diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 81f6bbe9182..9921f76167a 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -20477,14 +20477,7 @@ Module for handling Cisco network device logs. [float] -=== cisco - -Fields from Cisco logs. - - - -[float] -=== asa +=== cisco.asa Fields for Cisco ASA Firewall. @@ -20693,7 +20686,7 @@ type: keyword -- [float] -=== ftd +=== cisco.ftd Fields for Cisco Firepower Threat Defense Firewall. @@ -20911,7 +20904,7 @@ type: keyword -- [float] -=== ios +=== cisco.ios Fields for Cisco IOS logs. @@ -20939,7 +20932,7 @@ example: SEC -- -*`cisco.network.interface.name`*:: +*`network.interface.name`*:: + -- Name of the network interface where the traffic has been observed. @@ -20951,7 +20944,7 @@ type: keyword -*`cisco.rsa.internal.msg`*:: +*`rsa.internal.msg`*:: + -- This key is used to capture the raw message that comes into the Log Decoder @@ -20960,21 +20953,21 @@ type: keyword -- -*`cisco.rsa.internal.messageid`*:: +*`rsa.internal.messageid`*:: + -- type: keyword -- -*`cisco.rsa.internal.event_desc`*:: +*`rsa.internal.event_desc`*:: + -- type: keyword -- -*`cisco.rsa.internal.message`*:: +*`rsa.internal.message`*:: + -- This key captures the contents of instant messages @@ -20983,7 +20976,7 @@ type: keyword -- -*`cisco.rsa.internal.time`*:: +*`rsa.internal.time`*:: + -- This is the time at which a session hits a NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness. @@ -20992,7 +20985,7 @@ type: date -- -*`cisco.rsa.internal.level`*:: +*`rsa.internal.level`*:: + -- Deprecated key defined only in table map. @@ -21001,7 +20994,7 @@ type: long -- -*`cisco.rsa.internal.msg_id`*:: +*`rsa.internal.msg_id`*:: + -- This is the Message ID1 value that identifies the exact log parser definition which parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21010,7 +21003,7 @@ type: keyword -- -*`cisco.rsa.internal.msg_vid`*:: +*`rsa.internal.msg_vid`*:: + -- This is the Message ID2 value that identifies the exact log parser definition which parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21019,7 +21012,7 @@ type: keyword -- -*`cisco.rsa.internal.data`*:: +*`rsa.internal.data`*:: + -- Deprecated key defined only in table map. @@ -21028,7 +21021,7 @@ type: keyword -- -*`cisco.rsa.internal.obj_server`*:: +*`rsa.internal.obj_server`*:: + -- Deprecated key defined only in table map. @@ -21037,7 +21030,7 @@ type: keyword -- -*`cisco.rsa.internal.obj_val`*:: +*`rsa.internal.obj_val`*:: + -- Deprecated key defined only in table map. @@ -21046,7 +21039,7 @@ type: keyword -- -*`cisco.rsa.internal.resource`*:: +*`rsa.internal.resource`*:: + -- Deprecated key defined only in table map. @@ -21055,7 +21048,7 @@ type: keyword -- -*`cisco.rsa.internal.obj_id`*:: +*`rsa.internal.obj_id`*:: + -- Deprecated key defined only in table map. @@ -21064,7 +21057,7 @@ type: keyword -- -*`cisco.rsa.internal.statement`*:: +*`rsa.internal.statement`*:: + -- Deprecated key defined only in table map. @@ -21073,7 +21066,7 @@ type: keyword -- -*`cisco.rsa.internal.audit_class`*:: +*`rsa.internal.audit_class`*:: + -- Deprecated key defined only in table map. @@ -21082,7 +21075,7 @@ type: keyword -- -*`cisco.rsa.internal.entry`*:: +*`rsa.internal.entry`*:: + -- Deprecated key defined only in table map. @@ -21091,7 +21084,7 @@ type: keyword -- -*`cisco.rsa.internal.hcode`*:: +*`rsa.internal.hcode`*:: + -- Deprecated key defined only in table map. @@ -21100,7 +21093,7 @@ type: keyword -- -*`cisco.rsa.internal.inode`*:: +*`rsa.internal.inode`*:: + -- Deprecated key defined only in table map. @@ -21109,7 +21102,7 @@ type: long -- -*`cisco.rsa.internal.resource_class`*:: +*`rsa.internal.resource_class`*:: + -- Deprecated key defined only in table map. @@ -21118,7 +21111,7 @@ type: keyword -- -*`cisco.rsa.internal.dead`*:: +*`rsa.internal.dead`*:: + -- Deprecated key defined only in table map. @@ -21127,7 +21120,7 @@ type: long -- -*`cisco.rsa.internal.feed_desc`*:: +*`rsa.internal.feed_desc`*:: + -- This is used to capture the description of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21136,7 +21129,7 @@ type: keyword -- -*`cisco.rsa.internal.feed_name`*:: +*`rsa.internal.feed_name`*:: + -- This is used to capture the name of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21145,7 +21138,7 @@ type: keyword -- -*`cisco.rsa.internal.cid`*:: +*`rsa.internal.cid`*:: + -- This is the unique identifier used to identify a NetWitness Concentrator. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21154,7 +21147,7 @@ type: keyword -- -*`cisco.rsa.internal.device_class`*:: +*`rsa.internal.device_class`*:: + -- This is the Classification of the Log Event Source under a predefined fixed set of Event Source Classifications. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21163,7 +21156,7 @@ type: keyword -- -*`cisco.rsa.internal.device_group`*:: +*`rsa.internal.device_group`*:: + -- This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21172,7 +21165,7 @@ type: keyword -- -*`cisco.rsa.internal.device_host`*:: +*`rsa.internal.device_host`*:: + -- This is the Hostname of the log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21181,7 +21174,7 @@ type: keyword -- -*`cisco.rsa.internal.device_ip`*:: +*`rsa.internal.device_ip`*:: + -- This is the IPv4 address of the Log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21190,7 +21183,7 @@ type: ip -- -*`cisco.rsa.internal.device_ipv6`*:: +*`rsa.internal.device_ipv6`*:: + -- This is the IPv6 address of the Log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21199,7 +21192,7 @@ type: ip -- -*`cisco.rsa.internal.device_type`*:: +*`rsa.internal.device_type`*:: + -- This is the name of the log parser which parsed a given session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21208,7 +21201,7 @@ type: keyword -- -*`cisco.rsa.internal.device_type_id`*:: +*`rsa.internal.device_type_id`*:: + -- Deprecated key defined only in table map. @@ -21217,7 +21210,7 @@ type: long -- -*`cisco.rsa.internal.did`*:: +*`rsa.internal.did`*:: + -- This is the unique identifier used to identify a NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21226,7 +21219,7 @@ type: keyword -- -*`cisco.rsa.internal.entropy_req`*:: +*`rsa.internal.entropy_req`*:: + -- This key is only used by the Entropy Parser, the Meta Type can be either UInt16 or Float32 based on the configuration @@ -21235,7 +21228,7 @@ type: long -- -*`cisco.rsa.internal.entropy_res`*:: +*`rsa.internal.entropy_res`*:: + -- This key is only used by the Entropy Parser, the Meta Type can be either UInt16 or Float32 based on the configuration @@ -21244,7 +21237,7 @@ type: long -- -*`cisco.rsa.internal.event_name`*:: +*`rsa.internal.event_name`*:: + -- Deprecated key defined only in table map. @@ -21253,7 +21246,7 @@ type: keyword -- -*`cisco.rsa.internal.feed_category`*:: +*`rsa.internal.feed_category`*:: + -- This is used to capture the category of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21262,7 +21255,7 @@ type: keyword -- -*`cisco.rsa.internal.forward_ip`*:: +*`rsa.internal.forward_ip`*:: + -- This key should be used to capture the IPV4 address of a relay system which forwarded the events from the original system to NetWitness. @@ -21271,7 +21264,7 @@ type: ip -- -*`cisco.rsa.internal.forward_ipv6`*:: +*`rsa.internal.forward_ipv6`*:: + -- This key is used to capture the IPV6 address of a relay system which forwarded the events from the original system to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21280,7 +21273,7 @@ type: ip -- -*`cisco.rsa.internal.header_id`*:: +*`rsa.internal.header_id`*:: + -- This is the Header ID value that identifies the exact log parser header definition that parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21289,7 +21282,7 @@ type: keyword -- -*`cisco.rsa.internal.lc_cid`*:: +*`rsa.internal.lc_cid`*:: + -- This is a unique Identifier of a Log Collector. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21298,7 +21291,7 @@ type: keyword -- -*`cisco.rsa.internal.lc_ctime`*:: +*`rsa.internal.lc_ctime`*:: + -- This is the time at which a log is collected in a NetWitness Log Collector. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21307,7 +21300,7 @@ type: date -- -*`cisco.rsa.internal.mcb_req`*:: +*`rsa.internal.mcb_req`*:: + -- This key is only used by the Entropy Parser, the most common byte request is simply which byte for each side (0 thru 255) was seen the most @@ -21316,7 +21309,7 @@ type: long -- -*`cisco.rsa.internal.mcb_res`*:: +*`rsa.internal.mcb_res`*:: + -- This key is only used by the Entropy Parser, the most common byte response is simply which byte for each side (0 thru 255) was seen the most @@ -21325,7 +21318,7 @@ type: long -- -*`cisco.rsa.internal.mcbc_req`*:: +*`rsa.internal.mcbc_req`*:: + -- This key is only used by the Entropy Parser, the most common byte count is the number of times the most common byte (above) was seen in the session streams @@ -21334,7 +21327,7 @@ type: long -- -*`cisco.rsa.internal.mcbc_res`*:: +*`rsa.internal.mcbc_res`*:: + -- This key is only used by the Entropy Parser, the most common byte count is the number of times the most common byte (above) was seen in the session streams @@ -21343,7 +21336,7 @@ type: long -- -*`cisco.rsa.internal.medium`*:: +*`rsa.internal.medium`*:: + -- This key is used to identify if it’s a log/packet session or Layer 2 Encapsulation Type. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness. 32 = log, 33 = correlation session, < 32 is packet session @@ -21352,7 +21345,7 @@ type: long -- -*`cisco.rsa.internal.node_name`*:: +*`rsa.internal.node_name`*:: + -- Deprecated key defined only in table map. @@ -21361,7 +21354,7 @@ type: keyword -- -*`cisco.rsa.internal.nwe_callback_id`*:: +*`rsa.internal.nwe_callback_id`*:: + -- This key denotes that event is endpoint related @@ -21370,7 +21363,7 @@ type: keyword -- -*`cisco.rsa.internal.parse_error`*:: +*`rsa.internal.parse_error`*:: + -- This is a special key that stores any Meta key validation error found while parsing a log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21379,7 +21372,7 @@ type: keyword -- -*`cisco.rsa.internal.payload_req`*:: +*`rsa.internal.payload_req`*:: + -- This key is only used by the Entropy Parser, the payload size metrics are the payload sizes of each session side at the time of parsing. However, in order to keep @@ -21388,7 +21381,7 @@ type: long -- -*`cisco.rsa.internal.payload_res`*:: +*`rsa.internal.payload_res`*:: + -- This key is only used by the Entropy Parser, the payload size metrics are the payload sizes of each session side at the time of parsing. However, in order to keep @@ -21397,7 +21390,7 @@ type: long -- -*`cisco.rsa.internal.process_vid_dst`*:: +*`rsa.internal.process_vid_dst`*:: + -- Endpoint generates and uses a unique virtual ID to identify any similar group of process. This ID represents the target process. @@ -21406,7 +21399,7 @@ type: keyword -- -*`cisco.rsa.internal.process_vid_src`*:: +*`rsa.internal.process_vid_src`*:: + -- Endpoint generates and uses a unique virtual ID to identify any similar group of process. This ID represents the source process. @@ -21415,7 +21408,7 @@ type: keyword -- -*`cisco.rsa.internal.rid`*:: +*`rsa.internal.rid`*:: + -- This is a special ID of the Remote Session created by NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21424,7 +21417,7 @@ type: long -- -*`cisco.rsa.internal.session_split`*:: +*`rsa.internal.session_split`*:: + -- This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21433,7 +21426,7 @@ type: keyword -- -*`cisco.rsa.internal.site`*:: +*`rsa.internal.site`*:: + -- Deprecated key defined only in table map. @@ -21442,7 +21435,7 @@ type: keyword -- -*`cisco.rsa.internal.size`*:: +*`rsa.internal.size`*:: + -- This is the size of the session as seen by the NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21451,7 +21444,7 @@ type: long -- -*`cisco.rsa.internal.sourcefile`*:: +*`rsa.internal.sourcefile`*:: + -- This is the name of the log file or PCAPs that can be imported into NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -21460,7 +21453,7 @@ type: keyword -- -*`cisco.rsa.internal.ubc_req`*:: +*`rsa.internal.ubc_req`*:: + -- This key is only used by the Entropy Parser, Unique byte count is the number of unique bytes seen in each stream. 256 would mean all byte values of 0 thru 255 were seen at least once @@ -21469,7 +21462,7 @@ type: long -- -*`cisco.rsa.internal.ubc_res`*:: +*`rsa.internal.ubc_res`*:: + -- This key is only used by the Entropy Parser, Unique byte count is the number of unique bytes seen in each stream. 256 would mean all byte values of 0 thru 255 were seen at least once @@ -21478,7 +21471,7 @@ type: long -- -*`cisco.rsa.internal.word`*:: +*`rsa.internal.word`*:: + -- This is used by the Word Parsing technology to capture the first 5 character of every word in an unparsed log @@ -21488,7 +21481,7 @@ type: keyword -- -*`cisco.rsa.time.event_time`*:: +*`rsa.time.event_time`*:: + -- This key is used to capture the time mentioned in a raw session that represents the actual time an event occured in a standard normalized form @@ -21497,7 +21490,7 @@ type: date -- -*`cisco.rsa.time.duration_time`*:: +*`rsa.time.duration_time`*:: + -- This key is used to capture the normalized duration/lifetime in seconds. @@ -21506,7 +21499,7 @@ type: double -- -*`cisco.rsa.time.event_time_str`*:: +*`rsa.time.event_time_str`*:: + -- This key is used to capture the incomplete time mentioned in a session as a string @@ -21515,7 +21508,7 @@ type: keyword -- -*`cisco.rsa.time.starttime`*:: +*`rsa.time.starttime`*:: + -- This key is used to capture the Start time mentioned in a session in a standard form @@ -21524,21 +21517,21 @@ type: date -- -*`cisco.rsa.time.month`*:: +*`rsa.time.month`*:: + -- type: keyword -- -*`cisco.rsa.time.day`*:: +*`rsa.time.day`*:: + -- type: keyword -- -*`cisco.rsa.time.endtime`*:: +*`rsa.time.endtime`*:: + -- This key is used to capture the End time mentioned in a session in a standard form @@ -21547,7 +21540,7 @@ type: date -- -*`cisco.rsa.time.timezone`*:: +*`rsa.time.timezone`*:: + -- This key is used to capture the timezone of the Event Time @@ -21556,7 +21549,7 @@ type: keyword -- -*`cisco.rsa.time.duration_str`*:: +*`rsa.time.duration_str`*:: + -- A text string version of the duration @@ -21565,21 +21558,21 @@ type: keyword -- -*`cisco.rsa.time.date`*:: +*`rsa.time.date`*:: + -- type: keyword -- -*`cisco.rsa.time.year`*:: +*`rsa.time.year`*:: + -- type: keyword -- -*`cisco.rsa.time.recorded_time`*:: +*`rsa.time.recorded_time`*:: + -- The event time as recorded by the system the event is collected from. The usage scenario is a multi-tier application where the management layer of the system records it's own timestamp at the time of collection from its child nodes. Must be in timestamp format. @@ -21588,14 +21581,14 @@ type: date -- -*`cisco.rsa.time.datetime`*:: +*`rsa.time.datetime`*:: + -- type: keyword -- -*`cisco.rsa.time.effective_time`*:: +*`rsa.time.effective_time`*:: + -- This key is the effective time referenced by an individual event in a Standard Timestamp format @@ -21604,7 +21597,7 @@ type: date -- -*`cisco.rsa.time.expire_time`*:: +*`rsa.time.expire_time`*:: + -- This key is the timestamp that explicitly refers to an expiration. @@ -21613,7 +21606,7 @@ type: date -- -*`cisco.rsa.time.process_time`*:: +*`rsa.time.process_time`*:: + -- Deprecated, use duration.time @@ -21622,28 +21615,28 @@ type: keyword -- -*`cisco.rsa.time.hour`*:: +*`rsa.time.hour`*:: + -- type: keyword -- -*`cisco.rsa.time.min`*:: +*`rsa.time.min`*:: + -- type: keyword -- -*`cisco.rsa.time.timestamp`*:: +*`rsa.time.timestamp`*:: + -- type: keyword -- -*`cisco.rsa.time.event_queue_time`*:: +*`rsa.time.event_queue_time`*:: + -- This key is the Time that the event was queued. @@ -21652,77 +21645,77 @@ type: date -- -*`cisco.rsa.time.p_time1`*:: +*`rsa.time.p_time1`*:: + -- type: keyword -- -*`cisco.rsa.time.tzone`*:: +*`rsa.time.tzone`*:: + -- type: keyword -- -*`cisco.rsa.time.eventtime`*:: +*`rsa.time.eventtime`*:: + -- type: keyword -- -*`cisco.rsa.time.gmtdate`*:: +*`rsa.time.gmtdate`*:: + -- type: keyword -- -*`cisco.rsa.time.gmttime`*:: +*`rsa.time.gmttime`*:: + -- type: keyword -- -*`cisco.rsa.time.p_date`*:: +*`rsa.time.p_date`*:: + -- type: keyword -- -*`cisco.rsa.time.p_month`*:: +*`rsa.time.p_month`*:: + -- type: keyword -- -*`cisco.rsa.time.p_time`*:: +*`rsa.time.p_time`*:: + -- type: keyword -- -*`cisco.rsa.time.p_time2`*:: +*`rsa.time.p_time2`*:: + -- type: keyword -- -*`cisco.rsa.time.p_year`*:: +*`rsa.time.p_year`*:: + -- type: keyword -- -*`cisco.rsa.time.expire_time_str`*:: +*`rsa.time.expire_time_str`*:: + -- This key is used to capture incomplete timestamp that explicitly refers to an expiration. @@ -21731,7 +21724,7 @@ type: keyword -- -*`cisco.rsa.time.stamp`*:: +*`rsa.time.stamp`*:: + -- Deprecated key defined only in table map. @@ -21741,14 +21734,14 @@ type: date -- -*`cisco.rsa.misc.action`*:: +*`rsa.misc.action`*:: + -- type: keyword -- -*`cisco.rsa.misc.result`*:: +*`rsa.misc.result`*:: + -- This key is used to capture the outcome/result string value of an action in a session. @@ -21757,7 +21750,7 @@ type: keyword -- -*`cisco.rsa.misc.severity`*:: +*`rsa.misc.severity`*:: + -- This key is used to capture the severity given the session @@ -21766,7 +21759,7 @@ type: keyword -- -*`cisco.rsa.misc.event_type`*:: +*`rsa.misc.event_type`*:: + -- This key captures the event category type as specified by the event source. @@ -21775,7 +21768,7 @@ type: keyword -- -*`cisco.rsa.misc.reference_id`*:: +*`rsa.misc.reference_id`*:: + -- This key is used to capture an event id from the session directly @@ -21784,7 +21777,7 @@ type: keyword -- -*`cisco.rsa.misc.version`*:: +*`rsa.misc.version`*:: + -- This key captures Version of the application or OS which is generating the event. @@ -21793,7 +21786,7 @@ type: keyword -- -*`cisco.rsa.misc.disposition`*:: +*`rsa.misc.disposition`*:: + -- This key captures the The end state of an action. @@ -21802,7 +21795,7 @@ type: keyword -- -*`cisco.rsa.misc.result_code`*:: +*`rsa.misc.result_code`*:: + -- This key is used to capture the outcome/result numeric value of an action in a session @@ -21811,7 +21804,7 @@ type: keyword -- -*`cisco.rsa.misc.category`*:: +*`rsa.misc.category`*:: + -- This key is used to capture the category of an event given by the vendor in the session @@ -21820,7 +21813,7 @@ type: keyword -- -*`cisco.rsa.misc.obj_name`*:: +*`rsa.misc.obj_name`*:: + -- This is used to capture name of object @@ -21829,7 +21822,7 @@ type: keyword -- -*`cisco.rsa.misc.obj_type`*:: +*`rsa.misc.obj_type`*:: + -- This is used to capture type of object @@ -21838,7 +21831,7 @@ type: keyword -- -*`cisco.rsa.misc.event_source`*:: +*`rsa.misc.event_source`*:: + -- This key captures Source of the event that’s not a hostname @@ -21847,7 +21840,7 @@ type: keyword -- -*`cisco.rsa.misc.log_session_id`*:: +*`rsa.misc.log_session_id`*:: + -- This key is used to capture a sessionid from the session directly @@ -21856,7 +21849,7 @@ type: keyword -- -*`cisco.rsa.misc.group`*:: +*`rsa.misc.group`*:: + -- This key captures the Group Name value @@ -21865,7 +21858,7 @@ type: keyword -- -*`cisco.rsa.misc.policy_name`*:: +*`rsa.misc.policy_name`*:: + -- This key is used to capture the Policy Name only. @@ -21874,7 +21867,7 @@ type: keyword -- -*`cisco.rsa.misc.rule_name`*:: +*`rsa.misc.rule_name`*:: + -- This key captures the Rule Name @@ -21883,7 +21876,7 @@ type: keyword -- -*`cisco.rsa.misc.context`*:: +*`rsa.misc.context`*:: + -- This key captures Information which adds additional context to the event. @@ -21892,7 +21885,7 @@ type: keyword -- -*`cisco.rsa.misc.change_new`*:: +*`rsa.misc.change_new`*:: + -- This key is used to capture the new values of the attribute that’s changing in a session @@ -21901,14 +21894,14 @@ type: keyword -- -*`cisco.rsa.misc.space`*:: +*`rsa.misc.space`*:: + -- type: keyword -- -*`cisco.rsa.misc.client`*:: +*`rsa.misc.client`*:: + -- This key is used to capture only the name of the client application requesting resources of the server. See the user.agent meta key for capture of the specific user agent identifier or browser identification string. @@ -21917,21 +21910,21 @@ type: keyword -- -*`cisco.rsa.misc.msgIdPart1`*:: +*`rsa.misc.msgIdPart1`*:: + -- type: keyword -- -*`cisco.rsa.misc.msgIdPart2`*:: +*`rsa.misc.msgIdPart2`*:: + -- type: keyword -- -*`cisco.rsa.misc.change_old`*:: +*`rsa.misc.change_old`*:: + -- This key is used to capture the old value of the attribute that’s changing in a session @@ -21940,7 +21933,7 @@ type: keyword -- -*`cisco.rsa.misc.operation_id`*:: +*`rsa.misc.operation_id`*:: + -- An alert number or operation number. The values should be unique and non-repeating. @@ -21949,7 +21942,7 @@ type: keyword -- -*`cisco.rsa.misc.event_state`*:: +*`rsa.misc.event_state`*:: + -- This key captures the current state of the object/item referenced within the event. Describing an on-going event. @@ -21958,7 +21951,7 @@ type: keyword -- -*`cisco.rsa.misc.group_object`*:: +*`rsa.misc.group_object`*:: + -- This key captures a collection/grouping of entities. Specific usage @@ -21967,7 +21960,7 @@ type: keyword -- -*`cisco.rsa.misc.node`*:: +*`rsa.misc.node`*:: + -- Common use case is the node name within a cluster. The cluster name is reflected by the host name. @@ -21976,7 +21969,7 @@ type: keyword -- -*`cisco.rsa.misc.rule`*:: +*`rsa.misc.rule`*:: + -- This key captures the Rule number @@ -21985,7 +21978,7 @@ type: keyword -- -*`cisco.rsa.misc.device_name`*:: +*`rsa.misc.device_name`*:: + -- This is used to capture name of the Device associated with the node Like: a physical disk, printer, etc @@ -21994,7 +21987,7 @@ type: keyword -- -*`cisco.rsa.misc.param`*:: +*`rsa.misc.param`*:: + -- This key is the parameters passed as part of a command or application, etc. @@ -22003,7 +21996,7 @@ type: keyword -- -*`cisco.rsa.misc.change_attrib`*:: +*`rsa.misc.change_attrib`*:: + -- This key is used to capture the name of the attribute that’s changing in a session @@ -22012,7 +22005,7 @@ type: keyword -- -*`cisco.rsa.misc.event_computer`*:: +*`rsa.misc.event_computer`*:: + -- This key is a windows only concept, where this key is used to capture fully qualified domain name in a windows log. @@ -22021,7 +22014,7 @@ type: keyword -- -*`cisco.rsa.misc.reference_id1`*:: +*`rsa.misc.reference_id1`*:: + -- This key is for Linked ID to be used as an addition to "reference.id" @@ -22030,7 +22023,7 @@ type: keyword -- -*`cisco.rsa.misc.event_log`*:: +*`rsa.misc.event_log`*:: + -- This key captures the Name of the event log @@ -22039,7 +22032,7 @@ type: keyword -- -*`cisco.rsa.misc.OS`*:: +*`rsa.misc.OS`*:: + -- This key captures the Name of the Operating System @@ -22048,7 +22041,7 @@ type: keyword -- -*`cisco.rsa.misc.terminal`*:: +*`rsa.misc.terminal`*:: + -- This key captures the Terminal Names only @@ -22057,14 +22050,14 @@ type: keyword -- -*`cisco.rsa.misc.msgIdPart3`*:: +*`rsa.misc.msgIdPart3`*:: + -- type: keyword -- -*`cisco.rsa.misc.filter`*:: +*`rsa.misc.filter`*:: + -- This key captures Filter used to reduce result set @@ -22073,7 +22066,7 @@ type: keyword -- -*`cisco.rsa.misc.serial_number`*:: +*`rsa.misc.serial_number`*:: + -- This key is the Serial number associated with a physical asset. @@ -22082,7 +22075,7 @@ type: keyword -- -*`cisco.rsa.misc.checksum`*:: +*`rsa.misc.checksum`*:: + -- This key is used to capture the checksum or hash of the entity such as a file or process. Checksum should be used over checksum.src or checksum.dst when it is unclear whether the entity is a source or target of an action. @@ -22091,7 +22084,7 @@ type: keyword -- -*`cisco.rsa.misc.event_user`*:: +*`rsa.misc.event_user`*:: + -- This key is a windows only concept, where this key is used to capture combination of domain name and username in a windows log. @@ -22100,7 +22093,7 @@ type: keyword -- -*`cisco.rsa.misc.virusname`*:: +*`rsa.misc.virusname`*:: + -- This key captures the name of the virus @@ -22109,7 +22102,7 @@ type: keyword -- -*`cisco.rsa.misc.content_type`*:: +*`rsa.misc.content_type`*:: + -- This key is used to capture Content Type only. @@ -22118,7 +22111,7 @@ type: keyword -- -*`cisco.rsa.misc.group_id`*:: +*`rsa.misc.group_id`*:: + -- This key captures Group ID Number (related to the group name) @@ -22127,7 +22120,7 @@ type: keyword -- -*`cisco.rsa.misc.policy_id`*:: +*`rsa.misc.policy_id`*:: + -- This key is used to capture the Policy ID only, this should be a numeric value, use policy.name otherwise @@ -22136,7 +22129,7 @@ type: keyword -- -*`cisco.rsa.misc.vsys`*:: +*`rsa.misc.vsys`*:: + -- This key captures Virtual System Name @@ -22145,7 +22138,7 @@ type: keyword -- -*`cisco.rsa.misc.connection_id`*:: +*`rsa.misc.connection_id`*:: + -- This key captures the Connection ID @@ -22154,7 +22147,7 @@ type: keyword -- -*`cisco.rsa.misc.reference_id2`*:: +*`rsa.misc.reference_id2`*:: + -- This key is for the 2nd Linked ID. Can be either linked to "reference.id" or "reference.id1" value but should not be used unless the other two variables are in play. @@ -22163,7 +22156,7 @@ type: keyword -- -*`cisco.rsa.misc.sensor`*:: +*`rsa.misc.sensor`*:: + -- This key captures Name of the sensor. Typically used in IDS/IPS based devices @@ -22172,7 +22165,7 @@ type: keyword -- -*`cisco.rsa.misc.sig_id`*:: +*`rsa.misc.sig_id`*:: + -- This key captures IDS/IPS Int Signature ID @@ -22181,7 +22174,7 @@ type: long -- -*`cisco.rsa.misc.port_name`*:: +*`rsa.misc.port_name`*:: + -- This key is used for Physical or logical port connection but does NOT include a network port. (Example: Printer port name). @@ -22190,7 +22183,7 @@ type: keyword -- -*`cisco.rsa.misc.rule_group`*:: +*`rsa.misc.rule_group`*:: + -- This key captures the Rule group name @@ -22199,7 +22192,7 @@ type: keyword -- -*`cisco.rsa.misc.risk_num`*:: +*`rsa.misc.risk_num`*:: + -- This key captures a Numeric Risk value @@ -22208,7 +22201,7 @@ type: double -- -*`cisco.rsa.misc.trigger_val`*:: +*`rsa.misc.trigger_val`*:: + -- This key captures the Value of the trigger or threshold condition. @@ -22217,7 +22210,7 @@ type: keyword -- -*`cisco.rsa.misc.log_session_id1`*:: +*`rsa.misc.log_session_id1`*:: + -- This key is used to capture a Linked (Related) Session ID from the session directly @@ -22226,7 +22219,7 @@ type: keyword -- -*`cisco.rsa.misc.comp_version`*:: +*`rsa.misc.comp_version`*:: + -- This key captures the Version level of a sub-component of a product. @@ -22235,7 +22228,7 @@ type: keyword -- -*`cisco.rsa.misc.content_version`*:: +*`rsa.misc.content_version`*:: + -- This key captures Version level of a signature or database content. @@ -22244,7 +22237,7 @@ type: keyword -- -*`cisco.rsa.misc.hardware_id`*:: +*`rsa.misc.hardware_id`*:: + -- This key is used to capture unique identifier for a device or system (NOT a Mac address) @@ -22253,7 +22246,7 @@ type: keyword -- -*`cisco.rsa.misc.risk`*:: +*`rsa.misc.risk`*:: + -- This key captures the non-numeric risk value @@ -22262,28 +22255,28 @@ type: keyword -- -*`cisco.rsa.misc.event_id`*:: +*`rsa.misc.event_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.reason`*:: +*`rsa.misc.reason`*:: + -- type: keyword -- -*`cisco.rsa.misc.status`*:: +*`rsa.misc.status`*:: + -- type: keyword -- -*`cisco.rsa.misc.mail_id`*:: +*`rsa.misc.mail_id`*:: + -- This key is used to capture the mailbox id/name @@ -22292,7 +22285,7 @@ type: keyword -- -*`cisco.rsa.misc.rule_uid`*:: +*`rsa.misc.rule_uid`*:: + -- This key is the Unique Identifier for a rule. @@ -22301,7 +22294,7 @@ type: keyword -- -*`cisco.rsa.misc.trigger_desc`*:: +*`rsa.misc.trigger_desc`*:: + -- This key captures the Description of the trigger or threshold condition. @@ -22310,35 +22303,35 @@ type: keyword -- -*`cisco.rsa.misc.inout`*:: +*`rsa.misc.inout`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_msgid`*:: +*`rsa.misc.p_msgid`*:: + -- type: keyword -- -*`cisco.rsa.misc.data_type`*:: +*`rsa.misc.data_type`*:: + -- type: keyword -- -*`cisco.rsa.misc.msgIdPart4`*:: +*`rsa.misc.msgIdPart4`*:: + -- type: keyword -- -*`cisco.rsa.misc.error`*:: +*`rsa.misc.error`*:: + -- This key captures All non successful Error codes or responses @@ -22347,14 +22340,14 @@ type: keyword -- -*`cisco.rsa.misc.index`*:: +*`rsa.misc.index`*:: + -- type: keyword -- -*`cisco.rsa.misc.listnum`*:: +*`rsa.misc.listnum`*:: + -- This key is used to capture listname or listnumber, primarily for collecting access-list @@ -22363,14 +22356,14 @@ type: keyword -- -*`cisco.rsa.misc.ntype`*:: +*`rsa.misc.ntype`*:: + -- type: keyword -- -*`cisco.rsa.misc.observed_val`*:: +*`rsa.misc.observed_val`*:: + -- This key captures the Value observed (from the perspective of the device generating the log). @@ -22379,7 +22372,7 @@ type: keyword -- -*`cisco.rsa.misc.policy_value`*:: +*`rsa.misc.policy_value`*:: + -- This key captures the contents of the policy. This contains details about the policy @@ -22388,7 +22381,7 @@ type: keyword -- -*`cisco.rsa.misc.pool_name`*:: +*`rsa.misc.pool_name`*:: + -- This key captures the name of a resource pool @@ -22397,7 +22390,7 @@ type: keyword -- -*`cisco.rsa.misc.rule_template`*:: +*`rsa.misc.rule_template`*:: + -- A default set of parameters which are overlayed onto a rule (or rulename) which efffectively constitutes a template @@ -22406,35 +22399,35 @@ type: keyword -- -*`cisco.rsa.misc.count`*:: +*`rsa.misc.count`*:: + -- type: keyword -- -*`cisco.rsa.misc.number`*:: +*`rsa.misc.number`*:: + -- type: keyword -- -*`cisco.rsa.misc.sigcat`*:: +*`rsa.misc.sigcat`*:: + -- type: keyword -- -*`cisco.rsa.misc.type`*:: +*`rsa.misc.type`*:: + -- type: keyword -- -*`cisco.rsa.misc.comments`*:: +*`rsa.misc.comments`*:: + -- Comment information provided in the log message @@ -22443,7 +22436,7 @@ type: keyword -- -*`cisco.rsa.misc.doc_number`*:: +*`rsa.misc.doc_number`*:: + -- This key captures File Identification number @@ -22452,7 +22445,7 @@ type: long -- -*`cisco.rsa.misc.expected_val`*:: +*`rsa.misc.expected_val`*:: + -- This key captures the Value expected (from the perspective of the device generating the log). @@ -22461,7 +22454,7 @@ type: keyword -- -*`cisco.rsa.misc.job_num`*:: +*`rsa.misc.job_num`*:: + -- This key captures the Job Number @@ -22470,7 +22463,7 @@ type: keyword -- -*`cisco.rsa.misc.spi_dst`*:: +*`rsa.misc.spi_dst`*:: + -- Destination SPI Index @@ -22479,7 +22472,7 @@ type: keyword -- -*`cisco.rsa.misc.spi_src`*:: +*`rsa.misc.spi_src`*:: + -- Source SPI Index @@ -22488,14 +22481,14 @@ type: keyword -- -*`cisco.rsa.misc.code`*:: +*`rsa.misc.code`*:: + -- type: keyword -- -*`cisco.rsa.misc.agent_id`*:: +*`rsa.misc.agent_id`*:: + -- This key is used to capture agent id @@ -22504,7 +22497,7 @@ type: keyword -- -*`cisco.rsa.misc.message_body`*:: +*`rsa.misc.message_body`*:: + -- This key captures the The contents of the message body. @@ -22513,14 +22506,14 @@ type: keyword -- -*`cisco.rsa.misc.phone`*:: +*`rsa.misc.phone`*:: + -- type: keyword -- -*`cisco.rsa.misc.sig_id_str`*:: +*`rsa.misc.sig_id_str`*:: + -- This key captures a string object of the sigid variable. @@ -22529,28 +22522,28 @@ type: keyword -- -*`cisco.rsa.misc.cmd`*:: +*`rsa.misc.cmd`*:: + -- type: keyword -- -*`cisco.rsa.misc.misc`*:: +*`rsa.misc.misc`*:: + -- type: keyword -- -*`cisco.rsa.misc.name`*:: +*`rsa.misc.name`*:: + -- type: keyword -- -*`cisco.rsa.misc.cpu`*:: +*`rsa.misc.cpu`*:: + -- This key is the CPU time used in the execution of the event being recorded. @@ -22559,7 +22552,7 @@ type: long -- -*`cisco.rsa.misc.event_desc`*:: +*`rsa.misc.event_desc`*:: + -- This key is used to capture a description of an event available directly or inferred @@ -22568,7 +22561,7 @@ type: keyword -- -*`cisco.rsa.misc.sig_id1`*:: +*`rsa.misc.sig_id1`*:: + -- This key captures IDS/IPS Int Signature ID. This must be linked to the sig.id @@ -22577,42 +22570,42 @@ type: long -- -*`cisco.rsa.misc.im_buddyid`*:: +*`rsa.misc.im_buddyid`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_client`*:: +*`rsa.misc.im_client`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_userid`*:: +*`rsa.misc.im_userid`*:: + -- type: keyword -- -*`cisco.rsa.misc.pid`*:: +*`rsa.misc.pid`*:: + -- type: keyword -- -*`cisco.rsa.misc.priority`*:: +*`rsa.misc.priority`*:: + -- type: keyword -- -*`cisco.rsa.misc.context_subject`*:: +*`rsa.misc.context_subject`*:: + -- This key is to be used in an audit context where the subject is the object being identified @@ -22621,14 +22614,14 @@ type: keyword -- -*`cisco.rsa.misc.context_target`*:: +*`rsa.misc.context_target`*:: + -- type: keyword -- -*`cisco.rsa.misc.cve`*:: +*`rsa.misc.cve`*:: + -- This key captures CVE (Common Vulnerabilities and Exposures) - an identifier for known information security vulnerabilities. @@ -22637,7 +22630,7 @@ type: keyword -- -*`cisco.rsa.misc.fcatnum`*:: +*`rsa.misc.fcatnum`*:: + -- This key captures Filter Category Number. Legacy Usage @@ -22646,7 +22639,7 @@ type: keyword -- -*`cisco.rsa.misc.library`*:: +*`rsa.misc.library`*:: + -- This key is used to capture library information in mainframe devices @@ -22655,7 +22648,7 @@ type: keyword -- -*`cisco.rsa.misc.parent_node`*:: +*`rsa.misc.parent_node`*:: + -- This key captures the Parent Node Name. Must be related to node variable. @@ -22664,7 +22657,7 @@ type: keyword -- -*`cisco.rsa.misc.risk_info`*:: +*`rsa.misc.risk_info`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -22673,7 +22666,7 @@ type: keyword -- -*`cisco.rsa.misc.tcp_flags`*:: +*`rsa.misc.tcp_flags`*:: + -- This key is captures the TCP flags set in any packet of session @@ -22682,7 +22675,7 @@ type: long -- -*`cisco.rsa.misc.tos`*:: +*`rsa.misc.tos`*:: + -- This key describes the type of service @@ -22691,7 +22684,7 @@ type: long -- -*`cisco.rsa.misc.vm_target`*:: +*`rsa.misc.vm_target`*:: + -- VMWare Target **VMWARE** only varaible. @@ -22700,7 +22693,7 @@ type: keyword -- -*`cisco.rsa.misc.workspace`*:: +*`rsa.misc.workspace`*:: + -- This key captures Workspace Description @@ -22709,91 +22702,91 @@ type: keyword -- -*`cisco.rsa.misc.command`*:: +*`rsa.misc.command`*:: + -- type: keyword -- -*`cisco.rsa.misc.event_category`*:: +*`rsa.misc.event_category`*:: + -- type: keyword -- -*`cisco.rsa.misc.facilityname`*:: +*`rsa.misc.facilityname`*:: + -- type: keyword -- -*`cisco.rsa.misc.forensic_info`*:: +*`rsa.misc.forensic_info`*:: + -- type: keyword -- -*`cisco.rsa.misc.jobname`*:: +*`rsa.misc.jobname`*:: + -- type: keyword -- -*`cisco.rsa.misc.mode`*:: +*`rsa.misc.mode`*:: + -- type: keyword -- -*`cisco.rsa.misc.policy`*:: +*`rsa.misc.policy`*:: + -- type: keyword -- -*`cisco.rsa.misc.policy_waiver`*:: +*`rsa.misc.policy_waiver`*:: + -- type: keyword -- -*`cisco.rsa.misc.second`*:: +*`rsa.misc.second`*:: + -- type: keyword -- -*`cisco.rsa.misc.space1`*:: +*`rsa.misc.space1`*:: + -- type: keyword -- -*`cisco.rsa.misc.subcategory`*:: +*`rsa.misc.subcategory`*:: + -- type: keyword -- -*`cisco.rsa.misc.tbdstr2`*:: +*`rsa.misc.tbdstr2`*:: + -- type: keyword -- -*`cisco.rsa.misc.alert_id`*:: +*`rsa.misc.alert_id`*:: + -- Deprecated, New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -22802,7 +22795,7 @@ type: keyword -- -*`cisco.rsa.misc.checksum_dst`*:: +*`rsa.misc.checksum_dst`*:: + -- This key is used to capture the checksum or hash of the the target entity such as a process or file. @@ -22811,7 +22804,7 @@ type: keyword -- -*`cisco.rsa.misc.checksum_src`*:: +*`rsa.misc.checksum_src`*:: + -- This key is used to capture the checksum or hash of the source entity such as a file or process. @@ -22820,7 +22813,7 @@ type: keyword -- -*`cisco.rsa.misc.fresult`*:: +*`rsa.misc.fresult`*:: + -- This key captures the Filter Result @@ -22829,7 +22822,7 @@ type: long -- -*`cisco.rsa.misc.payload_dst`*:: +*`rsa.misc.payload_dst`*:: + -- This key is used to capture destination payload @@ -22838,7 +22831,7 @@ type: keyword -- -*`cisco.rsa.misc.payload_src`*:: +*`rsa.misc.payload_src`*:: + -- This key is used to capture source payload @@ -22847,7 +22840,7 @@ type: keyword -- -*`cisco.rsa.misc.pool_id`*:: +*`rsa.misc.pool_id`*:: + -- This key captures the identifier (typically numeric field) of a resource pool @@ -22856,7 +22849,7 @@ type: keyword -- -*`cisco.rsa.misc.process_id_val`*:: +*`rsa.misc.process_id_val`*:: + -- This key is a failure key for Process ID when it is not an integer value @@ -22865,7 +22858,7 @@ type: keyword -- -*`cisco.rsa.misc.risk_num_comm`*:: +*`rsa.misc.risk_num_comm`*:: + -- This key captures Risk Number Community @@ -22874,7 +22867,7 @@ type: double -- -*`cisco.rsa.misc.risk_num_next`*:: +*`rsa.misc.risk_num_next`*:: + -- This key captures Risk Number NextGen @@ -22883,7 +22876,7 @@ type: double -- -*`cisco.rsa.misc.risk_num_sand`*:: +*`rsa.misc.risk_num_sand`*:: + -- This key captures Risk Number SandBox @@ -22892,7 +22885,7 @@ type: double -- -*`cisco.rsa.misc.risk_num_static`*:: +*`rsa.misc.risk_num_static`*:: + -- This key captures Risk Number Static @@ -22901,7 +22894,7 @@ type: double -- -*`cisco.rsa.misc.risk_suspicious`*:: +*`rsa.misc.risk_suspicious`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -22910,7 +22903,7 @@ type: keyword -- -*`cisco.rsa.misc.risk_warning`*:: +*`rsa.misc.risk_warning`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -22919,7 +22912,7 @@ type: keyword -- -*`cisco.rsa.misc.snmp_oid`*:: +*`rsa.misc.snmp_oid`*:: + -- SNMP Object Identifier @@ -22928,7 +22921,7 @@ type: keyword -- -*`cisco.rsa.misc.sql`*:: +*`rsa.misc.sql`*:: + -- This key captures the SQL query @@ -22937,7 +22930,7 @@ type: keyword -- -*`cisco.rsa.misc.vuln_ref`*:: +*`rsa.misc.vuln_ref`*:: + -- This key captures the Vulnerability Reference details @@ -22946,1547 +22939,1547 @@ type: keyword -- -*`cisco.rsa.misc.acl_id`*:: +*`rsa.misc.acl_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.acl_op`*:: +*`rsa.misc.acl_op`*:: + -- type: keyword -- -*`cisco.rsa.misc.acl_pos`*:: +*`rsa.misc.acl_pos`*:: + -- type: keyword -- -*`cisco.rsa.misc.acl_table`*:: +*`rsa.misc.acl_table`*:: + -- type: keyword -- -*`cisco.rsa.misc.admin`*:: +*`rsa.misc.admin`*:: + -- type: keyword -- -*`cisco.rsa.misc.alarm_id`*:: +*`rsa.misc.alarm_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.alarmname`*:: +*`rsa.misc.alarmname`*:: + -- type: keyword -- -*`cisco.rsa.misc.app_id`*:: +*`rsa.misc.app_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.audit`*:: +*`rsa.misc.audit`*:: + -- type: keyword -- -*`cisco.rsa.misc.audit_object`*:: +*`rsa.misc.audit_object`*:: + -- type: keyword -- -*`cisco.rsa.misc.auditdata`*:: +*`rsa.misc.auditdata`*:: + -- type: keyword -- -*`cisco.rsa.misc.benchmark`*:: +*`rsa.misc.benchmark`*:: + -- type: keyword -- -*`cisco.rsa.misc.bypass`*:: +*`rsa.misc.bypass`*:: + -- type: keyword -- -*`cisco.rsa.misc.cache`*:: +*`rsa.misc.cache`*:: + -- type: keyword -- -*`cisco.rsa.misc.cache_hit`*:: +*`rsa.misc.cache_hit`*:: + -- type: keyword -- -*`cisco.rsa.misc.cefversion`*:: +*`rsa.misc.cefversion`*:: + -- type: keyword -- -*`cisco.rsa.misc.cfg_attr`*:: +*`rsa.misc.cfg_attr`*:: + -- type: keyword -- -*`cisco.rsa.misc.cfg_obj`*:: +*`rsa.misc.cfg_obj`*:: + -- type: keyword -- -*`cisco.rsa.misc.cfg_path`*:: +*`rsa.misc.cfg_path`*:: + -- type: keyword -- -*`cisco.rsa.misc.changes`*:: +*`rsa.misc.changes`*:: + -- type: keyword -- -*`cisco.rsa.misc.client_ip`*:: +*`rsa.misc.client_ip`*:: + -- type: keyword -- -*`cisco.rsa.misc.clustermembers`*:: +*`rsa.misc.clustermembers`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_acttimeout`*:: +*`rsa.misc.cn_acttimeout`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_asn_src`*:: +*`rsa.misc.cn_asn_src`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_bgpv4nxthop`*:: +*`rsa.misc.cn_bgpv4nxthop`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_ctr_dst_code`*:: +*`rsa.misc.cn_ctr_dst_code`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_dst_tos`*:: +*`rsa.misc.cn_dst_tos`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_dst_vlan`*:: +*`rsa.misc.cn_dst_vlan`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_engine_id`*:: +*`rsa.misc.cn_engine_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_engine_type`*:: +*`rsa.misc.cn_engine_type`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_f_switch`*:: +*`rsa.misc.cn_f_switch`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_flowsampid`*:: +*`rsa.misc.cn_flowsampid`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_flowsampintv`*:: +*`rsa.misc.cn_flowsampintv`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_flowsampmode`*:: +*`rsa.misc.cn_flowsampmode`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_inacttimeout`*:: +*`rsa.misc.cn_inacttimeout`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_inpermbyts`*:: +*`rsa.misc.cn_inpermbyts`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_inpermpckts`*:: +*`rsa.misc.cn_inpermpckts`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_invalid`*:: +*`rsa.misc.cn_invalid`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_ip_proto_ver`*:: +*`rsa.misc.cn_ip_proto_ver`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_ipv4_ident`*:: +*`rsa.misc.cn_ipv4_ident`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_l_switch`*:: +*`rsa.misc.cn_l_switch`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_log_did`*:: +*`rsa.misc.cn_log_did`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_log_rid`*:: +*`rsa.misc.cn_log_rid`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_max_ttl`*:: +*`rsa.misc.cn_max_ttl`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_maxpcktlen`*:: +*`rsa.misc.cn_maxpcktlen`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_min_ttl`*:: +*`rsa.misc.cn_min_ttl`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_minpcktlen`*:: +*`rsa.misc.cn_minpcktlen`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_1`*:: +*`rsa.misc.cn_mpls_lbl_1`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_10`*:: +*`rsa.misc.cn_mpls_lbl_10`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_2`*:: +*`rsa.misc.cn_mpls_lbl_2`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_3`*:: +*`rsa.misc.cn_mpls_lbl_3`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_4`*:: +*`rsa.misc.cn_mpls_lbl_4`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_5`*:: +*`rsa.misc.cn_mpls_lbl_5`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_6`*:: +*`rsa.misc.cn_mpls_lbl_6`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_7`*:: +*`rsa.misc.cn_mpls_lbl_7`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_8`*:: +*`rsa.misc.cn_mpls_lbl_8`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mpls_lbl_9`*:: +*`rsa.misc.cn_mpls_lbl_9`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mplstoplabel`*:: +*`rsa.misc.cn_mplstoplabel`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mplstoplabip`*:: +*`rsa.misc.cn_mplstoplabip`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mul_dst_byt`*:: +*`rsa.misc.cn_mul_dst_byt`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_mul_dst_pks`*:: +*`rsa.misc.cn_mul_dst_pks`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_muligmptype`*:: +*`rsa.misc.cn_muligmptype`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_sampalgo`*:: +*`rsa.misc.cn_sampalgo`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_sampint`*:: +*`rsa.misc.cn_sampint`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_seqctr`*:: +*`rsa.misc.cn_seqctr`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_spackets`*:: +*`rsa.misc.cn_spackets`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_src_tos`*:: +*`rsa.misc.cn_src_tos`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_src_vlan`*:: +*`rsa.misc.cn_src_vlan`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_sysuptime`*:: +*`rsa.misc.cn_sysuptime`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_template_id`*:: +*`rsa.misc.cn_template_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_totbytsexp`*:: +*`rsa.misc.cn_totbytsexp`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_totflowexp`*:: +*`rsa.misc.cn_totflowexp`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_totpcktsexp`*:: +*`rsa.misc.cn_totpcktsexp`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_unixnanosecs`*:: +*`rsa.misc.cn_unixnanosecs`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_v6flowlabel`*:: +*`rsa.misc.cn_v6flowlabel`*:: + -- type: keyword -- -*`cisco.rsa.misc.cn_v6optheaders`*:: +*`rsa.misc.cn_v6optheaders`*:: + -- type: keyword -- -*`cisco.rsa.misc.comp_class`*:: +*`rsa.misc.comp_class`*:: + -- type: keyword -- -*`cisco.rsa.misc.comp_name`*:: +*`rsa.misc.comp_name`*:: + -- type: keyword -- -*`cisco.rsa.misc.comp_rbytes`*:: +*`rsa.misc.comp_rbytes`*:: + -- type: keyword -- -*`cisco.rsa.misc.comp_sbytes`*:: +*`rsa.misc.comp_sbytes`*:: + -- type: keyword -- -*`cisco.rsa.misc.cpu_data`*:: +*`rsa.misc.cpu_data`*:: + -- type: keyword -- -*`cisco.rsa.misc.criticality`*:: +*`rsa.misc.criticality`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_agency_dst`*:: +*`rsa.misc.cs_agency_dst`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_analyzedby`*:: +*`rsa.misc.cs_analyzedby`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_av_other`*:: +*`rsa.misc.cs_av_other`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_av_primary`*:: +*`rsa.misc.cs_av_primary`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_av_secondary`*:: +*`rsa.misc.cs_av_secondary`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_bgpv6nxthop`*:: +*`rsa.misc.cs_bgpv6nxthop`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_bit9status`*:: +*`rsa.misc.cs_bit9status`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_context`*:: +*`rsa.misc.cs_context`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_control`*:: +*`rsa.misc.cs_control`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_data`*:: +*`rsa.misc.cs_data`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_datecret`*:: +*`rsa.misc.cs_datecret`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_dst_tld`*:: +*`rsa.misc.cs_dst_tld`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_eth_dst_ven`*:: +*`rsa.misc.cs_eth_dst_ven`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_eth_src_ven`*:: +*`rsa.misc.cs_eth_src_ven`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_event_uuid`*:: +*`rsa.misc.cs_event_uuid`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_filetype`*:: +*`rsa.misc.cs_filetype`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_fld`*:: +*`rsa.misc.cs_fld`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_if_desc`*:: +*`rsa.misc.cs_if_desc`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_if_name`*:: +*`rsa.misc.cs_if_name`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_ip_next_hop`*:: +*`rsa.misc.cs_ip_next_hop`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_ipv4dstpre`*:: +*`rsa.misc.cs_ipv4dstpre`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_ipv4srcpre`*:: +*`rsa.misc.cs_ipv4srcpre`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_lifetime`*:: +*`rsa.misc.cs_lifetime`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_log_medium`*:: +*`rsa.misc.cs_log_medium`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_loginname`*:: +*`rsa.misc.cs_loginname`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_modulescore`*:: +*`rsa.misc.cs_modulescore`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_modulesign`*:: +*`rsa.misc.cs_modulesign`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_opswatresult`*:: +*`rsa.misc.cs_opswatresult`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_payload`*:: +*`rsa.misc.cs_payload`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_registrant`*:: +*`rsa.misc.cs_registrant`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_registrar`*:: +*`rsa.misc.cs_registrar`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_represult`*:: +*`rsa.misc.cs_represult`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_rpayload`*:: +*`rsa.misc.cs_rpayload`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_sampler_name`*:: +*`rsa.misc.cs_sampler_name`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_sourcemodule`*:: +*`rsa.misc.cs_sourcemodule`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_streams`*:: +*`rsa.misc.cs_streams`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_targetmodule`*:: +*`rsa.misc.cs_targetmodule`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_v6nxthop`*:: +*`rsa.misc.cs_v6nxthop`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_whois_server`*:: +*`rsa.misc.cs_whois_server`*:: + -- type: keyword -- -*`cisco.rsa.misc.cs_yararesult`*:: +*`rsa.misc.cs_yararesult`*:: + -- type: keyword -- -*`cisco.rsa.misc.description`*:: +*`rsa.misc.description`*:: + -- type: keyword -- -*`cisco.rsa.misc.devvendor`*:: +*`rsa.misc.devvendor`*:: + -- type: keyword -- -*`cisco.rsa.misc.distance`*:: +*`rsa.misc.distance`*:: + -- type: keyword -- -*`cisco.rsa.misc.dstburb`*:: +*`rsa.misc.dstburb`*:: + -- type: keyword -- -*`cisco.rsa.misc.edomain`*:: +*`rsa.misc.edomain`*:: + -- type: keyword -- -*`cisco.rsa.misc.edomaub`*:: +*`rsa.misc.edomaub`*:: + -- type: keyword -- -*`cisco.rsa.misc.euid`*:: +*`rsa.misc.euid`*:: + -- type: keyword -- -*`cisco.rsa.misc.facility`*:: +*`rsa.misc.facility`*:: + -- type: keyword -- -*`cisco.rsa.misc.finterface`*:: +*`rsa.misc.finterface`*:: + -- type: keyword -- -*`cisco.rsa.misc.flags`*:: +*`rsa.misc.flags`*:: + -- type: keyword -- -*`cisco.rsa.misc.gaddr`*:: +*`rsa.misc.gaddr`*:: + -- type: keyword -- -*`cisco.rsa.misc.id3`*:: +*`rsa.misc.id3`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_buddyname`*:: +*`rsa.misc.im_buddyname`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_croomid`*:: +*`rsa.misc.im_croomid`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_croomtype`*:: +*`rsa.misc.im_croomtype`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_members`*:: +*`rsa.misc.im_members`*:: + -- type: keyword -- -*`cisco.rsa.misc.im_username`*:: +*`rsa.misc.im_username`*:: + -- type: keyword -- -*`cisco.rsa.misc.ipkt`*:: +*`rsa.misc.ipkt`*:: + -- type: keyword -- -*`cisco.rsa.misc.ipscat`*:: +*`rsa.misc.ipscat`*:: + -- type: keyword -- -*`cisco.rsa.misc.ipspri`*:: +*`rsa.misc.ipspri`*:: + -- type: keyword -- -*`cisco.rsa.misc.latitude`*:: +*`rsa.misc.latitude`*:: + -- type: keyword -- -*`cisco.rsa.misc.linenum`*:: +*`rsa.misc.linenum`*:: + -- type: keyword -- -*`cisco.rsa.misc.list_name`*:: +*`rsa.misc.list_name`*:: + -- type: keyword -- -*`cisco.rsa.misc.load_data`*:: +*`rsa.misc.load_data`*:: + -- type: keyword -- -*`cisco.rsa.misc.location_floor`*:: +*`rsa.misc.location_floor`*:: + -- type: keyword -- -*`cisco.rsa.misc.location_mark`*:: +*`rsa.misc.location_mark`*:: + -- type: keyword -- -*`cisco.rsa.misc.log_id`*:: +*`rsa.misc.log_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.log_type`*:: +*`rsa.misc.log_type`*:: + -- type: keyword -- -*`cisco.rsa.misc.logid`*:: +*`rsa.misc.logid`*:: + -- type: keyword -- -*`cisco.rsa.misc.logip`*:: +*`rsa.misc.logip`*:: + -- type: keyword -- -*`cisco.rsa.misc.logname`*:: +*`rsa.misc.logname`*:: + -- type: keyword -- -*`cisco.rsa.misc.longitude`*:: +*`rsa.misc.longitude`*:: + -- type: keyword -- -*`cisco.rsa.misc.lport`*:: +*`rsa.misc.lport`*:: + -- type: keyword -- -*`cisco.rsa.misc.mbug_data`*:: +*`rsa.misc.mbug_data`*:: + -- type: keyword -- -*`cisco.rsa.misc.misc_name`*:: +*`rsa.misc.misc_name`*:: + -- type: keyword -- -*`cisco.rsa.misc.msg_type`*:: +*`rsa.misc.msg_type`*:: + -- type: keyword -- -*`cisco.rsa.misc.msgid`*:: +*`rsa.misc.msgid`*:: + -- type: keyword -- -*`cisco.rsa.misc.netsessid`*:: +*`rsa.misc.netsessid`*:: + -- type: keyword -- -*`cisco.rsa.misc.num`*:: +*`rsa.misc.num`*:: + -- type: keyword -- -*`cisco.rsa.misc.number1`*:: +*`rsa.misc.number1`*:: + -- type: keyword -- -*`cisco.rsa.misc.number2`*:: +*`rsa.misc.number2`*:: + -- type: keyword -- -*`cisco.rsa.misc.nwwn`*:: +*`rsa.misc.nwwn`*:: + -- type: keyword -- -*`cisco.rsa.misc.object`*:: +*`rsa.misc.object`*:: + -- type: keyword -- -*`cisco.rsa.misc.operation`*:: +*`rsa.misc.operation`*:: + -- type: keyword -- -*`cisco.rsa.misc.opkt`*:: +*`rsa.misc.opkt`*:: + -- type: keyword -- -*`cisco.rsa.misc.orig_from`*:: +*`rsa.misc.orig_from`*:: + -- type: keyword -- -*`cisco.rsa.misc.owner_id`*:: +*`rsa.misc.owner_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_action`*:: +*`rsa.misc.p_action`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_filter`*:: +*`rsa.misc.p_filter`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_group_object`*:: +*`rsa.misc.p_group_object`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_id`*:: +*`rsa.misc.p_id`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_msgid1`*:: +*`rsa.misc.p_msgid1`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_msgid2`*:: +*`rsa.misc.p_msgid2`*:: + -- type: keyword -- -*`cisco.rsa.misc.p_result1`*:: +*`rsa.misc.p_result1`*:: + -- type: keyword -- -*`cisco.rsa.misc.password_chg`*:: +*`rsa.misc.password_chg`*:: + -- type: keyword -- -*`cisco.rsa.misc.password_expire`*:: +*`rsa.misc.password_expire`*:: + -- type: keyword -- -*`cisco.rsa.misc.permgranted`*:: +*`rsa.misc.permgranted`*:: + -- type: keyword -- -*`cisco.rsa.misc.permwanted`*:: +*`rsa.misc.permwanted`*:: + -- type: keyword -- -*`cisco.rsa.misc.pgid`*:: +*`rsa.misc.pgid`*:: + -- type: keyword -- -*`cisco.rsa.misc.policyUUID`*:: +*`rsa.misc.policyUUID`*:: + -- type: keyword -- -*`cisco.rsa.misc.prog_asp_num`*:: +*`rsa.misc.prog_asp_num`*:: + -- type: keyword -- -*`cisco.rsa.misc.program`*:: +*`rsa.misc.program`*:: + -- type: keyword -- -*`cisco.rsa.misc.real_data`*:: +*`rsa.misc.real_data`*:: + -- type: keyword -- -*`cisco.rsa.misc.rec_asp_device`*:: +*`rsa.misc.rec_asp_device`*:: + -- type: keyword -- -*`cisco.rsa.misc.rec_asp_num`*:: +*`rsa.misc.rec_asp_num`*:: + -- type: keyword -- -*`cisco.rsa.misc.rec_library`*:: +*`rsa.misc.rec_library`*:: + -- type: keyword -- -*`cisco.rsa.misc.recordnum`*:: +*`rsa.misc.recordnum`*:: + -- type: keyword -- -*`cisco.rsa.misc.ruid`*:: +*`rsa.misc.ruid`*:: + -- type: keyword -- -*`cisco.rsa.misc.sburb`*:: +*`rsa.misc.sburb`*:: + -- type: keyword -- -*`cisco.rsa.misc.sdomain_fld`*:: +*`rsa.misc.sdomain_fld`*:: + -- type: keyword -- -*`cisco.rsa.misc.sec`*:: +*`rsa.misc.sec`*:: + -- type: keyword -- -*`cisco.rsa.misc.sensorname`*:: +*`rsa.misc.sensorname`*:: + -- type: keyword -- -*`cisco.rsa.misc.seqnum`*:: +*`rsa.misc.seqnum`*:: + -- type: keyword -- -*`cisco.rsa.misc.session`*:: +*`rsa.misc.session`*:: + -- type: keyword -- -*`cisco.rsa.misc.sessiontype`*:: +*`rsa.misc.sessiontype`*:: + -- type: keyword -- -*`cisco.rsa.misc.sigUUID`*:: +*`rsa.misc.sigUUID`*:: + -- type: keyword -- -*`cisco.rsa.misc.spi`*:: +*`rsa.misc.spi`*:: + -- type: keyword -- -*`cisco.rsa.misc.srcburb`*:: +*`rsa.misc.srcburb`*:: + -- type: keyword -- -*`cisco.rsa.misc.srcdom`*:: +*`rsa.misc.srcdom`*:: + -- type: keyword -- -*`cisco.rsa.misc.srcservice`*:: +*`rsa.misc.srcservice`*:: + -- type: keyword -- -*`cisco.rsa.misc.state`*:: +*`rsa.misc.state`*:: + -- type: keyword -- -*`cisco.rsa.misc.status1`*:: +*`rsa.misc.status1`*:: + -- type: keyword -- -*`cisco.rsa.misc.svcno`*:: +*`rsa.misc.svcno`*:: + -- type: keyword -- -*`cisco.rsa.misc.system`*:: +*`rsa.misc.system`*:: + -- type: keyword -- -*`cisco.rsa.misc.tbdstr1`*:: +*`rsa.misc.tbdstr1`*:: + -- type: keyword -- -*`cisco.rsa.misc.tgtdom`*:: +*`rsa.misc.tgtdom`*:: + -- type: keyword -- -*`cisco.rsa.misc.tgtdomain`*:: +*`rsa.misc.tgtdomain`*:: + -- type: keyword -- -*`cisco.rsa.misc.threshold`*:: +*`rsa.misc.threshold`*:: + -- type: keyword -- -*`cisco.rsa.misc.type1`*:: +*`rsa.misc.type1`*:: + -- type: keyword -- -*`cisco.rsa.misc.udb_class`*:: +*`rsa.misc.udb_class`*:: + -- type: keyword -- -*`cisco.rsa.misc.url_fld`*:: +*`rsa.misc.url_fld`*:: + -- type: keyword -- -*`cisco.rsa.misc.user_div`*:: +*`rsa.misc.user_div`*:: + -- type: keyword -- -*`cisco.rsa.misc.userid`*:: +*`rsa.misc.userid`*:: + -- type: keyword -- -*`cisco.rsa.misc.username_fld`*:: +*`rsa.misc.username_fld`*:: + -- type: keyword -- -*`cisco.rsa.misc.utcstamp`*:: +*`rsa.misc.utcstamp`*:: + -- type: keyword -- -*`cisco.rsa.misc.v_instafname`*:: +*`rsa.misc.v_instafname`*:: + -- type: keyword -- -*`cisco.rsa.misc.virt_data`*:: +*`rsa.misc.virt_data`*:: + -- type: keyword -- -*`cisco.rsa.misc.vpnid`*:: +*`rsa.misc.vpnid`*:: + -- type: keyword -- -*`cisco.rsa.misc.autorun_type`*:: +*`rsa.misc.autorun_type`*:: + -- This is used to capture Auto Run type @@ -24495,7 +24488,7 @@ type: keyword -- -*`cisco.rsa.misc.cc_number`*:: +*`rsa.misc.cc_number`*:: + -- Valid Credit Card Numbers only @@ -24504,7 +24497,7 @@ type: long -- -*`cisco.rsa.misc.content`*:: +*`rsa.misc.content`*:: + -- This key captures the content type from protocol headers @@ -24513,7 +24506,7 @@ type: keyword -- -*`cisco.rsa.misc.ein_number`*:: +*`rsa.misc.ein_number`*:: + -- Employee Identification Numbers only @@ -24522,7 +24515,7 @@ type: long -- -*`cisco.rsa.misc.found`*:: +*`rsa.misc.found`*:: + -- This is used to capture the results of regex match @@ -24531,7 +24524,7 @@ type: keyword -- -*`cisco.rsa.misc.language`*:: +*`rsa.misc.language`*:: + -- This is used to capture list of languages the client support and what it prefers @@ -24540,7 +24533,7 @@ type: keyword -- -*`cisco.rsa.misc.lifetime`*:: +*`rsa.misc.lifetime`*:: + -- This key is used to capture the session lifetime in seconds. @@ -24549,7 +24542,7 @@ type: long -- -*`cisco.rsa.misc.link`*:: +*`rsa.misc.link`*:: + -- This key is used to link the sessions together. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -24558,7 +24551,7 @@ type: keyword -- -*`cisco.rsa.misc.match`*:: +*`rsa.misc.match`*:: + -- This key is for regex match name from search.ini @@ -24567,7 +24560,7 @@ type: keyword -- -*`cisco.rsa.misc.param_dst`*:: +*`rsa.misc.param_dst`*:: + -- This key captures the command line/launch argument of the target process or file @@ -24576,7 +24569,7 @@ type: keyword -- -*`cisco.rsa.misc.param_src`*:: +*`rsa.misc.param_src`*:: + -- This key captures source parameter @@ -24585,7 +24578,7 @@ type: keyword -- -*`cisco.rsa.misc.search_text`*:: +*`rsa.misc.search_text`*:: + -- This key captures the Search Text used @@ -24594,7 +24587,7 @@ type: keyword -- -*`cisco.rsa.misc.sig_name`*:: +*`rsa.misc.sig_name`*:: + -- This key is used to capture the Signature Name only. @@ -24603,7 +24596,7 @@ type: keyword -- -*`cisco.rsa.misc.snmp_value`*:: +*`rsa.misc.snmp_value`*:: + -- SNMP set request value @@ -24612,7 +24605,7 @@ type: keyword -- -*`cisco.rsa.misc.streams`*:: +*`rsa.misc.streams`*:: + -- This key captures number of streams in session @@ -24622,7 +24615,7 @@ type: long -- -*`cisco.rsa.db.index`*:: +*`rsa.db.index`*:: + -- This key captures IndexID of the index. @@ -24631,7 +24624,7 @@ type: keyword -- -*`cisco.rsa.db.instance`*:: +*`rsa.db.instance`*:: + -- This key is used to capture the database server instance name @@ -24640,7 +24633,7 @@ type: keyword -- -*`cisco.rsa.db.database`*:: +*`rsa.db.database`*:: + -- This key is used to capture the name of a database or an instance as seen in a session @@ -24649,7 +24642,7 @@ type: keyword -- -*`cisco.rsa.db.transact_id`*:: +*`rsa.db.transact_id`*:: + -- This key captures the SQL transantion ID of the current session @@ -24658,7 +24651,7 @@ type: keyword -- -*`cisco.rsa.db.permissions`*:: +*`rsa.db.permissions`*:: + -- This key captures permission or privilege level assigned to a resource. @@ -24667,7 +24660,7 @@ type: keyword -- -*`cisco.rsa.db.table_name`*:: +*`rsa.db.table_name`*:: + -- This key is used to capture the table name @@ -24676,7 +24669,7 @@ type: keyword -- -*`cisco.rsa.db.db_id`*:: +*`rsa.db.db_id`*:: + -- This key is used to capture the unique identifier for a database @@ -24685,7 +24678,7 @@ type: keyword -- -*`cisco.rsa.db.db_pid`*:: +*`rsa.db.db_pid`*:: + -- This key captures the process id of a connection with database server @@ -24694,7 +24687,7 @@ type: long -- -*`cisco.rsa.db.lread`*:: +*`rsa.db.lread`*:: + -- This key is used for the number of logical reads @@ -24703,7 +24696,7 @@ type: long -- -*`cisco.rsa.db.lwrite`*:: +*`rsa.db.lwrite`*:: + -- This key is used for the number of logical writes @@ -24712,7 +24705,7 @@ type: long -- -*`cisco.rsa.db.pread`*:: +*`rsa.db.pread`*:: + -- This key is used for the number of physical writes @@ -24722,7 +24715,7 @@ type: long -- -*`cisco.rsa.network.alias_host`*:: +*`rsa.network.alias_host`*:: + -- This key should be used when the source or destination context of a hostname is not clear.Also it captures the Device Hostname. Any Hostname that isnt ad.computer. @@ -24731,14 +24724,14 @@ type: keyword -- -*`cisco.rsa.network.domain`*:: +*`rsa.network.domain`*:: + -- type: keyword -- -*`cisco.rsa.network.host_dst`*:: +*`rsa.network.host_dst`*:: + -- This key should only be used when it’s a Destination Hostname @@ -24747,7 +24740,7 @@ type: keyword -- -*`cisco.rsa.network.network_service`*:: +*`rsa.network.network_service`*:: + -- This is used to capture layer 7 protocols/service names @@ -24756,7 +24749,7 @@ type: keyword -- -*`cisco.rsa.network.interface`*:: +*`rsa.network.interface`*:: + -- This key should be used when the source or destination context of an interface is not clear @@ -24765,7 +24758,7 @@ type: keyword -- -*`cisco.rsa.network.network_port`*:: +*`rsa.network.network_port`*:: + -- Deprecated, use port. NOTE: There is a type discrepancy as currently used, TM: Int32, INDEX: UInt64 (why neither chose the correct UInt16?!) @@ -24774,7 +24767,7 @@ type: long -- -*`cisco.rsa.network.eth_host`*:: +*`rsa.network.eth_host`*:: + -- Deprecated, use alias.mac @@ -24783,7 +24776,7 @@ type: keyword -- -*`cisco.rsa.network.sinterface`*:: +*`rsa.network.sinterface`*:: + -- This key should only be used when it’s a Source Interface @@ -24792,7 +24785,7 @@ type: keyword -- -*`cisco.rsa.network.dinterface`*:: +*`rsa.network.dinterface`*:: + -- This key should only be used when it’s a Destination Interface @@ -24801,7 +24794,7 @@ type: keyword -- -*`cisco.rsa.network.vlan`*:: +*`rsa.network.vlan`*:: + -- This key should only be used to capture the ID of the Virtual LAN @@ -24810,7 +24803,7 @@ type: long -- -*`cisco.rsa.network.zone_src`*:: +*`rsa.network.zone_src`*:: + -- This key should only be used when it’s a Source Zone. @@ -24819,7 +24812,7 @@ type: keyword -- -*`cisco.rsa.network.zone`*:: +*`rsa.network.zone`*:: + -- This key should be used when the source or destination context of a Zone is not clear @@ -24828,7 +24821,7 @@ type: keyword -- -*`cisco.rsa.network.zone_dst`*:: +*`rsa.network.zone_dst`*:: + -- This key should only be used when it’s a Destination Zone. @@ -24837,7 +24830,7 @@ type: keyword -- -*`cisco.rsa.network.gateway`*:: +*`rsa.network.gateway`*:: + -- This key is used to capture the IP Address of the gateway @@ -24846,7 +24839,7 @@ type: keyword -- -*`cisco.rsa.network.icmp_type`*:: +*`rsa.network.icmp_type`*:: + -- This key is used to capture the ICMP type only @@ -24855,7 +24848,7 @@ type: long -- -*`cisco.rsa.network.mask`*:: +*`rsa.network.mask`*:: + -- This key is used to capture the device network IPmask. @@ -24864,7 +24857,7 @@ type: keyword -- -*`cisco.rsa.network.icmp_code`*:: +*`rsa.network.icmp_code`*:: + -- This key is used to capture the ICMP code only @@ -24873,7 +24866,7 @@ type: long -- -*`cisco.rsa.network.protocol_detail`*:: +*`rsa.network.protocol_detail`*:: + -- This key should be used to capture additional protocol information @@ -24882,7 +24875,7 @@ type: keyword -- -*`cisco.rsa.network.dmask`*:: +*`rsa.network.dmask`*:: + -- This key is used for Destionation Device network mask @@ -24891,7 +24884,7 @@ type: keyword -- -*`cisco.rsa.network.port`*:: +*`rsa.network.port`*:: + -- This key should only be used to capture a Network Port when the directionality is not clear @@ -24900,7 +24893,7 @@ type: long -- -*`cisco.rsa.network.smask`*:: +*`rsa.network.smask`*:: + -- This key is used for capturing source Network Mask @@ -24909,7 +24902,7 @@ type: keyword -- -*`cisco.rsa.network.netname`*:: +*`rsa.network.netname`*:: + -- This key is used to capture the network name associated with an IP range. This is configured by the end user. @@ -24918,7 +24911,7 @@ type: keyword -- -*`cisco.rsa.network.paddr`*:: +*`rsa.network.paddr`*:: + -- Deprecated @@ -24927,91 +24920,91 @@ type: ip -- -*`cisco.rsa.network.faddr`*:: +*`rsa.network.faddr`*:: + -- type: keyword -- -*`cisco.rsa.network.lhost`*:: +*`rsa.network.lhost`*:: + -- type: keyword -- -*`cisco.rsa.network.origin`*:: +*`rsa.network.origin`*:: + -- type: keyword -- -*`cisco.rsa.network.remote_domain_id`*:: +*`rsa.network.remote_domain_id`*:: + -- type: keyword -- -*`cisco.rsa.network.addr`*:: +*`rsa.network.addr`*:: + -- type: keyword -- -*`cisco.rsa.network.dns_a_record`*:: +*`rsa.network.dns_a_record`*:: + -- type: keyword -- -*`cisco.rsa.network.dns_ptr_record`*:: +*`rsa.network.dns_ptr_record`*:: + -- type: keyword -- -*`cisco.rsa.network.fhost`*:: +*`rsa.network.fhost`*:: + -- type: keyword -- -*`cisco.rsa.network.fport`*:: +*`rsa.network.fport`*:: + -- type: keyword -- -*`cisco.rsa.network.laddr`*:: +*`rsa.network.laddr`*:: + -- type: keyword -- -*`cisco.rsa.network.linterface`*:: +*`rsa.network.linterface`*:: + -- type: keyword -- -*`cisco.rsa.network.phost`*:: +*`rsa.network.phost`*:: + -- type: keyword -- -*`cisco.rsa.network.ad_computer_dst`*:: +*`rsa.network.ad_computer_dst`*:: + -- Deprecated, use host.dst @@ -25020,7 +25013,7 @@ type: keyword -- -*`cisco.rsa.network.eth_type`*:: +*`rsa.network.eth_type`*:: + -- This key is used to capture Ethernet Type, Used for Layer 3 Protocols Only @@ -25029,7 +25022,7 @@ type: long -- -*`cisco.rsa.network.ip_proto`*:: +*`rsa.network.ip_proto`*:: + -- This key should be used to capture the Protocol number, all the protocol nubers are converted into string in UI @@ -25038,63 +25031,63 @@ type: long -- -*`cisco.rsa.network.dns_cname_record`*:: +*`rsa.network.dns_cname_record`*:: + -- type: keyword -- -*`cisco.rsa.network.dns_id`*:: +*`rsa.network.dns_id`*:: + -- type: keyword -- -*`cisco.rsa.network.dns_opcode`*:: +*`rsa.network.dns_opcode`*:: + -- type: keyword -- -*`cisco.rsa.network.dns_resp`*:: +*`rsa.network.dns_resp`*:: + -- type: keyword -- -*`cisco.rsa.network.dns_type`*:: +*`rsa.network.dns_type`*:: + -- type: keyword -- -*`cisco.rsa.network.domain1`*:: +*`rsa.network.domain1`*:: + -- type: keyword -- -*`cisco.rsa.network.host_type`*:: +*`rsa.network.host_type`*:: + -- type: keyword -- -*`cisco.rsa.network.packet_length`*:: +*`rsa.network.packet_length`*:: + -- type: keyword -- -*`cisco.rsa.network.host_orig`*:: +*`rsa.network.host_orig`*:: + -- This is used to capture the original hostname in case of a Forwarding Agent or a Proxy in between. @@ -25103,7 +25096,7 @@ type: keyword -- -*`cisco.rsa.network.rpayload`*:: +*`rsa.network.rpayload`*:: + -- This key is used to capture the total number of payload bytes seen in the retransmitted packets. @@ -25112,7 +25105,7 @@ type: keyword -- -*`cisco.rsa.network.vlan_name`*:: +*`rsa.network.vlan_name`*:: + -- This key should only be used to capture the name of the Virtual LAN @@ -25122,7 +25115,7 @@ type: keyword -- -*`cisco.rsa.investigations.ec_activity`*:: +*`rsa.investigations.ec_activity`*:: + -- This key captures the particular event activity(Ex:Logoff) @@ -25131,7 +25124,7 @@ type: keyword -- -*`cisco.rsa.investigations.ec_theme`*:: +*`rsa.investigations.ec_theme`*:: + -- This key captures the Theme of a particular Event(Ex:Authentication) @@ -25140,7 +25133,7 @@ type: keyword -- -*`cisco.rsa.investigations.ec_subject`*:: +*`rsa.investigations.ec_subject`*:: + -- This key captures the Subject of a particular Event(Ex:User) @@ -25149,7 +25142,7 @@ type: keyword -- -*`cisco.rsa.investigations.ec_outcome`*:: +*`rsa.investigations.ec_outcome`*:: + -- This key captures the outcome of a particular Event(Ex:Success) @@ -25158,7 +25151,7 @@ type: keyword -- -*`cisco.rsa.investigations.event_cat`*:: +*`rsa.investigations.event_cat`*:: + -- This key captures the Event category number @@ -25167,7 +25160,7 @@ type: long -- -*`cisco.rsa.investigations.event_cat_name`*:: +*`rsa.investigations.event_cat_name`*:: + -- This key captures the event category name corresponding to the event cat code @@ -25176,7 +25169,7 @@ type: keyword -- -*`cisco.rsa.investigations.event_vcat`*:: +*`rsa.investigations.event_vcat`*:: + -- This is a vendor supplied category. This should be used in situations where the vendor has adopted their own event_category taxonomy. @@ -25185,7 +25178,7 @@ type: keyword -- -*`cisco.rsa.investigations.analysis_file`*:: +*`rsa.investigations.analysis_file`*:: + -- This is used to capture all indicators used in a File Analysis. This key should be used to capture an analysis of a file @@ -25194,7 +25187,7 @@ type: keyword -- -*`cisco.rsa.investigations.analysis_service`*:: +*`rsa.investigations.analysis_service`*:: + -- This is used to capture all indicators used in a Service Analysis. This key should be used to capture an analysis of a service @@ -25203,7 +25196,7 @@ type: keyword -- -*`cisco.rsa.investigations.analysis_session`*:: +*`rsa.investigations.analysis_session`*:: + -- This is used to capture all indicators used for a Session Analysis. This key should be used to capture an analysis of a session @@ -25212,7 +25205,7 @@ type: keyword -- -*`cisco.rsa.investigations.boc`*:: +*`rsa.investigations.boc`*:: + -- This is used to capture behaviour of compromise @@ -25221,7 +25214,7 @@ type: keyword -- -*`cisco.rsa.investigations.eoc`*:: +*`rsa.investigations.eoc`*:: + -- This is used to capture Enablers of Compromise @@ -25230,7 +25223,7 @@ type: keyword -- -*`cisco.rsa.investigations.inv_category`*:: +*`rsa.investigations.inv_category`*:: + -- This used to capture investigation category @@ -25239,7 +25232,7 @@ type: keyword -- -*`cisco.rsa.investigations.inv_context`*:: +*`rsa.investigations.inv_context`*:: + -- This used to capture investigation context @@ -25248,7 +25241,7 @@ type: keyword -- -*`cisco.rsa.investigations.ioc`*:: +*`rsa.investigations.ioc`*:: + -- This is key capture indicator of compromise @@ -25258,7 +25251,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_c1`*:: +*`rsa.counters.dclass_c1`*:: + -- This is a generic counter key that should be used with the label dclass.c1.str only @@ -25267,7 +25260,7 @@ type: long -- -*`cisco.rsa.counters.dclass_c2`*:: +*`rsa.counters.dclass_c2`*:: + -- This is a generic counter key that should be used with the label dclass.c2.str only @@ -25276,7 +25269,7 @@ type: long -- -*`cisco.rsa.counters.event_counter`*:: +*`rsa.counters.event_counter`*:: + -- This is used to capture the number of times an event repeated @@ -25285,7 +25278,7 @@ type: long -- -*`cisco.rsa.counters.dclass_r1`*:: +*`rsa.counters.dclass_r1`*:: + -- This is a generic ratio key that should be used with the label dclass.r1.str only @@ -25294,7 +25287,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_c3`*:: +*`rsa.counters.dclass_c3`*:: + -- This is a generic counter key that should be used with the label dclass.c3.str only @@ -25303,7 +25296,7 @@ type: long -- -*`cisco.rsa.counters.dclass_c1_str`*:: +*`rsa.counters.dclass_c1_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c1 only @@ -25312,7 +25305,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_c2_str`*:: +*`rsa.counters.dclass_c2_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c2 only @@ -25321,7 +25314,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_r1_str`*:: +*`rsa.counters.dclass_r1_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r1 only @@ -25330,7 +25323,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_r2`*:: +*`rsa.counters.dclass_r2`*:: + -- This is a generic ratio key that should be used with the label dclass.r2.str only @@ -25339,7 +25332,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_c3_str`*:: +*`rsa.counters.dclass_c3_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c3 only @@ -25348,7 +25341,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_r3`*:: +*`rsa.counters.dclass_r3`*:: + -- This is a generic ratio key that should be used with the label dclass.r3.str only @@ -25357,7 +25350,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_r2_str`*:: +*`rsa.counters.dclass_r2_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r2 only @@ -25366,7 +25359,7 @@ type: keyword -- -*`cisco.rsa.counters.dclass_r3_str`*:: +*`rsa.counters.dclass_r3_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r3 only @@ -25376,7 +25369,7 @@ type: keyword -- -*`cisco.rsa.identity.auth_method`*:: +*`rsa.identity.auth_method`*:: + -- This key is used to capture authentication methods used only @@ -25385,7 +25378,7 @@ type: keyword -- -*`cisco.rsa.identity.user_role`*:: +*`rsa.identity.user_role`*:: + -- This key is used to capture the Role of a user only @@ -25394,7 +25387,7 @@ type: keyword -- -*`cisco.rsa.identity.dn`*:: +*`rsa.identity.dn`*:: + -- X.500 (LDAP) Distinguished Name @@ -25403,7 +25396,7 @@ type: keyword -- -*`cisco.rsa.identity.logon_type`*:: +*`rsa.identity.logon_type`*:: + -- This key is used to capture the type of logon method used. @@ -25412,7 +25405,7 @@ type: keyword -- -*`cisco.rsa.identity.profile`*:: +*`rsa.identity.profile`*:: + -- This key is used to capture the user profile @@ -25421,7 +25414,7 @@ type: keyword -- -*`cisco.rsa.identity.accesses`*:: +*`rsa.identity.accesses`*:: + -- This key is used to capture actual privileges used in accessing an object @@ -25430,7 +25423,7 @@ type: keyword -- -*`cisco.rsa.identity.realm`*:: +*`rsa.identity.realm`*:: + -- Radius realm or similar grouping of accounts @@ -25439,7 +25432,7 @@ type: keyword -- -*`cisco.rsa.identity.user_sid_dst`*:: +*`rsa.identity.user_sid_dst`*:: + -- This key captures Destination User Session ID @@ -25448,7 +25441,7 @@ type: keyword -- -*`cisco.rsa.identity.dn_src`*:: +*`rsa.identity.dn_src`*:: + -- An X.500 (LDAP) Distinguished name that is used in a context that indicates a Source dn @@ -25457,7 +25450,7 @@ type: keyword -- -*`cisco.rsa.identity.org`*:: +*`rsa.identity.org`*:: + -- This key captures the User organization @@ -25466,7 +25459,7 @@ type: keyword -- -*`cisco.rsa.identity.dn_dst`*:: +*`rsa.identity.dn_dst`*:: + -- An X.500 (LDAP) Distinguished name that used in a context that indicates a Destination dn @@ -25475,7 +25468,7 @@ type: keyword -- -*`cisco.rsa.identity.firstname`*:: +*`rsa.identity.firstname`*:: + -- This key is for First Names only, this is used for Healthcare predominantly to capture Patients information @@ -25484,7 +25477,7 @@ type: keyword -- -*`cisco.rsa.identity.lastname`*:: +*`rsa.identity.lastname`*:: + -- This key is for Last Names only, this is used for Healthcare predominantly to capture Patients information @@ -25493,7 +25486,7 @@ type: keyword -- -*`cisco.rsa.identity.user_dept`*:: +*`rsa.identity.user_dept`*:: + -- User's Department Names only @@ -25502,7 +25495,7 @@ type: keyword -- -*`cisco.rsa.identity.user_sid_src`*:: +*`rsa.identity.user_sid_src`*:: + -- This key captures Source User Session ID @@ -25511,7 +25504,7 @@ type: keyword -- -*`cisco.rsa.identity.federated_sp`*:: +*`rsa.identity.federated_sp`*:: + -- This key is the Federated Service Provider. This is the application requesting authentication. @@ -25520,7 +25513,7 @@ type: keyword -- -*`cisco.rsa.identity.federated_idp`*:: +*`rsa.identity.federated_idp`*:: + -- This key is the federated Identity Provider. This is the server providing the authentication. @@ -25529,7 +25522,7 @@ type: keyword -- -*`cisco.rsa.identity.logon_type_desc`*:: +*`rsa.identity.logon_type_desc`*:: + -- This key is used to capture the textual description of an integer logon type as stored in the meta key 'logon.type'. @@ -25538,7 +25531,7 @@ type: keyword -- -*`cisco.rsa.identity.middlename`*:: +*`rsa.identity.middlename`*:: + -- This key is for Middle Names only, this is used for Healthcare predominantly to capture Patients information @@ -25547,7 +25540,7 @@ type: keyword -- -*`cisco.rsa.identity.password`*:: +*`rsa.identity.password`*:: + -- This key is for Passwords seen in any session, plain text or encrypted @@ -25556,7 +25549,7 @@ type: keyword -- -*`cisco.rsa.identity.host_role`*:: +*`rsa.identity.host_role`*:: + -- This key should only be used to capture the role of a Host Machine @@ -25565,7 +25558,7 @@ type: keyword -- -*`cisco.rsa.identity.ldap`*:: +*`rsa.identity.ldap`*:: + -- This key is for Uninterpreted LDAP values. Ldap Values that don’t have a clear query or response context @@ -25574,7 +25567,7 @@ type: keyword -- -*`cisco.rsa.identity.ldap_query`*:: +*`rsa.identity.ldap_query`*:: + -- This key is the Search criteria from an LDAP search @@ -25583,7 +25576,7 @@ type: keyword -- -*`cisco.rsa.identity.ldap_response`*:: +*`rsa.identity.ldap_response`*:: + -- This key is to capture Results from an LDAP search @@ -25592,7 +25585,7 @@ type: keyword -- -*`cisco.rsa.identity.owner`*:: +*`rsa.identity.owner`*:: + -- This is used to capture username the process or service is running as, the author of the task @@ -25601,7 +25594,7 @@ type: keyword -- -*`cisco.rsa.identity.service_account`*:: +*`rsa.identity.service_account`*:: + -- This key is a windows specific key, used for capturing name of the account a service (referenced in the event) is running under. Legacy Usage @@ -25611,7 +25604,7 @@ type: keyword -- -*`cisco.rsa.email.email_dst`*:: +*`rsa.email.email_dst`*:: + -- This key is used to capture the Destination email address only, when the destination context is not clear use email @@ -25620,7 +25613,7 @@ type: keyword -- -*`cisco.rsa.email.email_src`*:: +*`rsa.email.email_src`*:: + -- This key is used to capture the source email address only, when the source context is not clear use email @@ -25629,7 +25622,7 @@ type: keyword -- -*`cisco.rsa.email.subject`*:: +*`rsa.email.subject`*:: + -- This key is used to capture the subject string from an Email only. @@ -25638,7 +25631,7 @@ type: keyword -- -*`cisco.rsa.email.email`*:: +*`rsa.email.email`*:: + -- This key is used to capture a generic email address where the source or destination context is not clear @@ -25647,7 +25640,7 @@ type: keyword -- -*`cisco.rsa.email.trans_from`*:: +*`rsa.email.trans_from`*:: + -- Deprecated key defined only in table map. @@ -25656,7 +25649,7 @@ type: keyword -- -*`cisco.rsa.email.trans_to`*:: +*`rsa.email.trans_to`*:: + -- Deprecated key defined only in table map. @@ -25666,7 +25659,7 @@ type: keyword -- -*`cisco.rsa.file.privilege`*:: +*`rsa.file.privilege`*:: + -- Deprecated, use permissions @@ -25675,7 +25668,7 @@ type: keyword -- -*`cisco.rsa.file.attachment`*:: +*`rsa.file.attachment`*:: + -- This key captures the attachment file name @@ -25684,14 +25677,14 @@ type: keyword -- -*`cisco.rsa.file.filesystem`*:: +*`rsa.file.filesystem`*:: + -- type: keyword -- -*`cisco.rsa.file.binary`*:: +*`rsa.file.binary`*:: + -- Deprecated key defined only in table map. @@ -25700,7 +25693,7 @@ type: keyword -- -*`cisco.rsa.file.filename_dst`*:: +*`rsa.file.filename_dst`*:: + -- This is used to capture name of the file targeted by the action @@ -25709,7 +25702,7 @@ type: keyword -- -*`cisco.rsa.file.filename_src`*:: +*`rsa.file.filename_src`*:: + -- This is used to capture name of the parent filename, the file which performed the action @@ -25718,14 +25711,14 @@ type: keyword -- -*`cisco.rsa.file.filename_tmp`*:: +*`rsa.file.filename_tmp`*:: + -- type: keyword -- -*`cisco.rsa.file.directory_dst`*:: +*`rsa.file.directory_dst`*:: + -- This key is used to capture the directory of the target process or file @@ -25734,7 +25727,7 @@ type: keyword -- -*`cisco.rsa.file.directory_src`*:: +*`rsa.file.directory_src`*:: + -- This key is used to capture the directory of the source process or file @@ -25743,7 +25736,7 @@ type: keyword -- -*`cisco.rsa.file.file_entropy`*:: +*`rsa.file.file_entropy`*:: + -- This is used to capture entropy vale of a file @@ -25752,7 +25745,7 @@ type: double -- -*`cisco.rsa.file.file_vendor`*:: +*`rsa.file.file_vendor`*:: + -- This is used to capture Company name of file located in version_info @@ -25761,7 +25754,7 @@ type: keyword -- -*`cisco.rsa.file.task_name`*:: +*`rsa.file.task_name`*:: + -- This is used to capture name of the task @@ -25771,7 +25764,7 @@ type: keyword -- -*`cisco.rsa.web.fqdn`*:: +*`rsa.web.fqdn`*:: + -- Fully Qualified Domain Names @@ -25780,7 +25773,7 @@ type: keyword -- -*`cisco.rsa.web.web_cookie`*:: +*`rsa.web.web_cookie`*:: + -- This key is used to capture the Web cookies specifically. @@ -25789,14 +25782,14 @@ type: keyword -- -*`cisco.rsa.web.alias_host`*:: +*`rsa.web.alias_host`*:: + -- type: keyword -- -*`cisco.rsa.web.reputation_num`*:: +*`rsa.web.reputation_num`*:: + -- Reputation Number of an entity. Typically used for Web Domains @@ -25805,7 +25798,7 @@ type: double -- -*`cisco.rsa.web.web_ref_domain`*:: +*`rsa.web.web_ref_domain`*:: + -- Web referer's domain @@ -25814,7 +25807,7 @@ type: keyword -- -*`cisco.rsa.web.web_ref_query`*:: +*`rsa.web.web_ref_query`*:: + -- This key captures Web referer's query portion of the URL @@ -25823,14 +25816,14 @@ type: keyword -- -*`cisco.rsa.web.remote_domain`*:: +*`rsa.web.remote_domain`*:: + -- type: keyword -- -*`cisco.rsa.web.web_ref_page`*:: +*`rsa.web.web_ref_page`*:: + -- This key captures Web referer's page information @@ -25839,7 +25832,7 @@ type: keyword -- -*`cisco.rsa.web.web_ref_root`*:: +*`rsa.web.web_ref_root`*:: + -- Web referer's root URL path @@ -25848,77 +25841,77 @@ type: keyword -- -*`cisco.rsa.web.cn_asn_dst`*:: +*`rsa.web.cn_asn_dst`*:: + -- type: keyword -- -*`cisco.rsa.web.cn_rpackets`*:: +*`rsa.web.cn_rpackets`*:: + -- type: keyword -- -*`cisco.rsa.web.urlpage`*:: +*`rsa.web.urlpage`*:: + -- type: keyword -- -*`cisco.rsa.web.urlroot`*:: +*`rsa.web.urlroot`*:: + -- type: keyword -- -*`cisco.rsa.web.p_url`*:: +*`rsa.web.p_url`*:: + -- type: keyword -- -*`cisco.rsa.web.p_user_agent`*:: +*`rsa.web.p_user_agent`*:: + -- type: keyword -- -*`cisco.rsa.web.p_web_cookie`*:: +*`rsa.web.p_web_cookie`*:: + -- type: keyword -- -*`cisco.rsa.web.p_web_method`*:: +*`rsa.web.p_web_method`*:: + -- type: keyword -- -*`cisco.rsa.web.p_web_referer`*:: +*`rsa.web.p_web_referer`*:: + -- type: keyword -- -*`cisco.rsa.web.web_extension_tmp`*:: +*`rsa.web.web_extension_tmp`*:: + -- type: keyword -- -*`cisco.rsa.web.web_page`*:: +*`rsa.web.web_page`*:: + -- type: keyword @@ -25926,7 +25919,7 @@ type: keyword -- -*`cisco.rsa.threat.threat_category`*:: +*`rsa.threat.threat_category`*:: + -- This key captures Threat Name/Threat Category/Categorization of alert @@ -25935,7 +25928,7 @@ type: keyword -- -*`cisco.rsa.threat.threat_desc`*:: +*`rsa.threat.threat_desc`*:: + -- This key is used to capture the threat description from the session directly or inferred @@ -25944,7 +25937,7 @@ type: keyword -- -*`cisco.rsa.threat.alert`*:: +*`rsa.threat.alert`*:: + -- This key is used to capture name of the alert @@ -25953,7 +25946,7 @@ type: keyword -- -*`cisco.rsa.threat.threat_source`*:: +*`rsa.threat.threat_source`*:: + -- This key is used to capture source of the threat @@ -25963,7 +25956,7 @@ type: keyword -- -*`cisco.rsa.crypto.crypto`*:: +*`rsa.crypto.crypto`*:: + -- This key is used to capture the Encryption Type or Encryption Key only @@ -25972,7 +25965,7 @@ type: keyword -- -*`cisco.rsa.crypto.cipher_src`*:: +*`rsa.crypto.cipher_src`*:: + -- This key is for Source (Client) Cipher @@ -25981,7 +25974,7 @@ type: keyword -- -*`cisco.rsa.crypto.cert_subject`*:: +*`rsa.crypto.cert_subject`*:: + -- This key is used to capture the Certificate organization only @@ -25990,7 +25983,7 @@ type: keyword -- -*`cisco.rsa.crypto.peer`*:: +*`rsa.crypto.peer`*:: + -- This key is for Encryption peer's IP Address @@ -25999,7 +25992,7 @@ type: keyword -- -*`cisco.rsa.crypto.cipher_size_src`*:: +*`rsa.crypto.cipher_size_src`*:: + -- This key captures Source (Client) Cipher Size @@ -26008,7 +26001,7 @@ type: long -- -*`cisco.rsa.crypto.ike`*:: +*`rsa.crypto.ike`*:: + -- IKE negotiation phase. @@ -26017,7 +26010,7 @@ type: keyword -- -*`cisco.rsa.crypto.scheme`*:: +*`rsa.crypto.scheme`*:: + -- This key captures the Encryption scheme used @@ -26026,7 +26019,7 @@ type: keyword -- -*`cisco.rsa.crypto.peer_id`*:: +*`rsa.crypto.peer_id`*:: + -- This key is for Encryption peer’s identity @@ -26035,7 +26028,7 @@ type: keyword -- -*`cisco.rsa.crypto.sig_type`*:: +*`rsa.crypto.sig_type`*:: + -- This key captures the Signature Type @@ -26044,14 +26037,14 @@ type: keyword -- -*`cisco.rsa.crypto.cert_issuer`*:: +*`rsa.crypto.cert_issuer`*:: + -- type: keyword -- -*`cisco.rsa.crypto.cert_host_name`*:: +*`rsa.crypto.cert_host_name`*:: + -- Deprecated key defined only in table map. @@ -26060,7 +26053,7 @@ type: keyword -- -*`cisco.rsa.crypto.cert_error`*:: +*`rsa.crypto.cert_error`*:: + -- This key captures the Certificate Error String @@ -26069,7 +26062,7 @@ type: keyword -- -*`cisco.rsa.crypto.cipher_dst`*:: +*`rsa.crypto.cipher_dst`*:: + -- This key is for Destination (Server) Cipher @@ -26078,7 +26071,7 @@ type: keyword -- -*`cisco.rsa.crypto.cipher_size_dst`*:: +*`rsa.crypto.cipher_size_dst`*:: + -- This key captures Destination (Server) Cipher Size @@ -26087,7 +26080,7 @@ type: long -- -*`cisco.rsa.crypto.ssl_ver_src`*:: +*`rsa.crypto.ssl_ver_src`*:: + -- Deprecated, use version @@ -26096,21 +26089,21 @@ type: keyword -- -*`cisco.rsa.crypto.d_certauth`*:: +*`rsa.crypto.d_certauth`*:: + -- type: keyword -- -*`cisco.rsa.crypto.s_certauth`*:: +*`rsa.crypto.s_certauth`*:: + -- type: keyword -- -*`cisco.rsa.crypto.ike_cookie1`*:: +*`rsa.crypto.ike_cookie1`*:: + -- ID of the negotiation — sent for ISAKMP Phase One @@ -26119,7 +26112,7 @@ type: keyword -- -*`cisco.rsa.crypto.ike_cookie2`*:: +*`rsa.crypto.ike_cookie2`*:: + -- ID of the negotiation — sent for ISAKMP Phase Two @@ -26128,14 +26121,14 @@ type: keyword -- -*`cisco.rsa.crypto.cert_checksum`*:: +*`rsa.crypto.cert_checksum`*:: + -- type: keyword -- -*`cisco.rsa.crypto.cert_host_cat`*:: +*`rsa.crypto.cert_host_cat`*:: + -- This key is used for the hostname category value of a certificate @@ -26144,7 +26137,7 @@ type: keyword -- -*`cisco.rsa.crypto.cert_serial`*:: +*`rsa.crypto.cert_serial`*:: + -- This key is used to capture the Certificate serial number only @@ -26153,7 +26146,7 @@ type: keyword -- -*`cisco.rsa.crypto.cert_status`*:: +*`rsa.crypto.cert_status`*:: + -- This key captures Certificate validation status @@ -26162,7 +26155,7 @@ type: keyword -- -*`cisco.rsa.crypto.ssl_ver_dst`*:: +*`rsa.crypto.ssl_ver_dst`*:: + -- Deprecated, use version @@ -26171,35 +26164,35 @@ type: keyword -- -*`cisco.rsa.crypto.cert_keysize`*:: +*`rsa.crypto.cert_keysize`*:: + -- type: keyword -- -*`cisco.rsa.crypto.cert_username`*:: +*`rsa.crypto.cert_username`*:: + -- type: keyword -- -*`cisco.rsa.crypto.https_insact`*:: +*`rsa.crypto.https_insact`*:: + -- type: keyword -- -*`cisco.rsa.crypto.https_valid`*:: +*`rsa.crypto.https_valid`*:: + -- type: keyword -- -*`cisco.rsa.crypto.cert_ca`*:: +*`rsa.crypto.cert_ca`*:: + -- This key is used to capture the Certificate signing authority only @@ -26208,7 +26201,7 @@ type: keyword -- -*`cisco.rsa.crypto.cert_common`*:: +*`rsa.crypto.cert_common`*:: + -- This key is used to capture the Certificate common name only @@ -26218,7 +26211,7 @@ type: keyword -- -*`cisco.rsa.wireless.wlan_ssid`*:: +*`rsa.wireless.wlan_ssid`*:: + -- This key is used to capture the ssid of a Wireless Session @@ -26227,7 +26220,7 @@ type: keyword -- -*`cisco.rsa.wireless.access_point`*:: +*`rsa.wireless.access_point`*:: + -- This key is used to capture the access point name. @@ -26236,7 +26229,7 @@ type: keyword -- -*`cisco.rsa.wireless.wlan_channel`*:: +*`rsa.wireless.wlan_channel`*:: + -- This is used to capture the channel names @@ -26245,7 +26238,7 @@ type: long -- -*`cisco.rsa.wireless.wlan_name`*:: +*`rsa.wireless.wlan_name`*:: + -- This key captures either WLAN number/name @@ -26255,7 +26248,7 @@ type: keyword -- -*`cisco.rsa.storage.disk_volume`*:: +*`rsa.storage.disk_volume`*:: + -- A unique name assigned to logical units (volumes) within a physical disk @@ -26264,7 +26257,7 @@ type: keyword -- -*`cisco.rsa.storage.lun`*:: +*`rsa.storage.lun`*:: + -- Logical Unit Number.This key is a very useful concept in Storage. @@ -26273,7 +26266,7 @@ type: keyword -- -*`cisco.rsa.storage.pwwn`*:: +*`rsa.storage.pwwn`*:: + -- This uniquely identifies a port on a HBA. @@ -26283,7 +26276,7 @@ type: keyword -- -*`cisco.rsa.physical.org_dst`*:: +*`rsa.physical.org_dst`*:: + -- This is used to capture the destination organization based on the GEOPIP Maxmind database. @@ -26292,7 +26285,7 @@ type: keyword -- -*`cisco.rsa.physical.org_src`*:: +*`rsa.physical.org_src`*:: + -- This is used to capture the source organization based on the GEOPIP Maxmind database. @@ -26302,7 +26295,7 @@ type: keyword -- -*`cisco.rsa.healthcare.patient_fname`*:: +*`rsa.healthcare.patient_fname`*:: + -- This key is for First Names only, this is used for Healthcare predominantly to capture Patients information @@ -26311,7 +26304,7 @@ type: keyword -- -*`cisco.rsa.healthcare.patient_id`*:: +*`rsa.healthcare.patient_id`*:: + -- This key captures the unique ID for a patient @@ -26320,7 +26313,7 @@ type: keyword -- -*`cisco.rsa.healthcare.patient_lname`*:: +*`rsa.healthcare.patient_lname`*:: + -- This key is for Last Names only, this is used for Healthcare predominantly to capture Patients information @@ -26329,7 +26322,7 @@ type: keyword -- -*`cisco.rsa.healthcare.patient_mname`*:: +*`rsa.healthcare.patient_mname`*:: + -- This key is for Middle Names only, this is used for Healthcare predominantly to capture Patients information @@ -26339,7 +26332,7 @@ type: keyword -- -*`cisco.rsa.endpoint.host_state`*:: +*`rsa.endpoint.host_state`*:: + -- This key is used to capture the current state of the machine, such as blacklisted, infected, firewall disabled and so on @@ -26348,7 +26341,7 @@ type: keyword -- -*`cisco.rsa.endpoint.registry_key`*:: +*`rsa.endpoint.registry_key`*:: + -- This key captures the path to the registry key @@ -26357,7 +26350,7 @@ type: keyword -- -*`cisco.rsa.endpoint.registry_value`*:: +*`rsa.endpoint.registry_value`*:: + -- This key captures values or decorators used within a registry entry @@ -51477,24 +51470,7 @@ fortinet Module -[float] -=== fortinet - -Fields from fortinet FortiOS - - - -*`fortinet.file.hash.crc32`*:: -+ --- -CRC32 Hash of file - - -type: keyword - --- - -*`fortinet.network.interface.name`*:: +*`network.interface.name`*:: + -- Name of the network interface where the traffic has been observed. @@ -51506,7 +51482,7 @@ type: keyword -*`fortinet.rsa.internal.msg`*:: +*`rsa.internal.msg`*:: + -- This key is used to capture the raw message that comes into the Log Decoder @@ -51515,21 +51491,21 @@ type: keyword -- -*`fortinet.rsa.internal.messageid`*:: +*`rsa.internal.messageid`*:: + -- type: keyword -- -*`fortinet.rsa.internal.event_desc`*:: +*`rsa.internal.event_desc`*:: + -- type: keyword -- -*`fortinet.rsa.internal.message`*:: +*`rsa.internal.message`*:: + -- This key captures the contents of instant messages @@ -51538,7 +51514,7 @@ type: keyword -- -*`fortinet.rsa.internal.time`*:: +*`rsa.internal.time`*:: + -- This is the time at which a session hits a NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness. @@ -51547,7 +51523,7 @@ type: date -- -*`fortinet.rsa.internal.level`*:: +*`rsa.internal.level`*:: + -- Deprecated key defined only in table map. @@ -51556,7 +51532,7 @@ type: long -- -*`fortinet.rsa.internal.msg_id`*:: +*`rsa.internal.msg_id`*:: + -- This is the Message ID1 value that identifies the exact log parser definition which parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51565,7 +51541,7 @@ type: keyword -- -*`fortinet.rsa.internal.msg_vid`*:: +*`rsa.internal.msg_vid`*:: + -- This is the Message ID2 value that identifies the exact log parser definition which parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51574,7 +51550,7 @@ type: keyword -- -*`fortinet.rsa.internal.data`*:: +*`rsa.internal.data`*:: + -- Deprecated key defined only in table map. @@ -51583,7 +51559,7 @@ type: keyword -- -*`fortinet.rsa.internal.obj_server`*:: +*`rsa.internal.obj_server`*:: + -- Deprecated key defined only in table map. @@ -51592,7 +51568,7 @@ type: keyword -- -*`fortinet.rsa.internal.obj_val`*:: +*`rsa.internal.obj_val`*:: + -- Deprecated key defined only in table map. @@ -51601,7 +51577,7 @@ type: keyword -- -*`fortinet.rsa.internal.resource`*:: +*`rsa.internal.resource`*:: + -- Deprecated key defined only in table map. @@ -51610,7 +51586,7 @@ type: keyword -- -*`fortinet.rsa.internal.obj_id`*:: +*`rsa.internal.obj_id`*:: + -- Deprecated key defined only in table map. @@ -51619,7 +51595,7 @@ type: keyword -- -*`fortinet.rsa.internal.statement`*:: +*`rsa.internal.statement`*:: + -- Deprecated key defined only in table map. @@ -51628,7 +51604,7 @@ type: keyword -- -*`fortinet.rsa.internal.audit_class`*:: +*`rsa.internal.audit_class`*:: + -- Deprecated key defined only in table map. @@ -51637,7 +51613,7 @@ type: keyword -- -*`fortinet.rsa.internal.entry`*:: +*`rsa.internal.entry`*:: + -- Deprecated key defined only in table map. @@ -51646,7 +51622,7 @@ type: keyword -- -*`fortinet.rsa.internal.hcode`*:: +*`rsa.internal.hcode`*:: + -- Deprecated key defined only in table map. @@ -51655,7 +51631,7 @@ type: keyword -- -*`fortinet.rsa.internal.inode`*:: +*`rsa.internal.inode`*:: + -- Deprecated key defined only in table map. @@ -51664,7 +51640,7 @@ type: long -- -*`fortinet.rsa.internal.resource_class`*:: +*`rsa.internal.resource_class`*:: + -- Deprecated key defined only in table map. @@ -51673,7 +51649,7 @@ type: keyword -- -*`fortinet.rsa.internal.dead`*:: +*`rsa.internal.dead`*:: + -- Deprecated key defined only in table map. @@ -51682,7 +51658,7 @@ type: long -- -*`fortinet.rsa.internal.feed_desc`*:: +*`rsa.internal.feed_desc`*:: + -- This is used to capture the description of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51691,7 +51667,7 @@ type: keyword -- -*`fortinet.rsa.internal.feed_name`*:: +*`rsa.internal.feed_name`*:: + -- This is used to capture the name of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51700,7 +51676,7 @@ type: keyword -- -*`fortinet.rsa.internal.cid`*:: +*`rsa.internal.cid`*:: + -- This is the unique identifier used to identify a NetWitness Concentrator. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51709,7 +51685,7 @@ type: keyword -- -*`fortinet.rsa.internal.device_class`*:: +*`rsa.internal.device_class`*:: + -- This is the Classification of the Log Event Source under a predefined fixed set of Event Source Classifications. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51718,7 +51694,7 @@ type: keyword -- -*`fortinet.rsa.internal.device_group`*:: +*`rsa.internal.device_group`*:: + -- This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51727,7 +51703,7 @@ type: keyword -- -*`fortinet.rsa.internal.device_host`*:: +*`rsa.internal.device_host`*:: + -- This is the Hostname of the log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51736,7 +51712,7 @@ type: keyword -- -*`fortinet.rsa.internal.device_ip`*:: +*`rsa.internal.device_ip`*:: + -- This is the IPv4 address of the Log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51745,7 +51721,7 @@ type: ip -- -*`fortinet.rsa.internal.device_ipv6`*:: +*`rsa.internal.device_ipv6`*:: + -- This is the IPv6 address of the Log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51754,7 +51730,7 @@ type: ip -- -*`fortinet.rsa.internal.device_type`*:: +*`rsa.internal.device_type`*:: + -- This is the name of the log parser which parsed a given session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51763,7 +51739,7 @@ type: keyword -- -*`fortinet.rsa.internal.device_type_id`*:: +*`rsa.internal.device_type_id`*:: + -- Deprecated key defined only in table map. @@ -51772,7 +51748,7 @@ type: long -- -*`fortinet.rsa.internal.did`*:: +*`rsa.internal.did`*:: + -- This is the unique identifier used to identify a NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51781,7 +51757,7 @@ type: keyword -- -*`fortinet.rsa.internal.entropy_req`*:: +*`rsa.internal.entropy_req`*:: + -- This key is only used by the Entropy Parser, the Meta Type can be either UInt16 or Float32 based on the configuration @@ -51790,7 +51766,7 @@ type: long -- -*`fortinet.rsa.internal.entropy_res`*:: +*`rsa.internal.entropy_res`*:: + -- This key is only used by the Entropy Parser, the Meta Type can be either UInt16 or Float32 based on the configuration @@ -51799,7 +51775,7 @@ type: long -- -*`fortinet.rsa.internal.event_name`*:: +*`rsa.internal.event_name`*:: + -- Deprecated key defined only in table map. @@ -51808,7 +51784,7 @@ type: keyword -- -*`fortinet.rsa.internal.feed_category`*:: +*`rsa.internal.feed_category`*:: + -- This is used to capture the category of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51817,7 +51793,7 @@ type: keyword -- -*`fortinet.rsa.internal.forward_ip`*:: +*`rsa.internal.forward_ip`*:: + -- This key should be used to capture the IPV4 address of a relay system which forwarded the events from the original system to NetWitness. @@ -51826,7 +51802,7 @@ type: ip -- -*`fortinet.rsa.internal.forward_ipv6`*:: +*`rsa.internal.forward_ipv6`*:: + -- This key is used to capture the IPV6 address of a relay system which forwarded the events from the original system to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51835,7 +51811,7 @@ type: ip -- -*`fortinet.rsa.internal.header_id`*:: +*`rsa.internal.header_id`*:: + -- This is the Header ID value that identifies the exact log parser header definition that parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51844,7 +51820,7 @@ type: keyword -- -*`fortinet.rsa.internal.lc_cid`*:: +*`rsa.internal.lc_cid`*:: + -- This is a unique Identifier of a Log Collector. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51853,7 +51829,7 @@ type: keyword -- -*`fortinet.rsa.internal.lc_ctime`*:: +*`rsa.internal.lc_ctime`*:: + -- This is the time at which a log is collected in a NetWitness Log Collector. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51862,7 +51838,7 @@ type: date -- -*`fortinet.rsa.internal.mcb_req`*:: +*`rsa.internal.mcb_req`*:: + -- This key is only used by the Entropy Parser, the most common byte request is simply which byte for each side (0 thru 255) was seen the most @@ -51871,7 +51847,7 @@ type: long -- -*`fortinet.rsa.internal.mcb_res`*:: +*`rsa.internal.mcb_res`*:: + -- This key is only used by the Entropy Parser, the most common byte response is simply which byte for each side (0 thru 255) was seen the most @@ -51880,7 +51856,7 @@ type: long -- -*`fortinet.rsa.internal.mcbc_req`*:: +*`rsa.internal.mcbc_req`*:: + -- This key is only used by the Entropy Parser, the most common byte count is the number of times the most common byte (above) was seen in the session streams @@ -51889,7 +51865,7 @@ type: long -- -*`fortinet.rsa.internal.mcbc_res`*:: +*`rsa.internal.mcbc_res`*:: + -- This key is only used by the Entropy Parser, the most common byte count is the number of times the most common byte (above) was seen in the session streams @@ -51898,7 +51874,7 @@ type: long -- -*`fortinet.rsa.internal.medium`*:: +*`rsa.internal.medium`*:: + -- This key is used to identify if it’s a log/packet session or Layer 2 Encapsulation Type. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness. 32 = log, 33 = correlation session, < 32 is packet session @@ -51907,7 +51883,7 @@ type: long -- -*`fortinet.rsa.internal.node_name`*:: +*`rsa.internal.node_name`*:: + -- Deprecated key defined only in table map. @@ -51916,7 +51892,7 @@ type: keyword -- -*`fortinet.rsa.internal.nwe_callback_id`*:: +*`rsa.internal.nwe_callback_id`*:: + -- This key denotes that event is endpoint related @@ -51925,7 +51901,7 @@ type: keyword -- -*`fortinet.rsa.internal.parse_error`*:: +*`rsa.internal.parse_error`*:: + -- This is a special key that stores any Meta key validation error found while parsing a log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51934,7 +51910,7 @@ type: keyword -- -*`fortinet.rsa.internal.payload_req`*:: +*`rsa.internal.payload_req`*:: + -- This key is only used by the Entropy Parser, the payload size metrics are the payload sizes of each session side at the time of parsing. However, in order to keep @@ -51943,7 +51919,7 @@ type: long -- -*`fortinet.rsa.internal.payload_res`*:: +*`rsa.internal.payload_res`*:: + -- This key is only used by the Entropy Parser, the payload size metrics are the payload sizes of each session side at the time of parsing. However, in order to keep @@ -51952,7 +51928,7 @@ type: long -- -*`fortinet.rsa.internal.process_vid_dst`*:: +*`rsa.internal.process_vid_dst`*:: + -- Endpoint generates and uses a unique virtual ID to identify any similar group of process. This ID represents the target process. @@ -51961,7 +51937,7 @@ type: keyword -- -*`fortinet.rsa.internal.process_vid_src`*:: +*`rsa.internal.process_vid_src`*:: + -- Endpoint generates and uses a unique virtual ID to identify any similar group of process. This ID represents the source process. @@ -51970,7 +51946,7 @@ type: keyword -- -*`fortinet.rsa.internal.rid`*:: +*`rsa.internal.rid`*:: + -- This is a special ID of the Remote Session created by NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51979,7 +51955,7 @@ type: long -- -*`fortinet.rsa.internal.session_split`*:: +*`rsa.internal.session_split`*:: + -- This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -51988,7 +51964,7 @@ type: keyword -- -*`fortinet.rsa.internal.site`*:: +*`rsa.internal.site`*:: + -- Deprecated key defined only in table map. @@ -51997,7 +51973,7 @@ type: keyword -- -*`fortinet.rsa.internal.size`*:: +*`rsa.internal.size`*:: + -- This is the size of the session as seen by the NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -52006,7 +51982,7 @@ type: long -- -*`fortinet.rsa.internal.sourcefile`*:: +*`rsa.internal.sourcefile`*:: + -- This is the name of the log file or PCAPs that can be imported into NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -52015,7 +51991,7 @@ type: keyword -- -*`fortinet.rsa.internal.ubc_req`*:: +*`rsa.internal.ubc_req`*:: + -- This key is only used by the Entropy Parser, Unique byte count is the number of unique bytes seen in each stream. 256 would mean all byte values of 0 thru 255 were seen at least once @@ -52024,7 +52000,7 @@ type: long -- -*`fortinet.rsa.internal.ubc_res`*:: +*`rsa.internal.ubc_res`*:: + -- This key is only used by the Entropy Parser, Unique byte count is the number of unique bytes seen in each stream. 