1+ [
2+ {
3+ "@timestamp" : " 2017-04-21T05:28:40.441Z" ,
4+ "auditd.log.a0" : " 3" ,
5+ "auditd.log.a1" : " 7ffd0dc80040" ,
6+ "auditd.log.a2" : " 7ffd0dc7ffd0" ,
7+ "auditd.log.a3" : " 0" ,
8+ "auditd.log.items" : " 0" ,
9+ "auditd.log.key" : " key=net" ,
10+ "auditd.log.sequence" : 8832 ,
11+ "auditd.log.ses" : " 4294967295" ,
12+ "auditd.log.success" : " yes" ,
13+ "auditd.log.syscall" : " 43" ,
14+ "auditd.log.tty" : " (none)" ,
15+ "event.action" : " syscall" ,
16+ "event.dataset" : " auditd.log" ,
17+ "event.kind" : " event" ,
18+ "event.module" : " auditd" ,
19+ "fileset.name" : " log" ,
20+ "host.architecture" : " x86_64" ,
21+ "input.type" : " log" ,
22+ "log.offset" : 0 ,
23+ "network.direction" : " ingress" ,
24+ "process.executable" : " /usr/sbin/sshd" ,
25+ "process.exit_code" : 5 ,
26+ "process.name" : " sshd" ,
27+ "process.pid" : 1663 ,
28+ "process.ppid" : 1 ,
29+ "service.type" : " auditd" ,
30+ "user.audit.id" : " 4294967295" ,
31+ "user.effective.group.id" : " 0" ,
32+ "user.effective.id" : " 0" ,
33+ "user.filesystem.group.id" : " 0" ,
34+ "user.filesystem.id" : " 0" ,
35+ "user.group.id" : " 0" ,
36+ "user.id" : " 0" ,
37+ "user.saved.group.id" : " 0" ,
38+ "user.saved.id" : " 0"
39+ },
40+ {
41+ "@timestamp" : " 2017-04-21T05:28:40.441Z" ,
42+ "auditd.log.saddr" : " 0200E31C4853E6640000000000000000" ,
43+ "auditd.log.sequence" : 8832 ,
44+ "event.action" : " sockaddr" ,
45+ "event.dataset" : " auditd.log" ,
46+ "event.kind" : " event" ,
47+ "event.module" : " auditd" ,
48+ "fileset.name" : " log" ,
49+ "input.type" : " log" ,
50+ "log.offset" : 300 ,
51+ "service.type" : " auditd"
52+ },
53+ {
54+ "@timestamp" : " 2017-04-21T05:28:40.441Z" ,
55+ "auditd.log.proctitle" : " (sshd)" ,
56+ "auditd.log.sequence" : 8832 ,
57+ "event.action" : " proctitle" ,
58+ "event.dataset" : " auditd.log" ,
59+ "event.kind" : " event" ,
60+ "event.module" : " auditd" ,
61+ "fileset.name" : " log" ,
62+ "input.type" : " log" ,
63+ "log.offset" : 385 ,
64+ "service.type" : " auditd"
65+ },
66+ {
67+ "@timestamp" : " 2017-04-21T05:38:27.096Z" ,
68+ "auditd.log.a0" : " 5" ,
69+ "auditd.log.a1" : " 7ffc12ac3ab0" ,
70+ "auditd.log.a2" : " 10" ,
71+ "auditd.log.a3" : " 4" ,
72+ "auditd.log.items" : " 0" ,
73+ "auditd.log.key" : " key=net" ,
74+ "auditd.log.sequence" : 9004 ,
75+ "auditd.log.ses" : " 4294967295" ,
76+ "auditd.log.success" : " no" ,
77+ "auditd.log.syscall" : " 42" ,
78+ "auditd.log.tty" : " (none)" ,
79+ "event.action" : " syscall" ,
80+ "event.dataset" : " auditd.log" ,
81+ "event.kind" : " event" ,
82+ "event.module" : " auditd" ,
83+ "fileset.name" : " log" ,
84+ "host.architecture" : " x86_64" ,
85+ "input.type" : " log" ,
86+ "log.offset" : 451 ,
87+ "network.direction" : " egress" ,
88+ "process.executable" : " /usr/bin/python3.5" ,
89+ "process.exit_code" : -115 ,
90+ "process.name" : " google_ip_forwa" ,
91+ "process.pid" : 1648 ,
92+ "process.ppid" : 1 ,
93+ "service.type" : " auditd" ,
94+ "user.audit.id" : " 4294967295" ,
95+ "user.effective.group.id" : " 0" ,
96+ "user.effective.id" : " 0" ,
97+ "user.filesystem.group.id" : " 0" ,
98+ "user.filesystem.id" : " 0" ,
99+ "user.group.id" : " 0" ,
100+ "user.id" : " 0" ,
101+ "user.saved.group.id" : " 0" ,
102+ "user.saved.id" : " 0"
103+ },
104+ {
105+ "@timestamp" : " 2017-04-21T05:38:27.096Z" ,
106+ "auditd.log.saddr" : " 02000050A9FEA9FE0000000000000000" ,
107+ "auditd.log.sequence" : 9004 ,
108+ "event.action" : " sockaddr" ,
109+ "event.dataset" : " auditd.log" ,
110+ "event.kind" : " event" ,
111+ "event.module" : " auditd" ,
112+ "fileset.name" : " log" ,
113+ "input.type" : " log" ,
114+ "log.offset" : 758 ,
115+ "service.type" : " auditd"
116+ },
117+ {
118+ "@timestamp" : " 2017-04-21T05:38:27.096Z" ,
119+ "auditd.log.proctitle" : " (g_daemon)" ,
120+ "auditd.log.sequence" : 9004 ,
121+ "event.action" : " proctitle" ,
122+ "event.dataset" : " auditd.log" ,
123+ "event.kind" : " event" ,
124+ "event.module" : " auditd" ,
125+ "fileset.name" : " log" ,
126+ "input.type" : " log" ,
127+ "log.offset" : 843 ,
128+ "service.type" : " auditd"
129+ }
130+ ]
0 commit comments