15361536 "user_agent.original" : " Debian APT-HTTP/1.3 (1.6.3ubuntu0.1)" ,
15371537 "user_agent.os.name" : " Debian" ,
15381538 "user_agent.version" : " 1.3"
1539+ },
1540+ {
1541+ "@timestamp" : " 2018-10-04T09:35:02.796Z" ,
1542+ "destination.address" : " 10.232.0.237" ,
1543+ "destination.domain" : " hostname.domain.net" ,
1544+ "destination.ip" : " 10.232.0.237" ,
1545+ "destination.port" : 9080 ,
1546+ "event.category" : [
1547+ " network"
1548+ ],
1549+ "event.dataset" : " suricata.eve" ,
1550+ "event.kind" : " event" ,
1551+ "event.module" : " suricata" ,
1552+ "event.original": "{\"tls\":{\"ja3s\":{\"string\":\"333,55555,66666-22\",\"hash\":\"0993626a07ad09e1ce91293be7aa5721\"},\"ja3\":{\"string\":\"001,22222-33333-00-44444-66666-333-333-55555-55555-22-55555-44444-22-33-66666-77777-22-88888-99999-333-22-66666-77777-22-99999-96611-22-33-88888-33333-88888-333-22222-33333-333-222-88888-444-99999-22222-666-777-888,22-33-44-55-6,77-88-99-0-11-11-22-33-44-55,0\",\"hash\":\"d92325c876e7279f4eb8c62415e3a6b7\"},\"notafter\":\"2024-07-16T14:52:35\",\"notbefore\":\"2019-07-17T14:52:35\",\"version\":\"TLS 1.2\",\"sni\":\"hostname.domain.net\",\"fingerprint\":\"00:11:22:33:44:55:66:77:88:99:aa:bb:cc:dd:ee:ff:00:11:22:33\",\"serial\":\"00:11:22:33:44:55:66:77:88\",\"issuerdn\":\"CN=UNKNOWN/DC=UNKNOWN/DC=UNKNOWN/C=UNKNOWN/ST=UNKNOWN/O=UNK-NOWN/OU=UNKNOWN\",\"subject\":\"C=UNKNOWN, ST=UNKNOWN, L=UNKNOWN, O=UNKNOWN, OU=UNKNOWN, CN=hostname.domain.net/emailAddress=user@domain.com\"},\"proto\":\"TCP\",\"dest_port\":9080,\"dest_ip\":\"10.232.0.237\",\"src_port\":45884,\"src_ip\":\"10.126.2.140\",\"event_type\":\"tls\",\"in_iface\":\"enp5s0\",\"flow_id\":1091813059495729,\"timestamp\":\"2018-10-04T09:35:02.796615+0000\"}",
1553+ "event.type" : [
1554+ " protocol"
1555+ ],
1556+ "fileset.name" : " eve" ,
1557+ "input.type" : " log" ,
1558+ "log.offset" : 16546 ,
1559+ "network.community_id" : " 1:qsGDjYDIWp+kHhxotTdhPbUaWSo=" ,
1560+ "network.protocol" : " tls" ,
1561+ "network.transport" : " tcp" ,
1562+ "related.hash" : [
1563+ " 00112233445566778899AABBCCDDEEFF00112233"
1564+ ],
1565+ "related.ip" : [
1566+ " 10.126.2.140" ,
1567+ " 10.232.0.237"
1568+ ],
1569+ "service.type" : " suricata" ,
1570+ "source.address" : " 10.126.2.140" ,
1571+ "source.ip" : " 10.126.2.140" ,
1572+ "source.port" : 45884 ,
1573+ "suricata.eve.event_type" : " tls" ,
1574+ "suricata.eve.flow_id" : 1091813059495729 ,
1575+ "suricata.eve.in_iface" : " enp5s0" ,
1576+ "suricata.eve.tls.fingerprint" : " 00:11:22:33:44:55:66:77:88:99:aa:bb:cc:dd:ee:ff:00:11:22:33" ,
1577+ "suricata.eve.tls.issuerdn" : " CN=UNKNOWN/DC=UNKNOWN/DC=UNKNOWN/C=UNKNOWN/ST=UNKNOWN/O=UNK-NOWN/OU=UNKNOWN" ,
1578+ "suricata.eve.tls.ja3.hash" : " d92325c876e7279f4eb8c62415e3a6b7" ,
1579+ "suricata.eve.tls.ja3.string" : " 001,22222-33333-00-44444-66666-333-333-55555-55555-22-55555-44444-22-33-66666-77777-22-88888-99999-333-22-66666-77777-22-99999-96611-22-33-88888-33333-88888-333-22222-33333-333-222-88888-444-99999-22222-666-777-888,22-33-44-55-6,77-88-99-0-11-11-22-33-44-55,0" ,