256 would mean all byte values of 0 thru 255 were seen at least once @@ -52033,7 +52009,7 @@ type: long -- -*`fortinet.rsa.internal.word`*:: +*`rsa.internal.word`*:: + -- This is used by the Word Parsing technology to capture the first 5 character of every word in an unparsed log @@ -52043,7 +52019,7 @@ type: keyword -- -*`fortinet.rsa.time.event_time`*:: +*`rsa.time.event_time`*:: + -- This key is used to capture the time mentioned in a raw session that represents the actual time an event occured in a standard normalized form @@ -52052,7 +52028,7 @@ type: date -- -*`fortinet.rsa.time.duration_time`*:: +*`rsa.time.duration_time`*:: + -- This key is used to capture the normalized duration/lifetime in seconds. @@ -52061,7 +52037,7 @@ type: double -- -*`fortinet.rsa.time.event_time_str`*:: +*`rsa.time.event_time_str`*:: + -- This key is used to capture the incomplete time mentioned in a session as a string @@ -52070,7 +52046,7 @@ type: keyword -- -*`fortinet.rsa.time.starttime`*:: +*`rsa.time.starttime`*:: + -- This key is used to capture the Start time mentioned in a session in a standard form @@ -52079,21 +52055,21 @@ type: date -- -*`fortinet.rsa.time.month`*:: +*`rsa.time.month`*:: + -- type: keyword -- -*`fortinet.rsa.time.day`*:: +*`rsa.time.day`*:: + -- type: keyword -- -*`fortinet.rsa.time.endtime`*:: +*`rsa.time.endtime`*:: + -- This key is used to capture the End time mentioned in a session in a standard form @@ -52102,7 +52078,7 @@ type: date -- -*`fortinet.rsa.time.timezone`*:: +*`rsa.time.timezone`*:: + -- This key is used to capture the timezone of the Event Time @@ -52111,7 +52087,7 @@ type: keyword -- -*`fortinet.rsa.time.duration_str`*:: +*`rsa.time.duration_str`*:: + -- A text string version of the duration @@ -52120,21 +52096,21 @@ type: keyword -- -*`fortinet.rsa.time.date`*:: +*`rsa.time.date`*:: + -- type: keyword -- -*`fortinet.rsa.time.year`*:: +*`rsa.time.year`*:: + -- type: keyword -- -*`fortinet.rsa.time.recorded_time`*:: +*`rsa.time.recorded_time`*:: + -- The event time as recorded by the system the event is collected from. The usage scenario is a multi-tier application where the management layer of the system records it's own timestamp at the time of collection from its child nodes. Must be in timestamp format. @@ -52143,14 +52119,14 @@ type: date -- -*`fortinet.rsa.time.datetime`*:: +*`rsa.time.datetime`*:: + -- type: keyword -- -*`fortinet.rsa.time.effective_time`*:: +*`rsa.time.effective_time`*:: + -- This key is the effective time referenced by an individual event in a Standard Timestamp format @@ -52159,7 +52135,7 @@ type: date -- -*`fortinet.rsa.time.expire_time`*:: +*`rsa.time.expire_time`*:: + -- This key is the timestamp that explicitly refers to an expiration. @@ -52168,7 +52144,7 @@ type: date -- -*`fortinet.rsa.time.process_time`*:: +*`rsa.time.process_time`*:: + -- Deprecated, use duration.time @@ -52177,28 +52153,28 @@ type: keyword -- -*`fortinet.rsa.time.hour`*:: +*`rsa.time.hour`*:: + -- type: keyword -- -*`fortinet.rsa.time.min`*:: +*`rsa.time.min`*:: + -- type: keyword -- -*`fortinet.rsa.time.timestamp`*:: +*`rsa.time.timestamp`*:: + -- type: keyword -- -*`fortinet.rsa.time.event_queue_time`*:: +*`rsa.time.event_queue_time`*:: + -- This key is the Time that the event was queued. @@ -52207,77 +52183,77 @@ type: date -- -*`fortinet.rsa.time.p_time1`*:: +*`rsa.time.p_time1`*:: + -- type: keyword -- -*`fortinet.rsa.time.tzone`*:: +*`rsa.time.tzone`*:: + -- type: keyword -- -*`fortinet.rsa.time.eventtime`*:: +*`rsa.time.eventtime`*:: + -- type: keyword -- -*`fortinet.rsa.time.gmtdate`*:: +*`rsa.time.gmtdate`*:: + -- type: keyword -- -*`fortinet.rsa.time.gmttime`*:: +*`rsa.time.gmttime`*:: + -- type: keyword -- -*`fortinet.rsa.time.p_date`*:: +*`rsa.time.p_date`*:: + -- type: keyword -- -*`fortinet.rsa.time.p_month`*:: +*`rsa.time.p_month`*:: + -- type: keyword -- -*`fortinet.rsa.time.p_time`*:: +*`rsa.time.p_time`*:: + -- type: keyword -- -*`fortinet.rsa.time.p_time2`*:: +*`rsa.time.p_time2`*:: + -- type: keyword -- -*`fortinet.rsa.time.p_year`*:: +*`rsa.time.p_year`*:: + -- type: keyword -- -*`fortinet.rsa.time.expire_time_str`*:: +*`rsa.time.expire_time_str`*:: + -- This key is used to capture incomplete timestamp that explicitly refers to an expiration. @@ -52286,7 +52262,7 @@ type: keyword -- -*`fortinet.rsa.time.stamp`*:: +*`rsa.time.stamp`*:: + -- Deprecated key defined only in table map. @@ -52296,14 +52272,14 @@ type: date -- -*`fortinet.rsa.misc.action`*:: +*`rsa.misc.action`*:: + -- type: keyword -- -*`fortinet.rsa.misc.result`*:: +*`rsa.misc.result`*:: + -- This key is used to capture the outcome/result string value of an action in a session. @@ -52312,7 +52288,7 @@ type: keyword -- -*`fortinet.rsa.misc.severity`*:: +*`rsa.misc.severity`*:: + -- This key is used to capture the severity given the session @@ -52321,7 +52297,7 @@ type: keyword -- -*`fortinet.rsa.misc.event_type`*:: +*`rsa.misc.event_type`*:: + -- This key captures the event category type as specified by the event source. @@ -52330,7 +52306,7 @@ type: keyword -- -*`fortinet.rsa.misc.reference_id`*:: +*`rsa.misc.reference_id`*:: + -- This key is used to capture an event id from the session directly @@ -52339,7 +52315,7 @@ type: keyword -- -*`fortinet.rsa.misc.version`*:: +*`rsa.misc.version`*:: + -- This key captures Version of the application or OS which is generating the event. @@ -52348,7 +52324,7 @@ type: keyword -- -*`fortinet.rsa.misc.disposition`*:: +*`rsa.misc.disposition`*:: + -- This key captures the The end state of an action. @@ -52357,7 +52333,7 @@ type: keyword -- -*`fortinet.rsa.misc.result_code`*:: +*`rsa.misc.result_code`*:: + -- This key is used to capture the outcome/result numeric value of an action in a session @@ -52366,7 +52342,7 @@ type: keyword -- -*`fortinet.rsa.misc.category`*:: +*`rsa.misc.category`*:: + -- This key is used to capture the category of an event given by the vendor in the session @@ -52375,7 +52351,7 @@ type: keyword -- -*`fortinet.rsa.misc.obj_name`*:: +*`rsa.misc.obj_name`*:: + -- This is used to capture name of object @@ -52384,7 +52360,7 @@ type: keyword -- -*`fortinet.rsa.misc.obj_type`*:: +*`rsa.misc.obj_type`*:: + -- This is used to capture type of object @@ -52393,7 +52369,7 @@ type: keyword -- -*`fortinet.rsa.misc.event_source`*:: +*`rsa.misc.event_source`*:: + -- This key captures Source of the event that’s not a hostname @@ -52402,7 +52378,7 @@ type: keyword -- -*`fortinet.rsa.misc.log_session_id`*:: +*`rsa.misc.log_session_id`*:: + -- This key is used to capture a sessionid from the session directly @@ -52411,7 +52387,7 @@ type: keyword -- -*`fortinet.rsa.misc.group`*:: +*`rsa.misc.group`*:: + -- This key captures the Group Name value @@ -52420,7 +52396,7 @@ type: keyword -- -*`fortinet.rsa.misc.policy_name`*:: +*`rsa.misc.policy_name`*:: + -- This key is used to capture the Policy Name only. @@ -52429,7 +52405,7 @@ type: keyword -- -*`fortinet.rsa.misc.rule_name`*:: +*`rsa.misc.rule_name`*:: + -- This key captures the Rule Name @@ -52438,7 +52414,7 @@ type: keyword -- -*`fortinet.rsa.misc.context`*:: +*`rsa.misc.context`*:: + -- This key captures Information which adds additional context to the event. @@ -52447,7 +52423,7 @@ type: keyword -- -*`fortinet.rsa.misc.change_new`*:: +*`rsa.misc.change_new`*:: + -- This key is used to capture the new values of the attribute that’s changing in a session @@ -52456,14 +52432,14 @@ type: keyword -- -*`fortinet.rsa.misc.space`*:: +*`rsa.misc.space`*:: + -- type: keyword -- -*`fortinet.rsa.misc.client`*:: +*`rsa.misc.client`*:: + -- This key is used to capture only the name of the client application requesting resources of the server. See the user.agent meta key for capture of the specific user agent identifier or browser identification string. @@ -52472,21 +52448,21 @@ type: keyword -- -*`fortinet.rsa.misc.msgIdPart1`*:: +*`rsa.misc.msgIdPart1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.msgIdPart2`*:: +*`rsa.misc.msgIdPart2`*:: + -- type: keyword -- -*`fortinet.rsa.misc.change_old`*:: +*`rsa.misc.change_old`*:: + -- This key is used to capture the old value of the attribute that’s changing in a session @@ -52495,7 +52471,7 @@ type: keyword -- -*`fortinet.rsa.misc.operation_id`*:: +*`rsa.misc.operation_id`*:: + -- An alert number or operation number. The values should be unique and non-repeating. @@ -52504,7 +52480,7 @@ type: keyword -- -*`fortinet.rsa.misc.event_state`*:: +*`rsa.misc.event_state`*:: + -- This key captures the current state of the object/item referenced within the event. Describing an on-going event. @@ -52513,7 +52489,7 @@ type: keyword -- -*`fortinet.rsa.misc.group_object`*:: +*`rsa.misc.group_object`*:: + -- This key captures a collection/grouping of entities. Specific usage @@ -52522,7 +52498,7 @@ type: keyword -- -*`fortinet.rsa.misc.node`*:: +*`rsa.misc.node`*:: + -- Common use case is the node name within a cluster. The cluster name is reflected by the host name. @@ -52531,7 +52507,7 @@ type: keyword -- -*`fortinet.rsa.misc.rule`*:: +*`rsa.misc.rule`*:: + -- This key captures the Rule number @@ -52540,7 +52516,7 @@ type: keyword -- -*`fortinet.rsa.misc.device_name`*:: +*`rsa.misc.device_name`*:: + -- This is used to capture name of the Device associated with the node Like: a physical disk, printer, etc @@ -52549,7 +52525,7 @@ type: keyword -- -*`fortinet.rsa.misc.param`*:: +*`rsa.misc.param`*:: + -- This key is the parameters passed as part of a command or application, etc. @@ -52558,7 +52534,7 @@ type: keyword -- -*`fortinet.rsa.misc.change_attrib`*:: +*`rsa.misc.change_attrib`*:: + -- This key is used to capture the name of the attribute that’s changing in a session @@ -52567,7 +52543,7 @@ type: keyword -- -*`fortinet.rsa.misc.event_computer`*:: +*`rsa.misc.event_computer`*:: + -- This key is a windows only concept, where this key is used to capture fully qualified domain name in a windows log. @@ -52576,7 +52552,7 @@ type: keyword -- -*`fortinet.rsa.misc.reference_id1`*:: +*`rsa.misc.reference_id1`*:: + -- This key is for Linked ID to be used as an addition to "reference.id" @@ -52585,7 +52561,7 @@ type: keyword -- -*`fortinet.rsa.misc.event_log`*:: +*`rsa.misc.event_log`*:: + -- This key captures the Name of the event log @@ -52594,7 +52570,7 @@ type: keyword -- -*`fortinet.rsa.misc.OS`*:: +*`rsa.misc.OS`*:: + -- This key captures the Name of the Operating System @@ -52603,7 +52579,7 @@ type: keyword -- -*`fortinet.rsa.misc.terminal`*:: +*`rsa.misc.terminal`*:: + -- This key captures the Terminal Names only @@ -52612,14 +52588,14 @@ type: keyword -- -*`fortinet.rsa.misc.msgIdPart3`*:: +*`rsa.misc.msgIdPart3`*:: + -- type: keyword -- -*`fortinet.rsa.misc.filter`*:: +*`rsa.misc.filter`*:: + -- This key captures Filter used to reduce result set @@ -52628,7 +52604,7 @@ type: keyword -- -*`fortinet.rsa.misc.serial_number`*:: +*`rsa.misc.serial_number`*:: + -- This key is the Serial number associated with a physical asset. @@ -52637,7 +52613,7 @@ type: keyword -- -*`fortinet.rsa.misc.checksum`*:: +*`rsa.misc.checksum`*:: + -- This key is used to capture the checksum or hash of the entity such as a file or process. Checksum should be used over checksum.src or checksum.dst when it is unclear whether the entity is a source or target of an action. @@ -52646,7 +52622,7 @@ type: keyword -- -*`fortinet.rsa.misc.event_user`*:: +*`rsa.misc.event_user`*:: + -- This key is a windows only concept, where this key is used to capture combination of domain name and username in a windows log. @@ -52655,7 +52631,7 @@ type: keyword -- -*`fortinet.rsa.misc.virusname`*:: +*`rsa.misc.virusname`*:: + -- This key captures the name of the virus @@ -52664,7 +52640,7 @@ type: keyword -- -*`fortinet.rsa.misc.content_type`*:: +*`rsa.misc.content_type`*:: + -- This key is used to capture Content Type only. @@ -52673,7 +52649,7 @@ type: keyword -- -*`fortinet.rsa.misc.group_id`*:: +*`rsa.misc.group_id`*:: + -- This key captures Group ID Number (related to the group name) @@ -52682,7 +52658,7 @@ type: keyword -- -*`fortinet.rsa.misc.policy_id`*:: +*`rsa.misc.policy_id`*:: + -- This key is used to capture the Policy ID only, this should be a numeric value, use policy.name otherwise @@ -52691,7 +52667,7 @@ type: keyword -- -*`fortinet.rsa.misc.vsys`*:: +*`rsa.misc.vsys`*:: + -- This key captures Virtual System Name @@ -52700,7 +52676,7 @@ type: keyword -- -*`fortinet.rsa.misc.connection_id`*:: +*`rsa.misc.connection_id`*:: + -- This key captures the Connection ID @@ -52709,7 +52685,7 @@ type: keyword -- -*`fortinet.rsa.misc.reference_id2`*:: +*`rsa.misc.reference_id2`*:: + -- This key is for the 2nd Linked ID. Can be either linked to "reference.id" or "reference.id1" value but should not be used unless the other two variables are in play. @@ -52718,7 +52694,7 @@ type: keyword -- -*`fortinet.rsa.misc.sensor`*:: +*`rsa.misc.sensor`*:: + -- This key captures Name of the sensor. Typically used in IDS/IPS based devices @@ -52727,7 +52703,7 @@ type: keyword -- -*`fortinet.rsa.misc.sig_id`*:: +*`rsa.misc.sig_id`*:: + -- This key captures IDS/IPS Int Signature ID @@ -52736,7 +52712,7 @@ type: long -- -*`fortinet.rsa.misc.port_name`*:: +*`rsa.misc.port_name`*:: + -- This key is used for Physical or logical port connection but does NOT include a network port. (Example: Printer port name). @@ -52745,7 +52721,7 @@ type: keyword -- -*`fortinet.rsa.misc.rule_group`*:: +*`rsa.misc.rule_group`*:: + -- This key captures the Rule group name @@ -52754,7 +52730,7 @@ type: keyword -- -*`fortinet.rsa.misc.risk_num`*:: +*`rsa.misc.risk_num`*:: + -- This key captures a Numeric Risk value @@ -52763,7 +52739,7 @@ type: double -- -*`fortinet.rsa.misc.trigger_val`*:: +*`rsa.misc.trigger_val`*:: + -- This key captures the Value of the trigger or threshold condition. @@ -52772,7 +52748,7 @@ type: keyword -- -*`fortinet.rsa.misc.log_session_id1`*:: +*`rsa.misc.log_session_id1`*:: + -- This key is used to capture a Linked (Related) Session ID from the session directly @@ -52781,7 +52757,7 @@ type: keyword -- -*`fortinet.rsa.misc.comp_version`*:: +*`rsa.misc.comp_version`*:: + -- This key captures the Version level of a sub-component of a product. @@ -52790,7 +52766,7 @@ type: keyword -- -*`fortinet.rsa.misc.content_version`*:: +*`rsa.misc.content_version`*:: + -- This key captures Version level of a signature or database content. @@ -52799,7 +52775,7 @@ type: keyword -- -*`fortinet.rsa.misc.hardware_id`*:: +*`rsa.misc.hardware_id`*:: + -- This key is used to capture unique identifier for a device or system (NOT a Mac address) @@ -52808,7 +52784,7 @@ type: keyword -- -*`fortinet.rsa.misc.risk`*:: +*`rsa.misc.risk`*:: + -- This key captures the non-numeric risk value @@ -52817,28 +52793,28 @@ type: keyword -- -*`fortinet.rsa.misc.event_id`*:: +*`rsa.misc.event_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.reason`*:: +*`rsa.misc.reason`*:: + -- type: keyword -- -*`fortinet.rsa.misc.status`*:: +*`rsa.misc.status`*:: + -- type: keyword -- -*`fortinet.rsa.misc.mail_id`*:: +*`rsa.misc.mail_id`*:: + -- This key is used to capture the mailbox id/name @@ -52847,7 +52823,7 @@ type: keyword -- -*`fortinet.rsa.misc.rule_uid`*:: +*`rsa.misc.rule_uid`*:: + -- This key is the Unique Identifier for a rule. @@ -52856,7 +52832,7 @@ type: keyword -- -*`fortinet.rsa.misc.trigger_desc`*:: +*`rsa.misc.trigger_desc`*:: + -- This key captures the Description of the trigger or threshold condition. @@ -52865,35 +52841,35 @@ type: keyword -- -*`fortinet.rsa.misc.inout`*:: +*`rsa.misc.inout`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_msgid`*:: +*`rsa.misc.p_msgid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.data_type`*:: +*`rsa.misc.data_type`*:: + -- type: keyword -- -*`fortinet.rsa.misc.msgIdPart4`*:: +*`rsa.misc.msgIdPart4`*:: + -- type: keyword -- -*`fortinet.rsa.misc.error`*:: +*`rsa.misc.error`*:: + -- This key captures All non successful Error codes or responses @@ -52902,14 +52878,14 @@ type: keyword -- -*`fortinet.rsa.misc.index`*:: +*`rsa.misc.index`*:: + -- type: keyword -- -*`fortinet.rsa.misc.listnum`*:: +*`rsa.misc.listnum`*:: + -- This key is used to capture listname or listnumber, primarily for collecting access-list @@ -52918,14 +52894,14 @@ type: keyword -- -*`fortinet.rsa.misc.ntype`*:: +*`rsa.misc.ntype`*:: + -- type: keyword -- -*`fortinet.rsa.misc.observed_val`*:: +*`rsa.misc.observed_val`*:: + -- This key captures the Value observed (from the perspective of the device generating the log). @@ -52934,7 +52910,7 @@ type: keyword -- -*`fortinet.rsa.misc.policy_value`*:: +*`rsa.misc.policy_value`*:: + -- This key captures the contents of the policy. This contains details about the policy @@ -52943,7 +52919,7 @@ type: keyword -- -*`fortinet.rsa.misc.pool_name`*:: +*`rsa.misc.pool_name`*:: + -- This key captures the name of a resource pool @@ -52952,7 +52928,7 @@ type: keyword -- -*`fortinet.rsa.misc.rule_template`*:: +*`rsa.misc.rule_template`*:: + -- A default set of parameters which are overlayed onto a rule (or rulename) which efffectively constitutes a template @@ -52961,35 +52937,35 @@ type: keyword -- -*`fortinet.rsa.misc.count`*:: +*`rsa.misc.count`*:: + -- type: keyword -- -*`fortinet.rsa.misc.number`*:: +*`rsa.misc.number`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sigcat`*:: +*`rsa.misc.sigcat`*:: + -- type: keyword -- -*`fortinet.rsa.misc.type`*:: +*`rsa.misc.type`*:: + -- type: keyword -- -*`fortinet.rsa.misc.comments`*:: +*`rsa.misc.comments`*:: + -- Comment information provided in the log message @@ -52998,7 +52974,7 @@ type: keyword -- -*`fortinet.rsa.misc.doc_number`*:: +*`rsa.misc.doc_number`*:: + -- This key captures File Identification number @@ -53007,7 +52983,7 @@ type: long -- -*`fortinet.rsa.misc.expected_val`*:: +*`rsa.misc.expected_val`*:: + -- This key captures the Value expected (from the perspective of the device generating the log). @@ -53016,7 +52992,7 @@ type: keyword -- -*`fortinet.rsa.misc.job_num`*:: +*`rsa.misc.job_num`*:: + -- This key captures the Job Number @@ -53025,7 +53001,7 @@ type: keyword -- -*`fortinet.rsa.misc.spi_dst`*:: +*`rsa.misc.spi_dst`*:: + -- Destination SPI Index @@ -53034,7 +53010,7 @@ type: keyword -- -*`fortinet.rsa.misc.spi_src`*:: +*`rsa.misc.spi_src`*:: + -- Source SPI Index @@ -53043,14 +53019,14 @@ type: keyword -- -*`fortinet.rsa.misc.code`*:: +*`rsa.misc.code`*:: + -- type: keyword -- -*`fortinet.rsa.misc.agent_id`*:: +*`rsa.misc.agent_id`*:: + -- This key is used to capture agent id @@ -53059,7 +53035,7 @@ type: keyword -- -*`fortinet.rsa.misc.message_body`*:: +*`rsa.misc.message_body`*:: + -- This key captures the The contents of the message body. @@ -53068,14 +53044,14 @@ type: keyword -- -*`fortinet.rsa.misc.phone`*:: +*`rsa.misc.phone`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sig_id_str`*:: +*`rsa.misc.sig_id_str`*:: + -- This key captures a string object of the sigid variable. @@ -53084,28 +53060,28 @@ type: keyword -- -*`fortinet.rsa.misc.cmd`*:: +*`rsa.misc.cmd`*:: + -- type: keyword -- -*`fortinet.rsa.misc.misc`*:: +*`rsa.misc.misc`*:: + -- type: keyword -- -*`fortinet.rsa.misc.name`*:: +*`rsa.misc.name`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cpu`*:: +*`rsa.misc.cpu`*:: + -- This key is the CPU time used in the execution of the event being recorded. @@ -53114,7 +53090,7 @@ type: long -- -*`fortinet.rsa.misc.event_desc`*:: +*`rsa.misc.event_desc`*:: + -- This key is used to capture a description of an event available directly or inferred @@ -53123,7 +53099,7 @@ type: keyword -- -*`fortinet.rsa.misc.sig_id1`*:: +*`rsa.misc.sig_id1`*:: + -- This key captures IDS/IPS Int Signature ID. This must be linked to the sig.id @@ -53132,42 +53108,42 @@ type: long -- -*`fortinet.rsa.misc.im_buddyid`*:: +*`rsa.misc.im_buddyid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_client`*:: +*`rsa.misc.im_client`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_userid`*:: +*`rsa.misc.im_userid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.pid`*:: +*`rsa.misc.pid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.priority`*:: +*`rsa.misc.priority`*:: + -- type: keyword -- -*`fortinet.rsa.misc.context_subject`*:: +*`rsa.misc.context_subject`*:: + -- This key is to be used in an audit context where the subject is the object being identified @@ -53176,14 +53152,14 @@ type: keyword -- -*`fortinet.rsa.misc.context_target`*:: +*`rsa.misc.context_target`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cve`*:: +*`rsa.misc.cve`*:: + -- This key captures CVE (Common Vulnerabilities and Exposures) - an identifier for known information security vulnerabilities. @@ -53192,7 +53168,7 @@ type: keyword -- -*`fortinet.rsa.misc.fcatnum`*:: +*`rsa.misc.fcatnum`*:: + -- This key captures Filter Category Number. Legacy Usage @@ -53201,7 +53177,7 @@ type: keyword -- -*`fortinet.rsa.misc.library`*:: +*`rsa.misc.library`*:: + -- This key is used to capture library information in mainframe devices @@ -53210,7 +53186,7 @@ type: keyword -- -*`fortinet.rsa.misc.parent_node`*:: +*`rsa.misc.parent_node`*:: + -- This key captures the Parent Node Name. Must be related to node variable. @@ -53219,7 +53195,7 @@ type: keyword -- -*`fortinet.rsa.misc.risk_info`*:: +*`rsa.misc.risk_info`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -53228,7 +53204,7 @@ type: keyword -- -*`fortinet.rsa.misc.tcp_flags`*:: +*`rsa.misc.tcp_flags`*:: + -- This key is captures the TCP flags set in any packet of session @@ -53237,7 +53213,7 @@ type: long -- -*`fortinet.rsa.misc.tos`*:: +*`rsa.misc.tos`*:: + -- This key describes the type of service @@ -53246,7 +53222,7 @@ type: long -- -*`fortinet.rsa.misc.vm_target`*:: +*`rsa.misc.vm_target`*:: + -- VMWare Target **VMWARE** only varaible. @@ -53255,7 +53231,7 @@ type: keyword -- -*`fortinet.rsa.misc.workspace`*:: +*`rsa.misc.workspace`*:: + -- This key captures Workspace Description @@ -53264,91 +53240,91 @@ type: keyword -- -*`fortinet.rsa.misc.command`*:: +*`rsa.misc.command`*:: + -- type: keyword -- -*`fortinet.rsa.misc.event_category`*:: +*`rsa.misc.event_category`*:: + -- type: keyword -- -*`fortinet.rsa.misc.facilityname`*:: +*`rsa.misc.facilityname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.forensic_info`*:: +*`rsa.misc.forensic_info`*:: + -- type: keyword -- -*`fortinet.rsa.misc.jobname`*:: +*`rsa.misc.jobname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.mode`*:: +*`rsa.misc.mode`*:: + -- type: keyword -- -*`fortinet.rsa.misc.policy`*:: +*`rsa.misc.policy`*:: + -- type: keyword -- -*`fortinet.rsa.misc.policy_waiver`*:: +*`rsa.misc.policy_waiver`*:: + -- type: keyword -- -*`fortinet.rsa.misc.second`*:: +*`rsa.misc.second`*:: + -- type: keyword -- -*`fortinet.rsa.misc.space1`*:: +*`rsa.misc.space1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.subcategory`*:: +*`rsa.misc.subcategory`*:: + -- type: keyword -- -*`fortinet.rsa.misc.tbdstr2`*:: +*`rsa.misc.tbdstr2`*:: + -- type: keyword -- -*`fortinet.rsa.misc.alert_id`*:: +*`rsa.misc.alert_id`*:: + -- Deprecated, New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -53357,7 +53333,7 @@ type: keyword -- -*`fortinet.rsa.misc.checksum_dst`*:: +*`rsa.misc.checksum_dst`*:: + -- This key is used to capture the checksum or hash of the the target entity such as a process or file. @@ -53366,7 +53342,7 @@ type: keyword -- -*`fortinet.rsa.misc.checksum_src`*:: +*`rsa.misc.checksum_src`*:: + -- This key is used to capture the checksum or hash of the source entity such as a file or process. @@ -53375,7 +53351,7 @@ type: keyword -- -*`fortinet.rsa.misc.fresult`*:: +*`rsa.misc.fresult`*:: + -- This key captures the Filter Result @@ -53384,7 +53360,7 @@ type: long -- -*`fortinet.rsa.misc.payload_dst`*:: +*`rsa.misc.payload_dst`*:: + -- This key is used to capture destination payload @@ -53393,7 +53369,7 @@ type: keyword -- -*`fortinet.rsa.misc.payload_src`*:: +*`rsa.misc.payload_src`*:: + -- This key is used to capture source payload @@ -53402,7 +53378,7 @@ type: keyword -- -*`fortinet.rsa.misc.pool_id`*:: +*`rsa.misc.pool_id`*:: + -- This key captures the identifier (typically numeric field) of a resource pool @@ -53411,7 +53387,7 @@ type: keyword -- -*`fortinet.rsa.misc.process_id_val`*:: +*`rsa.misc.process_id_val`*:: + -- This key is a failure key for Process ID when it is not an integer value @@ -53420,7 +53396,7 @@ type: keyword -- -*`fortinet.rsa.misc.risk_num_comm`*:: +*`rsa.misc.risk_num_comm`*:: + -- This key captures Risk Number Community @@ -53429,7 +53405,7 @@ type: double -- -*`fortinet.rsa.misc.risk_num_next`*:: +*`rsa.misc.risk_num_next`*:: + -- This key captures Risk Number NextGen @@ -53438,7 +53414,7 @@ type: double -- -*`fortinet.rsa.misc.risk_num_sand`*:: +*`rsa.misc.risk_num_sand`*:: + -- This key captures Risk Number SandBox @@ -53447,7 +53423,7 @@ type: double -- -*`fortinet.rsa.misc.risk_num_static`*:: +*`rsa.misc.risk_num_static`*:: + -- This key captures Risk Number Static @@ -53456,7 +53432,7 @@ type: double -- -*`fortinet.rsa.misc.risk_suspicious`*:: +*`rsa.misc.risk_suspicious`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -53465,7 +53441,7 @@ type: keyword -- -*`fortinet.rsa.misc.risk_warning`*:: +*`rsa.misc.risk_warning`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -53474,7 +53450,7 @@ type: keyword -- -*`fortinet.rsa.misc.snmp_oid`*:: +*`rsa.misc.snmp_oid`*:: + -- SNMP Object Identifier @@ -53483,7 +53459,7 @@ type: keyword -- -*`fortinet.rsa.misc.sql`*:: +*`rsa.misc.sql`*:: + -- This key captures the SQL query @@ -53492,7 +53468,7 @@ type: keyword -- -*`fortinet.rsa.misc.vuln_ref`*:: +*`rsa.misc.vuln_ref`*:: + -- This key captures the Vulnerability Reference details @@ -53501,1547 +53477,1547 @@ type: keyword -- -*`fortinet.rsa.misc.acl_id`*:: +*`rsa.misc.acl_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.acl_op`*:: +*`rsa.misc.acl_op`*:: + -- type: keyword -- -*`fortinet.rsa.misc.acl_pos`*:: +*`rsa.misc.acl_pos`*:: + -- type: keyword -- -*`fortinet.rsa.misc.acl_table`*:: +*`rsa.misc.acl_table`*:: + -- type: keyword -- -*`fortinet.rsa.misc.admin`*:: +*`rsa.misc.admin`*:: + -- type: keyword -- -*`fortinet.rsa.misc.alarm_id`*:: +*`rsa.misc.alarm_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.alarmname`*:: +*`rsa.misc.alarmname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.app_id`*:: +*`rsa.misc.app_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.audit`*:: +*`rsa.misc.audit`*:: + -- type: keyword -- -*`fortinet.rsa.misc.audit_object`*:: +*`rsa.misc.audit_object`*:: + -- type: keyword -- -*`fortinet.rsa.misc.auditdata`*:: +*`rsa.misc.auditdata`*:: + -- type: keyword -- -*`fortinet.rsa.misc.benchmark`*:: +*`rsa.misc.benchmark`*:: + -- type: keyword -- -*`fortinet.rsa.misc.bypass`*:: +*`rsa.misc.bypass`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cache`*:: +*`rsa.misc.cache`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cache_hit`*:: +*`rsa.misc.cache_hit`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cefversion`*:: +*`rsa.misc.cefversion`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cfg_attr`*:: +*`rsa.misc.cfg_attr`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cfg_obj`*:: +*`rsa.misc.cfg_obj`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cfg_path`*:: +*`rsa.misc.cfg_path`*:: + -- type: keyword -- -*`fortinet.rsa.misc.changes`*:: +*`rsa.misc.changes`*:: + -- type: keyword -- -*`fortinet.rsa.misc.client_ip`*:: +*`rsa.misc.client_ip`*:: + -- type: keyword -- -*`fortinet.rsa.misc.clustermembers`*:: +*`rsa.misc.clustermembers`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_acttimeout`*:: +*`rsa.misc.cn_acttimeout`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_asn_src`*:: +*`rsa.misc.cn_asn_src`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_bgpv4nxthop`*:: +*`rsa.misc.cn_bgpv4nxthop`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_ctr_dst_code`*:: +*`rsa.misc.cn_ctr_dst_code`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_dst_tos`*:: +*`rsa.misc.cn_dst_tos`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_dst_vlan`*:: +*`rsa.misc.cn_dst_vlan`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_engine_id`*:: +*`rsa.misc.cn_engine_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_engine_type`*:: +*`rsa.misc.cn_engine_type`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_f_switch`*:: +*`rsa.misc.cn_f_switch`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_flowsampid`*:: +*`rsa.misc.cn_flowsampid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_flowsampintv`*:: +*`rsa.misc.cn_flowsampintv`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_flowsampmode`*:: +*`rsa.misc.cn_flowsampmode`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_inacttimeout`*:: +*`rsa.misc.cn_inacttimeout`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_inpermbyts`*:: +*`rsa.misc.cn_inpermbyts`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_inpermpckts`*:: +*`rsa.misc.cn_inpermpckts`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_invalid`*:: +*`rsa.misc.cn_invalid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_ip_proto_ver`*:: +*`rsa.misc.cn_ip_proto_ver`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_ipv4_ident`*:: +*`rsa.misc.cn_ipv4_ident`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_l_switch`*:: +*`rsa.misc.cn_l_switch`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_log_did`*:: +*`rsa.misc.cn_log_did`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_log_rid`*:: +*`rsa.misc.cn_log_rid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_max_ttl`*:: +*`rsa.misc.cn_max_ttl`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_maxpcktlen`*:: +*`rsa.misc.cn_maxpcktlen`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_min_ttl`*:: +*`rsa.misc.cn_min_ttl`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_minpcktlen`*:: +*`rsa.misc.cn_minpcktlen`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_1`*:: +*`rsa.misc.cn_mpls_lbl_1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_10`*:: +*`rsa.misc.cn_mpls_lbl_10`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_2`*:: +*`rsa.misc.cn_mpls_lbl_2`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_3`*:: +*`rsa.misc.cn_mpls_lbl_3`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_4`*:: +*`rsa.misc.cn_mpls_lbl_4`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_5`*:: +*`rsa.misc.cn_mpls_lbl_5`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_6`*:: +*`rsa.misc.cn_mpls_lbl_6`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_7`*:: +*`rsa.misc.cn_mpls_lbl_7`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_8`*:: +*`rsa.misc.cn_mpls_lbl_8`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mpls_lbl_9`*:: +*`rsa.misc.cn_mpls_lbl_9`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mplstoplabel`*:: +*`rsa.misc.cn_mplstoplabel`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mplstoplabip`*:: +*`rsa.misc.cn_mplstoplabip`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mul_dst_byt`*:: +*`rsa.misc.cn_mul_dst_byt`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_mul_dst_pks`*:: +*`rsa.misc.cn_mul_dst_pks`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_muligmptype`*:: +*`rsa.misc.cn_muligmptype`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_sampalgo`*:: +*`rsa.misc.cn_sampalgo`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_sampint`*:: +*`rsa.misc.cn_sampint`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_seqctr`*:: +*`rsa.misc.cn_seqctr`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_spackets`*:: +*`rsa.misc.cn_spackets`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_src_tos`*:: +*`rsa.misc.cn_src_tos`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_src_vlan`*:: +*`rsa.misc.cn_src_vlan`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_sysuptime`*:: +*`rsa.misc.cn_sysuptime`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_template_id`*:: +*`rsa.misc.cn_template_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_totbytsexp`*:: +*`rsa.misc.cn_totbytsexp`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_totflowexp`*:: +*`rsa.misc.cn_totflowexp`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_totpcktsexp`*:: +*`rsa.misc.cn_totpcktsexp`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_unixnanosecs`*:: +*`rsa.misc.cn_unixnanosecs`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_v6flowlabel`*:: +*`rsa.misc.cn_v6flowlabel`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cn_v6optheaders`*:: +*`rsa.misc.cn_v6optheaders`*:: + -- type: keyword -- -*`fortinet.rsa.misc.comp_class`*:: +*`rsa.misc.comp_class`*:: + -- type: keyword -- -*`fortinet.rsa.misc.comp_name`*:: +*`rsa.misc.comp_name`*:: + -- type: keyword -- -*`fortinet.rsa.misc.comp_rbytes`*:: +*`rsa.misc.comp_rbytes`*:: + -- type: keyword -- -*`fortinet.rsa.misc.comp_sbytes`*:: +*`rsa.misc.comp_sbytes`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cpu_data`*:: +*`rsa.misc.cpu_data`*:: + -- type: keyword -- -*`fortinet.rsa.misc.criticality`*:: +*`rsa.misc.criticality`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_agency_dst`*:: +*`rsa.misc.cs_agency_dst`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_analyzedby`*:: +*`rsa.misc.cs_analyzedby`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_av_other`*:: +*`rsa.misc.cs_av_other`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_av_primary`*:: +*`rsa.misc.cs_av_primary`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_av_secondary`*:: +*`rsa.misc.cs_av_secondary`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_bgpv6nxthop`*:: +*`rsa.misc.cs_bgpv6nxthop`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_bit9status`*:: +*`rsa.misc.cs_bit9status`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_context`*:: +*`rsa.misc.cs_context`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_control`*:: +*`rsa.misc.cs_control`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_data`*:: +*`rsa.misc.cs_data`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_datecret`*:: +*`rsa.misc.cs_datecret`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_dst_tld`*:: +*`rsa.misc.cs_dst_tld`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_eth_dst_ven`*:: +*`rsa.misc.cs_eth_dst_ven`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_eth_src_ven`*:: +*`rsa.misc.cs_eth_src_ven`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_event_uuid`*:: +*`rsa.misc.cs_event_uuid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_filetype`*:: +*`rsa.misc.cs_filetype`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_fld`*:: +*`rsa.misc.cs_fld`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_if_desc`*:: +*`rsa.misc.cs_if_desc`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_if_name`*:: +*`rsa.misc.cs_if_name`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_ip_next_hop`*:: +*`rsa.misc.cs_ip_next_hop`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_ipv4dstpre`*:: +*`rsa.misc.cs_ipv4dstpre`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_ipv4srcpre`*:: +*`rsa.misc.cs_ipv4srcpre`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_lifetime`*:: +*`rsa.misc.cs_lifetime`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_log_medium`*:: +*`rsa.misc.cs_log_medium`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_loginname`*:: +*`rsa.misc.cs_loginname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_modulescore`*:: +*`rsa.misc.cs_modulescore`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_modulesign`*:: +*`rsa.misc.cs_modulesign`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_opswatresult`*:: +*`rsa.misc.cs_opswatresult`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_payload`*:: +*`rsa.misc.cs_payload`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_registrant`*:: +*`rsa.misc.cs_registrant`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_registrar`*:: +*`rsa.misc.cs_registrar`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_represult`*:: +*`rsa.misc.cs_represult`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_rpayload`*:: +*`rsa.misc.cs_rpayload`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_sampler_name`*:: +*`rsa.misc.cs_sampler_name`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_sourcemodule`*:: +*`rsa.misc.cs_sourcemodule`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_streams`*:: +*`rsa.misc.cs_streams`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_targetmodule`*:: +*`rsa.misc.cs_targetmodule`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_v6nxthop`*:: +*`rsa.misc.cs_v6nxthop`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_whois_server`*:: +*`rsa.misc.cs_whois_server`*:: + -- type: keyword -- -*`fortinet.rsa.misc.cs_yararesult`*:: +*`rsa.misc.cs_yararesult`*:: + -- type: keyword -- -*`fortinet.rsa.misc.description`*:: +*`rsa.misc.description`*:: + -- type: keyword -- -*`fortinet.rsa.misc.devvendor`*:: +*`rsa.misc.devvendor`*:: + -- type: keyword -- -*`fortinet.rsa.misc.distance`*:: +*`rsa.misc.distance`*:: + -- type: keyword -- -*`fortinet.rsa.misc.dstburb`*:: +*`rsa.misc.dstburb`*:: + -- type: keyword -- -*`fortinet.rsa.misc.edomain`*:: +*`rsa.misc.edomain`*:: + -- type: keyword -- -*`fortinet.rsa.misc.edomaub`*:: +*`rsa.misc.edomaub`*:: + -- type: keyword -- -*`fortinet.rsa.misc.euid`*:: +*`rsa.misc.euid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.facility`*:: +*`rsa.misc.facility`*:: + -- type: keyword -- -*`fortinet.rsa.misc.finterface`*:: +*`rsa.misc.finterface`*:: + -- type: keyword -- -*`fortinet.rsa.misc.flags`*:: +*`rsa.misc.flags`*:: + -- type: keyword -- -*`fortinet.rsa.misc.gaddr`*:: +*`rsa.misc.gaddr`*:: + -- type: keyword -- -*`fortinet.rsa.misc.id3`*:: +*`rsa.misc.id3`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_buddyname`*:: +*`rsa.misc.im_buddyname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_croomid`*:: +*`rsa.misc.im_croomid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_croomtype`*:: +*`rsa.misc.im_croomtype`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_members`*:: +*`rsa.misc.im_members`*:: + -- type: keyword -- -*`fortinet.rsa.misc.im_username`*:: +*`rsa.misc.im_username`*:: + -- type: keyword -- -*`fortinet.rsa.misc.ipkt`*:: +*`rsa.misc.ipkt`*:: + -- type: keyword -- -*`fortinet.rsa.misc.ipscat`*:: +*`rsa.misc.ipscat`*:: + -- type: keyword -- -*`fortinet.rsa.misc.ipspri`*:: +*`rsa.misc.ipspri`*:: + -- type: keyword -- -*`fortinet.rsa.misc.latitude`*:: +*`rsa.misc.latitude`*:: + -- type: keyword -- -*`fortinet.rsa.misc.linenum`*:: +*`rsa.misc.linenum`*:: + -- type: keyword -- -*`fortinet.rsa.misc.list_name`*:: +*`rsa.misc.list_name`*:: + -- type: keyword -- -*`fortinet.rsa.misc.load_data`*:: +*`rsa.misc.load_data`*:: + -- type: keyword -- -*`fortinet.rsa.misc.location_floor`*:: +*`rsa.misc.location_floor`*:: + -- type: keyword -- -*`fortinet.rsa.misc.location_mark`*:: +*`rsa.misc.location_mark`*:: + -- type: keyword -- -*`fortinet.rsa.misc.log_id`*:: +*`rsa.misc.log_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.log_type`*:: +*`rsa.misc.log_type`*:: + -- type: keyword -- -*`fortinet.rsa.misc.logid`*:: +*`rsa.misc.logid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.logip`*:: +*`rsa.misc.logip`*:: + -- type: keyword -- -*`fortinet.rsa.misc.logname`*:: +*`rsa.misc.logname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.longitude`*:: +*`rsa.misc.longitude`*:: + -- type: keyword -- -*`fortinet.rsa.misc.lport`*:: +*`rsa.misc.lport`*:: + -- type: keyword -- -*`fortinet.rsa.misc.mbug_data`*:: +*`rsa.misc.mbug_data`*:: + -- type: keyword -- -*`fortinet.rsa.misc.misc_name`*:: +*`rsa.misc.misc_name`*:: + -- type: keyword -- -*`fortinet.rsa.misc.msg_type`*:: +*`rsa.misc.msg_type`*:: + -- type: keyword -- -*`fortinet.rsa.misc.msgid`*:: +*`rsa.misc.msgid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.netsessid`*:: +*`rsa.misc.netsessid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.num`*:: +*`rsa.misc.num`*:: + -- type: keyword -- -*`fortinet.rsa.misc.number1`*:: +*`rsa.misc.number1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.number2`*:: +*`rsa.misc.number2`*:: + -- type: keyword -- -*`fortinet.rsa.misc.nwwn`*:: +*`rsa.misc.nwwn`*:: + -- type: keyword -- -*`fortinet.rsa.misc.object`*:: +*`rsa.misc.object`*:: + -- type: keyword -- -*`fortinet.rsa.misc.operation`*:: +*`rsa.misc.operation`*:: + -- type: keyword -- -*`fortinet.rsa.misc.opkt`*:: +*`rsa.misc.opkt`*:: + -- type: keyword -- -*`fortinet.rsa.misc.orig_from`*:: +*`rsa.misc.orig_from`*:: + -- type: keyword -- -*`fortinet.rsa.misc.owner_id`*:: +*`rsa.misc.owner_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_action`*:: +*`rsa.misc.p_action`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_filter`*:: +*`rsa.misc.p_filter`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_group_object`*:: +*`rsa.misc.p_group_object`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_id`*:: +*`rsa.misc.p_id`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_msgid1`*:: +*`rsa.misc.p_msgid1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_msgid2`*:: +*`rsa.misc.p_msgid2`*:: + -- type: keyword -- -*`fortinet.rsa.misc.p_result1`*:: +*`rsa.misc.p_result1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.password_chg`*:: +*`rsa.misc.password_chg`*:: + -- type: keyword -- -*`fortinet.rsa.misc.password_expire`*:: +*`rsa.misc.password_expire`*:: + -- type: keyword -- -*`fortinet.rsa.misc.permgranted`*:: +*`rsa.misc.permgranted`*:: + -- type: keyword -- -*`fortinet.rsa.misc.permwanted`*:: +*`rsa.misc.permwanted`*:: + -- type: keyword -- -*`fortinet.rsa.misc.pgid`*:: +*`rsa.misc.pgid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.policyUUID`*:: +*`rsa.misc.policyUUID`*:: + -- type: keyword -- -*`fortinet.rsa.misc.prog_asp_num`*:: +*`rsa.misc.prog_asp_num`*:: + -- type: keyword -- -*`fortinet.rsa.misc.program`*:: +*`rsa.misc.program`*:: + -- type: keyword -- -*`fortinet.rsa.misc.real_data`*:: +*`rsa.misc.real_data`*:: + -- type: keyword -- -*`fortinet.rsa.misc.rec_asp_device`*:: +*`rsa.misc.rec_asp_device`*:: + -- type: keyword -- -*`fortinet.rsa.misc.rec_asp_num`*:: +*`rsa.misc.rec_asp_num`*:: + -- type: keyword -- -*`fortinet.rsa.misc.rec_library`*:: +*`rsa.misc.rec_library`*:: + -- type: keyword -- -*`fortinet.rsa.misc.recordnum`*:: +*`rsa.misc.recordnum`*:: + -- type: keyword -- -*`fortinet.rsa.misc.ruid`*:: +*`rsa.misc.ruid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sburb`*:: +*`rsa.misc.sburb`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sdomain_fld`*:: +*`rsa.misc.sdomain_fld`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sec`*:: +*`rsa.misc.sec`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sensorname`*:: +*`rsa.misc.sensorname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.seqnum`*:: +*`rsa.misc.seqnum`*:: + -- type: keyword -- -*`fortinet.rsa.misc.session`*:: +*`rsa.misc.session`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sessiontype`*:: +*`rsa.misc.sessiontype`*:: + -- type: keyword -- -*`fortinet.rsa.misc.sigUUID`*:: +*`rsa.misc.sigUUID`*:: + -- type: keyword -- -*`fortinet.rsa.misc.spi`*:: +*`rsa.misc.spi`*:: + -- type: keyword -- -*`fortinet.rsa.misc.srcburb`*:: +*`rsa.misc.srcburb`*:: + -- type: keyword -- -*`fortinet.rsa.misc.srcdom`*:: +*`rsa.misc.srcdom`*:: + -- type: keyword -- -*`fortinet.rsa.misc.srcservice`*:: +*`rsa.misc.srcservice`*:: + -- type: keyword -- -*`fortinet.rsa.misc.state`*:: +*`rsa.misc.state`*:: + -- type: keyword -- -*`fortinet.rsa.misc.status1`*:: +*`rsa.misc.status1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.svcno`*:: +*`rsa.misc.svcno`*:: + -- type: keyword -- -*`fortinet.rsa.misc.system`*:: +*`rsa.misc.system`*:: + -- type: keyword -- -*`fortinet.rsa.misc.tbdstr1`*:: +*`rsa.misc.tbdstr1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.tgtdom`*:: +*`rsa.misc.tgtdom`*:: + -- type: keyword -- -*`fortinet.rsa.misc.tgtdomain`*:: +*`rsa.misc.tgtdomain`*:: + -- type: keyword -- -*`fortinet.rsa.misc.threshold`*:: +*`rsa.misc.threshold`*:: + -- type: keyword -- -*`fortinet.rsa.misc.type1`*:: +*`rsa.misc.type1`*:: + -- type: keyword -- -*`fortinet.rsa.misc.udb_class`*:: +*`rsa.misc.udb_class`*:: + -- type: keyword -- -*`fortinet.rsa.misc.url_fld`*:: +*`rsa.misc.url_fld`*:: + -- type: keyword -- -*`fortinet.rsa.misc.user_div`*:: +*`rsa.misc.user_div`*:: + -- type: keyword -- -*`fortinet.rsa.misc.userid`*:: +*`rsa.misc.userid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.username_fld`*:: +*`rsa.misc.username_fld`*:: + -- type: keyword -- -*`fortinet.rsa.misc.utcstamp`*:: +*`rsa.misc.utcstamp`*:: + -- type: keyword -- -*`fortinet.rsa.misc.v_instafname`*:: +*`rsa.misc.v_instafname`*:: + -- type: keyword -- -*`fortinet.rsa.misc.virt_data`*:: +*`rsa.misc.virt_data`*:: + -- type: keyword -- -*`fortinet.rsa.misc.vpnid`*:: +*`rsa.misc.vpnid`*:: + -- type: keyword -- -*`fortinet.rsa.misc.autorun_type`*:: +*`rsa.misc.autorun_type`*:: + -- This is used to capture Auto Run type @@ -55050,7 +55026,7 @@ type: keyword -- -*`fortinet.rsa.misc.cc_number`*:: +*`rsa.misc.cc_number`*:: + -- Valid Credit Card Numbers only @@ -55059,7 +55035,7 @@ type: long -- -*`fortinet.rsa.misc.content`*:: +*`rsa.misc.content`*:: + -- This key captures the content type from protocol headers @@ -55068,7 +55044,7 @@ type: keyword -- -*`fortinet.rsa.misc.ein_number`*:: +*`rsa.misc.ein_number`*:: + -- Employee Identification Numbers only @@ -55077,7 +55053,7 @@ type: long -- -*`fortinet.rsa.misc.found`*:: +*`rsa.misc.found`*:: + -- This is used to capture the results of regex match @@ -55086,7 +55062,7 @@ type: keyword -- -*`fortinet.rsa.misc.language`*:: +*`rsa.misc.language`*:: + -- This is used to capture list of languages the client support and what it prefers @@ -55095,7 +55071,7 @@ type: keyword -- -*`fortinet.rsa.misc.lifetime`*:: +*`rsa.misc.lifetime`*:: + -- This key is used to capture the session lifetime in seconds. @@ -55104,7 +55080,7 @@ type: long -- -*`fortinet.rsa.misc.link`*:: +*`rsa.misc.link`*:: + -- This key is used to link the sessions together. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -55113,7 +55089,7 @@ type: keyword -- -*`fortinet.rsa.misc.match`*:: +*`rsa.misc.match`*:: + -- This key is for regex match name from search.ini @@ -55122,7 +55098,7 @@ type: keyword -- -*`fortinet.rsa.misc.param_dst`*:: +*`rsa.misc.param_dst`*:: + -- This key captures the command line/launch argument of the target process or file @@ -55131,7 +55107,7 @@ type: keyword -- -*`fortinet.rsa.misc.param_src`*:: +*`rsa.misc.param_src`*:: + -- This key captures source parameter @@ -55140,7 +55116,7 @@ type: keyword -- -*`fortinet.rsa.misc.search_text`*:: +*`rsa.misc.search_text`*:: + -- This key captures the Search Text used @@ -55149,7 +55125,7 @@ type: keyword -- -*`fortinet.rsa.misc.sig_name`*:: +*`rsa.misc.sig_name`*:: + -- This key is used to capture the Signature Name only. @@ -55158,7 +55134,7 @@ type: keyword -- -*`fortinet.rsa.misc.snmp_value`*:: +*`rsa.misc.snmp_value`*:: + -- SNMP set request value @@ -55167,7 +55143,7 @@ type: keyword -- -*`fortinet.rsa.misc.streams`*:: +*`rsa.misc.streams`*:: + -- This key captures number of streams in session @@ -55177,7 +55153,7 @@ type: long -- -*`fortinet.rsa.db.index`*:: +*`rsa.db.index`*:: + -- This key captures IndexID of the index. @@ -55186,7 +55162,7 @@ type: keyword -- -*`fortinet.rsa.db.instance`*:: +*`rsa.db.instance`*:: + -- This key is used to capture the database server instance name @@ -55195,7 +55171,7 @@ type: keyword -- -*`fortinet.rsa.db.database`*:: +*`rsa.db.database`*:: + -- This key is used to capture the name of a database or an instance as seen in a session @@ -55204,7 +55180,7 @@ type: keyword -- -*`fortinet.rsa.db.transact_id`*:: +*`rsa.db.transact_id`*:: + -- This key captures the SQL transantion ID of the current session @@ -55213,7 +55189,7 @@ type: keyword -- -*`fortinet.rsa.db.permissions`*:: +*`rsa.db.permissions`*:: + -- This key captures permission or privilege level assigned to a resource. @@ -55222,7 +55198,7 @@ type: keyword -- -*`fortinet.rsa.db.table_name`*:: +*`rsa.db.table_name`*:: + -- This key is used to capture the table name @@ -55231,7 +55207,7 @@ type: keyword -- -*`fortinet.rsa.db.db_id`*:: +*`rsa.db.db_id`*:: + -- This key is used to capture the unique identifier for a database @@ -55240,7 +55216,7 @@ type: keyword -- -*`fortinet.rsa.db.db_pid`*:: +*`rsa.db.db_pid`*:: + -- This key captures the process id of a connection with database server @@ -55249,7 +55225,7 @@ type: long -- -*`fortinet.rsa.db.lread`*:: +*`rsa.db.lread`*:: + -- This key is used for the number of logical reads @@ -55258,7 +55234,7 @@ type: long -- -*`fortinet.rsa.db.lwrite`*:: +*`rsa.db.lwrite`*:: + -- This key is used for the number of logical writes @@ -55267,7 +55243,7 @@ type: long -- -*`fortinet.rsa.db.pread`*:: +*`rsa.db.pread`*:: + -- This key is used for the number of physical writes @@ -55277,7 +55253,7 @@ type: long -- -*`fortinet.rsa.network.alias_host`*:: +*`rsa.network.alias_host`*:: + -- This key should be used when the source or destination context of a hostname is not clear.Also it captures the Device Hostname. Any Hostname that isnt ad.computer. @@ -55286,14 +55262,14 @@ type: keyword -- -*`fortinet.rsa.network.domain`*:: +*`rsa.network.domain`*:: + -- type: keyword -- -*`fortinet.rsa.network.host_dst`*:: +*`rsa.network.host_dst`*:: + -- This key should only be used when it’s a Destination Hostname @@ -55302,7 +55278,7 @@ type: keyword -- -*`fortinet.rsa.network.network_service`*:: +*`rsa.network.network_service`*:: + -- This is used to capture layer 7 protocols/service names @@ -55311,7 +55287,7 @@ type: keyword -- -*`fortinet.rsa.network.interface`*:: +*`rsa.network.interface`*:: + -- This key should be used when the source or destination context of an interface is not clear @@ -55320,7 +55296,7 @@ type: keyword -- -*`fortinet.rsa.network.network_port`*:: +*`rsa.network.network_port`*:: + -- Deprecated, use port. NOTE: There is a type discrepancy as currently used, TM: Int32, INDEX: UInt64 (why neither chose the correct UInt16?!) @@ -55329,7 +55305,7 @@ type: long -- -*`fortinet.rsa.network.eth_host`*:: +*`rsa.network.eth_host`*:: + -- Deprecated, use alias.mac @@ -55338,7 +55314,7 @@ type: keyword -- -*`fortinet.rsa.network.sinterface`*:: +*`rsa.network.sinterface`*:: + -- This key should only be used when it’s a Source Interface @@ -55347,7 +55323,7 @@ type: keyword -- -*`fortinet.rsa.network.dinterface`*:: +*`rsa.network.dinterface`*:: + -- This key should only be used when it’s a Destination Interface @@ -55356,7 +55332,7 @@ type: keyword -- -*`fortinet.rsa.network.vlan`*:: +*`rsa.network.vlan`*:: + -- This key should only be used to capture the ID of the Virtual LAN @@ -55365,7 +55341,7 @@ type: long -- -*`fortinet.rsa.network.zone_src`*:: +*`rsa.network.zone_src`*:: + -- This key should only be used when it’s a Source Zone. @@ -55374,7 +55350,7 @@ type: keyword -- -*`fortinet.rsa.network.zone`*:: +*`rsa.network.zone`*:: + -- This key should be used when the source or destination context of a Zone is not clear @@ -55383,7 +55359,7 @@ type: keyword -- -*`fortinet.rsa.network.zone_dst`*:: +*`rsa.network.zone_dst`*:: + -- This key should only be used when it’s a Destination Zone. @@ -55392,7 +55368,7 @@ type: keyword -- -*`fortinet.rsa.network.gateway`*:: +*`rsa.network.gateway`*:: + -- This key is used to capture the IP Address of the gateway @@ -55401,7 +55377,7 @@ type: keyword -- -*`fortinet.rsa.network.icmp_type`*:: +*`rsa.network.icmp_type`*:: + -- This key is used to capture the ICMP type only @@ -55410,7 +55386,7 @@ type: long -- -*`fortinet.rsa.network.mask`*:: +*`rsa.network.mask`*:: + -- This key is used to capture the device network IPmask. @@ -55419,7 +55395,7 @@ type: keyword -- -*`fortinet.rsa.network.icmp_code`*:: +*`rsa.network.icmp_code`*:: + -- This key is used to capture the ICMP code only @@ -55428,7 +55404,7 @@ type: long -- -*`fortinet.rsa.network.protocol_detail`*:: +*`rsa.network.protocol_detail`*:: + -- This key should be used to capture additional protocol information @@ -55437,7 +55413,7 @@ type: keyword -- -*`fortinet.rsa.network.dmask`*:: +*`rsa.network.dmask`*:: + -- This key is used for Destionation Device network mask @@ -55446,7 +55422,7 @@ type: keyword -- -*`fortinet.rsa.network.port`*:: +*`rsa.network.port`*:: + -- This key should only be used to capture a Network Port when the directionality is not clear @@ -55455,7 +55431,7 @@ type: long -- -*`fortinet.rsa.network.smask`*:: +*`rsa.network.smask`*:: + -- This key is used for capturing source Network Mask @@ -55464,7 +55440,7 @@ type: keyword -- -*`fortinet.rsa.network.netname`*:: +*`rsa.network.netname`*:: + -- This key is used to capture the network name associated with an IP range. This is configured by the end user. @@ -55473,7 +55449,7 @@ type: keyword -- -*`fortinet.rsa.network.paddr`*:: +*`rsa.network.paddr`*:: + -- Deprecated @@ -55482,91 +55458,91 @@ type: ip -- -*`fortinet.rsa.network.faddr`*:: +*`rsa.network.faddr`*:: + -- type: keyword -- -*`fortinet.rsa.network.lhost`*:: +*`rsa.network.lhost`*:: + -- type: keyword -- -*`fortinet.rsa.network.origin`*:: +*`rsa.network.origin`*:: + -- type: keyword -- -*`fortinet.rsa.network.remote_domain_id`*:: +*`rsa.network.remote_domain_id`*:: + -- type: keyword -- -*`fortinet.rsa.network.addr`*:: +*`rsa.network.addr`*:: + -- type: keyword -- -*`fortinet.rsa.network.dns_a_record`*:: +*`rsa.network.dns_a_record`*:: + -- type: keyword -- -*`fortinet.rsa.network.dns_ptr_record`*:: +*`rsa.network.dns_ptr_record`*:: + -- type: keyword -- -*`fortinet.rsa.network.fhost`*:: +*`rsa.network.fhost`*:: + -- type: keyword -- -*`fortinet.rsa.network.fport`*:: +*`rsa.network.fport`*:: + -- type: keyword -- -*`fortinet.rsa.network.laddr`*:: +*`rsa.network.laddr`*:: + -- type: keyword -- -*`fortinet.rsa.network.linterface`*:: +*`rsa.network.linterface`*:: + -- type: keyword -- -*`fortinet.rsa.network.phost`*:: +*`rsa.network.phost`*:: + -- type: keyword -- -*`fortinet.rsa.network.ad_computer_dst`*:: +*`rsa.network.ad_computer_dst`*:: + -- Deprecated, use host.dst @@ -55575,7 +55551,7 @@ type: keyword -- -*`fortinet.rsa.network.eth_type`*:: +*`rsa.network.eth_type`*:: + -- This key is used to capture Ethernet Type, Used for Layer 3 Protocols Only @@ -55584,7 +55560,7 @@ type: long -- -*`fortinet.rsa.network.ip_proto`*:: +*`rsa.network.ip_proto`*:: + -- This key should be used to capture the Protocol number, all the protocol nubers are converted into string in UI @@ -55593,63 +55569,63 @@ type: long -- -*`fortinet.rsa.network.dns_cname_record`*:: +*`rsa.network.dns_cname_record`*:: + -- type: keyword -- -*`fortinet.rsa.network.dns_id`*:: +*`rsa.network.dns_id`*:: + -- type: keyword -- -*`fortinet.rsa.network.dns_opcode`*:: +*`rsa.network.dns_opcode`*:: + -- type: keyword -- -*`fortinet.rsa.network.dns_resp`*:: +*`rsa.network.dns_resp`*:: + -- type: keyword -- -*`fortinet.rsa.network.dns_type`*:: +*`rsa.network.dns_type`*:: + -- type: keyword -- -*`fortinet.rsa.network.domain1`*:: +*`rsa.network.domain1`*:: + -- type: keyword -- -*`fortinet.rsa.network.host_type`*:: +*`rsa.network.host_type`*:: + -- type: keyword -- -*`fortinet.rsa.network.packet_length`*:: +*`rsa.network.packet_length`*:: + -- type: keyword -- -*`fortinet.rsa.network.host_orig`*:: +*`rsa.network.host_orig`*:: + -- This is used to capture the original hostname in case of a Forwarding Agent or a Proxy in between. @@ -55658,7 +55634,7 @@ type: keyword -- -*`fortinet.rsa.network.rpayload`*:: +*`rsa.network.rpayload`*:: + -- This key is used to capture the total number of payload bytes seen in the retransmitted packets. @@ -55667,7 +55643,7 @@ type: keyword -- -*`fortinet.rsa.network.vlan_name`*:: +*`rsa.network.vlan_name`*:: + -- This key should only be used to capture the name of the Virtual LAN @@ -55677,7 +55653,7 @@ type: keyword -- -*`fortinet.rsa.investigations.ec_activity`*:: +*`rsa.investigations.ec_activity`*:: + -- This key captures the particular event activity(Ex:Logoff) @@ -55686,7 +55662,7 @@ type: keyword -- -*`fortinet.rsa.investigations.ec_theme`*:: +*`rsa.investigations.ec_theme`*:: + -- This key captures the Theme of a particular Event(Ex:Authentication) @@ -55695,7 +55671,7 @@ type: keyword -- -*`fortinet.rsa.investigations.ec_subject`*:: +*`rsa.investigations.ec_subject`*:: + -- This key captures the Subject of a particular Event(Ex:User) @@ -55704,7 +55680,7 @@ type: keyword -- -*`fortinet.rsa.investigations.ec_outcome`*:: +*`rsa.investigations.ec_outcome`*:: + -- This key captures the outcome of a particular Event(Ex:Success) @@ -55713,7 +55689,7 @@ type: keyword -- -*`fortinet.rsa.investigations.event_cat`*:: +*`rsa.investigations.event_cat`*:: + -- This key captures the Event category number @@ -55722,7 +55698,7 @@ type: long -- -*`fortinet.rsa.investigations.event_cat_name`*:: +*`rsa.investigations.event_cat_name`*:: + -- This key captures the event category name corresponding to the event cat code @@ -55731,7 +55707,7 @@ type: keyword -- -*`fortinet.rsa.investigations.event_vcat`*:: +*`rsa.investigations.event_vcat`*:: + -- This is a vendor supplied category. This should be used in situations where the vendor has adopted their own event_category taxonomy. @@ -55740,7 +55716,7 @@ type: keyword -- -*`fortinet.rsa.investigations.analysis_file`*:: +*`rsa.investigations.analysis_file`*:: + -- This is used to capture all indicators used in a File Analysis. This key should be used to capture an analysis of a file @@ -55749,7 +55725,7 @@ type: keyword -- -*`fortinet.rsa.investigations.analysis_service`*:: +*`rsa.investigations.analysis_service`*:: + -- This is used to capture all indicators used in a Service Analysis. This key should be used to capture an analysis of a service @@ -55758,7 +55734,7 @@ type: keyword -- -*`fortinet.rsa.investigations.analysis_session`*:: +*`rsa.investigations.analysis_session`*:: + -- This is used to capture all indicators used for a Session Analysis. This key should be used to capture an analysis of a session @@ -55767,7 +55743,7 @@ type: keyword -- -*`fortinet.rsa.investigations.boc`*:: +*`rsa.investigations.boc`*:: + -- This is used to capture behaviour of compromise @@ -55776,7 +55752,7 @@ type: keyword -- -*`fortinet.rsa.investigations.eoc`*:: +*`rsa.investigations.eoc`*:: + -- This is used to capture Enablers of Compromise @@ -55785,7 +55761,7 @@ type: keyword -- -*`fortinet.rsa.investigations.inv_category`*:: +*`rsa.investigations.inv_category`*:: + -- This used to capture investigation category @@ -55794,7 +55770,7 @@ type: keyword -- -*`fortinet.rsa.investigations.inv_context`*:: +*`rsa.investigations.inv_context`*:: + -- This used to capture investigation context @@ -55803,7 +55779,7 @@ type: keyword -- -*`fortinet.rsa.investigations.ioc`*:: +*`rsa.investigations.ioc`*:: + -- This is key capture indicator of compromise @@ -55813,7 +55789,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_c1`*:: +*`rsa.counters.dclass_c1`*:: + -- This is a generic counter key that should be used with the label dclass.c1.str only @@ -55822,7 +55798,7 @@ type: long -- -*`fortinet.rsa.counters.dclass_c2`*:: +*`rsa.counters.dclass_c2`*:: + -- This is a generic counter key that should be used with the label dclass.c2.str only @@ -55831,7 +55807,7 @@ type: long -- -*`fortinet.rsa.counters.event_counter`*:: +*`rsa.counters.event_counter`*:: + -- This is used to capture the number of times an event repeated @@ -55840,7 +55816,7 @@ type: long -- -*`fortinet.rsa.counters.dclass_r1`*:: +*`rsa.counters.dclass_r1`*:: + -- This is a generic ratio key that should be used with the label dclass.r1.str only @@ -55849,7 +55825,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_c3`*:: +*`rsa.counters.dclass_c3`*:: + -- This is a generic counter key that should be used with the label dclass.c3.str only @@ -55858,7 +55834,7 @@ type: long -- -*`fortinet.rsa.counters.dclass_c1_str`*:: +*`rsa.counters.dclass_c1_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c1 only @@ -55867,7 +55843,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_c2_str`*:: +*`rsa.counters.dclass_c2_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c2 only @@ -55876,7 +55852,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_r1_str`*:: +*`rsa.counters.dclass_r1_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r1 only @@ -55885,7 +55861,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_r2`*:: +*`rsa.counters.dclass_r2`*:: + -- This is a generic ratio key that should be used with the label dclass.r2.str only @@ -55894,7 +55870,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_c3_str`*:: +*`rsa.counters.dclass_c3_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c3 only @@ -55903,7 +55879,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_r3`*:: +*`rsa.counters.dclass_r3`*:: + -- This is a generic ratio key that should be used with the label dclass.r3.str only @@ -55912,7 +55888,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_r2_str`*:: +*`rsa.counters.dclass_r2_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r2 only @@ -55921,7 +55897,7 @@ type: keyword -- -*`fortinet.rsa.counters.dclass_r3_str`*:: +*`rsa.counters.dclass_r3_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r3 only @@ -55931,7 +55907,7 @@ type: keyword -- -*`fortinet.rsa.identity.auth_method`*:: +*`rsa.identity.auth_method`*:: + -- This key is used to capture authentication methods used only @@ -55940,7 +55916,7 @@ type: keyword -- -*`fortinet.rsa.identity.user_role`*:: +*`rsa.identity.user_role`*:: + -- This key is used to capture the Role of a user only @@ -55949,7 +55925,7 @@ type: keyword -- -*`fortinet.rsa.identity.dn`*:: +*`rsa.identity.dn`*:: + -- X.500 (LDAP) Distinguished Name @@ -55958,7 +55934,7 @@ type: keyword -- -*`fortinet.rsa.identity.logon_type`*:: +*`rsa.identity.logon_type`*:: + -- This key is used to capture the type of logon method used. @@ -55967,7 +55943,7 @@ type: keyword -- -*`fortinet.rsa.identity.profile`*:: +*`rsa.identity.profile`*:: + -- This key is used to capture the user profile @@ -55976,7 +55952,7 @@ type: keyword -- -*`fortinet.rsa.identity.accesses`*:: +*`rsa.identity.accesses`*:: + -- This key is used to capture actual privileges used in accessing an object @@ -55985,7 +55961,7 @@ type: keyword -- -*`fortinet.rsa.identity.realm`*:: +*`rsa.identity.realm`*:: + -- Radius realm or similar grouping of accounts @@ -55994,7 +55970,7 @@ type: keyword -- -*`fortinet.rsa.identity.user_sid_dst`*:: +*`rsa.identity.user_sid_dst`*:: + -- This key captures Destination User Session ID @@ -56003,7 +55979,7 @@ type: keyword -- -*`fortinet.rsa.identity.dn_src`*:: +*`rsa.identity.dn_src`*:: + -- An X.500 (LDAP) Distinguished name that is used in a context that indicates a Source dn @@ -56012,7 +55988,7 @@ type: keyword -- -*`fortinet.rsa.identity.org`*:: +*`rsa.identity.org`*:: + -- This key captures the User organization @@ -56021,7 +55997,7 @@ type: keyword -- -*`fortinet.rsa.identity.dn_dst`*:: +*`rsa.identity.dn_dst`*:: + -- An X.500 (LDAP) Distinguished name that used in a context that indicates a Destination dn @@ -56030,7 +56006,7 @@ type: keyword -- -*`fortinet.rsa.identity.firstname`*:: +*`rsa.identity.firstname`*:: + -- This key is for First Names only, this is used for Healthcare predominantly to capture Patients information @@ -56039,7 +56015,7 @@ type: keyword -- -*`fortinet.rsa.identity.lastname`*:: +*`rsa.identity.lastname`*:: + -- This key is for Last Names only, this is used for Healthcare predominantly to capture Patients information @@ -56048,7 +56024,7 @@ type: keyword -- -*`fortinet.rsa.identity.user_dept`*:: +*`rsa.identity.user_dept`*:: + -- User's Department Names only @@ -56057,7 +56033,7 @@ type: keyword -- -*`fortinet.rsa.identity.user_sid_src`*:: +*`rsa.identity.user_sid_src`*:: + -- This key captures Source User Session ID @@ -56066,7 +56042,7 @@ type: keyword -- -*`fortinet.rsa.identity.federated_sp`*:: +*`rsa.identity.federated_sp`*:: + -- This key is the Federated Service Provider. This is the application requesting authentication. @@ -56075,7 +56051,7 @@ type: keyword -- -*`fortinet.rsa.identity.federated_idp`*:: +*`rsa.identity.federated_idp`*:: + -- This key is the federated Identity Provider. This is the server providing the authentication. @@ -56084,7 +56060,7 @@ type: keyword -- -*`fortinet.rsa.identity.logon_type_desc`*:: +*`rsa.identity.logon_type_desc`*:: + -- This key is used to capture the textual description of an integer logon type as stored in the meta key 'logon.type'. @@ -56093,7 +56069,7 @@ type: keyword -- -*`fortinet.rsa.identity.middlename`*:: +*`rsa.identity.middlename`*:: + -- This key is for Middle Names only, this is used for Healthcare predominantly to capture Patients information @@ -56102,7 +56078,7 @@ type: keyword -- -*`fortinet.rsa.identity.password`*:: +*`rsa.identity.password`*:: + -- This key is for Passwords seen in any session, plain text or encrypted @@ -56111,7 +56087,7 @@ type: keyword -- -*`fortinet.rsa.identity.host_role`*:: +*`rsa.identity.host_role`*:: + -- This key should only be used to capture the role of a Host Machine @@ -56120,7 +56096,7 @@ type: keyword -- -*`fortinet.rsa.identity.ldap`*:: +*`rsa.identity.ldap`*:: + -- This key is for Uninterpreted LDAP values. Ldap Values that don’t have a clear query or response context @@ -56129,7 +56105,7 @@ type: keyword -- -*`fortinet.rsa.identity.ldap_query`*:: +*`rsa.identity.ldap_query`*:: + -- This key is the Search criteria from an LDAP search @@ -56138,7 +56114,7 @@ type: keyword -- -*`fortinet.rsa.identity.ldap_response`*:: +*`rsa.identity.ldap_response`*:: + -- This key is to capture Results from an LDAP search @@ -56147,7 +56123,7 @@ type: keyword -- -*`fortinet.rsa.identity.owner`*:: +*`rsa.identity.owner`*:: + -- This is used to capture username the process or service is running as, the author of the task @@ -56156,7 +56132,7 @@ type: keyword -- -*`fortinet.rsa.identity.service_account`*:: +*`rsa.identity.service_account`*:: + -- This key is a windows specific key, used for capturing name of the account a service (referenced in the event) is running under. Legacy Usage @@ -56166,7 +56142,7 @@ type: keyword -- -*`fortinet.rsa.email.email_dst`*:: +*`rsa.email.email_dst`*:: + -- This key is used to capture the Destination email address only, when the destination context is not clear use email @@ -56175,7 +56151,7 @@ type: keyword -- -*`fortinet.rsa.email.email_src`*:: +*`rsa.email.email_src`*:: + -- This key is used to capture the source email address only, when the source context is not clear use email @@ -56184,7 +56160,7 @@ type: keyword -- -*`fortinet.rsa.email.subject`*:: +*`rsa.email.subject`*:: + -- This key is used to capture the subject string from an Email only. @@ -56193,7 +56169,7 @@ type: keyword -- -*`fortinet.rsa.email.email`*:: +*`rsa.email.email`*:: + -- This key is used to capture a generic email address where the source or destination context is not clear @@ -56202,7 +56178,7 @@ type: keyword -- -*`fortinet.rsa.email.trans_from`*:: +*`rsa.email.trans_from`*:: + -- Deprecated key defined only in table map. @@ -56211,7 +56187,7 @@ type: keyword -- -*`fortinet.rsa.email.trans_to`*:: +*`rsa.email.trans_to`*:: + -- Deprecated key defined only in table map. @@ -56221,7 +56197,7 @@ type: keyword -- -*`fortinet.rsa.file.privilege`*:: +*`rsa.file.privilege`*:: + -- Deprecated, use permissions @@ -56230,7 +56206,7 @@ type: keyword -- -*`fortinet.rsa.file.attachment`*:: +*`rsa.file.attachment`*:: + -- This key captures the attachment file name @@ -56239,14 +56215,14 @@ type: keyword -- -*`fortinet.rsa.file.filesystem`*:: +*`rsa.file.filesystem`*:: + -- type: keyword -- -*`fortinet.rsa.file.binary`*:: +*`rsa.file.binary`*:: + -- Deprecated key defined only in table map. @@ -56255,7 +56231,7 @@ type: keyword -- -*`fortinet.rsa.file.filename_dst`*:: +*`rsa.file.filename_dst`*:: + -- This is used to capture name of the file targeted by the action @@ -56264,7 +56240,7 @@ type: keyword -- -*`fortinet.rsa.file.filename_src`*:: +*`rsa.file.filename_src`*:: + -- This is used to capture name of the parent filename, the file which performed the action @@ -56273,14 +56249,14 @@ type: keyword -- -*`fortinet.rsa.file.filename_tmp`*:: +*`rsa.file.filename_tmp`*:: + -- type: keyword -- -*`fortinet.rsa.file.directory_dst`*:: +*`rsa.file.directory_dst`*:: + -- This key is used to capture the directory of the target process or file @@ -56289,7 +56265,7 @@ type: keyword -- -*`fortinet.rsa.file.directory_src`*:: +*`rsa.file.directory_src`*:: + -- This key is used to capture the directory of the source process or file @@ -56298,7 +56274,7 @@ type: keyword -- -*`fortinet.rsa.file.file_entropy`*:: +*`rsa.file.file_entropy`*:: + -- This is used to capture entropy vale of a file @@ -56307,7 +56283,7 @@ type: double -- -*`fortinet.rsa.file.file_vendor`*:: +*`rsa.file.file_vendor`*:: + -- This is used to capture Company name of file located in version_info @@ -56316,7 +56292,7 @@ type: keyword -- -*`fortinet.rsa.file.task_name`*:: +*`rsa.file.task_name`*:: + -- This is used to capture name of the task @@ -56326,7 +56302,7 @@ type: keyword -- -*`fortinet.rsa.web.fqdn`*:: +*`rsa.web.fqdn`*:: + -- Fully Qualified Domain Names @@ -56335,7 +56311,7 @@ type: keyword -- -*`fortinet.rsa.web.web_cookie`*:: +*`rsa.web.web_cookie`*:: + -- This key is used to capture the Web cookies specifically. @@ -56344,14 +56320,14 @@ type: keyword -- -*`fortinet.rsa.web.alias_host`*:: +*`rsa.web.alias_host`*:: + -- type: keyword -- -*`fortinet.rsa.web.reputation_num`*:: +*`rsa.web.reputation_num`*:: + -- Reputation Number of an entity. Typically used for Web Domains @@ -56360,7 +56336,7 @@ type: double -- -*`fortinet.rsa.web.web_ref_domain`*:: +*`rsa.web.web_ref_domain`*:: + -- Web referer's domain @@ -56369,7 +56345,7 @@ type: keyword -- -*`fortinet.rsa.web.web_ref_query`*:: +*`rsa.web.web_ref_query`*:: + -- This key captures Web referer's query portion of the URL @@ -56378,14 +56354,14 @@ type: keyword -- -*`fortinet.rsa.web.remote_domain`*:: +*`rsa.web.remote_domain`*:: + -- type: keyword -- -*`fortinet.rsa.web.web_ref_page`*:: +*`rsa.web.web_ref_page`*:: + -- This key captures Web referer's page information @@ -56394,7 +56370,7 @@ type: keyword -- -*`fortinet.rsa.web.web_ref_root`*:: +*`rsa.web.web_ref_root`*:: + -- Web referer's root URL path @@ -56403,77 +56379,77 @@ type: keyword -- -*`fortinet.rsa.web.cn_asn_dst`*:: +*`rsa.web.cn_asn_dst`*:: + -- type: keyword -- -*`fortinet.rsa.web.cn_rpackets`*:: +*`rsa.web.cn_rpackets`*:: + -- type: keyword -- -*`fortinet.rsa.web.urlpage`*:: +*`rsa.web.urlpage`*:: + -- type: keyword -- -*`fortinet.rsa.web.urlroot`*:: +*`rsa.web.urlroot`*:: + -- type: keyword -- -*`fortinet.rsa.web.p_url`*:: +*`rsa.web.p_url`*:: + -- type: keyword -- -*`fortinet.rsa.web.p_user_agent`*:: +*`rsa.web.p_user_agent`*:: + -- type: keyword -- -*`fortinet.rsa.web.p_web_cookie`*:: +*`rsa.web.p_web_cookie`*:: + -- type: keyword -- -*`fortinet.rsa.web.p_web_method`*:: +*`rsa.web.p_web_method`*:: + -- type: keyword -- -*`fortinet.rsa.web.p_web_referer`*:: +*`rsa.web.p_web_referer`*:: + -- type: keyword -- -*`fortinet.rsa.web.web_extension_tmp`*:: +*`rsa.web.web_extension_tmp`*:: + -- type: keyword -- -*`fortinet.rsa.web.web_page`*:: +*`rsa.web.web_page`*:: + -- type: keyword @@ -56481,7 +56457,7 @@ type: keyword -- -*`fortinet.rsa.threat.threat_category`*:: +*`rsa.threat.threat_category`*:: + -- This key captures Threat Name/Threat Category/Categorization of alert @@ -56490,7 +56466,7 @@ type: keyword -- -*`fortinet.rsa.threat.threat_desc`*:: +*`rsa.threat.threat_desc`*:: + -- This key is used to capture the threat description from the session directly or inferred @@ -56499,7 +56475,7 @@ type: keyword -- -*`fortinet.rsa.threat.alert`*:: +*`rsa.threat.alert`*:: + -- This key is used to capture name of the alert @@ -56508,7 +56484,7 @@ type: keyword -- -*`fortinet.rsa.threat.threat_source`*:: +*`rsa.threat.threat_source`*:: + -- This key is used to capture source of the threat @@ -56518,7 +56494,7 @@ type: keyword -- -*`fortinet.rsa.crypto.crypto`*:: +*`rsa.crypto.crypto`*:: + -- This key is used to capture the Encryption Type or Encryption Key only @@ -56527,7 +56503,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cipher_src`*:: +*`rsa.crypto.cipher_src`*:: + -- This key is for Source (Client) Cipher @@ -56536,7 +56512,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_subject`*:: +*`rsa.crypto.cert_subject`*:: + -- This key is used to capture the Certificate organization only @@ -56545,7 +56521,7 @@ type: keyword -- -*`fortinet.rsa.crypto.peer`*:: +*`rsa.crypto.peer`*:: + -- This key is for Encryption peer's IP Address @@ -56554,7 +56530,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cipher_size_src`*:: +*`rsa.crypto.cipher_size_src`*:: + -- This key captures Source (Client) Cipher Size @@ -56563,7 +56539,7 @@ type: long -- -*`fortinet.rsa.crypto.ike`*:: +*`rsa.crypto.ike`*:: + -- IKE negotiation phase. @@ -56572,7 +56548,7 @@ type: keyword -- -*`fortinet.rsa.crypto.scheme`*:: +*`rsa.crypto.scheme`*:: + -- This key captures the Encryption scheme used @@ -56581,7 +56557,7 @@ type: keyword -- -*`fortinet.rsa.crypto.peer_id`*:: +*`rsa.crypto.peer_id`*:: + -- This key is for Encryption peer’s identity @@ -56590,7 +56566,7 @@ type: keyword -- -*`fortinet.rsa.crypto.sig_type`*:: +*`rsa.crypto.sig_type`*:: + -- This key captures the Signature Type @@ -56599,14 +56575,14 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_issuer`*:: +*`rsa.crypto.cert_issuer`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.cert_host_name`*:: +*`rsa.crypto.cert_host_name`*:: + -- Deprecated key defined only in table map. @@ -56615,7 +56591,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_error`*:: +*`rsa.crypto.cert_error`*:: + -- This key captures the Certificate Error String @@ -56624,7 +56600,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cipher_dst`*:: +*`rsa.crypto.cipher_dst`*:: + -- This key is for Destination (Server) Cipher @@ -56633,7 +56609,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cipher_size_dst`*:: +*`rsa.crypto.cipher_size_dst`*:: + -- This key captures Destination (Server) Cipher Size @@ -56642,7 +56618,7 @@ type: long -- -*`fortinet.rsa.crypto.ssl_ver_src`*:: +*`rsa.crypto.ssl_ver_src`*:: + -- Deprecated, use version @@ -56651,21 +56627,21 @@ type: keyword -- -*`fortinet.rsa.crypto.d_certauth`*:: +*`rsa.crypto.d_certauth`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.s_certauth`*:: +*`rsa.crypto.s_certauth`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.ike_cookie1`*:: +*`rsa.crypto.ike_cookie1`*:: + -- ID of the negotiation — sent for ISAKMP Phase One @@ -56674,7 +56650,7 @@ type: keyword -- -*`fortinet.rsa.crypto.ike_cookie2`*:: +*`rsa.crypto.ike_cookie2`*:: + -- ID of the negotiation — sent for ISAKMP Phase Two @@ -56683,14 +56659,14 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_checksum`*:: +*`rsa.crypto.cert_checksum`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.cert_host_cat`*:: +*`rsa.crypto.cert_host_cat`*:: + -- This key is used for the hostname category value of a certificate @@ -56699,7 +56675,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_serial`*:: +*`rsa.crypto.cert_serial`*:: + -- This key is used to capture the Certificate serial number only @@ -56708,7 +56684,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_status`*:: +*`rsa.crypto.cert_status`*:: + -- This key captures Certificate validation status @@ -56717,7 +56693,7 @@ type: keyword -- -*`fortinet.rsa.crypto.ssl_ver_dst`*:: +*`rsa.crypto.ssl_ver_dst`*:: + -- Deprecated, use version @@ -56726,35 +56702,35 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_keysize`*:: +*`rsa.crypto.cert_keysize`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.cert_username`*:: +*`rsa.crypto.cert_username`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.https_insact`*:: +*`rsa.crypto.https_insact`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.https_valid`*:: +*`rsa.crypto.https_valid`*:: + -- type: keyword -- -*`fortinet.rsa.crypto.cert_ca`*:: +*`rsa.crypto.cert_ca`*:: + -- This key is used to capture the Certificate signing authority only @@ -56763,7 +56739,7 @@ type: keyword -- -*`fortinet.rsa.crypto.cert_common`*:: +*`rsa.crypto.cert_common`*:: + -- This key is used to capture the Certificate common name only @@ -56773,7 +56749,7 @@ type: keyword -- -*`fortinet.rsa.wireless.wlan_ssid`*:: +*`rsa.wireless.wlan_ssid`*:: + -- This key is used to capture the ssid of a Wireless Session @@ -56782,7 +56758,7 @@ type: keyword -- -*`fortinet.rsa.wireless.access_point`*:: +*`rsa.wireless.access_point`*:: + -- This key is used to capture the access point name. @@ -56791,7 +56767,7 @@ type: keyword -- -*`fortinet.rsa.wireless.wlan_channel`*:: +*`rsa.wireless.wlan_channel`*:: + -- This is used to capture the channel names @@ -56800,7 +56776,7 @@ type: long -- -*`fortinet.rsa.wireless.wlan_name`*:: +*`rsa.wireless.wlan_name`*:: + -- This key captures either WLAN number/name @@ -56810,7 +56786,7 @@ type: keyword -- -*`fortinet.rsa.storage.disk_volume`*:: +*`rsa.storage.disk_volume`*:: + -- A unique name assigned to logical units (volumes) within a physical disk @@ -56819,7 +56795,7 @@ type: keyword -- -*`fortinet.rsa.storage.lun`*:: +*`rsa.storage.lun`*:: + -- Logical Unit Number.This key is a very useful concept in Storage. @@ -56828,7 +56804,7 @@ type: keyword -- -*`fortinet.rsa.storage.pwwn`*:: +*`rsa.storage.pwwn`*:: + -- This uniquely identifies a port on a HBA. @@ -56838,7 +56814,7 @@ type: keyword -- -*`fortinet.rsa.physical.org_dst`*:: +*`rsa.physical.org_dst`*:: + -- This is used to capture the destination organization based on the GEOPIP Maxmind database. @@ -56847,7 +56823,7 @@ type: keyword -- -*`fortinet.rsa.physical.org_src`*:: +*`rsa.physical.org_src`*:: + -- This is used to capture the source organization based on the GEOPIP Maxmind database. @@ -56857,7 +56833,7 @@ type: keyword -- -*`fortinet.rsa.healthcare.patient_fname`*:: +*`rsa.healthcare.patient_fname`*:: + -- This key is for First Names only, this is used for Healthcare predominantly to capture Patients information @@ -56866,7 +56842,7 @@ type: keyword -- -*`fortinet.rsa.healthcare.patient_id`*:: +*`rsa.healthcare.patient_id`*:: + -- This key captures the unique ID for a patient @@ -56875,7 +56851,7 @@ type: keyword -- -*`fortinet.rsa.healthcare.patient_lname`*:: +*`rsa.healthcare.patient_lname`*:: + -- This key is for Last Names only, this is used for Healthcare predominantly to capture Patients information @@ -56884,7 +56860,7 @@ type: keyword -- -*`fortinet.rsa.healthcare.patient_mname`*:: +*`rsa.healthcare.patient_mname`*:: + -- This key is for Middle Names only, this is used for Healthcare predominantly to capture Patients information @@ -56894,7 +56870,7 @@ type: keyword -- -*`fortinet.rsa.endpoint.host_state`*:: +*`rsa.endpoint.host_state`*:: + -- This key is used to capture the current state of the machine, such as blacklisted, infected, firewall disabled and so on @@ -56903,7 +56879,7 @@ type: keyword -- -*`fortinet.rsa.endpoint.registry_key`*:: +*`rsa.endpoint.registry_key`*:: + -- This key captures the path to the registry key @@ -56912,11 +56888,28 @@ type: keyword -- -*`fortinet.rsa.endpoint.registry_value`*:: +*`rsa.endpoint.registry_value`*:: + -- This key captures values or decorators used within a registry entry +type: keyword + +-- + +[float] +=== fortinet + +Fields from fortinet FortiOS + + + +*`fortinet.file.hash.crc32`*:: ++ +-- +CRC32 Hash of file + + type: keyword -- @@ -57081,7 +57074,7 @@ type: keyword *`fortinet.firewall.analyticssubmit`*:: + -- -The flag for analytics submission +The flag for analytics submission type: keyword @@ -58181,7 +58174,7 @@ type: keyword *`fortinet.firewall.ds`*:: + -- -Direction with distribution system +Direction with distribution system type: keyword @@ -58361,7 +58354,7 @@ type: keyword *`fortinet.firewall.eapolcnt`*:: + -- -EAPOL packet count +EAPOL packet count type: integer @@ -58381,7 +58374,7 @@ type: keyword *`fortinet.firewall.encrypt`*:: + -- -Whether the packet is encrypted or not +Whether the packet is encrypted or not type: integer @@ -58461,7 +58454,7 @@ type: keyword *`fortinet.firewall.expiry`*:: + -- -FortiGuard override expiry timestamp +FortiGuard override expiry timestamp type: keyword @@ -60221,7 +60214,7 @@ type: keyword *`fortinet.firewall.shapersentname`*:: + -- -Traffic shaper name for sent traffic +Traffic shaper name for sent traffic type: keyword @@ -60701,7 +60694,7 @@ type: integer *`fortinet.firewall.totalsession`*:: + -- -Total Number of Sessions +Total Number of Sessions type: integer @@ -87213,14 +87206,7 @@ Microsoft Module [float] -=== microsoft - -Fields from Microsoft ATP - - - -[float] -=== defender_atp +=== microsoft.defender_atp Module for ingesting Microsoft Defender ATP. @@ -87396,7 +87382,7 @@ type: keyword -- -*`microsoft.network.interface.name`*:: +*`network.interface.name`*:: + -- Name of the network interface where the traffic has been observed. @@ -87408,7 +87394,7 @@ type: keyword -*`microsoft.rsa.internal.msg`*:: +*`rsa.internal.msg`*:: + -- This key is used to capture the raw message that comes into the Log Decoder @@ -87417,21 +87403,21 @@ type: keyword -- -*`microsoft.rsa.internal.messageid`*:: +*`rsa.internal.messageid`*:: + -- type: keyword -- -*`microsoft.rsa.internal.event_desc`*:: +*`rsa.internal.event_desc`*:: + -- type: keyword -- -*`microsoft.rsa.internal.message`*:: +*`rsa.internal.message`*:: + -- This key captures the contents of instant messages @@ -87440,7 +87426,7 @@ type: keyword -- -*`microsoft.rsa.internal.time`*:: +*`rsa.internal.time`*:: + -- This is the time at which a session hits a NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness. @@ -87449,7 +87435,7 @@ type: date -- -*`microsoft.rsa.internal.level`*:: +*`rsa.internal.level`*:: + -- Deprecated key defined only in table map. @@ -87458,7 +87444,7 @@ type: long -- -*`microsoft.rsa.internal.msg_id`*:: +*`rsa.internal.msg_id`*:: + -- This is the Message ID1 value that identifies the exact log parser definition which parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87467,7 +87453,7 @@ type: keyword -- -*`microsoft.rsa.internal.msg_vid`*:: +*`rsa.internal.msg_vid`*:: + -- This is the Message ID2 value that identifies the exact log parser definition which parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87476,7 +87462,7 @@ type: keyword -- -*`microsoft.rsa.internal.data`*:: +*`rsa.internal.data`*:: + -- Deprecated key defined only in table map. @@ -87485,7 +87471,7 @@ type: keyword -- -*`microsoft.rsa.internal.obj_server`*:: +*`rsa.internal.obj_server`*:: + -- Deprecated key defined only in table map. @@ -87494,7 +87480,7 @@ type: keyword -- -*`microsoft.rsa.internal.obj_val`*:: +*`rsa.internal.obj_val`*:: + -- Deprecated key defined only in table map. @@ -87503,7 +87489,7 @@ type: keyword -- -*`microsoft.rsa.internal.resource`*:: +*`rsa.internal.resource`*:: + -- Deprecated key defined only in table map. @@ -87512,7 +87498,7 @@ type: keyword -- -*`microsoft.rsa.internal.obj_id`*:: +*`rsa.internal.obj_id`*:: + -- Deprecated key defined only in table map. @@ -87521,7 +87507,7 @@ type: keyword -- -*`microsoft.rsa.internal.statement`*:: +*`rsa.internal.statement`*:: + -- Deprecated key defined only in table map. @@ -87530,7 +87516,7 @@ type: keyword -- -*`microsoft.rsa.internal.audit_class`*:: +*`rsa.internal.audit_class`*:: + -- Deprecated key defined only in table map. @@ -87539,7 +87525,7 @@ type: keyword -- -*`microsoft.rsa.internal.entry`*:: +*`rsa.internal.entry`*:: + -- Deprecated key defined only in table map. @@ -87548,7 +87534,7 @@ type: keyword -- -*`microsoft.rsa.internal.hcode`*:: +*`rsa.internal.hcode`*:: + -- Deprecated key defined only in table map. @@ -87557,7 +87543,7 @@ type: keyword -- -*`microsoft.rsa.internal.inode`*:: +*`rsa.internal.inode`*:: + -- Deprecated key defined only in table map. @@ -87566,7 +87552,7 @@ type: long -- -*`microsoft.rsa.internal.resource_class`*:: +*`rsa.internal.resource_class`*:: + -- Deprecated key defined only in table map. @@ -87575,7 +87561,7 @@ type: keyword -- -*`microsoft.rsa.internal.dead`*:: +*`rsa.internal.dead`*:: + -- Deprecated key defined only in table map. @@ -87584,7 +87570,7 @@ type: long -- -*`microsoft.rsa.internal.feed_desc`*:: +*`rsa.internal.feed_desc`*:: + -- This is used to capture the description of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87593,7 +87579,7 @@ type: keyword -- -*`microsoft.rsa.internal.feed_name`*:: +*`rsa.internal.feed_name`*:: + -- This is used to capture the name of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87602,7 +87588,7 @@ type: keyword -- -*`microsoft.rsa.internal.cid`*:: +*`rsa.internal.cid`*:: + -- This is the unique identifier used to identify a NetWitness Concentrator. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87611,7 +87597,7 @@ type: keyword -- -*`microsoft.rsa.internal.device_class`*:: +*`rsa.internal.device_class`*:: + -- This is the Classification of the Log Event Source under a predefined fixed set of Event Source Classifications. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87620,7 +87606,7 @@ type: keyword -- -*`microsoft.rsa.internal.device_group`*:: +*`rsa.internal.device_group`*:: + -- This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87629,7 +87615,7 @@ type: keyword -- -*`microsoft.rsa.internal.device_host`*:: +*`rsa.internal.device_host`*:: + -- This is the Hostname of the log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87638,7 +87624,7 @@ type: keyword -- -*`microsoft.rsa.internal.device_ip`*:: +*`rsa.internal.device_ip`*:: + -- This is the IPv4 address of the Log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87647,7 +87633,7 @@ type: ip -- -*`microsoft.rsa.internal.device_ipv6`*:: +*`rsa.internal.device_ipv6`*:: + -- This is the IPv6 address of the Log Event Source sending the logs to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87656,7 +87642,7 @@ type: ip -- -*`microsoft.rsa.internal.device_type`*:: +*`rsa.internal.device_type`*:: + -- This is the name of the log parser which parsed a given session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87665,7 +87651,7 @@ type: keyword -- -*`microsoft.rsa.internal.device_type_id`*:: +*`rsa.internal.device_type_id`*:: + -- Deprecated key defined only in table map. @@ -87674,7 +87660,7 @@ type: long -- -*`microsoft.rsa.internal.did`*:: +*`rsa.internal.did`*:: + -- This is the unique identifier used to identify a NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87683,7 +87669,7 @@ type: keyword -- -*`microsoft.rsa.internal.entropy_req`*:: +*`rsa.internal.entropy_req`*:: + -- This key is only used by the Entropy Parser, the Meta Type can be either UInt16 or Float32 based on the configuration @@ -87692,7 +87678,7 @@ type: long -- -*`microsoft.rsa.internal.entropy_res`*:: +*`rsa.internal.entropy_res`*:: + -- This key is only used by the Entropy Parser, the Meta Type can be either UInt16 or Float32 based on the configuration @@ -87701,7 +87687,7 @@ type: long -- -*`microsoft.rsa.internal.event_name`*:: +*`rsa.internal.event_name`*:: + -- Deprecated key defined only in table map. @@ -87710,7 +87696,7 @@ type: keyword -- -*`microsoft.rsa.internal.feed_category`*:: +*`rsa.internal.feed_category`*:: + -- This is used to capture the category of the feed. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87719,7 +87705,7 @@ type: keyword -- -*`microsoft.rsa.internal.forward_ip`*:: +*`rsa.internal.forward_ip`*:: + -- This key should be used to capture the IPV4 address of a relay system which forwarded the events from the original system to NetWitness. @@ -87728,7 +87714,7 @@ type: ip -- -*`microsoft.rsa.internal.forward_ipv6`*:: +*`rsa.internal.forward_ipv6`*:: + -- This key is used to capture the IPV6 address of a relay system which forwarded the events from the original system to NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87737,7 +87723,7 @@ type: ip -- -*`microsoft.rsa.internal.header_id`*:: +*`rsa.internal.header_id`*:: + -- This is the Header ID value that identifies the exact log parser header definition that parses a particular log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87746,7 +87732,7 @@ type: keyword -- -*`microsoft.rsa.internal.lc_cid`*:: +*`rsa.internal.lc_cid`*:: + -- This is a unique Identifier of a Log Collector. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87755,7 +87741,7 @@ type: keyword -- -*`microsoft.rsa.internal.lc_ctime`*:: +*`rsa.internal.lc_ctime`*:: + -- This is the time at which a log is collected in a NetWitness Log Collector. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87764,7 +87750,7 @@ type: date -- -*`microsoft.rsa.internal.mcb_req`*:: +*`rsa.internal.mcb_req`*:: + -- This key is only used by the Entropy Parser, the most common byte request is simply which byte for each side (0 thru 255) was seen the most @@ -87773,7 +87759,7 @@ type: long -- -*`microsoft.rsa.internal.mcb_res`*:: +*`rsa.internal.mcb_res`*:: + -- This key is only used by the Entropy Parser, the most common byte response is simply which byte for each side (0 thru 255) was seen the most @@ -87782,7 +87768,7 @@ type: long -- -*`microsoft.rsa.internal.mcbc_req`*:: +*`rsa.internal.mcbc_req`*:: + -- This key is only used by the Entropy Parser, the most common byte count is the number of times the most common byte (above) was seen in the session streams @@ -87791,7 +87777,7 @@ type: long -- -*`microsoft.rsa.internal.mcbc_res`*:: +*`rsa.internal.mcbc_res`*:: + -- This key is only used by the Entropy Parser, the most common byte count is the number of times the most common byte (above) was seen in the session streams @@ -87800,7 +87786,7 @@ type: long -- -*`microsoft.rsa.internal.medium`*:: +*`rsa.internal.medium`*:: + -- This key is used to identify if it’s a log/packet session or Layer 2 Encapsulation Type. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness. 32 = log, 33 = correlation session, < 32 is packet session @@ -87809,7 +87795,7 @@ type: long -- -*`microsoft.rsa.internal.node_name`*:: +*`rsa.internal.node_name`*:: + -- Deprecated key defined only in table map. @@ -87818,7 +87804,7 @@ type: keyword -- -*`microsoft.rsa.internal.nwe_callback_id`*:: +*`rsa.internal.nwe_callback_id`*:: + -- This key denotes that event is endpoint related @@ -87827,7 +87813,7 @@ type: keyword -- -*`microsoft.rsa.internal.parse_error`*:: +*`rsa.internal.parse_error`*:: + -- This is a special key that stores any Meta key validation error found while parsing a log session. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87836,7 +87822,7 @@ type: keyword -- -*`microsoft.rsa.internal.payload_req`*:: +*`rsa.internal.payload_req`*:: + -- This key is only used by the Entropy Parser, the payload size metrics are the payload sizes of each session side at the time of parsing. However, in order to keep @@ -87845,7 +87831,7 @@ type: long -- -*`microsoft.rsa.internal.payload_res`*:: +*`rsa.internal.payload_res`*:: + -- This key is only used by the Entropy Parser, the payload size metrics are the payload sizes of each session side at the time of parsing. However, in order to keep @@ -87854,7 +87840,7 @@ type: long -- -*`microsoft.rsa.internal.process_vid_dst`*:: +*`rsa.internal.process_vid_dst`*:: + -- Endpoint generates and uses a unique virtual ID to identify any similar group of process. This ID represents the target process. @@ -87863,7 +87849,7 @@ type: keyword -- -*`microsoft.rsa.internal.process_vid_src`*:: +*`rsa.internal.process_vid_src`*:: + -- Endpoint generates and uses a unique virtual ID to identify any similar group of process. This ID represents the source process. @@ -87872,7 +87858,7 @@ type: keyword -- -*`microsoft.rsa.internal.rid`*:: +*`rsa.internal.rid`*:: + -- This is a special ID of the Remote Session created by NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87881,7 +87867,7 @@ type: long -- -*`microsoft.rsa.internal.session_split`*:: +*`rsa.internal.session_split`*:: + -- This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87890,7 +87876,7 @@ type: keyword -- -*`microsoft.rsa.internal.site`*:: +*`rsa.internal.site`*:: + -- Deprecated key defined only in table map. @@ -87899,7 +87885,7 @@ type: keyword -- -*`microsoft.rsa.internal.size`*:: +*`rsa.internal.size`*:: + -- This is the size of the session as seen by the NetWitness Decoder. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87908,7 +87894,7 @@ type: long -- -*`microsoft.rsa.internal.sourcefile`*:: +*`rsa.internal.sourcefile`*:: + -- This is the name of the log file or PCAPs that can be imported into NetWitness. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -87917,7 +87903,7 @@ type: keyword -- -*`microsoft.rsa.internal.ubc_req`*:: +*`rsa.internal.ubc_req`*:: + -- This key is only used by the Entropy Parser, Unique byte count is the number of unique bytes seen in each stream. 256 would mean all byte values of 0 thru 255 were seen at least once @@ -87926,7 +87912,7 @@ type: long -- -*`microsoft.rsa.internal.ubc_res`*:: +*`rsa.internal.ubc_res`*:: + -- This key is only used by the Entropy Parser, Unique byte count is the number of unique bytes seen in each stream. 256 would mean all byte values of 0 thru 255 were seen at least once @@ -87935,7 +87921,7 @@ type: long -- -*`microsoft.rsa.internal.word`*:: +*`rsa.internal.word`*:: + -- This is used by the Word Parsing technology to capture the first 5 character of every word in an unparsed log @@ -87945,7 +87931,7 @@ type: keyword -- -*`microsoft.rsa.time.event_time`*:: +*`rsa.time.event_time`*:: + -- This key is used to capture the time mentioned in a raw session that represents the actual time an event occured in a standard normalized form @@ -87954,7 +87940,7 @@ type: date -- -*`microsoft.rsa.time.duration_time`*:: +*`rsa.time.duration_time`*:: + -- This key is used to capture the normalized duration/lifetime in seconds. @@ -87963,7 +87949,7 @@ type: double -- -*`microsoft.rsa.time.event_time_str`*:: +*`rsa.time.event_time_str`*:: + -- This key is used to capture the incomplete time mentioned in a session as a string @@ -87972,7 +87958,7 @@ type: keyword -- -*`microsoft.rsa.time.starttime`*:: +*`rsa.time.starttime`*:: + -- This key is used to capture the Start time mentioned in a session in a standard form @@ -87981,21 +87967,21 @@ type: date -- -*`microsoft.rsa.time.month`*:: +*`rsa.time.month`*:: + -- type: keyword -- -*`microsoft.rsa.time.day`*:: +*`rsa.time.day`*:: + -- type: keyword -- -*`microsoft.rsa.time.endtime`*:: +*`rsa.time.endtime`*:: + -- This key is used to capture the End time mentioned in a session in a standard form @@ -88004,7 +87990,7 @@ type: date -- -*`microsoft.rsa.time.timezone`*:: +*`rsa.time.timezone`*:: + -- This key is used to capture the timezone of the Event Time @@ -88013,7 +87999,7 @@ type: keyword -- -*`microsoft.rsa.time.duration_str`*:: +*`rsa.time.duration_str`*:: + -- A text string version of the duration @@ -88022,21 +88008,21 @@ type: keyword -- -*`microsoft.rsa.time.date`*:: +*`rsa.time.date`*:: + -- type: keyword -- -*`microsoft.rsa.time.year`*:: +*`rsa.time.year`*:: + -- type: keyword -- -*`microsoft.rsa.time.recorded_time`*:: +*`rsa.time.recorded_time`*:: + -- The event time as recorded by the system the event is collected from. The usage scenario is a multi-tier application where the management layer of the system records it's own timestamp at the time of collection from its child nodes. Must be in timestamp format. @@ -88045,14 +88031,14 @@ type: date -- -*`microsoft.rsa.time.datetime`*:: +*`rsa.time.datetime`*:: + -- type: keyword -- -*`microsoft.rsa.time.effective_time`*:: +*`rsa.time.effective_time`*:: + -- This key is the effective time referenced by an individual event in a Standard Timestamp format @@ -88061,7 +88047,7 @@ type: date -- -*`microsoft.rsa.time.expire_time`*:: +*`rsa.time.expire_time`*:: + -- This key is the timestamp that explicitly refers to an expiration. @@ -88070,7 +88056,7 @@ type: date -- -*`microsoft.rsa.time.process_time`*:: +*`rsa.time.process_time`*:: + -- Deprecated, use duration.time @@ -88079,28 +88065,28 @@ type: keyword -- -*`microsoft.rsa.time.hour`*:: +*`rsa.time.hour`*:: + -- type: keyword -- -*`microsoft.rsa.time.min`*:: +*`rsa.time.min`*:: + -- type: keyword -- -*`microsoft.rsa.time.timestamp`*:: +*`rsa.time.timestamp`*:: + -- type: keyword -- -*`microsoft.rsa.time.event_queue_time`*:: +*`rsa.time.event_queue_time`*:: + -- This key is the Time that the event was queued. @@ -88109,77 +88095,77 @@ type: date -- -*`microsoft.rsa.time.p_time1`*:: +*`rsa.time.p_time1`*:: + -- type: keyword -- -*`microsoft.rsa.time.tzone`*:: +*`rsa.time.tzone`*:: + -- type: keyword -- -*`microsoft.rsa.time.eventtime`*:: +*`rsa.time.eventtime`*:: + -- type: keyword -- -*`microsoft.rsa.time.gmtdate`*:: +*`rsa.time.gmtdate`*:: + -- type: keyword -- -*`microsoft.rsa.time.gmttime`*:: +*`rsa.time.gmttime`*:: + -- type: keyword -- -*`microsoft.rsa.time.p_date`*:: +*`rsa.time.p_date`*:: + -- type: keyword -- -*`microsoft.rsa.time.p_month`*:: +*`rsa.time.p_month`*:: + -- type: keyword -- -*`microsoft.rsa.time.p_time`*:: +*`rsa.time.p_time`*:: + -- type: keyword -- -*`microsoft.rsa.time.p_time2`*:: +*`rsa.time.p_time2`*:: + -- type: keyword -- -*`microsoft.rsa.time.p_year`*:: +*`rsa.time.p_year`*:: + -- type: keyword -- -*`microsoft.rsa.time.expire_time_str`*:: +*`rsa.time.expire_time_str`*:: + -- This key is used to capture incomplete timestamp that explicitly refers to an expiration. @@ -88188,7 +88174,7 @@ type: keyword -- -*`microsoft.rsa.time.stamp`*:: +*`rsa.time.stamp`*:: + -- Deprecated key defined only in table map. @@ -88198,14 +88184,14 @@ type: date -- -*`microsoft.rsa.misc.action`*:: +*`rsa.misc.action`*:: + -- type: keyword -- -*`microsoft.rsa.misc.result`*:: +*`rsa.misc.result`*:: + -- This key is used to capture the outcome/result string value of an action in a session. @@ -88214,7 +88200,7 @@ type: keyword -- -*`microsoft.rsa.misc.severity`*:: +*`rsa.misc.severity`*:: + -- This key is used to capture the severity given the session @@ -88223,7 +88209,7 @@ type: keyword -- -*`microsoft.rsa.misc.event_type`*:: +*`rsa.misc.event_type`*:: + -- This key captures the event category type as specified by the event source. @@ -88232,7 +88218,7 @@ type: keyword -- -*`microsoft.rsa.misc.reference_id`*:: +*`rsa.misc.reference_id`*:: + -- This key is used to capture an event id from the session directly @@ -88241,7 +88227,7 @@ type: keyword -- -*`microsoft.rsa.misc.version`*:: +*`rsa.misc.version`*:: + -- This key captures Version of the application or OS which is generating the event. @@ -88250,7 +88236,7 @@ type: keyword -- -*`microsoft.rsa.misc.disposition`*:: +*`rsa.misc.disposition`*:: + -- This key captures the The end state of an action. @@ -88259,7 +88245,7 @@ type: keyword -- -*`microsoft.rsa.misc.result_code`*:: +*`rsa.misc.result_code`*:: + -- This key is used to capture the outcome/result numeric value of an action in a session @@ -88268,7 +88254,7 @@ type: keyword -- -*`microsoft.rsa.misc.category`*:: +*`rsa.misc.category`*:: + -- This key is used to capture the category of an event given by the vendor in the session @@ -88277,7 +88263,7 @@ type: keyword -- -*`microsoft.rsa.misc.obj_name`*:: +*`rsa.misc.obj_name`*:: + -- This is used to capture name of object @@ -88286,7 +88272,7 @@ type: keyword -- -*`microsoft.rsa.misc.obj_type`*:: +*`rsa.misc.obj_type`*:: + -- This is used to capture type of object @@ -88295,7 +88281,7 @@ type: keyword -- -*`microsoft.rsa.misc.event_source`*:: +*`rsa.misc.event_source`*:: + -- This key captures Source of the event that’s not a hostname @@ -88304,7 +88290,7 @@ type: keyword -- -*`microsoft.rsa.misc.log_session_id`*:: +*`rsa.misc.log_session_id`*:: + -- This key is used to capture a sessionid from the session directly @@ -88313,7 +88299,7 @@ type: keyword -- -*`microsoft.rsa.misc.group`*:: +*`rsa.misc.group`*:: + -- This key captures the Group Name value @@ -88322,7 +88308,7 @@ type: keyword -- -*`microsoft.rsa.misc.policy_name`*:: +*`rsa.misc.policy_name`*:: + -- This key is used to capture the Policy Name only. @@ -88331,7 +88317,7 @@ type: keyword -- -*`microsoft.rsa.misc.rule_name`*:: +*`rsa.misc.rule_name`*:: + -- This key captures the Rule Name @@ -88340,7 +88326,7 @@ type: keyword -- -*`microsoft.rsa.misc.context`*:: +*`rsa.misc.context`*:: + -- This key captures Information which adds additional context to the event. @@ -88349,7 +88335,7 @@ type: keyword -- -*`microsoft.rsa.misc.change_new`*:: +*`rsa.misc.change_new`*:: + -- This key is used to capture the new values of the attribute that’s changing in a session @@ -88358,14 +88344,14 @@ type: keyword -- -*`microsoft.rsa.misc.space`*:: +*`rsa.misc.space`*:: + -- type: keyword -- -*`microsoft.rsa.misc.client`*:: +*`rsa.misc.client`*:: + -- This key is used to capture only the name of the client application requesting resources of the server. See the user.agent meta key for capture of the specific user agent identifier or browser identification string. @@ -88374,21 +88360,21 @@ type: keyword -- -*`microsoft.rsa.misc.msgIdPart1`*:: +*`rsa.misc.msgIdPart1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.msgIdPart2`*:: +*`rsa.misc.msgIdPart2`*:: + -- type: keyword -- -*`microsoft.rsa.misc.change_old`*:: +*`rsa.misc.change_old`*:: + -- This key is used to capture the old value of the attribute that’s changing in a session @@ -88397,7 +88383,7 @@ type: keyword -- -*`microsoft.rsa.misc.operation_id`*:: +*`rsa.misc.operation_id`*:: + -- An alert number or operation number. The values should be unique and non-repeating. @@ -88406,7 +88392,7 @@ type: keyword -- -*`microsoft.rsa.misc.event_state`*:: +*`rsa.misc.event_state`*:: + -- This key captures the current state of the object/item referenced within the event. Describing an on-going event. @@ -88415,7 +88401,7 @@ type: keyword -- -*`microsoft.rsa.misc.group_object`*:: +*`rsa.misc.group_object`*:: + -- This key captures a collection/grouping of entities. Specific usage @@ -88424,7 +88410,7 @@ type: keyword -- -*`microsoft.rsa.misc.node`*:: +*`rsa.misc.node`*:: + -- Common use case is the node name within a cluster. The cluster name is reflected by the host name. @@ -88433,7 +88419,7 @@ type: keyword -- -*`microsoft.rsa.misc.rule`*:: +*`rsa.misc.rule`*:: + -- This key captures the Rule number @@ -88442,7 +88428,7 @@ type: keyword -- -*`microsoft.rsa.misc.device_name`*:: +*`rsa.misc.device_name`*:: + -- This is used to capture name of the Device associated with the node Like: a physical disk, printer, etc @@ -88451,7 +88437,7 @@ type: keyword -- -*`microsoft.rsa.misc.param`*:: +*`rsa.misc.param`*:: + -- This key is the parameters passed as part of a command or application, etc. @@ -88460,7 +88446,7 @@ type: keyword -- -*`microsoft.rsa.misc.change_attrib`*:: +*`rsa.misc.change_attrib`*:: + -- This key is used to capture the name of the attribute that’s changing in a session @@ -88469,7 +88455,7 @@ type: keyword -- -*`microsoft.rsa.misc.event_computer`*:: +*`rsa.misc.event_computer`*:: + -- This key is a windows only concept, where this key is used to capture fully qualified domain name in a windows log. @@ -88478,7 +88464,7 @@ type: keyword -- -*`microsoft.rsa.misc.reference_id1`*:: +*`rsa.misc.reference_id1`*:: + -- This key is for Linked ID to be used as an addition to "reference.id" @@ -88487,7 +88473,7 @@ type: keyword -- -*`microsoft.rsa.misc.event_log`*:: +*`rsa.misc.event_log`*:: + -- This key captures the Name of the event log @@ -88496,7 +88482,7 @@ type: keyword -- -*`microsoft.rsa.misc.OS`*:: +*`rsa.misc.OS`*:: + -- This key captures the Name of the Operating System @@ -88505,7 +88491,7 @@ type: keyword -- -*`microsoft.rsa.misc.terminal`*:: +*`rsa.misc.terminal`*:: + -- This key captures the Terminal Names only @@ -88514,14 +88500,14 @@ type: keyword -- -*`microsoft.rsa.misc.msgIdPart3`*:: +*`rsa.misc.msgIdPart3`*:: + -- type: keyword -- -*`microsoft.rsa.misc.filter`*:: +*`rsa.misc.filter`*:: + -- This key captures Filter used to reduce result set @@ -88530,7 +88516,7 @@ type: keyword -- -*`microsoft.rsa.misc.serial_number`*:: +*`rsa.misc.serial_number`*:: + -- This key is the Serial number associated with a physical asset. @@ -88539,7 +88525,7 @@ type: keyword -- -*`microsoft.rsa.misc.checksum`*:: +*`rsa.misc.checksum`*:: + -- This key is used to capture the checksum or hash of the entity such as a file or process. Checksum should be used over checksum.src or checksum.dst when it is unclear whether the entity is a source or target of an action. @@ -88548,7 +88534,7 @@ type: keyword -- -*`microsoft.rsa.misc.event_user`*:: +*`rsa.misc.event_user`*:: + -- This key is a windows only concept, where this key is used to capture combination of domain name and username in a windows log. @@ -88557,7 +88543,7 @@ type: keyword -- -*`microsoft.rsa.misc.virusname`*:: +*`rsa.misc.virusname`*:: + -- This key captures the name of the virus @@ -88566,7 +88552,7 @@ type: keyword -- -*`microsoft.rsa.misc.content_type`*:: +*`rsa.misc.content_type`*:: + -- This key is used to capture Content Type only. @@ -88575,7 +88561,7 @@ type: keyword -- -*`microsoft.rsa.misc.group_id`*:: +*`rsa.misc.group_id`*:: + -- This key captures Group ID Number (related to the group name) @@ -88584,7 +88570,7 @@ type: keyword -- -*`microsoft.rsa.misc.policy_id`*:: +*`rsa.misc.policy_id`*:: + -- This key is used to capture the Policy ID only, this should be a numeric value, use policy.name otherwise @@ -88593,7 +88579,7 @@ type: keyword -- -*`microsoft.rsa.misc.vsys`*:: +*`rsa.misc.vsys`*:: + -- This key captures Virtual System Name @@ -88602,7 +88588,7 @@ type: keyword -- -*`microsoft.rsa.misc.connection_id`*:: +*`rsa.misc.connection_id`*:: + -- This key captures the Connection ID @@ -88611,7 +88597,7 @@ type: keyword -- -*`microsoft.rsa.misc.reference_id2`*:: +*`rsa.misc.reference_id2`*:: + -- This key is for the 2nd Linked ID. Can be either linked to "reference.id" or "reference.id1" value but should not be used unless the other two variables are in play. @@ -88620,7 +88606,7 @@ type: keyword -- -*`microsoft.rsa.misc.sensor`*:: +*`rsa.misc.sensor`*:: + -- This key captures Name of the sensor. Typically used in IDS/IPS based devices @@ -88629,7 +88615,7 @@ type: keyword -- -*`microsoft.rsa.misc.sig_id`*:: +*`rsa.misc.sig_id`*:: + -- This key captures IDS/IPS Int Signature ID @@ -88638,7 +88624,7 @@ type: long -- -*`microsoft.rsa.misc.port_name`*:: +*`rsa.misc.port_name`*:: + -- This key is used for Physical or logical port connection but does NOT include a network port. (Example: Printer port name). @@ -88647,7 +88633,7 @@ type: keyword -- -*`microsoft.rsa.misc.rule_group`*:: +*`rsa.misc.rule_group`*:: + -- This key captures the Rule group name @@ -88656,7 +88642,7 @@ type: keyword -- -*`microsoft.rsa.misc.risk_num`*:: +*`rsa.misc.risk_num`*:: + -- This key captures a Numeric Risk value @@ -88665,7 +88651,7 @@ type: double -- -*`microsoft.rsa.misc.trigger_val`*:: +*`rsa.misc.trigger_val`*:: + -- This key captures the Value of the trigger or threshold condition. @@ -88674,7 +88660,7 @@ type: keyword -- -*`microsoft.rsa.misc.log_session_id1`*:: +*`rsa.misc.log_session_id1`*:: + -- This key is used to capture a Linked (Related) Session ID from the session directly @@ -88683,7 +88669,7 @@ type: keyword -- -*`microsoft.rsa.misc.comp_version`*:: +*`rsa.misc.comp_version`*:: + -- This key captures the Version level of a sub-component of a product. @@ -88692,7 +88678,7 @@ type: keyword -- -*`microsoft.rsa.misc.content_version`*:: +*`rsa.misc.content_version`*:: + -- This key captures Version level of a signature or database content. @@ -88701,7 +88687,7 @@ type: keyword -- -*`microsoft.rsa.misc.hardware_id`*:: +*`rsa.misc.hardware_id`*:: + -- This key is used to capture unique identifier for a device or system (NOT a Mac address) @@ -88710,7 +88696,7 @@ type: keyword -- -*`microsoft.rsa.misc.risk`*:: +*`rsa.misc.risk`*:: + -- This key captures the non-numeric risk value @@ -88719,28 +88705,28 @@ type: keyword -- -*`microsoft.rsa.misc.event_id`*:: +*`rsa.misc.event_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.reason`*:: +*`rsa.misc.reason`*:: + -- type: keyword -- -*`microsoft.rsa.misc.status`*:: +*`rsa.misc.status`*:: + -- type: keyword -- -*`microsoft.rsa.misc.mail_id`*:: +*`rsa.misc.mail_id`*:: + -- This key is used to capture the mailbox id/name @@ -88749,7 +88735,7 @@ type: keyword -- -*`microsoft.rsa.misc.rule_uid`*:: +*`rsa.misc.rule_uid`*:: + -- This key is the Unique Identifier for a rule. @@ -88758,7 +88744,7 @@ type: keyword -- -*`microsoft.rsa.misc.trigger_desc`*:: +*`rsa.misc.trigger_desc`*:: + -- This key captures the Description of the trigger or threshold condition. @@ -88767,35 +88753,35 @@ type: keyword -- -*`microsoft.rsa.misc.inout`*:: +*`rsa.misc.inout`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_msgid`*:: +*`rsa.misc.p_msgid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.data_type`*:: +*`rsa.misc.data_type`*:: + -- type: keyword -- -*`microsoft.rsa.misc.msgIdPart4`*:: +*`rsa.misc.msgIdPart4`*:: + -- type: keyword -- -*`microsoft.rsa.misc.error`*:: +*`rsa.misc.error`*:: + -- This key captures All non successful Error codes or responses @@ -88804,14 +88790,14 @@ type: keyword -- -*`microsoft.rsa.misc.index`*:: +*`rsa.misc.index`*:: + -- type: keyword -- -*`microsoft.rsa.misc.listnum`*:: +*`rsa.misc.listnum`*:: + -- This key is used to capture listname or listnumber, primarily for collecting access-list @@ -88820,14 +88806,14 @@ type: keyword -- -*`microsoft.rsa.misc.ntype`*:: +*`rsa.misc.ntype`*:: + -- type: keyword -- -*`microsoft.rsa.misc.observed_val`*:: +*`rsa.misc.observed_val`*:: + -- This key captures the Value observed (from the perspective of the device generating the log). @@ -88836,7 +88822,7 @@ type: keyword -- -*`microsoft.rsa.misc.policy_value`*:: +*`rsa.misc.policy_value`*:: + -- This key captures the contents of the policy. This contains details about the policy @@ -88845,7 +88831,7 @@ type: keyword -- -*`microsoft.rsa.misc.pool_name`*:: +*`rsa.misc.pool_name`*:: + -- This key captures the name of a resource pool @@ -88854,7 +88840,7 @@ type: keyword -- -*`microsoft.rsa.misc.rule_template`*:: +*`rsa.misc.rule_template`*:: + -- A default set of parameters which are overlayed onto a rule (or rulename) which efffectively constitutes a template @@ -88863,35 +88849,35 @@ type: keyword -- -*`microsoft.rsa.misc.count`*:: +*`rsa.misc.count`*:: + -- type: keyword -- -*`microsoft.rsa.misc.number`*:: +*`rsa.misc.number`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sigcat`*:: +*`rsa.misc.sigcat`*:: + -- type: keyword -- -*`microsoft.rsa.misc.type`*:: +*`rsa.misc.type`*:: + -- type: keyword -- -*`microsoft.rsa.misc.comments`*:: +*`rsa.misc.comments`*:: + -- Comment information provided in the log message @@ -88900,7 +88886,7 @@ type: keyword -- -*`microsoft.rsa.misc.doc_number`*:: +*`rsa.misc.doc_number`*:: + -- This key captures File Identification number @@ -88909,7 +88895,7 @@ type: long -- -*`microsoft.rsa.misc.expected_val`*:: +*`rsa.misc.expected_val`*:: + -- This key captures the Value expected (from the perspective of the device generating the log). @@ -88918,7 +88904,7 @@ type: keyword -- -*`microsoft.rsa.misc.job_num`*:: +*`rsa.misc.job_num`*:: + -- This key captures the Job Number @@ -88927,7 +88913,7 @@ type: keyword -- -*`microsoft.rsa.misc.spi_dst`*:: +*`rsa.misc.spi_dst`*:: + -- Destination SPI Index @@ -88936,7 +88922,7 @@ type: keyword -- -*`microsoft.rsa.misc.spi_src`*:: +*`rsa.misc.spi_src`*:: + -- Source SPI Index @@ -88945,14 +88931,14 @@ type: keyword -- -*`microsoft.rsa.misc.code`*:: +*`rsa.misc.code`*:: + -- type: keyword -- -*`microsoft.rsa.misc.agent_id`*:: +*`rsa.misc.agent_id`*:: + -- This key is used to capture agent id @@ -88961,7 +88947,7 @@ type: keyword -- -*`microsoft.rsa.misc.message_body`*:: +*`rsa.misc.message_body`*:: + -- This key captures the The contents of the message body. @@ -88970,14 +88956,14 @@ type: keyword -- -*`microsoft.rsa.misc.phone`*:: +*`rsa.misc.phone`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sig_id_str`*:: +*`rsa.misc.sig_id_str`*:: + -- This key captures a string object of the sigid variable. @@ -88986,28 +88972,28 @@ type: keyword -- -*`microsoft.rsa.misc.cmd`*:: +*`rsa.misc.cmd`*:: + -- type: keyword -- -*`microsoft.rsa.misc.misc`*:: +*`rsa.misc.misc`*:: + -- type: keyword -- -*`microsoft.rsa.misc.name`*:: +*`rsa.misc.name`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cpu`*:: +*`rsa.misc.cpu`*:: + -- This key is the CPU time used in the execution of the event being recorded. @@ -89016,7 +89002,7 @@ type: long -- -*`microsoft.rsa.misc.event_desc`*:: +*`rsa.misc.event_desc`*:: + -- This key is used to capture a description of an event available directly or inferred @@ -89025,7 +89011,7 @@ type: keyword -- -*`microsoft.rsa.misc.sig_id1`*:: +*`rsa.misc.sig_id1`*:: + -- This key captures IDS/IPS Int Signature ID. This must be linked to the sig.id @@ -89034,42 +89020,42 @@ type: long -- -*`microsoft.rsa.misc.im_buddyid`*:: +*`rsa.misc.im_buddyid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_client`*:: +*`rsa.misc.im_client`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_userid`*:: +*`rsa.misc.im_userid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.pid`*:: +*`rsa.misc.pid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.priority`*:: +*`rsa.misc.priority`*:: + -- type: keyword -- -*`microsoft.rsa.misc.context_subject`*:: +*`rsa.misc.context_subject`*:: + -- This key is to be used in an audit context where the subject is the object being identified @@ -89078,14 +89064,14 @@ type: keyword -- -*`microsoft.rsa.misc.context_target`*:: +*`rsa.misc.context_target`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cve`*:: +*`rsa.misc.cve`*:: + -- This key captures CVE (Common Vulnerabilities and Exposures) - an identifier for known information security vulnerabilities. @@ -89094,7 +89080,7 @@ type: keyword -- -*`microsoft.rsa.misc.fcatnum`*:: +*`rsa.misc.fcatnum`*:: + -- This key captures Filter Category Number. Legacy Usage @@ -89103,7 +89089,7 @@ type: keyword -- -*`microsoft.rsa.misc.library`*:: +*`rsa.misc.library`*:: + -- This key is used to capture library information in mainframe devices @@ -89112,7 +89098,7 @@ type: keyword -- -*`microsoft.rsa.misc.parent_node`*:: +*`rsa.misc.parent_node`*:: + -- This key captures the Parent Node Name. Must be related to node variable. @@ -89121,7 +89107,7 @@ type: keyword -- -*`microsoft.rsa.misc.risk_info`*:: +*`rsa.misc.risk_info`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -89130,7 +89116,7 @@ type: keyword -- -*`microsoft.rsa.misc.tcp_flags`*:: +*`rsa.misc.tcp_flags`*:: + -- This key is captures the TCP flags set in any packet of session @@ -89139,7 +89125,7 @@ type: long -- -*`microsoft.rsa.misc.tos`*:: +*`rsa.misc.tos`*:: + -- This key describes the type of service @@ -89148,7 +89134,7 @@ type: long -- -*`microsoft.rsa.misc.vm_target`*:: +*`rsa.misc.vm_target`*:: + -- VMWare Target **VMWARE** only varaible. @@ -89157,7 +89143,7 @@ type: keyword -- -*`microsoft.rsa.misc.workspace`*:: +*`rsa.misc.workspace`*:: + -- This key captures Workspace Description @@ -89166,91 +89152,91 @@ type: keyword -- -*`microsoft.rsa.misc.command`*:: +*`rsa.misc.command`*:: + -- type: keyword -- -*`microsoft.rsa.misc.event_category`*:: +*`rsa.misc.event_category`*:: + -- type: keyword -- -*`microsoft.rsa.misc.facilityname`*:: +*`rsa.misc.facilityname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.forensic_info`*:: +*`rsa.misc.forensic_info`*:: + -- type: keyword -- -*`microsoft.rsa.misc.jobname`*:: +*`rsa.misc.jobname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.mode`*:: +*`rsa.misc.mode`*:: + -- type: keyword -- -*`microsoft.rsa.misc.policy`*:: +*`rsa.misc.policy`*:: + -- type: keyword -- -*`microsoft.rsa.misc.policy_waiver`*:: +*`rsa.misc.policy_waiver`*:: + -- type: keyword -- -*`microsoft.rsa.misc.second`*:: +*`rsa.misc.second`*:: + -- type: keyword -- -*`microsoft.rsa.misc.space1`*:: +*`rsa.misc.space1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.subcategory`*:: +*`rsa.misc.subcategory`*:: + -- type: keyword -- -*`microsoft.rsa.misc.tbdstr2`*:: +*`rsa.misc.tbdstr2`*:: + -- type: keyword -- -*`microsoft.rsa.misc.alert_id`*:: +*`rsa.misc.alert_id`*:: + -- Deprecated, New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -89259,7 +89245,7 @@ type: keyword -- -*`microsoft.rsa.misc.checksum_dst`*:: +*`rsa.misc.checksum_dst`*:: + -- This key is used to capture the checksum or hash of the the target entity such as a process or file. @@ -89268,7 +89254,7 @@ type: keyword -- -*`microsoft.rsa.misc.checksum_src`*:: +*`rsa.misc.checksum_src`*:: + -- This key is used to capture the checksum or hash of the source entity such as a file or process. @@ -89277,7 +89263,7 @@ type: keyword -- -*`microsoft.rsa.misc.fresult`*:: +*`rsa.misc.fresult`*:: + -- This key captures the Filter Result @@ -89286,7 +89272,7 @@ type: long -- -*`microsoft.rsa.misc.payload_dst`*:: +*`rsa.misc.payload_dst`*:: + -- This key is used to capture destination payload @@ -89295,7 +89281,7 @@ type: keyword -- -*`microsoft.rsa.misc.payload_src`*:: +*`rsa.misc.payload_src`*:: + -- This key is used to capture source payload @@ -89304,7 +89290,7 @@ type: keyword -- -*`microsoft.rsa.misc.pool_id`*:: +*`rsa.misc.pool_id`*:: + -- This key captures the identifier (typically numeric field) of a resource pool @@ -89313,7 +89299,7 @@ type: keyword -- -*`microsoft.rsa.misc.process_id_val`*:: +*`rsa.misc.process_id_val`*:: + -- This key is a failure key for Process ID when it is not an integer value @@ -89322,7 +89308,7 @@ type: keyword -- -*`microsoft.rsa.misc.risk_num_comm`*:: +*`rsa.misc.risk_num_comm`*:: + -- This key captures Risk Number Community @@ -89331,7 +89317,7 @@ type: double -- -*`microsoft.rsa.misc.risk_num_next`*:: +*`rsa.misc.risk_num_next`*:: + -- This key captures Risk Number NextGen @@ -89340,7 +89326,7 @@ type: double -- -*`microsoft.rsa.misc.risk_num_sand`*:: +*`rsa.misc.risk_num_sand`*:: + -- This key captures Risk Number SandBox @@ -89349,7 +89335,7 @@ type: double -- -*`microsoft.rsa.misc.risk_num_static`*:: +*`rsa.misc.risk_num_static`*:: + -- This key captures Risk Number Static @@ -89358,7 +89344,7 @@ type: double -- -*`microsoft.rsa.misc.risk_suspicious`*:: +*`rsa.misc.risk_suspicious`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -89367,7 +89353,7 @@ type: keyword -- -*`microsoft.rsa.misc.risk_warning`*:: +*`rsa.misc.risk_warning`*:: + -- Deprecated, use New Hunting Model (inv.