Skip to content

Instantly share code, notes, and snippets.

@ceeeekay
Created March 22, 2018 00:12
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save ceeeekay/19365fa135be6bf039ebb589c242a68a to your computer and use it in GitHub Desktop.
Save ceeeekay/19365fa135be6bf039ebb589c242a68a to your computer and use it in GitHub Desktop.
{
"_index": "auditbeat-sysadmins-2018.03.21",
"_type": "doc",
"_id": "Uwx8SmIBDsv672O_MYzg",
"_version": 1,
"_score": null,
"_source": {
"user": {
"auid": "unset",
"sgid": "0",
"fsuid": "55653",
"euid": "55653",
"name_map": {
"sgid": "root",
"fsuid": "some_user",
"euid": "some_user",
"gid": "root",
"egid": "design",
"fsgid": "design",
"uid": "some_user",
"suid": "root"
},
"gid": "0",
"egid": "6002",
"fsgid": "6002",
"suid": "0",
"uid": "55653"
},
"auditd": {
"result": "success",
"summary": {
"actor": {
"secondary": "some_user",
"primary": "unset"
},
"object": {
"primary": "2F73686172652F706174685F612F66616B652E706174682F6D6164652E796F752E6C6F6F6B",
"type": "file"
},
"how": "/usr/sbin/smbd"
},
"sequence": 343535,
"session": "unset",
"paths": [
{
"ogid": "6002",
"name": "<plain text path redacted>",
"ouid": "10333",
"mode": "042775",
"item": "0",
"dev": "fc:00",
"nametype": "PARENT",
"rdev": "00:00",
"inode": "8790128"
},
{
"ogid": "6002",
"name": "2F73686172652F706174685F612F66616B652E706174682F6D6164652E796F752E6C6F6F6B",
"ouid": "55653",
"mode": "042775",
"item": "1",
"dev": "fc:00",
"nametype": "CREATE",
"rdev": "00:00",
"inode": "8970284"
}
],
"data": {
"tty": "(none)",
"syscall": "mkdir",
"a1": "1fd",
"a3": "fffffffffffffd30",
"exit": "0",
"a2": "1fd",
"arch": "x86_64",
"a0": "7f565028af40"
}
},
"host": "fileshare",
"tags": [
"beats_input_raw_event"
],
"timezone": "Pacific/Auckland",
"@timestamp": "2018-03-21T21:34:02.482Z",
"type": "beats",
"event": {
"category": "audit-rule",
"type": "syscall",
"module": "auditd",
"action": "created-directory"
},
"kelp_ingress_time": "2018-03-21T21:34:02.482Z",
"@version": "1",
"file": {
"group": "design",
"owner": "some_user",
"device": "00:00",
"mode": "0775",
"gid": "6002",
"path": "2F73686172652F706174685F612F66616B652E706174682F6D6164652E796F752E6C6F6F6B",
"uid": "55653",
"inode": "8970284"
},
"broker": [
"kafka-filter",
"kafka-index"
],
"beat": {
"hostname": "fileshare",
"name": "fileshare",
"version": "6.2.0"
},
"client_id": "sysadmins",
"process": {
"cwd": "/share/design",
"exe": "/usr/sbin/smbd",
"name": "smbd",
"ppid": "7531",
"pid": "17712"
}
},
"fields": {
"@timestamp": [
"2018-03-21T21:34:02.482Z"
]
},
"highlight": {
"event.action": [
"@kibana-highlighted-field@created-directory@/kibana-highlighted-field@"
]
},
"sort": [
1521668042482
]
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment