TSG-22690 Clickhouse新增xx_rule_uuid_list字段
This commit is contained in:
@@ -116,12 +116,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -368,12 +374,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -618,12 +630,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -869,12 +887,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -1119,12 +1143,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -1370,12 +1400,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -1958,12 +1994,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -2126,12 +2168,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -2295,12 +2343,18 @@ TO tsg_galaxy_v3.security_event_local
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -2543,12 +2597,18 @@ SELECT
|
||||
c2s_ttl,
|
||||
s2c_ttl,
|
||||
security_rule_list,
|
||||
security_rule_uuid_list,
|
||||
security_action,
|
||||
monitor_rule_list,
|
||||
monitor_rule_uuid_list,
|
||||
shaping_rule_list,
|
||||
shaping_rule_uuid_list,
|
||||
proxy_rule_list,
|
||||
proxy_rule_uuid_list,
|
||||
statistics_rule_list,
|
||||
statistics_rule_uuid_list,
|
||||
sc_rule_list,
|
||||
sc_rule_uuid_list,
|
||||
sc_rsp_raw,
|
||||
sc_rsp_decrypted,
|
||||
proxy_action,
|
||||
@@ -2762,7 +2822,7 @@ SELECT
|
||||
tunnel_endpoint_a_desc,
|
||||
tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record_local
|
||||
WHERE empty(security_rule_list) = 0
|
||||
WHERE empty(security_rule_uuid_list) = 0
|
||||
;
|
||||
|
||||
-- tsg_galaxy_v3.monitor_event_materialized_view
|
||||
@@ -2796,12 +2856,18 @@ TO tsg_galaxy_v3.monitor_event_local
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -3044,12 +3110,18 @@ SELECT
|
||||
c2s_ttl,
|
||||
s2c_ttl,
|
||||
security_rule_list,
|
||||
security_rule_uuid_list,
|
||||
security_action,
|
||||
monitor_rule_list,
|
||||
monitor_rule_uuid_list,
|
||||
shaping_rule_list,
|
||||
shaping_rule_uuid_list,
|
||||
proxy_rule_list,
|
||||
proxy_rule_uuid_list,
|
||||
statistics_rule_list,
|
||||
statistics_rule_uuid_list,
|
||||
sc_rule_list,
|
||||
sc_rule_uuid_list,
|
||||
sc_rsp_raw,
|
||||
sc_rsp_decrypted,
|
||||
proxy_action,
|
||||
@@ -3263,7 +3335,7 @@ SELECT
|
||||
tunnel_endpoint_a_desc,
|
||||
tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record_local
|
||||
WHERE empty(monitor_rule_list) = 0
|
||||
WHERE empty(monitor_rule_uuid_list) = 0
|
||||
;
|
||||
|
||||
|
||||
|
||||
@@ -2,13 +2,13 @@ SELECT log_id, recv_time, vsys_id, assessment_date, lot_number, file_name, asses
|
||||
FROM tsg_galaxy_v3.assessment_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT vsys_id, recv_time, log_id, profile_id, rule_id, start_time, end_time, attack_type, severity, conditions, destination_ip, destination_country, source_ip_list, source_country_list, sessions, session_rate, packets, packet_rate, bytes, bit_rate
|
||||
FROM tsg_galaxy_v3.dos_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, shaping_rule_list, proxy_rule_list, statistics_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.monitor_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, shaping_rule_list, proxy_rule_list, statistics_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, doh_url, doh_host, doh_request_line, doh_response_line, doh_cookie, doh_referer, doh_user_agent, doh_content_length, doh_content_type, doh_set_cookie, doh_version, doh_message_id, doh_qr, doh_opcode, doh_aa, doh_tc, doh_rd, doh_ra, doh_rcode, doh_qdcount, doh_ancount, doh_nscount, doh_arcount, doh_qname, doh_qtype, doh_qclass, doh_cname, doh_sub, doh_rr, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, doh_url, doh_host, doh_request_line, doh_response_line, doh_cookie, doh_referer, doh_user_agent, doh_content_length, doh_content_type, doh_set_cookie, doh_version, doh_message_id, doh_qr, doh_opcode, doh_aa, doh_tc, doh_rd, doh_ra, doh_rcode, doh_qdcount, doh_ancount, doh_nscount, doh_arcount, doh_qname, doh_qtype, doh_qclass, doh_cname, doh_sub, doh_rr, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.proxy_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, shaping_rule_list, proxy_rule_list, statistics_rule_list, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.security_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, shaping_rule_list, proxy_rule_list, statistics_rule_list, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, ingestion_time, processing_time, insert_time, address_type, vsys_id, client_ip, client_port, server_ip, server_port, sent_pkts, received_pkts, sent_bytes, received_bytes, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason
|
||||
FROM tsg_galaxy_v3.transaction_record where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
|
||||
@@ -116,12 +116,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -368,12 +374,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -618,12 +630,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -869,12 +887,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -1119,12 +1143,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -1370,12 +1400,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -1958,12 +1994,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -2126,12 +2168,18 @@ flags_identify_info String,
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -2295,12 +2343,18 @@ TO tsg_galaxy_v3.security_event_local
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -2543,12 +2597,18 @@ SELECT
|
||||
c2s_ttl,
|
||||
s2c_ttl,
|
||||
security_rule_list,
|
||||
security_rule_uuid_list,
|
||||
security_action,
|
||||
monitor_rule_list,
|
||||
monitor_rule_uuid_list,
|
||||
shaping_rule_list,
|
||||
shaping_rule_uuid_list,
|
||||
proxy_rule_list,
|
||||
proxy_rule_uuid_list,
|
||||
statistics_rule_list,
|
||||
statistics_rule_uuid_list,
|
||||
sc_rule_list,
|
||||
sc_rule_uuid_list,
|
||||
sc_rsp_raw,
|
||||
sc_rsp_decrypted,
|
||||
proxy_action,
|
||||
@@ -2762,7 +2822,7 @@ SELECT
|
||||
tunnel_endpoint_a_desc,
|
||||
tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record_local
|
||||
WHERE empty(security_rule_list) = 0
|
||||
WHERE empty(security_rule_uuid_list) = 0
|
||||
;
|
||||
|
||||
-- tsg_galaxy_v3.monitor_event_materialized_view
|
||||
@@ -2796,12 +2856,18 @@ TO tsg_galaxy_v3.monitor_event_local
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -3044,12 +3110,18 @@ SELECT
|
||||
c2s_ttl,
|
||||
s2c_ttl,
|
||||
security_rule_list,
|
||||
security_rule_uuid_list,
|
||||
security_action,
|
||||
monitor_rule_list,
|
||||
monitor_rule_uuid_list,
|
||||
shaping_rule_list,
|
||||
shaping_rule_uuid_list,
|
||||
proxy_rule_list,
|
||||
proxy_rule_uuid_list,
|
||||
statistics_rule_list,
|
||||
statistics_rule_uuid_list,
|
||||
sc_rule_list,
|
||||
sc_rule_uuid_list,
|
||||
sc_rsp_raw,
|
||||
sc_rsp_decrypted,
|
||||
proxy_action,
|
||||
@@ -3263,7 +3335,7 @@ SELECT
|
||||
tunnel_endpoint_a_desc,
|
||||
tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record_local
|
||||
WHERE empty(monitor_rule_list) = 0
|
||||
WHERE empty(monitor_rule_uuid_list) = 0
|
||||
;
|
||||
|
||||
|
||||
|
||||
@@ -2,13 +2,13 @@ SELECT log_id, recv_time, vsys_id, assessment_date, lot_number, file_name, asses
|
||||
FROM tsg_galaxy_v3.assessment_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT vsys_id, recv_time, log_id, profile_id, rule_id, start_time, end_time, attack_type, severity, conditions, destination_ip, destination_country, source_ip_list, source_country_list, sessions, session_rate, packets, packet_rate, bytes, bit_rate
|
||||
FROM tsg_galaxy_v3.dos_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, shaping_rule_list, proxy_rule_list, statistics_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.monitor_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, shaping_rule_list, proxy_rule_list, statistics_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, doh_url, doh_host, doh_request_line, doh_response_line, doh_cookie, doh_referer, doh_user_agent, doh_content_length, doh_content_type, doh_set_cookie, doh_version, doh_message_id, doh_qr, doh_opcode, doh_aa, doh_tc, doh_rd, doh_ra, doh_rcode, doh_qdcount, doh_ancount, doh_nscount, doh_arcount, doh_qname, doh_qtype, doh_qclass, doh