-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdb-sa.json
More file actions
72 lines (72 loc) · 3.21 KB
/
db-sa.json
File metadata and controls
72 lines (72 loc) · 3.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
{
"event": {
"srTotal": 100,
"total": 100,
"sessionId": "1111-2222-3333-4444-5555",
"queryUsingTime": 10,
"complete": true,
"errorCode": -1,
"entity": [{
"deviceSendProductName": "windows_eventLog",
"eventNum": "7036",
"endTime": "2017-03-06 20:08:11",
"destServiceName": "WinHTTP Web Proxy Auto-Discovery Service",
"startTime": "2017-03-06 20:08:11",
"deviceName": "192.168.27.48",
"eventId": "4547867547780798977",
"deviceCat": "/OperatingSystem",
"source_address": "51.15.1.100",
"windowsAgentSendSourceType": "Service Control Manager",
"hostName": "WIN2008.usmapp.com",
"userName": "SYSTEM",
"deviceVersion": "Windows 2008",
"rawEvent": "0|EventlogType=system|DetectTime=2017-03-06 20:08:11|EventSource=Service Control Manager|EventID=7036|EventType=Information|EventCategory=0|User=NT AUTHORITY\\\\SYSTEM|ComputerName=WIN2008.usmapp.com|Description=WinHTTP Web Proxy Auto-Discovery Service 服务处于 停止 状态。 ",
"recCollectorId": "1",
"deviceId": "124124",
"deviceVendor": "微软(Microsoft)",
"categoryType": "0",
"catSignificance": "/Informational",
"catBehavior": "/Execute/Stop",
"deviceAddress": "192.168.27.48",
"logType_zh": "系统",
"deviceAssetTypeId": "46",
"destGeoAddress": "波兰",
"timeEnd": "2017-03-06 20:40:59",
"timeStart": "2017-03-06 20:40:59",
"catTechnique": "/UNKNOW",
"ongo": "a",
"dateTime": "2017-03-06 20:08:11",
"securityTypeName": "设备异常",
"deviceModel": "Windows",
"destAssetId": "124124",
"destHostName": "WIN2008.usmapp.com",
"deviceAssetSubTypeId": "1",
"eventType": "1",
"mapperIdentifier": "b3a3ed97-509f-43bb-b70d-e3be34d65e37",
"externalId": "windows-Event:Service Control Manager-7036",
"destAssetName": "192.168.27.48",
"collectorReceiptTime": "2017-03-06 20:40:59",
"customerId": "8",
"name": "WinHTTP Web Proxy Auto-Discovery Service 服务处于停止状态",
"deviceAssetType": "主机类",
"destServiceType": "停止",
"deviceReceiptTime": "2017-03-06 20:08:11",
"catObject": "/Host/Application/Service",
"sourceType": "Service Control Manager",
"catOutcome": "OK",
"logEventSecType": "5",
"eventCount": "1",
"severity": "1",
"productVendorName": "microsoft",
"windowsAgentSendSecureTypeName": "Information",
"secureType": "信息",
"destAddress": "192.168.27.48",
"windowsAgentSendSecureType": "Information",
"message": "WinHTTP Web Proxy Auto-Discovery Service 服务处于停止状态。事件来源:Service Control Manager",
"goon": "a",
"deviceProtocol": "syslog",
"logType": "system",
"deviceAssetSubType": "Windows"
}]
}
}