Skip to content

Commit

Permalink
Sync okta package with beats
Browse files Browse the repository at this point in the history
  • Loading branch information
marc-gr committed Feb 17, 2021
1 parent 8049dcf commit d348d1a
Show file tree
Hide file tree
Showing 10 changed files with 1,083 additions and 580 deletions.

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
{
"fields": {
"@timestamp": "2020-04-28T11:07:58.223Z"
},
"dynamic_fields": {
"event.ingested": "^.*$"
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,373 @@
{
"expected": [
{
"@timestamp": "2020-02-14T22:18:51.843Z",
"related": {
"user": [
"xxxxxx"
],
"ip": [
"108.255.197.247"
]
},
"client": {
"geo": {
"country_name": "United States",
"city_name": "Dublin",
"location": {
"lon": -121.919,
"lat": 37.7201
},
"region_name": "California"
},
"user": {
"full_name": "xxxxxx",
"id": "00u1abvz4pYqdM8ms4x6"
},
"ip": "108.255.197.247"
},
"source": {
"geo": {
"continent_name": "North America",
"region_iso_code": "US-CA",
"city_name": "Dublin",
"country_iso_code": "US",
"country_name": "United States",
"region_name": "California",
"location": {
"lon": -121.919,
"lat": 37.7201
}
},
"as": {
"number": 7018,
"organization": {
"name": "AT\u0026T Services, Inc."
}
},
"user": {
"full_name": "xxxxxx",
"id": "00u1abvz4pYqdM8ms4x6"
},
"ip": "108.255.197.247"
},
"event": {
"ingested": "2021-02-16T11:12:28.827203700Z",
"kind": "event",
"action": "user.session.end",
"id": "faf7398a-4f77-11ea-97fb-5925e98228bd",
"category": [
"authentication",
"session"
],
"type": [
"end",
"user"
],
"outcome": "success"
},
"okta": {
"actor": {
"id": "00u1abvz4pYqdM8ms4x6",
"display_name": "xxxxxx",
"type": "User",
"alternate_id": "xxxxxx@elastic.co"
},
"debug_context": {
"debug_data": {
"threat_suspected": "false",
"request_id": "XkccyyMli2Uay2I93ZgRzQAAB0c",
"request_uri": "/login/signout",
"url": "/login/signout?message=login_page_messages.session_has_expired"
}
},
"event_type": "user.session.end",
"authentication_context": {
"authentication_step": 0,
"external_session_id": "102nZHzd6OHSfGG51vsoc22gw"
},
"display_message": "User logout from Okta",
"client": {
"zone": "null",
"device": "Computer",
"user_agent": {
"os": "Mac OS X",
"raw_user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0",
"browser": "FIREFOX"
},
"ip": "108.255.197.247"
},
"uuid": "faf7398a-4f77-11ea-97fb-5925e98228bd",
"outcome": {
"result": "SUCCESS"
},
"transaction": {
"type": "WEB",
"id": "XkccyyMli2Uay2I93ZgRzQAAB0c"
}
},
"user": {
"full_name": "xxxxxx"
},
"user_agent": {
"name": "Firefox",
"original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0",
"os": {
"name": "Mac OS X",
"version": "10.15",
"full": "Mac OS X 10.15"
},
"device": {
"name": "Mac"
},
"version": "72.0."
}
},
{
"@timestamp": "2020-02-14T22:18:51.843Z",
"related": {
"user": [
"xxxxxx"
],
"ip": [
"108.255.197.247"
]
},
"client": {
"geo": {
"country_name": "United States",
"city_name": "Dublin",
"location": {
"lon": -121.919,
"lat": 37.7201
},
"region_name": "California"
},
"user": {
"full_name": "xxxxxx",
"id": "00u1abvz4pYqdM8ms4x6"
},
"ip": "108.255.197.247"
},
"source": {
"geo": {
"continent_name": "North America",
"region_iso_code": "US-CA",
"city_name": "Dublin",
"country_iso_code": "US",
"country_name": "United States",
"region_name": "California",
"location": {
"lon": -121.919,
"lat": 37.7201
}
},
"as": {
"number": 7018,
"organization": {
"name": "AT\u0026T Services, Inc."
}
},
"user": {
"full_name": "xxxxxx",
"id": "00u1abvz4pYqdM8ms4x6"
},
"ip": "108.255.197.247"
},
"event": {
"ingested": "2021-02-16T11:12:28.827232900Z",
"kind": "event",
"action": "user.session.end",
"id": "faf7398a-4f77-11ea-97fb-5925e98228bd",
