You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/reference/auditbeat/configuring-ssl-logstash.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -65,10 +65,10 @@ To use SSL mutual authentication:
65
65
Before running Auditbeat, you should validate the Logstash server’s certificate. You can use `curl` to validate the certificate even though the protocol used to communicate with Logstash is not based on HTTP. For example:
If the test is successful, you’ll receive an empty response error:
71
+
If the test is successful, you’ll receive an empty response error. Here's an example response assuming the `HOST_URL` was `logs.example.com` and `PORT` was `5044`:
Copy file name to clipboardExpand all lines: docs/reference/auditbeat/exported-fields-ecs.md
+8-8Lines changed: 8 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -317,7 +317,7 @@ Client / server representations can add semantic context to an exchange, which i
317
317
318
318
319
319
**`client.subdomain`**
320
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
320
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
321
321
322
322
type: keyword
323
323
@@ -1044,7 +1044,7 @@ Destination fields are usually populated in conjunction with source fields. The
1044
1044
1045
1045
1046
1046
**`destination.subdomain`**
1047
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
1047
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
1048
1048
1049
1049
type: keyword
1050
1050
@@ -5510,7 +5510,7 @@ Client / server representations can add semantic context to an exchange, which i
5510
5510
5511
5511
5512
5512
**`server.subdomain`**
5513
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
5513
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
5514
5514
5515
5515
type: keyword
5516
5516
@@ -6006,7 +6006,7 @@ Source fields are usually populated in conjunction with destination fields. The
6006
6006
6007
6007
6008
6008
**`source.subdomain`**
6009
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
6009
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
6010
6010
6011
6011
type: keyword
6012
6012
@@ -7195,7 +7195,7 @@ Field is not indexed.
7195
7195
7196
7196
7197
7197
**`threat.enrichments.indicator.url.subdomain`**
7198
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
7198
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
7199
7199
7200
7200
type: keyword
7201
7201
@@ -7413,7 +7413,7 @@ Field is not indexed.
7413
7413
7414
7414
type: keyword
7415
7415
7416
-
example: bad-domain.com
7416
+
example: example.com
7417
7417
7418
7418
7419
7419
**`threat.enrichments.matched.field`**
@@ -8569,7 +8569,7 @@ Field is not indexed.
8569
8569
8570
8570
8571
8571
**`threat.indicator.url.subdomain`**
8572
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
8572
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
8573
8573
8574
8574
type: keyword
8575
8575
@@ -9645,7 +9645,7 @@ URL fields provide support for complete or partial URLs, and supports the breaki
9645
9645
9646
9646
9647
9647
**`url.subdomain`**
9648
-
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.mydomain.co.uk" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
9648
+
: The subdomain portion of a fully qualified domain name includes all of the names except the host name under the registered_domain. In a partially qualified domain, or if the the qualification level of the full name cannot be determined, subdomain contains all of the names below the registered domain. For example the subdomain portion of "www.east.example.com" is "east". If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com", the subdomain field should contain "sub2.sub1", with no trailing period.
Copy file name to clipboardExpand all lines: docs/reference/filebeat/configuring-ssl-logstash.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,7 @@ To use SSL mutual authentication:
26
26
27
27
```yaml
28
28
output.logstash:
29
-
hosts: ["logs.mycompany.com:5044"]
29
+
hosts: ["<HOST_URL>:<PORT>"]
30
30
ssl.certificate_authorities: ["/etc/ca.crt"]
31
31
ssl.certificate: "/etc/client.crt"
32
32
ssl.key: "/etc/client.key"
@@ -65,25 +65,25 @@ To use SSL mutual authentication:
65
65
Before running Filebeat, you should validate the Logstash server’s certificate. You can use `curl` to validate the certificate even though the protocol used to communicate with Logstash is not based on HTTP. For example:
If the test is successful, you’ll receive an empty response error:
71
+
If the test is successful, you’ll receive an empty response error. Here's an example response assuming the `HOST_URL` was `logs.example.com` and `PORT` was `5044`:
72
72
73
73
```shell
74
-
* Rebuilt URL to: https://logs.mycompany.com:5044/
74
+
* Rebuilt URL to: https://logs.example.com:5044/
75
75
* Trying 192.168.99.100...
76
-
* Connected to logs.mycompany.com (192.168.99.100) port 5044 (#0)
76
+
* Connected to logs.example.com (192.168.99.100) port 5044 (#0)
77
77
* TLS 1.2 connection using TLS_DHE_RSA_WITH_AES_256_CBC_SHA
78
-
* Server certificate: logs.mycompany.com
79
-
* Server certificate: mycompany.com
78
+
* Server certificate: logs.example.com
79
+
* Server certificate: example.com
80
80
> GET / HTTP/1.1
81
-
> Host: logs.mycompany.com:5044
81
+
> Host: logs.example.com:5044
82
82
> User-Agent: curl/7.43.0
83
83
> Accept: */*
84
84
>
85
85
* Empty reply from server
86
-
* Connection #0 to host logs.mycompany.com left intact
86
+
* Connection #0 to host logs.example.com left intact
87
87
curl: (52) Empty reply from server
88
88
```
89
89
@@ -93,7 +93,7 @@ The following example uses the IP address rather than the hostname to validate t
Validation for this test fails because the certificate is not valid for the specified IP address. It’s only valid for the `logs.mycompany.com`, the hostname that appears in the Subject field of the certificate.
96
+
Validation for this test fails because the certificate is not valid for the specified IP address. It’s only valid for the `logs.example.com`, the hostname that appears in the Subject field of the certificate.
Copy file name to clipboardExpand all lines: docs/reference/filebeat/exported-fields-cef.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -932,7 +932,7 @@ Collection of key-value pairs carried in the CEF extension field.
932
932
933
933
934
934
**`cef.extensions.sourceHostName`**
935
-
: Identifies the source that an event refers to in an IP network. The format should be a fully qualified domain name (FQDN) associated with the source node, when a mode is available. Examples: 'host' or 'host.domain.com'.
935
+
: Identifies the source that an event refers to in an IP network. The format should be a fully qualified domain name (FQDN) associated with the source node, when a mode is available. Examples: 'host' or 'host.example.com'.
0 commit comments