1580+ "suricata.eve.tls.ja3s.hash" : " 0993626a07ad09e1ce91293be7aa5721" ,
1581+ "suricata.eve.tls.ja3s.string" : " 333,55555,66666-22" ,
1582+ "suricata.eve.tls.notafter" : " 2024-07-16T14:52:35" ,
1583+ "suricata.eve.tls.notbefore" : " 2019-07-17T14:52:35" ,
1584+ "suricata.eve.tls.serial" : " 00:11:22:33:44:55:66:77:88" ,
1585+ "suricata.eve.tls.sni" : " hostname.domain.net" ,
1586+ "suricata.eve.tls.subject" : " C=UNKNOWN, ST=UNKNOWN, L=UNKNOWN, O=UNKNOWN, OU=UNKNOWN, CN=hostname.domain.net/emailAddress=user@domain.com" ,
1587+ "suricata.eve.tls.version" : " TLS 1.2" ,
1588+ "tags" : [
1589+ " suricata"
1590+ ],
1591+ "tls.client.ja3" : " d92325c876e7279f4eb8c62415e3a6b7" ,
1592+ "tls.client.server_name" : " hostname.domain.net" ,
1593+ "tls.server.hash.sha1" : " 00112233445566778899AABBCCDDEEFF00112233" ,
1594+ "tls.server.issuer" : " CN=UNKNOWN/DC=UNKNOWN/DC=UNKNOWN/C=UNKNOWN/ST=UNKNOWN/O=UNK-NOWN/OU=UNKNOWN" ,
1595+ "tls.server.ja3s" : " 0993626a07ad09e1ce91293be7aa5721" ,
1596+ "tls.server.not_after" : " 2024-07-16T14:52:35" ,
1597+ "tls.server.not_before" : " 2019-07-17T14:52:35" ,
1598+ "tls.server.subject" : " C=UNKNOWN, ST=UNKNOWN, L=UNKNOWN, O=UNKNOWN, OU=UNKNOWN, CN=hostname.domain.net/emailAddress=user@domain.com" ,
1599+ "tls.version" : " 1.2" ,
1600+ "tls.version_protocol" : " tls"
1601+ },
1602+ {
1603+ "@timestamp" : " 2020-06-26T15:00:03.342Z" ,
1604+ "destination.address" : " 10.128.2.48" ,
1605+ "destination.bytes" : 4660 ,
1606+ "destination.domain" : " host.domain.net" ,
1607+ "destination.ip" : " 10.128.2.48" ,
1608+ "destination.packets" : 8 ,
1609+ "destination.port" : 8443 ,
1610+ "event.category" : [
1611+ " network" ,
1612+ " intrusion_detection"
1613+ ],
1614+ "event.dataset" : " suricata.eve" ,
1615+ "event.kind" : " alert" ,
1616+ "event.module" : " suricata" ,
1617+ "event.original": "{\"flow\":{\"start\":\"2020-06-26T11:00:02.970011-0400\",\"bytes_toclient\":4660,\"bytes_toserver\":1074,\"pkts_toclient\":8,\"pkts_toserver\":7},\"app_proto\":\"tls\",\"tls\":{\"ja3s\":{\"string\":\"742,48172,30210-30\",\"hash\":\"391231ba5675e42807b9e1f457b2614e\"},\"ja3\":{\"string\":\"718,4682-2687-2686-41992-41911-53292-53297-41969-22905-41926-41924-94181-94711-15-23-95-12-11-205,0-33-50-53-6-61-39-23-34-85-81,93-04-52,3-9-3\",\"hash\":\"3f1ea03f5822e8021b60cc3e4b233181\"},\"notafter\":\"2026-06-25T17:36:29\",\"notbefore\":\"2016-06-27T17:36:29\",\"version\":\"TLS 1.2\",\"sni\":\"host.domain.net\",\"fingerprint\":\"36:3f:ee:2a:1c:fa:de:ad:be:ef:42:99:cf:a9:b0:91:01:eb:a9:cc\",\"serial\":\"72:A9:2C:51\",\"issuerdn\":\"C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown\",\"subject\":\"C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown\"},\"alert\":{\"severity\":3,\"category\":\"\",\"signature\":\"SURICATA TLS on unusual port\",\"rev\":1,\"signature_id\":2610003,\"gid\":1,\"action\":\"allowed\"},\"proto\":\"TCP\",\"dest_port\":8443,\"dest_ip\":\"10.128.2.48\",\"src_port\":64389,\"src_ip\":\"10.137.3.54\",\"event_type\":\"alert\",\"in_iface\":\"enp0s31f6\",\"flow_id\":991192778198299,\"timestamp\":\"2020-06-26T11:00:03.342282-0400\"}",
