This repository has been archived by the owner on Feb 15, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathsplunk-sanitized-payload-formatted.json
59 lines (59 loc) · 2.28 KB
/
splunk-sanitized-payload-formatted.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
{
"results_link": "https://splunk.example.com:8000/app/search/@go?sid=scheduler__abc0001__search__RMD5267e440bddd8ef1f_at_1581522000_11805",
"result": {
"contextData": "",
"date_month": "february",
"forcecdn": "",
"http_status_code": "200",
"_bkt": "ezproxy-http~158~A31E767E-7887-4A15-86F1-2CB85DB0F805",
"_indextime": "1581517935",
"_kv": "1",
"linecount": "1",
"ezproxy_time": "12/Feb/2020:08:32:15 -0600",
"_serial": "0",
"_time": "1581517935",
"eventtype": "lib_events",
"_eventtype_color": "none",
"sp": "",
"bhskip": "",
"_sourcetype": "ezproxy-http",
"punct": "..._-__[//:::_-]_\"_://...:///_/.\"___\"/._(__.;_;_)_",
"splunk_server": "splunk-index9000",
"session": "",
"host": "ezproxy",
"url": "",
"srcip": "192.168.2.3",
"splunk_server_group": "",
"_cd": "158:1576585",
"_si": [
"splunk-index9000",
"ezproxy-http"
],
"tag::eventtype": "library",
"timestartpos": "25",
"date_hour": "8",
"date_second": "15",
"timeendpos": "51",
"username": "abc0001",
"date_minute": "32",
"date_mday": "12",
"index": "ezproxy-http",
"timeZoneId": "",
"sourcetype": "ezproxy-http",
"rs": "",
"transitionType": "",
"date_wday": "wednesday",
"source": "/path/to/traffic/log/file.txt",
"date_zone": "-360",
"tag": "library",
"date_year": "2020",
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.100 Safari/537.36",
"_raw": "192.168.2.3 - abc0001 [12/Feb/2020:08:32:15 -0600] \"POST https://1.vendor.example.com:443/V1/Session/ExtendSessionActiveBrowser HTTP/1.1\" 200 0 \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.100 Safari/537.36\"",
"URL": "https://1.vendor.example.com:443/V1/Session/ExtendSessionActiveBrowser",
"vr": ""
},
"sid": "scheduler__abc0001__search__RMD5267e440bddd8ef1f_at_1581522000_11805",
"owner": "abc0001",
"app": "search",
"search_name": "TEST - Webhook - Echo"
}