Skip to content

Corelight

Overview

Corelight is an Open NDR (Network Detection and Response) platform built on Zeek and Suricata. Corelight sensors transform raw network traffic into rich, structured JSON logs (connections, DNS, HTTP, SSL/TLS, files, notices) and Suricata IDS alerts, providing network ground-truth evidence for threat detection, threat hunting and incident response. In this documentation we will explain how to collect and send Corelight Sensor logs to Sekoia.io.

Warning

Important note - This format is currently in beta. We highly value your feedback to improve its performance.

  • Vendor: Corelight
  • Supported environment: On premise (physical or virtual sensor)
  • Version compatibility: Sensor / Fleet Manager 28.3.1 or above (HTTP export), 28.4 or above (Syslog export)
  • Detection based on: Telemetry, Alert
  • Supported application or feature: Network protocol analysis, Network intrusion detection system, DNS records, Web logs, SSL/TLS certificates

Specification

Prerequisites

  • Resource:
    • A Corelight Sensor (physical or virtual) or a Corelight Fleet Manager
  • Network:
    • Outbound HTTPS traffic allowed from the sensor to your region HTTP Intake endpoint (for FRA1: https://intake.sekoia.io)
  • Permissions:
    • Administrator access to the Corelight Sensor or Fleet Manager to configure an exporter

Transport Protocol/Method

  • Direct HTTP(S) — the Corelight sensor pushes JSON events directly to Sekoia.io

Note

Corelight sends events to Sekoia.io in push mode. No connector is required for this integration.

Logs details

  • Supported functionalities: See section Overview
  • Supported type(s) of structure: JSON
  • Supported log types: conn, dns, http, ssl, files, notice, intel (Zeek Intelligence Framework) and suricata_corelight (Suricata IDS alerts)

Step-by-Step Configuration Procedure

This setup guide describes how to forward logs from a Corelight Sensor to Sekoia.io using the HTTP Exporter in push mode.

Instruction on Sekoia

Configure Your Intake

This section will guide you through creating the intake object in Sekoia, which provides a unique identifier called the "Intake key." The Intake key is essential for later configuration, as it references the Community, Entity, and Parser (Intake Format) used when receiving raw events on Sekoia.

  1. Go to the Sekoia Intake page.
  2. Click on the + New Intake button at the top right of the page.
  3. Search for your Intake by the product name in the search bar.
  4. Give it a Name and associate it with an Entity (and a Community if using multi-tenant mode).
  5. Click on Create.

Note

For more details on how to use the Intake page and to find the Intake key you just created, refer to this documentation.

Note

Corelight includes the emitting sensor name in every event (_system_name, mapped to observer.name). A single intake key can therefore be shared across a whole fleet: each event remains attributable to its source sensor, and you can filter events per sensor in Sekoia.io.

Instructions on the 3rd party solution

The following steps describe the configuration through the Corelight Fleet Manager. The equivalent settings are available directly on a standalone sensor.

Enable dynamic exporters

  1. In the Fleet Manager (or sensor UI), go to Configuration › Advanced › Advanced Configuration.
  2. Enable the setting bro.exporters.dynamic.enable.

Configure the HTTP Exporter

  1. Go to Policies › [your policy] › Export and add a new HTTP Exporter.
  2. Configure the exporter with the following values:
Field Value
URI https://intake.sekoia.io
Method POST
HTTP Headers Add a header — key: X-SEKOIAIO-INTAKE-KEY, value: the intake key generated on Sekoia.io
Compression gzip (default) — optional

Warning

The URI above works for the FRA1 region. For any other region, replace https://intake.sekoia.io with your region's HTTP Intake endpoint.

Example for USA1: https://app.usa1.sekoia.io/api/v1/intake-http

You can find your region endpoint here: https://docs.sekoia.com/getting_started/regions/

  1. (Recommended) Limit the volume by selecting the high-value log types for the SOC via Exporter Log Filters or Zeek Logs to Include: conn, dns, http, ssl, files, notice, intel, suricata_corelight.
  2. Save the policy and apply it to the sensor.

Once applied, the sensor starts pushing JSON events to Sekoia.io over HTTPS.

