1613 lines
44 KiB
JSON
1613 lines
44 KiB
JSON
{
|
|
"type":"record",
|
|
"name":"gtpc_record",
|
|
"namespace":"tsg_galaxy_v3",
|
|
"doc":
|
|
{
|
|
"primary_key":"common_log_id",
|
|
"partition_key":"common_recv_time",
|
|
"ttl":null,
|
|
"default_ttl":2592000,
|
|
"index_key":
|
|
[
|
|
"common_log_id",
|
|
"common_recv_time",
|
|
"common_data_center"
|
|
],
|
|
"functions":
|
|
{
|
|
"$ref":"public_schema_info.json#/functions"
|
|
},
|
|
"schema_query":
|
|
{
|
|
"dimensions":
|
|
[
|
|
"common_server_ip",
|
|
"common_client_ip",
|
|
"common_internal_ip",
|
|
"common_external_ip",
|
|
"common_sled_ip",
|
|
"common_device_id",
|
|
"common_client_location",
|
|
"common_server_location",
|
|
"common_client_port",
|
|
"common_server_port",
|
|
"common_schema_type",
|
|
"common_l4_protocol",
|
|
"common_l7_protocol",
|
|
"common_data_center",
|
|
"common_device_group",
|
|
"common_app_behavior",
|
|
"common_client_asn",
|
|
"common_server_asn",
|
|
"common_start_time",
|
|
"common_end_time",
|
|
"gtp_version",
|
|
"gtp_apn",
|
|
"gtp_imei",
|
|
"gtp_imsi",
|
|
"gtp_phone_number",
|
|
"gtp_msg_type"
|
|
],
|
|
"metrics":
|
|
[
|
|
"common_server_ip",
|
|
"common_client_ip",
|
|
"common_internal_ip",
|
|
"common_external_ip",
|
|
"common_sled_ip",
|
|
"common_device_id",
|
|
"common_c2s_pkt_num",
|
|
"common_s2c_pkt_num",
|
|
"common_c2s_byte_num",
|
|
"common_s2c_byte_num",
|
|
"common_sessions",
|
|
"common_con_duration_ms",
|
|
"common_establish_latency_ms",
|
|
"common_c2s_ipfrag_num",
|
|
"common_s2c_ipfrag_num",
|
|
"common_c2s_tcp_lostlen",
|
|
"common_s2c_tcp_lostlen",
|
|
"common_c2s_tcp_unorder_num",
|
|
"common_s2c_tcp_unorder_num",
|
|
"gtp_version",
|
|
"gtp_apn",
|
|
"gtp_imei",
|
|
"gtp_imsi",
|
|
"gtp_phone_number"
|
|
],
|
|
"filters":
|
|
[
|
|
"common_address_type",
|
|
"common_server_ip",
|
|
"common_client_ip",
|
|
"common_internal_ip",
|
|
"common_external_ip",
|
|
"common_client_port",
|
|
"common_server_port",
|
|
"common_client_location",
|
|
"common_server_location",
|
|
"common_c2s_pkt_num",
|
|
"common_s2c_pkt_num",
|
|
"common_c2s_byte_num",
|
|
"common_s2c_byte_num",
|
|
"common_c2s_ipfrag_num",
|
|
"common_s2c_ipfrag_num",
|
|
"common_c2s_tcp_lostlen",
|
|
"common_s2c_tcp_lostlen",
|
|
"common_c2s_tcp_unorder_num",
|
|
"common_s2c_tcp_unorder_num",
|
|
"common_l4_protocol",
|
|
"common_l7_protocol",
|
|
"common_stream_dir",
|
|
"common_direction",
|
|
"common_data_center",
|
|
"common_device_group",
|
|
"common_app_behavior",
|
|
"common_sled_ip",
|
|
"common_device_id",
|
|
"common_schema_type",
|
|
"common_client_asn",
|
|
"common_server_asn",
|
|
"common_start_time",
|
|
"common_end_time",
|
|
"common_con_duration_ms",
|
|
"common_establish_latency_ms",
|
|
"gtp_version",
|
|
"gtp_apn",
|
|
"gtp_imei",
|
|
"gtp_imsi",
|
|
"gtp_phone_number",
|
|
"gtp_end_user_ipv4",
|
|
"gtp_end_user_ipv6",
|
|
"gtp_uplink_teid",
|
|
"gtp_downlink_teid",
|
|
"gtp_msg_type"
|
|
],
|
|
"references":
|
|
{
|
|
"$ref":"public_schema_info.json#/schema_query/references"
|
|
},
|
|
"details":
|
|
{
|
|
"general":
|
|
[
|
|
"common_recv_time",
|
|
"common_log_id",
|
|
"common_stream_trace_id",
|
|
"common_address_type",
|
|
"common_schema_type",
|
|
"common_direction",
|
|
"common_stream_dir",
|
|
"common_start_time",
|
|
"common_end_time",
|
|
"common_con_duration_ms",
|
|
"common_establish_latency_ms",
|
|
"common_processing_time",
|
|
"common_ingestion_time",
|
|
"common_entrance_id",
|
|
"common_device_id",
|
|
"common_egress_link_id",
|
|
"common_ingress_link_id",
|
|
"common_isp",
|
|
"common_data_center",
|
|
"common_device_group",
|
|
"common_sled_ip"
|
|
],
|
|
"source":
|
|
[
|
|
"common_client_ip",
|
|
"common_internal_ip",
|
|
"common_client_port",
|
|
"common_client_location",
|
|
"common_client_asn",
|
|
"common_subscriber_id",
