From bdd3a10f5914738a64594619f7f853298aab3c3d Mon Sep 17 00:00:00 2001 From: lifengchao Date: Tue, 26 Mar 2024 12:04:08 +0800 Subject: [PATCH] =?UTF-8?q?TSG-20122=EF=BC=9ADoS=20Event=20=E6=96=B0?= =?UTF-8?q?=E5=A2=9E=E5=AD=97=E6=AE=B5=EF=BC=9Abytes,=20sessions,=20packet?= =?UTF-8?q?s=20,=20rule=5Fid?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../Clickhouse_TSG_建表语句.sql | 12 +++++++++++ .../Clickhouse_TSG_校验sql.sql | 2 +- .../TSG-24.04/clickhouse/check-24.04.sql | 20 +++++++++++++++++++ .../TSG-24.04/clickhouse/update-24.04-ck.sql | 20 +++++++++++++++++++ 4 files changed, 53 insertions(+), 1 deletion(-) create mode 100644 TSG发布版本更新记录/TSG-24.04/clickhouse/check-24.04.sql create mode 100644 TSG发布版本更新记录/TSG-24.04/clickhouse/update-24.04-ck.sql diff --git a/Clickhouse最新全量建表语句/Clickhouse_TSG_建表语句.sql b/Clickhouse最新全量建表语句/Clickhouse_TSG_建表语句.sql index 31e2b4a..4187890 100644 --- a/Clickhouse最新全量建表语句/Clickhouse_TSG_建表语句.sql +++ b/Clickhouse最新全量建表语句/Clickhouse_TSG_建表语句.sql @@ -6,6 +6,7 @@ CREATE TABLE IF NOT EXISTS tsg_galaxy_v3.dos_event_local on cluster ck_cluster ( recv_time Int64, log_id UInt64, profile_id Int64, + rule_id Int64, start_time Int64, end_time Int64, attack_type String, @@ -15,8 +16,11 @@ CREATE TABLE IF NOT EXISTS tsg_galaxy_v3.dos_event_local on cluster ck_cluster ( destination_country String, source_ip_list String, source_country_list String, + sessions Int64, session_rate Int64, + packets Int64, packet_rate Int64, + bytes Int64, bit_rate Int64 ) ENGINE = MergeTree @@ -28,6 +32,7 @@ CREATE TABLE IF NOT EXISTS tsg_galaxy_v3.dos_event on cluster ck_cluster ( recv_time Int64, log_id UInt64, profile_id Int64, + rule_id Int64, start_time Int64, end_time Int64, attack_type String, @@ -37,8 +42,11 @@ CREATE TABLE IF NOT EXISTS tsg_galaxy_v3.dos_event on cluster ck_cluster ( destination_country String, source_ip_list String, source_country_list String, + sessions Int64, session_rate Int64, + packets Int64, packet_rate Int64, + bytes Int64, bit_rate Int64 ) ENGINE =Distributed(ck_cluster,tsg_galaxy_v3,dos_event_local,rand()); @@ -48,6 +56,7 @@ CREATE TABLE IF NOT EXISTS tsg_galaxy_v3.dos_event on cluster ck_query ( recv_time Int64, log_id UInt64, profile_id Int64, + rule_id Int64, start_time Int64, end_time Int64, attack_type String, @@ -57,8 +66,11 @@ CREATE TABLE IF NOT EXISTS tsg_galaxy_v3.dos_event on cluster ck_query ( destination_country String, source_ip_list String, source_country_list String, + sessions Int64, session_rate Int64, + packets Int64, packet_rate Int64, + bytes Int64, bit_rate Int64 ) ENGINE =Distributed(ck_cluster,tsg_galaxy_v3,dos_event_local,rand()); diff --git a/Clickhouse最新全量建表语句/Clickhouse_TSG_校验sql.sql b/Clickhouse最新全量建表语句/Clickhouse_TSG_校验sql.sql index 5a6a17f..fe00711 100644 --- a/Clickhouse最新全量建表语句/Clickhouse_TSG_校验sql.sql +++ b/Clickhouse最新全量建表语句/Clickhouse_TSG_校验sql.sql @@ -1,6 +1,6 @@ SELECT log_id, recv_time, vsys_id, assessment_date, lot_number, file_name, assessment_file, assessment_type, features, `size`, file_checksum_sha FROM tsg_galaxy_v3.assessment_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time = toUnixTimestamp('2030-01-01 00:00:00') AND recv_time