1618+ "event.severity" : 3 ,
1619+ "event.start" : " 2020-06-26T15:00:02.970Z" ,
1620+ "event.type" : [
1621+ " allowed"
1622+ ],
1623+ "fileset.name" : " eve" ,
1624+ "input.type" : " log" ,
1625+ "log.offset" : 17606 ,
1626+ "message" : " " ,
1627+ "network.bytes" : 5734 ,
1628+ "network.community_id" : " 1:W6fjhboFUwyEchJ3ELaqSBzDEJE=" ,
1629+ "network.packets" : 15 ,
1630+ "network.protocol" : " tls" ,
1631+ "network.transport" : " tcp" ,
1632+ "related.hash" : [
1633+ " 363FEE2A1CFADEADBEEF4299CFA9B09101EBA9CC"
1634+ ],
1635+ "related.ip" : [
1636+ " 10.137.3.54" ,
1637+ " 10.128.2.48"
1638+ ],
1639+ "rule.id" : " 2610003" ,
1640+ "rule.name" : " SURICATA TLS on unusual port" ,
1641+ "service.type" : " suricata" ,
1642+ "source.address" : " 10.137.3.54" ,
1643+ "source.bytes" : 1074 ,
1644+ "source.ip" : " 10.137.3.54" ,
1645+ "source.packets" : 7 ,
1646+ "source.port" : 64389 ,
1647+ "suricata.eve.alert.category" : " " ,
1648+ "suricata.eve.alert.gid" : 1 ,
1649+ "suricata.eve.alert.rev" : 1 ,
1650+ "suricata.eve.alert.signature" : " SURICATA TLS on unusual port" ,
1651+ "suricata.eve.alert.signature_id" : 2610003 ,
1652+ "suricata.eve.event_type" : " alert" ,
1653+ "suricata.eve.flow_id" : 991192778198299 ,
1654+ "suricata.eve.in_iface" : " enp0s31f6" ,
1655+ "suricata.eve.tls.fingerprint" : " 36:3f:ee:2a:1c:fa:de:ad:be:ef:42:99:cf:a9:b0:91:01:eb:a9:cc" ,
1656+ "suricata.eve.tls.issuerdn" : " C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown" ,
1657+ "suricata.eve.tls.ja3.hash" : " 3f1ea03f5822e8021b60cc3e4b233181" ,
1658+ "suricata.eve.tls.ja3.string" : " 718,4682-2687-2686-41992-41911-53292-53297-41969-22905-41926-41924-94181-94711-15-23-95-12-11-205,0-33-50-53-6-61-39-23-34-85-81,93-04-52,3-9-3" ,
1659+ "suricata.eve.tls.ja3s.hash" : " 391231ba5675e42807b9e1f457b2614e" ,
1660+ "suricata.eve.tls.ja3s.string" : " 742,48172,30210-30" ,
1661+ "suricata.eve.tls.notafter" : " 2026-06-25T17:36:29" ,
1662+ "suricata.eve.tls.notbefore" : " 2016-06-27T17:36:29" ,
1663+ "suricata.eve.tls.serial" : " 72:A9:2C:51" ,
1664+ "suricata.eve.tls.sni" : " host.domain.net" ,
1665+ "suricata.eve.tls.subject" : " C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown" ,
1666+ "suricata.eve.tls.version" : " TLS 1.2" ,
1667+ "tags" : [
1668+ " suricata"
1669+ ],
1670+ "tls.client.ja3" : " 3f1ea03f5822e8021b60cc3e4b233181" ,
1671+ "tls.client.server_name" : " host.domain.net" ,
1672+ "tls.server.hash.sha1" : " 363FEE2A1CFADEADBEEF4299CFA9B09101EBA9CC" ,
1673+ "tls.server.issuer" : " C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown" ,
1674+ "tls.server.ja3s" : " 391231ba5675e42807b9e1f457b2614e" ,
1675+ "tls.server.not_after" : " 2026-06-25T17:36:29" ,
1676+ "tls.server.not_before" : " 2016-06-27T17:36:29" ,
1677+ "tls.server.subject" : " C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown" ,
1678+ "tls.version" : " 1.2" ,
1679+ "tls.version_protocol" : " tls"
15391680 }
15401681]
0 commit comments