|
|
"common_imei",
|
|
"common_imsi",
|
|
"common_phone_number"
|
|
],
|
|
"destination":
|
|
[
|
|
"common_server_ip",
|
|
"common_external_ip",
|
|
"common_server_port",
|
|
"common_server_location",
|
|
"common_server_asn"
|
|
],
|
|
"application":
|
|
[
|
|
"common_app_id",
|
|
"common_userdefine_app_name",
|
|
"common_app_identify_info",
|
|
"common_app_label",
|
|
"common_app_surrogate_id",
|
|
"common_l7_protocol",
|
|
"common_protocol_label",
|
|
"common_service_category",
|
|
"common_service",
|
|
"common_l4_protocol",
|
|
"common_app_behavior"
|
|
],
|
|
"transmission":
|
|
[
|
|
"common_sessions",
|
|
"common_c2s_pkt_num",
|
|
"common_s2c_pkt_num",
|
|
"common_c2s_byte_num",
|
|
"common_s2c_byte_num",
|
|
"common_c2s_pkt_diff",
|
|
"common_s2c_pkt_diff",
|
|
"common_c2s_byte_diff",
|
|
"common_s2c_byte_diff",
|
|
"common_c2s_ipfrag_num",
|
|
"common_s2c_ipfrag_num",
|
|
"common_c2s_tcp_lostlen",
|
|
"common_s2c_tcp_lostlen",
|
|
"common_c2s_tcp_unorder_num",
|
|
"common_s2c_tcp_unorder_num",
|
|
"common_c2s_pkt_retrans",
|
|
"common_s2c_pkt_retrans",
|
|
"common_c2s_byte_retrans",
|
|
"common_s2c_byte_retrans",
|
|
"common_first_ttl",
|
|
"common_tcp_client_isn",
|
|
"common_tcp_server_isn",
|
|
"common_mirrored_pkts",
|
|
"common_mirrored_bytes"
|
|
],
|
|
"other":
|
|
[
|
|
"common_device_tag",
|
|
"common_encapsulation",
|
|
"common_tunnels",
|
|
"common_address_list",
|
|
"common_has_dup_traffic",
|
|
"common_stream_error",
|
|
"common_link_info_c2s",
|
|
"common_link_info_s2c",
|
|
"common_packet_capture_file",
|
|
"common_action",
|
|
"common_sub_action",
|
|
"common_policy_id",
|
|
"common_user_tags",
|
|
"common_user_region"
|
|
]
|
|
|
|
}
|
|
|
|
},
|
|
"schema_type":
|
|
{
|
|
"GTP-C":
|
|
{
|
|
"columns":
|
|
[
|
|
"common_recv_time",
|
|
"common_log_id",
|
|
"common_policy_id",
|
|
"common_subscriber_id",
|
|
"common_imei",
|
|
"common_imsi",
|
|
"common_phone_number",
|
|
"common_client_ip",
|
|
"common_client_port",
|
|
"common_internal_ip",
|
|
"common_l4_protocol",
|
|
"common_address_type",
|
|
"common_server_ip",
|
|
"common_server_port",
|
|
"common_external_ip",
|
|
"common_action",
|
|
"common_direction",
|
|
"common_entrance_id",
|
|
"common_sled_ip",
|
|
"common_client_location",
|
|
"common_client_asn",
|
|
"common_server_location",
|
|
"common_server_asn",
|
|
"common_sessions",
|
|
"common_c2s_pkt_num",
|
|
"common_s2c_pkt_num",
|
|
"common_c2s_byte_num",
|
|
"common_s2c_byte_num",
|
|
"common_c2s_pkt_diff",
|
|
"common_s2c_pkt_diff",
|
|
"common_c2s_byte_diff",
|
|
"common_s2c_byte_diff",
|
|
"common_service",
|
|
"common_schema_type",
|
|
"common_user_tags",
|
|
"common_sub_action",
|
|
"common_user_region",
|
|
"common_device_id",
|
|
"common_egress_link_id",
|
|
"common_ingress_link_id",
|
|
"common_isp",
|
|
"common_device_tag",
|
|
"common_data_center",
|
|
"common_device_group",
|
|
"common_encapsulation",
|
|
"common_app_label",
|
|
"common_tunnels",
|
|
"common_protocol_label",
|
|
"common_app_id",
|
|
"common_app_surrogate_id",
|
|
"common_app_surrogate_id",
|
|
"common_service_category",
|
|
"common_l7_protocol",
|
|
"common_start_time",
|
|
"common_end_time",
|
|
"common_establish_latency_ms",
|
|
"common_con_duration_ms",
|
|
"common_stream_dir",
|
|
"common_address_list",
|
|
"common_has_dup_traffic",
|
|
"common_stream_error",
|
|
"common_stream_trace_id",
|
|
"common_link_info_c2s",
|
|
"common_link_info_s2c",
|
|
"common_c2s_ipfrag_num",
|
|
"common_s2c_ipfrag_num",
|
|
"common_c2s_tcp_lostlen",
|
|
"common_s2c_tcp_lostlen",
|
|
"common_c2s_tcp_unorder_num",
|
|
"common_s2c_tcp_unorder_num",
|
|
"common_c2s_pkt_retrans",
|
|
"common_s2c_pkt_retrans",
|
|
"common_c2s_byte_retrans",
|
|
"common_s2c_byte_retrans",
|
|
"common_tcp_client_isn",
|
|
"common_tcp_server_isn",
|
|
"common_first_ttl",
|
