Azure-Sentinel/Sample Data/CEF/onapsis_sample_logs.csv

14 KiB

1TenantIdSourceSystemTimeGenerated [UTC]ReceiptTimeDeviceVendorDeviceProductDeviceEventClassIDLogSeverityOriginalLogSeverityDeviceActionSimplifiedDeviceActionComputerCommunicationDirectionDeviceFacilityDestinationPortDestinationIPDeviceAddressDeviceNameMessageProtocolSourcePortSourceIPRemoteIPRemotePortMaliciousIPThreatSeverityIndicatorThreatTypeThreatDescriptionThreatConfidenceReportReferenceLinkMaliciousIPLongitudeMaliciousIPLatitudeMaliciousIPCountryDeviceVersionActivityApplicationProtocolEventCountDestinationDnsDomainDestinationServiceNameDestinationTranslatedAddressDestinationTranslatedPortDeviceDnsDomainDeviceExternalIDDeviceInboundInterfaceDeviceNtDomainDeviceOutboundInterfaceDevicePayloadIdProcessNameDeviceTranslatedAddressDestinationHostNameDestinationMACAddressDestinationNTDomainDestinationProcessIdDestinationUserPrivilegesDestinationProcessNameDeviceTimeZoneDestinationUserIDDestinationUserNameDeviceMacAddressProcessIDExternalIDFileCreateTimeFileHashFileIDFileModificationTimeFilePathFilePermissionFileTypeFileNameFileSizeReceivedBytesOldFileCreateTimeOldFileHashOldFileIDOldFileModificationTimeOldFileNameOldFilePathOldFilePermissionOldFileSizeOldFileTypeSentBytesRequestURLRequestClientApplicationRequestContextRequestCookiesRequestMethodSourceHostNameSourceMACAddressSourceNTDomainSourceDnsDomainSourceServiceNameSourceTranslatedAddressSourceTranslatedPortSourceProcessIdSourceUserPrivilegesSourceProcessNameSourceUserIDSourceUserNameEventTypeDeviceCustomIPv6Address1DeviceCustomIPv6Address1LabelDeviceCustomIPv6Address2DeviceCustomIPv6Address2LabelDeviceCustomIPv6Address3DeviceCustomIPv6Address3LabelDeviceCustomIPv6Address4DeviceCustomIPv6Address4LabelDeviceCustomFloatingPoint1DeviceCustomFloatingPoint1LabelDeviceCustomFloatingPoint2DeviceCustomFloatingPoint2LabelDeviceCustomFloatingPoint3DeviceCustomFloatingPoint3LabelDeviceCustomFloatingPoint4DeviceCustomFloatingPoint4LabelDeviceCustomNumber1DeviceCustomNumber1LabelDeviceCustomNumber2DeviceCustomNumber2LabelDeviceCustomNumber3DeviceCustomNumber3LabelDeviceCustomString1DeviceCustomString1LabelDeviceCustomString2DeviceCustomString2LabelDeviceCustomString3DeviceCustomString3LabelDeviceCustomString4DeviceCustomString4LabelDeviceCustomString5DeviceCustomString5LabelDeviceCustomString6DeviceCustomString6LabelDeviceCustomDate1DeviceCustomDate1LabelDeviceCustomDate2DeviceCustomDate2LabelFlexDate1FlexDate1LabelFlexNumber1FlexNumber1LabelFlexNumber2FlexNumber2LabelFlexString1FlexString1LabelFlexString2FlexString2LabelAdditionalExtensionsStartTime [UTC]EndTime [UTC]Type_ResourceId
243b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 11:23:37.472 AMOnapsisOSP30truetrueSTADnull192.168.206.20Dangerous RFC ExecutionNonenull192.168.206.20nullnullnull2.2020.92.0.0Vulnerable Access Alertnullnull__EMPTY__nullNonenullnullnullnullnullnullABAPnullnullNoneZONAPSISnullnullnullnullnull1confidencenullnullEBDasset_name000clientNoneloglineNov 07 2020 11:22:27 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=bd616cd67c011b2fe2aa9c6ce6f88b7c;OnapsisOSPProfileId=31;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=EBD;OnapsisOSPTerminalSource=192.168.206.20;OnapsisOSPVulnerabilityCvss=None;cat=VulnerableAccess;end=Nov 07 2020 11:23:37 UTC;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
343b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 11:23:37.484 AMOnapsisOSP40truetrueSTADnull192.168.206.20Dangerous RFC ExecutionNonenull192.168.206.20nullnullnull2.2020.92.0.0Sensitive Access Alertnullnull__EMPTY__nullNonenullnullnullnullnullnullABAPnullnullNoneZONAPSISnullnullnullnullnull1confidencenullnullEBDasset_name000clientNoneloglineNov 07 2020 11:22:27 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=b89ce0506f4b73b5e8a96c2f10d4d1bf;OnapsisOSPProfileId=30;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=EBD;OnapsisOSPTerminalSource=192.168.206.20;OnapsisOSPVulnerabilityCvss=None;cat=SensitiveAccess;end=Nov 07 2020 11:23:37 UTC;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
