Azure-Sentinel/Sample Data/Custom/MongoDBAudit_CL.json

1397 строки
27 KiB
JSON

[
{
"atype": "authCheck",
"ts": {
"$date": "2017-02-14T14:15:49.161+0100"
},
"uuid": {
"$binary": "88a062fc-8eca-41b5-94a0-4cab3444191f",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"command": "insert",
"ns": "test.orders",
"args": {
"insert": "orders",
"documents": [
{
"_id": {
"$oid": "58a3030507bd5e3486b1220d"
},
"id": 1,
"item": "paper clips"
}
],
"ordered": true
}
},
"result": 13
},
{
"atype": "authenticate",
"ts": {
"$date": "2017-02-14T14:11:29.975+0100"
},
"uuid": {
"$binary": "74b258fb-aa16-47cf-a2e5-6e2a847a4813",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42634
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"user": "root",
"db": "admin",
"mechanism": "SCRAM-SHA-1"
},
"result": 18
},
{
"atype": "createDatabase",
"ts": {
"$date": "2017-02-17T12:13:48.142+0100"
},
"uuid": {
"$binary": "b6cc5e4f-33a8-41f0-8659-bc21e3e630a8",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 47896
},
"users": [
{
"user": "prod_app",
"db": "admin"
}
],
"roles": [
{
"role": "root",
"db": "admin"
}
],
"param": {
"ns": "prod"
},
"result": 0
},
{
"atype": "clientMetadata",
"ts": {
"$date": "2022-02-08T08:18:31.142+0100"
},
"uuid": {
"$binary": "a24a8bb8-4505-44f4-b498-9ef0b0680cc6",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 47896
},
"users": [
{
"user": "prod_app",
"db": "admin"
}
],
"roles": [
{
"role": "root",
"db": "admin"
}
],
"param": {
"localEndpoint": {
"ip": "127.0.1.1",
"port": 27017
},
"clientMetadata": {
"driver": {
"name": "mongo-go-driver",
"version": "v1.3.4"
},
"os": {
"type": "linux",
"name": "linux",
"architecture": "amd64",
"version": "v1.2.3"
},
"platform": "go1.14.7",
"application": {
"name": "MongoDB Automation Agent v10.23.3.6702 (git: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx)"
}
}
},
"result": 0
},
{
"atype": "createCollection",
"ts": {
"$date": "2022-05-08T20:31:17.142+0100"
},
"uuid": {
"$binary": "8287d81c-b99f-4589-a4de-a48ba379c99f",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 47896
},
"users": [
{
"user": "prod_app",
"db": "admin"
}
],
"roles": [
{
"role": "root",
"db": "admin"
}
],
"param": {
"ns": "viewName",
"viewOn": "collName",
"pipeline": [
{
"_id": 0,
"name": "Pepperoni",
"size": "small",
"price": 19,
"quantity": 10,
"date": "2021-03-13T08:14:30Z"
},
{
"_id": 1,
"name": "Pepperoni",
"size": "medium",
"price": 20,
"quantity": 20,
"date": "2021-03-13T09:13:24Z"
}
]
},
"result": 0
},
{
"atype": "createIndex",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "testDatabase.testCollection",
"indexName": "indexName",
"indexSpec": "547e184b94219d5",
"indexBuildState": "IndexBuildSucceeded"
},
"result": 0
},
{
"atype": "directAuthMutation",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"document": {
"_id": 1,
"category": "caf\u00e9",
"status": "A"
},
"ns": "test.create",
"operation": "insert"
},
"result": 0
},
{
"atype": "renameCollection",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"old": "testDatabase.testCollection",
"new": "Database.Collection"
},
"result": 0
},
{
"atype": "dropCollection",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "viewName",
"viewOn": "collName",
"pipeline": [
{
"_id": 0,
"name": "Pepperoni",
"size": "small",
"price": 19,
"quantity": 10,
"date": "2021-03-13T08:14:30Z"
},
{
"_id": 1,
"name": "Pepperoni",
"size": "medium",
"price": 20,
"quantity": 20,
"date": "2021-03-13T09:13:24Z"
}
]
},
"result": 0
},
{
"atype": "dropDatabase",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "testDatabase"
},
"result": 0
},
{
"atype": "dropIndex",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "testDatabase.testCollection",
"indexName": "indexName"
},
"result": 0
},
{
"atype": "createUser",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"user": "Shap",
"db": "testDatabase",
"roles": [
{
"role": "read",
"db": "admin"
}
]
},
"result": 0
},
{
"atype": "dropUser",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"user": "Shap",
"db": "testDatabase"
},
"result": 0
},
{
"atype": "dropAllUsersFromDatabase",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"db": "testDatabase"
},
"result": 0
},
{
"atype": "updateUser",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"user": "Shap",
"db": "testDatabase",
"passwordChanged": true,
"roles": [
{
"role": "read",
"db": "admin"
}
]
},
