user_03\", \"emailAddresses\": \"dummy_user_03@dummy.net\"}}}, \"contentDateRange\": {\"query\": {\"type\": \"range\", \"value\": {\"startDate\": \"2024-10-01\", \"endDate\": \"2024-10-12\"}}}}, \"requestedOn\": \"2024-10-12T10:00:00Z\", \"includedDataInsightTypes\": [\"chat_messages\"], \"name\": \"Audit Search 1\", \"type\": \"COMPLIANCE_SEARCH\", \"format\": \"JSON\", \"expectedSearchResultCount\": \"25\", \"reportType\": \"AUDIT_SUMMARY\", \"completedOn\": \"2024-10-12T10:05:00Z\", \"isDeleted\": \"false\", \"dataAccessSetId\": \"das-101\", \"includeAiSummaries\": \"false\"}" + }, + { + "data": "{\"id\": \"usr-102\", \"tenantId\": \"tenant-002\", \"userName\": \"dummy_admin_02\", \"emailAddress\": \"dummy_admin_02@dummy.net\", \"sourceIp\": \"1.1.1.2\", \"auditName\": \"ExportAudit\", \"actionName\": \"DATA_EXPORT\", \"actionSummary\": \"Exported compliance report archive\", \"requestedOn\": \"2024-10-12T11:00:00Z\", \"name\": \"Export Audit 2\", \"type\": \"EXPORT\", \"format\": \"CSV\", \"completedOn\": \"2024-10-12T11:02:00Z\", \"isDeleted\": \"false\", \"includeAiSummaries\": \"false\"}" + }, + { + "data": "{\"id\": \"usr-103\", \"tenantId\": \"tenant-003\", \"userName\": \"dummy_secops_03\", \"emailAddress\": \"dummy_secops_03@dummy.net\", \"sourceIp\": \"1.1.1.3\", \"auditName\": \"PolicyUpdateAudit\", \"actionName\": \"POLICY_UPDATE\", \"actionSummary\": \"Updated retention policy settings\", \"requestedOn\": \"2024-10-12T12:00:00Z\", \"name\": \"Policy Update 3\", \"type\": \"ADMIN_ACTION\", \"completedOn\": \"2024-10-12T12:01:00Z\", \"isDeleted\": \"false\"}" + } + ], + "type": "AWARE_AUDIT" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/AWS_REDSHIFT_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/AWS_REDSHIFT_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..1b2c57f75b --- /dev/null +++ b/content/parsers/third_party/community/AWS_REDSHIFT_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,380 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "AWS_REDSHIFT", + "productEventType": "set" + }, + "network": { + "applicationProtocolVersion": "3.0", + "sessionDuration": "120s", + "sessionId": "sess-892348", + "tls": { + "cipher": "ECDHE-RSA-AES256-GCM-SHA384", + "version": "TLSv1.3" + } + }, + "principal": { + "application": "psql", + "asset": { + "ip": [ + "1.1.1.1" + ] + }, + "ip": [ + "1.1.1.1" + ], + "platformVersion": "x86_64-linux", + "process": { + "pid": "29381" + } + }, + "securityResult": [ + { + "detectionFields": [ + { + "key": "authmethod", + "value": "password" + }, + { + "key": "mtu", + "value": "1500" + }, + { + "key": "ssl_compression", + "value": "OFF" + }, + { + "key": "ssl_expansion", + "value": "OFF" + }, + { + "key": "iamauthguid", + "value": "iam-auth-guid-1234" + }, + { + "key": "driver_version", + "value": "1.4.15" + }, + { + "key": "plugin_name", + "value": "redshift-odbc" + }, + { + "key": "compression", + "value": "LZ4" + } + ] + } + ], + "target": { + "resource": { + "name": "dev_db", + "type": "DATABASE" + }, + "user": { + "userDisplayName": "dummy_user_01" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "AWS_REDSHIFT" + }, + "network": { + "sessionId": "89211" + }, + "principal": { + "process": { + "pid": "14022" + } + }, + "target": { + "resource": { + "attribute": { + "labels": [ + { + "key": "time_zone", + "value": "UTC" + }, + { + "key": "sql_query", + "value": "SELECT * FROM audit_table;" + } + ] + }, + "name": "analytics_db", + "type": "DATABASE" + }, + "user": { + "userDisplayName": "dummy_analyst" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "additional": { + "func": "pg_catalog.pg_stat_activity", + "lpclagg": "cluster-agg-01", + "lpcltype": "node-cluster-type" + }, + "metadata": { + "description": "Table scan threshold exceeded", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "AWS_REDSHIFT", + "productLogId": "req-8921-abcd-ef01" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.2" + ] + }, + "ip": [ + "1.1.1.2" + ], + "location": { + "name": "us-east-1" + }, + "user": { + "userid": "123456789012" + } + }, + "securityResult": [ + { + "severity": "ERROR" + } + ], + "target": { + "file": { + "fullPath": "/var/log/redshift/audit.log" + }, + "resource": { + "attribute": { + "labels": [ + { + "key": "expectedBucket", + "value": "masked-audit-bucket" + }, + { + "key": "expectedS3Prefix", + "value": "redshift-logs/2024/" + } + ] + }, + "name": "redshift-cluster-masked" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "AWS_REDSHIFT" + }, + "principal": { + "asset": { + "hostname": "redshift-hostname.internal" + }, + "hostname": "redshift-hostname.internal" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "AWS_REDSHIFT" + }, + "network": { + "sessionId": "300" + }, + "principal": { + "process": { + "pid": "5555" + } + }, + "target": { + "resource": { + "attribute": { + "labels": [ + { + "key": "time_zone", + "value": "UTC" + }, + { + "key": "sql_query", + "value": "SELECT 1;" + } + ] + }, + "name": "dev", + "type": "DATABASE" + }, + "user": { + "userDisplayName": "dummy_user" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Connection health check completed", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "AWS_REDSHIFT" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.3" + ] + }, + "ip": [ + "1.1.1.3" + ], + "location": { + "name": "eu-west-1" + } + }, + "securityResult": [ + { + "severity": "INFORMATIONAL" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "User exceeded soft query quota limit", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "AWS_REDSHIFT", + "productLogId": "req-warning-9988" + }, + "principal": { + "user": { + "userid": "987654321098" + } + }, + "securityResult": [ + { + "severity": "MEDIUM" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "additional": { + "func": "pg_catalog.pg_database" + }, + "metadata": { + "description": "Routine system maintenance finished", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "AWS_REDSHIFT", + "productLogId": "req-generic-0011" + }, + "target": { + "file": { + "fullPath": "/var/log/redshift/system.log" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "AWS_REDSHIFT", + "productEventType": "set" + }, + "target": { + "resource": { + "name": "dev_db", + "type": "DATABASE" + }, + "user": { + "userDisplayName": "dummy_service_user" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "AWS_REDSHIFT", + "productEventType": "disconnect" + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/AWS_REDSHIFT_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/AWS_REDSHIFT_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..415d961bea --- /dev/null +++ b/content/parsers/third_party/community/AWS_REDSHIFT_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,35 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "{\"records\":[\"set|2024-10-12T10:00:00.000Z|1.1.1.1|5439|29381|dev_db|dummy_user_01|password|120|TLSv1.3|ECDHE-RSA-AES256-GCM-SHA384|1500|OFF|OFF|iam-auth-guid-1234|psql|x86_64-linux|1.4.15|redshift-odbc|3.0|sess-892348|LZ4\",\"'2024-10-12T10:00:00.000Z UTC [db=analytics_db user=dummy_analyst pid=14022 userid=1001 xid=89211]' LOG:SELECT * FROM