*, ioc, boc, eoc, analysis.*) @@ -89376,7 +89362,7 @@ type: keyword -- -*`microsoft.rsa.misc.snmp_oid`*:: +*`rsa.misc.snmp_oid`*:: + -- SNMP Object Identifier @@ -89385,7 +89371,7 @@ type: keyword -- -*`microsoft.rsa.misc.sql`*:: +*`rsa.misc.sql`*:: + -- This key captures the SQL query @@ -89394,7 +89380,7 @@ type: keyword -- -*`microsoft.rsa.misc.vuln_ref`*:: +*`rsa.misc.vuln_ref`*:: + -- This key captures the Vulnerability Reference details @@ -89403,1547 +89389,1547 @@ type: keyword -- -*`microsoft.rsa.misc.acl_id`*:: +*`rsa.misc.acl_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.acl_op`*:: +*`rsa.misc.acl_op`*:: + -- type: keyword -- -*`microsoft.rsa.misc.acl_pos`*:: +*`rsa.misc.acl_pos`*:: + -- type: keyword -- -*`microsoft.rsa.misc.acl_table`*:: +*`rsa.misc.acl_table`*:: + -- type: keyword -- -*`microsoft.rsa.misc.admin`*:: +*`rsa.misc.admin`*:: + -- type: keyword -- -*`microsoft.rsa.misc.alarm_id`*:: +*`rsa.misc.alarm_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.alarmname`*:: +*`rsa.misc.alarmname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.app_id`*:: +*`rsa.misc.app_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.audit`*:: +*`rsa.misc.audit`*:: + -- type: keyword -- -*`microsoft.rsa.misc.audit_object`*:: +*`rsa.misc.audit_object`*:: + -- type: keyword -- -*`microsoft.rsa.misc.auditdata`*:: +*`rsa.misc.auditdata`*:: + -- type: keyword -- -*`microsoft.rsa.misc.benchmark`*:: +*`rsa.misc.benchmark`*:: + -- type: keyword -- -*`microsoft.rsa.misc.bypass`*:: +*`rsa.misc.bypass`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cache`*:: +*`rsa.misc.cache`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cache_hit`*:: +*`rsa.misc.cache_hit`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cefversion`*:: +*`rsa.misc.cefversion`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cfg_attr`*:: +*`rsa.misc.cfg_attr`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cfg_obj`*:: +*`rsa.misc.cfg_obj`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cfg_path`*:: +*`rsa.misc.cfg_path`*:: + -- type: keyword -- -*`microsoft.rsa.misc.changes`*:: +*`rsa.misc.changes`*:: + -- type: keyword -- -*`microsoft.rsa.misc.client_ip`*:: +*`rsa.misc.client_ip`*:: + -- type: keyword -- -*`microsoft.rsa.misc.clustermembers`*:: +*`rsa.misc.clustermembers`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_acttimeout`*:: +*`rsa.misc.cn_acttimeout`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_asn_src`*:: +*`rsa.misc.cn_asn_src`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_bgpv4nxthop`*:: +*`rsa.misc.cn_bgpv4nxthop`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_ctr_dst_code`*:: +*`rsa.misc.cn_ctr_dst_code`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_dst_tos`*:: +*`rsa.misc.cn_dst_tos`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_dst_vlan`*:: +*`rsa.misc.cn_dst_vlan`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_engine_id`*:: +*`rsa.misc.cn_engine_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_engine_type`*:: +*`rsa.misc.cn_engine_type`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_f_switch`*:: +*`rsa.misc.cn_f_switch`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_flowsampid`*:: +*`rsa.misc.cn_flowsampid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_flowsampintv`*:: +*`rsa.misc.cn_flowsampintv`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_flowsampmode`*:: +*`rsa.misc.cn_flowsampmode`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_inacttimeout`*:: +*`rsa.misc.cn_inacttimeout`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_inpermbyts`*:: +*`rsa.misc.cn_inpermbyts`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_inpermpckts`*:: +*`rsa.misc.cn_inpermpckts`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_invalid`*:: +*`rsa.misc.cn_invalid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_ip_proto_ver`*:: +*`rsa.misc.cn_ip_proto_ver`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_ipv4_ident`*:: +*`rsa.misc.cn_ipv4_ident`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_l_switch`*:: +*`rsa.misc.cn_l_switch`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_log_did`*:: +*`rsa.misc.cn_log_did`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_log_rid`*:: +*`rsa.misc.cn_log_rid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_max_ttl`*:: +*`rsa.misc.cn_max_ttl`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_maxpcktlen`*:: +*`rsa.misc.cn_maxpcktlen`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_min_ttl`*:: +*`rsa.misc.cn_min_ttl`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_minpcktlen`*:: +*`rsa.misc.cn_minpcktlen`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_1`*:: +*`rsa.misc.cn_mpls_lbl_1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_10`*:: +*`rsa.misc.cn_mpls_lbl_10`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_2`*:: +*`rsa.misc.cn_mpls_lbl_2`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_3`*:: +*`rsa.misc.cn_mpls_lbl_3`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_4`*:: +*`rsa.misc.cn_mpls_lbl_4`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_5`*:: +*`rsa.misc.cn_mpls_lbl_5`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_6`*:: +*`rsa.misc.cn_mpls_lbl_6`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_7`*:: +*`rsa.misc.cn_mpls_lbl_7`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_8`*:: +*`rsa.misc.cn_mpls_lbl_8`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mpls_lbl_9`*:: +*`rsa.misc.cn_mpls_lbl_9`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mplstoplabel`*:: +*`rsa.misc.cn_mplstoplabel`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mplstoplabip`*:: +*`rsa.misc.cn_mplstoplabip`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mul_dst_byt`*:: +*`rsa.misc.cn_mul_dst_byt`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_mul_dst_pks`*:: +*`rsa.misc.cn_mul_dst_pks`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_muligmptype`*:: +*`rsa.misc.cn_muligmptype`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_sampalgo`*:: +*`rsa.misc.cn_sampalgo`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_sampint`*:: +*`rsa.misc.cn_sampint`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_seqctr`*:: +*`rsa.misc.cn_seqctr`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_spackets`*:: +*`rsa.misc.cn_spackets`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_src_tos`*:: +*`rsa.misc.cn_src_tos`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_src_vlan`*:: +*`rsa.misc.cn_src_vlan`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_sysuptime`*:: +*`rsa.misc.cn_sysuptime`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_template_id`*:: +*`rsa.misc.cn_template_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_totbytsexp`*:: +*`rsa.misc.cn_totbytsexp`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_totflowexp`*:: +*`rsa.misc.cn_totflowexp`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_totpcktsexp`*:: +*`rsa.misc.cn_totpcktsexp`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_unixnanosecs`*:: +*`rsa.misc.cn_unixnanosecs`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_v6flowlabel`*:: +*`rsa.misc.cn_v6flowlabel`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cn_v6optheaders`*:: +*`rsa.misc.cn_v6optheaders`*:: + -- type: keyword -- -*`microsoft.rsa.misc.comp_class`*:: +*`rsa.misc.comp_class`*:: + -- type: keyword -- -*`microsoft.rsa.misc.comp_name`*:: +*`rsa.misc.comp_name`*:: + -- type: keyword -- -*`microsoft.rsa.misc.comp_rbytes`*:: +*`rsa.misc.comp_rbytes`*:: + -- type: keyword -- -*`microsoft.rsa.misc.comp_sbytes`*:: +*`rsa.misc.comp_sbytes`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cpu_data`*:: +*`rsa.misc.cpu_data`*:: + -- type: keyword -- -*`microsoft.rsa.misc.criticality`*:: +*`rsa.misc.criticality`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_agency_dst`*:: +*`rsa.misc.cs_agency_dst`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_analyzedby`*:: +*`rsa.misc.cs_analyzedby`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_av_other`*:: +*`rsa.misc.cs_av_other`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_av_primary`*:: +*`rsa.misc.cs_av_primary`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_av_secondary`*:: +*`rsa.misc.cs_av_secondary`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_bgpv6nxthop`*:: +*`rsa.misc.cs_bgpv6nxthop`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_bit9status`*:: +*`rsa.misc.cs_bit9status`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_context`*:: +*`rsa.misc.cs_context`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_control`*:: +*`rsa.misc.cs_control`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_data`*:: +*`rsa.misc.cs_data`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_datecret`*:: +*`rsa.misc.cs_datecret`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_dst_tld`*:: +*`rsa.misc.cs_dst_tld`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_eth_dst_ven`*:: +*`rsa.misc.cs_eth_dst_ven`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_eth_src_ven`*:: +*`rsa.misc.cs_eth_src_ven`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_event_uuid`*:: +*`rsa.misc.cs_event_uuid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_filetype`*:: +*`rsa.misc.cs_filetype`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_fld`*:: +*`rsa.misc.cs_fld`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_if_desc`*:: +*`rsa.misc.cs_if_desc`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_if_name`*:: +*`rsa.misc.cs_if_name`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_ip_next_hop`*:: +*`rsa.misc.cs_ip_next_hop`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_ipv4dstpre`*:: +*`rsa.misc.cs_ipv4dstpre`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_ipv4srcpre`*:: +*`rsa.misc.cs_ipv4srcpre`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_lifetime`*:: +*`rsa.misc.cs_lifetime`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_log_medium`*:: +*`rsa.misc.cs_log_medium`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_loginname`*:: +*`rsa.misc.cs_loginname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_modulescore`*:: +*`rsa.misc.cs_modulescore`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_modulesign`*:: +*`rsa.misc.cs_modulesign`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_opswatresult`*:: +*`rsa.misc.cs_opswatresult`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_payload`*:: +*`rsa.misc.cs_payload`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_registrant`*:: +*`rsa.misc.cs_registrant`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_registrar`*:: +*`rsa.misc.cs_registrar`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_represult`*:: +*`rsa.misc.cs_represult`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_rpayload`*:: +*`rsa.misc.cs_rpayload`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_sampler_name`*:: +*`rsa.misc.cs_sampler_name`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_sourcemodule`*:: +*`rsa.misc.cs_sourcemodule`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_streams`*:: +*`rsa.misc.cs_streams`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_targetmodule`*:: +*`rsa.misc.cs_targetmodule`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_v6nxthop`*:: +*`rsa.misc.cs_v6nxthop`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_whois_server`*:: +*`rsa.misc.cs_whois_server`*:: + -- type: keyword -- -*`microsoft.rsa.misc.cs_yararesult`*:: +*`rsa.misc.cs_yararesult`*:: + -- type: keyword -- -*`microsoft.rsa.misc.description`*:: +*`rsa.misc.description`*:: + -- type: keyword -- -*`microsoft.rsa.misc.devvendor`*:: +*`rsa.misc.devvendor`*:: + -- type: keyword -- -*`microsoft.rsa.misc.distance`*:: +*`rsa.misc.distance`*:: + -- type: keyword -- -*`microsoft.rsa.misc.dstburb`*:: +*`rsa.misc.dstburb`*:: + -- type: keyword -- -*`microsoft.rsa.misc.edomain`*:: +*`rsa.misc.edomain`*:: + -- type: keyword -- -*`microsoft.rsa.misc.edomaub`*:: +*`rsa.misc.edomaub`*:: + -- type: keyword -- -*`microsoft.rsa.misc.euid`*:: +*`rsa.misc.euid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.facility`*:: +*`rsa.misc.facility`*:: + -- type: keyword -- -*`microsoft.rsa.misc.finterface`*:: +*`rsa.misc.finterface`*:: + -- type: keyword -- -*`microsoft.rsa.misc.flags`*:: +*`rsa.misc.flags`*:: + -- type: keyword -- -*`microsoft.rsa.misc.gaddr`*:: +*`rsa.misc.gaddr`*:: + -- type: keyword -- -*`microsoft.rsa.misc.id3`*:: +*`rsa.misc.id3`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_buddyname`*:: +*`rsa.misc.im_buddyname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_croomid`*:: +*`rsa.misc.im_croomid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_croomtype`*:: +*`rsa.misc.im_croomtype`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_members`*:: +*`rsa.misc.im_members`*:: + -- type: keyword -- -*`microsoft.rsa.misc.im_username`*:: +*`rsa.misc.im_username`*:: + -- type: keyword -- -*`microsoft.rsa.misc.ipkt`*:: +*`rsa.misc.ipkt`*:: + -- type: keyword -- -*`microsoft.rsa.misc.ipscat`*:: +*`rsa.misc.ipscat`*:: + -- type: keyword -- -*`microsoft.rsa.misc.ipspri`*:: +*`rsa.misc.ipspri`*:: + -- type: keyword -- -*`microsoft.rsa.misc.latitude`*:: +*`rsa.misc.latitude`*:: + -- type: keyword -- -*`microsoft.rsa.misc.linenum`*:: +*`rsa.misc.linenum`*:: + -- type: keyword -- -*`microsoft.rsa.misc.list_name`*:: +*`rsa.misc.list_name`*:: + -- type: keyword -- -*`microsoft.rsa.misc.load_data`*:: +*`rsa.misc.load_data`*:: + -- type: keyword -- -*`microsoft.rsa.misc.location_floor`*:: +*`rsa.misc.location_floor`*:: + -- type: keyword -- -*`microsoft.rsa.misc.location_mark`*:: +*`rsa.misc.location_mark`*:: + -- type: keyword -- -*`microsoft.rsa.misc.log_id`*:: +*`rsa.misc.log_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.log_type`*:: +*`rsa.misc.log_type`*:: + -- type: keyword -- -*`microsoft.rsa.misc.logid`*:: +*`rsa.misc.logid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.logip`*:: +*`rsa.misc.logip`*:: + -- type: keyword -- -*`microsoft.rsa.misc.logname`*:: +*`rsa.misc.logname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.longitude`*:: +*`rsa.misc.longitude`*:: + -- type: keyword -- -*`microsoft.rsa.misc.lport`*:: +*`rsa.misc.lport`*:: + -- type: keyword -- -*`microsoft.rsa.misc.mbug_data`*:: +*`rsa.misc.mbug_data`*:: + -- type: keyword -- -*`microsoft.rsa.misc.misc_name`*:: +*`rsa.misc.misc_name`*:: + -- type: keyword -- -*`microsoft.rsa.misc.msg_type`*:: +*`rsa.misc.msg_type`*:: + -- type: keyword -- -*`microsoft.rsa.misc.msgid`*:: +*`rsa.misc.msgid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.netsessid`*:: +*`rsa.misc.netsessid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.num`*:: +*`rsa.misc.num`*:: + -- type: keyword -- -*`microsoft.rsa.misc.number1`*:: +*`rsa.misc.number1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.number2`*:: +*`rsa.misc.number2`*:: + -- type: keyword -- -*`microsoft.rsa.misc.nwwn`*:: +*`rsa.misc.nwwn`*:: + -- type: keyword -- -*`microsoft.rsa.misc.object`*:: +*`rsa.misc.object`*:: + -- type: keyword -- -*`microsoft.rsa.misc.operation`*:: +*`rsa.misc.operation`*:: + -- type: keyword -- -*`microsoft.rsa.misc.opkt`*:: +*`rsa.misc.opkt`*:: + -- type: keyword -- -*`microsoft.rsa.misc.orig_from`*:: +*`rsa.misc.orig_from`*:: + -- type: keyword -- -*`microsoft.rsa.misc.owner_id`*:: +*`rsa.misc.owner_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_action`*:: +*`rsa.misc.p_action`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_filter`*:: +*`rsa.misc.p_filter`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_group_object`*:: +*`rsa.misc.p_group_object`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_id`*:: +*`rsa.misc.p_id`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_msgid1`*:: +*`rsa.misc.p_msgid1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_msgid2`*:: +*`rsa.misc.p_msgid2`*:: + -- type: keyword -- -*`microsoft.rsa.misc.p_result1`*:: +*`rsa.misc.p_result1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.password_chg`*:: +*`rsa.misc.password_chg`*:: + -- type: keyword -- -*`microsoft.rsa.misc.password_expire`*:: +*`rsa.misc.password_expire`*:: + -- type: keyword -- -*`microsoft.rsa.misc.permgranted`*:: +*`rsa.misc.permgranted`*:: + -- type: keyword -- -*`microsoft.rsa.misc.permwanted`*:: +*`rsa.misc.permwanted`*:: + -- type: keyword -- -*`microsoft.rsa.misc.pgid`*:: +*`rsa.misc.pgid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.policyUUID`*:: +*`rsa.misc.policyUUID`*:: + -- type: keyword -- -*`microsoft.rsa.misc.prog_asp_num`*:: +*`rsa.misc.prog_asp_num`*:: + -- type: keyword -- -*`microsoft.rsa.misc.program`*:: +*`rsa.misc.program`*:: + -- type: keyword -- -*`microsoft.rsa.misc.real_data`*:: +*`rsa.misc.real_data`*:: + -- type: keyword -- -*`microsoft.rsa.misc.rec_asp_device`*:: +*`rsa.misc.rec_asp_device`*:: + -- type: keyword -- -*`microsoft.rsa.misc.rec_asp_num`*:: +*`rsa.misc.rec_asp_num`*:: + -- type: keyword -- -*`microsoft.rsa.misc.rec_library`*:: +*`rsa.misc.rec_library`*:: + -- type: keyword -- -*`microsoft.rsa.misc.recordnum`*:: +*`rsa.misc.recordnum`*:: + -- type: keyword -- -*`microsoft.rsa.misc.ruid`*:: +*`rsa.misc.ruid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sburb`*:: +*`rsa.misc.sburb`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sdomain_fld`*:: +*`rsa.misc.sdomain_fld`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sec`*:: +*`rsa.misc.sec`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sensorname`*:: +*`rsa.misc.sensorname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.seqnum`*:: +*`rsa.misc.seqnum`*:: + -- type: keyword -- -*`microsoft.rsa.misc.session`*:: +*`rsa.misc.session`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sessiontype`*:: +*`rsa.misc.sessiontype`*:: + -- type: keyword -- -*`microsoft.rsa.misc.sigUUID`*:: +*`rsa.misc.sigUUID`*:: + -- type: keyword -- -*`microsoft.rsa.misc.spi`*:: +*`rsa.misc.spi`*:: + -- type: keyword -- -*`microsoft.rsa.misc.srcburb`*:: +*`rsa.misc.srcburb`*:: + -- type: keyword -- -*`microsoft.rsa.misc.srcdom`*:: +*`rsa.misc.srcdom`*:: + -- type: keyword -- -*`microsoft.rsa.misc.srcservice`*:: +*`rsa.misc.srcservice`*:: + -- type: keyword -- -*`microsoft.rsa.misc.state`*:: +*`rsa.misc.state`*:: + -- type: keyword -- -*`microsoft.rsa.misc.status1`*:: +*`rsa.misc.status1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.svcno`*:: +*`rsa.misc.svcno`*:: + -- type: keyword -- -*`microsoft.rsa.misc.system`*:: +*`rsa.misc.system`*:: + -- type: keyword -- -*`microsoft.rsa.misc.tbdstr1`*:: +*`rsa.misc.tbdstr1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.tgtdom`*:: +*`rsa.misc.tgtdom`*:: + -- type: keyword -- -*`microsoft.rsa.misc.tgtdomain`*:: +*`rsa.misc.tgtdomain`*:: + -- type: keyword -- -*`microsoft.rsa.misc.threshold`*:: +*`rsa.misc.threshold`*:: + -- type: keyword -- -*`microsoft.rsa.misc.type1`*:: +*`rsa.misc.type1`*:: + -- type: keyword -- -*`microsoft.rsa.misc.udb_class`*:: +*`rsa.misc.udb_class`*:: + -- type: keyword -- -*`microsoft.rsa.misc.url_fld`*:: +*`rsa.misc.url_fld`*:: + -- type: keyword -- -*`microsoft.rsa.misc.user_div`*:: +*`rsa.misc.user_div`*:: + -- type: keyword -- -*`microsoft.rsa.misc.userid`*:: +*`rsa.misc.userid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.username_fld`*:: +*`rsa.misc.username_fld`*:: + -- type: keyword -- -*`microsoft.rsa.misc.utcstamp`*:: +*`rsa.misc.utcstamp`*:: + -- type: keyword -- -*`microsoft.rsa.misc.v_instafname`*:: +*`rsa.misc.v_instafname`*:: + -- type: keyword -- -*`microsoft.rsa.misc.virt_data`*:: +*`rsa.misc.virt_data`*:: + -- type: keyword -- -*`microsoft.rsa.misc.vpnid`*:: +*`rsa.misc.vpnid`*:: + -- type: keyword -- -*`microsoft.rsa.misc.autorun_type`*:: +*`rsa.misc.autorun_type`*:: + -- This is used to capture Auto Run type @@ -90952,7 +90938,7 @@ type: keyword -- -*`microsoft.rsa.misc.cc_number`*:: +*`rsa.misc.cc_number`*:: + -- Valid Credit Card Numbers only @@ -90961,7 +90947,7 @@ type: long -- -*`microsoft.rsa.misc.content`*:: +*`rsa.misc.content`*:: + -- This key captures the content type from protocol headers @@ -90970,7 +90956,7 @@ type: keyword -- -*`microsoft.rsa.misc.ein_number`*:: +*`rsa.misc.ein_number`*:: + -- Employee Identification Numbers only @@ -90979,7 +90965,7 @@ type: long -- -*`microsoft.rsa.misc.found`*:: +*`rsa.misc.found`*:: + -- This is used to capture the results of regex match @@ -90988,7 +90974,7 @@ type: keyword -- -*`microsoft.rsa.misc.language`*:: +*`rsa.misc.language`*:: + -- This is used to capture list of languages the client support and what it prefers @@ -90997,7 +90983,7 @@ type: keyword -- -*`microsoft.rsa.misc.lifetime`*:: +*`rsa.misc.lifetime`*:: + -- This key is used to capture the session lifetime in seconds. @@ -91006,7 +90992,7 @@ type: long -- -*`microsoft.rsa.misc.link`*:: +*`rsa.misc.link`*:: + -- This key is used to link the sessions together. This key should never be used to parse Meta data from a session (Logs/Packets) Directly, this is a Reserved key in NetWitness @@ -91015,7 +91001,7 @@ type: keyword -- -*`microsoft.rsa.misc.match`*:: +*`rsa.misc.match`*:: + -- This key is for regex match name from search.ini @@ -91024,7 +91010,7 @@ type: keyword -- -*`microsoft.rsa.misc.param_dst`*:: +*`rsa.misc.param_dst`*:: + -- This key captures the command line/launch argument of the target process or file @@ -91033,7 +91019,7 @@ type: keyword -- -*`microsoft.rsa.misc.param_src`*:: +*`rsa.misc.param_src`*:: + -- This key captures source parameter @@ -91042,7 +91028,7 @@ type: keyword -- -*`microsoft.rsa.misc.search_text`*:: +*`rsa.misc.search_text`*:: + -- This key captures the Search Text used @@ -91051,7 +91037,7 @@ type: keyword -- -*`microsoft.rsa.misc.sig_name`*:: +*`rsa.misc.sig_name`*:: + -- This key is used to capture the Signature Name only. @@ -91060,7 +91046,7 @@ type: keyword -- -*`microsoft.rsa.misc.snmp_value`*:: +*`rsa.misc.snmp_value`*:: + -- SNMP set request value @@ -91069,7 +91055,7 @@ type: keyword -- -*`microsoft.rsa.misc.streams`*:: +*`rsa.misc.streams`*:: + -- This key captures number of streams in session @@ -91079,7 +91065,7 @@ type: long -- -*`microsoft.rsa.db.index`*:: +*`rsa.db.index`*:: + -- This key captures IndexID of the index. @@ -91088,7 +91074,7 @@ type: keyword -- -*`microsoft.rsa.db.instance`*:: +*`rsa.db.instance`*:: + -- This key is used to capture the database server instance name @@ -91097,7 +91083,7 @@ type: keyword -- -*`microsoft.rsa.db.database`*:: +*`rsa.db.database`*:: + -- This key is used to capture the name of a database or an instance as seen in a session @@ -91106,7 +91092,7 @@ type: keyword -- -*`microsoft.rsa.db.transact_id`*:: +*`rsa.db.transact_id`*:: + -- This key captures the SQL transantion ID of the current session @@ -91115,7 +91101,7 @@ type: keyword -- -*`microsoft.rsa.db.permissions`*:: +*`rsa.db.permissions`*:: + -- This key captures permission or privilege level assigned to a resource. @@ -91124,7 +91110,7 @@ type: keyword -- -*`microsoft.rsa.db.table_name`*:: +*`rsa.db.table_name`*:: + -- This key is used to capture the table name @@ -91133,7 +91119,7 @@ type: keyword -- -*`microsoft.rsa.db.db_id`*:: +*`rsa.db.db_id`*:: + -- This key is used to capture the unique identifier for a database @@ -91142,7 +91128,7 @@ type: keyword -- -*`microsoft.rsa.db.db_pid`*:: +*`rsa.db.db_pid`*:: + -- This key captures the process id of a connection with database server @@ -91151,7 +91137,7 @@ type: long -- -*`microsoft.rsa.db.lread`*:: +*`rsa.db.lread`*:: + -- This key is used for the number of logical reads @@ -91160,7 +91146,7 @@ type: long -- -*`microsoft.rsa.db.lwrite`*:: +*`rsa.db.lwrite`*:: + -- This key is used for the number of logical writes @@ -91169,7 +91155,7 @@ type: long -- -*`microsoft.rsa.db.pread`*:: +*`rsa.db.pread`*:: + -- This key is used for the number of physical writes @@ -91179,7 +91165,7 @@ type: long -- -*`microsoft.rsa.network.alias_host`*:: +*`rsa.network.alias_host`*:: + -- This key should be used when the source or destination context of a hostname is not clear.Also it captures the Device Hostname. Any Hostname that isnt ad.computer. @@ -91188,14 +91174,14 @@ type: keyword -- -*`microsoft.rsa.network.domain`*:: +*`rsa.network.domain`*:: + -- type: keyword -- -*`microsoft.rsa.network.host_dst`*:: +*`rsa.network.host_dst`*:: + -- This key should only be used when it’s a Destination Hostname @@ -91204,7 +91190,7 @@ type: keyword -- -*`microsoft.rsa.network.network_service`*:: +*`rsa.network.network_service`*:: + -- This is used to capture layer 7 protocols/service names @@ -91213,7 +91199,7 @@ type: keyword -- -*`microsoft.rsa.network.interface`*:: +*`rsa.network.interface`*:: + -- This key should be used when the source or destination context of an interface is not clear @@ -91222,7 +91208,7 @@ type: keyword -- -*`microsoft.rsa.network.network_port`*:: +*`rsa.network.network_port`*:: + -- Deprecated, use port. NOTE: There is a type discrepancy as currently used, TM: Int32, INDEX: UInt64 (why neither chose the correct UInt16?!) @@ -91231,7 +91217,7 @@ type: long -- -*`microsoft.rsa.network.eth_host`*:: +*`rsa.network.eth_host`*:: + -- Deprecated, use alias.mac @@ -91240,7 +91226,7 @@ type: keyword -- -*`microsoft.rsa.network.sinterface`*:: +*`rsa.network.sinterface`*:: + -- This key should only be used when it’s a Source Interface @@ -91249,7 +91235,7 @@ type: keyword -- -*`microsoft.rsa.network.dinterface`*:: +*`rsa.network.dinterface`*:: + -- This key should only be used when it’s a Destination Interface @@ -91258,7 +91244,7 @@ type: keyword -- -*`microsoft.rsa.network.vlan`*:: +*`rsa.network.vlan`*:: + -- This key should only be used to capture the ID of the Virtual LAN @@ -91267,7 +91253,7 @@ type: long -- -*`microsoft.rsa.network.zone_src`*:: +*`rsa.network.zone_src`*:: + -- This key should only be used when it’s a Source Zone. @@ -91276,7 +91262,7 @@ type: keyword -- -*`microsoft.rsa.network.zone`*:: +*`rsa.network.zone`*:: + -- This key should be used when the source or destination context of a Zone is not clear @@ -91285,7 +91271,7 @@ type: keyword -- -*`microsoft.rsa.network.zone_dst`*:: +*`rsa.network.zone_dst`*:: + -- This key should only be used when it’s a Destination Zone. @@ -91294,7 +91280,7 @@ type: keyword -- -*`microsoft.rsa.network.gateway`*:: +*`rsa.network.gateway`*:: + -- This key is used to capture the IP Address of the gateway @@ -91303,7 +91289,7 @@ type: keyword -- -*`microsoft.rsa.network.icmp_type`*:: +*`rsa.network.icmp_type`*:: + -- This key is used to capture the ICMP type only @@ -91312,7 +91298,7 @@ type: long -- -*`microsoft.rsa.network.mask`*:: +*`rsa.network.mask`*:: + -- This key is used to capture the device network IPmask. @@ -91321,7 +91307,7 @@ type: keyword -- -*`microsoft.rsa.network.icmp_code`*:: +*`rsa.network.icmp_code`*:: + -- This key is used to capture the ICMP code only @@ -91330,7 +91316,7 @@ type: long -- -*`microsoft.rsa.network.protocol_detail`*:: +*`rsa.network.protocol_detail`*:: + -- This key should be used to capture additional protocol information @@ -91339,7 +91325,7 @@ type: keyword -- -*`microsoft.rsa.network.dmask`*:: +*`rsa.network.dmask`*:: + -- This key is used for Destionation Device network mask @@ -91348,7 +91334,7 @@ type: keyword -- -*`microsoft.rsa.network.port`*:: +*`rsa.network.port`*:: + -- This key should only be used to capture a Network Port when the directionality is not clear @@ -91357,7 +91343,7 @@ type: long -- -*`microsoft.rsa.network.smask`*:: +*`rsa.network.smask`*:: + -- This key is used for capturing source Network Mask @@ -91366,7 +91352,7 @@ type: keyword -- -*`microsoft.rsa.network.netname`*:: +*`rsa.network.netname`*:: + -- This key is used to capture the network name associated with an IP range. This is configured by the end user. @@ -91375,7 +91361,7 @@ type: keyword -- -*`microsoft.rsa.network.paddr`*:: +*`rsa.network.paddr`*:: + -- Deprecated @@ -91384,91 +91370,91 @@ type: ip -- -*`microsoft.rsa.network.faddr`*:: +*`rsa.network.faddr`*:: + -- type: keyword -- -*`microsoft.rsa.network.lhost`*:: +*`rsa.network.lhost`*:: + -- type: keyword -- -*`microsoft.rsa.network.origin`*:: +*`rsa.network.origin`*:: + -- type: keyword -- -*`microsoft.rsa.network.remote_domain_id`*:: +*`rsa.network.remote_domain_id`*:: + -- type: keyword -- -*`microsoft.rsa.network.addr`*:: +*`rsa.network.addr`*:: + -- type: keyword -- -*`microsoft.rsa.network.dns_a_record`*:: +*`rsa.network.dns_a_record`*:: + -- type: keyword -- -*`microsoft.rsa.network.dns_ptr_record`*:: +*`rsa.network.dns_ptr_record`*:: + -- type: keyword -- -*`microsoft.rsa.network.fhost`*:: +*`rsa.network.fhost`*:: + -- type: keyword -- -*`microsoft.rsa.network.fport`*:: +*`rsa.network.fport`*:: + -- type: keyword -- -*`microsoft.rsa.network.laddr`*:: +*`rsa.network.laddr`*:: + -- type: keyword -- -*`microsoft.rsa.network.linterface`*:: +*`rsa.network.linterface`*:: + -- type: keyword -- -*`microsoft.rsa.network.phost`*:: +*`rsa.network.phost`*:: + -- type: keyword -- -*`microsoft.rsa.network.ad_computer_dst`*:: +*`rsa.network.ad_computer_dst`*:: + -- Deprecated, use host.dst @@ -91477,7 +91463,7 @@ type: keyword -- -*`microsoft.rsa.network.eth_type`*:: +*`rsa.network.eth_type`*:: + -- This key is used to capture Ethernet Type, Used for Layer 3 Protocols Only @@ -91486,7 +91472,7 @@ type: long -- -*`microsoft.rsa.network.ip_proto`*:: +*`rsa.network.ip_proto`*:: + -- This key should be used to capture the Protocol number, all the protocol nubers are converted into string in UI @@ -91495,63 +91481,63 @@ type: long -- -*`microsoft.rsa.network.dns_cname_record`*:: +*`rsa.network.dns_cname_record`*:: + -- type: keyword -- -*`microsoft.rsa.network.dns_id`*:: +*`rsa.network.dns_id`*:: + -- type: keyword -- -*`microsoft.rsa.network.dns_opcode`*:: +*`rsa.network.dns_opcode`*:: + -- type: keyword -- -*`microsoft.rsa.network.dns_resp`*:: +*`rsa.network.dns_resp`*:: + -- type: keyword -- -*`microsoft.rsa.network.dns_type`*:: +*`rsa.network.dns_type`*:: + -- type: keyword -- -*`microsoft.rsa.network.domain1`*:: +*`rsa.network.domain1`*:: + -- type: keyword -- -*`microsoft.rsa.network.host_type`*:: +*`rsa.network.host_type`*:: + -- type: keyword -- -*`microsoft.rsa.network.packet_length`*:: +*`rsa.network.packet_length`*:: + -- type: keyword -- -*`microsoft.rsa.network.host_orig`*:: +*`rsa.network.host_orig`*:: + -- This is used to capture the original hostname in case of a Forwarding Agent or a Proxy in between. @@ -91560,7 +91546,7 @@ type: keyword -- -*`microsoft.rsa.network.rpayload`*:: +*`rsa.network.rpayload`*:: + -- This key is used to capture the total number of payload bytes seen in the retransmitted packets. @@ -91569,7 +91555,7 @@ type: keyword -- -*`microsoft.rsa.network.vlan_name`*:: +*`rsa.network.vlan_name`*:: + -- This key should only be used to capture the name of the Virtual LAN @@ -91579,7 +91565,7 @@ type: keyword -- -*`microsoft.rsa.investigations.ec_activity`*:: +*`rsa.investigations.ec_activity`*:: + -- This key captures the particular event activity(Ex:Logoff) @@ -91588,7 +91574,7 @@ type: keyword -- -*`microsoft.rsa.investigations.ec_theme`*:: +*`rsa.investigations.ec_theme`*:: + -- This key captures the Theme of a particular Event(Ex:Authentication) @@ -91597,7 +91583,7 @@ type: keyword -- -*`microsoft.rsa.investigations.ec_subject`*:: +*`rsa.investigations.ec_subject`*:: + -- This key captures the Subject of a particular Event(Ex:User) @@ -91606,7 +91592,7 @@ type: keyword -- -*`microsoft.rsa.investigations.ec_outcome`*:: +*`rsa.investigations.ec_outcome`*:: + -- This key captures the outcome of a particular Event(Ex:Success) @@ -91615,7 +91601,7 @@ type: keyword -- -*`microsoft.rsa.investigations.event_cat`*:: +*`rsa.investigations.event_cat`*:: + -- This key captures the Event category number @@ -91624,7 +91610,7 @@ type: long -- -*`microsoft.rsa.investigations.event_cat_name`*:: +*`rsa.investigations.event_cat_name`*:: + -- This key captures the event category name corresponding to the event cat code @@ -91633,7 +91619,7 @@ type: keyword -- -*`microsoft.rsa.investigations.event_vcat`*:: +*`rsa.investigations.event_vcat`*:: + -- This is a vendor supplied category. This should be used in situations where the vendor has adopted their own event_category taxonomy. @@ -91642,7 +91628,7 @@ type: keyword -- -*`microsoft.rsa.investigations.analysis_file`*:: +*`rsa.investigations.analysis_file`*:: + -- This is used to capture all indicators used in a File Analysis. This key should be used to capture an analysis of a file @@ -91651,7 +91637,7 @@ type: keyword -- -*`microsoft.rsa.investigations.analysis_service`*:: +*`rsa.investigations.analysis_service`*:: + -- This is used to capture all indicators used in a Service Analysis. This key should be used to capture an analysis of a service @@ -91660,7 +91646,7 @@ type: keyword -- -*`microsoft.rsa.investigations.analysis_session`*:: +*`rsa.investigations.analysis_session`*:: + -- This is used to capture all indicators used for a Session Analysis. This key should be used to capture an analysis of a session @@ -91669,7 +91655,7 @@ type: keyword -- -*`microsoft.rsa.investigations.boc`*:: +*`rsa.investigations.boc`*:: + -- This is used to capture behaviour of compromise @@ -91678,7 +91664,7 @@ type: keyword -- -*`microsoft.rsa.investigations.eoc`*:: +*`rsa.investigations.eoc`*:: + -- This is used to capture Enablers of Compromise @@ -91687,7 +91673,7 @@ type: keyword -- -*`microsoft.rsa.investigations.inv_category`*:: +*`rsa.investigations.inv_category`*:: + -- This used to capture investigation category @@ -91696,7 +91682,7 @@ type: keyword -- -*`microsoft.rsa.investigations.inv_context`*:: +*`rsa.investigations.inv_context`*:: + -- This used to capture investigation context @@ -91705,7 +91691,7 @@ type: keyword -- -*`microsoft.rsa.investigations.ioc`*:: +*`rsa.investigations.ioc`*:: + -- This is key capture indicator of compromise @@ -91715,7 +91701,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_c1`*:: +*`rsa.counters.dclass_c1`*:: + -- This is a generic counter key that should be used with the label dclass.c1.str only @@ -91724,7 +91710,7 @@ type: long -- -*`microsoft.rsa.counters.dclass_c2`*:: +*`rsa.counters.dclass_c2`*:: + -- This is a generic counter key that should be used with the label dclass.c2.str only @@ -91733,7 +91719,7 @@ type: long -- -*`microsoft.rsa.counters.event_counter`*:: +*`rsa.counters.event_counter`*:: + -- This is used to capture the number of times an event repeated @@ -91742,7 +91728,7 @@ type: long -- -*`microsoft.rsa.counters.dclass_r1`*:: +*`rsa.counters.dclass_r1`*:: + -- This is a generic ratio key that should be used with the label dclass.r1.str only @@ -91751,7 +91737,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_c3`*:: +*`rsa.counters.dclass_c3`*:: + -- This is a generic counter key that should be used with the label dclass.c3.str only @@ -91760,7 +91746,7 @@ type: long -- -*`microsoft.rsa.counters.dclass_c1_str`*:: +*`rsa.counters.dclass_c1_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c1 only @@ -91769,7 +91755,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_c2_str`*:: +*`rsa.counters.dclass_c2_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c2 only @@ -91778,7 +91764,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_r1_str`*:: +*`rsa.counters.dclass_r1_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r1 only @@ -91787,7 +91773,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_r2`*:: +*`rsa.counters.dclass_r2`*:: + -- This is a generic ratio key that should be used with the label dclass.r2.str only @@ -91796,7 +91782,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_c3_str`*:: +*`rsa.counters.dclass_c3_str`*:: + -- This is a generic counter string key that should be used with the label dclass.c3 only @@ -91805,7 +91791,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_r3`*:: +*`rsa.counters.dclass_r3`*:: + -- This is a generic ratio key that should be used with the label dclass.r3.str only @@ -91814,7 +91800,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_r2_str`*:: +*`rsa.counters.dclass_r2_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r2 only @@ -91823,7 +91809,7 @@ type: keyword -- -*`microsoft.rsa.counters.dclass_r3_str`*:: +*`rsa.counters.dclass_r3_str`*:: + -- This is a generic ratio string key that should be used with the label dclass.r3 only @@ -91833,7 +91819,7 @@ type: keyword -- -*`microsoft.rsa.identity.auth_method`*:: +*`rsa.identity.auth_method`*:: + -- This key is used to capture authentication methods used only @@ -91842,7 +91828,7 @@ type: keyword -- -*`microsoft.rsa.identity.user_role`*:: +*`rsa.identity.user_role`*:: + -- This key is used to capture the Role of a user only @@ -91851,7 +91837,7 @@ type: keyword -- -*`microsoft.rsa.identity.dn`*:: +*`rsa.identity.dn`*:: + -- X.500 (LDAP) Distinguished Name @@ -91860,7 +91846,7 @@ type: keyword -- -*`microsoft.rsa.identity.logon_type`*:: +*`rsa.identity.logon_type`*:: + -- This key is used to capture the type of logon method used. @@ -91869,7 +91855,7 @@ type: keyword -- -*`microsoft.rsa.identity.profile`*:: +*`rsa.identity.profile`*:: + -- This key is used to capture the user profile @@ -91878,7 +91864,7 @@ type: keyword -- -*`microsoft.rsa.identity.accesses`*:: +*`rsa.identity.accesses`*:: + -- This key is used to capture actual privileges used in accessing an object @@ -91887,7 +91873,7 @@ type: keyword -- -*`microsoft.rsa.identity.realm`*:: +*`rsa.identity.realm`*:: + -- Radius realm or similar grouping of accounts @@ -91896,7 +91882,7 @@ type: keyword -- -*`microsoft.rsa.identity.user_sid_dst`*:: +*`rsa.identity.user_sid_dst`*:: + -- This key captures Destination User Session ID @@ -91905,7 +91891,7 @@ type: keyword -- -*`microsoft.rsa.identity.dn_src`*:: +*`rsa.identity.dn_src`*:: + -- An X.500 (LDAP) Distinguished name that is used in a context that indicates a Source dn @@ -91914,7 +91900,7 @@ type: keyword -- -*`microsoft.rsa.identity.org`*:: +*`rsa.identity.org`*:: + -- This key captures the User organization @@ -91923,7 +91909,7 @@ type: keyword -- -*`microsoft.rsa.identity.dn_dst`*:: +*`rsa.identity.dn_dst`*:: + -- An X.500 (LDAP) Distinguished name that used in a context that indicates a Destination dn @@ -91932,7 +91918,7 @@ type: keyword -- -*`microsoft.rsa.identity.firstname`*:: +*`rsa.identity.firstname`*:: + -- This key is for First Names only, this is used for Healthcare predominantly to capture Patients information @@ -91941,7 +91927,7 @@ type: keyword -- -*`microsoft.rsa.identity.lastname`*:: +*`rsa.identity.lastname`*:: + -- This key is for Last Names only, this is used for Healthcare predominantly to capture Patients information @@ -91950,7 +91936,7 @@ type: keyword -- -*`microsoft.rsa.identity.user_dept`*:: +*`rsa.identity.user_dept`*:: + -- User's Department Names only @@ -91959,7 +91945,7 @@ type: keyword -- -*`microsoft.rsa.identity.user_sid_src`*:: +*`rsa.identity.user_sid_src`*:: + -- This key captures Source User Session ID @@ -91968,7 +91954,7 @@ type: keyword -- -*`microsoft.rsa.identity.federated_sp`*:: +*`rsa.identity.federated_sp`*:: + -- This key is the Federated Service Provider. This is the application requesting authentication. @@ -91977,7 +91963,7 @@ type: keyword -- -*`microsoft.rsa.identity.federated_idp`*:: +*`rsa.identity.federated_idp`*:: + -- This key is the federated Identity Provider. This is the server providing the authentication. @@ -91986,7 +91972,7 @@ type: keyword -- -*`microsoft.rsa.identity.logon_type_desc`*:: +*`rsa.identity.logon_type_desc`*:: + -- This key is used to capture the textual description of an integer logon type as stored in the meta key 'logon.type'. @@ -91995,7 +91981,7 @@ type: keyword -- -*`microsoft.rsa.identity.middlename`*:: +*`rsa.identity.middlename`*:: + -- This key is for Middle Names only, this is used for Healthcare predominantly to capture Patients information @@ -92004,7 +91990,7 @@ type: keyword -- -*`microsoft.rsa.identity.password`*:: +*`rsa.identity.password`*:: + -- This key is for Passwords seen in any session, plain text or encrypted @@ -92013,7 +91999,7 @@ type: keyword -- -*`microsoft.rsa.identity.host_role`*:: +*`rsa.identity.host_role`*:: + -- This key should only be used to capture the role of a Host Machine @@ -92022,7 +92008,7 @@ type: keyword -- -*`microsoft.rsa.identity.ldap`*:: +*`rsa.identity.ldap`*:: + -- This key is for Uninterpreted LDAP values. Ldap Values that don’t have a clear query or response context @@ -92031,7 +92017,7 @@ type: keyword -- -*`microsoft.rsa.identity.ldap_query`*:: +*`rsa.identity.ldap_query`*:: + -- This key is the Search criteria from an LDAP search @@ -92040,7 +92026,7 @@ type: keyword -- -*`microsoft.rsa.identity.ldap_response`*:: +*`rsa.identity.ldap_response`*:: + -- This key is to capture Results from an LDAP search @@ -92049,7 +92035,7 @@ type: keyword -- -*`microsoft.rsa.identity.owner`*:: +*`rsa.identity.owner`*:: + -- This is used to capture username the process or service is running as, the author of the task @@ -92058,7 +92044,7 @@ type: keyword -- -*`microsoft.rsa.identity.service_account`*:: +*`rsa.identity.service_account`*:: + -- This key is a windows specific key, used for capturing name of the account a service (referenced in the event) is running under. Legacy Usage @@ -92068,7 +92054,7 @@ type: keyword -- -*`microsoft.rsa.email.email_dst`*:: +*`rsa.email.email_dst`*:: + -- This key is used to capture the Destination email address only, when the destination context is not clear use email @@ -92077,7 +92063,7 @@ type: keyword -- -*`microsoft.rsa.email.email_src`*:: +*`rsa.email.email_src`*:: + -- This key is used to capture the source email address only, when the source context is not clear use email @@ -92086,7 +92072,7 @@ type: keyword -- -*`microsoft.rsa.email.subject`*:: +*`rsa.email.subject`*:: + -- This key is used to capture the subject string from an Email only. @@ -92095,7 +92081,7 @@ type: keyword -- -*`microsoft.rsa.email.email`*:: +*`rsa.email.email`*:: + -- This key is used to capture a generic email address where the source or destination context is not clear @@ -92104,7 +92090,7 @@ type: keyword -- -*`microsoft.rsa.email.trans_from`*:: +*`rsa.email.trans_from`*:: + -- Deprecated key defined only in table map. @@ -92113,7 +92099,7 @@ type: keyword -- -*`microsoft.rsa.email.trans_to`*:: +*`rsa.email.trans_to`*:: + -- Deprecated key defined only in table map. @@ -92123,7 +92109,7 @@ type: keyword -- -*`microsoft.rsa.file.privilege`*:: +*`rsa.file.privilege`*:: + -- Deprecated, use permissions @@ -92132,7 +92118,7 @@ type: keyword -- -*`microsoft.rsa.file.attachment`*:: +*`rsa.file.attachment`*:: + -- This key captures the attachment file name @@ -92141,14 +92127,14 @@ type: keyword -- -*`microsoft.rsa.file.filesystem`*:: +*`rsa.file.filesystem`*:: + -- type: keyword -- -*`microsoft.rsa.file.binary`*:: +*`rsa.file.binary`*:: + -- Deprecated key defined only in table map. @@ -92157,7 +92143,7 @@ type: keyword -- -*`microsoft.rsa.file.filename_dst`*:: +*`rsa.file.filename_dst`*:: + -- This is used to capture name of the file targeted by the action @@ -92166,7 +92152,7 @@ type: keyword -- -*`microsoft.rsa.file.filename_src`*:: +*`rsa.file.filename_src`*:: + -- This is used to capture name of the parent filename, the file which performed the action @@ -92175,14 +92161,14 @@ type: keyword -- -*`microsoft.rsa.file.filename_tmp`*:: +*`rsa.file.filename_tmp`*:: + -- type: keyword -- -*`microsoft.rsa.file.directory_dst`*:: +*`rsa.file.directory_dst`*:: + -- This key is used to capture the directory of the target process or file @@ -92191,7 +92177,7 @@ type: keyword -- -*`microsoft.rsa.file.directory_src`*:: +*`rsa.file.directory_src`*:: + -- This key is used to capture the directory of the source process or file @@ -92200,7 +92186,7 @@ type: keyword -- -*`microsoft.rsa.file.file_entropy`*:: +*`rsa.file.file_entropy`*:: + -- This is used to capture entropy vale of a file @@ -92209,7 +92195,7 @@ type: double -- -*`microsoft.rsa.file.file_vendor`*:: +*`rsa.file.file_vendor`*:: + -- This is used to capture Company name of file located in version_info @@ -92218,7 +92204,7 @@ type: keyword -- -*`microsoft.rsa.file.task_name`*:: +*`rsa.file.task_name`*:: + -- This is used to capture name of the task @@ -92228,7 +92214,7 @@ type: keyword -- -*`microsoft.rsa.web.fqdn`*:: +*`rsa.web.fqdn`*:: + -- Fully Qualified Domain Names @@ -92237,7 +92223,7 @@ type: keyword -- -*`microsoft.rsa.web.web_cookie`*:: +*`rsa.web.web_cookie`*:: + -- This key is used to capture the Web cookies specifically. @@ -92246,14 +92232,14 @@ type: keyword -- -*`microsoft.rsa.web.alias_host`*:: +*`rsa.web.alias_host`*:: + -- type: keyword -- -*`microsoft.rsa.web.reputation_num`*:: +*`rsa.web.reputation_num`*:: + -- Reputation Number of an entity. Typically used for Web Domains @@ -92262,7 +92248,7 @@ type: double -- -*`microsoft.rsa.web.web_ref_domain`*:: +*`rsa.web.web_ref_domain`*:: + -- Web referer's domain @@ -92271,7 +92257,7 @@ type: keyword -- -*`microsoft.rsa.web.web_ref_query`*:: +*`rsa.web.web_ref_query`*:: + -- This key captures Web referer's query portion of the URL @@ -92280,14 +92266,14 @@ type: keyword -- -*`microsoft.rsa.web.remote_domain`*:: +*`rsa.web.remote_domain`*:: + -- type: keyword -- -*`microsoft.rsa.web.web_ref_page`*:: +*`rsa.web.web_ref_page`*:: + -- This key captures Web referer's page information @@ -92296,7 +92282,7 @@ type: keyword -- -*`microsoft.rsa.web.web_ref_root`*:: +*`rsa.web.web_ref_root`*:: + -- Web referer's root URL path @@ -92305,77 +92291,77 @@ type: keyword -- -*`microsoft.rsa.web.cn_asn_dst`*:: +*`rsa.web.cn_asn_dst`*:: + -- type: keyword -- -*`microsoft.rsa.web.cn_rpackets`*:: +*`rsa.web.cn_rpackets`*:: + -- type: keyword -- -*`microsoft.rsa.web.urlpage`*:: +*`rsa.web.urlpage`*:: + -- type: keyword -- -*`microsoft.rsa.web.urlroot`*:: +*`rsa.web.urlroot`*:: + -- type: keyword -- -*`microsoft.rsa.web.p_url`*:: +*`rsa.web.p_url`*:: + -- type: keyword -- -*`microsoft.rsa.web.p_user_agent`*:: +*`rsa.web.p_user_agent`*:: + -- type: keyword -- -*`microsoft.rsa.web.p_web_cookie`*:: +*`rsa.web.p_web_cookie`*:: + -- type: keyword -- -*`microsoft.rsa.web.p_web_method`*:: +*`rsa.web.p_web_method`*:: + -- type: keyword -- -*`microsoft.rsa.web.p_web_referer`*:: +*`rsa.web.p_web_referer`*:: + -- type: keyword -- -*`microsoft.rsa.web.web_extension_tmp`*:: +*`rsa.web.web_extension_tmp`*:: + -- type: keyword -- -*`microsoft.rsa.web.web_page`*:: +*`rsa.web.web_page`*:: + -- type: keyword @@ -92383,7 +92369,7 @@ type: keyword -- -*`microsoft.rsa.threat.threat_category`*:: +*`rsa.threat.threat_category`*:: + -- This key captures Threat Name/Threat Category/Categorization of alert @@ -92392,7 +92378,7 @@ type: keyword -- -*`microsoft.rsa.threat.threat_desc`*:: +*`rsa.threat.threat_desc`*:: + -- This key is used to capture the threat description from the session directly or inferred @@ -92401,7 +92387,7 @@ type: keyword -- -*`microsoft.rsa.threat.alert`*:: +*`rsa.threat.alert`*:: + -- This key is used to capture name of the alert @@ -92410,7 +92396,7 @@ type: keyword -- -*`microsoft.rsa.threat.threat_source`*:: +*`rsa.threat.threat_source`*:: + -- This key is used to capture source of the threat @@ -92420,7 +92406,7 @@ type: keyword -- -*`microsoft.rsa.crypto.crypto`*:: +*`rsa.crypto.crypto`*:: + -- This key is used to capture the Encryption Type or Encryption Key only @@ -92429,7 +92415,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cipher_src`*:: +*`rsa.crypto.cipher_src`*:: + -- This key is for Source (Client) Cipher @@ -92438,7 +92424,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_subject`*:: +*`rsa.crypto.cert_subject`*:: + -- This key is used to capture the Certificate organization only @@ -92447,7 +92433,7 @@ type: keyword -- -*`microsoft.rsa.crypto.peer`*:: +*`rsa.crypto.peer`*:: + -- This key is for Encryption peer's IP Address @@ -92456,7 +92442,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cipher_size_src`*:: +*`rsa.crypto.cipher_size_src`*:: + -- This key captures Source (Client) Cipher Size @@ -92465,7 +92451,7 @@ type: long -- -*`microsoft.rsa.crypto.ike`*:: +*`rsa.crypto.ike`*:: + -- IKE