|
1 | 1 | { |
2 | 2 | "v": 1, |
3 | | - "id": "0cd3d0ac-2fd5-495a-8117-3e894de0e786", |
| 3 | + "id": "ab54d5e8-3495-4f2e-9647-e8572295297b", |
4 | 4 | "rev": 1, |
5 | 5 | "name": "BD Training Day 3", |
6 | 6 | "summary": "BD Training Day 3", |
|
12 | 12 | { |
13 | 13 | "v": "1", |
14 | 14 | "type": { |
15 | | - "name": "pipeline", |
| 15 | + "name": "stream", |
16 | 16 | "version": "1" |
17 | 17 | }, |
18 | | - "id": "568cab41-dae0-46a4-9f34-ebd854fd587b", |
| 18 | + "id": "32badf1d-4ed5-4307-8df0-2cf5a5700ce2", |
19 | 19 | "data": { |
| 20 | + "alarm_callbacks": [], |
| 21 | + "outputs": [], |
| 22 | + "remove_matches": { |
| 23 | + "@type": "boolean", |
| 24 | + "@value": true |
| 25 | + }, |
20 | 26 | "title": { |
21 | 27 | "@type": "string", |
22 | | - "@value": "Firewall Routing Pipeline" |
| 28 | + "@value": "Firewall Stream" |
23 | 29 | }, |
24 | | - "description": { |
| 30 | + "stream_rules": [], |
| 31 | + "alert_conditions": [], |
| 32 | + "matching_type": { |
25 | 33 | "@type": "string", |
26 | | - "@value": "Route firewall logs to Firewall Stream" |
| 34 | + "@value": "AND" |
27 | 35 | }, |
28 | | - "source": { |
| 36 | + "disabled": { |
| 37 | + "@type": "boolean", |
| 38 | + "@value": false |
| 39 | + }, |
| 40 | + "description": { |
29 | 41 | "@type": "string", |
30 | | - "@value": "pipeline \"Firewall Routing Pipeline\"\nstage 0 match either\nrule \"Route - Firewall Logs - Route to Firewall Stream\"\nend" |
| 42 | + "@value": "Firewall Logs" |
31 | 43 | }, |
32 | | - "connected_streams": [ |
33 | | - { |
34 | | - "@type": "string", |
35 | | - "@value": "95b4fe20-52f4-4559-9357-93f72b863a7e" |
36 | | - } |
37 | | - ] |
| 44 | + "default_stream": { |
| 45 | + "@type": "boolean", |
| 46 | + "@value": false |
| 47 | + } |
38 | 48 | }, |
39 | 49 | "constraints": [ |
40 | 50 | { |
|
49 | 59 | "name": "pipeline", |
50 | 60 | "version": "1" |
51 | 61 | }, |
52 | | - "id": "92f9b165-f029-49c7-bfe4-80de4426ff0b", |
| 62 | + "id": "3bf62201-1e35-4b21-a238-5d75c0d4455f", |
53 | 63 | "data": { |
54 | 64 | "title": { |
55 | 65 | "@type": "string", |
|
66 | 76 | "connected_streams": [ |
67 | 77 | { |
68 | 78 | "@type": "string", |
69 | | - "@value": "d312daf9-14fc-4e0b-ad06-c5a9f1eaccbf" |
| 79 | + "@value": "32badf1d-4ed5-4307-8df0-2cf5a5700ce2" |
70 | 80 | } |
71 | 81 | ] |
72 | 82 | }, |
|
80 | 90 | { |
81 | 91 | "v": "1", |
82 | 92 | "type": { |
83 | | - "name": "pipeline_rule", |
| 93 | + "name": "pipeline", |
84 | 94 | "version": "1" |
85 | 95 | }, |
86 | | - "id": "68bfa6f5-3b43-4f54-a60d-919ed1b3c337", |
| 96 | + "id": "38452db3-53d8-4867-9b0c-dc1c14643983", |
87 | 97 | "data": { |
88 | 98 | "title": { |
89 | 99 | "@type": "string", |
90 | | - "@value": "Route - Firewall Logs - Route to Firewall Stream" |
| 100 | + "@value": "Firewall Routing Pipeline" |
91 | 101 | }, |
92 | 102 | "description": { |
93 | 103 | "@type": "string", |
94 | 104 | "@value": "Route firewall logs to Firewall Stream" |
95 | 105 | }, |
96 | 106 | "source": { |
97 | 107 | "@type": "string", |
98 | | - "@value": "rule \"Route - Firewall Logs - Route to Firewall Stream\"\nwhen\n contains(\n value: to_string($message.message),\n search: \"zone=LAB\"\n )\nthen\n route_to_stream(\n name: \"Firewall Stream\",\n remove_from_default: true\n );\nend" |
