diff --git a/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl.sql b/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl.sql index 0840c6c..13890d3 100644 --- a/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl.sql +++ b/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl.sql @@ -220,6 +220,8 @@ ssl_cn String, ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, +ssl_ja4_fingerprint String, +ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -470,6 +472,8 @@ ssl_cn String, ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, +ssl_ja4_fingerprint String, +ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -718,6 +722,8 @@ ssl_cn String, ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, +ssl_ja4_fingerprint String, +ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -967,6 +973,8 @@ ssl_cn String, ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, +ssl_ja4_fingerprint String, +ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -1215,6 +1223,8 @@ ssl_cn String, ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, +ssl_ja4_fingerprint String, +ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -1464,6 +1474,8 @@ ssl_cn String, ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, +ssl_ja4_fingerprint String, +ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -2387,6 +2399,8 @@ TO tsg_galaxy_v3.security_event_local ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, + ssl_ja4_fingerprint String, + ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -2633,6 +2647,8 @@ SELECT ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, + ssl_ja4_fingerprint, + ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, @@ -2884,6 +2900,8 @@ TO tsg_galaxy_v3.monitor_event_local ssl_handshake_latency_ms Nullable(Int32), ssl_ja3_hash String, ssl_ja3s_hash String, + ssl_ja4_fingerprint String, + ssl_ja4s_fingerprint String, ssl_cert_issuer String, ssl_cert_subject String, ssl_esni_flag Nullable(Int32), @@ -3130,6 +3148,8 @@ SELECT ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, + ssl_ja4_fingerprint, + ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, diff --git a/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl_check.sql b/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl_check.sql index 2bf242c..534cb8b 100644 --- a/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl_check.sql +++ b/tsg_olap/installation/clickhouse/最新全量建表语句/tsg_olap_clickhouse_ddl_check.sql @@ -2,13 +2,13 @@ SELECT log_id, recv_time, vsys_id, assessment_date, lot_number, file_name, asses FROM tsg_galaxy_v3.assessment_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time