443b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 11:23:37.484 AMOnapsisOSP40truetrueSTADnull192.168.206.20Dangerous RFC ExecutionNonenull192.168.206.20nullnullnull2.2020.92.0.0Sensitive Access Alertnullnull__EMPTY__nullNonenullnullnullnullnullnullABAPnullnullNoneZONAPSISnullnullnullnullnull1confidencenullnullEBDasset_name000clientNoneloglineNov 07 2020 11:22:27 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=9460b245a8db018f57a0a7f3e4d52c94;OnapsisOSPProfileId=30;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=EBD;OnapsisOSPTerminalSource=192.168.206.20;OnapsisOSPVulnerabilityCvss=None;cat=SensitiveAccess;end=Nov 07 2020 11:23:37 UTC;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
543b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.243 PMOnapsisOSP10truetrueSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneUAT_USERnullnullnullnullnull3confidencenullnullUA5asset_name000clientNoneloglineNonepatch_appliedNov 07 2020 14:07:15 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:08:09 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
643b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.255 PMOnapsisOSP10truetrueSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneOP_USERnullnullnullnullnull3confidencenullnullUA5asset_name001clientNoneloglineNonepatch_appliedNov 07 2020 14:08:02 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:08:09 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
743b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.269 PMOnapsisOSP10truetrueSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneUAT_USERnullnullnullnullnull3confidencenullnullUA5asset_name000clientNoneloglineNonepatch_appliedNov 07 2020 14:08:15 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:09:09 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
843b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.270 PMOnapsisOSP10falsefalseSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneUNKNOWNnullnullnullnullnull3confidencenullnullUA5asset_name000clientNoneloglineNonepatch_appliedNov 07 2020 14:08:46 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:09:09 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
943b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.270 PMOnapsisOSP10falsefalseSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneUNKNOWNnullnullnullnullnull3confidencenullnullUA5asset_name000clientNoneloglineNonepatch_appliedNov 07 2020 14:08:46 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:09:09 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
1043b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.270 PMOnapsisOSP10truetrueSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneOP_USERnullnullnullnullnull3confidencenullnullUA5asset_name001clientNoneloglineNonepatch_appliedNov 07 2020 14:09:02 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:09:09 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog
1143b17a91-11c4-45ef-9d0f-b544951e7039OpsManager11/7/2020, 2:15:49.284 PMOnapsisOSP10truetrueSTADnull192.168.224.36CS_UAT_102RFCnullnullnullnull2.2020.92.0.0CS_UAT_102nullnull__EMPTY__nullNonenullnullnullnullnullnullABAPlabsapsrv254.orl.onanullnullNoneUAT_USERnullnullnullnullnull3confidencenullnullUA5asset_name000clientNoneloglineNonepatch_appliedNov 07 2020 14:09:15 UTCnullnullOnapsisOSPColumnBname=None;OnapsisOSPColumnProfile=None;OnapsisOSPDetectedCompliance=None;OnapsisOSPDownloadedTable=None;OnapsisOSPEvents=None;OnapsisOSPIncidentDetail=None;OnapsisOSPMatchingRule=None;OnapsisOSPModuleCategory=None;OnapsisOSPModuleDescription=None;OnapsisOSPModuleName=None;OnapsisOSPPolicy=None;OnapsisOSPProfileId=68;OnapsisOSPProgramName=None;OnapsisOSPResult=None;OnapsisOSPSapSecNotes=None;OnapsisOSPSid=UA5;OnapsisOSPTerminalSource=labsapsrv254.orl.ona;OnapsisOSPVulnerabilityCvss=None;cat=UserActivity;end=Nov 07 2020 14:10:10 ;event_id=None;reason=None;sev=61/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog