Skip to content

Commit 967373d

Browse files
authored
[SEC-31850][k9] OCSF facets: add type: integer (DataDog#23785)
1 parent 7119f33 commit 967373d

7 files changed

Lines changed: 30 additions & 0 deletions

File tree

azure_active_directory/assets/logs/azure.activedirectory.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -162,6 +162,7 @@ facets:
162162
name: Activity ID
163163
path: ocsf.activity_id
164164
source: log
165+
type: integer
165166
- groups:
166167
- OCSF
167168
name: Activity Name
@@ -172,6 +173,7 @@ facets:
172173
name: Category ID
173174
path: ocsf.category_uid
174175
source: log
176+
type: integer
175177
- groups:
176178
- OCSF
177179
name: Category
@@ -182,6 +184,7 @@ facets:
182184
name: Class ID
183185
path: ocsf.class_uid
184186
source: log
187+
type: integer
185188
- groups:
186189
- OCSF
187190
name: Class
@@ -212,6 +215,7 @@ facets:
212215
name: Status ID
213216
path: ocsf.status_id
214217
source: log
218+
type: integer
215219
pipeline:
216220
type: pipeline
217221
name: Azure Active Directory

cisco_duo/assets/logs/cisco-duo.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,7 @@ facets:
3535
name: Activity ID
3636
path: ocsf.activity_id
3737
source: log
38+
type: integer
3839
- groups:
3940
- OCSF
4041
name: Activity Name
@@ -45,6 +46,7 @@ facets:
4546
name: Category ID
4647
path: ocsf.category_uid
4748
source: log
49+
type: integer
4850
- groups:
4951
- OCSF
5052
name: Category
@@ -55,6 +57,7 @@ facets:
5557
name: Class ID
5658
path: ocsf.class_uid
5759
source: log
60+
type: integer
5861
- groups:
5962
- OCSF
6063
name: Class
@@ -110,6 +113,7 @@ facets:
110113
name: Status ID
111114
path: ocsf.status_id
112115
source: log
116+
type: integer
113117
pipeline:
114118
type: pipeline
115119
name: Cisco Duo

cisco_umbrella_dns/assets/logs/cisco-umbrella-dns.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -190,11 +190,13 @@ facets:
190190
name: Activity ID
191191
path: ocsf.activity_id
192192
source: log
193+
type: integer
193194
- groups:
194195
- OCSF
195196
name: Category ID
196197
path: ocsf.category_uid
197198
source: log
199+
type: integer
198200
- groups:
199201
- OCSF
200202
name: Category
@@ -205,6 +207,7 @@ facets:
205207
name: Class ID
206208
path: ocsf.class_uid
207209
source: log
210+
type: integer
208211
- groups:
209212
- OCSF
210213
name: Class
@@ -230,6 +233,7 @@ facets:
230233
name: Status ID
231234
path: ocsf.status_id
232235
source: log
236+
type: integer
233237
- groups:
234238
- OCSF
235239
name: Request URL String

lastpass/assets/logs/lastpass.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,7 @@ facets:
5959
name: Activity ID
6060
path: ocsf.activity_id
6161
source: log
62+
type: integer
6263
- groups:
6364
- OCSF
6465
name: Activity Name
@@ -69,6 +70,7 @@ facets:
6970
name: Category ID
7071
path: ocsf.category_uid
7172
source: log
73+
type: integer
7274
- groups:
7375
- OCSF
7476
name: Category
@@ -79,6 +81,7 @@ facets:
7981
name: Class ID
8082
path: ocsf.class_uid
8183
source: log
84+
type: integer
8285
- groups:
8386
- OCSF
8487
name: Class
@@ -119,6 +122,7 @@ facets:
119122
name: Status ID
120123
path: ocsf.status_id
121124
source: log
125+
type: integer
122126
pipeline:
123127
type: pipeline
124128
name: LastPass

ssh_check/assets/logs/sshd.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,11 +28,13 @@ facets:
2828
name: Activity ID
2929
path: ocsf.activity_id
3030
source: log
31+
type: integer
3132
- groups:
3233
- OCSF
3334
name: Category ID
3435
path: ocsf.category_uid
3536
source: log
37+
type: integer
3638
- groups:
3739
- OCSF
3840
name: Category
@@ -43,6 +45,7 @@ facets:
4345
name: Class ID
4446
path: ocsf.class_uid
4547
source: log
48+
type: integer
4649
- groups:
4750
- OCSF
4851
name: Class
@@ -68,6 +71,7 @@ facets:
6871
name: Status ID
6972
path: ocsf.status_id
7073
source: log
74+
type: integer
7175
pipeline:
7276
type: pipeline
7377
name: Sshd

tomcat/assets/logs/tomcat.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -87,11 +87,13 @@ facets:
8787
name: Activity ID
8888
path: ocsf.activity_id
8989
source: log
90+
type: integer
9091
- groups:
9192
- OCSF
9293
name: Category ID
9394
path: ocsf.category_uid
9495
source: log
96+
type: integer
9597
- groups:
9698
- OCSF
9799
name: Category
@@ -102,6 +104,7 @@ facets:
102104
name: Class ID
103105
path: ocsf.class_uid
104106
source: log
107+
type: integer
105108
- groups:
106109
- OCSF
107110
name: Class
@@ -122,6 +125,7 @@ facets:
122125
name: Status ID
123126
path: ocsf.status_id
124127
source: log
128+
type: integer
125129
- groups:
126130
- OCSF
127131
name: Severity
@@ -132,6 +136,7 @@ facets:
132136
name: Severity ID
133137
path: ocsf.severity_id
134138
source: log
139+
type: integer
135140
- groups:
136141
- OCSF
137142
name: Request URL String

zeek/assets/logs/zeek.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -395,6 +395,7 @@ facets:
395395
name: Activity ID
396396
path: ocsf.activity_id
397397
source: log
398+
type: integer
398399
- groups:
399400
- OCSF
400401
name: Activity Name
@@ -405,6 +406,7 @@ facets:
405406
name: Category ID
406407
path: ocsf.category_uid
407408
source: log
409+
type: integer
408410
- groups:
409411
- OCSF
410412
name: Category
@@ -415,6 +417,7 @@ facets:
415417
name: Class ID
416418
path: ocsf.class_uid
417419
source: log
420+
type: integer
418421
- groups:
419422
- OCSF
420423
name: Class
@@ -430,6 +433,7 @@ facets:
430433
name: Severity ID
431434
path: ocsf.severity_id
432435
source: log
436+
type: integer
433437
- groups:
434438
- OCSF
435439
name: Status
@@ -440,6 +444,7 @@ facets:
440444
name: Status ID
441445
path: ocsf.status_id
442446
source: log
447+
type: integer
443448
- groups:
444449
- OCSF
445450
name: Source IP Address

0 commit comments

Comments
 (0)