_cname, doh_sub, doh_rr, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, doh_url, doh_host, doh_request_line, doh_response_line, doh_cookie, doh_referer, doh_user_agent, doh_content_length, doh_content_type, doh_set_cookie, doh_version, doh_message_id, doh_qr, doh_opcode, doh_aa, doh_tc, doh_rd, doh_ra, doh_rcode, doh_qdcount, doh_ancount, doh_nscount, doh_arcount, doh_qname, doh_qtype, doh_qclass, doh_cname, doh_sub, doh_rr, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.proxy_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, shaping_rule_list, proxy_rule_list, statistics_rule_list, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.security_event where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_action, monitor_rule_list, sc_rule_list, sc_rsp_raw, sc_rsp_decrypted, shaping_rule_list, proxy_rule_list, statistics_rule_list, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
SELECT recv_time, log_id, decoded_as, session_id, start_timestamp_ms, end_timestamp_ms, duration_ms, tcp_handshake_latency_ms, ingestion_time, processing_time, insert_time, device_id, out_link_id, in_link_id, device_tag, data_center, device_group, sled_ip, address_type, direction, vsys_id, t_vsys_id, flags, flags_identify_info, c2s_ttl, s2c_ttl, security_rule_list, security_rule_uuid_list, security_action, monitor_rule_list, monitor_rule_uuid_list, shaping_rule_list, shaping_rule_uuid_list, proxy_rule_list, proxy_rule_uuid_list, statistics_rule_list, statistics_rule_uuid_list, sc_rule_list, sc_rule_uuid_list, sc_rsp_raw, sc_rsp_decrypted, proxy_action, proxy_pinning_status, proxy_intercept_status, proxy_passthrough_reason, proxy_client_side_latency_ms, proxy_server_side_latency_ms, proxy_client_side_version, proxy_server_side_version, proxy_cert_verify, proxy_intercept_error, monitor_mirrored_pkts, monitor_mirrored_bytes, client_ip, client_ip_tags, client_port, client_os_desc, client_geolocation, client_country, client_super_administrative_area, client_administrative_area, client_sub_administrative_area, client_asn, subscriber_id, imei, imsi, phone_number, apn, server_ip, server_ip_tags, server_port, server_os_desc, server_geolocation, server_country, server_super_administrative_area, server_administrative_area, server_sub_administrative_area, server_asn, server_fqdn, server_fqdn_tags, server_domain, app_transition, app, app_category, app_debug_info, app_content, app_extra_info, fqdn_category_list, ip_protocol, decoded_path, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, ssl_version, ssl_sni, ssl_san, ssl_cn, ssl_handshake_latency_ms, ssl_ja3_hash, ssl_ja3s_hash, ssl_ja4_fingerprint, ssl_ja4s_fingerprint, ssl_cert_issuer, ssl_cert_subject, ssl_esni_flag, ssl_ech_flag, dtls_cookie, dtls_version, dtls_sni, dtls_san, dtls_cn, dtls_handshake_latency_ms, dtls_ja3_fingerprint, dtls_ja3_hash, dtls_cert_issuer, dtls_cert_subject, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, ftp_account, ftp_url, ftp_link_type, quic_version, quic_sni, quic_user_agent, rdp_cookie, rdp_security_protocol, rdp_client_channels, rdp_keyboard_layout, rdp_client_version, rdp_client_name, rdp_client_product_id, rdp_desktop_width, rdp_desktop_height, rdp_requested_color_depth, rdp_certificate_type, rdp_certificate_count, rdp_certificate_permanent, rdp_encryption_level, rdp_encryption_method, ssh_version, ssh_auth_success, ssh_client_version, ssh_server_version, ssh_cipher_alg, ssh_mac_alg, ssh_compression_alg, ssh_kex_alg, ssh_host_key_alg, ssh_host_key, ssh_hassh, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason, rtp_payload_type_c2s, rtp_payload_type_s2c, rtp_pcap_path, rtp_originator_dir, stratum_cryptocurrency, stratum_mining_pools, stratum_mining_program, stratum_mining_subscribe, sent_pkts, received_pkts, sent_bytes, received_bytes, tcp_c2s_ip_fragments, tcp_s2c_ip_fragments, tcp_c2s_lost_bytes, tcp_s2c_lost_bytes, tcp_c2s_o3_pkts, tcp_s2c_o3_pkts, tcp_c2s_rtx_pkts, tcp_s2c_rtx_pkts, tcp_c2s_rtx_bytes, tcp_s2c_rtx_bytes, tcp_rtt_ms, tcp_client_isn, tcp_server_isn, packet_capture_file, in_src_mac, out_src_mac, in_dest_mac, out_dest_mac, encapsulation, dup_traffic_flag, tunnel_id_list, tunnel_endpoint_a_desc, tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
