diff --git a/tsg_olap/upgrade/TSG-24.08/groot_stream/templates/traffic_sketch_metric.yaml.j2 b/tsg_olap/upgrade/TSG-24.08/groot_stream/templates/traffic_sketch_metric.yaml.j2 index 51d8ee3..a13aad9 100644 --- a/tsg_olap/upgrade/TSG-24.08/groot_stream/templates/traffic_sketch_metric.yaml.j2 +++ b/tsg_olap/upgrade/TSG-24.08/groot_stream/templates/traffic_sketch_metric.yaml.j2 @@ -26,72 +26,7 @@ processing_pipelines: output_fields: [ recv_time ] parameters: precision: seconds - interval: 300 - - aggregate_processor: - type: aggregate - group_by_fields: [vsys_id,device_id,device_group,data_center,ip_protocol,direction,client_ip,server_ip,server_domain,app,recv_time] - window_type: tumbling_processing_time # tumbling_event_time,sliding_processing_time,sliding_event_time - window_size: 300 - functions: - - function: NUMBER_SUM - lookup_fields: [ sessions ] - - function: NUMBER_SUM - lookup_fields: [ bytes ] - - function: NUMBER_SUM - lookup_fields: [ sent_bytes ] - - function: NUMBER_SUM - lookup_fields: [ received_bytes ] - - function: NUMBER_SUM - lookup_fields: [ pkts ] - - function: NUMBER_SUM - lookup_fields: [ sent_pkts ] - - function: NUMBER_SUM - lookup_fields: [ received_pkts ] - - function: NUMBER_SUM - lookup_fields: [ asymmetric_c2s_flows ] - - function: NUMBER_SUM - lookup_fields: [ asymmetric_s2c_flows ] - - function: NUMBER_SUM - lookup_fields: [ c2s_fragments ] - - function: NUMBER_SUM - lookup_fields: [ s2c_fragments ] - - function: NUMBER_SUM - lookup_fields: [ c2s_tcp_lost_bytes ] - - function: NUMBER_SUM - lookup_fields: [ s2c_tcp_lost_bytes ] - - function: NUMBER_SUM - lookup_fields: [ c2s_tcp_retransmitted_pkts ] - - function: NUMBER_SUM - lookup_fields: [ s2c_tcp_retransmitted_pkts ] - - function: FIRST_VALUE - lookup_fields: [ client_country ] - - function: FIRST_VALUE - lookup_fields: [ server_country ] - - function: FIRST_VALUE - lookup_fields: [ client_asn ] - - function: FIRST_VALUE - lookup_fields: [ server_asn ] - - function: FIRST_VALUE - lookup_fields: [ server_fqdn ] - - function: FIRST_VALUE - lookup_fields: [ app_category ] - - function: FIRST_VALUE - lookup_fields: [ c2s_ttl ] - - function: FIRST_VALUE - lookup_fields: [ s2c_ttl ] - - function: FIRST_VALUE - lookup_fields: [ c2s_link_id ] - - function: FIRST_VALUE - lookup_fields: [ s2c_link_id ] - - - - post_etl_processor: # [object] Processing Pipeline - type: projection - remove_fields: - output_fields: - functions: # [array of object] Function List + interval: 60 - function: EVAL output_fields: [ internal_ip ] parameters: @@ -100,7 +35,6 @@ processing_pipelines: output_fields: [ external_ip ] parameters: value_expression: 'direction=Outbound? server_ip : client_ip' - - function: SNOWFLAKE_ID lookup_fields: [ '' ] output_fields: [ log_id ]