es 新建索引

新建索引后
dac_db_test/test/_mappings post

{
“test”: {
“properties”: {
“server_name”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“suspicious_url”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“che_result_static”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“src_ip_city”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“user_name”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“file_direct”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“threat_score”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“dst_ip”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“src_ip”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“dst_ip_city”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“log_type”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“protocol”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“file_type”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“categories”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“suspicious_addr”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“suspicious_domain”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“file_name”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“end_time”: {
“type”: “long”
},
“dst_ip_country”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“file_size”: {
“type”: “long”
},
“src_port”: {
“type”: “long”
},
“start_time”: {
“type”: “long”
},
“dst_port”: {
“type”: “long”
},
“organizations”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“callback”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“event_level”: {
“type”: “long”
},
“dev_ip”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“src_ip_country”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“family”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“ioc”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“match_tag”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
},
“md5”: {
“type”: “keyword”,
“fields”: {
“keyword”: {
“ignore_above”: 256,
“type”: “keyword”
}
}
}
}
}
}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值