SELECT recv_time, log_id, decoded_as, session_id, ingestion_time, processing_time, insert_time, address_type, vsys_id, client_ip, client_port, server_ip, server_port, sent_pkts, received_pkts, sent_bytes, received_bytes, dns_message_id, dns_qr, dns_opcode, dns_aa, dns_tc, dns_rd, dns_ra, dns_rcode, dns_qdcount, dns_ancount, dns_nscount, dns_arcount, dns_qname, dns_qtype, dns_qclass, dns_cname, dns_sub, dns_rr, dns_response_latency_ms, http_url, http_host, http_request_line, http_response_line, http_request_body, http_response_body, http_proxy_flag, http_sequence, http_cookie, http_referer, http_user_agent, http_request_content_length, http_request_content_type, http_response_content_length, http_response_content_type, http_set_cookie, http_version, http_status_code, http_response_latency_ms, http_session_duration_ms, http_action_file_size, mail_protocol_type, mail_account, mail_from_cmd, mail_to_cmd, mail_from, mail_password, mail_to, mail_cc, mail_bcc, mail_subject, mail_subject_charset, mail_attachment_name, mail_attachment_name_charset, mail_starttls_flag, mail_eml_file, sip_call_id, sip_originator_description, sip_responder_description, sip_user_agent, sip_server, sip_originator_sdp_connect_ip, sip_originator_sdp_media_port, sip_originator_sdp_media_type, sip_originator_sdp_content, sip_responder_sdp_connect_ip, sip_responder_sdp_media_port, sip_responder_sdp_media_type, sip_responder_sdp_content, sip_duration_s, sip_bye, sip_bye_reason
|
||||
FROM tsg_galaxy_v3.transaction_record where recv_time >= toUnixTimestamp('2030-01-01 00:00:00') AND recv_time <toUnixTimestamp('2030-01-01 00:00:01');
|
||||
|
||||
@@ -22,6 +22,85 @@ ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS ssl_ja4s_fingerprint String after ssl_ja4_fingerprint;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS ssl_ja4s_fingerprint String after ssl_ja4_fingerprint;
|
||||
|
||||
-- TSG-22690 Clickhouse新增xx_rule_uuid_list字段
|
||||
|
||||
ALTER table tsg_galaxy_v3.session_record_local on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
ALTER table tsg_galaxy_v3.session_record on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.security_event_local on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.proxy_event_local on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
ALTER table tsg_galaxy_v3.proxy_event on cluster ck_cluster add column IF NOT EXISTS security_rule_uuid_list Array(String) after security_rule_list;
|
||||
|
||||
|
||||
ALTER table tsg_galaxy_v3.session_record_local on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
ALTER table tsg_galaxy_v3.session_record on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.security_event_local on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.proxy_event_local on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
ALTER table tsg_galaxy_v3.proxy_event on cluster ck_cluster add column IF NOT EXISTS monitor_rule_uuid_list Array(String) after monitor_rule_list;
|
||||
|
||||
|
||||
ALTER table tsg_galaxy_v3.session_record_local on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
ALTER table tsg_galaxy_v3.session_record on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.security_event_local on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.proxy_event_local on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
ALTER table tsg_galaxy_v3.proxy_event on cluster ck_cluster add column IF NOT EXISTS shaping_rule_uuid_list Array(String) after shaping_rule_list;
|
||||
|
||||
|
||||
ALTER table tsg_galaxy_v3.session_record_local on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
ALTER table tsg_galaxy_v3.session_record on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.security_event_local on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.proxy_event_local on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