Enjoy your events on the Events page

Raw Events Samples

In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.

{
    "_path": "conn",
    "_system_name": "sensor",
    "uid": "CGAXp90w9BVzA9KJf",
    "ts": "2025-03-06T20:20:18.552640Z",
    "id.orig_h": "10.10.199.202",
    "id.orig_p": 59694,
    "id.resp_h": "203.0.113.125",
    "id.resp_p": 5222,
    "proto": "tcp",
    "duration": 14.604184,
    "orig_bytes": 24,
    "resp_bytes": 23,
    "conn_state": "OTH",
    "local_orig": true,
    "local_resp": false,
    "missed_bytes": 0,
    "history": "DadA",
    "enrichment_orig.role": "Developer",
    "enrichment_orig.user": "John Doe",
    "enrichment_orig.city_location": "Arlington, VA",
    "enrichment_orig.building": "Workstation Hotel",
    "community_id": "1:mKFqUrNZNgj9CY71jy3UIDILWs4="
}
{
    "_path": "dns",
    "_system_name": "sensor",
    "ts": "2025-03-06T20:20:18.552640Z",
    "uid": "CdnsTest123456",
    "id.orig_h": "10.0.35.10",
    "id.orig_p": 51000,
    "id.resp_h": "203.0.113.198",
    "id.resp_p": 53,
    "query": "abcdef0123456789.tunnel.example.com",
    "qtype_name": "NULL",
    "rcode_name": "NOERROR",
    "answers": [
        "10.0.0.1"
    ]
}
{
    "_path": "files",
    "_system_name": "sensor",
    "ts": "2025-03-06T20:23:38.591404Z",
    "uid": "CfilesTest123",
    "id.orig_h": "10.0.35.10",
    "id.resp_h": "203.0.113.198",
    "source": "HTTP",
    "md5": "0cea15a1205bcfa2b91de90fcc566d6c",
    "sha1": "caf07a8bdbd1c9ad3474fd6a31fefdcdc8964c5f",
    "sha256": "75475fb40984ddb7c83638cb1f4a79827396ba7b638e501f7aff6293adb8cf51",
    "mime_type": "application/x-dosexec",
    "seen_bytes": 539136
}
{
    "_path": "http",
    "_system_name": "sensor",
    "ts": "2025-03-06T20:20:18.552640Z",
    "uid": "CbsaT01N3Llhz2HRoa",
    "id.orig_h": "10.1.146.99",
    "id.orig_p": 51000,
    "id.resp_h": "203.0.113.131",
    "id.resp_p": 80,
    "host": "c.example.com",
    "method": "GET",
    "uri": "/r/r4.crl",
    "request_body_len": 0,
    "response_body_len": 0,
    "status_code": 304,
    "status_msg": "Not Modified",
    "user_agent": "Microsoft-CryptoAPI/10.0"
}
{
    "_path": "intel",
    "_system_name": "sensor",
    "ts": "2018-05-21T20:58:18.214197Z",
    "uid": "CintelTest12",
    "id.orig_h": "10.0.0.1",
    "id.orig_p": 55552,
    "id.resp_h": "203.0.113.94",
    "id.resp_p": 53,
    "seen.indicator": "evil.example.com",
    "seen.indicator_type": "Intel::DOMAIN",
    "seen.where": "DNS::IN_REQUEST",
    "matched": [
        "Intel::DOMAIN"
    ],
    "sources": [
        "MyList"
    ]
}
{
    "_path": "notice",
    "_system_name": "sensor",
    "ts": "2025-03-06T20:20:18.552640Z",
    "uid": "CnoticeTest1",
    "id.orig_h": "10.0.35.10",
    "id.resp_h": "192.168.100.10",
    "note": "ATTACK::Lateral_Movement",
    "msg": "SMB::FILE_WRITE to admin file share",
    "sub": "Saved a copy of the file written to SMB admin file share"
}
{
    "_path": "ssl",
    "_system_name": "sensor",
    "ts": "2025-03-06T20:26:09.490256Z",
    "uid": "Cx0XUo11iFOMEEz2Ck",
    "id.orig_h": "10.1.75.180",
    "id.orig_p": 54122,
    "id.resp_h": "203.0.113.32",
    "id.resp_p": 443,
    "version": "TLSv13",
    "cipher": "TLS_AES_256_GCM_SHA384",
    "curve": "secp384r1",
    "established": true,
    "ja3": "d76a5a80b4bb0c75ac45782b0b53da91",
    "ja3s": "15af977ce25de452b96affa2addb1036",
    "server_name": "westus-0.in.applicationinsights.azure.com",
    "validation_status": "self signed certificate"
}
{
    "_path": "suricata_corelight",
    "_system_name": "sensor.lan",
    "_write_ts": "2020-04-20T18:47:54.345633Z",
    "ts": "2020-04-20T18:47:54.339051Z",
    "uid": "CoO6zA3B7cX7KT6v07",
    "id.orig_h": "10.3.11.194",
    "id.orig_p": 50136,
    "id.resp_h": "203.0.113.98",
    "id.resp_p": 447,
    "suri_id": "SYy9Irj5XdH2",
    "service": "tls",
    "flow_id": 504752850478551,
    "tx_id": 0,
    "alert.action": "allowed",
    "alert.gid": 1,
    "alert.signature_id": 2810654,
    "alert.rev": 4,
    "alert.signature": "ETPRO POLICY Possibly Suspicious example.com SSL Cert",
    "alert.category": "A Network Trojan was detected",
    "alert.severity": 1,
    "community_id": "1:q5mSw5JpjV6tvM5dzM00Y0AQDlc="
}