|
"common_processing_time",
|
|
"common_ingestion_time",
|
|
"common_mirrored_pkts",
|
|
"common_mirrored_bytes",
|
|
"gtp_version",
|
|
"gtp_apn",
|
|
"gtp_imei",
|
|
"gtp_imsi",
|
|
"gtp_phone_number",
|
|
"gtp_end_user_ipv4",
|
|
"gtp_end_user_ipv6",
|
|
"gtp_uplink_teid",
|
|
"gtp_downlink_teid",
|
|
"gtp_msg_type"
|
|
],
|
|
"default_columns":
|
|
[
|
|
"common_recv_time",
|
|
"common_log_id",
|
|
"gtp_version",
|
|
"gtp_msg_type",
|
|
"gtp_imsi",
|
|
"gtp_imei",
|
|
"gtp_phone_number",
|
|
"common_client_ip",
|
|
"common_server_ip"
|
|
]
|
|
|
|
}
|
|
|
|
},
|
|
"default_columns":
|
|
[
|
|
"common_recv_time",
|
|
"common_log_id",
|
|
"gtp_version",
|
|
"gtp_msg_type",
|
|
"gtp_imsi",
|
|
"gtp_imei",
|
|
"gtp_phone_number",
|
|
"common_client_ip",
|
|
"common_server_ip"
|
|
],
|
|
"internal_columns":
|
|
[
|
|
"common_recv_time",
|
|
"common_log_id",
|
|
"common_processing_time",
|
|
"common_ingestion_time",
|
|
"common_packet_capture_file"
|
|
],
|
|
"tunnel_type":
|
|
{
|
|
"$ref":"public_schema_info.json#/tunnel_type"
|
|
}
|
|
|
|
},
|
|
"fields":
|
|
[
|
|
{
|
|
"name":"common_recv_time",
|
|
"label":"Receive Time",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"timestamp"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_log_id",
|
|
"label":"Log ID",
|
|
"doc":
|
|
{
|
|
"format":
|
|
{
|
|
"functions":"snowflake_id"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_policy_id",
|
|
"label":"Policy ID",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_subscriber_id",
|
|
"label":"Subscriber ID",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_imei",
|
|
"label":"IMEI",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_imsi",
|
|
"label":"IMSI",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_phone_number",
|
|
"label":"Phone Number",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_client_ip",
|
|
"label":"Client IP",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"ip"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"geo_asn",
|
|
"appendTo":"common_client_asn"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_internal_ip",
|
|
"label":"Internal IP",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"ip"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"if",
|
|
"param":"$.common_direction=69,$.common_client_ip,$.common_server_ip"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_client_port",
|
|
"label":"Client Port",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_l4_protocol",
|
|
"label":"L4 Protocol",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_address_type",
|
|
"label":"Address Type",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
[
|
|
{
|
|
"code":"4",
|
|
"value":"ipv4"
|
|
},
|
|
{
|
|
"code":"6",
|
|
"value":"ipv6"
|
|
}
|
|
|
|
],
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_server_ip",
|
|
"label":"Server IP",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"ip"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"geo_asn",
|
|
"appendTo":"common_server_asn"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_server_port",
|
|
"label":"Server Port",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_external_ip",
|
|
"label":"External IP",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"ip"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"if",
|
|
"param":"$.common_direction=73,$.common_client_ip,$.common_server_ip"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_action",
|
|
"label":"Action",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
[
|
|
{
|
|
"code":"0",
|
|
"value":"None"
|
|
},
|
|
{
|
|
"code":"1",
|
|
"value":"Monitor"
|
|
},
|
|
{
|
|
"code":"2",
|
|
"value":"Intercept"
|
|
},
|
|
{
|
|
"code":"16",
|
|
"value":"Deny"
|
|
},
|
|
{
|
|
"code":"128",
|
|
"value":"Allow"
|
|
}
|
|
|
|
],
