Files
geedge-jira/attachment/45812/query.desc.session_record_local.txt
2025-09-14 22:00:20 +00:00

261 lines
21 KiB
Plaintext

common_recv_time Int64
common_log_id UInt64
common_stream_trace_id UInt64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_direction Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_stream_dir Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_start_time Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_end_time Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_con_duration_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_establish_latency_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_processing_time Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_insert_time Int64 MATERIALIZED toUnixTimestamp(now())
common_ingestion_time Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_entrance_id Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_device_id String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_egress_link_id Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_ingress_link_id Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_isp String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_data_center String
common_sled_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_device_group String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_app_behavior String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_action Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_sub_action String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_policy_id Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_user_tags String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_user_region String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_shaping_rule_ids Array(Int64)
common_client_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_internal_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_client_port Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_client_location LowCardinality(String) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_client_asn String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_subscriber_id String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_imei String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_imsi String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_phone_number String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_out_src_mac String
common_in_src_mac String
common_server_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_external_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_server_port Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_server_location LowCardinality(String) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_server_asn String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_server_fqdn String
common_server_domain String
common_in_dest_mac String
common_out_dest_mac String
common_app_id String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_app_full_path String
common_userdefine_app_name String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_app_identify_info String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_app_label LowCardinality(String) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_app_surrogate_id String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_l7_protocol LowCardinality(String) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_protocol_label String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_service_category Array(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_service Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_l4_protocol LowCardinality(String) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_sessions Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_pkt_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_pkt_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_pkt_diff Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_pkt_diff Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_byte_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_byte_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_byte_diff Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_byte_diff Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_ipfrag_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_ipfrag_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_tcp_lostlen Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_tcp_lostlen Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_tcp_unorder_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_tcp_unorder_num Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_pkt_retrans Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_pkt_retrans Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_c2s_byte_retrans Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_s2c_byte_retrans Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_first_ttl Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_tcp_client_isn Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_tcp_server_isn Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_mirrored_pkts Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_mirrored_bytes Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_address_type Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_schema_type LowCardinality(String) toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_vsys_id Int64 DEFAULT 1
common_t_vsys_id Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_flags UInt64
common_flags_identify_info String
common_device_tag String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_encapsulation Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_tunnels String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_address_list String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_has_dup_traffic Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_stream_error String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_link_info_c2s String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_link_info_s2c String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_packet_capture_file String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_tunnel_endpoint_a_desc String toDateTime(common_recv_time) + toIntervalSecond(2592000)
common_tunnel_endpoint_b_desc String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_url String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_host String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_domain String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_line String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_line String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_header String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_header String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_body String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_body String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_body_key String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_body_key String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_proxy_flag Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_sequence Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_snapshot String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_cookie String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_referer String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_user_agent String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_content_length String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_request_content_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_content_length String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_content_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_content_length String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_content_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_set_cookie String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_response_latency_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_session_duration_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
http_action_file_size Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_protocol_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_account String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_to_cmd String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_from_cmd String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_from String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_to String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_cc String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_bcc String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_subject String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_subject_charset String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_content_charset String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_attachment_name String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_attachment_name_charset String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_attachment_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_eml_file String toDateTime(common_recv_time) + toIntervalSecond(2592000)
mail_snapshot String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_message_id Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_qr Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_opcode Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_aa Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_tc Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_rd Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_ra Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_rcode Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_qdcount Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_ancount Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_nscount Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_arcount Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_qname String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_qtype Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_qclass Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_cname String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_sub Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_rr String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dns_response_latency_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_sni String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_san String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_cn String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_pinningst Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_intercept_state Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_passthrough_reason String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_server_side_latency Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_client_side_latency Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_server_side_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_client_side_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_cert_verify Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_error String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_con_latency_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_ja3_fingerprint String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_ja3_hash String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_ja3s_fingerprint String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_ja3s_hash String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_cert_issuer String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssl_cert_subject String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_cookie String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_sni String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_san String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_cn String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_con_latency_ms Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_ja3_fingerprint String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_ja3_hash String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_cert_issuer String toDateTime(common_recv_time) + toIntervalSecond(2592000)
dtls_cert_subject String toDateTime(common_recv_time) + toIntervalSecond(2592000)
quic_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
quic_sni String toDateTime(common_recv_time) + toIntervalSecond(2592000)
quic_user_agent String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ftp_account String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ftp_url String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ftp_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ftp_link_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
bgp_type Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
bgp_as_num String toDateTime(common_recv_time) + toIntervalSecond(2592000)
bgp_route String toDateTime(common_recv_time) + toIntervalSecond(2592000)
voip_calling_account String toDateTime(common_recv_time) + toIntervalSecond(2592000)
voip_called_account String toDateTime(common_recv_time) + toIntervalSecond(2592000)
voip_calling_number String toDateTime(common_recv_time) + toIntervalSecond(2592000)
voip_called_number String toDateTime(common_recv_time) + toIntervalSecond(2592000)
streaming_media_url String toDateTime(common_recv_time) + toIntervalSecond(2592000)
streaming_media_protocol String toDateTime(common_recv_time) + toIntervalSecond(2592000)
app_extra_info String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_cookie String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_security_protocol String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_client_channels String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_keyboard_layout String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_client_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_client_name String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_client_product_id String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_desktop_width String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_desktop_height String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_requested_color_depth String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_certificate_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_certificate_count Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_certificate_permanent Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_encryption_level String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rdp_encryption_method String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_call_id String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_originator_description String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_responder_description String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_user_agent String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_server String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_originator_sdp_connect_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_originator_sdp_media_port Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_originator_sdp_media_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_originator_sdp_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_responder_sdp_connect_ip String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_responder_sdp_media_port Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_responder_sdp_media_type String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_responder_sdp_content String toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_duration_s Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
sip_bye String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rtp_payload_type_c2s Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
rtp_payload_type_s2c Nullable(Int64) toDateTime(common_recv_time) + toIntervalSecond(2592000)
rtp_pcap_path String toDateTime(common_recv_time) + toIntervalSecond(2592000)
rtp_originator_dir Int64 toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_auth_success String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_client_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_server_version String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_cipher_alg String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_mac_alg String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_compression_alg String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_kex_alg String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_host_key_alg String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_host_key String toDateTime(common_recv_time) + toIntervalSecond(2592000)
ssh_hassh String toDateTime(common_recv_time) + toIntervalSecond(2592000)
stratum_cryptocurrency String toDateTime(common_recv_time) + toIntervalSecond(2592000)
stratum_mining_pools String toDateTime(common_recv_time) + toIntervalSecond(2592000)
stratum_mining_program String toDateTime(common_recv_time) + toIntervalSecond(2592000)