Detection section

The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.

No related built-in rules was found. This message is automatically generated.

Event Categories

The following table lists the data source offered by this integration.

Data Source Description
Network protocol analysis Corelight conn, dns, http and ssl logs provide a structured overview of network activity.
Network intrusion detection system The suricata_corelight log carries Suricata IDS alerts (signature, category, severity).
DNS records The dns log records queries, query types and answers observed on the network.
Web logs The http log provides requested hosts, URIs, methods, user agents and status codes.
SSL/TLS certificates The ssl log exposes TLS version, cipher, server name and JA3/JA3S fingerprints.

In details, the following table denotes the type of events produced by this integration.

Name Values
Kind alert, enrichment
Category file, intrusion_detection, network, threat
Type connection, indicator, info

Transformed Events Samples after Ingestion

This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.

{
    "message": "{\"_path\":\"conn\",\"_system_name\":\"sensor\",\"uid\":\"CGAXp90w9BVzA9KJf\",\"ts\":\"2025-03-06T20:20:18.552640Z\",\"id.orig_h\":\"10.10.199.202\",\"id.orig_p\":59694,\"id.resp_h\":\"203.0.113.125\",\"id.resp_p\":5222,\"proto\":\"tcp\",\"duration\":14.604184,\"orig_bytes\":24,\"resp_bytes\":23,\"conn_state\":\"OTH\",\"local_orig\":true,\"local_resp\":false,\"missed_bytes\":0,\"history\":\"DadA\",\"enrichment_orig.role\":\"Developer\",\"enrichment_orig.user\":\"John Doe\",\"enrichment_orig.city_location\":\"Arlington, VA\",\"enrichment_orig.building\":\"Workstation Hotel\",\"community_id\":\"1:mKFqUrNZNgj9CY71jy3UIDILWs4=\"}",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "conn",
        "duration": 14604184000,
        "module": "corelight",
        "type": [
            "connection"
        ]
    },
    "@timestamp": "2025-03-06T20:20:18.552640Z",
    "corelight": {
        "conn": {
            "history": "DadA",
            "state": "OTH"
        },
        "uid": "CGAXp90w9BVzA9KJf"
    },
    "destination": {
        "address": "203.0.113.125",
        "bytes": 23,
        "ip": "203.0.113.125",
        "port": 5222
    },
    "network": {
        "community_id": "1:mKFqUrNZNgj9CY71jy3UIDILWs4=",
        "transport": "tcp"
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "ip": [
            "10.10.199.202",
            "203.0.113.125"
        ],
        "user": [
            "John Doe"
        ]
    },
    "source": {
        "address": "10.10.199.202",
        "bytes": 24,
        "geo": {
            "name": "Arlington, VA"
        },
        "ip": "10.10.199.202",
        "port": 59694,
        "user": {
            "name": "John Doe",
            "roles": [
                "Developer"
            ]
        }
    }
}
{
    "message": "{\"_path\":\"dns\",\"_system_name\":\"sensor\",\"ts\":\"2025-03-06T20:20:18.552640Z\",\"uid\":\"CdnsTest123456\",\"id.orig_h\":\"10.0.35.10\",\"id.orig_p\":51000,\"id.resp_h\":\"203.0.113.198\",\"id.resp_p\":53,\"query\":\"abcdef0123456789.tunnel.example.com\",\"qtype_name\":\"NULL\",\"rcode_name\":\"NOERROR\",\"answers\":[\"10.0.0.1\"]}",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "dns",
        "module": "corelight",
        "type": [
            "connection"
        ]
    },
    "@timestamp": "2025-03-06T20:20:18.552640Z",
    "corelight": {
