복사 스키마: ThinkstCanary.Alert
설명: Thinkst Canary의 알러트 로그
참조URL: https://help.canary.tools/hc/en-gb/articles/360002431478-I-want-to-integrate-my-SIEM-with-my-Canaries
필드:
- name: AdditionalDetails
type: array
element:
type: array
element:
유형: json
- name: AlertType
type: string
- name: CanaryID
type: string
- name: CanaryIP
type: string
지표:
- ip
- name: CanaryPublicIP
type: string
지표:
- ip
- name: CanaryLocation
type: string
- name: CanaryName
type: string
- name: CanaryPort
type: string
- name: Description
required: true
type: string
- name: Flock
type: string
- name: IncidentHash
type: string
지표:
- md5
- name: IncidentKey
type: string
- name: Intro
required: true
type: string
- name: Reminder
type: string
- name: ReverseDNS
type: string
- name: MatchedAnnotations
type: string
- name: TimestampGlobalTZ
type: string
- name: Token
type: string
- name: Triggered
type: string
- name: SourceIP
type: string
지표:
- ip
- name: Timestamp
required: true
type: timestamp
timeFormats:
- '%Y-%m-%d %H:%M:%S (%Z)'
isEventTime: true