Documentation ¶
Overview ¶
ECS event mapping functions.
ECS history mapping functions.
ECS jumplist mapping functions.
ECS shellbag mapping functions.
ECS specification.
Index ¶
Constants ¶
View Source
const (
Version = "8.11"
)
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Evt ¶
type Evt struct { Kind string `json:"kind,omitempty"` Module string `json:"module,omitempty"` Dataset string `json:"dataset,omitempty"` Severity int64 `json:"severity,omitempty"` ID string `json:"id,omitempty"` Code string `json:"code,omitempty"` Provider string `json:"provider,omitempty"` Ingested time.Time `json:"ingested,omitempty"` Original string `json:"original,omitempty"` Hash string `json:"hash,omitempty"` }
type Log ¶ added in v0.27.0
type Log struct { Base Ecs *Ecs `json:"ecs"` Agent *Agent `json:"agent"` Event *Evt `json:"event"` File *File `json:"file"` Url *Url `json:"url,omitempty"` Host *Host `json:"host,omitempty"` User *User `json:"user,omitempty"` Process *Process `json:"process,omitempty"` Registry *Registry `json:"registry,omitempty"` }
func MapJumpList ¶ added in v0.27.0
func MapShellBag ¶ added in v0.28.0
type Process ¶
type Process struct { PID int64 `json:"pid,omitempty"` Thread *Thread `json:"thread,omitempty"` EntityID string `json:"entity_id,omitempty"` Name string `json:"name,omitempty"` Title string `json:"title,omitempty"` Args []string `json:"args,omitempty"` ArgsCount int64 `json:"args_count,omitempty"` Executable string `json:"executable,omitempty"` CommandLine string `json:"command_line,omitempty"` WorkingDirectory string `json:"working_directory,omitempty"` }
type Url ¶ added in v0.30.0
type Url struct { Original string `json:"original,omitempty"` Full string `json:"full,omitempty"` Scheme string `json:"scheme,omitempty"` Domain string `json:"domain,omitempty"` Port int64 `json:"port,omitempty"` Path string `json:"path,omitempty"` Query string `json:"query,omitempty"` Fragment string `json:"fragment,omitempty"` Username string `json:"username,omitempty"` Password string `json:"password,omitempty"` }
Click to show internal directories.
Click to hide internal directories.