        "uid": "CdnsTest123456"
    },
    "destination": {
        "address": "203.0.113.198",
        "ip": "203.0.113.198",
        "port": 53
    },
    "dns": {
        "answers": [
            {
                "data": "10.0.0.1"
            }
        ],
        "question": {
            "name": "abcdef0123456789.tunnel.example.com",
            "registered_domain": "example.com",
            "subdomain": "abcdef0123456789.tunnel",
            "top_level_domain": "com",
            "type": "NULL"
        },
        "response_code": "NOERROR"
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "hosts": [
            "abcdef0123456789.tunnel.example.com"
        ],
        "ip": [
            "10.0.35.10",
            "203.0.113.198"
        ]
    },
    "source": {
        "address": "10.0.35.10",
        "ip": "10.0.35.10",
        "port": 51000
    }
}
{
    "message": "{\"_path\":\"files\",\"_system_name\":\"sensor\",\"ts\":\"2025-03-06T20:23:38.591404Z\",\"uid\":\"CfilesTest123\",\"id.orig_h\":\"10.0.35.10\",\"id.resp_h\":\"203.0.113.198\",\"source\":\"HTTP\",\"md5\":\"0cea15a1205bcfa2b91de90fcc566d6c\",\"sha1\":\"caf07a8bdbd1c9ad3474fd6a31fefdcdc8964c5f\",\"sha256\":\"75475fb40984ddb7c83638cb1f4a79827396ba7b638e501f7aff6293adb8cf51\",\"mime_type\":\"application/x-dosexec\",\"seen_bytes\":539136}",
    "event": {
        "category": [
            "file"
        ],
        "dataset": "files",
        "module": "corelight",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-03-06T20:23:38.591404Z",
    "corelight": {
        "files": {
            "source": "HTTP"
        }
    },
    "destination": {
        "address": "203.0.113.198",
        "ip": "203.0.113.198"
    },
    "file": {
        "hash": {
            "md5": "0cea15a1205bcfa2b91de90fcc566d6c",
            "sha1": "caf07a8bdbd1c9ad3474fd6a31fefdcdc8964c5f",
            "sha256": "75475fb40984ddb7c83638cb1f4a79827396ba7b638e501f7aff6293adb8cf51"
        },
        "mime_type": "application/x-dosexec",
        "size": 539136
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "hash": [
            "0cea15a1205bcfa2b91de90fcc566d6c",
            "75475fb40984ddb7c83638cb1f4a79827396ba7b638e501f7aff6293adb8cf51",
            "caf07a8bdbd1c9ad3474fd6a31fefdcdc8964c5f"
        ],
        "ip": [
            "10.0.35.10",
            "203.0.113.198"
        ]
    },
    "source": {
        "address": "10.0.35.10",
        "ip": "10.0.35.10"
    }
}
{
    "message": "{\"_path\":\"http\",\"_system_name\":\"sensor\",\"ts\":\"2025-03-06T20:20:18.552640Z\",\"uid\":\"CbsaT01N3Llhz2HRoa\",\"id.orig_h\":\"10.1.146.99\",\"id.orig_p\":51000,\"id.resp_h\":\"203.0.113.131\",\"id.resp_p\":80,\"host\":\"c.example.com\",\"method\":\"GET\",\"uri\":\"/r/r4.crl\",\"request_body_len\":0,\"response_body_len\":0,\"status_code\":304,\"status_msg\":\"Not Modified\",\"user_agent\":\"Microsoft-CryptoAPI/10.0\"}",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "http",
        "module": "corelight",
        "type": [
            "connection"
        ]
    },
    "@timestamp": "2025-03-06T20:20:18.552640Z",
    "corelight": {
        "uid": "CbsaT01N3Llhz2HRoa"
    },
    "destination": {
        "address": "203.0.113.131",
        "ip": "203.0.113.131",
        "port": 80
    },
    "http": {
        "request": {
            "body": {
                "bytes": 0
            },
            "method": "GET"
        },
        "response": {
            "body": {