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_direction",
|
|
"label":"Direction",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
[
|
|
{
|
|
"code":"69",
|
|
"value":"outbound"
|
|
},
|
|
{
|
|
"code":"73",
|
|
"value":"inbound"
|
|
}
|
|
|
|
],
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_entrance_id",
|
|
"label":"Entrance ID",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_sled_ip",
|
|
"label":"Sled IP",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"ip"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_client_location",
|
|
"label":"Client Location",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_client_asn",
|
|
"label":"Client ASN",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_server_location",
|
|
"label":"Server Location",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_server_asn",
|
|
"label":"Server ASN",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_sessions",
|
|
"label":"Sessions",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_pkt_num",
|
|
"label":"Packets Sent",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_pkt_num",
|
|
"label":"Packets Received",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_byte_num",
|
|
"label":"Bytes Sent",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_byte_num",
|
|
"label":"Bytes Received",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_pkt_diff",
|
|
"label":"Packets Sent (Delta)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_pkt_diff",
|
|
"label":"Packets Received (Delta)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_byte_diff",
|
|
"label":"Bytes Sent (Delta)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_byte_diff",
|
|
"label":"Bytes Received (Delta)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_service",
|
|
"label":"Service",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_schema_type",
|
|
"label":"Schema Type",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
[
|
|
{
|
|
"code":"GTP-C",
|
|
"value":"GTP-C"
|
|
}
|
|
|
|
],
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_user_tags",
|
|
"label":"User Tags",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_sub_action",
|
|
"label":"Sub Action",
|
|
"doc":
|
|
{
|
|
"data":
|
|
[
|
|
{
|
|
"code":"allow",
|
|
"value":"Allow"
|
|
},
|
|
{
|
|
"code":"deny",
|
|
"value":"Deny"
|
|
},
|
|
{
|
|
"code":"monitor",
|
|
"value":"Monitor"
|
|
},
|
|
{
|
|
"code":"replace",
|
|
"value":"Replace"
|
|
},
|
|
{
|
|
"code":"redirect",
|
|
"value":"Redirect"
|
|
},
|
|
{
|
|
"code":"insert",
|
|
"value":"Insert"
|
|
},
|
|
{
|
|
"code":"hijack",
|
|
"value":"Hijack"
|
|
}
|
|
|
|
],
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_user_region",
|
|
"label":"User Region",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_device_id",
|
|
"label":"Device ID",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_egress_link_id",
|
|
"label":"Egress Link ID",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_ingress_link_id",
|
|
"label":"Ingress Link ID",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_isp",
|
|
"label":"ISP",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_device_tag",
|
|
"label":"Device Tag",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"format":
|
|
{
|
|
"functions":"flattenSpec,flattenSpec",
|
|
"appendTo":"common_data_center,common_device_group",
|
|
"param":"$.tags[?(@.tag=='data_center')].value,$.tags[?(@.tag=='device_group')].value"
|
|
},
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_data_center",
|
|
"label":"Data Center",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
{
|
|
"$ref":"device_tag.json#",
|
|
"key":"$[?(@.tagType=='data_center')].subTags.[?(@.tagType=='data_center')]['tagValue']",
|
|
