@@ -146,7 +146,7 @@ Example input:
146
146
| :--- | :--- | :--- | :--- | :--- |
147
147
| count| integer| True| Number of log entries found| 10|
148
148
|results_events|[]events|False|Query Results|[{"labels": [],"timestamp": 1601598638768,"sequence_number": 123456789123456789,"log_id": "64z0f0p9-1a99-4501-xe36-a6d03687f313","message": {"timestamp": "2020-10-02T00:29:14.649Z","destination_asset": "iagent-win7","source_asset_address": "192.168.100.50","destination_asset_address": "example-host","destination_local_account": "user","logon_type": "NETWORK","result": "SUCCESS","new_authentication": "false","service": "ntlmssp ","source_json": {"sourceName": "Microsoft-Windows-Security-Auditing","insertionStrings": ["S-1-0-0","-","-","0x0","X-X-X-XXXXXXXXXXX","user@example.com","example-host","0x204f163c","3","NtLmSsp ","NTLM","","{00000000-0000-0000-0000-000000000000}","-","NTLM V2","128","0x0","-","192.168.50.1","59090"],"eventCode": 4624,"computerName": "example-host","sid": "","isDomainController": false,"eventData": null,"timeWritten": "2020-10-02T00:29:13.670722000Z"}},"links": [{"rel": "Context","href": "https://us.api.insight.rapid7.com/log_search/query/context/xxxx"}],"sequence_number_str": "123456789123456789"}]|
149
- |results_statistical|statistics|False|Query Results|{"leql":{"during":{"from":1699579214000,"to":1699622414000},"statement":"groupby(r7_context.asset.name)"},"logs":["123456-abcd-1234-abcd-123456abc"],"search_stats":{"bytes_all":9961260,"bytes_checked":9961260,"duration_ms":19,"events_all":1640,"events_checked":1640,"events_matched":1639,"index_factor":0.0},"statistics":{"all_exact_result":true,"cardinality":0,"from":1699579214000,"granularity":4320000,"groups":[{"linux":{"count":1163.0}},{"windowsx64":{"count":476.0}}],"groups_timeseries":[{"linux":{"groups_timeseries":[],"series":[{"count":45.0},{"count":21.0},{"count":16.0},{"count":270.0},{"count":27.0},{"count":43.0},{"count":27.0},{"count":39.0},{"count":29.0},{"count":646.0}],"totals":{"count":1163.0}}},{"windowsx64":{"groups_timeseries":[],"series":[{"count":54.0},{"count":40.0},{"count":60.0},{"count":37.0},{"count":42.0},{"count":62.0},{"count":41.0},{"count":47.0},{"count":49.0},{"count":44.0}],"totals":{"count":476.0}}}],"others":{"series":[]},"stats":{},"status":200,"timeseries":{},"to":1699622414000,"type":"count"}}|
149
+ |results_statistical|results_statistics|False|Query Results|{"leql":{"during":{"from":1699579214000,"to":1699622414000},"statement":"groupby(r7_context.asset.name)"},"logs":["123456-abcd-1234-abcd-123456abc"],"search_stats":{"bytes_all":9961260,"bytes_checked":9961260,"duration_ms":19,"events_all":1640,"events_checked":1640,"events_matched":1639,"index_factor":0.0},"statistics":{"all_exact_result":true,"cardinality":0,"from":1699579214000,"granularity":4320000,"groups":[{"linux":{"count":1163.0}},{"windowsx64":{"count":476.0}}],"groups_timeseries":[{"linux":{"groups_timeseries":[],"series":[{"count":45.0},{"count":21.0},{"count":16.0},{"count":270.0},{"count":27.0},{"count":43.0},{"count":27.0},{"count":39.0},{"count":29.0},{"count":646.0}],"totals":{"count":1163.0}}},{"windowsx64":{"groups_timeseries":[],"series":[{"count":54.0},{"count":40.0},{"count":60.0},{"count":37.0},{"count":42.0},{"count":62.0},{"count":41.0},{"count":47.0},{"count":49.0},{"count":44.0}],"totals":{"count":476.0}}}],"others":{"series":[]},"stats":{},"status":200,"timeseries":{},"to":1699622414000,"type":"count"}}|
150
150
151
151
Example output:
152
152
@@ -377,7 +377,7 @@ Example input:
377
377
| :--- | :--- | :--- | :--- | :--- |