                "bytes": 0
            },
            "status_code": 304
        }
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "hosts": [
            "c.example.com"
        ],
        "ip": [
            "10.1.146.99",
            "203.0.113.131"
        ]
    },
    "source": {
        "address": "10.1.146.99",
        "ip": "10.1.146.99",
        "port": 51000
    },
    "url": {
        "domain": "c.example.com",
        "path": "/r/r4.crl",
        "registered_domain": "example.com",
        "subdomain": "c",
        "top_level_domain": "com"
    },
    "user_agent": {
        "device": {
            "name": "Other"
        },
        "name": "Microsoft-CryptoAPI",
        "original": "Microsoft-CryptoAPI/10.0",
        "os": {
            "name": "Other"
        },
        "version": "10.0"
    }
}
{
    "message": "{\"_path\":\"intel\",\"_system_name\":\"sensor\",\"ts\":\"2018-05-21T20:58:18.214197Z\",\"uid\":\"CintelTest12\",\"id.orig_h\":\"10.0.0.1\",\"id.orig_p\":55552,\"id.resp_h\":\"203.0.113.94\",\"id.resp_p\":53,\"seen.indicator\":\"evil.example.com\",\"seen.indicator_type\":\"Intel::DOMAIN\",\"seen.where\":\"DNS::IN_REQUEST\",\"matched\":[\"Intel::DOMAIN\"],\"sources\":[\"MyList\"]}",
    "event": {
        "category": [
            "threat"
        ],
        "dataset": "intel",
        "kind": "enrichment",
        "module": "corelight",
        "type": [
            "indicator"
        ]
    },
    "@timestamp": "2018-05-21T20:58:18.214197Z",
    "corelight": {
        "intel": {
            "sources": [
                "MyList"
            ],
            "where": "DNS::IN_REQUEST"
        },
        "uid": "CintelTest12"
    },
    "destination": {
        "address": "203.0.113.94",
        "ip": "203.0.113.94",
        "port": 53
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "ip": [
            "10.0.0.1",
            "203.0.113.94"
        ]
    },
    "source": {
        "address": "10.0.0.1",
        "ip": "10.0.0.1",
        "port": 55552
    },
    "threat": {
        "indicator": {
            "name": "evil.example.com",
            "type": "Intel::DOMAIN"
        }
    }
}
{
    "message": "{\"_path\":\"notice\",\"_system_name\":\"sensor\",\"ts\":\"2025-03-06T20:20:18.552640Z\",\"uid\":\"CnoticeTest1\",\"id.orig_h\":\"10.0.35.10\",\"id.resp_h\":\"192.168.100.10\",\"note\":\"ATTACK::Lateral_Movement\",\"msg\":\"SMB::FILE_WRITE to admin file share\",\"sub\":\"Saved a copy of the file written to SMB admin file share\"}",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "notice",
        "kind": "alert",
        "module": "corelight",
        "type": [
            "info"
        ]
    },
    "@timestamp": "2025-03-06T20:20:18.552640Z",
    "corelight": {
        "notice": {
            "message": "SMB::FILE_WRITE to admin file share",
            "sub": "Saved a copy of the file written to SMB admin file share"
        },
        "uid": "CnoticeTest1"
    },
    "destination": {
        "address": "192.168.100.10",
        "ip": "192.168.100.10"
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "ip": [
            "10.0.35.10",
            "192.168.100.10"
        ]
    },
    "rule": {
        "name": "ATTACK::Lateral_Movement"
    },
    "source": {
        "address": "10.0.35.10",
        "ip": "10.0.35.10"
    }
}
{