"value":"$[?(@.tagType=='data_center')].subTags.[?(@.tagType=='data_center')]['tagName']"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_device_group",
|
|
"label":"Device Group",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
{
|
|
"$ref":"device_tag.json#",
|
|
"key":"$[?(@.tagType=='device_group')].subTags.[?(@.tagType=='device_group')]['tagValue']",
|
|
"value":"$[?(@.tagType=='device_group')].subTags.[?(@.tagType=='device_group')]['tagName']"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_app_behavior",
|
|
"label":"Application Behavior",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_encapsulation",
|
|
"label":"Encapsulation",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
{
|
|
"$ref":"public_schema_info.json#/fields/common_encapsulation/data"
|
|
},
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_app_label",
|
|
"label":"Application Label",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_tunnels",
|
|
"label":"Tunnels",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_protocol_label",
|
|
"label":"Protocol Label",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_app_id",
|
|
"label":"Application ID",
|
|
"type":"string",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
}
|
|
|
|
},
|
|
{
|
|
"name":"common_userdefine_app_name",
|
|
"label":"User Define App Name",
|
|
"type":"string",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
}
|
|
|
|
},
|
|
{
|
|
"name":"common_app_identify_info",
|
|
"label":"App Identity Info",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_app_surrogate_id",
|
|
"label":"Surrogate ID",
|
|
"type":"string",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
}
|
|
|
|
},
|
|
{
|
|
"name":"common_l7_protocol",
|
|
"label":"L7 Protocol",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_service_category",
|
|
"label":"FQDN Category",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"has"
|
|
},
|
|
"visibility":"disabled",
|
|
"dict_location":
|
|
{
|
|
"path":"/v1/category/dict",
|
|
"key":"categoryId",
|
|
"value":"categoryName"
|
|
},
|
|
"ttl":null
|
|
},
|
|
"type":
|
|
{
|
|
"type":"array",
|
|
"items":"int"
|
|
}
|
|
|
|
},
|
|
{
|
|
"name":"common_start_time",
|
|
"label":"Start Time",
|
|
"doc":
|
|
{
|
|
"allow_query":"false",
|
|
"constraints":
|
|
{
|
|
"type":"timestamp"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_end_time",
|
|
"label":"End Time",
|
|
"doc":
|
|
{
|
|
"allow_query":"false",
|
|
"constraints":
|
|
{
|
|
"type":"timestamp"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"get_value",
|
|
"appendTo":"common_recv_time"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_establish_latency_ms",
|
|
"label":"TCP Handshake Latency (ms)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_con_duration_ms",
|
|
"label":"Duration (ms)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_stream_dir",
|
|
"label":"Stream Direction",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
[
|
|
{
|
|
"code":"1",
|
|
"value":"c2s"
|
|
},
|
|
{
|
|
"code":"2",
|
|
"value":"s2c"
|
|
},
|
|
{
|
|
"code":"3",
|
|
"value":"double"
|
|
}
|
|
|
|
],
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_address_list",
|
|
"label":"Address List",
|
|
"doc":
|
|
{
|
|
"visibility":"disabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_has_dup_traffic",
|
|
"label":"Duplication Traffic",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
{
|
|
"$ref":"public_schema_info.json#/fields/common_has_dup_traffic/data"
|
|
},
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_stream_error",
|
|
"label":"Stream Error",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_stream_trace_id",
|
|
"label":"Session ID",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_link_info_c2s",
|
|
"label":"Link Info (c2s)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_link_info_s2c",
|
|