ALTER table tsg_galaxy_v3.proxy_event on cluster ck_cluster add column IF NOT EXISTS proxy_rule_uuid_list Array(String) after proxy_rule_list;
|
||||
|
||||
|
||||
ALTER table tsg_galaxy_v3.session_record_local on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
ALTER table tsg_galaxy_v3.session_record on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.security_event_local on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.proxy_event_local on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
ALTER table tsg_galaxy_v3.proxy_event on cluster ck_cluster add column IF NOT EXISTS statistics_rule_uuid_list Array(String) after statistics_rule_list;
|
||||
|
||||
|
||||
ALTER table tsg_galaxy_v3.session_record_local on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
ALTER table tsg_galaxy_v3.session_record on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.security_event_local on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
ALTER table tsg_galaxy_v3.security_event on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.monitor_event_local on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
ALTER table tsg_galaxy_v3.monitor_event on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
|
||||
ALTER table tsg_galaxy_v3.proxy_event_local on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
ALTER table tsg_galaxy_v3.proxy_event on cluster ck_cluster add column IF NOT EXISTS sc_rule_uuid_list Array(String) after sc_rule_list;
|
||||
|
||||
|
||||
-- tsg_galaxy_v3.security_event_materialized_view
|
||||
CREATE MATERIALIZED VIEW IF NOT EXISTS tsg_galaxy_v3.security_event_materialized_view on cluster ck_cluster
|
||||
@@ -54,12 +133,18 @@ TO tsg_galaxy_v3.security_event_local
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -302,12 +387,18 @@ SELECT
|
||||
c2s_ttl,
|
||||
s2c_ttl,
|
||||
security_rule_list,
|
||||
security_rule_uuid_list,
|
||||
security_action,
|
||||
monitor_rule_list,
|
||||
monitor_rule_uuid_list,
|
||||
shaping_rule_list,
|
||||
shaping_rule_uuid_list,
|
||||
proxy_rule_list,
|
||||
proxy_rule_uuid_list,
|
||||
statistics_rule_list,
|
||||
statistics_rule_uuid_list,
|
||||
sc_rule_list,
|
||||
sc_rule_uuid_list,
|
||||
sc_rsp_raw,
|
||||
sc_rsp_decrypted,
|
||||
proxy_action,
|
||||
@@ -521,7 +612,7 @@ SELECT
|
||||
tunnel_endpoint_a_desc,
|
||||
tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record_local
|
||||
WHERE empty(security_rule_list) = 0
|
||||
WHERE empty(security_rule_uuid_list) = 0
|
||||
;
|
||||
|
||||
-- tsg_galaxy_v3.monitor_event_materialized_view
|
||||
@@ -555,12 +646,18 @@ TO tsg_galaxy_v3.monitor_event_local
|
||||
c2s_ttl Nullable(Int32),
|
||||
s2c_ttl Nullable(Int32),
|
||||
security_rule_list Array(Int64),
|
||||
security_rule_uuid_list Array(String),
|
||||
security_action String,
|
||||
monitor_rule_list Array(Int64),
|
||||
monitor_rule_uuid_list Array(String),
|
||||
shaping_rule_list Array(Int64),
|
||||
shaping_rule_uuid_list Array(String),
|
||||
proxy_rule_list Array(Int64),
|
||||
proxy_rule_uuid_list Array(String),
|
||||
statistics_rule_list Array(Int64),
|
||||
statistics_rule_uuid_list Array(String),
|
||||
sc_rule_list Array(Int64),
|
||||
sc_rule_uuid_list Array(String),
|
||||
sc_rsp_raw Array(Int64),
|
||||
sc_rsp_decrypted Array(Int64),
|
||||
proxy_action String,
|
||||
@@ -803,12 +900,18 @@ SELECT
|
||||
c2s_ttl,
|
||||
s2c_ttl,
|
||||
security_rule_list,
|
||||
security_rule_uuid_list,
|
||||
security_action,
|
||||
monitor_rule_list,
|
||||
monitor_rule_uuid_list,
|
||||
shaping_rule_list,
|
||||
shaping_rule_uuid_list,
|
||||
proxy_rule_list,
|
||||
proxy_rule_uuid_list,
|
||||
statistics_rule_list,
|
||||
statistics_rule_uuid_list,
|
||||
sc_rule_list,
|
||||
sc_rule_uuid_list,
|
||||
sc_rsp_raw,
|
||||
sc_rsp_decrypted,
|
||||
proxy_action,
|
||||
@@ -1022,6 +1125,6 @@ SELECT
|
||||
tunnel_endpoint_a_desc,
|
||||
tunnel_endpoint_b_desc
|
||||
FROM tsg_galaxy_v3.session_record_local
|
||||
WHERE empty(monitor_rule_list) = 0
|
||||
WHERE empty(monitor_rule_uuid_list) = 0
|
||||
;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user