audit_table;\"]}" + }, + { + "data": "{\"accountID\":\"123456789012\",\"ClusterIdentifier\":\"redshift-cluster-masked\",\"expectedBucket\":\"masked-audit-bucket\",\"expectedS3Prefix\":\"redshift-logs/2024/\",\"file\":\"/var/log/redshift/audit.log\",\"func\":\"pg_catalog.pg_stat_activity\",\"event\":{\"src_ip\":\"1.1.1.2\"},\"level\":\"Error\",\"lpclagg\":\"cluster-agg-01\",\"lpcltype\":\"node-cluster-type\",\"msg\":\"Table scan threshold exceeded\",\"region\":\"us-east-1\",\"requestID\":\"req-8921-abcd-ef01\"}" + }, + { + "data": "{\"records\":[\" |2024-10-12T10:00:00.000Z|redshift-hostname.internal|invalid_port||||||||0||||||||0||(null) \"]}" + }, + { + "data": "'2024-10-12T10:00:00.000Z UTC [db=dev user=dummy_user pid=5555 userid=200 xid=300]' LOG:SELECT 1;" + }, + { + "data": "{\"event\":{\"src_ip\":\"1.1.1.3\"},\"level\":\"Info\",\"msg\":\"Connection health check completed\",\"region\":\"eu-west-1\"}" + }, + { + "data": "{\"accountID\":\"987654321098\",\"level\":\"Warning\",\"msg\":\"User exceeded soft query quota limit\",\"requestID\":\"req-warning-9988\"}" + }, + { + "data": "{\"file\":\"/var/log/redshift/system.log\",\"func\":\"pg_catalog.pg_database\",\"msg\":\"Routine system maintenance finished\",\"requestID\":\"req-generic-0011\"}" + }, + { + "data": "{\"records\":[\"set|2024-10-12T10:00:00.000Z||||dev_db|dummy_service_user||||||||||||||\"]}" + }, + { + "data": "{\"records\":[\"disconnect|2024-10-12T10:00:00.000Z||||||||||||||||||||\"]}" + } + ], + "type": "AWS_REDSHIFT" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/AWS_VPC_TRANSIT_GATEWAY_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/AWS_VPC_TRANSIT_GATEWAY_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..f0f346327c --- /dev/null +++ b/content/parsers/third_party/community/AWS_VPC_TRANSIT_GATEWAY_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,369 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "additional": { + "ip_version": "IPv4", + "packets_lostblackhole": "0", + "packets_lostmtuexceeded": "0", + "packets_lostnoroute": "0", + "packets_lostttl": "0", + "tcpflags": "2", + "tgw_attachment_id": "tgw-attach-0123456789abcdef0", + "tgw_id": "tgw-0123456789abcdef0", + "tgw_pair_attachment_id": "tgw-attach-pair12345" + }, + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "NETWORK_CONNECTION", + "logType": "AWS_VPC_TRANSIT_GATEWAY", + "productLogId": "123456789012", + "productName": "AWS VPC Transit Gateway", + "productVersion": "2", + "vendorName": "AWS" + }, + "network": { + "direction": "INBOUND" + }, + "principal": { + "asset": { + "assetId": "ASSET_ID: eni-0123456789abcdef0", + "ip": [ + "1.1.1.1" + ] + }, + "assetId": "ASSET_ID: eni-0123456789abcdef0", + "ip": [ + "1.1.1.1" + ], + "location": { + "countryOrRegion": "us-east-1" + }, + "resource": { + "attribute": { + "labels": [ + { + "key": "tgw_src_az_id", + "value": "use1-az1" + }, + { + "key": "pkt_srcawsservice", + "value": "dummy_service" + } + ] + }, + "name": "subnet-0123456789abcdef0", + "productObjectId": "vpc-0123456789abcdef0", + "resourceSubtype": "TransitGateway" + }, + "user": { + "userid": "123456789012" + } + }, + "securityResult": [ + { + "action": [ + "ALLOW" + ], + "detectionFields": [ + { + "key": "protocolnumber", + "value": "6" + } + ] + } + ], + "target": { + "asset": { + "assetId": "ASSET_ID: eni-abcdef01234567890", + "ip": [ + "1.1.1.2" + ] + }, + "assetId": "ASSET_ID: eni-abcdef01234567890", + "ip": [ + "1.1.1.2" + ], + "location": { + "countryOrRegion": "use1-az2" + }, + "resource": { + "attribute": { + "labels": [ + { + "key": "pkt_dstaws_service", + "value": "dummy_service" + } + ] + }, + "name": "subnet-abcdef01234567890", + "productObjectId": "vpc-abcdef01234567890" + }, + "user": { + "userid": "210987654321" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "NETWORK_CONNECTION", + "logType": "AWS_VPC_TRANSIT_GATEWAY", + "productLogId": "123456789012", + "productName": "AWS VPC Transit Gateway", + "vendorName": "AWS" + }, + "network": { + "direction": "OUTBOUND" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.3" + ] + }, + "ip": [ + "1.1.1.3" + ] + }, + "target": { + "asset": { + "ip": [ + "1.1.1.3" + ] + }, + "ip": [ + "1.1.1.3" + ] + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "AWS_VPC_TRANSIT_GATEWAY", + "productLogId": "123456789012", + "productName": "AWS VPC Transit Gateway", + "productVersion": "2", + "vendorName": "AWS" + }, + "principal": { + "location": { + "countryOrRegion": "use1-az1" + }, + "resource": { + "resourceSubtype": "TransitGateway" + }, + "user": { + "userid": "123456789012" + } + }, + "target": { + "location": { + "countryOrRegion": "use1-az2" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:01:00Z", + "idm": { + "readOnlyUdm": { + "additional": { + "ip_version": "IPv4", + "packets_lostblackhole": "0", + "packets_lostmtuexceeded": "0", + "packets_lostnoroute": "0", + "packets_lostttl": "0", + "starttime": "1728727200", + "tcpflags": "SYN", + "tgw_attachment_id": "tgw-attach-0123456789abcdef0", + "tgw_id": "tgw-0123456789abcdef0", + "tgw_pair_attachment_id": "tgw-attach-pair12345" + }, + "metadata": { + "eventTimestamp": "2024-10-12T10:01:00Z", + "eventType": "NETWORK_CONNECTION", + "logType": "AWS_VPC_TRANSIT_GATEWAY", + "productLogId": "123456789012", + "productName": "AWS VPC Transit Gateway", + "productVersion": "2", + "vendorName": "AWS" + }, + "network": { + "direction": "INBOUND", + "sentBytes": "1024", + "sentPackets": "20" + }, + "principal": { + "asset": { + "assetId": "ASSET_ID: eni-0123456789abcdef0", + "ip": [ + "1.1.1.1" + ] + }, + "assetId": "ASSET_ID: eni-0123456789abcdef0", + "ip": [ + "1.1.1.1" + ], + "location": { + "countryOrRegion": "us-east-1" + }, + "port": 443, + "resource": { + "attribute": { + "labels": [ + { + "key": "tgw_src_az_id", + "value": "use1-az1" + }, + { + "key": "pkt_srcawsservice", + "value": "dummy_service" + } + ] + }, + "name": "subnet-0123456789abcdef0", + "productObjectId": "vpc-0123456789abcdef0", + "resourceSubtype": "TransitGateway" + }, + "user": { + "userid": "123456789012" + } + }, + "securityResult": [ + { + "action": [ + "ALLOW" + ], + "detectionFields": [ + { + "key": "protocolnumber", + "value": "6" + } + ] + } + ], + "target": { + "asset": { + "assetId": "ASSET_ID: eni-abcdef01234567890", + "ip": [ + "1.1.1.2" + ] + }, + "assetId": "ASSET_ID: eni-abcdef01234567890", + "ip": [ + "1.1.1.2" + ], + "location": { + "countryOrRegion": "use1-az2" + }, + "port": 80, + "resource": { + "attribute": { + "labels": [ + { + "key": "pkt_dstaws_service", + "value": "dummy_service" + } + ] + }, + "name": "subnet-abcdef01234567890", + "productObjectId": "vpc-abcdef01234567890" + }, + "user": { + "userid": "210987654321" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:01:00Z", + "idm": { + "readOnlyUdm": { + "additional": { + "packets_lostblackhole": "0", + "packets_lostmtuexceeded": "0", + "packets_lostnoroute": "-", + "packets_lostttl": "0", + "starttime": "1728727200", + "tgw_attachment_id": "tgw-attach-0123456789abcdef0", + "tgw_id": "tgw-0123456789abcdef0" + }, + "metadata": { + "eventTimestamp": "2024-10-12T10:01:00Z", + "eventType": "GENERIC_EVENT", + "logType": "AWS_VPC_TRANSIT_GATEWAY", + "productLogId": "123456789012", + "productName": "AWS VPC Transit