"label":"Link Info (s2c)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_packet_capture_file",
|
|
"label":"Packet Capture File",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"constraints":
|
|
{
|
|
"type":"file"
|
|
},
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"common_c2s_ipfrag_num",
|
|
"label":"Fragmentation Packets (c2s)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_ipfrag_num",
|
|
"label":"Fragmentation Packets (s2c)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_tcp_lostlen",
|
|
"label":"Sequence Gap Loss (c2s)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_tcp_lostlen",
|
|
"label":"Sequence Gap Loss (s2c)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_tcp_unorder_num",
|
|
"label":"Unordered Packets (c2s)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_tcp_unorder_num",
|
|
"label":"Unordered Packets (s2c)",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_pkt_retrans",
|
|
"label":"Packet Retransmission (c2s)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_pkt_retrans",
|
|
"label":"Packet Retransmission (s2c)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_c2s_byte_retrans",
|
|
"label":"Byte Retransmission (c2s)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_s2c_byte_retrans",
|
|
"label":"Byte Retransmission (s2c)",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_tcp_client_isn",
|
|
"label":"TCP Client ISN",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_tcp_server_isn",
|
|
"label":"TCP Server ISN",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_first_ttl",
|
|
"label":"First TTL",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
},
|
|
"type":"int"
|
|
},
|
|
{
|
|
"name":"common_processing_time",
|
|
"label":"Processing Time",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"timestamp"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"current_timestamp"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_ingestion_time",
|
|
"label":"Ingestion Time",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"type":"timestamp"
|
|
},
|
|
"format":
|
|
{
|
|
"functions":"ingestion_time"
|
|
},
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"common_mirrored_pkts",
|
|
"label":"Mirrored Packets",
|
|
"type":"long",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
}
|
|
|
|
},
|
|
{
|
|
"name":"common_mirrored_bytes",
|
|
"label":"Mirrored Bytes",
|
|
"type":"long",
|
|
"doc":
|
|
{
|
|
"visibility":"hidden",
|
|
"ttl":null
|
|
}
|
|
|
|
},
|
|
{
|
|
"name":"gtp_version",
|
|
"label":"Version",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_apn",
|
|
"label":"APN",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_imei",
|
|
"label":"IMEI",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_imsi",
|
|
"label":"IMSI",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_phone_number",
|
|
"label":"Phone Number",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_uplink_teid",
|
|
"label":"Uplink TEID",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"gtp_downlink_teid",
|
|
"label":"Downlink TEID",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"long"
|
|
},
|
|
{
|
|
"name":"gtp_msg_type",
|
|
"label":"Message Type",
|
|
"doc":
|
|
{
|
|
"constraints":
|
|
{
|
|
"operator_functions":"=,!="
|
|
},
|
|
"data":
|
|
[
|
|
{
|
|
"code":"create",
|
|
"value":"create"
|
|
},
|
|
{
|
|
"code":"modify",
|
|
"value":"modify"
|
|
},
|
|
{
|
|
"code":"delete",
|
|
"value":"delete"
|
|
}
|
|
|
|
],
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_end_user_ipv4",
|
|
"label":"End User Address V4",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
},
|
|
{
|
|
"name":"gtp_end_user_ipv6",
|
|
"label":"End User Address V6",
|
|
"doc":
|
|
{
|
|
"visibility":"enabled",
|
|
"ttl":null
|
|
},
|
|
"type":"string"
|
|
}
|
|
|
|
]
|
|
|
|
} |