"category": [
"authentication",
"session"
],
"type": [
"end",
"user"
],
"outcome": "success"
},
"okta": {
"actor": {
"id": "00u1abvz4pYqdM8ms4x6",
"display_name": "xxxxxx",
"type": "User",
"alternate_id": "xxxxxx@elastic.co"
},
"debug_context": {
"debug_data": {
"threat_suspected": "false",
"request_id": "XkccyyMli2Uay2I93ZgRzQAAB0c",
"request_uri": "/login/signout",
"url": "/login/signout?message=login_page_messages.session_has_expired"
}
},
"event_type": "user.session.end",
"authentication_context": {
"authentication_step": 0,
"external_session_id": "102nZHzd6OHSfGG51vsoc22gw"
},
"display_message": "User logout from Okta",
"client": {
"zone": "null",
"device": "Computer",
"user_agent": {
"os": "Mac OS X",
"raw_user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0",
"browser": "FIREFOX"
},
"ip": "108.255.197.247"
},
"uuid": "faf7398a-4f77-11ea-97fb-5925e98228bd",
"outcome": {
"result": "SUCCESS"
},
"transaction": {
"type": "WEB",
"id": "XkccyyMli2Uay2I93ZgRzQAAB0c"
}
},
"user": {
"full_name": "xxxxxx"
},
"user_agent": {
"name": "Firefox",
"original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0",
"os": {
"name": "Mac OS X",
"version": "10.15",
"full": "Mac OS X 10.15"
},
"device": {
"name": "Mac"
},
"version": "72.0."
}
},
{
"@timestamp": "2020-02-14T22:18:51.843Z",
"related": {
"user": [
"xxxxxx"
],
"ip": [
"108.255.197.247"
]
},
"client": {
"geo": {
"country_name": "United States",
"city_name": "Dublin",
"location": {
"lon": -121.919,
"lat": 37.7201
},
"region_name": "California"
},
"user": {
"full_name": "xxxxxx",
"id": "00u1abvz4pYqdM8ms4x6"
},
"ip": "108.255.197.247"
},
"source": {
"geo": {
"continent_name": "North America",
"region_iso_code": "US-CA",
"city_name": "Dublin",
"country_iso_code": "US",
"country_name": "United States",
"region_name": "California",
"location": {
"lon": -121.919,
"lat": 37.7201
}
},
"as": {
"number": 7018,
"organization": {
"name": "AT\u0026T Services, Inc."
}
},
"user": {
"full_name": "xxxxxx",
"id": "00u1abvz4pYqdM8ms4x6"
},
"ip": "108.255.197.247"
},
"event": {
"ingested": "2021-02-16T11:12:28.827245800Z",
"kind": "event",
"action": "user.session.end",
"id": "faf7398a-4f77-11ea-97fb-5925e98228bd",
"category": [
"authentication",
"session"
],
"type": [
"end",
"user"
],
"outcome": "success"
},
"okta": {
"actor": {
"id": "00u1abvz4pYqdM8ms4x6",
"display_name": "xxxxxx",
"type": "User",
"alternate_id": "xxxxxx@elastic.co"
},
"debug_context": {
"debug_data": {
"threat_suspected": "false",
"request_id": "XkccyyMli2Uay2I93ZgRzQAAB0c",
"request_uri": "/login/signout",
"url": "/login/signout?message=login_page_messages.session_has_expired"
}
},
"event_type": "user.session.end",
"authentication_context": {
"authentication_step": 0,
"external_session_id": "102nZHzd6OHSfGG51vsoc22gw"
},
"display_message": "User logout from Okta",
"client": {
"zone": "null",
"device": "Computer",
"user_agent": {
"os": "Mac OS X",
"raw_user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0",
"browser": "FIREFOX"
},
"ip": "108.255.197.247"
},
"uuid": "faf7398a-4f77-11ea-97fb-5925e98228bd",
"outcome": {
"result": "SUCCESS"
},
"transaction": {
"type": "WEB",
"id": "XkccyyMli2Uay2I93ZgRzQAAB0c"
}
},
"user": {
"full_name": "xxxxxx"
},
"user_agent": {
"name": "Firefox",
"original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0",
"os": {
"name": "Mac OS X",
"version": "10.15",
"full": "Mac OS X 10.15"
},
"device": {
"name": "Mac"
},
"version": "72.0."
}
}
]
}
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
input: logfile
vars:
keep_original_message: true
paths:
- "{{SERVICE_LOGS_DIR}}/*system*.log"
Loading

0 comments on commit d348d1a

Please sign in to comment.