378
378
| count| integer| True| Number of log entries found| 10|
379
379
|results_events|[]events|False|Query Results|[{"labels": [],"timestamp": 1601598638768,"sequence_number": 123456789123456789,"log_id": "64z0f0p9-1a99-4501-xe36-a6d03687f313","message": {"timestamp": "2020-10-02T00:29:14.649Z","destination_asset": "iagent-win7","source_asset_address": "192.168.100.50","destination_asset_address": "example-host","destination_local_account": "user","logon_type": "NETWORK","result": "SUCCESS","new_authentication": "false","service": "ntlmssp ","source_json": {"sourceName": "Microsoft-Windows-Security-Auditing","insertionStrings": ["S-1-0-0","-","-","0x0","X-X-X-XXXXXXXXXXX","user@example.com","example-host","0x204f163c","3","NtLmSsp ","NTLM","","{00000000-0000-0000-0000-000000000000}","-","NTLM V2","128","0x0","-","192.168.50.1","59090"],"eventCode": 4624,"computerName": "example-host","sid": "","isDomainController": false,"eventData": null,"timeWritten": "2020-10-02T00:29:13.670722000Z"}},"links": [{"rel": "Context","href": "https://us.api.insight.rapid7.com/log_search/query/context/xxxx"}],"sequence_number_str": "123456789123456789"}]|
380
- |results_statistical|statistics|False|Query Results|{"leql":{"during":{"from":1699579214000,"to":1699622414000},"statement":"groupby(r7_context.asset.name)"},"logs":["123456-abcd-1234-abcd-123456abc"],"search_stats":{"bytes_all":9961260,"bytes_checked":9961260,"duration_ms":19,"events_all":1640,"events_checked":1640,"events_matched":1639,"index_factor":0.0},"statistics":{"all_exact_result":true,"cardinality":0,"from":1699579214000,"granularity":4320000,"groups":[{"linux":{"count":1163.0}},{"windowsx64":{"count":476.0}}],"groups_timeseries":[{"linux":{"groups_timeseries":[],"series":[{"count":45.0},{"count":21.0},{"count":16.0},{"count":270.0},{"count":27.0},{"count":43.0},{"count":27.0},{"count":39.0},{"count":29.0},{"count":646.0}],"totals":{"count":1163.0}}},{"windowsx64":{"groups_timeseries":[],"series":[{"count":54.0},{"count":40.0},{"count":60.0},{"count":37.0},{"count":42.0},{"count":62.0},{"count":41.0},{"count":47.0},{"count":49.0},{"count":44.0}],"totals":{"count":476.0}}}],"others":{"series":[]},"stats":{},"status":200,"timeseries":{},"to":1699622414000,"type":"count"}}|
380
+ |results_statistical|results_statistics|False|Query Results|{"leql":{"during":{"from":1699579214000,"to":1699622414000},"statement":"groupby(r7_context.asset.name)"},"logs":["123456-abcd-1234-abcd-123456abc"],"search_stats":{"bytes_all":9961260,"bytes_checked":9961260,"duration_ms":19,"events_all":1640,"events_checked":1640,"events_matched":1639,"index_factor":0.0},"statistics":{"all_exact_result":true,"cardinality":0,"from":1699579214000,"granularity":4320000,"groups":[{"linux":{"count":1163.0}},{"windowsx64":{"count":476.0}}],"groups_timeseries":[{"linux":{"groups_timeseries":[],"series":[{"count":45.0},{"count":21.0},{"count":16.0},{"count":270.0},{"count":27.0},{"count":43.0},{"count":27.0},{"count":39.0},{"count":29.0},{"count":646.0}],"totals":{"count":1163.0}}},{"windowsx64":{"groups_timeseries":[],"series":[{"count":54.0},{"count":40.0},{"count":60.0},{"count":37.0},{"count":42.0},{"count":62.0},{"count":41.0},{"count":47.0},{"count":49.0},{"count":44.0}],"totals":{"count":476.0}}}],"others":{"series":[]},"stats":{},"status":200,"timeseries":{},"to":1699622414000,"type":"count"}}|
381
381
382
382
Example output:
383
383
@@ -3068,13 +3068,16 @@ Example output:
3068
3068
3069
3069
| Name| Type| Default| Required| Description| Example|
3070
3070
| :--- | :--- | :--- | :--- | :--- | :--- |