    "message": "{\"_path\": \"ssl\", \"_system_name\": \"sensor\", \"ts\": \"2025-03-06T20:26:09.490256Z\", \"uid\": \"Cx0XUo11iFOMEEz2Ck\", \"id.orig_h\": \"10.1.75.180\", \"id.orig_p\": 54122, \"id.resp_h\": \"203.0.113.32\", \"id.resp_p\": 443, \"version\": \"TLSv13\", \"cipher\": \"TLS_AES_256_GCM_SHA384\", \"curve\": \"secp384r1\", \"established\": true, \"ja3\": \"d76a5a80b4bb0c75ac45782b0b53da91\", \"ja3s\": \"15af977ce25de452b96affa2addb1036\", \"server_name\": \"westus-0.in.applicationinsights.azure.com\", \"validation_status\": \"self signed certificate\"}",
    "event": {
        "category": [
            "network"
        ],
        "dataset": "ssl",
        "module": "corelight",
        "type": [
            "connection"
        ]
    },
    "@timestamp": "2025-03-06T20:26:09.490256Z",
    "corelight": {
        "ssl": {
            "validation_status": "self signed certificate"
        },
        "uid": "Cx0XUo11iFOMEEz2Ck"
    },
    "destination": {
        "address": "203.0.113.32",
        "ip": "203.0.113.32",
        "port": 443
    },
    "observer": {
        "name": "sensor",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "ip": [
            "10.1.75.180",
            "203.0.113.32"
        ]
    },
    "source": {
        "address": "10.1.75.180",
        "ip": "10.1.75.180",
        "port": 54122
    },
    "tls": {
        "cipher": "TLS_AES_256_GCM_SHA384",
        "client": {
            "ja3": "d76a5a80b4bb0c75ac45782b0b53da91",
            "server_name": "westus-0.in.applicationinsights.azure.com"
        },
        "curve": "secp384r1",
        "established": true,
        "server": {
            "ja3s": "15af977ce25de452b96affa2addb1036"
        },
        "version": "TLSv13"
    }
}
{
    "message": "{\"_path\":\"suricata_corelight\",\"_system_name\":\"sensor.lan\",\"_write_ts\":\"2020-04-20T18:47:54.345633Z\",\"ts\":\"2020-04-20T18:47:54.339051Z\",\"uid\":\"CoO6zA3B7cX7KT6v07\",\"id.orig_h\":\"10.3.11.194\",\"id.orig_p\":50136,\"id.resp_h\":\"203.0.113.98\",\"id.resp_p\":447,\"suri_id\":\"SYy9Irj5XdH2\",\"service\":\"tls\",\"flow_id\":504752850478551,\"tx_id\":0,\"alert.action\":\"allowed\",\"alert.gid\":1,\"alert.signature_id\":2810654,\"alert.rev\":4,\"alert.signature\":\"ETPRO POLICY Possibly Suspicious example.com SSL Cert\",\"alert.category\":\"A Network Trojan was detected\",\"alert.severity\":1,\"community_id\":\"1:q5mSw5JpjV6tvM5dzM00Y0AQDlc=\"}",
    "event": {
        "action": "allowed",
        "category": [
            "intrusion_detection"
        ],
        "dataset": "suricata_corelight",
        "kind": "alert",
        "module": "corelight",
        "severity": 1,
        "type": [
            "info"
        ]
    },
    "@timestamp": "2020-04-20T18:47:54.339051Z",
    "action": {
        "name": "allowed"
    },
    "corelight": {
        "uid": "CoO6zA3B7cX7KT6v07"
    },
    "destination": {
        "address": "203.0.113.98",
        "ip": "203.0.113.98",
        "port": 447
    },
    "network": {
        "community_id": "1:q5mSw5JpjV6tvM5dzM00Y0AQDlc=",
        "protocol": "tls"
    },
    "observer": {
        "name": "sensor.lan",
        "product": "Open NDR",
        "type": "ndr",
        "vendor": "Corelight"
    },
    "related": {
        "ip": [
            "10.3.11.194",
            "203.0.113.98"
        ]
    },
    "rule": {
        "category": "A Network Trojan was detected",
        "id": "2810654",
        "name": "ETPRO POLICY Possibly Suspicious example.com SSL Cert"
    },
    "source": {
        "address": "10.3.11.194",
        "ip": "10.3.11.194",
        "port": 50136
    }
}

