Documentation
¶
Overview ¶
ECS event mapping functions.
ECS history mapping functions.
ECS jumplist mapping functions.
ECS shellbag mapping functions.
ECS specification.
Index ¶
Constants ¶
View Source
const (
Version = "8.11"
)
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Evt ¶
type Evt struct {
Kind string `json:"kind,omitempty"`
Module string `json:"module,omitempty"`
Dataset string `json:"dataset,omitempty"`
Severity int64 `json:"severity,omitempty"`
ID string `json:"id,omitempty"`
Code string `json:"code,omitempty"`
Provider string `json:"provider,omitempty"`
Ingested time.Time `json:"ingested,omitempty"`
Original string `json:"original,omitempty"`
Hash string `json:"hash,omitempty"`
}
type Log ¶
type Log struct {
Base
Ecs *Ecs `json:"ecs"`
Agent *Agent `json:"agent"`
Event *Evt `json:"event"`
File *File `json:"file"`
Url *Url `json:"url,omitempty"`
Host *Host `json:"host,omitempty"`
User *User `json:"user,omitempty"`
Process *Process `json:"process,omitempty"`
Registry *Registry `json:"registry,omitempty"`
}
func MapJumpList ¶
func MapShellBag ¶
type Process ¶
type Process struct {
PID int64 `json:"pid,omitempty"`
Thread *Thread `json:"thread,omitempty"`
EntityID string `json:"entity_id,omitempty"`
Name string `json:"name,omitempty"`
Title string `json:"title,omitempty"`
Args []string `json:"args,omitempty"`
ArgsCount int64 `json:"args_count,omitempty"`
Executable string `json:"executable,omitempty"`
CommandLine string `json:"command_line,omitempty"`
WorkingDirectory string `json:"working_directory,omitempty"`
}
type Url ¶
type Url struct {
Original string `json:"original,omitempty"`
Full string `json:"full,omitempty"`
Scheme string `json:"scheme,omitempty"`
Domain string `json:"domain,omitempty"`
Port int64 `json:"port,omitempty"`
Path string `json:"path,omitempty"`
Query string `json:"query,omitempty"`
Fragment string `json:"fragment,omitempty"`
Username string `json:"username,omitempty"`
Password string `json:"password,omitempty"`
}
Click to show internal directories.
Click to hide internal directories.