"result": 0
},
{
"atype": "grantRolesToUser",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"user": "Shap",
"db": "testDatabase",
"roles": [
{
"role": "read",
"db": "admin"
}
]
},
"result": 0
},
{
"atype": "revokeRolesFromUser",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"user": "Shap",
"db": "testDatabase",
"roles": [
{
"role": "read",
"db": "admin"
}
]
},
"result": 0
},
{
"atype": "createRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase"
},
"result": 0
},
{
"atype": "updateRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase"
},
"result": 0
},
{
"atype": "dropRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase"
},
"result": 0
},
{
"atype": "dropAllRolesFromDatabase",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"db": "testDatabase"
},
"result": 0
},
{
"atype": "grantRolesToRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase",
"roles": [
{
"role": "read",
"db": "admin"
}
]
},
"result": 0
},
{
"atype": "revokeRolesFromRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase",
"roles": [
{
"role": "read",
"db": "admin"
}
]
},
"result": 0
},
{
"atype": "grantPrivilegesToRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase",
"privileges": [
{
"resource": {
"cluster": true
},
"actions": [
"shutdown"
]
}
]
},
"result": 0
},
{
"atype": "revokePrivilegesFromRole",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"role": "read",
"db": "testDatabase",
"privileges": [
{
"resource": {
"cluster": true
},
"actions": [
"shutdown"
]
}
]
},
"result": 0
},
{
"atype": "replSetReconfig",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"old": {
"_id": "124124124bh21",
"version": 5,
"term": 12,
"protocolVersion": 1,
"writeConcernMajorityJournalDefault": true,
"configsvr": true,
"members": [
{
"_id": "124124124bh21",
"host": "localhost",
"arbiterOnly": false,
"buildIndexes": true,
"hidden": false,
"priority": 1,
"tags": {
"tag1": "string1",
"tag2": "string2"
},
"secondaryDelaySecs": 1,
"votes": 1
}
],
"settings": {
"chainingAllowed": true,
"heartbeatIntervalMillis": 30000,
"heartbeatTimeoutSecs": 10,
"electionTimeoutMillis": 10000,
"catchUpTimeoutMillis": -1,
"replicaSetId": "61d5abf2404700b3e321b7b7"
}
},
"new": {
"_id": "124124124bh21",
"version": 5,
"term": 12,
"protocolVersion": 1,
"writeConcernMajorityJournalDefault": false,
"configsvr": true,
"members": [
{
"_id": "124124124bh21",
"host": "localhost",
"arbiterOnly": false,
"buildIndexes": true,
"hidden": false,
"priority": 1,
"tags": {
"tag1": "string1",
"tag2": "string2"
},
"secondaryDelaySecs": 1,
"votes": 1
}
],
"settings": {
"chainingAllowed": true,
"heartbeatIntervalMillis": 30000,
"heartbeatTimeoutSecs": 10,
"electionTimeoutMillis": 10000,
"catchUpTimeoutMillis": -1,
"replicaSetId": "61d5abf2404700b3e321b7b7"
}
}
},
"result": 0
},
{
"atype": "enableSharding",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "testDatabase"
},
"result": 0
},
{
"atype": "shardCollection",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "testDatabase.testCollection",
"key": {
"customer_id": 1,
"order_id": 1
},
"options": {
"unique": true
}
},
"result": 0
},
{
"atype": "addShard",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"shard": "rs1",
"connectionString": "mongodb0.example.net:27018",
"maxSize": 16
},
"result": 0
},
{
"atype": "refineCollectionShardKey",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"ns": "testDatabase.testCollection",
"key": {
"customer_id": 1,
"order_id": 1
}
},
"result": 0
},
{
"atype": "removeShard",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"shard": "rs1"
},
"result": 0
},
{
"atype": "shutdown",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {},
"result": 0
},
{
"atype": "applicationMessage",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"msg": "Wrong login or password."
},
"result": 0
},
{
"atype": "logout",
"ts": {
"$date": "2022-05-08T17:55:16.161+0100"
},
"uuid": {
"$binary": "43c246fa-f9c9-4824-8e72-d1770056c000",
"$type": "04"
},
"local": {
"ip": "127.0.1.1",
"port": 27017
},
"remote": {
"ip": "127.0.0.1",
"port": 42636
},
"users": [
{
"user": "antun",
"db": "admin"
}
],
"roles": [
{
"role": "read",
"db": "admin"
}
],
"param": {
"reason": "Implicit logout due to client connection closure",
"initialUsers": [
{
"user": "Shap",
"db": "testDatabase"
}
],
"updatedUsers": [
{
"user": "Shap",
"db": "testDatabase"
}
]
},
"result": 0
}
]