Gateway", + "productVersion": "2", + "vendorName": "AWS" + }, + "principal": { + "location": { + "countryOrRegion": "us-east-1" + }, + "resource": { + "resourceSubtype": "TransitGateway" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "AWS_VPC_TRANSIT_GATEWAY", + "productLogId": "123456789012", + "productName": "AWS VPC Transit Gateway", + "productVersion": "2", + "vendorName": "AWS" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.1" + ] + }, + "ip": [ + "1.1.1.1" + ], + "resource": { + "resourceSubtype": "TransitGateway" + } + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/AWS_VPC_TRANSIT_GATEWAY_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/AWS_VPC_TRANSIT_GATEWAY_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..2dab7a17e6 --- /dev/null +++ b/content/parsers/third_party/community/AWS_VPC_TRANSIT_GATEWAY_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,26 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "{\"version\":\"2\",\"resource_type\":\"TransitGateway\",\"account_id\":\"123456789012\",\"tgw_id\":\"tgw-0123456789abcdef0\",\"tgw_attachment_id\":\"tgw-attach-0123456789abcdef0\",\"tgw_src_vpc_account_id\":\"123456789012\",\"tgw_dst_vpc_account_id\":\"210987654321\",\"tgw_src_vpc_id\":\"vpc-0123456789abcdef0\",\"tgw_dst_vpc_id\":\"vpc-abcdef01234567890\",\"tgw_src_subnet_id\":\"subnet-0123456789abcdef0\",\"tgw_dst_subnet_id\":\"subnet-abcdef01234567890\",\"tgw_src_eni\":\"eni-0123456789abcdef0\",\"tgw_dst_eni\":\"eni-abcdef01234567890\",\"tgw_src_az_id\":\"use1-az1\",\"tgw_dst_az_id\":\"use1-az2\",\"tgw_pair_attachment_id\":\"tgw-attach-pair12345\",\"region\":\"us-east-1\",\"srcaddr\":\"1.1.1.1\",\"dstaddr\":\"1.1.1.2\",\"srcport\":443,\"dstport\":80,\"protocol\":6,\"packets\":20,\"bytes\":1024,\"start_time\":1728727200,\"end_time\":1728727260,\"log_status\":\"OK\",\"type\":\"IPv4\",\"packets_lost_no_route\":0,\"packets_lost_blackhole\":0,\"packets_lost_mtu_exceeded\":0,\"packets_lost_ttl_expired\":0,\"tcp_flags\":\"2\",\"flow_direction\":\"ingress\",\"pkt_src_aws_service\":\"dummy_service\",\"pkt_dst_aws_service\":\"dummy_service\"}" + }, + { + "data": "{\"protocol\":{\"bad\":\"struct\"},\"packets_lost_no_route\":[\"bad_arr\"],\"packets_lost_blackhole\":{\"bad\":\"struct\"},\"packets_lost_mtu_exceeded\":[\"bad_arr\"],\"packets_lost_ttl_expired\":{\"bad\":\"struct\"},\"tcp_flags\":[\"bad_arr\"],\"srcport\":443,\"dstport\":80,\"packets\":10,\"bytes\":100,\"end_time\":\"not_a_unix_timestamp\",\"srcaddr\":\"1.1.1.3\",\"dstaddr\":\"1.1.1.3\",\"flow_direction\":\"egress\",\"log_status\":\"NODATA\",\"account_id\":\"123456789012\"}" + }, + { + "data": "{\"version\":\"2\",\"resource_type\":\"TransitGateway\",\"account_id\":\"123456789012\",\"tgw_src_vpc_account_id\":\"123456789012\",\"tgw_dst_az_id\":\"use1-az2\",\"tgw_src_az_id\":\"use1-az1\",\"region\":\"\",\"srcaddr\":\"\",\"dstaddr\":\"\",\"tgw_id\":\"\",\"tgw_attachment_id\":\"\",\"srcport\":\"\",\"dstport\":\"\",\"protocol\":\"\",\"packets\":\"\",\"bytes\":\"\",\"start_time\":\"\",\"type\":\"-\",\"tcp_flags\":\"null\",\"pkt_src_aws_service\":\"-\",\"pkt_dst_aws_service\":\"null\"}" + }, + { + "data": "2 TransitGateway 123456789012 tgw-0123456789abcdef0 tgw-attach-0123456789abcdef0 123456789012 210987654321 vpc-0123456789abcdef0 vpc-abcdef01234567890 subnet-0123456789abcdef0 subnet-abcdef01234567890 eni-0123456789abcdef0 eni-abcdef01234567890 use1-az1 use1-az2 tgw-attach-pair12345 1.1.1.1 1.1.1.2 443 80 6 20 1024 1728727200 1728727260 OK IPv4 0 0 0 0 SYN us-east-1 ingress dummy_service dummy_service" + }, + { + "data": "2 TransitGateway 123456789012 tgw-0123456789abcdef0 tgw-attach-0123456789abcdef0 1728727200 1728727260 NODATA - - 0 0 0 - us-east-1 - - -" + }, + { + "data": "{\"version\":\"2\",\"resource_type\":\"TransitGateway\",\"account_id\":\"123456789012\",\"srcaddr\":\"1.1.1.1\",\"start_time\":1728727200,\"end_time\":1728727260}" + } + ], + "type": "AWS_VPC_TRANSIT_GATEWAY" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/CITRIX_MONITOR_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/CITRIX_MONITOR_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..d9188c06ca --- /dev/null +++ b/content/parsers/third_party/community/CITRIX_MONITOR_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,189 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "additional": { + "userid": "1001" + }, + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_UNCATEGORIZED", + "ingestionLabels": [ + { + "key": "LogOnDuration", + "value": "42" + }, + { + "key": "SessionKey", + "value": "sess-key-9999" + }, + { + "key": "ConnectionState", + "value": "1" + } + ], + "logType": "CITRIX_MONITOR", + "productName": "CITRIX_MONITOR", + "productVersion": "1.1.1.2", + "vendorName": "CITRIX_MONITOR" + }, + "network": { + "dnsDomain": "vdi01.dummy.com", + "http": { + "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" + }, + "sessionId": "54321" + }, + "principal": { + "administrativeDomain": "vdi-domain-01", + "asset": { + "assetId": "MachineId:mach-id-1001", + "hostname": "srv-host-01.example.local", + "ip": [ + "1.1.1.1", + "1.1.1.3", + "1.1.1.4" + ] + }, + "assetId": "MachineId:mach-id-1001", + "hostname": "srv-host-01.example.local", + "ip": [ + "1.1.1.1", + "1.1.1.3", + "1.1.1.4" + ], + "user": { + "emailAddresses": [ + "test_user1@dummy.com", + "test_user2@dummy.com" + ], + "userDisplayName": "Masked User Display Name", + "windowsSid": "S-1-5-21-123456789-123456789-123456789-1001" + } + }, + "target": { + "administrativeDomain": "corp.example.local", + "application": "TestApp", + "asset": { + "ip": [ + "1.1.1.5" + ] + }, + "ip": [ + "1.1.1.5" + ], + "platform": "WINDOWS", + "process": { + "file": { + "fullPath": "C:\\Program Files\\App\\app.exe", + "md5": "e4d909c290d0fb1ca068ffadd08220ec" + }, + "parentProcess": { + "file": { + "fullPath": "C:\\Program Files\\Admin" + } + } + }, + "user": { + "emailAddresses": [ + "target_user@dummy.com" + ], + "userDisplayName": "Target User Full Name", + "userid": "test_target_user", + "windowsSid": "S-1-5-21-987654321-987654321-987654321-2002" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:05:00Z", + "idm": { + "readOnlyUdm": { + "additional": { + "userid": "2002" + }, + "metadata": { + "eventTimestamp": "2024-10-12T10:05:00Z", + "eventType": "USER_UNCATEGORIZED", + "ingestionLabels": [ + { + "key": "LogOnDuration", + "value": "10" + }, + { + "key": "ConnectionState", + "value": "2" + } + ], + "logType": "CITRIX_MONITOR", + "productName": "CITRIX_MONITOR", + "vendorName": "CITRIX_MONITOR" + }, + "network": { + "sessionId": "12345" + }, + "principal": { + "asset": { + "assetId": "MachineId:mach-nested-2002" + }, + "assetId": "MachineId:mach-nested-2002" + }, + "target": { + "platform": "MAC", + "user": { + "userid": "test_mac_user" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "CITRIX_MONITOR", + "productName": "CITRIX_MONITOR", + "vendorName": "CITRIX_MONITOR" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:15:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:15:00Z", + "eventType": "GENERIC_EVENT", + "logType": "CITRIX_MONITOR", + "productName": "CITRIX_MONITOR", + "vendorName": "CITRIX_MONITOR" + }, + "principal": { + "asset": { + "hostname": "linux-host-01.example.local" + }, + "hostname": "linux-host-01.example.local" + }, + "target": { + "platform": "LINUX" + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/CITRIX_MONITOR_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/CITRIX_MONITOR_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..1c660194d5 --- /dev/null +++ b/content/parsers/third_party/community/CITRIX_MONITOR_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,20 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "{\"CreatedDate\":\"2024-10-12T10:00:00Z\",\"MachineId\":\"mach-id-1001\",\"Machine\":{\"Id\":\"mach-nested-ignored\",\"Sid\":\"S-1-5-21-123456789-123456789-123456789-1001\",\"IPAddress\":\"1.1.1.1\",\"HostingServerName\":\"srv-host-01.example.local\",\"HostedMachineName\":\"vdi-domain-01\",\"AssociatedUserUPNs\":\"test_user1@dummy.com,test_user2@dummy.com\",\"AssociatedUserFullNames\":\"Masked User Display Name\",\"DnsName\":\"vdi01.dummy.com\",\"AgentVersion\":\"1.1.1.2\",\"Hash\":\"E4D909C290D0FB1CA068FFADD08220EC\",\"OSType\":\"Windows 10 Enterprise\"},\"User\":{\"Id\":1001,\"UserName\":\"test_target_user\",\"FullName\":\"Target User Full Name\",\"Sid\":\"S-1-5-21-987654321-987654321-987654321-2002\",\"Domain\":\"corp.example.local\",\"Upn\":\"target_user@dummy.com\"},\"CurrentConnectionId\":54321,\"Connections\":[{\"ClientAddress\":\"1.1.1.3\",\"ConnectedViaIPAddress\":\"1.1.1.4\",\"LaunchedViaIPAddress\":\"1.1.1.5\"}],\"ApplicationInstances\":[{\"Application\":{\"Name\":\"TestApp\",\"AdminFolder\":\"C:\\\\Program Files\\\\Admin\",\"Path\":\"C:\\\\Program Files\\\\App\\\\app.exe\",\"BrowserName\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64)\"}}],\"LogOnDuration\":42,\"SessionKey\":\"sess-key-9999\",\"ConnectionState\":1}" + }, + { + "data": "{\"CreatedDate\":\"2024-10-12T10:05:00Z\",\"Machine\":{\"Id\":\"mach-nested-2002\",\"OSType\":\"macOS Sonoma 14.0\"},\"User\":{\"Id\":2002,\"UserName\":\"test_mac_user\"},\"CurrentConnectionId\":12345,\"Connections\":[{}],\"ApplicationInstances\":[{}],\"LogOnDuration\":10,\"ConnectionState\":2}" + }, + { + "data": "{'invalid_json': true, \"unquoted_key\": value}" + }, + { + "data": "{\"CreatedDate\":\"2024-10-12T10:15:00Z\",\"Machine\":{\"OSType\":\"Linux Ubuntu 22.04 LTS\",\"HostingServerName\":\"linux-host-01.example.local\"}}" + } + ], + "type": "CITRIX_MONITOR" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/COMFORTE_SECURDPS_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/COMFORTE_SECURDPS_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..ee7c52c541 --- /dev/null +++ b/content/parsers/third_party/community/COMFORTE_SECURDPS_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,197 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "additional": { + "cribl_pipe": "pipe_syslog_comforte", + "index": "comforte_audit" + }, + "metadata": { + "description": "SecureDPS full batch audit event", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "NETWORK_CONNECTION", + "logType": "COMFORTE_SECURDPS", + "productEventType": "comforte:securdps:json", + "productName": "Comforte SecureDPS", + "vendorName": "COMFORTE_SECURDPS" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.1" + ] + }, + "ip": [ + "1.1.1.1" + ] + }, + "securityResult": [ + { + "detectionFields": [ + { + "key": "facility", + "value": "1" + }, + { + "key": "facilityName", + "value": "USER" + }, + { + "key": "_PROTECTS", + "value": "100" + }, + { + "key": "_DENIEDPROTECTS", + "value": "0" + }, + { + "key": "_REVEALS", + "value": "20" + }, + { + "key": "_DENIEDREVEALS", + "value": "1" + }, + { + "key": "_LOOKUPS", + "value": "5" + }, + { + "key": "_INTERVAL", + "value": "30s" + } + ], + "severity": "INFORMATIONAL", + "severityDetails": "6" + } + ], + "target": { + "application": "PaymentGateway", + "asset": { + "ip": [ + "1.1.1.2" + ] + }, + "file": { + "sha256": "a591a6d40bf420404a011733cfb7b190d62c65bf0bcda32b57b277d9ad9f146e" + }, + "ip": [ + "1.1.1.2" + ], + "process": { + "pid": "2048" + }, + "user": { + "userid": "TEST_ZOS_01" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "COMFORTE_SECURDPS", + "productName": "Comforte SecureDPS", + "vendorName": "COMFORTE_SECURDPS" + }, + "principal": { + "asset": { + "hostname": "securdps-node01.example.net" + }, + "hostname": "securdps-node01.example.net" + }, + "securityResult": [ + { + "severity": "INFORMATIONAL" + } + ], + "target": { + "process": { + "pid": "3099" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "COMFORTE_SECURDPS", + "productName": "Comforte SecureDPS", + "vendorName": "COMFORTE_SECURDPS" + }, + "securityResult": [ + { + "severity": "ERROR" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "COMFORTE_SECURDPS", + "productName": "Comforte SecureDPS", + "vendorName": "COMFORTE_SECURDPS" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "COMFORTE_SECURDPS", + "productName": "Comforte SecureDPS", + "vendorName": "COMFORTE_SECURDPS" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "COMFORTE_SECURDPS", + "productName": "Comforte SecureDPS", + "vendorName": "COMFORTE_SECURDPS" + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/COMFORTE_SECURDPS_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/COMFORTE_SECURDPS_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..2fd3a7c735 --- /dev/null +++ b/content/parsers/third_party/community/COMFORTE_SECURDPS_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,26 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "[{\"msg_data\":\"SecureDPS full batch audit event\",\"severity\":6,\"facility\":1,\"host\":\"1.1.1.1\",\"severityName\":\"info\",\"facilityName\":\"USER\",\"_time\":1728727200,\"index\":\"comforte_audit\",\"sourcetype\":\"comforte:securdps:json\",\"cribl_pipe\":\"pipe_syslog_comforte\",\"_raw\":\"SDRedis[2048] meta}}} _STRATEGY=Tokenize_CC, _PROTECTS=100, _DENIEDPROTECTS=0, _REVEALS=20, _DENIEDREVEALS=1, _LOOKUPS=5, _INTERVAL=30s, _APPLICATION=PaymentGateway, _ZOSUSER=TEST_ZOS_01, _IPADDRESS=1.1.1.2, _USER=test_service_account SHA256:a591a6d40bf420404a011733cfb7b190d62c65bf0bcda32b57b277d9ad9f146e\"}]" + }, + { + "data": "[{\"severity\":{\"invalid\":\"object\"},\"facility\":[\"invalid_array\"],\"_time\":{\"invalid\":\"time\"},\"host\":\"securdps-node01.example.net\",\"severityName\":\"info\",\"_raw\":\"SDRedis[3099] meta}}} _APPLICATION=AuthService, _USER=test_user_02 SHA256:NON_HEX_HASH_VALUE_ZZZ\"}]" + }, + { + "data": "[{\"msg_data\":\"\",\"severity\":\"\",\"facility\":\"\",\"host\":\"\",\"severityName\":\"ERROR\",\"facilityName\":\"\",\"_time\":\"\",\"index\":\"\",\"sourcetype\":\"\",\"cribl_pipe\":\"\",\"_raw\":\"\"}]" + }, + { + "data": "\u003c134\u003e1728727200 SDRedis[5012] sys_meta}}} _STRATEGY=Reveal_Token, _APPLICATION=AccountingApp, _ZOSUSER=TEST_ZOS_02, _IPADDRESS=1.1.1.3, _USER=test_ops_user SHA256:b5a2c96250612366acfc8bee363566081d4d74590353861cb614f7042703dbe2" + }, + { + "data": "\u003c134\u003e1728727200 securdps_core[6010]: error: DPD_POLICY_VIOLATION: Data protection policy violation detected during token lookup" + }, + { + "data": "\u003c134\u003e1728727200 securdps_sshd[7020]: Connection closed by 1.1.1.4 port 51432" + } + ], + "type": "COMFORTE_SECURDPS" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/CSG_CITRIX_RX_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/CSG_CITRIX_RX_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..197f312e37 --- /dev/null +++ b/content/parsers/third_party/community/CSG_CITRIX_RX_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,150 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "NETWORK_CONNECTION", + "logType": "CSG_CITRIX_RX", + "productLogId": "log_1001", + "productName": "CSG Citrix RX", + "vendorName": "CSG Citrix RX" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.1" + ] + }, + "ip": [ + "1.1.1.1" + ], + "user": { + "userid": "test_user_01" + } + }, + "target": { + "application": "app_citrix_01", + "asset": { + "ip": [ + "1.1.1.2" + ] + }, + "ip": [ + "1.1.1.2" + ], + "resource": { + "attribute": { + "creationTime": "2024-10-12T10:00:00Z" + }, + "name": "desktop_vdi_01" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "CSG_CITRIX_RX", + "productLogId": "log_1002", + "productName": "CSG Citrix RX", + "vendorName": "CSG Citrix RX" + }, + "principal": { + "user": { + "userid": "test_user_02" + } + }, + "target": { + "application": "app_citrix_02", + "asset": { + "ip": [ + "1.1.1.3" + ] + }, + "ip": [ + "1.1.1.3" + ], + "resource": { + "name": "desktop_vdi_02" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "GENERIC_EVENT", + "logType": "CSG_CITRIX_RX", + "productName": "CSG Citrix RX", + "vendorName": "CSG Citrix RX" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "NETWORK_CONNECTION", + "logType": "CSG_CITRIX_RX", + "productLogId": "log_1004", + "productName": "CSG Citrix RX", + "vendorName": "CSG Citrix RX" + }, + "principal": { + "asset": { + "ip": [ + "1.1.1.4" + ] + }, + "ip": [ + "1.1.1.4" + ], + "user": { + "userid": "test_user_04" + } + }, + "target": { + "application": "app_citrix_04", + "asset": { + "ip": [ + "1.1.1.5" + ] + }, + "ip": [ + "1.1.1.5" + ], + "resource": { + "attribute": { + "creationTime": "2024-10-12T10:00:00Z" + }, + "name": "desktop_vdi_04" + } + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/CSG_CITRIX_RX_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/CSG_CITRIX_RX_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..d543e7e929 --- /dev/null +++ b/content/parsers/third_party/community/CSG_CITRIX_RX_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,20 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "\u003c134\u003eOct 12 10:00:00 test_host_01 log_1001,app_citrix_01,desktop_vdi_01,1.1.1.1,12/10/2024 10:00:00,test_user_01,1.1.1.2" + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 test_host_02 log_1002,app_citrix_02,desktop_vdi_02,not_an_ip,invalid_date_str,test_user_02,1.1.1.3" + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 test_host_03 ,,,,,," + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 test_host_04 log_1004,app_citrix_04,desktop_vdi_04,1.1.1.4,12/10/2024 10:00:00,test_user_04,1.1.1.5" + } + ], + "type": "CSG_CITRIX_RX" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/DOMAINTOOLS_THREATINTEL_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/DOMAINTOOLS_THREATINTEL_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..955bdef9d6 --- /dev/null +++ b/content/parsers/third_party/community/DOMAINTOOLS_THREATINTEL_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,568 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "about": [ + { + "labels": [ + { + "key": "isp", + "value": "Secondary ISP" + }, + { + "key": "ip_address", + "value": "1.1.1.2" + }, + { + "key": "asn", + "value": "11111" + } + ], + "location": { + "countryOrRegion": "GB" + } + }, + { + "domain": { + "nameServer": [ + "ns1.dummy.com" + ] + }, + "labels": [ + { + "key": "ip", + "value": "1.1.1.3" + }, + { + "key": "name_server_domain", + "value": "dummy.com" + } + ] + }, + { + "labels": [ + { + "key": "ssl_info_email", + "value": "cert1@dummy.com" + } + ] + }, + { + "labels": [ + { + "key": "hash", + "value": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4" + }, + { + "key": "subject", + "value": "CN=backup.dummy.com" + }, + { + "key": "issuer_common_name", + "value": "Backup CA" + }, + { + "key": "not_after", + "value": "20260101" + }, + { + "key": "not_before", + "value": "20240101" + }, + { + "key": "organization", + "value": "OrgSecondary" + }, + { + "key": "common_name", + "value": "backup.dummy.com" + }, + { + "key": "duration", + "value": "730" + }, + { + "key": "alt_names", + "value": "api.dummy.com" + } + ] + }, + { + "labels": [ + { + "key": "ssl_info_email", + "value": "cert2@dummy.com" + } + ] + }, + { + "domain": { + "name": "dummy.com" + }, + "hostname": "mail.dummy.com", + "ip": [ + "1.1.1.4" + ], + "securityResult": [ + { + "priorityDetails": "10" + } + ] + }, + { + "file": { + "tags": [ + "malicious_host" + ] + }, + "labels": [ + { + "key": "adsense", + "value": "pub-1234567890123456" + }, + { + "key": "alexa", + "value": "1000" + }, + { + "key": "popularity_rank", + "value": "500" + }, + { + "key": "google_analytics", + "value": "UA-123456-1" + }, + { + "key": "email_domain", + "value": "dummy.com" + }, + { + "key": "ssl_email", + "value": "ssl@dummy.com" + }, + { + "key": "additional_whois_email", + "value": "whois_extra@dummy.com" + }, + { + "key": "asn", + "value": "67890" + }, + { + "key": "redirect", + "value": "https://redirect.dummy.com" + }, + { + "key": "redirect_domain", + "value": "redirect.dummy.com" + }, + { + "key": "registrant_name", + "value": "dummy_registrant_name" + }, + { + "key": "registrant_org", + "value": "dummy_registrant_org" + }, + { + "key": "registrar_status", + "value": "clientTransferProhibited" + }, + { + "key": "registrar_status", + "value": "clientUpdateProhibited" + }, + { + "key": "spf_info", + "value": "v=spf1 include:_spf.dummy.com ~all" + }, + { + "key": "tld", + "value": "com" + }, + { + "key": "website_title", + "value": "Example Domain Portal" + }, + { + "key": "common_name", + "value": "dummy.com" + }, + { + "key": "duration", + "value": "365" + }, + { + "key": "alt_names", + "value": "www.dummy.com" + }, + { + "key": "ga4", + "value": "G-ABC123XYZ" + }, + { + "key": "gtm_codes", + "value": "GTM-TEST1234" + }, + { + "key": "fb_codes", + "value": "FB-PIXEL-987" + }, + { + "key": "hotjar_codes", + "value": "HJ-45678" + }, + { + "key": "baidu_codes", + "value": "BAIDU-12345" + }, + { + "key": "yandex_codes", + "value": "YANDEX-6789" + }, + { + "key": "matomo_codes", + "value": "MATOMO-1011" + }, + { + "key": "statcounter_project_codes", + "value": "SC-PROJ-1" + }, + { + "key": "statcounter_security_codes", + "value": "SC-SEC-1" + }, + { + "key": "allow_domain", + "value": "trusted.dummy.com" + }, + { + "key": "monitor_tag", + "value": "tier1_monitor" + }, + { + "key": "monitor_domain", + "value": "watch.dummy.com" + }, + { + "key": "tag_name", + "value": "threat_intel_feed" + }, + { + "key": "timestamp", + "value": "1728727200" + }, + { + "key": "allow_list_name", + "value": "trusted_whitelist" + }, + { + "key": "monitoring_tag_list_name", + "value": "tag_watchlist" + }, + { + "key": "monitoring_domain_list_name", + "value": "domain_watchlist" + } + ] + } + ], + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "ingestionLabels": [ + { + "key": "subdomain", + "value": "api.dummy.com" + }, + { + "key": "first_seen", + "value": "2024-01-10" + }, + { + "key": "last_seen", + "value": "2024-10-10" + }, + { + "key": "count", + "value": "42" + } + ], + "logType": "DOMAINTOOLS_THREATINTEL", + "productName": "DOMAINTOOLS", + "vendorName": "DOMAINTOOLS" + }, + "network": { + "asn": "12345", + "organizationName": "OrgPrimary", + "tls": { + "client": { + "serverName": "nginx/1.18.0" + }, + "server": { + "certificate": { + "issuer": "Generic CA", + "notAfter": "2025-12-31T00:00:00Z", + "notBefore": "2024-01-01T00:00:00Z", + "sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709", + "subject": "CN=dummy.com" + } + } + } + }, + "principal": { + "asset": { + "hostname": "dummy.com", + "ip": [ + "1.1.1.1", + "1.1.1.2" + ] + }, + "domain": { + "admin": { + "attribute": { + "labels": [ + { + "key": "postal", + "value": "90210" + }, + { + "key": "fax", + "value": "+1-555-0101" + } + ] + }, + "companyName": "Generic Organization", + "emailAddresses": [ + "admin@dummy.com" + ], + "officeAddress": { + "city": "Test City", + "countryOrRegion": "US", + "name": "123 Test Street", + "state": "Test State" + }, + "phoneNumbers": [ + "+1-555-0100" + ], + "userDisplayName": "dummy_admin_user" + }, + "billing": { + "attribute": { + "labels": [ + { + "key": "postal", + "value": "10001" + }, + { + "key": "fax", + "value": "+1-555-0201" + } + ] + }, + "companyName": "Generic Billing Org", + "emailAddresses": [ + "billing@dummy.com" + ], + "officeAddress": { + "city": "Billing City", + "countryOrRegion": "US", + "name": "456 Billing Ave", + "state": "Billing State" + }, + "phoneNumbers": [ + "+1-555-0200" + ], + "userDisplayName": "dummy_billing_user" + }, + "creationTime": "2024-01-01T00:00:00Z", + "expirationTime": "2025-01-01T00:00:00Z", + "firstSeenTime": "2023-05-15T00:00:00Z", + "nameServer": [ + "ns1.dummy.com" + ], + "registrant": { + "attribute": { + "labels": [ + { + "key": "postal", + "value": "30301" + }, + { + "key": "fax", + "value": "+1-555-0301" + } + ] + }, + "companyName": "Generic Registrant Org", + "emailAddresses": [ + "registrant@dummy.com" + ], + "officeAddress": { + "city": "Registrant City", + "countryOrRegion": "US", + "name": "789 Registrant Rd", + "state": "Registrant State" + }, + "phoneNumbers": [ + "+1-555-0300" + ], + "userDisplayName": "dummy_registrant_user" + }, + "registrar": "Example Registrar LLC", + "status": "true", + "tech": { + "attribute": { + "labels": [ + { + "key": "postal", + "value": "94016" + }, + { + "key": "fax", + "value": "+1-555-0401" + } + ] + }, + "companyName": "Generic Tech Org", + "emailAddresses": [ + "tech@dummy.com" + ], + "officeAddress": { + "city": "Tech City", + "countryOrRegion": "US", + "name": "101 Tech Blvd", + "state": "Tech State" + }, + "phoneNumbers": [ + "+1-555-0400" + ], + "userDisplayName": "dummy_tech_user" + }, + "whoisServer": "https://whois.dummy.com" + }, + "hostname": "dummy.com", + "ip": [ + "1.1.1.1", + "1.1.1.2" + ], + "labels": [ + { + "key": "isp", + "value": "Primary ISP" + } + ], + "location": { + "countryOrRegion": "US" + }, + "network": { + "http": { + "responseCode": 200 + } + }, + "user": { + "emailAddresses": [ + "soa@dummy.com" + ] + } + }, + "securityResult": [ + { + "riskScore": 75.5 + }, + { + "categoryDetails": [ + "Phishing Risk" + ], + "detectionFields": [ + { + "key": "threats", + "value": "malware_host" + }, + { + "key": "evidence", + "value": "suspicious_dga_pattern" + } + ], + "riskScore": 80, + "threatName": "phishing_c2" + }, + { + "detectionFields": [ + { + "key": "scope", + "value": "global" + }, + { + "key": "tagged_at", + "value": "2024-06-01T00:00:00Z" + } + ] + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "STATUS_UPDATE", + "logType": "DOMAINTOOLS_THREATINTEL", + "productName": "DOMAINTOOLS", + "vendorName": "DOMAINTOOLS" + }, + "principal": { + "asset": { + "hostname": "error-test.dummy.com" + }, + "hostname": "error-test.dummy.com" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "about": [ + { + "labels": [ + { + "key": "spf_info", + "value": "v=spf1 ~all" + }, + { + "key": "tld", + "value": "com" + } + ] + } + ], + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "DOMAINTOOLS_THREATINTEL", + "productName": "DOMAINTOOLS", + "vendorName": "DOMAINTOOLS" + }, + "principal": { + "domain": { + "whoisServer": "https://whois.dummy.com" + } + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/DOMAINTOOLS_THREATINTEL_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/DOMAINTOOLS_THREATINTEL_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..441a5d6bcb --- /dev/null +++ b/content/parsers/third_party/community/DOMAINTOOLS_THREATINTEL_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,17 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "{\"domain\":\"dummy.com\",\"whois_url\":\"https://whois.dummy.com\",\"adsense\":{\"value\":\"pub-1234567890123456\"},\"alexa\":1000,\"popularity_rank\":500,\"active\":\"true\",\"google_analytics\":{\"value\":\"UA-123456-1\"},\"admin_contact\":{\"name\":{\"value\":\"dummy_admin_user\"},\"org\":{\"value\":\"Generic Organization\"},\"street\":{\"value\":\"123 Test Street\"},\"city\":{\"value\":\"Test City\"},\"state\":{\"value\":\"Test State\"},\"postal\":{\"value\":\"90210\"},\"country\":{\"value\":\"US\"},\"phone\":{\"value\":\"+1-555-0100\"},\"fax\":{\"value\":\"+1-555-0101\"},\"email\":[{\"value\":\"admin@dummy.com\"}]},\"billing_contact\":{\"name\":{\"value\":\"dummy_billing_user\"},\"org\":{\"value\":\"Generic Billing Org\"},\"street\":{\"value\":\"456 Billing Ave\"},\"city\":{\"value\":\"Billing City\"},\"state\":{\"value\":\"Billing State\"},\"postal\":{\"value\":\"10001\"},\"country\":{\"value\":\"US\"},\"phone\":{\"value\":\"+1-555-0200\"},\"fax\":{\"value\":\"+1-555-0201\"},\"email\":[{\"value\":\"billing@dummy.com\"}]},\"registrant_contact\":{\"name\":{\"value\":\"dummy_registrant_user\"},\"org\":{\"value\":\"Generic Registrant Org\"},\"street\":{\"value\":\"789 Registrant Rd\"},\"city\":{\"value\":\"Registrant City\"},\"state\":{\"value\":\"Registrant State\"},\"postal\":{\"value\":\"30301\"},\"country\":{\"value\":\"US\"},\"phone\":{\"value\":\"+1-555-0300\"},\"fax\":{\"value\":\"+1-555-0301\"},\"email\":[{\"value\":\"registrant@dummy.com\"}]},\"technical_contact\":{\"name\":{\"value\":\"dummy_tech_user\"},\"org\":{\"value\":\"Generic Tech Org\"},\"street\":{\"value\":\"101 Tech Blvd\"},\"city\":{\"value\":\"Tech City\"},\"state\":{\"value\":\"Tech State\"},\"postal\":{\"value\":\"94016\"},\"country\":{\"value\":\"US\"},\"phone\":{\"value\":\"+1-555-0400\"},\"fax\":{\"value\":\"+1-555-0401\"},\"email\":[{\"value\":\"tech@dummy.com\"}]},\"create_date\":{\"value\":\"2024-01-01\"},\"expiration_date\":{\"value\":\"2025-01-01\"},\"email_domain\":[{\"value\":\"dummy.com\"}],\"soa_email\":[{\"value\":\"soa@dummy.com\"}],\"ssl_email\":[{\"value\":\"ssl@dummy.com\"}],\"additional_whois_email\":[{\"value\":\"whois_extra@dummy.com\"}],\"ip\":[{\"address\":{\"value\":\"1.1.1.1\"},\"country_code\":{\"value\":\"US\"},\"isp\":{\"value\":\"Primary ISP\"},\"asn\":[{\"value\":12345},{\"value\":67890}]},{\"address\":{\"value\":\"1.1.1.2\"},\"country_code\":{\"value\":\"GB\"},\"isp\":{\"value\":\"Secondary ISP\"},\"asn\":[{\"value\":11111}]}],\"name_server\":[{\"host\":{\"value\":\"ns1.dummy.com\"},\"domain\":{\"value\":\"dummy.com\"},\"ip\":[{\"value\":\"1.1.1.3\"}]}],\"first_seen\":{\"value\":\"2023-05-15\"},\"data_updated_timestamp\":\"2024-10-12 12:00:00\",\"registrar\":{\"value\":\"Example Registrar LLC\"},\"domain_risk\":{\"risk_score\":75.5,\"components\":[{\"risk_score\":80.0,\"name\":\"Phishing Risk\",\"threats\":[\"phishing_c2\",\"malware_host\"],\"evidence\":[\"suspicious_dga_pattern\"]}]},\"redirect\":{\"value\":\"https://redirect.dummy.com\"},\"redirect_domain\":{\"value\":\"redirect.dummy.com\"},\"registrant_name\":{\"value\":\"dummy_registrant_name\"},\"registrant_org\":{\"value\":\"dummy_registrant_org\"},\"registrar_status\":[\"clientTransferProhibited\",\"clientUpdateProhibited\"],\"spf_info\":\"v=spf1 include:_spf.dummy.com ~all\",\"tld\":\"com\",\"website_title\":{\"value\":\"Example Domain Portal\"},\"server_type\":{\"value\":\"nginx/1.18.0\"},\"website_response\":200,\"tags\":[{\"label\":\"malicious_host\",\"scope\":\"global\",\"tagged_at\":\"2024-06-01T00:00:00Z\"}],\"ssl_info\":[{\"hash\":{\"value\":\"da39a3ee5e6b4b0d3255bfef95601890afd80709\"},\"subject\":{\"value\":\"CN=dummy.com\"},\"issuer_common_name\":{\"value\":\"Generic CA\"},\"not_after\":{\"value\":\"20251231\"},\"not_before\":{\"value\":\"20240101\"},\"organization\":{\"value\":\"OrgPrimary\"},\"common_name\":{\"value\":\"dummy.com\"},\"duration\":{\"value\":365},\"alt_names\":[{\"value\":\"www.dummy.com\"}],\"email\":[{\"value\":\"cert1@dummy.com\"}]},{\"hash\":{\"value\":\"e3b0c44298fc1c149afbf4c8996fb92427ae41e4\"},\"subject\":{\"value\":\"CN=backup.dummy.com\"},\"issuer_common_name\":{\"value\":\"Backup CA\"},\"not_after\":{\"value\":\"20260101\"},\"not_before\":{\"value\":\"20240101\"},\"organization\":{\"value\":\"OrgSecondary\"},\"common_name\":{\"value\":\"backup.dummy.com\"},\"duration\":{\"value\":730},\"alt_names\":[{\"value\":\"api.dummy.com\"}],\"email\":[{\"value\":\"cert2@dummy.com\"}]}],\"mx\":[{\"host\":{\"value\":\"mail.dummy.com\"},\"domain\":{\"value\":\"dummy.com\"},\"ip\":[{\"value\":\"1.1.1.4\"}],\"priority\":10}],\"ga4\":[{\"value\":\"G-ABC123XYZ\"}],\"gtm_codes\":[{\"value\":\"GTM-TEST1234\"}],\"fb_codes\":[{\"value\":\"FB-PIXEL-987\"}],\"hotjar_codes\":[{\"value\":\"HJ-45678\"}],\"baidu_codes\":[{\"value\":\"BAIDU-12345\"}],\"yandex_codes\":[{\"value\":\"YANDEX-6789\"}],\"matomo_codes\":[{\"value\":\"MATOMO-1011\"}],\"statcounter_project_codes\":[{\"value\":\"SC-PROJ-1\"}],\"statcounter_security_codes\":[{\"value\":\"SC-SEC-1\"}],\"allow_domain\":\"trusted.dummy.com\",\"monitor_tag\":\"tier1_monitor\",\"monitor_domain\":\"watch.dummy.com\",\"tag_name\":\"threat_intel_feed\",\"timestamp\":1728727200,\"allow_list_name\":\"trusted_whitelist\",\"monitoring_tag_list_name\":\"tag_watchlist\",\"monitoring_domain_list_name\":\"domain_watchlist\",\"subdomains\":[{\"subdomain\":\"api.dummy.com\",\"first_seen\":\"2024-01-10\",\"last_seen\":\"2024-10-10\",\"count\":42}]}" + }, + { + "data": "{\"domain\":\"error-test.dummy.com\",\"ssl_info\":[{},{\"hash\":{\"value\":{}},\"subject\":{\"value\":{}},\"issuer_common_name\":{\"value\":{}},\"not_after\":{\"value\":{}},\"not_before\":{\"value\":{}},\"organization\":{\"value\":{}},\"common_name\":{\"value\":{}},\"duration\":{\"value\":{}}}],\"ga4\":[{\"value\":{}}],\"gtm_codes\":[{\"value\":{}}],\"fb_codes\":[{\"value\":{}}],\"hotjar_codes\":[{\"value\":{}}],\"baidu_codes\":[{\"value\":{}}],\"yandex_codes\":[{\"value\":{}}],\"matomo_codes\":[{\"value\":{}}],\"statcounter_project_codes\":[{\"value\":{}}],\"statcounter_security_codes\":[{\"value\":{}}],\"allow_domain\":{},\"monitor_tag\":{},\"monitor_domain\":{},\"tag_name\":{},\"timestamp\":{},\"website_response\":{},\"create_date\":{\"value\":\"invalid_date_str\"},\"expiration_date\":{\"value\":\"invalid_date_str\"},\"first_seen\":{\"value\":\"invalid_date_str\"},\"data_updated_timestamp\":\"invalid_date_str\"}" + }, + { + "data": "{\"whois_url\":\"https://whois.dummy.com\",\"tld\":\"com\",\"spf_info\":\"v=spf1 ~all\"}" + } + ], + "type": "DOMAINTOOLS_THREATINTEL" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/ENTRUST_HSM_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/ENTRUST_HSM_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..6137c82a4c --- /dev/null +++ b/content/parsers/third_party/community/ENTRUST_HSM_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,144 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Connection accepted from user test_user_01 1.1.1.1 port 54321", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "ENTRUST_HSM", + "productEventType": "hardserver", + "productName": "Entrust nShield HSM", + "vendorName": "ENTRUST HSM" + }, + "principal": { + "application": "nfast-server", + "asset": { + "ip": [ + "1.1.1.1" + ] + }, + "ip": [ + "1.1.1.1" + ], + "port": 54321, + "user": { + "userid": "test_user_01" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "audit: Key generation completed; rhost=1.1.1.2 key_type=RSA", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "STATUS_UPDATE", + "logType": "ENTRUST_HSM", + "productEventType": "hardserver", + "productName": "Entrust nShield HSM", + "vendorName": "ENTRUST HSM" + }, + "principal": { + "application": "nfast-server", + "asset": { + "ip": [ + "1.1.1.2" + ] + }, + "ip": [ + "1.1.1.2" + ] + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Module status changed to operational", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "GENERIC_EVENT", + "logType": "ENTRUST_HSM", + "productEventType": "hardserver", + "productName": "Entrust nShield HSM", + "vendorName": "ENTRUST HSM" + }, + "principal": { + "application": "nfast-server" + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Closing session 98765 of user test_user_02.", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "ENTRUST_HSM", + "productEventType": "hardserver", + "productName": "Entrust nShield HSM", + "vendorName": "ENTRUST HSM" + }, + "network": { + "sessionId": "98765" + }, + "principal": { + "application": "nfast-server", + "user": { + "userid": "test_user_02" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Connection established from 1.1.1.3 port 8080", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "STATUS_UPDATE", + "logType": "ENTRUST_HSM", + "productEventType": "hardserver", + "productName": "Entrust nShield HSM", + "vendorName": "ENTRUST HSM" + }, + "principal": { + "application": "nfast-server", + "asset": { + "ip": [ + "1.1.1.3" + ] + }, + "ip": [ + "1.1.1.3" + ], + "port": 8080 + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/ENTRUST_HSM_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/ENTRUST_HSM_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..3f539e6dac --- /dev/null +++ b/content/parsers/third_party/community/ENTRUST_HSM_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,23 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "\u003c134\u003eOct 12 10:00:00 nfast-server hardserver[12345]: Connection accepted from user test_user_01 1.1.1.1 port 54321" + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 nfast-server hardserver[12345]: audit: Key generation completed; rhost=1.1.1.2 key_type=RSA" + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 nfast-server hardserver[12345]: Module status changed to operational" + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 nfast-server hardserver[12345]: Closing session 98765 of user test_user_02." + }, + { + "data": "\u003c134\u003eOct 12 10:00:00 nfast-server hardserver[12345]: Connection established from 1.1.1.3 port 8080" + } + ], + "type": "ENTRUST_HSM" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/EVISION_FIRCOSOFT_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/EVISION_FIRCOSOFT_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..43a836a781 --- /dev/null +++ b/content/parsers/third_party/community/EVISION_FIRCOSOFT_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,108 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "EVISION_FIRCOSOFT", + "productEventType": "Estadisticas", + "productName": "Fircosoft", + "vendorName": "eVision" + }, + "principal": { + "user": { + "userid": "test_user_01" + } + }, + "securityResult": [ + { + "action": [ + "ALLOW" + ], + "actionDetails": "EXECUTE_QUERY_SUCCESS" + } + ], + "target": { + "resource": { + "name": "RESOURCE_TABLE_01" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "EVISION_FIRCOSOFT", + "productEventType": "Otros", + "productName": "Fircosoft", + "vendorName": "eVision" + }, + "principal": { + "user": { + "userid": "test_user_02" + } + }, + "securityResult": [ + { + "action": [ + "BLOCK" + ], + "actionDetails": "ACCESS_DENIED_BLOCKED" + } + ], + "target": { + "resource": { + "name": "RESOURCE_TABLE_02" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_RESOURCE_ACCESS", + "logType": "EVISION_FIRCOSOFT", + "productName": "Fircosoft", + "vendorName": "eVision" + }, + "principal": { + "user": { + "userid": "test_user_03" + } + }, + "securityResult": [ + { + "action": [ + "BLOCK" + ], + "actionDetails": "GENERIC_OPERATION" + } + ], + "target": { + "resource": { + "name": "RESOURCE_TABLE_03" + } + } + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/EVISION_FIRCOSOFT_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/EVISION_FIRCOSOFT_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..a305c9b727 --- /dev/null +++ b/content/parsers/third_party/community/EVISION_FIRCOSOFT_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,17 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "2024/10/12 10:00:00.000 |test_user_01 |RESOURCE_TABLE_01 |EXECUTE_QUERY_SUCCESS |C |SI" + }, + { + "data": "2024/10/12 10:00:00.000 |test_user_02 |RESOURCE_TABLE_02 |ACCESS_DENIED_BLOCKED |A |NO" + }, + { + "data": "2024/10/12 10:00:00.000 |test_user_03 |RESOURCE_TABLE_03 |GENERIC_OPERATION |X |UNKNOWN" + } + ], + "type": "EVISION_FIRCOSOFT" + } +} \ No newline at end of file diff --git a/content/parsers/third_party/community/IBM_OPENPAGES_GUS/cbn/testdata/expected_events/default_events.json b/content/parsers/third_party/community/IBM_OPENPAGES_GUS/cbn/testdata/expected_events/default_events.json new file mode 100644 index 0000000000..b60fecbdb5 --- /dev/null +++ b/content/parsers/third_party/community/IBM_OPENPAGES_GUS/cbn/testdata/expected_events/default_events.json @@ -0,0 +1,174 @@ +{ + "events": [ + { + "event": { + "timestamp": "2024-10-12T10:00:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "User logged in successfully", + "eventTimestamp": "2024-10-12T10:00:00Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "IBM_OPENPAGES", + "productEventType": "USER_LOGIN", + "productName": "OpenPages", + "vendorName": "IBM" + }, + "principal": { + "user": { + "userid": "dummy_principal_user_01" + } + }, + "securityResult": [ + { + "action": [ + "ALLOW" + ], + "actionDetails": "Logon Successful", + "description": "Logon Successful?=Yes Attempt Counter=1", + "detectionFields": [ + { + "key": "Counter", + "value": "1" + } + ], + "summary": "User login attempt" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:05:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:05:00Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "IBM_OPENPAGES", + "productEventType": "USER_PROFILE", + "productName": "OpenPages", + "vendorName": "IBM" + }, + "principal": { + "user": { + "userid": "dummy_admin_user_01" + } + }, + "securityResult": [ + { + "detectionFields": [ + { + "key": "OLDVALUE", + "value": "dummy_target_user_01--\u003edummy_target_role_01" + }, + { + "key": "NEWVALUE", + "value": "dummy_target_user_01--\u003edummy_target_role_02" + } + ], + "summary": "Role assignment modified" + } + ], + "target": { + "user": { + "attribute": { + "roles": [ + { + "name": "dummy_target_role_01" + } + ] + }, + "userid": "dummy_target_user_01" + } + } + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:10:00Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Invalid password provided", + "eventTimestamp": "2024-10-12T10:10:00Z", + "eventType": "USER_UNCATEGORIZED", + "logType": "IBM_OPENPAGES", + "productEventType": "USER_LOGIN", + "productName": "OpenPages", + "vendorName": "IBM" + }, + "principal": { + "user": { + "userid": "dummy_principal_user_02" + } + }, + "securityResult": [ + { + "action": [ + "BLOCK" + ], + "actionDetails": "Logon Failed", + "description": "Logon Successful?=No Attempt Counter=3", + "detectionFields": [ + { + "key": "Counter", + "value": "3" + } + ], + "summary": "Failed login attempt" + } + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "IBM_OPENPAGES", + "productName": "OpenPages", + "vendorName": "IBM" + }, + "securityResult": [ + {} + ] + } + } + } + }, + { + "event": { + "timestamp": "2024-10-12T10:00:00.123456789Z", + "idm": { + "readOnlyUdm": { + "metadata": { + "description": "Audit detail text", + "eventTimestamp": "2024-10-12T10:00:00.123456789Z", + "eventType": "GENERIC_EVENT", + "logType": "IBM_OPENPAGES", + "productEventType": "SYSTEM_AUDIT", + "productName": "OpenPages", + "vendorName": "IBM" + }, + "securityResult": [ + { + "description": "unstructured_arbitrary_column4_data", + "summary": "System event observed" + } + ] + } + } + } + } + ] +} \ No newline at end of file diff --git a/content/parsers/third_party/community/IBM_OPENPAGES_GUS/cbn/testdata/raw_logs/default_log.json b/content/parsers/third_party/community/IBM_OPENPAGES_GUS/cbn/testdata/raw_logs/default_log.json new file mode 100644 index 0000000000..dcd905ffe6 --- /dev/null +++ b/content/parsers/third_party/community/IBM_OPENPAGES_GUS/cbn/testdata/raw_logs/default_log.json @@ -0,0 +1,23 @@ +{ + "create_time": "2024-10-12T10:00:00.123456789Z", + "raw_logs": { + "entries": [ + { + "data": "USER_LOGIN|User login attempt|2024-10-12 10:00:00|Logon Successful?=Yes Attempt Counter=1|User logged in successfully|dummy_principal_user_01" + }, + { + "data": "USER_PROFILE|Role assignment modified|2024-10-12 10:05:00|dummy_target_user_01--\u003edummy_target_role_01|dummy_target_user_01--\u003edummy_target_role_02|dummy_admin_user_01" + }, + { + "data": "USER_LOGIN|Failed login attempt|2024-10-12 10:10:00|Logon Successful?=No Attempt Counter=3|Invalid password provided|dummy_principal_user_02" + }, + { + "data": "|||||" + }, + { + "data": "SYSTEM_AUDIT|System event observed|invalid_timestamp_string|unstructured_arbitrary_column4_data|Audit detail text|" + } + ], + "type": "IBM_OPENPAGES" + } +} \ No newline at end of file