Extracted Fields

The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.

Name Type Description
@timestamp date Date/time when the event originated.
corelight.conn.history keyword Zeek connection history string (sequence of connection state flags).
corelight.conn.state keyword Zeek connection state (conn_state), e.g. SF, OTH, S1.
corelight.files.source keyword Protocol over which the file was seen (e.g. HTTP, SMTP, FTP).
corelight.intel.sources keyword Threat intelligence sources that matched in the Zeek Intelligence Framework.
corelight.intel.where keyword Location in the connection where the intel indicator was seen (seen.where).
corelight.notice.message keyword Human-readable Zeek notice message (msg field), e.g. "SMB::FILE_WRITE to admin file share".
corelight.notice.sub keyword Sub-message of a Zeek notice (sub field).
corelight.ssl.validation_status keyword TLS certificate chain validation status (e.g. ok, self signed certificate, unable to get local issuer certificate).
corelight.uid keyword Zeek connection unique identifier (uid), used to pivot across logs.
destination.bytes long Bytes sent from the destination to the source.
destination.ip ip IP address of the destination.
destination.port long Port of the destination.
dns.answers object Array of DNS answers.
dns.question.name keyword The name being queried.
dns.question.type keyword The type of record being queried.
dns.response_code keyword The DNS response code.
event.action keyword The action captured by the event.
event.category keyword Event category. The second categorization field in the hierarchy.
event.dataset keyword Name of the dataset.
event.duration long Duration of the event in nanoseconds.
event.kind keyword The kind of the event. The highest categorization field in the hierarchy.
event.module keyword Name of the module this data is coming from.
event.severity long Numeric severity of the event.
event.type keyword Event type. The third categorization field in the hierarchy.
file.hash.md5 keyword MD5 hash.
file.hash.sha1 keyword SHA1 hash.
file.hash.sha256 keyword SHA256 hash.
file.mime_type keyword Media type of file, document, or arrangement of bytes.
file.size long File size in bytes.
http.request.body.bytes long Size in bytes of the request body.
http.request.method keyword HTTP request method.
http.response.body.bytes long Size in bytes of the response body.
http.response.status_code long HTTP response status code.
network.community_id keyword A hash of source and destination IPs and ports.
network.protocol keyword Application protocol name.
network.transport keyword Protocol Name corresponding to the field iana_number.
observer.name keyword Custom name of the observer.
observer.product keyword The product name of the observer.
observer.type keyword The type of the observer the data is coming from.
observer.vendor keyword Vendor name of the observer.
rule.category keyword Rule category
rule.id keyword Rule ID
rule.name keyword Rule name
source.bytes long Bytes sent from the source to the destination.
source.geo.name keyword User-defined description of a location.
source.ip ip IP address of the source.
source.port long Port of the source.
source.user.name keyword Short name or login of the user.
source.user.roles keyword Array of user roles at the time of the event.
threat.indicator.type keyword Type of indicator
tls.cipher keyword String indicating the cipher used during the current connection.
tls.client.ja3 keyword A hash that identifies clients based on how they perform an SSL/TLS handshake.
tls.client.server_name keyword Hostname the client is trying to connect to. Also called the SNI.
tls.curve keyword String indicating the curve used for the given cipher, when applicable.
tls.established boolean Boolean flag indicating if the TLS negotiation was successful and transitioned to an encrypted tunnel.
tls.server.ja3s keyword A hash that identifies servers based on how they perform an SSL/TLS handshake.
tls.version keyword Numeric part of the version parsed from the original string.
url.domain keyword Domain of the url.
url.path wildcard Path of the request, such as "/search".
user_agent.original keyword Unparsed user_agent string.

For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.

Further Readings