99 | | - } |
| 108 | + "@value": "pipeline \"Firewall Routing Pipeline\"\nstage 0 match either\nrule \"Route - Firewall Logs - Route to Firewall Stream\"\nend" |
| 109 | + }, |
| 110 | + "connected_streams": [ |
| 111 | + { |
| 112 | + "@type": "string", |
| 113 | + "@value": "db9b1e9a-1fa7-4bb2-8cf2-448a3ac4fb78" |
| 114 | + } |
| 115 | + ] |
100 | 116 | }, |
101 | 117 | "constraints": [ |
102 | 118 | { |
|
108 | 124 | { |
109 | 125 | "v": "1", |
110 | 126 | "type": { |
111 | | - "name": "stream_title", |
| 127 | + "name": "pipeline_rule", |
112 | 128 | "version": "1" |
113 | 129 | }, |
114 | | - "id": "95b4fe20-52f4-4559-9357-93f72b863a7e", |
| 130 | + "id": "081333f5-768e-459d-8669-3307487483bc", |
115 | 131 | "data": { |
116 | 132 | "title": { |
117 | 133 | "@type": "string", |
118 | | - "@value": "Default Stream" |
| 134 | + "@value": "Parse - Firewall Logs - Base Parser" |
| 135 | + }, |
| 136 | + "description": { |
| 137 | + "@type": "string", |
| 138 | + "@value": "Parse Firewall Logs" |
| 139 | + }, |
| 140 | + "source": { |
| 141 | + "@type": "string", |
| 142 | + "@value": "rule \"Parse - Firewall Logs - Base Parser\"\nwhen\n true\nthen\n let x = key_value(\n value: to_string($message.message),\n trim_value_chars: '\"'\n );\n \n set_fields(x);\nend" |
119 | 143 | } |
120 | 144 | }, |
121 | 145 | "constraints": [ |
|
131 | 155 | "name": "pipeline_rule", |
132 | 156 | "version": "1" |
133 | 157 | }, |
134 | | - "id": "280b7fb8-3ce2-4f3a-8b1a-dd1537625fe0", |
| 158 | + "id": "7ded77ae-1061-4faf-a841-efbaee8640b3", |
135 | 159 | "data": { |
136 | 160 | "title": { |
137 | 161 | "@type": "string", |
|
159 | 183 | "name": "pipeline_rule", |
160 | 184 | "version": "1" |
161 | 185 | }, |
162 | | - "id": "6b506b75-4964-49b6-847e-bad925212e01", |
| 186 | + "id": "60c00610-26a7-4938-b780-f1907bcbd3d9", |
163 | 187 | "data": { |
164 | 188 | "title": { |
165 | 189 | "@type": "string", |
166 | | - "@value": "Parse - Firewall Logs - Base Parser" |
| 190 | + "@value": "Route - Firewall Logs - Route to Firewall Stream" |
167 | 191 | }, |
168 | 192 | "description": { |
169 | 193 | "@type": "string", |
170 | | - "@value": "Parse Firewall Logs" |
| 194 | + "@value": "Route firewall logs to Firewall Stream" |
171 | 195 | }, |
172 | 196 | "source": { |
173 | 197 | "@type": "string", |
174 | | - "@value": "rule \"Parse - Firewall Logs - Base Parser\"\nwhen\n true\nthen\n let x = key_value(\n value: to_string($message.message),\n trim_value_chars: '\"'\n );\n \n set_fields(x);\nend" |
| 198 | + "@value": "rule \"Route - Firewall Logs - Route to Firewall Stream\"\nwhen\n contains(\n value: to_string($message.message),\n search: \"zone=LAB\"\n )\nthen\n route_to_stream(\n name: \"Firewall Stream\",\n remove_from_default: true\n );\nend" |
175 | 199 | } |
176 | 200 | }, |
177 | 201 | "constraints": [ |
|
187 | 211 | "name": "stream_title", |
188 | 212 | "version": "1" |
189 | 213 | }, |
190 | | - "id": "d312daf9-14fc-4e0b-ad06-c5a9f1eaccbf", |
| 214 | + "id": "db9b1e9a-1fa7-4bb2-8cf2-448a3ac4fb78", |
191 | 215 | "data": { |
192 | 216 | "title": { |
193 | 217 | "@type": "string", |
194 | | - "@value": "Firewall Stream" |
| 218 | + "@value": "Default Stream" |
195 | 219 | } |
196 | 220 | }, |
197 | 221 | "constraints": [ |
|
0 commit comments