id
string
rule
{ "comment":string, "group":string, "level":bigint, "sidid":bigint, "CIS":[string], "cve":string, "firedtimes":bigint, "frequency":bigint, "groups":[string], "info":string, "PCI_DSS":[string] }
TimeStamp
timestamp
location
string
hostname
string
full_log
string
action
string
agentip
string
agent_name
string
command
string
data
string
decoder
string
decoder_desc
{ "accumulate":bigint, "fts":bigint, "ftscomment":string, "name":string, "parent":string }
decoder_parent
string
dstgeoip
string
dstip
string
dstport
string
dstuser
string
logfile
string