3071
- | Computer Name| string| None| None| None| None|
3072
- | Event Code| integer| None| None| None| None|
3073
- | Event Data| eventData| None| None| None| None|
3074
- | Is Domain Controller| boolean| None| None| None| None|
3075
- | SID| string| None| None| None| None|
3076
- | Source Name| string| None| None| None| None|
3077
- | Time Written| string| None| None| None| None|
3071
+ | Destination Asset| string| None| None| None| None|
3072
+ | Destination Asset Address| string| None| None| None| None|
3073
+ | Destination Local Account| string| None| None| None| None|
3074
+ | Logon Type| string| None| None| None| None|
3075
+ | New Authentication| string| None| None| None| None|
3076
+ | Result| string| None| None| None| None|
3077
+ | Service| string| None| None| None| None|
3078
+ | Source Asset Address| string| None| None| None| None|
3079
+ | Source JSON| source_json| None| None| None| None|
3080
+ | Timestamp| string| None| None| None| None|
3078
3081
3079
3082
** events**
3080
3083
@@ -3085,8 +3088,18 @@ Example output:
3085
3088
| Log ID| string| None| None| Log ID| None|
3086
3089
| Message| message| None| None| Message| None|
3087
3090
| Sequence Number| integer| None| None| Sequence number| None|
3091
+ | Sequence Number String| string| None| None| Sequence number string| None|
3088
3092
| Timestamp| integer| None| None| Timestamp| None|
3089
3093
3094
+ ** results_statistics**
3095
+
3096
+ | Name| Type| Default| Required| Description| Example|
3097
+ | :--- | :--- | :--- | :--- | :--- | :--- |
3098
+ | LEQL| object| None| False| The LEQL 'WHERE' clause to match against| None|
3099
+ | Logs| array| None| False| Holds the Log ID of the matching log entry| None|
3100
+ | Search Stats| object| None| False| Holds data regarding the query execution| None|
3101
+ | statistics| statistics| None| False| Holds the overall statistical results| None|
3102
+
3090
3103
** statistics**
3091
3104
3092
3105
| Name| Type| Default| Required| Description| Example|
@@ -3105,6 +3118,19 @@ Example output:
3105
3118
| To| integer| None| False| The end of the time range for the query, as a UNIX timestamp in milliseconds| None|
3106
3119
| Type| string| None| False| The type of function performed, for example, "count", "max", "average", "standarddeviation"| None|
3107
3120
3121
+ ** source_json**
3122
+
3123
+ | Name| Type| Default| Required| Description| Example|
3124
+ | :--- | :--- | :--- | :--- | :--- | :--- |
3125
+ | Computer Name| string| None| False| None| None|
3126
+ | Event Code| integer| None| False| None| None|
3127
+ | Event Data| eventData| None| False| None| None|
3128
+ | Insertion Strings| [ ] string| None| False| Insertion Strings| None|
3129
+ | Is Domain Controller| boolean| None| False| None| None|
3130
+ | SID| string| None| False| None| None|
3131
+ | Source Name| string| None| False| Source Name| None|
3132
+ | Time Written| string| None| False| None| None|
3133
+
3108
3134
** links**
3109
3135
3110
3136
| Name| Type| Default| Required| Description| Example|
@@ -3401,6 +3427,7 @@ Example output:
3401
3427
3402
3428
# Version History
3403
3429
3430
+ * 11.0.0 - Updating schema for query actions (` advanced_query_on_log ` , ` advanced_query_on_log_set ` & ` query ` ) to account for missing keys/invalid mapping in the schema
3404
3431
* 10.3.4 - Bumping requirements.txt | SDK bump to 6.2.2
3405
3432
* 10.3.3 - Bumping requirements.txt | SDK bump to 6.2.0
3406
3433
* 10.3.2 - Initial updates for fedramp compliance | Updated SDK to the latest version
0 commit comments