negotiation phase. @@ -92474,7 +92460,7 @@ type: keyword -- -*`microsoft.rsa.crypto.scheme`*:: +*`rsa.crypto.scheme`*:: + -- This key captures the Encryption scheme used @@ -92483,7 +92469,7 @@ type: keyword -- -*`microsoft.rsa.crypto.peer_id`*:: +*`rsa.crypto.peer_id`*:: + -- This key is for Encryption peer’s identity @@ -92492,7 +92478,7 @@ type: keyword -- -*`microsoft.rsa.crypto.sig_type`*:: +*`rsa.crypto.sig_type`*:: + -- This key captures the Signature Type @@ -92501,14 +92487,14 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_issuer`*:: +*`rsa.crypto.cert_issuer`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.cert_host_name`*:: +*`rsa.crypto.cert_host_name`*:: + -- Deprecated key defined only in table map. @@ -92517,7 +92503,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_error`*:: +*`rsa.crypto.cert_error`*:: + -- This key captures the Certificate Error String @@ -92526,7 +92512,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cipher_dst`*:: +*`rsa.crypto.cipher_dst`*:: + -- This key is for Destination (Server) Cipher @@ -92535,7 +92521,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cipher_size_dst`*:: +*`rsa.crypto.cipher_size_dst`*:: + -- This key captures Destination (Server) Cipher Size @@ -92544,7 +92530,7 @@ type: long -- -*`microsoft.rsa.crypto.ssl_ver_src`*:: +*`rsa.crypto.ssl_ver_src`*:: + -- Deprecated, use version @@ -92553,21 +92539,21 @@ type: keyword -- -*`microsoft.rsa.crypto.d_certauth`*:: +*`rsa.crypto.d_certauth`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.s_certauth`*:: +*`rsa.crypto.s_certauth`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.ike_cookie1`*:: +*`rsa.crypto.ike_cookie1`*:: + -- ID of the negotiation — sent for ISAKMP Phase One @@ -92576,7 +92562,7 @@ type: keyword -- -*`microsoft.rsa.crypto.ike_cookie2`*:: +*`rsa.crypto.ike_cookie2`*:: + -- ID of the negotiation — sent for ISAKMP Phase Two @@ -92585,14 +92571,14 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_checksum`*:: +*`rsa.crypto.cert_checksum`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.cert_host_cat`*:: +*`rsa.crypto.cert_host_cat`*:: + -- This key is used for the hostname category value of a certificate @@ -92601,7 +92587,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_serial`*:: +*`rsa.crypto.cert_serial`*:: + -- This key is used to capture the Certificate serial number only @@ -92610,7 +92596,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_status`*:: +*`rsa.crypto.cert_status`*:: + -- This key captures Certificate validation status @@ -92619,7 +92605,7 @@ type: keyword -- -*`microsoft.rsa.crypto.ssl_ver_dst`*:: +*`rsa.crypto.ssl_ver_dst`*:: + -- Deprecated, use version @@ -92628,35 +92614,35 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_keysize`*:: +*`rsa.crypto.cert_keysize`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.cert_username`*:: +*`rsa.crypto.cert_username`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.https_insact`*:: +*`rsa.crypto.https_insact`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.https_valid`*:: +*`rsa.crypto.https_valid`*:: + -- type: keyword -- -*`microsoft.rsa.crypto.cert_ca`*:: +*`rsa.crypto.cert_ca`*:: + -- This key is used to capture the Certificate signing authority only @@ -92665,7 +92651,7 @@ type: keyword -- -*`microsoft.rsa.crypto.cert_common`*:: +*`rsa.crypto.cert_common`*:: + -- This key is used to capture the Certificate common name only @@ -92675,7 +92661,7 @@ type: keyword -- -*`microsoft.rsa.wireless.wlan_ssid`*:: +*`rsa.wireless.wlan_ssid`*:: + -- This key is used to capture the ssid of a Wireless Session @@ -92684,7 +92670,7 @@ type: keyword -- -*`microsoft.rsa.wireless.access_point`*:: +*`rsa.wireless.access_point`*:: + -- This key is used to capture the access point name. @@ -92693,7 +92679,7 @@ type: keyword -- -*`microsoft.rsa.wireless.wlan_channel`*:: +*`rsa.wireless.wlan_channel`*:: + -- This is used to capture the channel names @@ -92702,7 +92688,7 @@ type: long -- -*`microsoft.rsa.wireless.wlan_name`*:: +*`rsa.wireless.wlan_name`*:: + -- This key captures either WLAN number/name @@ -92712,7 +92698,7 @@ type: keyword -- -*`microsoft.rsa.storage.disk_volume`*:: +*`rsa.storage.disk_volume`*:: + -- A unique name assigned to logical units (volumes) within a physical disk @@ -92721,7 +92707,7 @@ type: keyword -- -*`microsoft.rsa.storage.lun`*:: +*`rsa.storage.lun`*:: + -- Logical Unit Number.This key is a very useful concept in Storage. @@ -92730,7 +92716,7 @@ type: keyword -- -*`microsoft.rsa.storage.pwwn`*:: +*`rsa.storage.pwwn`*:: + -- This uniquely identifies a port on a HBA. @@ -92740,7 +92726,7 @@ type: keyword -- -*`microsoft.rsa.physical.org_dst`*:: +*`rsa.physical.org_dst`*:: + -- This is used to capture the destination organization based on the GEOPIP Maxmind database. @@ -92749,7 +92735,7 @@ type: keyword -- -*`microsoft.rsa.physical.org_src`*:: +*`rsa.physical.org_src`*:: + -- This is used to capture the source organization based on the GEOPIP Maxmind database. @@ -92759,7 +92745,7 @@ type: keyword -- -*`microsoft.rsa.healthcare.patient_fname`*:: +*`rsa.healthcare.patient_fname`*:: + -- This key is for First Names only, this is used for Healthcare predominantly to capture Patients information @@ -92768,7 +92754,7 @@ type: keyword -- -*`microsoft.rsa.healthcare.patient_id`*:: +*`rsa.healthcare.patient_id`*:: + -- This key captures the unique ID for a patient @@ -92777,7 +92763,7 @@ type: keyword -- -*`microsoft.rsa.healthcare.patient_lname`*:: +*`rsa.healthcare.patient_lname`*:: + -- This key is for Last Names only, this is used for Healthcare predominantly to capture Patients information @@ -92786,7 +92772,7 @@ type: keyword -- -*`microsoft.rsa.healthcare.patient_mname`*:: +*`rsa.healthcare.patient_mname`*:: + -- This key is for Middle Names only, this is used for Healthcare predominantly to capture Patients information @@ -92796,7 +92782,7 @@ type: keyword -- -*`microsoft.rsa.endpoint.host_state`*:: +*`rsa.endpoint.host_state`*:: + -- This key is used to capture the current state of the machine, such as blacklisted, infected, firewall disabled and so on @@ -92805,7 +92791,7 @@ type: keyword -- -*`microsoft.rsa.endpoint.registry_key`*:: +*`rsa.endpoint.registry_key`*:: + -- This key captures the path to the registry key @@ -92814,7 +92800,7 @@ type: keyword -- -*`microsoft.rsa.endpoint.registry_value`*:: +*`rsa.endpoint.registry_value`*:: + -- This key captures values or decorators used within a registry entry diff --git a/x-pack/filebeat/module/cisco/_meta/fields.yml b/x-pack/filebeat/module/cisco/_meta/fields.yml index 8209de0cd6f..fbe1e33d2c8 100644 --- a/x-pack/filebeat/module/cisco/_meta/fields.yml +++ b/x-pack/filebeat/module/cisco/_meta/fields.yml @@ -3,8 +3,4 @@ description: > Module for handling Cisco network device logs. fields: - - name: cisco - type: group - description: > - Fields from Cisco logs. - fields: + diff --git a/x-pack/filebeat/module/cisco/asa/_meta/fields.yml b/x-pack/filebeat/module/cisco/asa/_meta/fields.yml index 5915c246ff5..678615265fa 100644 --- a/x-pack/filebeat/module/cisco/asa/_meta/fields.yml +++ b/x-pack/filebeat/module/cisco/asa/_meta/fields.yml @@ -1,4 +1,4 @@ -- name: asa +- name: cisco.asa type: group description: > Fields for Cisco ASA Firewall. diff --git a/x-pack/filebeat/module/cisco/fields.go b/x-pack/filebeat/module/cisco/fields.go index a644fa716ac..695aec368e4 100644 --- a/x-pack/filebeat/module/cisco/fields.go +++ b/x-pack/filebeat/module/cisco/fields.go @@ -19,5 +19,5 @@ func init() { // AssetCisco returns asset data. // This is the base64 encoded gzipped contents of module/cisco. func AssetCisco() string { - return "eJzsvW1zIzeSIPx9fgUeRzznbofMttsve+Ob3QutpB7rpl+0re723sVEVICoJAmrCqgGUKToX3+BBKpYrEKREgVQ6j3Phwm3SCYSiUQi3/NbcgPrXwjjmsm/EGK4KeAXcub/mYNmileGS/EL+be/EELIG5nXBZCZVGRBRV5wMXdfJwLMSqobksOSMyCFnOvJXwiZcShy/Qv++FsiaAmb5ez/zLqCX8hcybryfwmsav/3CgGRmZKlX7FZwv6vu0x3Kapp+7fQYjsW7C4qlV/z9PqUvOIKVrQoJp2v9tffYFCC1nQOGc+3IDtUbmC9kmr7kx3oEPJhAR1MPGzCcxCGzzioDU4BVHQ9m/HbO6IBt7SsLDdo0JpLcXcc3+HfaeHXI3RmQJH/3yJ8V0RlrRhkXBhQM8ogBuWuESZpYeKhmgWQWSFXRCoCSxBmJ1o5aMMFtfDj4na+AfwgBFVdQGb/MwZSb2kJRM4QhVPGQGtyJoVRsiCvuTa4GDELakhJDVtATsyC6ztg6U+31qBS4GrhOry4xj+49Tw574Rh96CPhmZn0fvgWtKqgjxrrkwVwLP3x70CxigqdEEN5A3tLq8IzXMFWt8Dl4XU5s5Um9G6MBmK0V/IjBYaHoqzXf4e2FZShbAtpJg/FBML+i6YbMmXyAfZ5a77nWYXq8c60i72dz3XLt4pDreL094TNgsF1GQFLKGIowdYeAThobQoabGiCsgLMpVGgLGYzmacTcg7gTJnCWr9bSFXJ8T+Xw9cKXNQ1MAJWfD5wj42+HX7j7tsi1EDc6nWMXZ25mG1z9/4zl7ZR7FRU5Zc1frEf6e/P6Pk71ScEDBs536YFAKYu4BR9LWPgn+uuwoabovim74TE87KKrOLBrDQiz4778Th8uzNFf5y/4JM5rEWtKDuSuuRfaYRK5+u3nbWJltrh3QBWmUKmFS5vh8iD9DwqdZ8LiAn56dXpL94g9jM5FFNG2vWVHIFqhEu5zADoeGJ2DuvPpx/WfaORfhPe+dPe+dPe+eLtnfIRw3k4uzafzQR1Ex49acZdKAZFCLnE7aPWnQ7n9+DBf60nfbjtM0WfTr/aVn9aVn9aVltLbjXstLAasVNiGnk9Hdg4wv2lntPV17TR+Jee7jkwr7Su51HX7h1lxLFO1l3XOqo1t3lu+utgBnZacRR1H+zgt/jybqjHmgfV6ddW+g7eWhGGS/CfLzTgru+OLvfiTQLESPJasHZwolHb20qmIHS5NlsIxRPyPXbN1cn5Pp/X58QKqyK0wM7k8osnk/I6QY4o4JMgVCyoCpHwetipSeEkkpJI5ksTggKsdKFWeWsL22ter/WBkqi5cxYIBNyaUgOQhrYUv+9jGe01i3t3U/7L5Tb5mTAgj6iO2kttEnPLpBLUCvFjX2uVA0Dfh0e0p7Ls+OguizUhJo3puNqAQrwM/+EkQXVZAogiJxqUEvIh/tTW7HhfZsZXr6dWxm/W4i1oNvKyvjqY+uHlujocXreO+ZdK+y6Vb1T+WCttBtYWyuu1tYIloTRytSe/oqu2ouD1h6TJWi7aWk/74Em5LWck3OwT5oKb8TB4n2kDt1OAxcNTavnssiAPcKJqe9J7m48k8LYB9neDy60ocI0aOggjoaXhyCYU9P/YIidt+7tEoQaL05p41UjC240oeQtmN+4EfYZ8Kc/GbBGu1m9kHWREwFLUFaCNnxXUaWBvAFDLWrU5YZslnr2Ws71iyvKbsDo5wPw51wBM8X6xHkeuEXrPThh4ThcdNCcBAk5tDruRsmB8dSj5DlUChiaShaTHGbcKgxSFIiWodPCqu9VGKtSz/tKdlwO9Gf8xt/zy/PvyZIWtb/xrUruvgW3lBmre7jzUoODwN1xVNcct+D37HFUVBnO6oIq/L0/2MkoZwxAH8QpIc4YQB7nlNEjWR73TF7+eSa7z8SumuZAHnZ95fT3DDfSP5Yng92SHiL0kqOmwOm+TxE3S7ZU9/9hmGlDDZQgzFNEjtY5NxkraO8OPxH0QJieb+6JILYY+JueCGJcHIZYWo2pkRxPl9NyoIdIj7Rkm4GLFcSyoUb0mpCd2fli4xaw2Az0kIGS8DAroqeHDKDvsSLGqTgIuR6FiqLjVQmSz5FrsM1I5CMBCt6bfOwYanU9iDY0+/d/Wm8btWdSMPs4UCOfumU7Im6WPK047FL3zC7DZ5zR7n1+Lecu0tDkstQiB4XOUvCCarD1Gb+FnGgwFsjWj7fX0OMGS3MIA9gPNljaQxiAvtehDD2B8f1LhzHmYF/3oMn9aDAIpifhy1+lNl0RWfQ5UoPIuZg3H+oQ23R8SF8OffkhDDb40ShhL6+WPzY5FqPXvU/cwe6N/FKJu/w5NXl//n+XvIN4cxLZ0JcLzpHW9ZblhJI5X4JonWRfriJgSXSY/yKtBZI/ReXvy4hojDo0ZLXOFHxOcNbd4CEeMO57ukYqX7ilyRVepBPvzTaUfFhXQBgdSpApEOBmAYp8vBTm+5+JVORVIan54SWZUo1c1ATIZnxeK1T99uz7EHX3C943hkHTGZ8R/AvBFLijWMfNyl+8g0GqFVV5MqWuI9E62+5S8vLq05a+R4mCgvaPlDS5Le4R9Whjoj04TvX1//bfUvE5x6oL95ttbWUPHVLpXzsSIy6vPv0cIEE4J4dEIEGL0ZDKMV6fDaMOFcdDX58F0BzUUWLXv+JS5PL8IVFSh283WIpgDouVPmknW8Gy5H422ihalxtFCy+KNV3OZFEAM1J9iQLYUu8Rcm4sz3FNmCMd5BbTLUX1teyrLWQHoZ+gxVey6VNRVUupMdmtlIJM14NDI0TB5xo0lj9pXlbF2p+T/TIm6gJlC6J5DuTZd8QsVE1e/vTTc7KimmgA0a6ygxJPQnm9AyV0JYWGdKRgXwxXMFmLtiRO1OXUCT17lXUQAnlGp3IJHWJwEcysbMSbNgpoOXp/2BfDNo9MKsh53dfTYhDqq5Dm2DoW+Ixw88/65Xff/1U7kf6iQgHaIP3PwW7+ae3B13QNirwkF4LRSteFi6xYk/Jecj0E/YHBj0BuZWiVH16Sf7XbPSE//ED+lTCprL6Mu/CLnpD/Vpj/Yb/INdkmylfBIxQyD5QLPxFbV6wgY7QoppTdpNWAHXJNwQA1zq6wRASRV5ILg6aJgXCCMzJHBkrJRPlpG31QV8A4LRBjxFQbqaxmLdZO67AfLGnBc8cYIaQImcla5PaFKQCR52LulaO9yYvbN2IAOUYs0F+HHWGjkVNYF5LmT+Wd8+gQzf8AUoJRnAWsDm8Kd7+MtrB77hshbJ99ajYarZw1xzYhv8qVPZqhzckFkcoaY0aSG4BqD9GexIv3hRBNSSwGW/I8y1NFXS8ayTMHgfWyGsuqamdHe7twyZWpaWGN9i3fuwi4OHjJrdmNsXIkhtuFv+qX50RZaa3RoYJEo2oOpv3aXkpolSjp6dEp0VTr76KEShIKGgr+y/PG9/oeSmmAXHt+ZwrwoZ2uxwQlwT4jLhDzBQRe/EqZrgqeMrPhSZvzmg/U/iehm1mZm5Df8dbZN6Ap0/Rc11gt/gn5rxFhdOJlxotHiNHbVa1xdHV2euV1X1+Uy8tKqr7GS/CJ/OLSIOqn4f7wDRrQEEfTPeRK3Tbl681PNga703PQMp+Qlz/9TFZI9xKoILQowr4CdOqjmrTxH5EVKHBgscEH1YZI0SsX2Sbio6uJXzYRA3c1RdjW0+43qXIkHGY1AVsIWcj5uh+Im3E10GIJ+YmwBVWUGUdEe6nXiD86zQWphc/pKbZ85qMVtbELul2gPmUQYUfsEi2K0iqZUjRhBEVXozINJWtPraQMNVYXoxDe5yAZq1UDURsqcqpyIqQqacH/COX3SlUG6ZP7LIeDSSTr6eBJuheRNli3yLwo+AxwxwEDXwOTIh9RsDfHnWmT0s+yY0NcMFlWBZggA4w6USkq8Ebxnhjs1Jsp80iMfG3XDrLzGCtvc+Yo+5VSmEWkY9rUp8bKedlkOeWPRPgLkacguwX5hxSpuy3sEIt29UbFdOm1H/oUHoioZDf6lBi4Nf7ykSUo3SmnyHflgQXO96HMtgYaa5ubMj0mVQ55unfQJ9n4Z0q3KzY6RpNp036xG18fvlZKlhOEWmNRvmYgqOLSqfVlXRj+reGgCK2qoql+2fSyKamg81BpLiEFhne22vo0raQIN19rIlfCRcYMLau+Z9BjjJ03lRwmH3GjCVtwa93IHPSEvKm1QTOpC9TeSmpG8nKpgQMPaacAm80s3ks4hiaEh9ws6GiHraBAMMcQ1KrWOV/y3Go2yA9hQXbdCLIPPeKFN3lbcXW0HW7O08WCbi0nclOsm75XRqK+ZpFybRl3+kYjHvqoC+fESuNWnk0GS7bpZLKOLYHKgSL3UIgt/WNfFdQgP9dQH42VLHc7LtrIxxXVBJHIR/gGkfs+NlEjKgVbBE0g0+alSfD6zssUuFZZAlSrLIX2XMUURdtAX0aHmkBX6rwij2NC9szH4BszeC7v9eYcKjb3ybVDggWbB6LXDSG2I4iygRIfQ7HWdZE67DRiRcnaMFnCC4dDa7xgVvagASaxfOFIsGVAjjAILGHQCPdoG2tW90WAncjOLpdP2uLFQe9A90q3lS4WGsadKmB8xjeGT1i79U3cR3jK68rps5kCB9C6GHm+KZhoXFS5D7IE8fZm87EO4dO2ld61BKUi7659aizXTUJA369GfF/Y3ugEslUlqSupeUTBcSfeQnNa5K7DFKbyN3d3tAtPXZhhq+zHEkWiLkFxdl9ZFNzbEarYdmysW8nW3gwnltz9HmxtCSKXyifM7tyZnP7+CN1rmtBuoKF5F7H0teADclsJuhsxJ+lT9qr7anghfdW/FzPey7WgbW6xkIZQHBBhkQwn0BZynjWJKo8i1BtGvLdQP0bPlC3Z93dMt8Ku1Sg+woq/LDhbp749O+TCFSLgm2uLYj0il4NjlhIT8H1dACIWFqdSGLhNrbG2CF0K56/b9EOlea7t/+GjSosGoVADmD2PM1tQMYdMwCq1LBgLXMKqE+pHJcQYxae1gY6EGOboa4e61da7z19YdOiqPzvs4VYLK3iytpW7iIaGYD+/yCHT1d8Cxi1WgFmCNQ0H9SbnSy1BTcg1uEOpNagJnQO28vaZ7jOpGhwGsBswTm9nbtyW+32nb4VUZKrkyn7W/NXrms7sGu0nfZlfUWViu+lawLE9Kv5OyUF16LHulCzyVm1MdaVkBT6gmOotPhWEFqBMm12kNov6v7nwlhcfnSYAmIQUUJhzIqT4VkEFaMnsyn5As+GYTw6rlbIXprVX8CRRj3vBXYStCf8MdrbiZuGVZSfryTkuOMVqE0Gk+HYu7X/veAlQSckCimPCfdNOMPAFImCRlDNipYPhoCfkeiNT+oMNupVVaTA+c+V8tbZGjCsZdck2uRe/nvCUsKLWpmFI/4/BMeFPuLYn6WuivX/DKr746bgKdHTtx92wsEXv2jKlU8q+3md4WSzPEQtCtZaMo7/UnkbQnsQDe81v4BdCSbVYa85oQXKub05IpXAmCg4R+zqsKFNFD6m9vOdD7+psFC3BgNKkohq7eGls5OB6ETBZllaKya2g/bC0ZmseGhk+Te49eCyNr3OGCR4mJ76ZLKt6eAcTHBslKy5yufL5tEwKBpU5aTMpRokx2OasLoo1+VzTwjk/c1lSLrzUEJ2FCjnydHW9nrHUpR1btyrhay5uIPe1QE0iOtXonfIGiv3kqxa1Cc93HVwx6AqRVNR1Jzs5t0QfgQa9d9ePhde7ynteyfWwXU8bdAZV8v5gp9QuVr8mYuv4f7em/UNkTXvGi/R3vN3yK1ytvcYK8poBaSJHEHa3aVCcFlngNU32iFzjko3a3H8fOw+gfWFG/QLAbvRBLQdieIz96vahW1C9aG+oVQsDVYY1W7jM36bGpi0zPGsg9VqE2Y20y0y0YvZX7b+HlabEynNBOObc1YIVQJX9EzbC26DmCwg3Q/BcYef+6IMTfvWwz9OTfrGYLKfNJF0523qwfNmousfrhaNej+3p62ojiMC4x+84AdLAlThzq7uejOOeUmfBJXeNt+RzXubLc/LWSZpnvnEDcdP2fNGvxe15WK92DujH8OV33M+X50hSX/LWiomh92A7IufSAN0WJo6JrCxYcR02Upd6nbKX/XZU1xdoO3Vhpx97ZCxy4kt3tpmRe3m+V5ON5Z/bo8laxF6KfKPRTsiZq8/0/U4L98FubRYRVNvf+P4r746b1qat3JSmfYxqUYB2lJHuQVlJsqSK02kxqAJ0TRm4IFVBRwSBBqGT9kfZOtCuqupWnlhJZTWMpr6Q23O+fnF51dehiW8Z6zwKY3XZBw4UvHMt5CbS4pAkl8KQaz4XFIXFCItWUqVsXvv1QH5ZJr1qdDeJXR3xPy0i3bHTlstyGWCct+8+EC5YUedgxZkfZOtG4D+7aAYYXzmHiAOL0nsS9otgZO7osU10Tm2eljBmXN9YlfsAvO5RitdxY771T8N7rm92hFyN4vM5qHQj7MIk+9SNBXgc3IhmBXohi9xyj7PVRyaNboXej+BZGMbevVR+9t7pGM/bZhyX5+EykjtH55ksq+zIeVd4Kj73Cse4Ov+erqffWnSkwPrUmZvNnddszErzaukjZY11MW+lpVTYecDK9Qa/kSlxfhD5oyiAw676M5x97h4iu4mR1sjPrBCl5A1lTT/lsHJrRdBR7Rgpvm0UVLVbCjlbM/pQawVUR88N1oaaOpbi3PqjKC8ezeywi0/lLeH5i/H3y76s9TEwtBh9HDQ+dnfBYhG+us07lnj63oDJz4dz9w55zriQdawYZ6eORM+j3ykrSWM6HQYe2R8jA07dmXGLJU6Lwso9omvGQOtZXZALuz5hMgdtWaJp9hu2LLjI4TYyAQquzWGa5wNlCy6MpphqkJiCwvhmSRUvMIMn4MFz8XcxJxSJ+K39bXBnIgEfyqlrLvRIGrFfnTxr8zkrULryRbdOwgxI5lWETUJ80+Hp+UiRoXNzDd/j1AklTvlqk7y8r8p9235IudAkB0N5EXAyTGVtOr8b2Zosjp6b2XhsaZvHhniMP6QGyqpIls1zSnKYUR8C8p0vmxi+z9a0WvESVEHXWMhlpH9cybPAjbQfoNXtfw2zpgrc+eq14abGxowkuLGNbTBs2PTQ6xo1itXx7zAaG9MEsorJsrT3KQ0bnTnohHeSfSsllzx3/rOmi1wJejQRKpfs8EDj/b1lr3ix0RpZNy8vrBrcVpj09Diyvlk9raz/XU4P9DsdvL3/Jac+ABO+XRVP1zj3HBOK3clfX12Sy4FC1UUjWddaX12yG4OIhV1tNew8qiF9H3+Yz60OK/dORGRTmaeu+BpU3PWVDo8LsbiMqEeL+N0SXMjgCJXnHRewLx12CbRtPITPed6GckaceGVsq3FQBh7h5Y+n5LX7ruqUz1Qz3fvqo+ue0wSiMFnjFljd9SK41K8phMpbmy5MuxI3juAICXrF822HSFtdSZeUF3QYyCCtK5xgfeUMlBqZtODu0CG+/nhxN2+slL4BlAvADrbk0w00n09GJCIvs2md5+vo/hleZlHrgDpwaw2HNTrf6aWKD1FxGbHLQa/ELtP1MQoSuO5mr7qeq7TOuWkr6zZ90TxGocF2m4oNJ0o24YXdm3RZYrEpuDyaVX726YI887USn+rC6spTXmABB+aBXdxWUttvPiffDh0Noh+FuRFyJbYMIQ2sxmYWy23oI5M2GT2CC66fFnrWVLm/9aVJr2FO2Zp8HDXXCj5V9DGK8v3CWyTmgpSUi5miJexMx6iowqm96fskbCmXV7gseStzlxy9aQvYyToLIEX2aF+YKmAJkcpC2u4b9xZW5NdaoCn5RuZQkGdcLCffnBAu2QmZ2v8D+39U0GKtuZ58E44vGlZls4IOJufH1qG2NfyzK4KLoq8L5eS6GX4lZzsbNRiZFFP316nHs2mDoEFZRg4itCzjyt0eZp/e/EYVkA8uAfibbz69+e30/cU337ic2yVVlI/y5Eqqm5gly3sv2G/Ngt0I26gTjIrYSoSv2YnbpaR9Diizz8U6gQkzkwqE5iymAOm4khJgXMb3ggTiA7GAZivKh8OJH+wdwN7nsYHa6xO7RF3X00SXwkxzbVTsynes107mEOu+pdHe0abmI52T9NBil81gsIFK44tNNnUvvt7FgpjxUUdTs9VkjthDtxrsRhTYZr+8JyyUD+4neH/HhUXe6//vh6tuVGY3+e9RWCzv+Og9IjuRfBTmaOK4u/CT8ghJW1sn27FLn5k2o73JssM+mc/R7Tbg3P2R6aZlNT9GPAyLvmaUF5bWTTOXKy8zLs+7tW3YicuagwbmgRYG41mFTc51ZlXEA/ZzSOI1plv76qMzWZa16HuiBtiJwxo3PRS7t3Br/g5hnbrFTR+mWT8Ut2sq8n+X4ajZBjdDDT9EMjwYu+HCW8jpWleccRktS/RYFjxiv6JKDIMOTx11Lcoqk6mE8fXbN1fknfOjbpJSw4h8PmoqwfV/vCafa1AjvVvrQmQK+p060yY3dByia/K+KToLpnW1WjqL+JB2gcrYYwQs0Oogx9E+qCYQHHsw3Dz+gAZaUFUmOC0LNoF7gVYRC5BboHUebSrtFsy43a62QOfU9LXCh8KdgmCLkqpYZSUt3HVFB+OLHxx9omyQThUFZraIzgsMZnELqFrAszm2WkoAVk5/TwC1otEnYbiOU9HZC4PuGY/94PjObSVY1TM60iKjDAejxC8/sbC1iGi8dwBP59XyR3FrFtHfdyYyZlSW66h91zvQLeTDIk93ALwsaHSJITIQcy4iFkUOQafIjRbZLNMrblh0+SGyWSFXmpbxc1e6sIVZpoOeIOrCRMZFSnHCRQWqnK6jJbwPYFfsJg3wJS1S8AqvskpJI7P4ISmEvvwxQ49jfNhFsrtZyHmWpyC2BRw//42JrKS3mTGx3AbbgC1HF5DgUSi5SIQ0F+mQrgqdFdMiix0W3YL9XULg0TuDd2DH7oXYhR27qrcL+6eEsH9OCPtfEsL+7wlh/zUNbCOrgk4hhUhpocc3z0RW1gUq39N1gneyAV7dJNBLyrrg87JKo31bLZMW89hJSB4yT6GUaPjM4vtGRKZdQmKCE9SKpbEmLeA01qRe67pKMIuUibasOompaqSxpgfcJhAhRhprmKWCjWZNEuC14LeCCqmBJWDC5c+WKokeheXPsjILoHkCt5osq4wVCXzYFnCCIAnCVdO1ie8WtZB1EshVnSWIaTDFDWe0SFBApDM6B8HWEbOuurAFLdZ/QD5NgfcywzagSSC7djBpsHaJtUmgT+fV8uc0PmidTbn5a5JGY0xncWfF9QArGV1U6yTXHKECU/Gr3LTz8UebtdUBDGbh/PzxnSMOOKp9SYC7bvLxOsh1YM94ASlsGJ3NUhwin8Uszt4GnEI30BmvMEkxSyLqeLX8MdemGjTzjwRbK5YEdsFnkMKM0ehoLiHn0QpGt2FzkYZLSpnXBWgmU1DbA+fzBLJJVnpFTdSZ/x3ooQzyKIAVzLk2isb3hGxgJ9D4FFSpSK2S0VpjJ3KVSL66zHzH4gmgGwW0TKBIulKgVGinU65XC8l15ibMxoe+poomYfB8pBA2BuSlm28fGy7Xhoroc45zbaa1ijUssIEKblZQCqh1dFzj69FNTXJssDi5YRZ/2PWhnQZ2wZzTPI99B3geO6zatA5K8BbxMmNKyjJJVyILOIGZxsssTXKk73iUgszVTfT2TJWO37KUV7pSPDLQghpu6ujZZwUXEK/FzgaqjjpRp4WLxbfx3VqFdF1Ps1khoz/nLfAEKf/W5o0udSzQBBLH2tAJUI2em1DIeRLWFfMkF7iSKrYAK6f1PMU1K7lmKcRCqZMwbIo5EAIMNleKDje6DHcNoGNn/DmosdPxxGoV2wJJUlEm3QDo6JaojK8ZScXnWWAe14PhrgSo+G9WlbmhvNHBRp1MvQHrRrwmYbIEhZt+Jk5sYeDBxpYGVeYcSdHRpVrbDzO2iFXnPwANtxWPHgioQJVzRYUZ9NyNAXmVBHD8p9d1Ivv4sTcFNAJgJecZ1VXEgQFd0IrGhqqAFin0OwUM6eC6jiYCHp/IFnLcFq4dyFLlCTCO78jUCXzD2vmGE+QDaIidCOAGHicwTjR8js8AoQat0aAmMKU0nycQvLqK7WXTiqW4B4rl0RVprVioK24EwCbeiK0uzFpH76q5ZCJ2oURwWuxDgbomnbG3b+YmPls5oPEjeu1Mz9hw11X0bq11Pk2Sh16rIsFbWGtQWc5jV70nGVvRRIZSkMEwbWgZ2xu8zLjQhs4SaAZLrkwKNXxZiQStm4xUtYjpZg21RQt0FD2tjSTva0EGS7fZIwmH5X2iBc/JmYKcG3JGVe67GWps/x5Gx03OSkilsQmhCAaH6BPsb8BkQUKlOm0+BBfpKHdRVoVcw2Cw4F76zWQdran3HXnM0tD5jHDemYI53JKS9hstbGKxYl73h4EkR7LgGoczNKv7o8cGSkTXVSWVIcPGo4SsFtQQbkilYDbGCg9Iy73PEIoQ4b3V0aJAuPCd3Uf6QhdcpJ7I30HVrtbFUxMj52AWoCab7+uFrAcvGiEClqDacURGkooqDeQNGIoTwd1dpS0Jnr2Wc/3iypW9PifnfsTXCTGLwJQibAb8HvzoY0RbkLdgfuNGgA6f85CpkxBvhiO721uEi7vNaqCKLSZc8CB+OHP3CP21e+ITZ2FgMsSLgtYCZ/3Oa5zj2jRxDzdw7/Vr37Gn9O242z21Tbj9/OIRY98eRBaxpulunVdxWfIBbg3eijF3wTGmUY8IpM3gurc4oVoUIxMvsXtuwnHg2D9XgyEKPtegzY6m3YdnK9+/V75TGXAsj1vVSey+R6rNO912p+zCyWGEsbGtv2OHdv1LcOcxZ//vn29oF7s8b4QCrh3mDbQa4iXx3pOF7eMypRqIS9dusSGDW9Wekv/F4+Ar2lHwLeZSufb1QTISQjXRADjujO6eV6Wo0JQdYbzvoMO0W1qg2rthGlYrnIC2C+kKVMmdunEspDdLusEcfMkLmAMpYAkFoVrzuXAHt5nXH2Z9bMn8iPIb19/B6dNHmfRsMasF/1xDf0wiDV++Dr6HdUw8bApKo9Hw3F1IJoUAzK0gK24WY4KCkEBlSKuxKziovOjepoUlJ8qT9okq5JwzWhCLwYjpg1g8Lna41MiYxsejXbVY6zB6nXS2lexltcZ+4GnBqc4WMrlN4Iy41lzDWSqboUZWKnZH8IT7ARB3aSy2+Kb5QSysAKomp4WW1hDfum/nGCwnv/pfTMipWLf/GkA3aMtrYQjNJ0yWVW1AhcVwEje+3Vg68+yr/lngjMWtA+Hmn/XL777/q7V9zzvH0VDsqyDank+zuBGzuzpu6BoU+ZfWJ6dfeDQQufCtj13/k57nxQbnLa7feR4HJi/vk21f9wem2HUm5O27Dxd276DAOU/QX5pzzRRUVLC11Sq9elb0c0EIUuiEfHjzC7kU5oeXJ+Ty7fnFf/5CPl4K8/OP5NlqsSYCuFmAImwhtR+VJpUCZvBb3//8P/+/518HKQJmkVDG9emBMnVS0vA4Hp2Y++55za8dL142SIWveP60kO7Kpj2YH9gw7s4PfAjfnmK6sU4+cWVqWpDXp2+DyP4hBaTzZR3GGf9HCpiEaWvR/WJEKG5kv/DEI3iKb/COc5hTAyv6CCPSkbuvyGmeK/TTOi4PodM+vaysDo1zPjQWcnn25sq9SqPhsZLqI0Y/tpxKTlP1bze5vLKojHi/LA0PnAQRhYZ27XEaNppY5qZrHVdAdNClec7tl2mxCdh2ZvmH37kjMoA1CfGCS3/Dz7dZYIDKJtc6iV531yeNkrcewyupTCuSB0I3xwAbHgA36/2SVx+Z9m4/XMybx6TZ1psxwgsI2Y3H8uJ67NDypVpLxq3K6fxGAx2HWLmsqJjDpDWdmBQzPq8V5GS6RpggcswaCsuZ6sDWA4Oi0RFtObjoLEG/gyKi7t8t4YruAFBQSgOZz+yOn2cUn7S50BnNXCp+AtCVUWmAzxKwxCxBtXCR4jqk6n9SJSAqzbPGE5dOLe9b8HYfk/5qXWfCI2iwF2YBSoAhH9YVnJCPzTP2Gh1gP5CrxgE2eAnejWlqzaieIygTI6Zxg7T3i58QWhRBZaLafBET3KjCxLwlKPsGcmEk0QYfcy7Ix8tRgcIwQTaZvIousi1QWSUY+2YBK9CxM3ot2AQlLu5FjJ2Kjv72BNi60QpZAWIefVIk4myVj4Ra6IgG6lQeWnQCMIIwTCeYEUpeSbWiKh/O6SbkdI7JXopQe+NvMZduCmYFIMKqZ+SuifeNcUtDi26oziFDsGU8ZkYMdsiFz3PFtISSGyuW/IiN8BaXBRXHiOPfwUHZJIh0XJSDDW67LDeRlKW1YOdowG6/PLEjlcCwC8EyXj+4u0XsqTKc1QVVBPtFkwaJZxe3v7yWczmbhae/A8vMApIf7xayH+yC7jZ28L6weFt0T2uzAGF8svgo2rqO2Tnhbgk9bslx1D9qUKMIy9oweVxK+yXHEb6uGQOtR3DGzuOHNUc7LPEE8SJWxZ1LtSaBwoQBbscQTls4Qg9HK5UwwKcrKey7YuVWSDlsf0gGitL2rpbx+tGNvJuUuK6lWDNQcMjb/Xg/TE8f5oJobuqA/CRYXABeRHuoC6oJzWVlXxezAK6IXInNkTnCGXorhSxH8mpxJofmrkX9cZUIq9xzkVv5I5VuCUDJK14AOfWITQZkuIuzV7Qbc3dyNGG83f+jpCuMkuDaZy3EpUJojwFCxKx3fwAhXL7eta/XiE2J8YTQqUxZPRDY/BQWdMlljdolk2WlZMlHMhTh2MhdCDotsIhsRs5248bFshU7CZHsY7ildZIgAlsYRh0ucwCCgfVb/FKfbueV3dy3UbbblFnWwvTL2WJr9DmWgWfsELP+TloQvsdzEKA4a7aEBMFEv35qATcLfGpDs92IR3bCvp9oo8aDn82eDmm79Wh7erl7T169cGsl3FfQNG2NcMNL0FauO21PQQWjQSR/CtGaQuw9CGw8+MBjUHdkrUN6dz8aa/1wtz19n+loQ07vvDXvMN63w8HecMcbgXAHYfDl7u7l3t2po56du2hR9qb2n1y0XqrHESB75HgrQL5cdvxh/5HFGm1wnCO7m3xUR5UgMe/YHeTHUdkx5t4GzNgq9ViC1vNTR6/cqc0iK8Es5CNESeiWJ5k4NPzXRg8ceykpmdTrtCOq814W3l9rEdnBl4k8If85+em778iz1+enV8/JOdeGi3nN9QJyLIUP4lLIuUzeF2hXJAyzZWcOD3/M+MWRjDElE3sVd9V/2lMNYdDeGPTIRxv6fJ/rwjDtv6377Tj+EKdQzJSKUJv0TaYYLWJ1p+tt5D3Nea3dCkQqonnJC6qceLJi094hhu96uLwK77nm+TE7jXQz5T9aRmi8iL2+mJtLnq7O4lTsuusY1vCVhh3/r3cS4ScDXvCOG+iUZeRhV6ZUKRMDBiEbJLVUcyr4HzuyqkU6VrgrsQ+gdJenRsg94ypYS5qo688ruxy+Fq7Fl+tdtJXV/CvQwiwYVUAqBbksuaDBgruOeLqihoMwem96fEGPudvX9FE361o/QpWIce3V+doKrooqg82QNlvdLVaP2OzIC5u7SNQZ5KCogTyLllS2gz+s8HnVrNgGz66UXPK8bR7mv0erqvCa6oAxfPMf+6xt67RhBWezSZ4faZftkr7Xn1mPbDM4PBQzJ5fcRc8XfcV9pAVcq3TGHAp+X80TblFn6vyoUwk9D2zU6aiosVJNtJHKSXwLrQRDcbWv8VsT+62vw7sveZ4XcDwp9wbXu6ucCxxvR+4dJOea8RjH2e6VX63TYUism+jsCakKao/Mvs9SERBMrasxLz+mQh7BnrxDBp1qbctfpTbkDWULLkZMupwmkhxf9Wn9UWCmf6XAig+rH7kmZ3pCXue0Ip/wH04/yqVwdaf/HD6eZEGXYDWnAqgin2tQa4I9CHUlhYZGowoXp9r9Zvib48hL3wOPWciKN10ghdu+68s3jmezpSOgumGg97456l0xxSlPaR1mfR5vWktvNTGytqF/eLkmqhYiaMfqk/blcZFn10ZqpMbOQ8y8hZn+IChZcZHLlSa6AsZnnNlPTkJ1gj5PdnhB7PYcvpucG/IMO8KCYJtnCEOXzzvUIrXAd/w1zClbk496u/FtG4Et+4W00bNr7QpHMNhHXvuuqYWoYK0aMpl9EQcUb/sABKr/typNsZxnSL7tbadXqMe68zr1OrBj3GGQ0fxvDtjscfJ6x7bqM3y9672RdRe49fEuoMPdHMdh1wYMts9mk5DpjmFwQuGGFPuLn7FsIOZIwNEKN9xyDjMuvK8ehRN29StpNdJ0ELE7qFAsEW4bB0xP/YstGFufbeq9+15KI70pWx+2MZQtyiO3wN+sigQnA+uoexxJhrxMuYg3QSzq3bBbxqLCtI9nQEh1y3bwWFwb7U15f2Bq5wDrtG/fHqwrqhqesn8+2WxlteCDVurE3g5ry7rk9zttz0SfWeLaWki1Tnfgf9MVFf+2t2NMg8h2F/VGPQ89TZYsf3uB0Pfs7dFUosGumn7ru3c1ygUZCKNkdYjoyGU9HTgX7sTjfk1rbcOecgTE0VV3HPcensmyomLd3ke8djhO39krS1D2Gcq4mMmwUkD1TeoaoT3yo2dFNpitIG1X9NnnVDkCr+qiWJP/qGnBZxxyco51z845GERlBdOMSXnDHyno/htMiVt/Yz/TYkybj95tdhMOr2qDKveBI0z33/X37RJ+yo53Rzuf/IR8WFdu6xvPgSWOO8Hxw1Mwy6I2k+2hbXFwjgj1tQ61re0jcwxXXatcbmPnPIuVVI23H0PM71+PHHmnV05kdmpoUaWdQ7SDFHblvZ77Bk0lZSJNZBspu449D1JRE3ZNMpFRHTPa3wGsfDl9ZMi1KiIecwdqxFNpjdGsVrG8IR2YGlRG5/Fsyg3o6M/TNuio6Y/boD3XJxAscGtAoGoV3zix8KNxc6voLRT0UmVia1RuiWPUEm7J3A+4LKpXL/x/n3kUXvj/8HlNIbc/LUCFs/P8dh4xeu420w2eo8e1M2ptsJ3cD0SzJhUXM1BqJO463PdR9tVV/PeSPuiePQKSTV/iWecYAlcKw9oy6ZUKLHE09rtwcXvLdh8wg1h1//QPGCZojQ/85NUC1HH8EVZn9xlPz85w9ONzcobrh1EDZY7ULGWEzmeg/PBP2MrC3NGcF5KGjjuE7By4XfRr3ekUvfOk+R+HeiXv3xolfNrkmv8R9tbwm0Qy5fIfF0TAXBruDrBaUD0yAUqzY7cV6hylW3x8uKA96mQToAYJLj0eaxqnN/U34YQUzefHqKjY7m/UTj38MDpo2UoTrnUdXelEyJgslc5b97AYCmIISiX1gQ4OpSs9L+zi5BqD07uk01EyJNrO4D6K/OwaUzt3P0Yd6XkYkveXnjtwHBehWhfZMuWL3g+pekd2EJk8s6xH6+htGnUqwPwGvEWdqLnBV5txJd0HCWXrj0RjvE4qcnl9+o83V+TKvlPknRiZvrLBNlEl9SHYfljJMLYohtgC2I0+yIl8NyGctgdZaOhc26+zbRGGaaB+BOFGCu7QckHxQVPIR1ByHR5tV5BRowFxNtTUR5vw2cVySQueO0YMINEXhEfrar1LECLFbmCt+2I7Euc3CaSRYS+MqXTGcQZtEtB4lCkIwugTuE18LprKF6m4We+5UUyWZdI+cXfE2+HhHULhEvwVV1D0Lc3YLpZVQUWm9WMNvLUrOxn+m99tU6MVxNaVGmeV5MdIqw4h7DAgiAEiFbYGkKxsQYUYNM5I3W7Kr4qIjMRsj9S2uX1Y/MzD316fvvXv3ove8u2DYqTq+/6j92zj+iZbyqJORYDTZo6z8HNu2snYzTjfWnCjyTOHhH6O3TqwsLeZqNsDTxDp4G6KOpE0e+1x/Si48ekCk+2igyUozBSY1QVhUjCojDWUr90ZjrRXWK1SSl9HeGuwNyO0LaKVVIZIS99f//00lIIbJHtsvpNqfvwEy36BwZaLdUpds5Ngo5i/X7y7urwib+htyUXejvUOH6vd29HTMLeGKI5sy29jsLtd22rVp3DJYvT0bFflmM2OV7D52EX4zZaTqx1bzjIvlS/PfZdej8VODIvjHcoj9wpodlz+l68bbgtzRD7UJGPfbvSXWBP6kbIb/bhqtOLboG7pintPiK4DKepUk79po6SY/9u0oOym4NpA/rcX/m8n7adczICFP5pxBStaBBUZOi06vyFU5ERLMsKWCuZcG7W2lv0xhUVFzcI3629xIH0cBkiiU+pYaLpCaFevxaTqdCFv9ckWcxBGrf/yfwMAAP//iL61wg==" + return "eJzsvW1zIzeSIPx9fgUeRzznbofMttsve+Ob3QutpB7rpl+0re723sVEVICoJAmrCqgGUKToX3+BBKpYrEKREgVQ6j3Phwm3SCYSiUQi3/NbcgPrXwjjmsm/EGK4KeAXcub/mYNmileGS/EL+be/EELIG5nXBZCZVGRBRV5wMXdfJwLMSqobksOSMyCFnOvJXwiZcShy/ctf8Nf2f98SQUvwa06opu0nhJh1Bb+QuZJ11flrAI3mf68QOqLjsDi9PiWvuIIVLYpJ56sNGpu/NHiUoDWdQ8bzLcgOlRtYr6Ta/mQHOoR8WEAHEw+b8ByE4TMOaoNTABVdz2b89o5owC0tK3taGrTmUtwdx3f4d1r49QidGVDk/7cI3xVRWSsGGRcG1IwyiEG5a4RJWph4qGYBZFbIFZGKwBKE2YlWDtpwQS38uLidbwA/CEFVF5DZ/4yB1FtaApEzROGUMdCanElhlCzIa64NLkbMghpSUsMWkBOz4PoOWPrTrTWoFLhauA4vrvEPbj1Pzjth2D3oo6HZWfQ+uJa0qiDPmitTBfDs/XGvgDGKCl1QA3lDu8srQvNcgdb3wGUhtbkz1Wa0LkyGYvQXMqOFhofibJe/B7aVVCFsCynmD8XEgr4LJlvyJfJBdrnrfqfZxeqxjrSL/V3PtYt3isPt4rT3hM1CATVZAUso4ugBFh5BeCgtSlqsqALygkylEWAsprMZZxPyTqDMWYJaf1vI1Qmx/9cDV8ocFDVwQhZ8vrCPDX7d/uMu22LUwFyqdYydnXlY7fM3vrNX9lFs1JQlV7U+8d/p788o+TsVJwQM27kfJoUA5i5gFH3to+Cf666Chtui+KbvxISzssrsogEs9KLPzjtxuDx7c4W/3L8gk3msBS2ou9J6ZJ9pxMqnq7edtcnW2iFdgFaZAiZVru+HyAM0fKo1nwvIyfnpFekvvm3gzEwe1cCxxk0lV6AaEXMOMxAanojV8+rD+Zdl9ViE/7R6/rR6/rR6vmirh3zUQC7Orv1HE0HNhFd/GkMHGkMhcj5hK6lFt/P5PVjgTwtqP07bbNGn85/21Z/21Z/21daCe+0rDaxW3ISYRk5/Bza+YG+593TlNX0k7rWHSy7sK73bhfSF23gpUbyHjceljmrjXb67buNnzf/GTTmKWnBW8Hs8XHfUBu0T63RsC30nJ80o40WYm3facdcXZ/c7l2YhYiRZLThbOCHpbU4FM1CaPJttROMJuX775uqEXP/v6xNChVV0emBnUpnF8wk53QBnVJApEEoWVOUofl1c84RQUilpJJPFCUFRVrqQqJz1Za5V8tfaQEm0nBkLZEIuDclBSANbRoCX9IzWuqW9+2n/nXLbnAwY0UdfJ62dNulZB3IJaqW4sY+WqmHAr8ND2nOFdhxUl4WasPDGgFwtQAF+5h8ysqCaTAEEkVMNagn5cH9qK068bzPDy7dzK+N3C7EWdFtlGV99bP3QEh1tTs97x7xrhV23qncqH6ytdgNra8vV2prCkjBamdrTX9FVe3HQ5mOyBG03Le3nPdCEvJZzcg72YVPhjThYvI/Uodtp4KK5abVdFhmwRzgx9T3J3Y1nUhj7LNv7wYU2VJgGDR3E0fDyEARzavofDLHzNr5dglDjxSltfGtkwY0mlLwF8xs3wj4D/vQnA9ZoN6sXsi5yImAJykrQhu8qqjSQN2CoRY2SmZJlZ6lnr+Vcv7ii7AaMfj4Af84VMFOsT5z/gVu03oMTFo7DRQfNSZCQQ9vjbpQcmFA9Sp5DpYChwWQxyWHGrdogRYFoGTotrBJfhbEq9byvasflQH/Gb/w9vzz/nixpUfsb3yrm7ltwS5mxuoc7LzU4CNwdR6XNcQt+zx5HRZXhrC6owt/7g52McsYA9EGcEuKMAeRxThk9kuVxz+Tln2ey+0zsqmkO5GHXV05/z3Aj/WN5Mtgt6SFCLzlqCpzu+xRxs2RLdf8fhpk21EAJwjxF5Gidc5Oxgvbu8BNBD4TpeeieCGKLgdfpiSDGxWGIpdWYGsnxdDktB3qI9EhLthm4iEEsG2pErwnZmZ0vNm4Bi81ADxkoCQ+zInp6yAD6HitinIqDwOtRqCg6XpUg+Ry5BtuMRD4SoOC9yceOoVbXg5hDs3//p/W2UXsmBbOPAzXyqVu2I+JmydOKwy51z+wyfMYZ7d7n13Lu4g1NRkstclDoLAUvqAZbn/FbyIkGY4Fs/Xh7DT1usDSHMID9YIOlPYQB6HsdytATGN+/dBhjDvZ1D5rcjwaDkHoSvvxVatMVkUWfIzWInIt586EOsU3Hh/Tl0JcfwmCDH40S9vJq+WOTaTF63fvEHezeyC+VuMufU5P35/93yTuIOieRDX254BxpXW9ZTiiZ8yWI1kn25SoClkSH+S/SWiD5U1T+voyIxqhDQ1brTMHnBGfdDR7iAeO+p2uk8oVbmlzhRTrx3mxDyYd1BYTRoQSZAgFuFqDIx0thvv+ZSEVeFZKaH16SKdXIRU2AbMbntULVb8++D1F3v+B9Yxg0nfEZwb8QTIQ7inXcrPzFOxikWlGVJ1PqOhKts+0uJS+vPm3pe5QoKGj/SEmT2+IeUY82ptuD41TtiGf/LRWfc6y9cL/Z1lb20CGV/rUjMeLy6tPPARKEc3JIBBK0GA2pHOP12TDqUHE89PVZAM1BHSV2/SsuRS7PHxIldfh2g6UI5rBY6ZN2shUsS+5no42idblRtPCiWNPlTBYFMCPVlyiALfUeIefG8hzXhDnSQW4x3VJUX8u+2kJ2EPoJWnwlmz4VVbWUGpPdSinIdD04NEIUfK5BYxGU5mVVrP052S9joi5QtiCa50CefUfMQtXk5U8/PScrqokGEO0qOyjxJJTXO1BCV1JoSEcK9sVwBZO1aAvjRF1OndCzV1kHIZBndCqX0CEGF8HMyka8aaOAlqP3h30xbPPIpIKc1309LQahvgppjq1jgc8IN/+sX373/V+1E+kvKhSgDdL/HOzmn9YefE3XoMhLciEYrXRduMiKNSnvJddD0B8Y/AjkVoZW+eEl+Ve73RPyww/kXwmTyurLuAu/6An5b4X5H/aLXJNtonwVPEIh80DR8BOxdcUKMkaLYkrZTVoN2CHXFAxQ4+wKS0QQeSW5MGiaGAgnOCNzZKCUTJSfttEHdQWM0wIxRky1kcpq1mLttA77wZIWPHeMEUKKkJmsRW5fmAIQeS7mXjnam7y4fSMGkGPEAv112BE2GjmFdSFp/lTeOY8O0fwPICUYxVnA6vCmcPfLaAu7574RwvbZp2aj0cpZc2wT8qtc2aMZ2pxcEKmsMWYkuQGo9hDtSbx4XwjRlMRisCXPszxV1PWikTxzEFg1q7GsqnZ2tLcLl1yZmhbWaN/yvYuAi4OX3JrdGCtHYrhd+Kt+eU6UldYaHSpINKrmYNqv7aWEVomSnh6dEk3N/i5KqCShoKHgvzxvfK/voZQGyLXnd6YAH9rpekxQEuw24gIxX0Dgxa+U6argKTMbnrQ5r/lA7X8SupmVuQn5HW+dfQOaMk3PdY3V4p+Q/xoRRideZrx4hBi9XdUaR1dnp1de9/VFubyspOprvASfyC8uDaJ+Gu4P36YBDXE03UOu1G1Tvt78ZGOwOz0HLfMJefnTz2SFdC+BCkKLIuwrQKc+qkkb/xFZgQIHFtt8UG2IFL1ykW0iPrqa+GUTMXBXU4RtPe1+kypHwmFWE7CFkIWcr/uBuBlXAy2WkJ8IW1BFmXFEtJd6jfij01yQWvicnmLLZz5aURu7oNsF6lMGEXbELtGiKK2SKUUTRlB0NSrTULL21ErKUGN1MQrhfQ6SsVo1ELWhIqcqJ0Kqkhb8j1B+r1RlkD65z3I4mESyng6epHsRaYN1i8yLgs8Adxww8DUwKfIRBXtz3Jk2Kf0sOzbEBZNlVYAJMsCoE5WiAm8U74nBTr2ZMo/EyNd27SA7j7HyNmeOsl8phVlEOqZNfWqsnJdNllP+SIS/EHkKsluQf0iRutvCDrFoV29UTJde+6FP4YGISnajT4mBW+MvH1mC0p1yinxXHljgfB/KbGugsba5KdNjUuWQp3sHfZKNf6Z0u2KjYzSZNu0Xu/H14WulZDlBqDUW5WsGgiounVpf1oXh3xoOitCqKprql00vm5IKOg+V5hJSYHhnq61P01CKcPO1JnIlXGTM0LLqewY9xth/U8lh8hE3mrAFt9aNzEFPyJtaGzSTukDtraRmJC+XGjjwkHYKsNnM4r2EY2hCeMjNgo522AoKBHMMQa1qnfMlz61mg/wQFmTXjSD70CNeeJO3FVdH2+HmPF0s6NZyIjfFuul7ZSTqaxYp15xxp2804qGPunBOrDRu5dlksGSbTibr2BKoHChyD4XY0j/2VUEN8nMN9dFYyXK346KNfFxRTRCJfIRvELnvYxM1olKwRdAEMm1emgSv77xMgWuVJUC1ylJoz1VMUbQN9GV0qAl0pc4r8jgmZM98DL4xg+fyXm/OoWJzn1w7JFiweSB63RBiO4IoGyjxMRRrXRepw04jVpSsDZMlvHA4tMYLZmUPGmASyxeOBFsG5AiDwBIG7XCPtrFmdV8E2Ins7HL5pC1eHPQOdK90W+lioWHcqQLGZ3xj+IS1W9/KfYSnvK6cPpspcACti5Hnm4KJxkWV+yBLEG9vNh/rED5tW+ldS1Aq8u7ap8Zy3SQE9P1qxPeF7Q1QIFtVkrqSmkcUHHfiLTSnRe46TGEqf3N3R7vw1IUZNsx+LFEk6hIUZ/eVRcG9HaGKbcfGupVs7c1wYsnd78HWliByqXzC7M6dyenvj9C9pgntBtqadxFLXws+ILeVoLsRc5I+Za+6r4YX0lf9ezHjvVwL2uYWC2kIxTERFslwAm0h51mTqPIoQr1hxHsL9WP0TNmSfX/HdCvsWo3iI6z4y4Kzderbs0MuXCECvrm2KNYjcjk4bCkxAd/XBSBiYXEqhYHb1Bpri9ClcP66TT9Umufa/h8+qrRoEAo1gNnzOLMFFXPIBKxSy4KxwCWsOqF+VEKMUXxaG+hIiGGOvnaoW229+/yFRYeu+hPEHm61sIIna1u5i2hoCPbzixwyXf0tYNxiBZglWNNwUG9yvtQS1IRcgzuUWoOa0DlgK2+f6T6TqsFhALsB4/R25oZuud93+lZIRaZKruxnzV+9runMrtF+0pf5FVUmtpuuBRzbo+LvlBxUhx7rTskib9XGVFdKVuADiqne4lNBaAHKtNlFarOo/5sLb3nx0WkCgElIAYU5J0KKbxVUgJbMruwHNBuO+eSwWil7YVp7BU8S9bgX3EXYmvDPYGcrbhZeWXaynpzjglOsNhFEim/n0v73jpcAlZQsoDgm3DftBANfIAIWSTkjVjoYDnpCrjcypT/YoFtZlQbjM1fOV2trxLiSUZdsk3vx6wlPCStqbRqG9P8YHBP+hGt7kr4m2vs3rOKLn46rQEfXftwNC1v0ri1TOqXs632Gl8XyHLEgVGvJOPpL7WkE7Uk8sNf8Bn4hlFSLteaMFiTn+uaEVApnouAosa/DijJV9JDay3s+9K7ORtESDChNKqqxi5fGRg6uFwGTZWmlmNwK2g9La7amopHh0+Teg8fS+DpnmOBhcuKbybKqh3cwwbFRsuIilyufT8ukYFCZkzaTYpQYg23O6qJYk881LZzzM5cl5cJLDdFZqJAjT1fX6xlLXdqxdasSvubiBnJfC9QkolON3ilvoNhPvmpRm/B818EVg64QSUVdd7KTc0v0EWjQe3f9WHi9q7znlVwP2/W0QWdQJe8PdkrtYvVrIraO/3dr2j9E1rRnvEh/x9stv8LV2musIK8ZkCZyBGF3mwbFaZEFXtNkj8g1Ltmozf33sfMA2hdm1C8A7EYf1HIghsfYr24fugXVi/aGWrUwUGVYs4XL/G1qbNoyw7MGUq9FmN1Iu8xEK2Z/1f57WGlKrDwXhGPOXS1YAVTZP2EjvA1qvoBwMwTPFXbujz444VcP+zw96ReLyXLazNOVs60Hy5eNqnu8Xjjw9dievq42ggiMe/yOEyANXIkzt7rryTjuKXUWXHLXeEs+52W+PCdvnaR55hs3EDdtzxf9Wtyeh/Vq54B+DF9+x/18eY4k9SVvrZgYeg+2I3IuDdBtYeKYyMqCFddhI3Wp1yl72W9HdX2BtlMXdvqxR4YjJ750Z5tJuZfnezXZWP65PZqsReylyDca7YScufpM3++0cB/s1mYRQbX9je+/8u64aW3ayk1p2seoFgVoRxnpHpSVJEuqOJ0WgypA15SBC1IVdEQQaBA6aX+UrQPtqqpu5YmVVFbDaOoLuT3n6xeXV30dmviWsc6jMFaXfeBAwTvXQm4iLQ5JcikMueZzQVFYjLBoJVXK5rVfD+SXZdKrRneT2NUR/9Mi0h0+bbkslwHGefvuA+GCFXUOVpz5QbZuEP6zi2aA8ZVziDiwKL0nYb8IRuaOHttE59TmaQljxvWNVbkPwOsepXgdN+Zb/zS85/pmR8jVKD6fg0o3wi5Msk/dWIDHwY1oVqAXssgt9zhbfWTS6Fbo/QiehWHs3UvlZ++djvG8bcZxeR4uI7lzdJ7JssqOnHeFp+Jzr3CMq/Pv6Xr6rUVHCqxPnbnZ3HnNxqw0r5Y+UtZYF/NWWkqFnQesXG/wG5kS5weRP4oCOOyqP8PZ5+4hspsYaY38zApRSt5Q1vRTDiu3VgQd1Y6R4ttGQVW7pZCzNaMPtVZAdfTcYG2oqWMpzq0/ivLi0cwOu/hU3hKevxh/v+zLWh8DQ4vRx0HjY3cXLBbhq9u8Y4mn7w2Y/Hw4d++Q54wLWceKcXbqSPQ8+p2ykjSm02Hgkf0xMuDUnRm3WOK0KKzcI7pmDLSe1QW5sOsTJnPQliWaZr9hy4KLHG4jE6Dg2hymeT5QtuDCaIqpBokpKIxvllTxAjN4Ah48F38Xc0KRiN/a3wZ3JhLwoZy65kKPpBH71cmzNp+zAqUrX3TrJMyAZF5F2CTENx2eno8UGTo31/A9Tp1Q4pSvNsnL+6rct+2HlAtNcjCUFwEnw1TWpvO7ka3J4ui5mY3HlrZ5bIjH+ENqoKyKZNk8pySHGfUhIN/5sonh+2xNqxUvQRV0jYVcRvrHlTwL3Ej7AVrd/tcwa6rAna9eG25qbMxIghvb2AbDhk0Pva5Ro1gd/w6jsTFNIKuYLEt7n9Kw0ZmDTngn2bdScslz5z9rusiVoEcToXLJDg803t9b9ooXG62RdfPywqrBbYVJT48j65vV08r63+X0QL/Twdv7X3LqAzDh21XxdI1zzzGh2J389dUluRwoVF00knWt9dUluzGIWNjVVsPOoxrS9/GH+dzqsHLvREQ2lXnqiq9BxV1f6fC4EIvLiHq0iN8twYUMjlB53nEB+9Jhl0DbxkP4nOdtKGfEiVfGthoHZeARXv54Sl6776pO+Uw1072vPrruOU0gCpM1boHVXS+CS/2aQqi8tenCtCtx4wiOkKBXPN92iLTVlXRJeUGHgQzSusIJ1lfOQKmRSQvuDh3i648Xd/PGSukbQLkA7GBLPt1A8/lkRCLyMpvWeb6O7p/hZRa1DqgDt9ZwWKPznV6q+BAVlxG7HPRK7DJdH6Mggetu9qrruUrrnJu2sm7TF81jFBpst6nYcKJkE17YvUmXJRabgsujWeVnny7IM18r8akurK485QUWcGAe2MVtJbX95nPy7dDRIPpRmBshV2LLENLAamxmsdyGPjJpk9EjuOD6aaFnTZX7W1+a9BrmlK3Jx1FzreBTRR+jKN8vvEViLkhJuZgpWsLOdIyKKpzam75PwpZyeYXLkrcyd8nRm7aAnayzAFJkj/aFqQKWEKkspO2+cW9hRX6tBZqSb2QOBXnGxXLyzQnhkp2Qqf0/sP9HBS3WmuvJN+H4omFVNivoYHJ+bB1qW8M/uyK4KPq6UE6um+FXcrazUYORSTF1f516PJs2CBqUZeQgQssyrtztYfbpzW9UAfngEoC/+ebTm99O3198843LuV1SRfkoT66kuolZsrz3gv3WLNiNsI06waiIrUT4mp24XUra54Ay+1ysE5gwM6lAaM5iCpCOKykBxmV8L0ggPhALaLaifDic+MHeAex9HhuovT6xS9R1PU10Kcw010bFrnzHeu1kDrHuWxrtHW1qPtI5SQ8tdtkMBhuoNL7YZFP34utdLIgZH3U0NVtN5og9dKvBbkSBbfbLe8JC+eB+gvd3XFjkvf7/frjqRmV2k/8ehcXyjo/eI7ITyUdhjiaOuws/KY+QtLV1sh279JlpM9qbLDvsk/kc3W4Dzt0fmW5aVvNjxMOw6GtGeWFp3TRzufIy4/K8W9uGnbisOWhgHmhhMJ5V2ORcZ1ZFPGA/hyReY7q1rz46k2VZi74naoCdOKxx00Oxewu35u8Q1qlb3PRhmvVDcbumIv93GY6abXAz1PBDJMODsRsuvIWcrnXFGZfRskSPZcEj9iuqxDDo8NRR16KsMplKGF+/fXNF3jk/6iYpNYzI56OmElz/x2vyuQY10ru1LkSmoN+pM21yQ8chuibvm6KzYFpXq6WziA9pF6iMPUbAAq0Ochztg2oCwbEHw83jD2igBVVlgtOyYBO4F2gVsQC5BVrn0abSbsGM2+1qC3ROTV8rfCjcKQi2KKmKVVbSwl1XdDC++MHRJ8oG6VRRYGaL6LzAYBa3gKoFPJtjq6UEYOX09wRQKxp9EobrOBWdvTDonvHYD47v3FaCVT2jIy0yynAwSvzyEwtbi4jGewfwdF4tfxS3ZhH9fWciY0ZluY7ad70D3UI+LPJ0B8DLgkaXGCIDMeciYlHkEHSK3GiRzTK94oZFlx8imxVypWkZP3elC1uYZTroCaIuTGRcpBQnXFSgyuk6WsL7AHbFbtIAX9IiBa/wKquUNDKLH5JC6MsfM/Q4xoddJLubhZxneQpiW8Dx89+YyEp6mxkTy22wDdhydAEJHoWSi0RIc5EO6arQWTEtsthh0S3Y3yUEHr0zeAd27F6IXdixq3q7sH9KCPvnhLD/JSHs/54Q9l/TwDayKugUUoiUFnp880xkZV2g8j1dJ3gnG+DVTQK9pKwLPi+rNNq31TJpMY+dhOQh8xRKiYbPLL5vRGTaJSQmOEGtWBpr0gJOY03qta6rBLNImWjLqpOYqkYaa3rAbQIRYqSxhlkq2GjWJAFeC34rqJAaWAImXP5sqZLoUVj+LCuzAJoncKvJsspYkcCHbQEnCJIgXDVdm/huUQtZJ4Fc1VmCmAZT3HBGiwQFRDqjcxBsHTHrqgtb0GL9B+TTFHgvM2wDmgSyaweTBmuXWJsE+nReLX9O44PW2ZSbvyZpNMZ0FndWXA+wktFFtU5yzREqMBW/yk07H3+0WVsdwGAWzs8f3znigKPalwS46yYfr4NcB/aMF5DChtHZLMUh8lnM4uxtwCl0A53xCpMUsySijlfLH3NtqkEz/0iwtWJJYBd8BinMGI2O5hJyHq1gdBs2F2m4pJR5XYBmMgW1PXA+TyCbZKVX1ESd+d+BHsogjwJYwZxro2h8T8gGdgKNT0GVitQqGa01diJXieSry8x3LJ4AulFAywSKpCsFSoV2OuV6tZBcZ27CbHzoa6poEgbPRwphY0Beuvn2seFybaiIPuc412Zaq1jDAhuo4GYFpYBaR8c1vh7d1CTHBouTG2bxh10f2mlgF8w5zfPYd4DnscOqTeugBG8RLzOmpCyTdCWygBOYabzM0iRH+o5HKchc3URvz1Tp+C1LeaUrxSMDLajhpo6efVZwAfFa7Gyg6qgTdVq4WHwb361VSNf1NJsVMvpz3gJPkPJvbd7oUscCTSBxrA2dANXouQmFnCdhXTFPcoErqWILsHJaz1Ncs5JrlkIslDoJw6aYAyHAYHOl6HCjy3DXADp2xp+DGjsdT6xWsS2QJBVl0g2Ajm6JyviakVR8ngXmcT0Y7kqAiv9mVZkbyhsdbNTJ1BuwbsRrEiZLULjpZ+LEFgYebGxpUGXOkRQdXaq1/TBji1h1/gPQcFvx6IGAClQ5V1SYQc/dGJBXSQDHf3pdJ7KPH3tTQCMAVnKeUV1FHBjQBa1obKgKaJFCv1PAkA6u62gi4PGJbCHHbeHagSxVngDj+I5MncA3rJ1vOEE+gIbYiQBu4HEC40TD5/gMEGrQGg1qAlNK83kCwaur2F42rViKe6BYHl2R1oqFuuJGAGzijdjqwqx19K6aSyZiF0oEp8U+FKhr0hl7+2Zu4rOVAxo/otfO9IwNd11F79Za59Mkeei1KhK8hbUGleU8dtV7krEVTWQoBRkM04aWsb3By4wLbegsgWaw5MqkUMOXlUjQuslIVYuYbtZQW7RAR9HT2kjyvhZksHSbPZJwWN4nWvCcnCnIuSFnVOW+m6HG9u9hdNzkrIRUGpsQimBwiD7B/gZMFiRUqtPmQ3CRjnIXZVXINQwGC+6l30zW0Zp635HHLA2dzwjnnSmYwy0pab/RwiYWK+Z1fxhIciQLrnE4Q7O6P3psoER0XVVSGTJsPErIakEN4YZUCmZjrPCAtNz7DKEIEd5bHS0KhAvf2X2kL3TBReqJ/B1U7WpdPDUxcg5mAWqy+b5eyHrwohEiYAmqHUdkJKmo0kDegKE4EdzdVdqS4NlrOdcvrlzZ63Ny7kd8nRCzCEwpwmbA78GPPka0BXkL5jduBOjwOQ+ZOgnxZjiyu71FuLjbrAaq2GLCBQ/ihzN3j9Bfuyc+cRYGJkO8KGgtcNbvvMY5rk0T93AD916/9h17St+Ou91T24Tbzy8eMfbtQWQRa5ru1nkVlyUf4NbgrRhzFxxjGvWIQNoMrnuLE6pFMTLxErvnJhwHjv1zNRii4HMN2uxo2n14tvL9e+U7lQHH8rhVncTue6TavNNtd8ounBxGGBvb+jt2aNe/BHcec/b//vmGdrHL80Yo4Nph3kCrIV4S7z1Z2D4uU6qBuHTtFhsyuFXtKflfPA6+oh0F32IulWtfHyQjIVQTDYDjzujueVWKCk3ZEcb7DjpMu6UFqr0bpmG1wglou5CuQJXcqRvHQnqzpBvMwZe8gDmQApZQEKo1nwt3cJt5/WHWx5bMjyi/cf0dnD59lEnPFrNa8M819Mck0vDl6+B7WMfEw6agNBoNz92FZFIIwNwKsuJmMSYoCAlUhrQau4KDyovubVpYcqI8aZ+oQs45owWxGIyYPojF42KHS42MaXw82lWLtQ6j10lnW8leVmvsB54WnOpsIZPbBM6Ia801nKWyGWpkpWJ3BE+4HwBxl8Zii2+aH8TCCqBqclpoaQ3xrft2jsFy8qv/xYScinX7rwF0g7a8FobQfMJkWdUGVFgMJ3Hj242lM8++6p8FzljcOhBu/lm//O77v1rb97xzHA3Fvgqi7fk0ixsxu6vjhq5BkX9pfXL6hUcDkQvf+tj1P+l5Xmxw3uL6nedxYPLyPtn2dX9gil1nQt6++3Bh9w4KnPME/aU510xBRQVbW63Sq2dFPxeEIIVOyIc3v5BLYX54eUIu355f/Ocv5OOlMD//SJ6tFmsigJsFKMIWUvtRaVIpYAa/9f3P//P/e/51kCJgFgllXJ8eKFMnJQ2P49GJue+e1/za8eJlg1T4iudPC+mubNqD+YEN4+78wIfw7SmmG+vkE1empgV5ffo2iOwfUkA6X9ZhnPF/pIBJmLYW3S9GhOJG9gtPPIKn+AbvOIc5NbCijzAiHbn7ipzmuUI/rePyEDrt08vK6tA450NjIZdnb67cqzQaHiupPmL0Y8up5DRV/3aTyyuLyoj3y9LwwEkQUWho1x6nYaOJZW661nEFRAddmufcfpkWm4BtZ5Z/+J07IgNYkxAvuPQ3/HybBQaobHKtk+h1d33SKHnrMbySyrQieSB0cwyw4QFws94vefWRae/2w8W8eUyabb0ZI7yAkN14LC+uxw4tX6q1ZNyqnM5vNNBxiJXLioo5TFrTiUkx4/NaQU6ma4QJIsesobCcqQ5sPTAoGh3RloOLzhL0Oygi6v7dEq7oDgAFpTSQ+czu+HlG8UmbC53RzKXiJwBdGZUG+CwBS8wSVAsXKa5Dqv4nVQKi0jxrPHHp1PK+BW/3Memv1nUmPIIGe2EWoAQY8mFdwQn52Dxjr9EB9gO5ahxgg5fg3Zim1ozqOYIyMWIaN0h7v/gJoUURVCaqzRcxwY0qTMxbgrJvIBdGEm3wMeeCfLwcFSgME2STyavoItsClVWCsW8WsAIdO6PXgk1Q4uJexNip6OhvT4CtG62QFSDm0SdFIs5W+UiohY5ooE7loUUnACMIw3SCGaHklVQrqvLhnG5CTueY7KUItTf+FnPppmBWACKsekbumnjfGLc0tOiG6hwyBFvGY2bEYIdc+DxXTEsoubFiyY/YCG9xWVBxjDj+HRyUTYJIx0U52OC2y3ITSVlaC3aOBuz2yxM7UgkMuxAs4/WDu1vEnirDWV1QRbBfNGmQeHZx+8trOZezWXj6O7DMLCD58W4h+8Eu6G5jB+8Li7dF97Q2CxDGJ4uPoq3rmJ0T7pbQ45YcR/2jBjWKsKwNk8eltF9yHOHrmjHQegRn7Dx+WHO0wxJPEC9iVdy5VGsSKEwY4HYM4bSFI/RwtFIJA3y6ksK+K1ZuhZTD9odkoCht72oZrx/dyLtJietaijUDBYe83Y/3w/T0YS6I5qYOyE+CxQXgRbSHuqCa0FxW9nUxC+CKyJXYHJkjnKG3UshyJK8WZ3Jo7lrUH1eJsMo9F7mVP1LplgCUvOIFkFOP2GRAhrs4e0W7MXcnRxPG2/0/SrrCKAmufdZCXCqE9hggRMx69wcQwuXrXft6jdiUGE8IncqU1QOBzU9hQZdc1qhdMllWSpZ8JEMRjo3chaDTAovIZuRsN25cLFuxkxDJPoZbWicJIrCFYdThMgcgGFi/xS/16XZe2c19G2W7TZllLUy/nC22Rp9jGXjGDjHr76QF4Xs8BwGKs2ZLSBBM9OunFnCzwKc2NNuNeGQn7PuJNmo8+Nns6ZC2W4+2p5e79+TVC7dWwn0FTdPWCDe8BG3lutP2FFQwGkTypxCtKcTeg8DGgw88BnVH1jqkd/ejsdYPd9vT95mONuT0zlvzDuN9OxzsDXe8EQh3EAZf7u5e7t2dOurZuYsWZW9q/8lF66V6HAGyR463AuTLZccf9h9ZrNEGxzmyu8lHdVQJEvOO3UF+HJUdY+5twIytUo8laD0/dfTKndosshLMQj5ClIRueZKJQ8N/bfTAsZeSkkm9TjuiOu9l4f21FpEdfJnIE/Kfk5+++448e31+evWcnHNtuJjXXC8gx1L4IC6FnMvkfYF2RcIwW3bm8PDHjF8cyRhTMrFXcVf9pz3VEAbtjUGPfLShz/e5LgzT/tu6347jD3EKxUypCLVJ32SK0SJWd7reRt7TnNfarUCkIpqXvKDKiScrNu0dYviuh8ur8J5rnh+z00g3U/6jZYTGi9jri7m55OnqLE7FrruOYQ1fadjx/3onEX4y4AXvuIFOWUYedmVKlTIxYBCyQVJLNaeC/7Ejq1qkY4W7EvsASnd5aoTcM66CtaSJuv68ssvha+FafLneRVtZzb8CLcyCUQWkUpDLkgsaLLjriKcrajgIo/emxxf0mLt9TR91s671I1SJGNdena+t4KqoMtgMabPV3WL1iM2OvLC5i0SdQQ6KGsizaEllO/jDCp9XzYpt8OxKySXP2+Zh/nu0qgqvqQ4Ywzf/sc/atk4bVnA2m+T5kXbZLul7/Zn1yDaDw0Mxc3LJXfR80VfcR1rAtUpnzKHg99U84RZ1ps6POpXQ88BGnY6KGivVRBupnMS30EowFFf7Gr81sd/6Orz7kud5AceTcm9wvbvKucDxduTeQXKuGY9xnO1e+dU6HYbEuonOnpCqoPbI7PssFQHB1Loa8/JjKuQR7Mk7ZNCp1rb8VWpD3lC24GLEpMtpIsnxVZ/WHwVm+lcKrPiw+pFrcqYn5HVOK/IJ/+H0o1wKV3f6z+HjSRZ0CVZzKoAq8rkGtSbYg1BXUmhoNKpwcardb4a/OY689D3wmIWseNMFUrjtu75843g2WzoCqhsGeu+bo94VU5zylNZh1ufxprX0VhMjaxv6h5dromohgnasPmlfHhd5dm2kRmrsPMTMW5jpD4KSFRe5XGmiK2B8xpn95CRUJ+jzZIcXxG7P4bvJuSHPsCMsCLZ5hjB0+bxDLVILfMdfw5yyNfmotxvfthHYsl9IGz271q5wBIN95LXvmlqICtaqIZPZF3FA8bYPQKD6f6vSFMt5huTb3nZ6hXqsO69TrwM7xh0GGc3/5oDNHievd2yrPsPXu94bWXeBWx/vAjrczXEcdm3AYPtsNgmZ7hgGJxRuSLG/+BnLBmKOBBytcMMt5zDjwvvqUThhV7+SViNNBxG7gwrFEuG2ccD01L/YgrH12abeu++lNNKbsvVhG0PZojxyC/zNqkhwMrCOuseRZMjLlIt4E8Si3g27ZSwqTPt4BoRUt2wHj8W10d6U9wemdg6wTvv27cG6oqrhKfvnk81WVgs+aKVO7O2wtqxLfr/T9kz0mSWurYVU63QH/jddUfFvezvGNIhsd1Fv1PPQ02TJ8rcXCH3P3h5NJRrsqum3vntXo1yQgTBKVoeIjlzW04Fz4U487te01jbsKUdAHF11x3Hv4ZksKyrW7X3Ea4fj9J29sgRln6GMi5kMKwVU36SuEdojP3pWZIPZCtJ2RZ99TpUj8KouijX5j5oWfMYhJ+dY9+ycg0FUVjDNmJQ3/JGC7r/BlLj1N/YzLca0+ejdZjfh8Ko2qHIfOMJ0/11/3y7hp+x4d7TzyU/Ih3Xltr7xHFjiuBMcPzwFsyxqM9ke2hYH54hQX+tQ29o+Msdw1bXK5TZ2zrNYSdV4+zHE/P71yJF3euVEZqeGFlXaOUQ7SGFX3uu5b9BUUibSRLaRsuvY8yAVNWHXJBMZ1TGj/R3AypfTR4ZcqyLiMXegRjyV1hjNahXLG9KBqUFldB7PptyAjv48bYOOmv64DdpzfQLBArcGBKpW8Y0TCz8aN7eK3kJBL1UmtkblljhGLeGWzP2Ay6J69cL/95lH4YX/D5/XFHL70wJUODvPb+cRo+duM93gOXpcO6PWBtvJ/UA0a1JxMQOlRuKuw30fZV9dxX8v6YPu2SMg2fQlnnWOIXClMKwtk16pwBJHY78LF7e3bPcBM4hV90//gGGC1vjAT14tQB3HH2F1dp/x9OwMRz8+J2e4fhg1UOZIzVJG6HwGyg//hK0szB3NeSFp6LhDyM6B20W/1p1O0TtPmv9xqFfy/q1RwqdNrvkfYW8Nv0kkUy7/cUEEzKXh7gCrBdUjE6A0O3Zboc5RusXHhwvao042AWqQ4NLjsaZxelN/E05I0Xx+jIqK7f5G7dTDD6ODlq004VrX0ZVOhIzJUum8dQ+LoSCGoFRSH+jgULrS88IuTq4xOL1LOh0lQ6LtDO6jyM+uMbVz92PUkZ6HIXl/6bkDx3ERqnWRLVO+6P2QqndkB5HJM8t6tI7eplGnAsxvwFvUiZobfLUZV9J9kFC2/kg0xuukIpfXp/94c0Wu7DtF3omR6SsbbBNVUh+C7YeVDGOLYogtgN3og5zIdxPCaXuQhYbOtf062xZhmAbqRxBupOAOLRcUHzSFfAQl1+HRdgUZNRoQZ0NNfbQJn10sl7TguWPEABJ9QXi0rta7BCFS7AbWui+2I3F+k0AaGfbCmEpnHGfQJgGNR5mCIIw+gdvE56KpfJGKm/WeG8VkWSbtE3dHvB0e3iEULsFfcQVF39KM7WJZFVRkWj/WwFu7spPhv/ndNjVaQWxdqXFWSX6MtOoQwg4DghggUmFrAMnKFlSIQeOM1O2m/KqIyEjM9khtm9uHxc88/O316Vv/7r3oLd8+KEaqvu8/es82rm+ypSzqVAQ4beY4Cz/npp2M3YzzrQU3mjxzSOjn2K0DC3ubibo98ASRDu6mqBNJs9ce14+CG58uMNkuOliCwkyBWV0QJgWDylhD+dqd4Uh7hdUqpfR1hLcGezNC2yJaSWWItPT99d9PQym4QbLH5jup5sdPsOwXGGy5WKfUNTsJNor5+8W7q8sr8obellzk7Vjv8LHavR09DXNriOLItvw2Brvbta1WfQqXLEZPz3ZVjtnseAWbj12E32w5udqx5SzzUvny3Hfp9VjsxLA43qE8cq+AZsflf/m64bYwR+RDTTL27UZ/iTWhHym70Y+rRiu+DeqWrrj3hOg6kKJONfmbNkqK+b9NC8puCq4N5H974f920n7KxQxY+KMZV7CiRVCRodOi8xtCRU60JCNsqWDOtVFra9kfU1hU1Cx8s/4WB9LHYYAkOqWOhaYrhHb1WkyqThfyVp9sMQdh1Pov/zcAAP//rhmfyQ==" } diff --git a/x-pack/filebeat/module/cisco/ftd/_meta/fields.yml b/x-pack/filebeat/module/cisco/ftd/_meta/fields.yml index e6db84b9385..7c31ecd11ff 100644 --- a/x-pack/filebeat/module/cisco/ftd/_meta/fields.yml +++ b/x-pack/filebeat/module/cisco/ftd/_meta/fields.yml @@ -1,4 +1,4 @@ -- name: ftd +- name: cisco.ftd type: group description: > Fields for Cisco Firepower Threat Defense Firewall. diff --git a/x-pack/filebeat/module/cisco/ios/_meta/fields.yml b/x-pack/filebeat/module/cisco/ios/_meta/fields.yml index 8acb2c9cf4e..2f394f7ac87 100644 --- a/x-pack/filebeat/module/cisco/ios/_meta/fields.yml +++ b/x-pack/filebeat/module/cisco/ios/_meta/fields.yml @@ -1,4 +1,4 @@ -- name: ios +- name: cisco.ios type: group description: > Fields for Cisco IOS logs. diff --git a/x-pack/filebeat/module/fortinet/_meta/fields.yml b/x-pack/filebeat/module/fortinet/_meta/fields.yml index 21a001384ef..6cfa7a7a609 100644 --- a/x-pack/filebeat/module/fortinet/_meta/fields.yml +++ b/x-pack/filebeat/module/fortinet/_meta/fields.yml @@ -3,12 +3,3 @@ description: > fortinet Module fields: - - name: fortinet - type: group - description: > - Fields from fortinet FortiOS - fields: - - name: file.hash.crc32 - type: keyword - description: > - CRC32 Hash of file \ No newline at end of file diff --git a/x-pack/filebeat/module/fortinet/fields.go b/x-pack/filebeat/module/fortinet/fields.go index 535e8089827..852c9d9d77a 100644 --- a/x-pack/filebeat/module/fortinet/fields.go +++ b/x-pack/filebeat/module/fortinet/fields.go @@ -19,5 +19,5 @@ func init() { // AssetFortinet returns asset data. // This is the base64 encoded gzipped contents of module/fortinet. func AssetFortinet() string { - return "eJzsveuT2ziWL/h9/gpsfdhyddjpLld33Tu1M7ORk2m3cyczrbb8mNjoCAVEHknoJAEaAKVU/fUbeJAiRVBkSgdK193bHzrKKemcH14HB+f5ijzA9jeyEFIzDvpfCNFMZ/Abebf7SwoqkazQTPDfyH/8CyGk/j65E2mZwb8QsmCQpeo3++krwmkOLarmf3pbwG9kKUVZ+L8EKJv/vbO0yEKKfMfJAvow9V9qsmuxZBlcrKhaXSQy+eVN/XnF/QG2GyHTxt97MJj/XX28+uUNeU/VioiFJd3hx0FvhHy4YFyDXNAELszfG1TEGuRGMg2/ES1LGAVoQctMz+wQfyMLmikYh/ee5mCQ6hVUwEgNjGxWIMF+piVdLFhCVlSROQAnYq5AriG96IxPKvqEwTTXdsRQ9hdxx9ai5jRrDa+fex//EIsdk1wtW38/zKF/wTqr8mnFlPkeYYqUClKiBUlooUs//5JuSA5K0aX5N9UkETkoM2hhPt8jTcitWJJrSEQKMjwQR4vtgzp2OBVdWAPXMzM0ZMIecOTZ91Ou7JwngmvgWpnzwbjSlOsKhgpi1Cw/BmBK9f4HXXTMYTIsCNVks2LJilCiQCkmOFkxrQgl96C/Ms1BqWr1Lzpbox6sWokySwmHNUgyh3rfFVQqIHegqYFGnVDdsXpxK5bq9YQmD6DVTx3y10xCorPtS6I9bko+ghMWbofzBsyL4ERmsIbsiJnMBN8/n62ZvIZCQkK1R5LCgnFIieCZhaXpPAOS0yKMKlfLGdqBObDGd/6c31z/TNY0K/2JZylwzRbM7054pIkmmVi69ZKdhbCjY4a83y32e2Y5Cio1S8qMSvt7v7AXvTujQ/qonRLaGR3K/Tuld0nW512TN/97TQ6vieEaZ0FOO75i/s+ZHcj+snw36Nb0GKEXHZoEJUqZRLp7T5+2WOf/NGRKUw05cP09gqNlyvQsyejeGf5O4AHXcvs9AlsZnep7BMb4ccDiakyV5Ph+d1oK9BjpEXfaFgAp5huqR68JvTMbX6zMAgZNRw/pKAmnvSL29JAO9YFXRP8s7plWzjSLvGFVCU6fm67OMJGmjwRm8MnTl5xDrS45+1bCTo2W9fj9n7btR+2V4Im5HKgW3/vLtkfcrFlccdic3SvDhi1YQpvn+VYsyds1cE2mVjiTkqcgzRNEghdUnaEv2COkRIE2RFo/bvNQ/Q+WahE6tE9+sNSL0CH9pEXpWgLx7UvHbczOuJ4wJ0+bg5VQkfTV5r58L5Ruishsf0cq4Cnjy+pDFdo2DRvSH2d+2TEbrPOj3om9maz/QmiaSiMr+477/uR2Rq/FH3Vy17/Gnt5f//87vWa24suGfbngDGlNa1lKKFmyNfDaSPbHVQTMFB1nv4j7Akm/R+Xvj+HR6DVoiGI7k/Atwlo3nYd2ge2451s7y28dazKxB+mlt2ZrSj5tCyAJ7UqQORBgegWSfL7h+udfiZDkXSao/uUNmVNld1HlIFuwZSmt6jcw7mPU3T/wuK0bNN7jE8G+YH69FLHMbIdexxXnP7yBQcgNlWk0pa4h0RrDbs7kzeRLS9+jREJG95eUELVVGnJ/iXrYhtoK3E71gTPm30KyJeM0q37T1lYG5iGW/nUgMOJm8uXXwBR4+J2ZOH0KakTdWca4fXYbtas4Hnv7rICmIM/iu35vWZGb61O8pA5v01lqyRznK/2ujWxZMotuZ6OVonWzU7TsQTFPlyuRZZBoIf+IAtjM3jPE3Jg9xxRJ3NRBapC2FNVbsa+2kAMT/R2++PJk/r2oqrlQNtgtF5zMt51FI0TCtxKUNgQVy4ts69fJfNkIegI0WRHFUiAv/kz0SpbkzV//+hPZUEUUAK+5HJiJ70J5HTETqhBcQbypSP4wuyIRJde1TaHM507omaOsghTICzoXa2hMBuPByMpKvCktgea95yf5w2ybZ54qSFm5r6dhTNQPIc2xNiywBWH6H+WbP//8r8qJ9NeFFaAV6H90RvMP8x68pVuQ5A15yxNaqDJznhXzpHySXA9RP9H5EYitDHH55Q35dzPcl+SXX8i/k0RIoy/bUXimL8n/men/y3yRKdKelB+CS8hFCt/tW5dvYJbQLJvT5CGuBuzAcaHtsaHavSvMJAJPC8G4tk8TDeEAZ7s5ZiCliBSfttMHVQEJo5lFbJEqLaTRrPnWaR3mgzXNWOo2RggUIQtR8tTcMBlY8IwvvXI0GLzYPhEdyhi+QH8cDriNelZhmwmafi/3nIdDFPsdSA5asiTw6vBP4eaX7VvYXfeVEDbXPtU7jVYsqmW7IO/FxixN983JOBHSPMa0IA8AxcCkfRc33h9k0qRIQKnZmqWzNJbX9W0leZbAQVJtD3lqZrDxLlwzqUuamUd7y/bOAyYOljPz7La+cjsZbhT+qN9cE2mktbIGFTtpVC5B118bnAklIwU9PftMuEi4wzMho7iCuoL/5rqyvX6EXGggU7/fEwn2op1v+wSl+V/liPkDOF48p5kqMhYzsuG7fs4r1lH7vwvdzMjciPvdnjpzB/i9Xu266tXir5D/NTyMTry0Ek5RV/qQj95wNY+jydXlxOu+CeVmelheCLmv8RJ7Rf7hwiDK78P88dldVfYhbp/uIVNq+ylf7n6ye7A7Pce+zC/Im7/+SjZ23nOgnNAsC9sKrFHfqkk7+xHZgARHlmqSAVWaCL6XLtKexGdXE//Ykxg4qzHctn7uvgqZ2omzUU2QrLjIxHK774hbMNnRYgn5K0lWVNJEu0k0h3pr8VujOScl9zE9Wctm3ptRi53Q7Rz1MZ0IB3yX9kWRGyVT8MqNIOmmV6ZZybqnVtLEaqzOR8G9zUEkSSkrikpTnlKZEi5kTjP2eyi+V8g8OD+pj3I4eopEOe9cSU+apB3qGszrjC3AjjjwwFeQCJ72KNi75Z4pHdPOcmBAjCciLzLQwQ3Qa0SlVoHXku2JwUa+mdTPtJGnhndwO/dt5fbO7N1+ueB6hbRMu/xUrJiXXZRT+kwT/5anMabdkPxd8NjVFg6IRcO9UjFdeO2n/RnuiKhoJ/qSaHjU/vCRNUjVSKdID8WBBdb31M22BYo1zF2aXiJkCmm8e9AH2fhrStUcKx2jirSpv9j0r3dvKynyC0u1tEn5KgFOJRNOrc/LTLNXmoEktCiyKvtlV8smp5wuQ6m5hGTWvVO9Fx0oh1URpn9URGy484xpmhf7lkGP2HAzELunTyuSrJh53YgU1AW5K5W2z6QmUXMqqe6Jy6UajlykgwJssTC413AOTcgucsXQzZ2EBUjgidsQ1KjWKVuz1Gg2dj+EBdm0EmSf9iYvPMjHgsmzjXC3ns4X9Gh2ItPZ1g1WGaFn9DUDym7Qw7ZRxEXvNeG8NNK4lmcXHZZ1OJkosSVQ3lHkTqVYzz/2UbEa5LcSyrNtJbO73S7ayccNVcSCSHv2jQX3M/akIioFrQmNINOWuY5w+y7zGFiLWQSoxSyG9lxgiqI20TfoVCPoSo1b5HmekHvPx+Ad07kun3TnHCs2h+TaMc6C3QWxVw0B2xBEk44Sj6FYqzKL7XbqeUWJUicih9cOQ/14sVHZYtHZIZT7KWg9IHs2CKxBMh0zdeTAwCruPgmw4dk5ZPKJm7zYqR3obuk608VQs36nAhK2YLuHT1i7dc6cvpoqXleOH80UWIDaxMjSXcJEZaJKvZMliNs/m8+1CF/ar/TmS1BI8mHqQ2OZqgIC9u1qln+1Qn1ZkqoQiiEKjlF7yz6neeoqTNlQ/urs9lbhKTM9i1e66ImiiJc5SJY8VRYFx3aGLLYDA2tmstUnw4kld747Q1sDT4X0AbMHRybm/3yG6jWVa1fM/wlJ+B1tgMXPBe9Mt5Ggh4E5SR+zVt0P3QPps/69mPFWrhWtY4u50ISSla94EQ6gzcRyVgWqPItQrzbik4X6OWqmtGTf32y4la1abcVHWPEXGUu2sU/PAbkwsQB8cW2ebXvkcpnFjJsOT+DHMgMLLCxOBdfwGFtjrQHdcGev29VDpWmqzP/ZS5VmFaBQAZiByzlZUb6EGYdNbFnQ57iETcPVb5UQrSWblxoaEqIbo68cdKOtN6+/sOhQBUUTdvXMZSxa2cpDk2YfgvvxRQ5MU38LPG5tBpiZsKrgoNrFfMk1yAsyBbcopQJ5QZdgS3n7SPeFkBWGDu2KjNPbE/t74n7fqFshJJlLsTGfVX/1uqZ7dvXWk75JJ1RqbDNdTRjbouLPlOhkh57rTIksrdXGWEdKFOAdirHu4ktOaAZS19FFcsfU/825t7z4aBQBsEFIAYU5JVzwVxIKsC+ZQ9EP9tlwzisnKaU0B6Z+r9iVtHrca+Y8bJX7pzOyDdMrryw7WU+uLcO5zTbhRPBXS2H++8BNYJWUWUBxjDhu2nAGvrYADEixIEY6aAbqgkx3MmW/sUEzsyoO4iuXzlcq84hxKaMu2Cb14tdPPCVJVipdbUj/j84y2Z8wZVbS50R7+4ZRfO2n/SrQ2bUfd8LCL3pXlimeUvbj0MPLoLy2KAhVSiTM2kvNagTfk3bBbtkD/EYoKVZbxRKakZSph5ekkLYnyksCOvkxrChTSY/JvXziRe/ybCTNQYNUpKDKVvFStpCDq0WQiDw3Uky0nPbd1BrQyUF1z90Hz6XxNdYwwsXkxHci8qLsnsEIy0bJhvFUbHw8bSJ4AoV+WUdS9E5GZ5iLMsu25FtJM2f8TEVOGfdSgzcYZaLn6mpaPbHUpQNDNyrhLeMPkPpcoCoQnSprnfIPFPPJDzW0C5YeWrisUxUiqqhrdnZyZol9ABW8ukPW2XF9KLzllUy75XpqpzPInO03doptYvU8LVq3/w9r2r8ga9oLlsU/4/WQ31lu9TGWkJYJkMpzBGFzmwLJaDYL3KbRLpGpZVmpzfv3Y+MCNDdMr10Akgd1VMkBDIux524uupXvEmdPqFELA1mGZbJykb9Vjk2dZnhVUdorEWYGUrO5UDIxv6r/3c00JUaec8JszF3JkwyoNH+yhfB20HwCobd2yiqxc9j74IRf2a3z9F3fWInI54zXdbObF5ZPG5VPuL3WTJbq3Ja+pjZiAfRb/M7jIA0ciSvH3dVk7LeUuhdcdNN4PX3OynxzTe6dpHnhCzcQ123PJ/0abD+F9WpngH4OW37D/HxzbafUp7zVYqJrPWh75FwYoBvChdtERhZsmAo/UtdqG7OWfdur6xO0nbpw0I7N3eP7jLvGTP1VzZjcXA9qslj2uQFN1gB7w9OdRntBrlx+pq93mrkPDmuzFqBsf+PnH7w5bl7qOnNT6PoyKnkGys2McBfKRpA1lYzOs04WoCvKwDgpMtojCBRwFbU+SmtBm6qq43xhJJXRMKr8QmbWefr6ZrKvQxNfMtZZFPryso9sKDg6F3LnaXEgyQ3XZMqWnFph0bNFCyFjFq/9sSO/zCadVLqbsFUd7X8aII2zbHdZKgIb5/7DJ8J4kpUpGHHmG9man1+QF28faV5k8BuZOIOII2ul90XYLmI9c2f3bVrj1O5qCSNj6sGo3EfgekIqXsOMee+vho9MPRxwuWrJlkuQ8VrYhafsS9MX4DFY7XQlQa1Elprd497qPZ1GW673M1gWur53L5VffHQ6xk91MY6b63AayWjvfCLyYnbmuCu7Kj72yrZxdfY9Vc5fGTiC2/zUhW03I9Iy6XulebX0maLGmshraSmkrTxg5HqFr6dLHJXphsrnidDrVtU30pX6i8gMoqc08gsjRCm5o0lVTzms3BoRdNZ3jOCvKgVVHpZC7q2J3tRaAlXoscFKU11iKc61PYqy7NmeHYb5XDwSlr7uv7/MzVqeA6FB9LlT+NidBYMifHSreyxy973OJr/u9t075jpjXJRYPs5GHolaop8pI0kxjQ4di+xfkAnHrszY2hKXWWbkHlFlkoBSizIjbw1/kogUlNkSVbHf8MuC8RQekScgY0ofp3meKFssY/sUkxWIOUjr38ypZJmN4AlY8Jz/nS8JtZP4yvw2ODIeYR+KuSsu9EwasedOXtTxnAVIVfikWydhOlPmVYRdQHxV4emnniRDZ+bq3sexA0qc8lUHeXlblfu2+ZAyrkgKmrIsYGSYi1I3ftczNJGdPTazstjSOo7N4ui/SDXkRRYtmueSpLCg3gXkK19WPnwfrWm04jXIjG5tIpcW/nIlLwIn0nxgX93+17CossCdrV5ppktbmJEEB7Z7G3QLNp16XFG9WA37TkKxkUaQVYnIc3Oe4myjK0edsEawbyHFmqXOflZVkctB9QZCpSI53tH4dGvZO5bttMakGZcXVg0eCxv09DyyvuIeV9b/U8yPtDsdPbz/R8y9AyZ8ugoWr3DutQ0odis/ndyQm45C1YQRrWqtzy45jAAxsavOhl2iPqSfYg/zsdVh5d6JiNlcpLEzvjoZd/tKh8dCDJYe9WiFXy3BuQzOkHneMAH71GEXQFv7Q9iSpbUrp8eIl2O/Gjtp4Ag3P56SV4+7KGNeU1V378lnVz2nckTZYI1HSMqmFcGFfs0hlN5aVWE6FLhxBkNI0Cqetg0idXYlXVOW0a4jg9SmcGLzKxcgZU+nBXeGjrH14/nd/GMl9wWgnAO2MyQfbqDY8qJHIrJ8Ni/TdItun2H5DDUPqEG3VHBcofODVip8ipIJxCoHeyl2M1WeIyGBqWb0qqu5SsuU6TqzblcXzSMKNbbbZWw4UbJzLxwepIsSw57B9dle5Vdf3pIXPlfiS5kZXXnOMpvAYePA3j4WQplv/kRedQ0NfN8L88DFhrceQgqS0hazWLep93TaTOgZTHD7YaFXVZb7vU9NuoUlTbbkc+9zLWNzSZ8jKd8zbk0x4ySnjC8kzeFgOEZBpe3aG79OQku5nFi25F6kLjh6VxawEXUWAEUGtC8bKmAmItYLqV037h425H3J7VPyTqSQkReMry/+9JIwkbwkc/N/YP6PcpptFVMXfwr7F3VSzBYZ7XTOx9ah2hr+1YRYptbWZeXktmp+JRYHCzVoERWp++vc46zKICiQZiMHAa1zXLm7h+zL3VcqgXxyAcB/+tOXu6+XH9/+6U8u5nZNJWW9e3Ij5ANmyvLgAftaMWx62HqNYJRjKxE+Zwe3Skl9HdDEXBfbCE+YhZDAFUswBUjDlBQBcY5vBQn4B7CIzjaUdZsTn2wdsLXPsYma44Odoq7KeaRDoeep0hI7893ma0cziDXvUrR7tMr5iGckPTbZZdcYrKPS+GSTXd6Lz3cxJBas19BUDTWaIfbYoQarEQWGuZ/eExbKR9cTfLrhwoD3+v/HLtedyuw6/z3LFksbNnoP5CDIZ9kclR/3ED4hzhC01VrZxrv0ha4j2qsoO1sn8ydrduvs3GHPdFWymp3DH2aTvhaUZWauq2IuEy8zbq6buW22Epd5DmpYBkoY9EcVVjHXM6MiHjGeYwKvbbi1zz66Enle8n1LVAcdP65w06no7uFR/w3COnWNTR2nWZ+KbUp5+p8i7DXbYdNUs2Mkw8nouoxb4FSpCpYwgRYleq4XvEW/oZJ3nQ7fO3TF82ImYgnj6f3dhHxwdtRdUGoYyLezhhJM/35LvpUge2q3lhmfSdiv1Bk3uKFhEN2Sj1XSWTCsq9bSE8SLtElUYLcRMESLowxHQ1R1wDl2Mt0Uv0EDzajMI6yWIRvBvEALxATkmmiZonWlbdHErXbVIp1Sva8Vnkp3DjxZ5VRipZXUdLcF7bQvPtn7RJNOOBUKzdkKfS8ksMBNoKoJL5a21FIEsmL+zwhUC4reCcNVnELfXtbpPmPYF46v3JaDUT3RQfMZTWxjFPz0E0NbccTHe4PwfFms/8If9Qr9fk/4LNFylirUuusN6obycZ6nEYTXGUWXGHwGfMk4YlJkl3SM2Gg+W8zUhukEXX7w2SITG0Vz/NiVJm2u1/GoR/C6JHzGeExxwngBMp9v0QLeO7SL5CEO8TXNYuwVVswKKbSY4bukLPX1X2bW4ohPO4t2NjOxnKUxJtsQxo9/S/gsp48zrbHMBm3CZkdnEOFSyBmPBJrxeKCLTM2yeTbDdou2aP85InH0yuAN2ti1EJu0sbN6m7T/GpH2rxFp/4+ItP9nRNr/Goe2FkVG5xBDpNTU8Z9nfJaXmVW+59sI92RFvHiIoJfkZcaWeRFH+zZaJs2W2EFInjKLoZQo+Jbg20b4TLmAxAgrqGQS5zVpCMd5TaqtKosIvUgTXqdVR3mqaqHN0wMeI4gQLbR5mMWibZ81UYiXnD1yyoWCJMImXP9qZiXSpbD+VRR6BTSNYFYTeTFLsgg2bEM4gpPE0pXzrcY3ixrKKgrlopxF8GkkkmmW0CxCApGa0SXwZIsYddWkzWm2/R3SeQzc65ktAxqFsisHEwe1C6yNQn2+LNa/xrFBq9mc6X+NUmgsUTPcXnF7hKVAF9UqyjG3VCGR+Fluytn40XptNQiDXjk7P75xxBG3al8U4q6aPF4FuQbtBcsgxhtGzRYxFpEtMJOz24Rj6AZqxgobpDiLIupYsf5LqnTRKeaPRFvJJArtjC0gxjNGWUNzDilDSxht02Y8zi7JRVpmoBIRY7Y9cbaMIJtEoTZUo/b8b1APRZCjEJawZEpLim8J2dGOoPFJKGJNtYw218pWIpeR5KuLzHdbPAJ1LYHmERRJlwoUC3Y85XqzEkzNXIdZfOpbKmmUDZ72JMJiUF67/vbYdJnSlKP3OU6VnpcSq1lgRRVcr6AYVEt0rPh6dJWTjE3Wdm5Y4De7PrbSwCGaS5qm2GeApdhu1ap0UIS7iOWzRAqRR6lKZAhHeKaxfBYnONJXPIoxzcUDenmmQuGXLGWFKiRDJppRzXSJHn2WMQ54JXZ2VBVqR52ark2+xTdrZcJVPZ0tMoF+ndfEI4T8mzcvutQxRCNIHPOGjgAVPTYhE8soW5cvoxzgQkhsAZbPy2WMY5YzlcQQC7mKsmFj9IHgoG1xJXS66DLcFYDGjvhzVLHD8fhmg/0CiZJRJlwDaPSXqMDXjIRky1mgH9fJdDccJP6dVcxcU150sqidqXdkXYvXKJssQuKm74mDLQw8WWxpUMycIQkdLlXKfDhLVlh5/h3S8FgwdEdAATJfSsp1p+YuBuVNFML4V6+rRPb5814XUATCUixnVBWIDQOapCXFpiqBZjH0OwmJnQdXdTQScfxJNpRxS7g2KAuZRkCMb8hUEWzDytmGI8QDKMAOBHANjyM8ThR8w98AoQKtaFQjPKUUW0YQvKrAtrIpmcQ4BzJJ0RVpJZNQVVwEwhqvxVaTZqnQq2quE46dKBHsFnsqUVekE3v4eqnxt5Ujiu/Rq3t6YtPdFujVWst0HiUOvZRZhLuwVCBnKcPOeo/StqLyDMWYBp0oTXNsa/B6xrjSdBFBM1gzqWOo4euCRyjdpIUsOaaZNVQWLVBR9LLUgnwsOemwrqNHIjbL+0IzlpIrCSnT5IrK1FczVLb8exiO65wVcZb6OoRaMraJPrH1DRKRkVCqTh0PwXi8mXubF5nYQqex4OD8LUSJVtR75B4zc+hsRrbfmYQlPJKc7hda2Pli+bLcbwYSHWTGlG3OUHH3S28LKBFVFoWQmnQLjxKyWVFNmCaFhEXfVjghLPcpTShCE+9fHTUEwriv7N5TFzpjPHZH/gZUw62JUxEtlqBXIC9231crUXZuNEI4rEHW7Yi0IAWVCsgdaGo7gruzSuspeHErlur1xKW9/kSufYuvl0SvAl2KbDHgj+BbH1vYnNyD/so0BxVe5+6mjjJ5C9uyuz5FlrkbrAIqk9UF4yyIz/bcPUN97T3xaXth2GCI1xktue31uyxtH9eqiHu4gPtevfYDY4pfjrseU12E2/cv7nnsm4WYIeY0jau8atmST/Co7anoMxecoxt1j0DaNa67tx2qedbT8dJWz43YDtzWz1WgiYRvJSh9oGj38dHKT6+V71QG25bHcXUSe98iVcedts0phzA5RNY31vq7rdCufguOHLP3/3B/Q8Ps5roSCpZ3eG/YVwNeEO8Tt7C5XOZUAXHh2jUa0jlV9Sr5XzwPXl63gq+RC+nK1wenkRCqiAKw7c7o4X5VknJFkzO09+1UmHasuVV7d5smKaXtgHYIdAEyZ07dOBfoHUvXmIOtWQZLIBmsISNUKbbkbuF2/frDW9+WZH5G+W35H9jp82fp9GyQlZx9K2G/TSINH74G3uMqJh7XBaXSaFjqDmQiOAcbW0E2TK/6BAUhgcyQWmOXcFR60ZOfFmY6rTypr6hMLFlCM2IQ9Dx9LIrnRWdZ9bRpfL65K1ZbFYbXCGfbiL2oVuwLnmaMqtlKRH8TuEdc/VyzvVR2TY2MVGy24AnXAyDu0Bi09k7zjViSDKi8uMyUMA/x1nm7ts5y8t7/4oJc8m39rw51bd/yimtC04tE5EWpQYbFcBQzvhlYvOfZD/trYXssthaE6X+Ub/7887+at+91YzmqGfshCNvv0xmux2ys4YZuQZL/Udvk1GsPw4ILn3rs/J/4e57vMLd2/cH1ODJ4eUi2/bjfMMXwuSD3Hz69NWMHCc54Yu2lKVOJhILyZGu0Sq+eZfuxIMTO0Evy6e43csP1L29ekpv767f//Rv5fMP1r38hLzarLeHA9AokSVZC+VZpQkpItP3Wz7/+3//HTz8GZwT0KqKM258PK1Mvchpux6Mi774nHvOp24s3FajwEU+/L9BN2TSA/MiCcaMv+BDePcV09zr5wqQuaUZuL++DYH8XHOLZso7bGf+v4HARnlsD9w8jQu1AhoWnXYLv8Q4+sA5LqmFDn6FFut3dE3KZptLaad0uD8Gpr94kL471c57qC7m5upu4W6nXPZZTdUbvR8uo5DRVf3eTm4mB0mP9MnN4ZCcIlDk0vPvnsNLEZq671nkFRAMuTVNmvkyzncO20cs/fM+dcQOYJ6E94MKf8Ov2FuhA2cVaR9Hrxl5plNx7hBMhdS2SO0I3tQ42uwBMb4clrzrz3LvxML6sLpNqWHd9E88h9G48lxXXo7MvX6qUSJhROZ3dqKPjECOXJeVLuKifTongC7YsJaRkvrU0gac2aigsZ4ojSw90kkZ7tOUg00WEegcZou7fTOFCNwBIyIWGmY/sxo8zwp/alKsZnblQ/AikCy3jEF9E2BKLCNnCWYzjEKv+SRFhUmk6qyxx8dTy/Re8GcfFPremMeEZNNi3egWSgyaftgW8JJ+ra+zWGsB+IZPKANa5CT70aWpVq54zKBM9T+MKtLeLvyQ0y4LKRLH7og1wo9IG5q1BmjuQcS2I0vYyZ5x8vukVKIkNkI0mr9BFtiEqight3wxhCQo7oteQjZDi4m5E7FB0a2+PgNa1VphlwJfonSItZqN8RNRCezRQp/LQrOGA4SSx4QQLQsk7ITdUpt0+3YRcLm2wlyTUnPhHG0s3B70B4GHVE7lq4lN93ELTrOmqc2CILRlvIyM6I2Tcx7nasIScaSOWfIuN8BDXGeXn8OOPMFBWASINE2VngG2T5c6TsjYv2KV9wLZvHmxPJSS2CsEarx7cOI89lZolZUYlsfWiSQXixdvH327FUiwW4e7vkMz0CqIvbwvsJ8PQncYG7rcGt4F7WeoVcO2DxXthqxKzcsK4gB7Hsh/6ZwWyF7AodSLOO9OeZT/gaZkkoFQPZlt5/LjiaMcFnlhcxKi4SyG3JJCY0MF2DuHUwgh7GI1Usg4+VQhu7hUjt0LKYf1D0lGU2qNa49Wj67k3KXFVS23OQMYgrcfj7TB7+jDjRDFdBuQnsckF4EW0p7qiitBUFOZ20StgkogN3y2ZmzhNHwUXeU9cre3JoZgrUX9eJcIo94ynRv4IqeoJoOQdy4BcemAXnWkYY+zl9cDcmewNGK/H/yzhCr1TMPVRC7izEBpjYCIw891PmAgXrzf1+RrYM9EfEDoXMbMHAoOfw4qumSitdpmIvJAiZz0RinBucG85nWc2iWxBrg5jY3xdi52IIPcRtrROEgTQQojaXOYIgAH+Nb7Yq9u4ZXfnrXfb7dIsS67309mwNfrUpoHPkmOe9aO0IHsfL4GDZEk1JDshNtBvP7SA6ZW9akO93YgHe5H8fKG07Hd+VmM6puzWs43pzeExefXC8Yo4ruDTtH6Ea5aDMnLdaXsSCuh1IvlVQCsKMbgQtvDgicsgR26tY2p3P9vW+mXcmH6eKbQmp6OH5g3GQyPsjM2OeCcQRgiDP+7o3gyOTp517dxBQxmbHF45tFqq5xEgA3K8FiB/3O34y/CSYbU2OM+SjZOP8qwSBPOMjZAfZ92OmGPrbMZaqbcpaHt2avTMnVKvZjnolXgGLwltWZKJg+G/1rvgtpaSFFGtTge8Oh9F5u21BsiBfRnJEvLfF3/985/Ji9vry8lP5JopzfiyZGoFqU2FD2LJxFJErwt0yBNmo2UXDodfZvvFnogxKSJbFQ/lf5pVDSGoT4y1yKM1fX7KcUls2H+d99sw/FlMIZ8p5aEy6btIMZphVafbG8hHmrJSOQ5ESKJYzjIqnXgyYtOcocTe6+H0KnvOFUvPWWmkGSn/2WyEyoq4Vxdzd8jj5Vlc8kNn3bo1fKZhw/7rjUT2k85e8IYbaKRlpGFTppAxAwM6Lhs71UIuKWe/H4iq5vG2wtjJPmKmm3uqZ7oXTAZzSSNV/Xln2NnbwpX4crWLWlHN74FmepVQCaSQkIqccRpMuGuIpwnVDLhWg+HxGT3naG/psw7WlX6EItLGNUfnRyO4Ciq1LYa0G+phsXrGYkde2IyRqAtIQVIN6QwtqOzA/jDC513FsXaeTaRYs7QuHua/R4si85pqZ2P44j/mWmvrtGEFZzdIlp5plDVLX+tPb3uGGWweaiMn18x5z1f7intPCbha6cRsCv5UzRMerc7U+FEjE3oZGKjTUa3GShVRWkgn8Q21HDS13H6037ow3/oxPPqcpWkG55Nyd5bfWDkXWN6G3DtKzlXtMc4z3Inn1qgwxLeVd/YlKTJqlszcz0IS4IncFn1WfhsKeYb35IgIOlm/Ld8LpckdTVaM9zzpUhpJcvywP9efuY30LyQY8WH0I1fkTF2Q25QW5Iv9h9OPUsFd3uk/upcnWdE1GM0pAyrJtxLkltgahKoQXEGlUYWTU814Z/Y355GXvgZeYihLVlWB5G74ri5fP85qSGeAuttAH31x1LFIbZenuAaz/T1elZZuFTEyb0N/8TJFZMl58B2rXtY3j/M8uzJSPTl2nuLMvzDjLwQlG8ZTsVFEFZCwBUvMJy9DeYI+TrZ7QMzwHN5dzA15YSvCAk9215B1Xf7UmC1ScnuP38KSJlvyWbUL39Ye2Hw/kRY9utZwOMODvee2bz61LBSbq2Y3mbkROzNe1wEIZP+3Mk1tOk93+trDjq9Q91Xndep1YMR2hMGN5n9zxGDPE9fbN1Qf4etN75Wse2uH3l8FtDua8xjsaodBe212AZluGTorFC5IMZz8bNMGMFsC9ma42SGnsGDc2+qtcLJV/XJa9BQdtOiOShSLhG1ngNlT/7AFY22zjT12X0uppzZlbcPWmiar/Mwl8Hdc7YSTzuuouRxRmrzMGcfrIIZ6NsyQbVJh3MszIKSaaTt2WVwZ7V16f6BrZwd13LtvAHVBZbWnzJ9f7oayWbFOKXViTod5y7rg91HD0+g9S1xZCyG38Rb831RB+X8MVoypgLSrqFfqeehqMtPyb68t9YGxPZtK1BlVVW/98Kh6d8EMuJaiOEZ0pKKcd4wLo/a452le2zCQjmAxuuyO857DK5EXlG/r82iPnW2n794ra5DmGpoxvhBhpYCqh9g5QgPyY+8VWSHbQNyq6ItvsWIE3pVZtiV/L2nGFgxScm3znp1xMAhlA/NZIsQDeyan+1eYE8d/936mWZ82j15tducOL0ptVe4jW5gOn/WPNQvfZcebo51N/oJ82hZu6DvLgZkct4L9iydhMUMtJrsH22Bwhgj5owqVrd0Hcw5TXa1cttE5y2IhZGXtty7mj7c9S96olYO8naq5KOL2ITowFYbzoOW+gimFiKSJtEEZPmY9SEF12DSZ8BlVmN7+BmHp0+mRKZcyQ1zmBlXEVakfo7NSYllDGjQVyBld4r0pd6TRr6c2adTwxzZpv+sjCBZ41MCtaoX/ODH00XZzreitJOyFymBrVI7FOXIJWzL3k2Vr1avX/r+vPITX/j98XFPI7E8zkOHoPD+cZ/Seu8E0nefW4tpotdYZTuobopknFeMLkLLH79od91nG1VT8B6c+aJ49A8iqLvGisQyBI2Xd2iLqkQqwONv2e+v89mbbfbIRxLL5p/+CboBWf8NPVqxAnsceYXR2H/H04sq2fvyJXFn+YWgg9ZmKpfTM8xVI3/wTWlGYB4rzQlTXcWMiGwtumP6oGpWiD640+/1Yq+TTS6OEV5tM2e9haw17iCRTbv7rLeGwFJq5BSxWVPV0gFLJucsKNZbSMe9vLmiWOloHqE6Ay94eqwqnV/k34YAUxZbnyKho1zequx5+6m20bKQJU6pEVzotZRssFc9ad5oPxSIEKaPaQDuL0pSebw1zMrXO6UPS6SwREnVlcO9FfjG1oZ2HL6OG9DwO5NOl5wGM/SJUqWy2jnmj77tUvSE7CCadma1HS/QyjSoWYfYA/kUdqbjBD7t2Jc0LycrWvxBl/XVCkpvp5X/dTcjE3FPkA+/pvrJDGymT+hi0nzYijNaKoWQFyYM6yog8TgjHrUEWajpX1+usS4TZMFDfgnAnBQ9ouSBZpyjkMyi5DkddFaT30WAxa6rLs3X4bKJc04ylbiMGQOwLwrNVtT4kCO2MPcBW7YttpJ1fBZAi015pXagZsz1oo5C2SxljQhL6HZwmtuRV5ouQTG8HTlQi8jxqnbiRuB0ObxAKp+BvmIRs/6WJbWLZZJTPlHquhreGs5PhX/1oqxytIFqXajwrBDtHWHUIsENALAILKvwasNOarCjnncIZsctNea4WSI/P9kxlm+uLxfc8/Hp7ee/vvdd77OsLRQu5b/tHr9nG1MNsLbIy1gRcVn2cue9zU3fGrtr5lpxpRV44EOonW63DJvZWHXX3yBMLOjiarIwkzW491s+caR8ucNFOOliDtJECizIjieAJFNo8lKduDXvKK2w2MaWvm3jzYK9aaBughZCaCDO/7//zMhSCG5x27H0n5PL8AZb7CQYtE+ucumInwUIxf3v7YXIzIXf0MWc8rdt6h5fVjO3sYZitJoo9w/LD6Izu0LBq9Smcsogenu2yHGeL8yVsPncSfjXk6GpHy1jmpfLNta/S61EcRJidb1GeuVZANeL8f/m84Toxh6ddTRL7dFt7iXlCP1N0o29XbV/xtVM3d8m9L4kqAyHqVJF/U1oKvvyPeUaTh4wpDem/vfZ/e1l/yvgCkvBHCyZhQ7OgIkPnWeM3hPKUKEF6tqWEJVNabs3L/pzCoqB65Yv11xjIPoYOSGuUOhdMlwjt8rUSIRtVyGt9skYOXDdiUhq1X/ZXKbzHzduMKviNzEE3X/0pLGiZ6Zk9Ab+RBc1aicetAbTj9e9EWmZgj3hBpTJv+HdCasZBE7VVmVg2r+SDVeSSxJ2wY2f2Pzqb9NJlwtrGmvbcvPh4eX3zebprhdGD5EGzjvA8BUdGZU4ukwcuNhmkSyCfmvR7QKBOREt29jHsxuKcwHNq7Y117sSeOaAXQqCrzgkg3l/WREkOqpXUHIbQbXLo2B9uJdrlHAgx6GUYcgKfsto+RbTl4O1lvpT7I0Ng/beW4Onh3b2BT+N97di2axj28M47kdonjTpnrtjbANtOOKTfW8E6MgNMjQixTVsgETxV5JWtS25rqEBKFOMJ2CpZ7S5hfbg6hrgTpsPWaLI0ySsCywv33//+w534nWUZff3Xiz//MADICMzOq+KEyXISuFEvqodtN5zwJLHfJBfmyGm21SxRIUffCaw/WQuicx+2EjNVOfct4ezjqWI/EqX7NS7MRUaXbTAOpCvxNQAMU3w4k/Ck9ZTo4Vq8ejaJXRSomsEnezcnpfW5OBXAV0QoClszQIpsEBHqSd2VSBs+r+a7HVPcKevQYH7lBt+p49qHRO6bdtGQfGTqgdzCGgZXQiWd9usn7o1mqPPl5KXLhiaGD4fUvvlS0Pb16KtPLUvzxUGgmLfvEw5u0BOPxHvfw94DAVlyNAHoYfHhvRgoKu5l5RIZrevaH3TYnIt7X8EKrAvMF2ixbKDFpx8Ppsiw9MZov/aL4V5UJ86Flmy5BEkKqjVIrqyEcHaY5AF0SjV1Ne3nVMGvfyHAE9Hq0zsMuOeyOWXK6to4KXntWu6OwYN66zkggxdembK+CRhyNgeYGmrjeKpEdCy3J24Vx33aItwPoNcg8/Rh233KGhk8hv4QBL3CfSe7OBfv6RrzWi71CnXnt9smDG8CvQo16D9xD9S99F0Vcs40o5Uq0a4POwwvWHQWb4b2yAdhzClPNyztRNqegOI/OyT7OHNIZ7LsVA44gff95RX5VlJJuWYcDBRz3X4sva9nFKKuNxkdkM+cuRlQOueUBzietjSGfeuHYc5Cc9DB8gCnsLdUm3U5xqBAUr4887Gq1zwQmnaKadnXtZzC8PWV0CzrOqhPYH5FswzkCL5SMpAzQLw1jMi03pUPU3Ll6BPg6SsXxlbFyowRmN3I7xOUl+v76S6ee3hegonVeIK6wyAMA1EsXV354pGjzkKSSqtvYj5Drro0w7yBa0kzTvuUyKPW/8pRJfeXn4aXH9XCehXIGOhli2yza4YBDz+8DYAVVYiaQZN/i3KY/2JJdae52SnsBV+wZSndoTO02bwcXIbFUsz/GQvEXpOiPgSdkjGIEFq0+wCgPmHb/G15VG/GHTyKi6V+LMSmR2k+ThS00Hz6b9KmH8YRjK8+AUQdg361R/kQe1zhMJ2+ryO4RwiHFVWK9alIxy2EIzm8CcI5Zsiup8pePGxIT1bLFdB0v+H3aUEAnz5NyPs9qmHuWSrm/0Q+ntxWkfTSaXhBbP7/rDcO4SgUX9mCecpVAekhFKJMsSNCrgzRUbEoln2pMJ/zjvmwjz4RWZmHB33UQfzy4WZCrtpEexjnOeWYW+/2hlztEe3lXHLUuJvp/d3EMm/T7WFv7gwbqYX5LGhfRfvk+5CYw8rCjS5PwGIfba6yRyURqoo0g4is4QkRSuWtqEiTXKQjUGhJu9lap4iky3c2sXFnA5SgtGR2Zoakk3vrpExRmfc4s44C5Z5x1W017knlvoT8tnBEXcki6463d5i7GYfw2BKoeFi+TO7JVbtwXg/jbpOUkzTJkmvlOnw61XbEYSm5pkWPhesYELvyqpdFQa60zEgmlopQpUTiTNV1d+1REY4O4joKwi8Y2BK2CO+dE9Fd3bybYuBLsyjLe307QUHHo0ze9T3K3IU6mKDgc45vBISL/dKGKPAWCwxsrIiytjcTlLVVPaalE9GZdywKuij7bjq9xUC3oVG2ndFwMNDtlZDHQgdz8xzXIE8FWZSIt/7k817rsTBPeeBtehxjp5w3SquPeqdKpllCM2TdZ7dKFQNinjF8OaQXd0oyn/Rg3p+RESGIicxaX3ouFP3xKkctyFTk0PzOAPs1oJqQvrwdtBqlFLr1UE7geW3pET7oVU6pppLynsSGI3lrSixN+06VUAipB3Z+2k3MPA3B0LBTrg4EnDzVnX5tNLwxESZpt47zKeMcu6NdjC8TPFjm/CQEnjDZo9wDY43vPr4GG0swzm2cwppxHUrxPy1JLXUgbrgGuaDJmACbFNa4Rgc/EcPv7HSVFLNc7YfdncL6/dWE3I3Jz0vN9KOegLqmBqsmfwgBapy/UkJ5vatFuZd3JpayT9o9PRjymqkHowAuGV8SOSz3sgIetdyvGHbKCtxOiCUZzPIPgxBJsKj6iSgWjC9BFpJxbViUtsngHqMePDllPNEys3GIgSIBpyimN++mnoMNcyRt+iMA9UoJHDwj5EUNBzsGrgNmj8EAHKRgOIvCx+ENRSHumOPeIU0MI7S2GkVlfY+wSTyanVOlNvWPBddTqhFpmjrUD6BxL2WWPuLNkUfh3+CDCn4DBm7OWxvHiAlB9C1c20YfZmtYm0PKlAsjsgHXtnnrQAJoqvQM1S11jEJgfqEXUmDGXgdxkBaPPjDontTrVhvpEX7UVOlIqvoOSPoktd0CwlaXO2BGXIVKL2jOOrWekHB8mJI98n0oVptgp08kHO+/kj3yh3B0awHjApHDRkx7hkGrNe7rOnCElYtdH4QjFO7Nt7dNxsh5LVTUxfkwHb04h2wtR12+DRij7C5K46YwNAFMp4O3v9Iq7kFRYqE3VHZLc/fhKblRuI0Ohf4Wa8ByXHx0P6TjnmNKlyXmWn3+vCvt3wR3MxkXTJeiorG2ks9DOwZoIbIE0ynx9nLy4dbn8To1YEA3sxBw79wWhuHbFlxTHrw5+LoCWwJ5l9FMmKrYQEqEJFwMzkvdKghxYnbth8YYUqEQnYKBp2wNQ25X69G27mZ8OSLcF1QR6ExyykRMJ3sJQYMAbMz8QkjEGGiD4lOHbBjAY89KHMX4jrKMvH1MVpQvQbnQsev7KZGgCsEVEMrVBiRRMMK7CZ7OdwuvsIVHVNXRCnH9PGkbYdCl3weHYT52bMzo30oqU1t6UrIUPA+bva40zYsBSbOguZoVtFSIpp26uuMlp9lWMVfi4Y5yurQ1L+rkzEmLbw++33Gt2RacBfY7SHLrzdofBw2mi0RDrjCL0jQjft/6ArVkOr0fxIGqKzRRDKoMtjgnHu/7TxNfEWePcg/zDJwJCg/BJ1f0TIOsS+r6HNmtqzCwcHVvR9xT5hsrqlao6ezvPNFRWq0bSF/e7glODzs/48woMaygOwzD+9N8DflVfDshssxgxHvYsUe2Ie1GP6zNLsxhXpoLwVyXeCAuuWaqoLnVWtqVj/twbKhMIV1gmo9c6L1/T+14DED5lmLK7L9fD8lnSXPA3QJ1smKXdg8EgJSph1CLldMudglgHcydn/fgEIgK8zujCUJzCwxzn62TrFR9N8aRcV62lMiaSV3SjHj6vtnNACJF1yBThlmc8d30kuwTDTPfOCNWqB3QKXsT5qSQ4nHrbWQjpOSSatjQsBr8VL/q3xwtwoqmXCCTyUS8rVQLFx02gEk2K+CePCt3kAu5HVXtz1Y4xkzrtaV1XZXjoetyRV8VkoULNh3F+/0lmUhmu7MNcZ4hl3Z+fzmmRtaKznCdcO8vycdBj9uK8lStaKcd9ynZk9Nb8r5Dtoc7Zk2J90YbrTtypmLDM0HTURryap7ymQSqMM1a74FKPQeqLRayRz6Mgy1XyOHY7yuSZEHnkiVElXlOh5TllcD00r/3jVMP82QU29K8/pWwASWMJXmRNHNIT2fcMLJPbNMvZ3y/ubqbjCvjbzChVpxyikFxNBhcpdGWMNwW9pQ+AUfVTA1RY7oHvRHygWhJFwuWhHiEsfCZKhjejNxMpm+vCONzUfKUTCc3Q+wTi9R18eWIt+SNp9xuEDyExhkiMFF408bd3XQcbyPh+3M3jn7bV+Rd9flsOHejEQWK7Vi82ZEeZXJhHLPWfbVDmS0UPXhWXS1MzBf2B8mWjFObqOnD3ywz10quNi7U1uYhgPvBUScD/AiZdfKOjLvCjQR/MnPbjzmniPZAI9XvLq/qx46NifOMyIfPQyINJ5i1moehQFaGfKXt+I4whYU5nMD9v9yPdj5MBVQmA6W8HhhmuRZbKKZFMsg0o7wngvrp7pLby3tzE4qc8eXuBudkvtUw8LLNKBdlWDoeh0OU2t3dT8QBFNO7ZYMr2jTDbFkCXMEsY6j9UO7oI8vLvJEA2vDgOOuHUT1vHfchiH3Qjqtj5G1iPlz4I/iWrbctNj1IOKKgsOekRbKHaU/VHIxmSwOsRbf183HC+NZQMiLRdTqdTCbXjfpBQygQE7RuxXLcG8PqFnh8ff2BoZSOTGyQ3/zv3Eu/QzjIHlULsCIop8k4Q3hOM6PUzlKqw0lZxxct86TBdVceCQM1PzUAY3wWdk55iagf3hlyNNGlHGUHz6nSIFOlUffGnaXa3B1eMqyE0k5fzMtMsyIDwv3LvFZoB3eSoa1kgq7TOsot1baB2pb+X1F1AnJIWZnHEQCONhkjBADRH+Z9DKURuFUmjNJUMzXcrS0HtcpR7XG1j9KQHlEvzt8UyEX0nDRwpEe8EbBT1W0FtjHBlfky16iRt7YPV60RupBoIdnvkFY1PReZsG10jNCzcVjauZOHdgrqLnEGjhG7w7YMxuM7ubp5dT2d7tPt4c2ZFvIVrp/UNTcnd474iNz9CgbuAdmDMVxdMi8wU9lrKXE3mf7XAGO1RO4m44sHkElVTfJ+hN0114ili+7oo4v5rVpXfuZMky/D8TS4e3F483HMGDJb839kFxAO2JXPfWnle9BD3nAOmxl287972FRhCMLbU/cCpnuhhBrMn4hk74E+Yh/ABr30ugHiq66POoEOA3bxc49iVAF0DhuVCcziXbAh00zokeN/1L0970+xVGiQa5o1+0NXxiPDsqFLXgwAXCBrcfdi16NmxBXFBcO079lC6PctmkG2IkvRxUXtf5mOiBwyAJCFRM1/T1IMP2ZFlqJLihrNPuUDCLDlRI2hEhZjjqzIUlyBsdsXY6WGgYBoZPuQpWQ63lstsnRTSIFoWzEAvsKcvHOh0JMxHZcF3zDMlJ9L18dVC8J46rrqsKrtMWHK8/MZfgPQCpDoRRg+FOBqQLrK2EPRRwYDeneXHYZxnV2wc9h3/KfOJDJCdOGnsHdQjEqZFqXGjXj5UOrhOBdRalw3ueE60kVeUKUgjWOWc7THmOXMNzeYrw6r4adO3bfEhUzH1y7DbT41oXpFxIJkQhSuYUGj5YVzY/vW/i5ycQAbYGZffb28J6LQLK+63LbI9wKYcaMg4sH4Mrm3dAkXY5sjFiuq4A1yLL3FYQmPkFrFSqC7TCctmmG2mMrVRArbmn7oAVaIjCVb3EfGxNIc8bwohEAuxGZmWohszCKLnlaIR033rViSssgETQlIKSQZzosw35hDn7/2uLhDP3obKOtt1lqQNpdeMNATT4MJBYYCbAop5oBsnbxl/KG2y04Mg9pQOQgmadrVTkby+eNtpWbv0z4EoLf9+kmiwXZhH13judh7Fpw8F/6dMcJU5lnP1pjxXk+113kQyKk11SS4pKLRKJDltQcxLLC/GS7rvvCaY7sXfytB6arJ0Jgc2G8lleqhJ+TyqCn4+66vuSFM4LHIKB+hrXwrhabwmACkmK2wbhaOsnXNzwE46fDoh5PTcIr400MDq4g4h4VmmdhASl41DZvmmc5yeDWnqvrIBg7aD1wwoftsBHDcbf13C3rYVW1Zl6pn+Z4+aY5vqY6YKfvRT4fhSpoyMUftVfjRkCTzwVaFljWmluoYD+monm2SCQU9WV0ncSdG9DhTk+dh/ynFsjR/HAXO1ejHTCIJoNusWLIiFasngcRs0FC7mh1zQ3yM1JZ00xsnd+S23biotPHMMT2gNfvB/Zus0xQy1KFDAmwNqZcgbephEMjJoZcZSD0qJ1R6rHhHY+ry4R9gW1fJ6nI5iCVC1apDoMZWsZKYOoSPYmsYx8yVI4enaAFS0qzEbGfU6HcVot8DJBd9tfyfnFZjSJHJZDK6bKTjvtFF7+PryINrkVhPqJHwpSK0VTCPtPj1QDPvNewEIPtSH9aWJHzD5mz1/3GszTexTYMfbiYV6RF2IwmqzBBDeGrL5D7lMHfUCguG98TyfjOiuLlUKuxAOU69aYnGjCgtgS9typ11AA5Vr5ZKidkDIPr4Pl5e33yekun0A6HaVcIfp9eUGSArNmUGI8L+DWPks2gYDx9E36IZbzM0mkr67s93d9MBAW1A9Mrmp7/aKsbD4lclAr07uas0+aGqNDltsQij8L6laGp9h0EPDK6YZmvc/vU7otZAWfcDajQJGoaFmb19f3llUY2KL1bANbK+PzWjH63rK/iGyfpbCTyBUdEpruwC4p6s3ZiqLhffZHAARE9ZiWN1+7HxOQdq5R/3zrquyn+9+/v1PRFyMDfc942doVZgcTQHn7qeN6aN6Ovl9RPY67JArGhb8Z0auiMq2SpYA65Qnu5TDPNd0QJkKkUhk3Vq5EQERc2LHymKwv7Lcx2LzEhFXGRNoXgMqgIkK8wvcWFd11gMsgLMiT0CGO4r55PP63cMLDfywmEbsDe7X5h9FR+R80b6/eZt4mPQmb11HnSGU10kYRga40sXYYEpEfewOQbDstG+sxDlcltdvJzc7LPogfE7lnR2RWsNwZHlKnAjh23A8CiVADMlvx1S9pQ6V4of8qAch+a+qsfW9J2IJ3gmFD/oOTkd1dE+E8VzUKuCSsDscLfDZrN598iHgeBXahuMXFUywe3s50v4jQxeVTLBb+q3D2GEyUvJBD2U3MMY1cpPyQS7YZ1nP6ZRnZIJfqM6z39FZeo7Xg13qvNAkCPJu0hGBJLbnYncqq6zMUd1qVMywVV5PIxhE7iSCXZHOM97TDM4wx21GZznPdwHznCOtg2f1gJOyQS3y5pH8XmwT4lS2NtuejVmz6Eu+X9SBXWrnCnoYeVZZbRd9Qlh3LfkckQlKaWy/pJWRxrVri33Ntk+5gfcsCdx36MbZq8pcgbLztNgk3AFV69dFY+hp4Pua/dwgho2ohKp0hS1ItD//PObi58fq8G3amf18cdc/Ms0Z9yXQB3RSh87CXhM7q/STGM2hbsstajK3lrSREu2XMJgIIYq5/8EzIYW/r28R7aPN3ahmKtWetS0nL+6sxzGOFTK+b5KdDKcyy8hsn3scd2st2LZIdrDWRUsYaLnDJzqa62pj3G3bszeRc7MqOvF+Hip0Yl8assT9BIBn1ZgCVdlRWxFN12XUBuBCHeb1HhsXPwT0agSOXLJp9vukQ1yR76z9F5lZrGoSv1oDfIlYQvCBYeX5ou88lcMTJBeSaDIMVRfb66nnvCIIArc1bGFR7xlCdaDNiXMQ+yuFS3GNBrUIkLfqLTRsOKY5lFaaEzD+CdDjuQ2+nIEY+8yxebfEPOOgRpwV2hJE4jiNE4yqlaO/uBDS0vKU4bZYO/+8pOlqjJaJxkNY0CtdGKLF1qq7hE5ahY8XtSWMvfTuuGhRZONRGP11TOoxEM4SkgyrpFq7b9jGeymo4SqnONQfIUuOYcMc3+416CjO7wajj3OHLQ5jxo47p3ZAjDiaKIy9w+QYbYlogfGPYH3gr4/34xBYWuPlgokdm+Wz7yBpyqvMaZJS9nXpOW4zGRh24+XRZFt26TDzGUWoSfu54+3Y3vi1gAyhulVbSBoEe7DgL4bdvxH7QGJLBMa/Eccir7EzRMfx5+VbYcy8Co23GcLIftffkfB2HUZqAsHjpgJnaPbqKtoA6+3FCB9Nfj5lnz+dHcY0JoiqnFVwv6Q235NC9zCyjvGI6or4z9u9h80Q/0AKwSzHFovn5OBfNkDskf/MBhkM/I+lhGm5GctHoEdO/d0ANbLjprS96XMOEg6Z5kRECqh3HMZ4c1Dd6J+GeM0XWNWjKiWYEhpXjOJaaP8YsiNmWHzPcw3imN8c01elJx9K8FxaHScHAgjXQtWzJDNxzZ1rxhVymddYO62yX3zK4Oc3fMGj//NREFCvhScfHIPpxECoOD4xmntm6Aa/cTMyd44w0BkuLzccZvy47tRFr51mfEEs/B6W/hdUQ3LQWufAYF6IlsYht4qhjvyJdTiP0IkbVCNJl++3g4PepN9K2mGmpFh+O4T7WOO7rU0zEf5LNebYp1R3P32dUK+3F7eD876BrFJ4tfjmyRuKBeFpgVyq0yD6EOzsuZlUWR18v7gK22D2brxq2vduBRHzA7Qhw0UbI04M0AfyFcoyI1rn2sm5IvtEXEYyiMt9Qq5sNp/X5Z6Nbqs2mNlWMMG8FnBmIzRR9SEuSox47+DJ3X3H/9fAAAA///IryL4" + return "eJzsvetzGzmWL/h9/gpsfdhyddhyV1V33Tu1M7Ohkey2tiWZbfrRsdERDDDzkEQpE0gDSFKsv34Dj0zmWxCFQ7nu3v7QURZJnB9eB+d9XpE72P9KVkJqxkH/GyGa6Qx+JW8Pf0lBJZIVmgn+K/mvfyOE1N8nNyItM/g3QlYMslT9aj81/3tFOM3hV8JB74S8O2Ncg1zRBM7M3+uvESK2IHeSafiVaFk2P9H7An41+HZCpo2/p7CiZaYXluSvZEUzBa2Pe3Cr/93SHIhYEb2BChipgZHdBiTYz7SkqxVLyIYqsgTgRCwVyC2kZ735SUUfMZm1FGURPpXuoh7IWtScZq3pjVMfoz9E4kAkV+vW36cpjG9Yb1c+bpgy3yNMkVJBSrQgCS106ddf0h3JQSm6Nv+mmiQiB2UmLcznnaEJuRZrcgmJSEEOT8SNxbqgjp1ONS5sgeuFmVrkgT1g5NX3S67smieCa+BamfvBuNKU6wqGGsSoWX4MwJTq7gd9dMxhMiQI1WS3YcmGUKJAKSY42TCtCCW3oL8wzUGpavfPekejnqzaiDJLCYctSLKE+twVVCogN6CpgUbJSoq8QerFtVir1zOa3IFWP/SGv2QSEp3tXxLtcVPyARyzcCecN2CeDS5kBlvIjljJTPDu/Wyt5CUUEhKqPZIUVoxDSgTPLCxNlxmQnBbDqHK1XkS7MBN7fOPv+dXlj2RLs9LfeJYC12zF/OmEe5pokom12y/Z2wg7O2aG96fFfs9sR0GlZkmZUWl/7zf2bPRk9IY+6qQMnYzeyOMnZXRLtqfdk5/+955M74mhirMhT7u+Yvnbwk6kuy3fDLotPYbpoUOToEQpE6S39+nLhnX/n4ZMaaohB66/RXC0TJleJBnt3OFvBB5wLfffIrCNkam+RWCMHwcMV2KqOMe3e9JSoMdwD9xlWwGkMXWoEblmSM9sfLEyCxg0PTmkJyQ8TYvoyCG90R/QIsZXsWNaOdEq8oZVZXD53HL1phlp+cjACj56+ZJTiNUlZ19LOIjRsp6//9O+rdReCJ6Yx4Fq8a1rtiPsZstw2WFzdS8MGbZiCW3e52uxJm+2wDWZW+ZMSp6CNCqIBM+oelNfsXtIiQJtBmn9uE1DjSss1Sb0xn6ywlJvQm/oR21K3xIY37503MHszesRa/K4NdgIhSSvNs/lO6F0k0Vm3ROpgKeMr6sP1dCxadiQ/jjry445YL0fjS7s1Wz7F0LTVBpeOXbdu4vbm70Wf9TF3f6Cvby//P93ec1q4fOGLl9whrSmtSwllKzZFnhtJPvjCgJmiY6zX+BqIOm3KPz9MTwaowYNUewXEr4i7HXTeWg32M57uber/MaRJjN7kV56a7am5OO+AJLQPgdZAgGmNyDJpyuuf/yFCEneZoLqn38iS6rsKaocZCu2LqUV/R6Y9zHi7h943tYNiqd8RrAvmF+vBZaZbUo7rij/4Q0MQu6oTNGEugZHa0y7uZJXs88teY8SCRntbikhaq805P4R9bDNaBtwJ1W5xTP/FpKtGadZ9Zu2tPLAOmDJXxOBEVezz78MLIGH31uJpy9Bjai/yjFen8NB7QuOx74+G6ApyJP4rt9ZUuTq8ileUoe36Sy1wxznK/2mjWxZskC3s9FK0Lo6CFr2ohjV5UJkGSRayD8iAzar9wwxN+bMMUUSt3SQGqQtQfVadMUWMrHQ36DGlyfLb0VUzYWywW654GS5720aIRK+lqC0GVCxvMj2fp/Mlw2jJ0CTDVEsBfLiz0RvZEl++utffyA7qogC4DWViZX4JoTXgJVQheAK8JYi+cOcikSUXNc2hTJfOqZnrrIaHIG8oEuxhcZiMD4YWVmxN6Ul0Hz0/iR/mGPzzEsFKSu7clqMhfpuSHKsDQtsRZj+V/nTn3/8d+VY+uvCMtAK9L96s/mX0Qev6R4k+Ym84QktVJk5z4pRKR/F14dGf6LzYyC2cojKzz+R/zTTfUl+/pn8J0mENPKynYUn+pL8n5n+v8wXmSLtRflucAu5SOGb1XX5DhYJzbIlTe5wJWAHjgttrw3VTq8wiwg8LQTj2qomGoYDnO3hWICUAik+7SAPqgISRjOL2CJVWkgjWfO9kzrMB1uasdQdjCFQhKxEyVPzwmRgwTO+9sLRg8GL7RvRGzmGL9Bfhwm30cgu7DNB02/lnfNwiGK/A8lBS5YMaB1eFW5+2erC7rmvmLB59qk+SLRiVW3bGXkndmZr+jon40RIo4xpQe4AigcW7Zt48f4giyZFAkottixdpFhe1zcV51kDB0m1veSpWcGGXrhlUpc0M0p7y/bOB0wcLGdG7ba+crsYbhb+ql9dEmm4tbIGFbtoVK5B1197cCWURAp6evaVcJFw0yshUVxBfcZ/dVnZXj9ALjSQuT/viQT70C73Y4zS/K9yxPwBHC+e0kIVGcOMbPim1XnFemL/NyGbGZ6LeN7trTNvgD/r1amrtBb/hPyv4WF07GXFsmfw0RuqRjmaXZzPvOybUG6Wh+WFkF2Jl9gn8g8XBlF+G+aPT+6psoq4Vd2HTKltVb48/OSgsDs5x2rmZ+Snv/5Cdnbdc6Cc0CwbthVYo74Vkw72I7IDCW5YqkkGVGkieCddpL2Izy4m/rEXceCuYrht/dp9ETK1C2ejmiDZcJGJ9b7riFsx2ZNiCfkrSTZU0kS7RTSXem/xW6M5JyX3MT1Zy2Y+mlEbO6HbOeoxnQgTvkurUeRGyBS8ciNIuhvlaZazdsRKmliJ1fkouLc5iCQpZTWi0pSnVKaEC5nTjP0+FN8rZD64PqmPcjh6iUS57D1Jj1qkA+oazOuMrcDOeEDBV5AIno4I2IftXiiNaWeZmBDjiciLDPTgARg1olIrwGvJOmywkW8m9TMd5LmhPXicx45y+2SOHr9ccL2JtE2H/NRYMS+HKKf0mRb+DU8xlt0M+bvg2NUWJtiioV6JmC689mN3hXssCu1GnxMN99pfPrIFqRrpFOlUHNjA/j71sO2BxprmIU0vETKFFO8d9EE2/plSNcVKxqgibeovNv3r/ddKivzMjlrapHyVAKeSCSfW52Wm2SvNQBJaFFmV/XKoZZNTTtdDqbmEZNa9U+mLDpTDqgjT3ysidtx5xjTNi65l0CM21AzE/u3TiiQbZrQbkYI6Izel0lZNag5qbiXVI3G5VMORmzTJwFYrg3sLp5CE7CZXBN3aSViBBJ64A0GNaJ2yLUuNZGPPwzAjm1eM7GNn8YYneV8webIZHvbT+YLuzUlkOtu7ySrD9Iy8ZkDZAzptG4246aMmnJeGG9f87KxHsg4nE2VsDpT3BLmnjlivf+yrYiXIryWUJztK5nS7U3TgjzuqiAWRjpwbC+7H2IsaUShoLSgCT1vnGuH1XecYWIsFAtRigSE9FzFZUXvQn6KPiiArNV6R51EhO+rj4BvTey4f9eYcyzYf4mvHOAsOD0SnGkJsQxBNekJ8DMFalRm222lEixKlTkQOrx2GWnmxUdli1TshlPslaCmQIwcEtiCZxkwdmZhYRd0nATY8O1MmH9zkxV7tQPdK15kuZjTrdyogYSt2UHyGpVvnzBmrqeJlZfxopoENqE2MLD0kTFQmqtQ7WQZxe7X5VJvwua2lNzVBIcn7uQ+NZaoKCOja1Sz9aofGsiRVIRSLyDiCzpZVp3nqKkzZUP7q7o5W4SkzvcArXfRIVsTLHCRLHsuLBud2giy2iYk1M9nqm+HYkrvfvaltgadC+oDZyZmJ5W/PUL2mcu2K5W+QDOvRBhh+LnhvuQ0HnQbmOD1mrbrv+hfSZ/17NuOtXBtaxxZzoQklG1/xYjiANhPrRRWo8ixMvTqIj2bqp6iZ0uJ9f7PhVrZqtWUfw4K/yFiyx749E3xhZgH44to824/w5TLDjJseXsAPZQYW2DA7FVzDPbbEWgO64s5ed6iHStNUmf+zjyrNKkBDBWAeeJyTDeVrWHDYYfOCMccl7BqufiuEaC3ZstTQ4BD9GH3loBtpvfn8DbMOVdBozK5euYyhla2cWjSrCHbjixyYpvw2oNzaDDCzYFXBQXWI+ZJbkGdkDm5TSgXyjK7BlvL2ke4rISsMvbGrYZzcntjfE/f7Rt0KIclSip35rPqrlzWd2jVaT/oqnVGpY5vp6oFjW1T8nRK97NBT3SmRpbXYiHWlRAHeoYj1Fp9zQjOQuo4ukgei/m/OveXZR6MIgA1CGhCYU8IFfyWhAKvJTEU/WLXhlE9OUkppLkytr9idtHLca+Y8bJX7pzezHdMbLyw7Xk8uLcGlzTbhRPBXa2H+e+IlsELKYkBwRJw3bTgDX1sABqRYEcMdNAN1RuYHntJtbNDMrMJBfOHS+UpllBiXMuqCbVLPfv3CU5JkpdLVgfT/6G2T/QlTZid9TrS3bxjB1346LgKdXPpxN2xYo3dlmfCEsu8fUrwMykuLglClRMKsvdTsxqA+aTfsmt3Br4SSYrNXLKEZSZm6e0kKaXuivCSgk++HBWUq6TG5l4986F2ejaQ5aJCKFFTZKl7KFnJwtQgSkeeGi4mW076fWgM6mRT33HvwXBJfYw8RHibHvhORF2X/DiJsGyU7xlOx8/G0ieAJFPplHUkxuhi9aa7KLNuTryXNnPEzFTll3HMN3iCUiZGnq2n1jCUuTUzdiITXjN9B6nOBqkB0qqx1yiso5pPvamhnLJ3auKxXFQKV1TU7OzmzRBdABe/9/LlwvS+85ZXM++V6aqczyJx1Gzthm1g9TYvWnf9pSfvnyJL2imX4d7ye8ltLrb7GEtIyAVJ5jmDY3KZAMpotBl5TtEdkbklWYnP3fWw8gOaFGbULQHKnjio5EMNi7Kmbh25D1aa+oUYsHMgyLJONi/ytcmzqNMOLaqROiTAzkZrMmZKJ+VX9736mKTH8nBNmY+5KnmRApfmTLYR3gOYTCL21U1aJnQ97HxzzK/t1nr7pFysR+ZLxum5288HyaaPyEa/XlslSndrS15RGLIBxi99pHKQDV+LCUXc1GcctpU6DQzeN18vnrMxXl+TWcZoXvnADcd32fNKvwfbDsFztDNDPYctvmJ+vLu2S+pS3mk30rQdtj5wLA3RTOHOHyPCCHVPDSupW7TFr2be9uj5B24kLk3Zs7pTvE54as/QXNWFydfmgJBvLPveAJGuA/cTTg0R7Ri5cfqavd5q5D6alWQtQtr/x43feHLcsdZ25KXT9GJU8A+VWRrgHZSfIlkpGl1kvC9AVZWCcFBkdYQQKuEKtj9La0Kao6iifGU5lJIwqv5CZfZ6/vpp1ZWjiS8Y6i8JYXvaRDQWDcyEPnhYHklxxTeZszallFiNHtBASs3jt9z3+ZQ7prJLdhK3qaP/TAGncZXvKUjFwcG7ffySMJ1mZgmFnvpGt+fkZefHmnuZFBr+SmTOIuGEt9z4btotYz9zJfZvWOHV4WoaRMXVnRO4jcD0iFa9hxrz1T8MHpu4mXK5asvUaJF4Lu+El+9z0BXgMVjrdSFAbkaXm9DhdfaTTaMv1fgLLQt/37rnyiw9OxvihLsZxdTmcRhLsnU9EXixOHHdld8XHXtk2rs6+p8rlKwNHcJufurLtZkRaJmNamhdLnylqrIm85pZC2soDhq9X+Ea6xFGZ7qh8ngi9flV9w12pf4jMJEZKI78wTJSSG5pU9ZSHhVvDgk6qxwj+qhJQ5TQXcrpm9KbWEqiKHhusNNVlLMG5tkdRlj2b2mGIL8U9Yenr8ffLvKzlKRAaRJ96hY/dXTAohq9u9Y4hd9/rHfLLft+9Y54zxkUZy8fZyCNR6+h3ynDSmEaHnkX2L5EHxq7M2DoS51lm+B5RZZKAUqsyI28MfZKIFJQ5ElWx32HNgvEU7iMvQMaUPk7yfCJvsYStKiYrEEuQ1r+ZU8kyG8EzYMFz/ne+JtQu4ivz28GZcYRzKJauuNAzScSeOnlRx3MWIFXhk24dh+ktmRcRDgHxVYWnH0aSDJ2Zq/8eYweUOOGrDvLytir3bfMhZVyRFDRl2YCRYSlK3fjdyNREdvLYzMpiS+s4Notj/CHVkBcZWjTPOUlhRb0LyFe+rHz4PlrTSMVbkBnd20QuLfzjSl4M3EjzgdW6/a9hVWWBO1u90kyXtjAjGZzYQTfoF2x66nWN6sVq2HcSGhspAq9KRJ6b+4RzjC7c6IQ1gn0LKbYsdfazqopcDmo0ECoVyfGOxsdby96y7CA1Js24vGHR4L6wQU/Pw+sr6ri8/jexPNLudPT0/h+x9A6Y4dtVMLzCuZc2oNjt/Hx2Ra56AlUTBlrVWp9dMo0gYmJXnQ27jqpIP8Ye5mOrh4V7xyIWS5FiZ3z1Mu66QofHQgyWEfFoE79agnMZnCDzvGEC9qnDLoC29oewNUtrV86IES+PrTX20sAjvPzxhLx63kWJ+UxV3b1nn1z1nMoRZYM17iEpm1YEF/q1hKH01qoK01TgxgkMIYNW8bRtEKmzK+mWsoz2HRmkNoUTm1+5AilHOi24O3SMrT+e380rK7kvAOUcsL0p+XADxdZnIxyR5Ytlmab76PYZli+i5gE1xi0VHFfofNJKFX9EyUTEKgedFLuFKk+RkMBUM3rV1VylZcp0nVl3qIvmEQ01tjtkbDhWcnAvTE/SRYnFXsHtybTyi89vyAufK/G5zIysvGSZTeCwcWBv7guhzDd/IK/6hgbe9cLccbHjLUVIQVLaYhbb9ugjnTYTegITXDcs9KLKcr/1qUnXsKbJnnwaVdcytpT0OZLyPeHWEjNOcsr4StIcJsMxCipt1178Ogkt4XJmyZJbkbrg6ENZwEbU2QAo8oD0ZUMFzEJgaUjtunG3sCPvSm5VyRuRQkZeML49+9NLwkTykizN/4H5P8pptldMnf1p2L+ok2Kxymivc35sGaot4V/MiCVqbV2WT+6r5ldiNVmoQQtUpO6vS4+zKoOgQJqDPAhom8flux1kn2++UAnkowsA/tOfPt98Of/w5k9/cjG3WyopGz2TOyHvYqYsP3jBvlQEmx62USMY5bGFCJ+zE7dKSf0c0MQ8F3sEFWYlJHDFkpgMpGFKQkCcx7eCDPgHYg262FHWb078ZOuArX0ee1BzfWKnqKtyiXQp9DJVWsbOfLf52mgGseZbGu0drXI+8Iykxya7HBqD9UQan2xyyHvx+S5miBUbNTRVU0UzxB471cFqRAPT7Kb3DDPlo+sJPt5wYcB7+f9Dn+pBZHad/57liKUNG70HMgnyWQ5H5cedwifECYK2Wjvb0Etf6DqivYqys3Uyf7Bmt97JfdgzXZWsZqfwh9mkrxVlmVnrqpjLzPOMq8tmbputxGXUQQ3rgRIG41GFVcz1woiIR8znmMBrG27ts48uRJ6XvGuJ6qHjxxVueiq6W7jXf4NhmbrGpo6TrJ+KbU55+t9i2Gt2wKapZsdwhiej6xNugVOlKljCRLQo0VNp8Bb9jkredzp869AVz4uFwGLG89ubGXnv7KiHoNRhIF9PGkow/8c1+VqCHKndWmZ8IaFbqRM3uKFhEN2TD1XS2WBYVy2lJxEf0uagInYbATNocZTh6KFR9YBz7MnjpvEbNNCMyhxht8ywCOYFWkRMQK4HLdNoXWlbY8atdtUaOqW6KxU+ddwl8GSTUxkrraQed1/QXvviJ3ufaNILp4oy5mIT/SwksIqbQFUPvFrbUksIw4rlbwijFjR6JwxXcSr68bJO9wWL/eD4ym05GNEzOmi+oIltjBI//cSMrXhE5b0x8HJdbP/C7/Um+vue8EWi5SJVUeuuN0Y3Ix/neQoYeJvR6ByDL4CvGY+YFNkfGiM2mi9WC7VjOonOP/hilYmdonn82JXm2Fxv8UZH8LokfME4JjthvACZL/fRAt57YxfJHc7gW5phnBVWLAoptFjEd0nZ0bd/WViLY/yxM7S7mYn1IsVYbDNw/Pi3hC9yer/QOpbZoD2wOdEZIDwKOeNIoBnHA11kapEts0Vst2hr7D8jDh69Mnhj7Ni1EJtjx87qbY79V8Sxf0Ec+38gjv0/Ecf+d5yxtSgyugQMllKPHl8944u8zKzwvdwjvJPV4MUdglySlxlb5wWO9G2kTJqtYwch+ZEZhlCi4GsS3zbCF8oFJCLsoJIJjjZpBsbRJtVelQVCL9KE12nVKKqqFtqoHnCPwEK00EYxwxrbqjUog5ec3XPKhYIE4RBufzGrgvQobH8Rhd4ATRHMaiIvFkmGYMM2AyM4Sey4crnX8c2iZmSFMnJRLhB8GolkmiU0Q0ggUgu6Bp7sI0ZdNcfmNNv/DukSA/d2YcuAoozsysHgoHaBtSijL9fF9hccG7RaLJn+d5RCY4laxO0V1xlYiuisWqFcczsqJDJ+lptyNv5ovbYaA4PeODt/fOOIG9yKfSiDu2ry8SrINcZesQwwdBi1WGFsIlvFTM5uD4whG6gFK2yQ4gKF1bFi+5dU6aJXzD/S2EomKGNnbAUYaoyyhuYcUhYtYbQ9NuM4pyQXaZmBSgTGavvB2RqBN4lC7aiO2vO/MfpQBHmUgSWsmdKSxreEHMZGkPgkFFhLLdHWWtlK5BKJv7rIfHfEEUbXEmiOIEi6VCAs2HjC9W4jmFq4DrPxR99TSVEOeDqSCBtj5K3rbx97XKY05dH7HKdKL0sZq1lgNSq4XkEYo5bRscaXo6uc5NjD2s4Nq/jNro+tNDA15pqmaew7wNLYbtWqdBDCW8TyRSKFyFGqEpmBEdQ0li9wgiN9xSOMZS7uopdnKlT8kqWsUIVkkQfNqGa6jB59ljEO8UrsHEZVUTvq1OPa5Nv4Zq1MuKqni1Umoj/n9eAIIf9G543OdcygCBzH6NAIUKPHJmRijXJ0+RrlAhdCxmZg+bJcY1yznKkEgy3kCuXAYvSB4KBtcaXo40bn4a4AdOyIPzdq7HA8vtvF1kBQMsqEawAdXRMV8SUjIdl6MdCP68nj7jjI+G9WsXBNeaMPG7Uz9WFY1+IV5ZAhJG76njixmYEfNjY3KBbOkBQdLlXKfLhINrHy/HtDw33BojsCCpD5WlKuezV3Y4y8Qxk4/tPrKpF9+tTpAhphYCnWC6qKiA0DmkNLGntUCTTDkO8kJHYdXNVRpMHjL7IZOW4J18bIQqYIiOMbMhWCbVg52zBCPICC2IEAruExgnKi4Gv8AzBUoDXaqAiqlGJrBMarithWNiUTjHsgkzS6IK1kMlQVN8LAOl6LreaYpYpeVXOb8NiJEoPdYp86qCvSGXv6eq3jHys3aHyPXt3TM/a4+yJ6tdYyXaLEoZcyQ3gLSwVykbLYWe8obSsqzxDGMuhEaZrHtgZvF4wrTVcIksGWSY0hhm8LjlC6SQtZ8phm1qGyaAMVRc9LLciHkpMe6Tp6BLFZ3measZRcSEiZJhdUpr6aobLl34fhuM5ZiKs01iHUDmOb6BNb3yARGRlK1anjIRjHW7k3eZGJPfQaCz64fitRRivqHXjGzBo6m5HtdyZhDfckp91CCwdfLF+X3WYg6CAzpmxzhoq633pbQImosiiE1KRfeJSQ3YZqwjQpJKzGjsITwnIf04RiaOG91lFDIIz7yu4jdaEzxrE78jegGmpNnIposQa9AXl2+L7aiLL3ohHCYQuybkekBSmoVEBuQFPbEdzdVVovwYtrsVavZy7t9Qdy6Vt8vSR6M9ClyBYD/gC+9bGFzckt6C9Mc1DD+9w/1CiLt7Itu+tbZIm7ySqgMtmcMc4G8dmeuyeor91hn7YXhg2GeJ3Rkttev+vS9nGtirgPF3Dv1GufmBN+Oe56TnURbt+/eETZNxuxiJjTFFZ51ZIlH+Fe21sxZi44RTfqEYZ0aFx3aztU82yk46WtnovYDtzWz1WgiYSvJSg9UbT7+Gjlx9fKdyKDbcvjqDqO3bVI1XGnbXPKFCaHyPrGWn+3FdrVr4Mzj9n7/+H+hobY1WXFFCzt4bNhtYZ4QbyPPMLmcVlSBcSFa9doSO9W1bvkf/E8eHndCr5GLqQrXz+4jIRQRRSAbXdGp/tVScoVTU7Q3rdXYdqR5lbsPRyapJS2A9oU6AJkzpy4cSrQB5KuMQfbsgzWQDLYQkaoUmzN3cYd+vUPH31bkvkZ+belP3HSl8/S6dkgKzn7WkK3TSIdvnwNvMdVTDyuC0ol0bDUXchEcA42toLsmN6MMQpCBjJDaoldwlHpRY9WLcxyWn5SP1GZWLOEZsQgGFF9LIrnRWdJjbRpfL61KzZ7NQyvEc62E52o1tgPPM0YVYuNQNcJnBJXq2u2l8qhqZHhis0WPMP1AIi7NAatfdN8I5YkAyrPzjMljCLeum+X1llO3vlfnJFzvq//1RtdW11ecU1oepaIvCg1yGE2jGLGNxPDU8++6+6F7bHY2hCm/1X+9Ocf/93ovpeN7ahW7LtB2P6cLuJ6zEINN3QPkvyP2ianXnsYFtzwrY+d/4N/5vkBc+vUT+7HkcHLD/G277sNUwydM3L7/uMbM3eQ4Iwn1l6aMpVIKChP9kaq9OJZ1o0FIXaFXpKPN7+SK65//uklubq9fPPPX8mnK65/+Qt5sdvsCQemNyBJshHKt0oTUkKi7bd+/OX//j9++H5wRUBvEHlcdz0sTz3L6XA7HoV8+h55zefuLF5VoIavePptgW7ypgeQH1kwLviBH8LbEUwP2slnJnVJM3J9fjsI9nfBAc+WddzJ+H8Fh7PhtTVw/zAs1E7kYeZpt+BbfIMn9mFNNezoM7RIt6d7Rs7TVFo7rTvlQ3DqpzfJi2P9nE/1hVxd3MzcqzTqHsupOqH3o2VUcpKqf7vJ1cxAGbF+mTU8shNElDU0tMfXsJLEFq671mkZRAMuTVNmvkyzg8O20ct/+J074QEwKqG94MLf8Mv2EehBOcRao8h1oU8aJbce4UxIXbPkHtNNrYPNbgDT+4c5rzrx2rv5ML6uHpNqWjdjC89hSG88lRXXo7OaL1VKJMyInM5u1JNxiOHLkvI1nNWqUyL4iq1LCSlZ7u2YwFMbNTTMZ4ojSw/0kkZHpOVBoiuEegdZRNm/mcIV3QAgIRcaFj6yO36cUfylTbla0IULxUcYutASZ/AVwpFYIWQLZxjXAav+SYGwqDRdVJY4PLG8q8GbeZx1qTWNCc8gwb7RG5AcNPm4L+Al+VQ9Y9fWAPYzmVUGsN5L8H5MUqta9ZxAmBhRjSvQ3i7+ktAsGxQmisMXbYAblTYwbwvSvIGMa0GUto854+TT1ShDSWyALBq/is6yzaCiQGj7ZgaWoGJH9JphEVJc3IsYOxTd2tsR0LrWCosM+Dp6p0iL2QgfiFLoiATqRB6aNRwwnCQ2nGBFKHkr5I7KtN+nm5DztQ32koSaG39vY+mWoHcAfFj0jFw18bE+bqFp1nTVOTDEloy3kRG9GTLu41xtWELOtGFLvsXG8BS3GeWn8OMHGCirAJGGibI3wbbJ8uBJ2RoNdm0V2PbLE9tTCYmtQrCNVw8uzGNPpWZJmVFJbL1oUoF48eb+12uxFqvVcPd3SBZ6A+jb2wL70RB0t7GB+43BbeCel3oDXPtg8VHYqoxZOSEsoMeRHIf+SYEcBSxKnYjTrrQnOQ54XiYJKDWC2VYeP6442nGBJxYXMSLuWsg9GUhM6GE7BXNqYYQORsOVrINPFYKbd8XwrSHhsP4h6QlK7Vlt49WjG3k3KXFVS23OQMYgrefj7TAdeZhxopguB/gnsckF4Fm0H3VDFaGpKMzrojfAJBE7ftgyt3Ca3gsu8pG4WtuTQzFXov60QoQR7hlPDf8RUtULQMlblgE598DOessQYuzl9cTcnRwNGK/n/yzhCqNLMPdRC3FXYWiOAwsRM9/9CQvh4vXmPl8j9kqMB4QuBWb2wMDkl7ChWyZKK10mIi+kyNlIhCKcGtwbTpeZTSJbkYtpbIxva7aDCLKLsCV1kkEALYRRm8scAXCAfo0Pe3cbr+zhvo0eu0OaZcl1N50ttkSf2jTwRXKMWh8kBdn3eA0cJEuqKdkFsYF+3dACpjf2qR3q7UY82LPkxzOl5bjzs5rTMWW3nm1OP03PyYsXjhbivAZV01oJ1ywHZfi6k/YkFDDqRPK7EK0oxIMbYQsPPnEbZODROqZ297MdrZ/D5vTjQkVrcho8NW8wfmiGvbnZGR8YQgAz+OPO7qcHZydPunfuokWZm3x456LVUj0NA3mAj9cM5I97HH9+eMtitTY4zZaF8Ud5Ug4S844F8I+THseYc+sdxlqotyloHTt19MydUm8WOeiNeAYvCW1ZkomD4b82uuG2lpIUqFanCa/OB5F5e60BMnEukSwh/zz765//TF5cX57PfiCXTGnG1yVTG0htKvwglkysBXpdoClPmI2WXTkcfpvtF0cixqRAtipO5X+aXR1CUN8Ya5GP1vT5MdclsWH/dd5vw/BnMQ35TCkfKpN+iBSjWazqdJ2JfKApK5WjQIQkiuUso9KxJ8M2zR1K7Ls+nF5l77li6SkrjTQj5T+Zg1BZETt1MQ+XHC/P4pxP3XXr1vCZhg37rzcS2U96Z8EbbqCRlpEOmzKFxAwM6Lls7FILuaac/T4RVc3xjkLoYh+x0s0zNbLcKyYHc0mRqv68NeTsa+FKfLnaRa2o5ndAM71JqARSSEhFzjgdTLhrsKcZ1Qy4Vg+Gx2f0lLO9ps86WVf6EQqkg2uuzveGcRVUalsM6TDVabZ6wmJHntmEcNQVpCCphnQRLahs4nwY5vO2olg7z2ZSbFlaFw/z36NFkXlJtXcwfPEf86y1ZdphAecwSZaeaJY1SV/rT+9HpjnYPNRGTm6Z855vuoL7SAm4WuiM2RT8sZIn3FuZqfGjRib0emCiTka1EitVRGkhHcc3o+WgqaX2vf3WmfnW98Ozz1maZnA6Lndj6YXyuYHtbfC9o/hc1R7jNNOdeWqNCkN8X3lnX5Iio2bLzPssJAGeyH0xZuW3oZAn0CcDIuhkrVu+E0qTG5psGB9R6VKKxDm+6671J24j/QsJhn0Y+cgVOVNn5DqlBfls/+Hko1Rwl3f6r/7jSTZ0C0ZyyoBK8rUEuSe2BqEqBFdQSVTDyalmvgv7m9PwS18DLzEjS1ZVgeRu+q4u3zjOakongHo4QB98cdRQpLbLE67BrHvGq9LSrSJGRjf0Dy9TRJacD+qx6mX98jjPsysjNZJj50dceA0TfyMo2TGeip0iqoCErVhiPnk5lCfo42T7F8RMz+E9xNyQF7YiLPDk8AxZ1+UPjdUiJbfv+DWsabInn1S78G3tgc27ibTRo2sNhRMo7COvfVPVslBsrpo9ZOZF7K14XQdgIPu/lWlq03n6y9eeNr5APVad14nXAzO2Mxw8aP43R0z2NHG9Y1P1Eb7e9F7xujd26uNVQPuzOY3BrnYYtPfmEJDptqG3Q8MFKR5OfrZpAzFbAo5muNkpp7Bi3NvqLXOyVf1yWowUHbTojkoUQ8J2MMB0xL/YjLG22WLP3ddSGqlNWduwtabJJj9xCfwDVbvgpKcdNbcDpcnLkvF4HcSi3g0zZZtUiPt4DjCpZtqO3RZXRvuQ3j/QtbOHGvftewB1QWV1psyfXx6mstuwXil1Ym6H0WVd8HvQ9HT0niWurIWQe7wN/w9VUP5fD1aMqYC0q6hX4vnQ02SW5T9e29EfmNuziUS9WVX11qdnNXoKFsC1FMUxrCMV5bJnXAg6456m0bbhgXQEi9Fld5z2Hl6IvKB8X99He+1sO32nr2xBmmdowfhKDAsFVN1h5wg9wD86WmSFbAe4VdFXX7FiBN6WWbYn/yhpxlYMUnJp856dcXAQyg6Wi0SIO/ZMTvcvsCSO/kF/ptmYNB+92uzBHV6U2orcR7Ywffiuf6hJ+C473hztbPJn5OO+cFM/WA7M4rgdHN88CatF1GKyHdgGgzNEyO/VUNnaLphTmOpq4bKNzlkWCyEra791MX+4HtnyRq2cyMepWosCtw/RxFIYyg9a7iuYUggkSaQNytAx+0EKqodNkwlfUBXT298YWPp0+sgjlzKLuM2NUSPuSq2MLkoZyxrSGFOBXNB1PJ3yMHT056k9dNTwx/bQ/tQjMBa418CtaBVfOTHjRzvNtaC3kdAJlYktUTkSp8glbPHcj5asFa9e+/++8BBe+//wcU1DZn+agRyOzvPTeUbvuZtM03luLa6NVmu96aS+IZpRqRhfgZQjftf+vE8yr6bg/+DSD5pnTwCyqku8amzDwJWybm2BeqUGSJzs+L1xfntz7D7aCGLZ/NPfoR+gNd7wkxUbkKexRxiZ3Uc8vbiwrR9/IBeW/jA0kPpExVJG1vkCpG/+Ca0ozInivIDqOm4sZGPDDdHvVaNS9OROs9+PtUo+vjTK8G6TOft92FrD7pB4ytXf3xAOa6GZ28BiQ9VIByiVnLqsUGMrHfHx5oJmq9E6QPUCXDpnrCqcXuXfDAekKLY+RUZFu75R3fXw42ijZcNNmFJldKHTjmyDpfCsdU/zoViEICWqDbS3KU3u+cYQJ3PrnJ7iTieJkKgrg3sv8ou5De2cfowa3PM4kI/nnhMYx1moUtlii/mid12q3pA9CCZdmKNHy+hlGhXWwOwOvEaNVNzgu0O7kuaDZHnrX4iy/johydX8/O83MzIz7xR5z0e6rxzQImVSH4P2404Mo7VsKNlAcqeOMiKHMWHcGmRDTefqep11iTAbBupbEB644ISUC5L1ikI+g5DrcNRVQUaVBotZU12erMNnE+WWZix1B3EARJcRnqyq9RQjtCt2B3vVZduRTn4VQBp57I3WhVow24MWZWi7lRgLktBv4DaxNa8yX4Rkev/AjUpEnqPWiQvE7XB4g9BwCv6OSci6mmZsE8suo3yh1HM1vDWUHQ//4mdb5WgNonWpxotCsFOEVQ8BdgiIRWBBDWsDdlmTDeW8VzgDu9yUp2qBjPhsT1S2uX5YfM/DL9fnt/7de90hXz8oWsiu7T96zTam7hZbkZVYC3Be9XHmvs9N3Rm7audbcqYVeeFAqB9stQ6b2Ft11O0MTyzowdlkJRI3u/ZYP3GmfbjAWTvpYAvSRgqsyowkgidQaKMoz90ejpRX2O0wua9beKOwVy20DdBCSE2EWd93/30+FII7uOyxz52Q69MHWHYTDFom1iV1xU4GC8X87c372dWM3ND7nPG0bus9vK1mbicPw2w1URyZlp9Gb3ZT06rFp+GUxejh2S7LcbE6XcLmcyfhV1NGFztaxjLPla8ufZVej2ISYXa6TXnmWgHVjPP/5fOG68QcnvYlydi329pLjAr9TNGNvl211eJrp27ukntfElUOhKhTRf5DaSn4+r+WGU3uMqY0pP/x2v/tZf0p4ytIhj9aMQk7mg0KMnSZNX5DKE+JEmTkWEpYM6Xl3mj2p2QWBdUbX6y/xkC6GHogrVHqVDBdIrTL10qEbFQhr+XJGjlw3YhJqaOAhdSMQ/MGDJ/xFpJ24P1be/hdbEY1Hnlr/uP9vPHFyWBklsHZhqrNWSKTn7tm1uAV+q/eYbv4cPHzT+QdVZsqPLz+ygiQwVM7du8JMTorVfArWYLuWkNSWNEy0ws781/Jima9pOwH4N+ItMzAssGCSsX42i2sWWG1V5lYdwvLD60yaSvQjhv1vjG9zgFgzf/OXQaxbUhq+c2LD+eXV5/mPwwvexvZnWa9hycWrozKnJwnd1zsMkjXQD42aU2AQluo1ps0BWAozikKhrm169Y5Kh2zyySkgQ5GkUC9O68JkBxUK5l8HFK/weQBTq+VayCSgVCPSQBDDnkS6bT41N2W430SzFoOzToilL+1mOEEliGuGQvLpYPRrj05gSXvRdnHQmKGtiWmAmD0QlsPIMbqAgWBMCzNNuOBRPBUkVe23rytjQMpUYwnYKuftbu/TeHsGVlJnOWytbjs+OQVgfWZ++///O5G/M6yjL7+69mfvwsAaJh6T4MkcRbTvRiNOmETMPqhpCTWs9UcehwBp9les0QNOX0jQfloLcvOrdxK2FXl0rcKtEp1BeURqN0IeLBXGV23wTnQoe8dFvdynoRZSwOdQFG8+mYemKJAE4w+WlEkKa0rz0k/vtBGUdhSFFJkQQjRGMOhEl8YezDf71l9SaR9a4C5cIvTKx88hUx2vQooyD4wdUeuYQtBO6cSivRKf+z0CT2fvXRJ+sTQ5JBaU0QK2ho1fFG0dWm+GAQcS7h4JKMYDBpBwNINDJmAhMi5moB0GPvyDrnoGsN55el7lOpgfzRI8jnQjNVmIQjvsa9LZElCi+Y0PiyWZccOVSbsl4fbskXCY9ZKS7ZegyQF1RokV5ZDOfNkcgc6pZq6Vg9LquCXvxDgiWi1rw6bwMRjGWNJ6xJSKXntOlOH4kN7xR2woAe8TNnUAg3EaoSCMCOHY1CJGHCCRDtqDs28RWQa0KS97vhlseeeNRLlDK0QSHqDZ/Zw4WXewRxq/Cj1Bu1mtbuXhB0ivSmk6CXURUL00ZXV1CIRmW8OwJlmtBKl2mWbw+CO1IPGWMEOqVFYS8rTHUt7QfGRUP13b/gpJBzShSx7RT8iYbk9vyBfSyop14yDgWbEiQ+ld9kGI+wHhqAC9AlxVwFC+5LyEepxttLAaQ0wjkRoDnqwEkgsOJZCsxxPKCoE4dSDeYxouhyIUiWRPCG+3O0cwp7jhGZZP3YlEpgLmmUgA3FIyUAuAOnVMyzde3LJhaNFgKevXPRrFWIXytD7SSMkjjB3eTs/pIWErdtgjQaC8rD0iI3DQmKTFxe+Rm3wXUtSaWV2LDXwoj/+OBbgWtKM0ykh/Enn58JRILfnH8OOD5rB/2IgkWkSBqJNuJmtEGZYMYA2VCFJRk08LSrjeFZrqnt9GWPBEXzF1qV0l9zQYcsyaNtWa7H87RSgOr3XphD1qmEhQWrRmQKEZpJo47FVob2bIejqr9b6vhC7CaXkaayohe7jP0mb1jiuwVSTSKDq1JyLDpWH4OAxp/n8XZ3oEsicNlQpNiVCPm3j3PBhh2g4PZfgeWor/0aYYyjZrDdAU5BIToR3Hz/OyLsOhXE0WSqWvyGyA26L9XpuGbaBttTKYjLs6EmovrAV81Squv0hqESZYgaMXRgCwaFrFk6psMw3DkxYyE0isjIfX5QnXfzP769m5KJNYAJInlOOdZSvr8hFh8AkkpKjhfHNb29mFkybxgQc8+7Z4FEstaz9tHZJTSEzDIIN9zCOhM0q2a6AU8WRqsJjQQit8RIJWuWtq8iQXKSBqLSk/UTdSLi+nL+1+e0Hm7MEpSWzKxfCLZ3+mTJFZT7hDH4SSKd2V69vuMrrvoio2zkCrrKdDa+xb7J79UPw2WrZONg+z27JRbve6gSQfn8tEksSL7lWrlG0UxUCL2PJNS0mLKZPAXWo2n1eFORCy4xkYq0IVUokztVSNf4PD+h2kLfoiD/Hwpqw1fjZi4T24urtPBbeNEM/DpfXs2hoOfriXt5GW9uh5lrR8bpAlUiIV/0qvJHhrlaxsLIC/SxczaKdBTVheoyEdj5/Fw8t+rmdz69jod1R9GNrJLpYaDvdUzDQwpKsWKZBxgBdlEhSzOxTpyPnOAb5gO3gaUCcctPoQBJsR5BMs4RmiLLeYVcrYsSoiXwdokf0uhmQWAaO7ooFhlAnMmt98VtBNR2/9qQNnIscmt8LgLMFNJPi5zdBVsSUQr8UWSQMl3ZswoOiPFKqqaR8Ii/tiVg0JXZ8a0eQUAipA25W2q+ZEA9RyLKkXD0QgHZs+MulkYBDI87SfgsGEmkdHnNjXF4EE3ywY0k0RJ4I6VCZgLXFDee4BBsbFB7GkcKWcT1UzScSonfnlkYC5IprkCuahAbkpbDFMyr5hQqzk6SbpFjkaihEOAaUdxczchOaPp6a7UK7YXXpLVZtVggitLwspYTycmqLyiSWTKzlFDc+Ptj7kqk7I0CvGV8TGcaXswLuteyW2yCRdux6Ruzwg8WDxkGJZKSddjRUK8bXIAvJuDbkStvLuEN0Al9OGU+0zGxc9UA9IhJJ0L96O/fUbAg3adMKBDjJpeLiC+RXNTzMGN0euA6xAHgIwboWlY8bDomqPoDBewObmAKl3BpV5TFCPmQe3cGBWLuqHgN2pOo0ib+MPUoPoHPWD5be46yhR+VtLEEKVQMWXs51G1fggiH5yi5tvzNztKzNKWXKhSHahJZ2D/sJbHqB5qU9Vv4xv9IrKbBSWwZxkRa9KXCogQpNbMFhCqnSJ9CEDsDSR2tFFiCm9tEDF/iyK72iORuoohkd1/s56ZCaQrXZDfZUR8D17gvpkHoIV78LAx4wGWZDtzwDtNriGUsGWIZyqUNB8ITCe8g7xyz0WdJCnWwz388ftZkPmd6eJFs0YAWb4ZTGy0BrAprPg4QdpdXpLqISK72jst+AZQpfyY0OY8RKVNW4AdNR9MlXkIZrx0qXJdbefvp0aPDUBHs1C4/tTdHQWVPZp5ATB7QQWYLlg3tzPnt/7ctadOK6phHhiRQtSGHCBLhujjhL9GUDto/Gof4HYaoiCSkRknARsmx1y0mkdTu0tAy14kMhBgpRxzlYZuhDPfFMJNa1G5gLAaoY6IBHIi3UfNbJFg0CZJOWVkIiJZAYVB97JMYB3U/s3JOA3FCWkTf3yYbyNfgK05e3cyJBFYIrIJSrHUiiIDCUAPxYfxi4ha1EpqrOq0j77cnYcKE+rSl4DEvVtAHxfyupTG35dMlS8PRsaRilaR5QgGVFc7UoaNmru03isJa6GPc5p9leMVee6YZyurb1rOrCArMWhgm8v+N5WixYC/R3kOTau1w+BBnnV4mGXGEVuGtmP7zxPRnIfH4bhAtNMGqiCpKPbO11HCy3H2e+2l6HygSYDJyJEgfRR1f/VYOsu074ehB7V+1n5VpDBD6z5lsbqjZopWLeegLBKoGb3FTNiggOPbt+4TY0bIv7AVPYeTdfRTRpXM+ILDMINGY4OIgGxsPqhOkCthnG2rxhRgLAAXXONVMFza3Q1m4+MoVrR2UK6QrLtujSnrxye6AXAO1rivXG/OMy5D2RNAe8I1Qn0vfpTEACSJm6G+qM2AT2NEFGAthAj94wE7gEkv7x1gjO0DxCYWgW2yQr1dSL98QYU1tWbMukLmlGPC3fzzIAoaJbkCnDKpz9dn5OugTGweyc1XOoC2gkPF9gSQop7vfewBrIxddUw46OaxXHxjD8zY1LWNHkS2Q2m4k3lWjlIlMDMMpmA4UuwqfpkJALuQ+urGyba2CVtLBdGlyDjRBxYENfFZKNF5d8EpZ352QmmW3wHIJkgdh15N15aP3PDV3gebDfnZMPQe7qDeWp2tA7tEos1+Rdj8QEGqz6ULbLlxWBiFiRVOx4JmgarIFslilfSKAKyyr6DqjUS6DaYiMdUuO42HqDmPryrhqerOhSsoSoMs9piDKyEVgRNu+E0mGvBaOYbpHtL4QFCK0syYukWRMhLpCGx2hm+xg7T9LVxc0svEOWwYhWPdMJRsWTwOEJ3bac9L6wXOGRuKoe0kgS5S3onZB3REu6WrFkiN44Nr5QBcNZsavZ/M0FYXwpSp6S+ewqBE5i0SuQjGYcSQq48lSIIxMse1d9SrFQeVPXzc08HIt5labz9J5sy6lIuUZNWVieXiPqHdNrf3UgE2ySYxyrTVR14pltahLEG1xtcywLynvJ1oxTW3TAh+Zawq57d21Yqp0jIYC70ZdRAX+AzEZcPCLIEy/r5igwW5qxNKdI9mfzCt2cX9TKp43X9UTJ+08hLDZ+YH+1TiFB/QzxiT7gCDStjlOLgObv7seHkAEFVCYBZUvvGFZpN1tkrjX8KIiM8onslOPdh9fnt+aVFznj64PEwslyryHAUpFRLspx7v00XKLUTlY5AhdQLO+wjaxqjz8OgyXAFSwyhtYK8Ybes7zMG8UOGh5OZw0zovu1QxICeQrq02oqehurT7X4AE5CINctkhPIOBKjsvewNfwEiImKfDH7vAZAEQmdEDOPfDyuzaiGZdvWmmQ2m102aheGoEJK/r0W63Adz8pXODh8raCQ9L1M7BBtPG+dZadHZBQOmhRkWWJOk3DHTk4zoygsUtrrr08iMRtzpz0ZSEmL0MOw0GozDMB6XIWTnPISSb6+MUPTRJcy2K+TU6VBpkqjna0bS6F5ujxn2gilnbydl5lmRQaEe8tLrSAEnUQzvpIJqo7gqLRUhcYsbFutDVVPnAmkrMzxGY6jExrMnQOSP9n71ErzIPisSOtgYyqsUXUOapOj2XfrmABDJrC2rn/dEAsSO+7jyATqZJhlYWx12tBY8nyda7Q0BdtDuJagXb6JkOx3SKt67atM2BachgHbOFDtwj1CThraKXMGrsDTJVK0lnKzi6tXl/N5l8YEFs60kK/w4hTeAc30htw4QoF1dCpYeBewAyusEnheYJWNqbnUzWz+9wAgao3YadIX9iGzqvL3baAfINdIZRZv6L1LmciZrfhIPnGmyeeweDy8sx12mDlWjKvtp/WIDn8cMLv++DYft6BDolk47BaYjdRvYVeFHQlv3+/kpkxCa4d6RkfWMcAEniPYobYhMsB8B6LgG+8wYTb+8aiCm/9w2KlMYBUyhR2ZZ0I/Yn3utTmGSMKSs1RpkFuaNUxWtbHRkG/I4mcBgFeIUu+tOPSzDHxyuWBY9mPbBOi2Nf4oDJGlqOyq9kfOAyMTDSBEJlXj6XCqMGOEyFJUTlWj61J5ABEmn6oxVcwqlEWILMVjWIdz9RiuZSAhGW3fZymZPy66RGTprpACydZmAH2BJXnrUk9mUoTFMwq+Y1gZo+dkldG1zfniqevIyVzg1/mMMOVpB+ejiwIkakWl9wW4et6uq0tIdKPBhNrp8YApvMsjZgGZA565M5EFslLc+jE9VMH1R0Sp8SLk3pc6LC5OlBovzMWgeESIS0GVghTf7OvohJp9zbd3WFqf1ahSp15ZQkKmj6vritcYd0b1hogVyYQoXHOwRns6F3aSlJLpvY/MDsAKWNm+X85viSg0y9nvvo8vhPAr860FN0I1DqzPs1tLg3DxmEb0xYYq+Akx98niskQCuWixEaghC7PW+OMwsITPmRQJqDAFuRAZS/Z4St7Mjh+o3hVCIBaxNTsjRBZ6SMRE2/knbc+1WJOyyARNCUgpJAnLgzPfWsJU/MTT4qr96tjEAu9z0YK0KU6Cg4l4PAxoEBKgV0ixBETr+DXjd7XfYGaI1YbyIHBJ01YbFdmnD9eVGtOl8xAgzSbuYBTWZCg8rj9J0VHFurCexqXc4IGmVw9lscWKPz3GHuxBIaZiVovkklQfhQrxffGgwh6Yr4bidio870khqLdz8rUEpasGpqE1Ir6WVKq7iZDzJy3RP0oqKdeMAzFECNwXGeWB0tvXUmgK9wlAitW292rlqNhQmyUAJz160/ByOl6i5fhQ5yqC12GjWSZ2kJJXTcM6W1lG9mpJVfWRDYS2H7jgaPdZ4ETwrsk/7CTCQksslFJNbPfxi+pwlOqIlbQf/fAwfElTJpZofd8/mOHJMqjtu4WCJeU7ICEyvoeRZELBRBZxFDTEsD5nmvT07D+lWJfmj8FgXf8rrCTCAbS7DUs2pCL7aNBYzdPqUBAHxhAKfVUk3U3G8T7xGuxclOzjwGBFHNRwgu5Dsk1TyNCWBhJgW0g9B2tTGgeFWAzhPAOpg2sgSI8f5+rNXX2aO9jXBUL7FB/EhlykcwrkY4p2SiyZyUfZNoyr5smUYUu4AilpVmK1Um306h2iNQEsF1N9so5OuzTDktls9qga4A7NTheTyvATGYVFZiMPzItUKkJb9YlJi/YEVKNDYyaMWstLmPQo4SsmEqtfhUMx38Y0Pb+/mlVkAu2KElSZIYUA1pbwLpVxNGgVkwyWmcXyU2CnH6nUuAPxaeJei3VnRGkJfG1Twq1DPaQVi1RKLO4AyWf+4fzy6tOczOfvCdWuq1S4nFdmgCjolRkEpmkZIIh33wAJu/gqoZxjCTCNhv+ODLm5mQc8KAbU5FtyvFZdAQl7LlQisPaoUUj8fVVIfN4iN47K+19Pokb1iE3A4opptkVDNj8QsAbxutdoowFpGEys6ii35xcWZXC+hgKuEfWruVmdR+lWCr5iQflaAk8gOHrNlVJCOuN12ICqey01iT0AaqKM1FN1qcfE9z3QiOppevBlVR717T8ub4mQQbVYFNgskwVaRTc3fpDpwmPBsil+Ob98JBxdFkgdFCocc0MjsHOCgi3gPSLz7ujjODa0AJlKUchkmxpehSzYenYoRVHYf3kEj0FquDYe0ibTPhZlAZIV5td4MC9rbAZpAYZDHAkUT+v86OvuOGKWMnnhsAb4R9yvzLk8LULn7ffn1ft0QtGas3l6tIbq45AyvnYBVVgMugPVEQtj1Vb1RXo22tL1+eyqS24C1u8Yj4friWAGf0R1KrzEC5tvESwBYVXIaUe4Prasp+IPORCfhu62KmfbdB2KRzriFH/QcRgP5ZNchornoDYFlYDVDfyA1Ra76JAaB4Zb6DYokF/JBK9Luq+g/IhYfiUT3AbpXUiBFlMlE9RMHg8ruC26kglmc28PJ7Spt5IJblNvj2dDZeq79YZ19fbAEBN5+sgC83jsSUds69076MEdvZVM8CRADyvMg6Nkgtkt22MJbZRt0KA1yvZYwnpkGyQnOdaPb4+tZILXcdqj+hTUtlApzGM8vwg9w2hH5r+pgroT5xx0mHKiMtouZBkV03x+Tc4DC2UqlU1X8HyijfbSommTmALzQFREFDQdGuNwNEVMaDw41myNCsHVa1fkK0R101Pd2iKIrYGF6pWmaAUL/+effzr78b5anFbZ0Ck8WIfnPM0Z9xXz22Qm0WDVzAgtlaE001gttM9LLaouC5YM0ZKt1xAUl6XK5W+A1a/O20M6JKawYNalu2hl387L5asbSy3Uv1guu2JjVHjnn4dITMHBi3q4FusegQkkqmAJExN3LFboQ00pNPphZ+4DYiJeXZ7Oh2s+Ku9c7XmCWtHn4wYskaoKmS2Qq+sKtIEI8Y5Zjc+mLR2BTpWIgZK+GkWHxCgaxDdYdxqLiFVViVBrkC8JWxEuOLw0X+SVey5gAfVGAkUM4fxydTn3RAJjqPB209Yp85ZJ2AbZJLGYhnsWtQjt864FctvbtNF/7tjet1poLEfPRzM0yW3weSAQH7GAiafxLDliAe+RljQB9JCOJKNq42gF6cFaUp4yrPblt+cfLQWV0TpFNQwTWp00W2raUnD6f/Aq+TmgNaS8ndft5y267BHorMh/Yg0jBFcJScY1QmertyyDw3KVUBXnDomu0iXnkGGdL6e8Oxphu+fgxF+jNpLghcETCVqAAlkBGhiv/4XBKJEclM6i0UnB+XQVispWpy8VSMxOjp94A19VbCu0pWM51dLxaXU9xM7gKIsi27fJjIORmWMZLB1P339aS/UP1xVXCrn6NaCMYQU5NBC1iExhQj1NBzzBZ0gi8qQGnsBLN1WmIJKt45OyzRIDhEqDZrESclpRfxKsQ8+vuqxz4ErpHNXFUgUXeTmuAOl7KS335NPHm4cBbimS2FuV0wmJytnSAq8tyAFIYG8QXF2zq1+GdF+vEC1yaCmjUYF97gDr0HoYHKLXo4st0PPxTZWKwoz8PQ6QDZxBS0j/XGYcJF2yzDAolVDuKQY6y1FjGj6HxjBssepDVVsWopRsmcQykX82Q4fuiPkuls7ogFxdkhclZ19LcNSI7YXPVgxkQJD9VrBigejtsInnRXChwW2BdXpnt82vBSFxKicOnquZgoR8Ljj56BTbQAZUcFzfinWreJu3WbPOGowDk+PFfJ92yD+8DTYob8uMJ1hti9rM+YJqWAcZlw0oNA7QwhSiOxo0iI9qC08gi9yhGdU+f7kOW5Rd9rWkGVo+nsHRJTAFBjVowIAJDhnY7optRvHO75cZ+Xx9fhu0SzukFvZfntbCfke5KDQtCkSn6Pkted+ss35eFFldeidIq95hNdr/4hrtr8WRqwf0bgcF2yKtHNA78gUKcsWZZm7BPtuObw9Du6el3iCWqf3neak3jypSe18ZbjEBfVIQWj/hHi29u8rT++cgZzj8x/8XAAD//xm+hU8=" } diff --git a/x-pack/filebeat/module/fortinet/firewall/_meta/fields.yml b/x-pack/filebeat/module/fortinet/firewall/_meta/fields.yml index 2ac3946889f..d9bdebd7a1e 100644 --- a/x-pack/filebeat/module/fortinet/firewall/_meta/fields.yml +++ b/x-pack/filebeat/module/fortinet/firewall/_meta/fields.yml @@ -1,2154 +1,2164 @@ -- name: firewall +- name: fortinet type: group - release: beta - default_field: false description: > - Module for parsing Fortinet syslog. + Fields from fortinet FortiOS fields: - - name: acct_stat - type: keyword - description: > - Accounting state (RADIUS) - - - name: acktime - type: keyword - description: > - Alarm Acknowledge Time - - - name: act - type: keyword - description: > - Action - - - name: action - type: keyword - description: > - Status of the session - - - name: activity - type: keyword - description: > - HA activity message - - - name: addr - type: ip - description: > - IP Address - - - name: addr_type - type: keyword - description: > - Address Type - - - name: addrgrp - type: keyword - description: > - Address Group - - - name: adgroup - type: keyword - description: > - AD Group Name - - - name: admin - type: keyword - description: > - Admin User - - - name: age - type: integer - description: > - Time in seconds - time passed since last seen - - - name: agent - type: keyword - description: > - User agent - eg. agent="Mozilla/5.0" - - - name: alarmid - type: integer - description: > - Alarm ID - - - name: alert - type: keyword - description: > - Alert - - - name: analyticscksum - type: keyword - description: > - The checksum of the file submitted for analytics - - - name: analyticssubmit - type: keyword - description: > - The flag for analytics submission - - - name: ap - type: keyword - description: > - Access Point - - - name: app-type - type: keyword - description: > - Address Type - - - name: appact - type: keyword - description: > - The security action from app control - - - name: appid - type: integer - description: > - Application ID - - - name: applist - type: keyword - description: > - Application Control profile - - - name: apprisk - type: keyword - description: > - Application Risk Level - - - name: apscan - type: keyword - description: > - The name of the AP, which scanned and detected the rogue AP - - - name: apsn - type: keyword - description: > - Access Point - - - name: apstatus - type: keyword - description: > - Access Point status - - - name: aptype - type: keyword - description: > - Access Point type - - - name: assigned - type: ip - description: > - Assigned IP Address - - - name: assignip - type: ip - description: > - Assigned IP Address - - - name: attachment - type: keyword - description: > - The flag for email attachement - - - name: attack - type: keyword - description: > - Attack Name - - - name: attackcontext - type: keyword - description: > - The trigger patterns and the packetdata with base64 encoding - - - name: attackcontextid - type: keyword - description: > - Attack context id / total - - - name: attackid - type: integer - description: > - Attack ID - - - name: auditid - type: long - description: > - Audit ID - - - name: auditscore - type: keyword - description: > - The Audit Score - - - name: audittime - type: long - description: > - The time of the audit - - - name: authgrp - type: keyword - description: > - Authorization Group - - - name: authid - type: keyword - description: > - Authentication ID - - - name: authproto - type: keyword - description: > - The protocol that initiated the authentication - - - name: authserver - type: keyword - description: > - Authentication server - - - name: bandwidth - type: keyword - description: > - Bandwidth - - - name: banned_rule - type: keyword - description: > - NAC quarantine Banned Rule Name - - - name: banned_src - type: keyword - description: > - NAC quarantine Banned Source IP - - - name: banword - type: keyword - description: > - Banned word - - - name: botnetdomain - type: keyword - description: > - Botnet Domain Name - - - name: botnetip - type: ip - description: > - Botnet IP Address - - - name: bssid - type: keyword - description: > - Service Set ID - - - name: call_id - type: keyword - description: > - Caller ID - - - name: carrier_ep - type: keyword - description: > - The FortiOS Carrier end-point identification - - - name: cat - type: integer - description: > - DNS category ID - - - name: category - type: keyword - description: > - Authentication category - - - name: cc - type: keyword - description: > - CC Email Address - - - name: cdrcontent - type: keyword - description: > - Cdrcontent - - - name: centralnatid - type: integer - description: > - Central NAT ID - - - name: cert - type: keyword - description: > - Certificate - - - name: cert-type - type: keyword - description: > - Certificate type - - - name: certhash - type: keyword - description: > - Certificate hash - - - name: cfgattr - type: keyword - description: > - Configuration attribute - - - name: cfgobj - type: keyword - description: > - Configuration object - - - name: cfgpath - type: keyword - description: > - Configuration path - - - name: cfgtid - type: keyword - description: > - Configuration transaction ID - - - name: cfgtxpower - type: integer - description: > - Configuration TX power - - - name: channel - type: integer - description: > - Wireless Channel - - - name: channeltype - type: keyword - description: > - SSH channel type - - - name: chassisid - type: integer - description: > - Chassis ID - - - name: checksum - type: keyword - description: > - The checksum of the scanned file - - - name: chgheaders - type: keyword - description: > - HTTP Headers - - - name: cldobjid - type: keyword - description: > - Connector object ID - - - name: client_addr - type: keyword - description: > - Wifi client address - - - name: cloudaction - type: keyword - description: > - Cloud Action - - - name: clouduser - type: keyword - description: > - Cloud User - - - name: column - type: integer - description: > - VOIP Column - - - name: command - type: keyword - description: > - CLI Command - - - name: community - type: keyword - description: > - SNMP Community - - - name: configcountry - type: keyword - description: > - Configuration country - - - name: connection_type - type: keyword - description: > - FortiClient Connection Type - - - name: conserve - type: keyword - description: > - Flag for conserve mode - - - name: constraint - type: keyword - description: > - WAF http protocol restrictions - - - name: contentdisarmed - type: keyword - description: > - Email scanned content - - - name: contenttype - type: keyword - description: > - Content Type from HTTP header - - - name: cookies - type: keyword - description: > - VPN Cookie - - - name: count - type: integer - description: > - Counts of action type - - - name: countapp - type: integer - description: > - Number of App Ctrl logs associated with the session - - - name: countav - type: integer - description: > - Number of AV logs associated with the session - - - name: countcifs - type: integer - description: > - Number of CIFS logs associated with the session - - - name: countdlp - type: integer - description: > - Number of DLP logs associated with the session - - - name: countdns - type: integer - description: > - Number of DNS logs associated with the session - - - name: countemail - type: integer - description: > - Number of email logs associated with the session - - - name: countff - type: integer - description: > - Number of ff logs associated with the session - - - name: countips - type: integer - description: > - Number of IPS logs associated with the session - - - name: countssh - type: integer - description: > - Number of SSH logs associated with the session - - - name: countssl - type: integer - description: > - Number of SSL logs associated with the session - - - name: countwaf - type: integer - description: > - Number of WAF logs associated with the session - - - name: countweb - type: integer - description: > - Number of Web filter logs associated with the session - - - name: cpu - type: integer - description: > - CPU Usage - - - name: craction - type: integer - description: > - Client Reputation Action - - - name: criticalcount - type: integer - description: > - Number of critical ratings - - - name: crl - type: keyword - description: > - Client Reputation Level - - - name: crlevel - type: keyword - description: > - Client Reputation Level - - - name: crscore - type: integer - description: > - Some description - - - name: cveid - type: keyword - description: > - CVE ID - - - name: daemon - type: keyword - description: > - Daemon name - - - name: datarange - type: keyword - description: > - Data range for reports - - - name: date - type: keyword - description: > - Date - - - name: ddnsserver - type: ip - description: > - DDNS server - - - name: desc - type: keyword - description: > - Description - - - name: detectionmethod - type: keyword - description: > - Detection method - - - name: devcategory - type: keyword - description: > - Device category - - - name: devintfname - type: keyword - description: > - HA device Interface Name - - - name: devtype - type: keyword - description: > - Device type - - - name: dhcp_msg - type: keyword - description: > - DHCP Message - - - name: dintf - type: keyword - description: > - Destination interface - - - name: disk - type: keyword - description: > - Assosciated disk - - - name: disklograte - type: long - description: > - Disk logging rate - - - name: dlpextra - type: keyword - description: > - DLP extra information - - - name: docsource - type: keyword - description: > - DLP fingerprint document source - - - name: domainctrlauthstate - type: integer - description: > - CIFS domain auth state - - - name: domainctrlauthtype - type: integer - description: > - CIFS domain auth type - - - name: domainctrldomain - type: keyword - description: > - CIFS domain auth domain - - - name: domainctrlip - type: ip - description: > - CIFS Domain IP - - - name: domainctrlname - type: keyword - description: > - CIFS Domain name - - - name: domainctrlprotocoltype - type: integer - description: > - CIFS Domain connection protocol - - - name: domainctrlusername - type: keyword - description: > - CIFS Domain username - - - name: domainfilteridx - type: integer - description: > - Domain filter ID - - - name: domainfilterlist - type: keyword - description: > - Domain filter name - - - name: ds - type: keyword - description: > - Direction with distribution system - - - name: dst_int - type: keyword - description: > - Destination interface - - - name: dstintfrole - type: keyword - description: > - Destination interface role - - - name: dstcountry - type: keyword - description: > - Destination country - - - name: dstdevcategory - type: keyword - description: > - Destination device category - - - name: dstdevtype - type: keyword - description: > - Destination device type - - - name: dstfamily - type: keyword - description: > - Destination OS family - - - name: dsthwvendor - type: keyword - description: > - Destination HW vendor - - - name: dsthwversion - type: keyword - description: > - Destination HW version - - - name: dstinetsvc - type: keyword - description: > - Destination interface service - - - name: dstosname - type: keyword - description: > - Destination OS name - - - name: dstosversion - type: keyword - description: > - Destination OS version - - - name: dstserver - type: integer - description: > - Destination server - - - name: dstssid - type: keyword - description: > - Destination SSID - - - name: dstswversion - type: keyword - description: > - Destination software version - - - name: dstunauthusersource - type: keyword - description: > - Destination unauthenticated source - - - name: dstuuid - type: keyword - description: > - UUID of the Destination IP address - - - name: duid - type: keyword - description: > - DHCP UID - - - name: eapolcnt - type: integer - description: > - EAPOL packet count - - - name: eapoltype - type: keyword - description: > - EAPOL packet type - - - name: encrypt - type: integer - description: > - Whether the packet is encrypted or not - - - name: encryption - type: keyword - description: > - Encryption method - - - name: epoch - type: integer - description: > - Epoch used for locating file - - - name: espauth - type: keyword - description: > - ESP Authentication - - - name: esptransform - type: keyword - description: > - ESP Transform - - - name: exch - type: keyword - description: > - Mail Exchanges from DNS response answer section - - - name: exchange - type: keyword - description: > - Mail Exchanges from DNS response answer section - - - name: expectedsignature - type: keyword - description: > - Expected SSL signature - - - name: expiry - type: keyword - description: > - FortiGuard override expiry timestamp - - - name: fams_pause - type: integer - description: > - Fortinet Analysis and Management Service Pause - - - name: fazlograte - type: long - description: > - FortiAnalyzer Logging Rate - - - name: fctemssn - type: keyword - description: > - FortiClient Endpoint SSN - - - name: fctuid - type: keyword - description: > - FortiClient UID - - - name: field - type: keyword - description: > - NTP status field - - - name: filefilter - type: keyword - description: > - The filter used to identify the affected file - - - name: filehashsrc - type: keyword - description: > - Filehash source - - - name: filtercat - type: keyword - description: > - DLP filter category - - - name: filteridx - type: integer - description: > - DLP filter ID - - - name: filtername - type: keyword - description: > - DLP rule name - - - name: filtertype - type: keyword - description: > - DLP filter type - - - name: fortiguardresp - type: keyword - description: > - Antispam ESP value - - - name: forwardedfor - type: keyword - description: > - Email address forwarded - - - name: fqdn - type: keyword - description: > - FQDN - - - name: frametype - type: keyword - description: > - Wireless frametype - - - name: freediskstorage - type: integer - description: > - Free disk integer - - - name: from - type: keyword - description: > - From email address - - - name: from_vcluster - type: integer - description: > - Source virtual cluster number - - - name: fsaverdict - type: keyword - description: > - FSA verdict - - - name: fwserver_name - type: keyword - description: > - Web proxy server name - - - name: gateway - type: ip - description: > - Gateway ip address for PPPoE status report - - - name: green - type: keyword - description: > - Memory status - - - name: groupid - type: integer - description: > - User Group ID - - - name: ha-prio - type: integer - description: > - HA Priority - - - name: ha_group - type: keyword - description: > - HA Group - - - name: ha_role - type: keyword - description: > - HA Role - - - name: handshake - type: keyword - description: > - SSL Handshake - - - name: hash - type: keyword - description: > - Hash value of downloaded file - - - name: hbdn_reason - type: keyword - description: > - Heartbeat down reason - - - name: highcount - type: integer - description: > - Highcount fabric summary - - - name: host - type: keyword - description: > - Hostname - - - name: iaid - type: keyword - description: > - DHCPv6 id - - - name: icmpcode - type: keyword - description: > - Destination Port of the ICMP message - - - name: icmpid - type: keyword - description: > - Source port of the ICMP message - - - name: icmptype - type: keyword - description: > - The type of ICMP message - - - name: identifier - type: integer - description: > - Network traffic identifier - - - name: in_spi - type: keyword - description: > - IPSEC inbound SPI - - - name: incidentserialno - type: integer - description: > - Incident serial number - - - name: infected - type: integer - description: > - Infected MMS - - - name: infectedfilelevel - type: integer - description: > - DLP infected file level - - - name: informationsource - type: keyword - description: > - Information source - - - name: init - type: keyword - description: > - IPSEC init stage - - - name: initiator - type: keyword - description: > - Original login user name for Fortiguard override - - - name: interface - type: keyword - description: > - Related interface - - - name: intf - type: keyword - description: > - Related interface - - - name: invalidmac - type: keyword - description: > - The MAC address with invalid OUI - - - name: ip - type: ip - description: > - Related IP - - - name: iptype - type: keyword - description: > - Related IP type - - - name: keyword - type: keyword - description: > - Keyword used for search - - - name: kind - type: keyword - description: > - VOIP kind - - - name: lanin - type: long - description: > - LAN incoming traffic in bytes - - - name: lanout - type: long - description: > - LAN outbound traffic in bytes - - - name: lease - type: integer - description: > - DHCP lease - - - name: license_limit - type: keyword - description: > - Maximum Number of FortiClients for the License - - - name: limit - type: integer - description: > - Virtual Domain Resource Limit - - - name: line - type: keyword - description: > - VOIP line - - - name: live - type: integer - description: > - Time in seconds - - - name: local - type: ip - description: > - Local IP for a PPPD Connection - - - name: log - type: keyword - description: > - Log message - - - name: login - type: keyword - description: > - SSH login - - - name: lowcount - type: integer - description: > - Fabric lowcount - - - name: mac - type: keyword - description: > - DHCP mac address - - - name: malform_data - type: integer - description: > - VOIP malformed data - - - name: malform_desc - type: keyword - description: > - VOIP malformed data description - - - name: manuf - type: keyword - description: > - Manufacturer name - - - name: masterdstmac - type: keyword - description: > - Master mac address for a host with multiple network interfaces - - - name: mastersrcmac - type: keyword - description: > - The master MAC address for a host that has multiple network interfaces - - - name: mediumcount - type: integer - description: > - Fabric medium count - - - name: mem - type: keyword - description: > - Memory usage system statistics - - - name: meshmode - type: keyword - description: > - Wireless mesh mode - - - name: message_type - type: keyword - description: > - VOIP message type - - - name: method - type: keyword - description: > - HTTP method - - - name: mgmtcnt - type: integer - description: > - The number of unauthorized client flooding managemet frames - - - name: mode - type: keyword - description: > - IPSEC mode - - - name: module - type: keyword - description: > - PCI-DSS module - - - name: monitor-name - type: keyword - description: > - Health Monitor Name - - - name: monitor-type - type: keyword - description: > - Health Monitor Type - - - name: mpsk - type: keyword - description: > - Wireless MPSK - - - name: msgproto - type: keyword - description: > - Message Protocol Number - - - name: mtu - type: integer - description: > - Max Transmission Unit Value - - - name: name - type: keyword - description: > - Name - - - name: nat - type: keyword - description: > - NAT IP Address - - - name: netid - type: keyword - description: > - Connector NetID - - - name: new_status - type: keyword - description: > - New status on user change - - - name: new_value - type: keyword - description: > - New Virtual Domain Name - - - name: newchannel - type: integer - description: > - New Channel Number - - - name: newchassisid - type: integer - description: > - New Chassis ID - - - name: newslot - type: integer - description: > - New Slot Number - - - name: nextstat - type: integer - description: > - Time interval in seconds for the next statistics. - - - name: nf_type - type: keyword - description: > - Notification Type - - - name: noise - type: integer - description: > - Wifi Noise - - - name: old_status - type: keyword - description: > - Original Status - - - name: old_value - type: keyword - description: > - Original Virtual Domain name - - - name: oldchannel - type: integer - description: > - Original channel - - - name: oldchassisid - type: integer - description: > - Original Chassis Number - - - name: oldslot - type: integer - description: > - Original Slot Number - - - name: oldsn - type: keyword - description: > - Old Serial number - - - name: oldwprof - type: keyword - description: > - Old Web Filter Profile - - - name: onwire - type: keyword - description: > - A flag to indicate if the AP is onwire or not - - - name: opercountry - type: keyword - description: > - Operating Country - - - name: opertxpower - type: integer - description: > - Operating TX power - - - name: osname - type: keyword - description: > - Operating System name - - - name: osversion - type: keyword - description: > - Operating System version - - - name: out_spi - type: keyword - description: > - Out SPI - - - name: outintf - type: keyword - description: > - Out interface - - - name: passedcount - type: integer - description: > - Fabric passed count - - - name: passwd - type: keyword - description: > - Changed user password information - - - name: path - type: keyword - description: > - Path of looped configuration for security fabric - - - name: peer - type: keyword - description: > - WAN optimization peer - - - name: peer_notif - type: keyword - description: > - VPN peer notification - - - name: phase2_name - type: keyword - description: > - VPN phase2 name - - - name: phone - type: keyword - description: > - VOIP Phone - - - name: pid - type: integer - description: > - Process ID - - - name: policytype - type: keyword - description: > - Policy Type - - - name: poolname - type: keyword - description: > - IP Pool name - - - name: port - type: integer - description: > - Log upload error port - - - name: portbegin - type: integer - description: > - IP Pool port number to begin - - - name: portend - type: integer - description: > - IP Pool port number to end - - - name: probeproto - type: keyword - description: > - Link Monitor Probe Protocol - - - name: process - type: keyword - description: > - URL Filter process - - - name: processtime - type: integer - description: > - Process time for reports - - - name: profile - type: keyword - description: > - Profile Name - - - name: profile_vd - type: keyword - description: > - Virtual Domain Name - - - name: profilegroup - type: keyword - description: > - Profile Group Name - - - name: profiletype - type: keyword - description: > - Profile Type - - - name: qtypeval - type: integer - description: > - DNS question type value - - - name: quarskip - type: keyword - description: > - Quarantine skip explanation - - - name: quotaexceeded - type: keyword - description: > - If quota has been exceeded - - - name: quotamax - type: long - description: > - Maximum quota allowed - in seconds if time-based - in bytes if traffic-based - - - name: quotatype - type: keyword - description: > - Quota type - - - name: quotaused - type: long - description: > - Quota used - in seconds if time-based - in bytes if trafficbased) - - - name: radioband - type: keyword - description: > - Radio band - - - name: radioid - type: integer - description: > - Radio ID - - - name: radioidclosest - type: integer - description: > - Radio ID on the AP closest the rogue AP - - - name: radioiddetected - type: integer - description: > - Radio ID on the AP which detected the rogue AP - - - name: rate - type: keyword - description: > - Wireless rogue rate value - - - name: rawdata - type: keyword - description: > - Raw data value - - - name: rawdataid - type: keyword - description: > - Raw data ID - - - name: rcvddelta - type: keyword - description: > - Received bytes delta - - - name: reason - type: keyword - description: > - Alert reason - - - name: received - type: integer - description: > - Server key exchange received - - - name: receivedsignature - type: keyword - description: > - Server key exchange received signature - - - name: red - type: keyword - description: > - Memory information in red - - - name: referralurl - type: keyword - description: > - Web filter referralurl - - - name: remote - type: ip - description: > - Remote PPP IP address - - - name: remotewtptime - type: keyword - description: > - Remote Wifi Radius authentication time - - - name: reporttype - type: keyword - description: > - Report type - - - name: reqtype - type: keyword - description: > - Request type - - - name: request_name - type: keyword - description: > - VOIP request name - - - name: result - type: keyword - description: > - VPN phase result - - - name: role - type: keyword - description: > - VPN Phase 2 role - - - name: rssi - type: integer - description: > - Received signal strength indicator - - - name: rsso_key - type: keyword - description: > - RADIUS SSO attribute value - - - name: ruledata - type: keyword - description: > - Rule data - - - name: ruletype - type: keyword - description: > - Rule type - - - name: scanned - type: integer - description: > - Number of Scanned MMSs - - - name: scantime - type: long - description: > - Scanned time - - - name: scope - type: keyword - description: > - FortiGuard Override Scope - - - name: security - type: keyword - description: > - Wireless rogue security - - - name: sensitivity - type: keyword - description: > - Sensitivity for document fingerprint - - - name: sensor - type: keyword - description: > - NAC Sensor Name - - - name: sentdelta - type: keyword - description: > - Sent bytes delta - - - name: seq - type: keyword - description: > - Sequence number - - - name: serial - type: keyword - description: > - WAN optimisation serial - - - name: serialno - type: keyword - description: > - Serial number - - - name: server - type: keyword - description: > - AD server FQDN or IP - - - name: session_id - type: keyword - description: > - Session ID - - - name: sessionid - type: integer - description: > - WAD Session ID - - - name: setuprate - type: long - description: > - Session Setup Rate - - - name: severity - type: keyword - description: > - Severity - - - name: shaperdroprcvdbyte - type: integer - description: > - Received bytes dropped by shaper - - - name: shaperdropsentbyte - type: integer - description: > - Sent bytes dropped by shaper - - - name: shaperperipdropbyte - type: integer - description: > - Dropped bytes per IP by shaper - - - name: shaperperipname - type: keyword - description: > - Traffic shaper name (per IP) - - - name: shaperrcvdname - type: keyword - description: > - Traffic shaper name for received traffic - - - name: shapersentname - type: keyword - description: > - Traffic shaper name for sent traffic - - - name: shapingpolicyid - type: integer - description: > - Traffic shaper policy ID - - - name: signal - type: integer - description: > - Wireless rogue API signal - - - name: size - type: long - description: > - Email size in bytes - - - name: slot - type: integer - description: > - Slot number - - - name: sn - type: keyword - description: > - Security fabric serial number - - - name: snclosest - type: keyword - description: > - SN of the AP closest to the rogue AP - - - name: sndetected - type: keyword - description: > - SN of the AP which detected the rogue AP - - - name: snmeshparent - type: keyword - description: > - SN of the mesh parent - - - name: spi - type: keyword - description: > - IPSEC SPI - - - name: src_int - type: keyword - description: > - Source interface - - - name: srcintfrole - type: keyword - description: > - Source interface role - - - name: srccountry - type: keyword - description: > - Source country - - - name: srcfamily - type: keyword - description: > - Source family - - - name: srchwvendor - type: keyword - description: > - Source hardware vendor - - - name: srchwversion - type: keyword - description: > - Source hardware version - - - name: srcinetsvc - type: keyword - description: > - Source interface service - - - name: srcname - type: keyword - description: > - Source name - - - name: srcserver - type: integer - description: > - Source server - - - name: srcssid - type: keyword - description: > - Source SSID - - - name: srcswversion - type: keyword - description: > - Source software version - - - name: srcuuid - type: keyword - description: > - Source UUID - - - name: sscname - type: keyword - description: > - SSC name - - - name: ssid - type: keyword - description: > - Base Service Set ID - - - name: sslaction - type: keyword - description: > - SSL Action - - - name: ssllocal - type: keyword - description: > - WAD SSL local - - - name: sslremote - type: keyword - description: > - WAD SSL remote - - - name: stacount - type: integer - description: > - Number of stations/clients - - - name: stage - type: keyword - description: > - IPSEC stage - - - name: stamac - type: keyword - description: > - 802.1x station mac - - - name: state - type: keyword - description: > - Admin login state - - - name: status - type: keyword - description: > - Status - - - name: stitch - type: keyword - description: > - Automation stitch triggered - - - name: subject - type: keyword - description: > - Email subject - - - name: submodule - type: keyword - description: > - Configuration Sub-Module Name - - - name: subservice - type: keyword - description: > - AV subservice - - - name: subtype - type: keyword - description: > - Log subtype - - - name: suspicious - type: integer - description: > - Number of Suspicious MMSs - - - name: switchproto - type: keyword - description: > - Protocol change information - - - name: sync_status - type: keyword - description: > - The sync status with the master - - - name: sync_type - type: keyword - description: > - The sync type with the master - - - name: sysuptime - type: keyword - description: > - System uptime - - - name: tamac - type: keyword - description: > - the MAC address of Transmitter, if none, then Receiver - - - name: threattype - type: keyword - description: > - WIDS threat type - - - name: time - type: keyword - description: > - Time of the event - - - name: to - type: keyword - description: > - Email to field - - - name: to_vcluster - type: integer - description: > - destination virtual cluster number - - - name: total - type: integer - description: > - Total memory - - - name: totalsession - type: integer - description: > - Total Number of Sessions - - - name: trace_id - type: keyword - description: > - Session clash trace ID - - - name: trandisp - type: keyword - description: > - NAT translation type - - - name: transid - type: integer - description: > - HTTP transaction ID - - - name: translationid - type: keyword - description: > - DNS filter transaltion ID - - - name: trigger - type: keyword - description: > - Automation stitch trigger - - - name: trueclntip - type: ip - description: > - File filter true client IP - - - name: tunnelid - type: integer - description: > - IPSEC tunnel ID - - - name: tunnelip - type: ip - description: > - IPSEC tunnel IP - - - name: tunneltype - type: keyword - description: > - IPSEC tunnel type - - - name: type - type: keyword - description: > - Module type - - - name: ui - type: keyword - description: > - Admin authentication UI type - - - name: unauthusersource - type: keyword - description: > - Unauthenticated user source - - - name: unit - type: integer - description: > - Power supply unit - - - name: urlfilteridx - type: integer - description: > - URL filter ID - - - name: urlfilterlist - type: keyword - description: > - URL filter list - - - name: urlsource - type: keyword - description: > - URL filter source - - - name: urltype - type: keyword - description: > - URL filter type - - - name: used - type: integer - description: > - Number of Used IPs - - - name: used_for_type - type: integer - description: > - Connection for the type - - - name: utmaction - type: keyword - description: > - Security action performed by UTM - - - name: vap - type: keyword - description: > - Virtual AP - - - name: vapmode - type: keyword - description: > - Virtual AP mode - - - name: vcluster - type: integer - description: > - virtual cluster id - - - name: vcluster_member - type: integer - description: > - Virtual cluster member - - - name: vcluster_state - type: keyword - description: > - Virtual cluster state - - - name: vd - type: keyword - description: > - Virtual Domain Name - - - name: vdname - type: keyword - description: > - Virtual Domain Name - - - name: vendorurl - type: keyword - description: > - Vulnerability scan vendor name - - - name: version - type: keyword - description: > - Version - - - name: vip - type: keyword - description: > - Virtual IP - - - name: virus - type: keyword - description: > - Virus name - - - name: virusid - type: integer - description: > - Virus ID (unique virus identifier) - - - name: voip_proto - type: keyword - description: > - VOIP protocol - - - name: vpn - type: keyword - description: > - VPN description - - - name: vpntunnel - type: keyword - description: > - IPsec Vpn Tunnel Name - - - name: vpntype - type: keyword - description: > - The type of the VPN tunnel - - - name: vrf - type: integer - description: > - VRF number - - - name: vulncat - type: keyword - description: > - Vulnerability Category - - - name: vulnid - type: integer - description: > - Vulnerability ID - - - name: vulnname - type: keyword - description: > - Vulnerability name - - - name: vwlid - type: integer - description: > - VWL ID - - - name: vwlquality - type: keyword - description: > - VWL quality - - - name: vwlservice - type: keyword - description: > - VWL service - - - name: vwpvlanid - type: integer - description: > - VWP VLAN ID - - - name: wanin - type: long - description: > - WAN incoming traffic in bytes - - - name: wanoptapptype - type: keyword - description: > - WAN Optimization Application type - - - name: wanout - type: long - description: > - WAN outgoing traffic in bytes - - - name: weakwepiv - type: keyword - description: > - Weak Wep Initiation Vector - - - name: xauthgroup - type: keyword - description: > - XAuth Group Name - - - name: xauthuser - type: keyword - description: > - XAuth User Name - - - name: xid - type: integer - description: > - Wireless X ID + - name: file.hash.crc32 + type: keyword + description: > + CRC32 Hash of file + + - name: firewall + type: group + release: beta + default_field: false + description: > + Module for parsing Fortinet syslog. + fields: + - name: acct_stat + type: keyword + description: > + Accounting state (RADIUS) + + - name: acktime + type: keyword + description: > + Alarm Acknowledge Time + + - name: act + type: keyword + description: > + Action + + - name: action + type: keyword + description: > + Status of the session + + - name: activity + type: keyword + description: > + HA activity message + + - name: addr + type: ip + description: > + IP Address + + - name: addr_type + type: keyword + description: > + Address Type + + - name: addrgrp + type: keyword + description: > + Address Group + + - name: adgroup + type: keyword + description: > + AD Group Name + + - name: admin + type: keyword + description: > + Admin User + + - name: age + type: integer + description: > + Time in seconds - time passed since last seen + + - name: agent + type: keyword + description: > + User agent - eg. agent="Mozilla/5.0" + + - name: alarmid + type: integer + description: > + Alarm ID + + - name: alert + type: keyword + description: > + Alert + + - name: analyticscksum + type: keyword + description: > + The checksum of the file submitted for analytics + + - name: analyticssubmit + type: keyword + description: > + The flag for analytics submission + + - name: ap + type: keyword + description: > + Access Point + + - name: app-type + type: keyword + description: > + Address Type + + - name: appact + type: keyword + description: > + The security action from app control + + - name: appid + type: integer + description: > + Application ID + + - name: applist + type: keyword + description: > + Application Control profile + + - name: apprisk + type: keyword + description: > + Application Risk Level + + - name: apscan + type: keyword + description: > + The name of the AP, which scanned and detected the rogue AP + + - name: apsn + type: keyword + description: > + Access Point + + - name: apstatus + type: keyword + description: > + Access Point status + + - name: aptype + type: keyword + description: > + Access Point type + + - name: assigned + type: ip + description: > + Assigned IP Address + + - name: assignip + type: ip + description: > + Assigned IP Address + + - name: attachment + type: keyword + description: > + The flag for email attachement + + - name: attack + type: keyword + description: > + Attack Name + + - name: attackcontext + type: keyword + description: > + The trigger patterns and the packetdata with base64 encoding + + - name: attackcontextid + type: keyword + description: > + Attack context id / total + + - name: attackid + type: integer + description: > + Attack ID + + - name: auditid + type: long + description: > + Audit ID + + - name: auditscore + type: keyword + description: > + The Audit Score + + - name: audittime + type: long + description: > + The time of the audit + + - name: authgrp + type: keyword + description: > + Authorization Group + + - name: authid + type: keyword + description: > + Authentication ID + + - name: authproto + type: keyword + description: > + The protocol that initiated the authentication + + - name: authserver + type: keyword + description: > + Authentication server + + - name: bandwidth + type: keyword + description: > + Bandwidth + + - name: banned_rule + type: keyword + description: > + NAC quarantine Banned Rule Name + + - name: banned_src + type: keyword + description: > + NAC quarantine Banned Source IP + + - name: banword + type: keyword + description: > + Banned word + + - name: botnetdomain + type: keyword + description: > + Botnet Domain Name + + - name: botnetip + type: ip + description: > + Botnet IP Address + + - name: bssid + type: keyword + description: > + Service Set ID + + - name: call_id + type: keyword + description: > + Caller ID + + - name: carrier_ep + type: keyword + description: > + The FortiOS Carrier end-point identification + + - name: cat + type: integer + description: > + DNS category ID + + - name: category + type: keyword + description: > + Authentication category + + - name: cc + type: keyword + description: > + CC Email Address + + - name: cdrcontent + type: keyword + description: > + Cdrcontent + + - name: centralnatid + type: integer + description: > + Central NAT ID + + - name: cert + type: keyword + description: > + Certificate + + - name: cert-type + type: keyword + description: > + Certificate type + + - name: certhash + type: keyword + description: > + Certificate hash + + - name: cfgattr + type: keyword + description: > + Configuration attribute + + - name: cfgobj + type: keyword + description: > + Configuration object + + - name: cfgpath + type: keyword + description: > + Configuration path + + - name: cfgtid + type: keyword + description: > + Configuration transaction ID + + - name: cfgtxpower + type: integer + description: > + Configuration TX power + + - name: channel + type: integer + description: > + Wireless Channel + + - name: channeltype + type: keyword + description: > + SSH channel type + + - name: chassisid + type: integer + description: > + Chassis ID + + - name: checksum + type: keyword + description: > + The checksum of the scanned file + + - name: chgheaders + type: keyword + description: > + HTTP Headers + + - name: cldobjid + type: keyword + description: > + Connector object ID + + - name: client_addr + type: keyword + description: > + Wifi client address + + - name: cloudaction + type: keyword + description: > + Cloud Action + + - name: clouduser + type: keyword + description: > + Cloud User + + - name: column + type: integer + description: > + VOIP Column + + - name: command + type: keyword + description: > + CLI Command + + - name: community + type: keyword + description: > + SNMP Community + + - name: configcountry + type: keyword + description: > + Configuration country + + - name: connection_type + type: keyword + description: > + FortiClient Connection Type + + - name: conserve + type: keyword + description: > + Flag for conserve mode + + - name: constraint + type: keyword + description: > + WAF http protocol restrictions + + - name: contentdisarmed + type: keyword + description: > + Email scanned content + + - name: contenttype + type: keyword + description: > + Content Type from HTTP header + + - name: cookies + type: keyword + description: > + VPN Cookie + + - name: count + type: integer + description: > + Counts of action type + + - name: countapp + type: integer + description: > + Number of App Ctrl logs associated with the session + + - name: countav + type: integer + description: > + Number of AV logs associated with the session + + - name: countcifs + type: integer + description: > + Number of CIFS logs associated with the session + + - name: countdlp + type: integer + description: > + Number of DLP logs associated with the session + + - name: countdns + type: integer + description: > + Number of DNS logs associated with the session + + - name: countemail + type: integer + description: > + Number of email logs associated with the session + + - name: countff + type: integer + description: > + Number of ff logs associated with the session + + - name: countips + type: integer + description: > + Number of IPS logs associated with the session + + - name: countssh + type: integer + description: > + Number of SSH logs associated with the session + + - name: countssl + type: integer + description: > + Number of SSL logs associated with the session + + - name: countwaf + type: integer + description: > + Number of WAF logs associated with the session + + - name: countweb + type: integer + description: > + Number of Web filter logs associated with the session + + - name: cpu + type: integer + description: > + CPU Usage + + - name: craction + type: integer + description: > + Client Reputation Action + + - name: criticalcount + type: integer + description: > + Number of critical ratings + + - name: crl + type: keyword + description: > + Client Reputation Level + + - name: crlevel + type: keyword + description: > + Client Reputation Level + + - name: crscore + type: integer + description: > + Some description + + - name: cveid + type: keyword + description: > + CVE ID + + - name: daemon + type: keyword + description: > + Daemon name + + - name: datarange + type: keyword + description: > + Data range for reports + + - name: date + type: keyword + description: > + Date + + - name: ddnsserver + type: ip + description: > + DDNS server + + - name: desc + type: keyword + description: > + Description + + - name: detectionmethod + type: keyword + description: > + Detection method + + - name: devcategory + type: keyword + description: > + Device category + + - name: devintfname + type: keyword + description: > + HA device Interface Name + + - name: devtype + type: keyword + description: > + Device type + + - name: dhcp_msg + type: keyword + description: > + DHCP Message + + - name: dintf + type: keyword + description: > + Destination interface + + - name: disk + type: keyword + description: > + Assosciated disk + + - name: disklograte + type: long + description: > + Disk logging rate + + - name: dlpextra + type: keyword + description: > + DLP extra information + + - name: docsource + type: keyword + description: > + DLP fingerprint document source + + - name: domainctrlauthstate + type: integer + description: > + CIFS domain auth state + + - name: domainctrlauthtype + type: integer + description: > + CIFS domain auth type + + - name: domainctrldomain + type: keyword + description: > + CIFS domain auth domain + + - name: domainctrlip + type: ip + description: > + CIFS Domain IP + + - name: domainctrlname + type: keyword + description: > + CIFS Domain name + + - name: domainctrlprotocoltype + type: integer + description: > + CIFS Domain connection protocol + + - name: domainctrlusername + type: keyword + description: > + CIFS Domain username + + - name: domainfilteridx + type: integer + description: > + Domain filter ID + + - name: domainfilterlist + type: keyword + description: > + Domain filter name + + - name: ds + type: keyword + description: > + Direction with distribution system + + - name: dst_int + type: keyword + description: > + Destination interface + + - name: dstintfrole + type: keyword + description: > + Destination interface role + + - name: dstcountry + type: keyword + description: > + Destination country + + - name: dstdevcategory + type: keyword + description: > + Destination device category + + - name: dstdevtype + type: keyword + description: > + Destination device type + + - name: dstfamily + type: keyword + description: > + Destination OS family + + - name: dsthwvendor + type: keyword + description: > + Destination HW vendor + + - name: dsthwversion + type: keyword + description: > + Destination HW version + + - name: dstinetsvc + type: keyword + description: > + Destination interface service + + - name: dstosname + type: keyword + description: > + Destination OS name + + - name: dstosversion + type: keyword + description: > + Destination OS version + + - name: dstserver + type: integer + description: > + Destination server + + - name: dstssid + type: keyword + description: > + Destination SSID + + - name: dstswversion + type: keyword + description: > + Destination software version + + - name: dstunauthusersource + type: keyword + description: > + Destination unauthenticated source + + - name: dstuuid + type: keyword + description: > + UUID of the Destination IP address + + - name: duid + type: keyword + description: > + DHCP UID + + - name: eapolcnt + type: integer + description: > + EAPOL packet count + + - name: eapoltype + type: keyword + description: > + EAPOL packet type + + - name: encrypt + type: integer + description: > + Whether the packet is encrypted or not + + - name: encryption + type: keyword + description: > + Encryption method + + - name: epoch + type: integer + description: > + Epoch used for locating file + + - name: espauth + type: keyword + description: > + ESP Authentication + + - name: esptransform + type: keyword + description: > + ESP Transform + + - name: exch + type: keyword + description: > + Mail Exchanges from DNS response answer section + + - name: exchange + type: keyword + description: > + Mail Exchanges from DNS response answer section + + - name: expectedsignature + type: keyword + description: > + Expected SSL signature + + - name: expiry + type: keyword + description: > + FortiGuard override expiry timestamp + + - name: fams_pause + type: integer + description: > + Fortinet Analysis and Management Service Pause + + - name: fazlograte + type: long + description: > + FortiAnalyzer Logging Rate + + - name: fctemssn + type: keyword + description: > + FortiClient Endpoint SSN + + - name: fctuid + type: keyword + description: > + FortiClient UID + + - name: field + type: keyword + description: > + NTP status field + + - name: filefilter + type: keyword + description: > + The filter used to identify the affected file + + - name: filehashsrc + type: keyword + description: > + Filehash source + + - name: filtercat + type: keyword + description: > + DLP filter category + + - name: filteridx + type: integer + description: > + DLP filter ID + + - name: filtername + type: keyword + description: > + DLP rule name + + - name: filtertype + type: keyword + description: > + DLP filter type + + - name: fortiguardresp + type: keyword + description: > + Antispam ESP value + + - name: forwardedfor + type: keyword + description: > + Email address forwarded + + - name: fqdn + type: keyword + description: > + FQDN + + - name: frametype + type: keyword + description: > + Wireless frametype + + - name: freediskstorage + type: integer + description: > + Free disk integer + + - name: from + type: keyword + description: > + From email address + + - name: from_vcluster + type: integer + description: > + Source virtual cluster number + + - name: fsaverdict + type: keyword + description: > + FSA verdict + + - name: fwserver_name + type: keyword + description: > + Web proxy server name + + - name: gateway + type: ip + description: > + Gateway ip address for PPPoE status report + + - name: green + type: keyword + description: > + Memory status + + - name: groupid + type: integer + description: > + User Group ID + + - name: ha-prio + type: integer + description: > + HA Priority + + - name: ha_group + type: keyword + description: > + HA Group + + - name: ha_role + type: keyword + description: > + HA Role + + - name: handshake + type: keyword + description: > + SSL Handshake + + - name: hash + type: keyword + description: > + Hash value of downloaded file + + - name: hbdn_reason + type: keyword + description: > + Heartbeat down reason + + - name: highcount + type: integer + description: > + Highcount fabric summary + + - name: host + type: keyword + description: > + Hostname + + - name: iaid + type: keyword + description: > + DHCPv6 id + + - name: icmpcode + type: keyword + description: > + Destination Port of the ICMP message + + - name: icmpid + type: keyword + description: > + Source port of the ICMP message + + - name: icmptype + type: keyword + description: > + The type of ICMP message + + - name: identifier + type: integer + description: > + Network traffic identifier + + - name: in_spi + type: keyword + description: > + IPSEC inbound SPI + + - name: incidentserialno + type: integer + description: > + Incident serial number + + - name: infected + type: integer + description: > + Infected MMS + + - name: infectedfilelevel + type: integer + description: > + DLP infected file level + + - name: informationsource + type: keyword + description: > + Information source + + - name: init + type: keyword + description: > + IPSEC init stage + + - name: initiator + type: keyword + description: > + Original login user name for Fortiguard override + + - name: interface + type: keyword + description: > + Related interface + + - name: intf + type: keyword + description: > + Related interface + + - name: invalidmac + type: keyword + description: > + The MAC address with invalid OUI + + - name: ip + type: ip + description: > + Related IP + + - name: iptype + type: keyword + description: > + Related IP type + + - name: keyword + type: keyword + description: > + Keyword used for search + + - name: kind + type: keyword + description: > + VOIP kind + + - name: lanin + type: long + description: > + LAN incoming traffic in bytes + + - name: lanout + type: long + description: > + LAN outbound traffic in bytes + + - name: lease + type: integer + description: > + DHCP lease + + - name: license_limit + type: keyword + description: > + Maximum Number of FortiClients for the License + + - name: limit + type: integer + description: > + Virtual Domain Resource Limit + + - name: line + type: keyword + description: > + VOIP line + + - name: live + type: integer + description: > + Time in seconds + + - name: local + type: ip + description: > + Local IP for a PPPD Connection + + - name: log + type: keyword + description: > + Log message + + - name: login + type: keyword + description: > + SSH login + + - name: lowcount + type: integer + description: > + Fabric lowcount + + - name: mac + type: keyword + description: > + DHCP mac address + + - name: malform_data + type: integer + description: > + VOIP malformed data + + - name: malform_desc + type: keyword + description: > + VOIP malformed data description + + - name: manuf + type: keyword + description: > + Manufacturer name + + - name: masterdstmac + type: keyword + description: > + Master mac address for a host with multiple network interfaces + + - name: mastersrcmac + type: keyword + description: > + The master MAC address for a host that has multiple network interfaces + + - name: mediumcount + type: integer + description: > + Fabric medium count + + - name: mem + type: keyword + description: > + Memory usage system statistics + + - name: meshmode + type: keyword + description: > + Wireless mesh mode + + - name: message_type + type: keyword + description: > + VOIP message type + + - name: method + type: keyword + description: > + HTTP method + + - name: mgmtcnt + type: integer + description: > + The number of unauthorized client flooding managemet frames + + - name: mode + type: keyword + description: > + IPSEC mode + + - name: module + type: keyword + description: > + PCI-DSS module + + - name: monitor-name + type: keyword + description: > + Health Monitor Name + + - name: monitor-type + type: keyword + description: > + Health Monitor Type + + - name: mpsk + type: keyword + description: > + Wireless MPSK + + - name: msgproto + type: keyword + description: > + Message Protocol Number + + - name: mtu + type: integer + description: > + Max Transmission Unit Value + + - name: name + type: keyword + description: > + Name + + - name: nat + type: keyword + description: > + NAT IP Address + + - name: netid + type: keyword + description: > + Connector NetID + + - name: new_status + type: keyword + description: > + New status on user change + + - name: new_value + type: keyword + description: > + New Virtual Domain Name + + - name: newchannel + type: integer + description: > + New Channel Number + + - name: newchassisid + type: integer + description: > + New Chassis ID + + - name: newslot + type: integer + description: > + New Slot Number + + - name: nextstat + type: integer + description: > + Time interval in seconds for the next statistics. + + - name: nf_type + type: keyword + description: > + Notification Type + + - name: noise + type: integer + description: > + Wifi Noise + + - name: old_status + type: keyword + description: > + Original Status + + - name: old_value + type: keyword + description: > + Original Virtual Domain name + + - name: oldchannel + type: integer + description: > + Original channel + + - name: oldchassisid + type: integer + description: > + Original Chassis Number + + - name: oldslot + type: integer + description: > + Original Slot Number + + - name: oldsn + type: keyword + description: > + Old Serial number + + - name: oldwprof + type: keyword + description: > + Old Web Filter Profile + + - name: onwire + type: keyword + description: > + A flag to indicate if the AP is onwire or not + + - name: opercountry + type: keyword + description: > + Operating Country + + - name: opertxpower + type: integer + description: > + Operating TX power + + - name: osname + type: keyword + description: > + Operating System name + + - name: osversion + type: keyword + description: > + Operating System version + + - name: out_spi + type: keyword + description: > + Out SPI + + - name: outintf + type: keyword + description: > + Out interface + + - name: passedcount + type: integer + description: > + Fabric passed count + + - name: passwd + type: keyword + description: > + Changed user password information + + - name: path + type: keyword + description: > + Path of looped configuration for security fabric + + - name: peer + type: keyword + description: > + WAN optimization peer + + - name: peer_notif + type: keyword + description: > + VPN peer notification + + - name: phase2_name + type: keyword + description: > + VPN phase2 name + + - name: phone + type: keyword + description: > + VOIP Phone + + - name: pid + type: integer + description: > + Process ID + + - name: policytype + type: keyword + description: > + Policy Type + + - name: poolname + type: keyword + description: > + IP Pool name + + - name: port + type: integer + description: > + Log upload error port + + - name: portbegin + type: integer + description: > + IP Pool port number to begin + + - name: portend + type: integer + description: > + IP Pool port number to end + + - name: probeproto + type: keyword + description: > + Link Monitor Probe Protocol + + - name: process + type: keyword + description: > + URL Filter process + + - name: processtime + type: integer + description: > + Process time for reports + + - name: profile + type: keyword + description: > + Profile Name + + - name: profile_vd + type: keyword + description: > + Virtual Domain Name + + - name: profilegroup + type: keyword + description: > + Profile Group Name + + - name: profiletype + type: keyword + description: > + Profile Type + + - name: qtypeval + type: integer + description: > + DNS question type value + + - name: quarskip + type: keyword + description: > + Quarantine skip explanation + + - name: quotaexceeded + type: keyword + description: > + If quota has been exceeded + + - name: quotamax + type: long + description: > + Maximum quota allowed - in seconds if time-based - in bytes if traffic-based + + - name: quotatype + type: keyword + description: > + Quota type + + - name: quotaused + type: long + description: > + Quota used - in seconds if time-based - in bytes if trafficbased) + + - name: radioband + type: keyword + description: > + Radio band + + - name: radioid + type: integer + description: > + Radio ID + + - name: radioidclosest + type: integer + description: > + Radio ID on the AP closest the rogue AP + + - name: radioiddetected + type: integer + description: > + Radio ID on the AP which detected the rogue AP + + - name: rate + type: keyword + description: > + Wireless rogue rate value + + - name: rawdata + type: keyword + description: > + Raw data value + + - name: rawdataid + type: keyword + description: > + Raw data ID + + - name: rcvddelta + type: keyword + description: > + Received bytes delta + + - name: reason + type: keyword + description: > + Alert reason + + - name: received + type: integer + description: > + Server key exchange received + + - name: receivedsignature + type: keyword + description: > + Server key exchange received signature + + - name: red + type: keyword + description: > + Memory information in red + + - name: referralurl + type: keyword + description: > + Web filter referralurl + + - name: remote + type: ip + description: > + Remote PPP IP address + + - name: remotewtptime + type: keyword + description: > + Remote Wifi Radius authentication time + + - name: reporttype + type: keyword + description: > + Report type + + - name: reqtype + type: keyword + description: > + Request type + + - name: request_name + type: keyword + description: > + VOIP request name + + - name: result + type: keyword + description: > + VPN phase result + + - name: role + type: keyword + description: > + VPN Phase 2 role + + - name: rssi + type: integer + description: > + Received signal strength indicator + + - name: rsso_key + type: keyword + description: > + RADIUS SSO attribute value + + - name: ruledata + type: keyword + description: > + Rule data + + - name: ruletype + type: keyword + description: > + Rule type + + - name: scanned + type: integer + description: > + Number of Scanned MMSs + + - name: scantime + type: long + description: > + Scanned time + + - name: scope + type: keyword + description: > + FortiGuard Override Scope + + - name: security + type: keyword + description: > + Wireless rogue security + + - name: sensitivity + type: keyword + description: > + Sensitivity for document fingerprint + + - name: sensor + type: keyword + description: > + NAC Sensor Name + + - name: sentdelta + type: keyword + description: > + Sent bytes delta + + - name: seq + type: keyword + description: > + Sequence number + + - name: serial + type: keyword + description: > + WAN optimisation serial + + - name: serialno + type: keyword + description: > + Serial number + + - name: server + type: keyword + description: > + AD server FQDN or IP + + - name: session_id + type: keyword + description: > + Session ID + + - name: sessionid + type: integer + description: > + WAD Session ID + + - name: setuprate + type: long + description: > + Session Setup Rate + + - name: severity + type: keyword + description: > + Severity + + - name: shaperdroprcvdbyte + type: integer + description: > + Received bytes dropped by shaper + + - name: shaperdropsentbyte + type: integer + description: > + Sent bytes dropped by shaper + + - name: shaperperipdropbyte + type: integer + description: > + Dropped bytes per IP by shaper + + - name: shaperperipname + type: keyword + description: > + Traffic shaper name (per IP) + + - name: shaperrcvdname + type: keyword + description: > + Traffic shaper name for received traffic + + - name: shapersentname + type: keyword + description: > + Traffic shaper name for sent traffic + + - name: shapingpolicyid + type: integer + description: > + Traffic shaper policy ID + + - name: signal + type: integer + description: > + Wireless rogue API signal + + - name: size + type: long + description: > + Email size in bytes + + - name: slot + type: integer + description: > + Slot number + + - name: sn + type: keyword + description: > + Security fabric serial number + + - name: snclosest + type: keyword + description: > + SN of the AP closest to the rogue AP + + - name: sndetected + type: keyword + description: > + SN of the AP which detected the rogue AP + + - name: snmeshparent + type: keyword + description: > + SN of the mesh parent + + - name: spi + type: keyword + description: > + IPSEC SPI + + - name: src_int + type: keyword + description: > + Source interface + + - name: srcintfrole + type: keyword + description: > + Source interface role + + - name: srccountry + type: keyword + description: > + Source country + + - name: srcfamily + type: keyword + description: > + Source family + + - name: srchwvendor + type: keyword + description: > + Source hardware vendor + + - name: srchwversion + type: keyword + description: > + Source hardware version + + - name: srcinetsvc + type: keyword + description: > + Source interface service + + - name: srcname + type: keyword + description: > + Source name + + - name: srcserver + type: integer + description: > + Source server + + - name: srcssid + type: keyword + description: > + Source SSID + + - name: srcswversion + type: keyword + description: > + Source software version + + - name: srcuuid + type: keyword + description: > + Source UUID + + - name: sscname + type: keyword + description: > + SSC name + + - name: ssid + type: keyword + description: > + Base Service Set ID + + - name: sslaction + type: keyword + description: > + SSL Action + + - name: ssllocal + type: keyword + description: > + WAD SSL local + + - name: sslremote + type: keyword + description: > + WAD SSL remote + + - name: stacount + type: integer + description: > + Number of stations/clients + + - name: stage + type: keyword + description: > + IPSEC stage + + - name: stamac + type: keyword + description: > + 802.1x station mac + + - name: state + type: keyword + description: > + Admin login state + + - name: status + type: keyword + description: > + Status + + - name: stitch + type: keyword + description: > + Automation stitch triggered + + - name: subject + type: keyword + description: > + Email subject + + - name: submodule + type: keyword + description: > + Configuration Sub-Module Name + + - name: subservice + type: keyword + description: > + AV subservice + + - name: subtype + type: keyword + description: > + Log subtype + + - name: suspicious + type: integer + description: > + Number of Suspicious MMSs + + - name: switchproto + type: keyword + description: > + Protocol change information + + - name: sync_status + type: keyword + description: > + The sync status with the master + + - name: sync_type + type: keyword + description: > + The sync type with the master + + - name: sysuptime + type: keyword + description: > + System uptime + + - name: tamac + type: keyword + description: > + the MAC address of Transmitter, if none, then Receiver + + - name: threattype + type: keyword + description: > + WIDS threat type + + - name: time + type: keyword + description: > + Time of the event + + - name: to + type: keyword + description: > + Email to field + + - name: to_vcluster + type: integer + description: > + destination virtual cluster number + + - name: total + type: integer + description: > + Total memory + + - name: totalsession + type: integer + description: > + Total Number of Sessions + + - name: trace_id + type: keyword + description: > + Session clash trace ID + + - name: trandisp + type: keyword + description: > + NAT translation type + + - name: transid + type: integer + description: > + HTTP transaction ID + + - name: translationid + type: keyword + description: > + DNS filter transaltion ID + + - name: trigger + type: keyword + description: > + Automation stitch trigger + + - name: trueclntip + type: ip + description: > + File filter true client IP + + - name: tunnelid + type: integer + description: > + IPSEC tunnel ID + + - name: tunnelip + type: ip + description: > + IPSEC tunnel IP + + - name: tunneltype + type: keyword + description: > + IPSEC tunnel type + + - name: type + type: keyword + description: > + Module type + + - name: ui + type: keyword + description: > + Admin authentication UI type + + - name: unauthusersource + type: keyword + description: > + Unauthenticated user source + + - name: unit + type: integer + description: > + Power supply unit + + - name: urlfilteridx + type: integer + description: > + URL filter ID + + - name: urlfilterlist + type: keyword + description: > + URL filter list + + - name: urlsource + type: keyword + description: > + URL filter source + + - name: urltype + type: keyword + description: > + URL filter type + + - name: used + type: integer + description: > + Number of Used IPs + + - name: used_for_type + type: integer + description: > + Connection for the type + + - name: utmaction + type: keyword + description: > + Security action performed by UTM + + - name: vap + type: keyword + description: > + Virtual AP + + - name: vapmode + type: keyword + description: > + Virtual AP mode + + - name: vcluster + type: integer + description: > + virtual cluster id + + - name: vcluster_member + type: integer + description: > + Virtual cluster member + + - name: vcluster_state + type: keyword + description: > + Virtual cluster state + + - name: vd + type: keyword + description: > + Virtual Domain Name + + - name: vdname + type: keyword + description: > + Virtual Domain Name + + - name: vendorurl + type: keyword + description: > + Vulnerability scan vendor name + + - name: version + type: keyword + description: > + Version + + - name: vip + type: keyword + description: > + Virtual IP + + - name: virus + type: keyword + description: > + Virus name + + - name: virusid + type: integer + description: > + Virus ID (unique virus identifier) + + - name: voip_proto + type: keyword + description: > + VOIP protocol + + - name: vpn + type: keyword + description: > + VPN description + + - name: vpntunnel + type: keyword + description: > + IPsec Vpn Tunnel Name + + - name: vpntype + type: keyword + description: > + The type of the VPN tunnel + + - name: vrf + type: integer + description: > + VRF number + + - name: vulncat + type: keyword + description: > + Vulnerability Category + + - name: vulnid + type: integer + description: > + Vulnerability ID + + - name: vulnname + type: keyword + description: > + Vulnerability name + + - name: vwlid + type: integer + description: > + VWL ID + + - name: vwlquality + type: keyword + description: > + VWL quality + + - name: vwlservice + type: keyword + description: > + VWL service + + - name: vwpvlanid + type: integer + description: > + VWP VLAN ID + + - name: wanin + type: long + description: > + WAN incoming traffic in bytes + + - name: wanoptapptype + type: keyword + description: > + WAN Optimization Application type + + - name: wanout + type: long + description: > + WAN outgoing traffic in bytes + + - name: weakwepiv + type: keyword + description: > + Weak Wep Initiation Vector + + - name: xauthgroup + type: keyword + description: > + XAuth Group Name + + - name: xauthuser + type: keyword + description: > + XAuth User Name + + - name: xid + type: integer + description: > + Wireless X ID diff --git a/x-pack/filebeat/module/microsoft/_meta/fields.yml b/x-pack/filebeat/module/microsoft/_meta/fields.yml index 6c034898d5f..fcc100e25bd 100644 --- a/x-pack/filebeat/module/microsoft/_meta/fields.yml +++ b/x-pack/filebeat/module/microsoft/_meta/fields.yml @@ -3,8 +3,3 @@ description: > Microsoft Module fields: - - name: microsoft - type: group - description: > - Fields from Microsoft ATP - fields: diff --git a/x-pack/filebeat/module/microsoft/defender_atp/_meta/fields.yml b/x-pack/filebeat/module/microsoft/defender_atp/_meta/fields.yml index 4fdc0266976..fae3cf2cfd0 100644 --- a/x-pack/filebeat/module/microsoft/defender_atp/_meta/fields.yml +++ b/x-pack/filebeat/module/microsoft/defender_atp/_meta/fields.yml @@ -1,4 +1,4 @@ -- name: defender_atp +- name: microsoft.defender_atp type: group release: beta default_field: false @@ -88,4 +88,4 @@ - name: evidence.userPrincipalName type: keyword description: > - Principal name of the user involved in the alert \ No newline at end of file + Principal name of the user involved in the alert diff --git a/x-pack/filebeat/module/microsoft/fields.go b/x-pack/filebeat/module/microsoft/fields.go index 1d9507c6237..2576fcb8ac7 100644 --- a/x-pack/filebeat/module/microsoft/fields.go +++ b/x-pack/filebeat/module/microsoft/fields.go @@ -19,5 +19,5 @@ func init() { // AssetMicrosoft returns asset data. // This is the base64 encoded gzipped contents of module/microsoft. func AssetMicrosoft() string { - return "eJzsfe9zG7eS4Pf3V+Dy4WynHDlxfuw939u90krORre2o7VkZ+vqVU2BmCaJJwwwBjCkmL/+Cg3McMjBkBIFUPLe+UNiS2SjuwE0+nd/R25g9YZUnGll1NT+hRDLrYA35H3vRyUYpnltuZJvyL/8hRCy/jV5r8pGwF8ImXIQpXmDv/6OSFrBJmD3x65qeENmWjV1+EkEtvvzKwIjU62q3lqn15fhE/3F+guWMAVZgi6orbtfxtZ1fzQIoAbekAlY2vt5CVPaCFvgIm/IlAoDG7+OooxsQWaQqdKEyxkYy+Wsh/95wM4RctL74jY1fYoENfZTXVIL17yCjY+0dLlfbv1iB47uz/Uc8FuEypJYXgF5ziX5dH32gtg5ECpAW7KkBlcnDS5frjGOIqrBKLGAMiuaXJLlnLM5omkstY0harqFNJtTOYOSWEWefQxYPduDPZeMlyDtRRnF/QZWS6W3f3cH9C8CXHJx3iJ66hDdi87CnZ4ZdbDT49QD7hDTINwGO4YdhOCVHW7tA3FkjdaObW6PoeXcBuJ7EKTG8JmE8lqlQ+z3pQS9cd72IOFPaDoErmpgfMrBIAZ9Hm3dgxNyqYzhEwFkQUUDhlANb8izT/JGqqV89pI8+wBL978LeanVTIMxz/Ca3fnGMOFYPOUMdyM5jR7sfYn61cnqS2W45QtwP7jWzfrfeygqwYKuuMxDUNi0jUXuRN4HZU8XlAs6EUjSaW3d/95TsaQaf3IFrNHcri5BGyUliP4Pr/0z5H70SS6ptFBeqaltv/u7nYPexxk710Dtr7TiYvWBjsj3A++6g0ymCHrfCzOh7N/cG54WhU8GtNcNtgUhbstunGDhxDuDk1JVlMu0mJ0jTFzpIajx+rQs3Q2PYsbr+yF1cUmoB+ceARQV7lm+L1KUlo7xKd+29RPbuC19EHaMqUba9AcN9zIVliCtu+CrOvHj677ukGwXuiM6jp5L7TSpmoq0rOvAknsysEVSgl0qfXPCpQU9pQxO5CaCagF6qbl10k43MDAehmgfbiZ86NEQECMdYmQ5Bw34O6vpdMoZmVNDJgCSqIkBveir4p1sNPQexGxbQntIGdonazXQujMtNsgbX31s/d0mUGVmWwdi1wr3OGfXc27c5wg37iyhcGW0tk3gv6ZLUoExdOb+TS1hqgIn9rwQHpzSd2pGzoGpEnScEA+LbyN1KDnrGwjSFo60xIADwpm5H1gelFolLUiL6iyXxlJpWzRMXDcZ2pt3QXCfNYrYcY8Tmp7UBtOTEgPGOO1tzq0hlHwA+we30r2IYfdPImI1EGvmqhElkbAATSbQnbuaagPkPVjqUKPe9bFe6vk7NTOvLim7AWteDDUFroFZsXpJbMCbko/ghYU/4bKH5knc0wALEAdwUii5fT83OHkOtQaGyovDpIQpl1ASJQWiZZ1eSypax7GqzKxIdmF27PH7cM8vzn/w6re/8Wi8r7V3uKXMEqFmfr/0YCOQOo66vT8t+Dm3HTXVlrNGUI3fDxt7MnoyBqAPOimxkzGAPH5SRrdkcdw9ef3/92T3nrhV82zIw66vmvyjQEK2t+XJYLeghwi97KhpMKrRLNPb+3C25br/D8MM3YUVSPsUkaNNyW2BfrOniB5Iq1dPEbG506meImJcHoZYXo2plRxP96SVQA+RHnnZNgUoU9pQI3pNzM7sfbB1CzhsBnrIQEl4mBWxpYcMoO+xIsa5KIe+nyNwse8ZirLPs2tAZiL2kQgH780+dgy1upH8SwNrNVp39IcfrTaN2jMlmXscqFVP3bIdETcLnlcc9rl7thEXaw/kOzUjbxcgLblC4UwaTASgpNYQBNWA9Cm/hZIYsA7Ixpc31zDjBku7CQPYDzZYuk0YgL7Xpgw9gen9S4cdzAFd9+DJ/XgwVyaTvto/l78pY/siUmyfSAOy5HLW/tLEjk3Ph/T18HcQ4boLd3eHxfqMvbhc/NSFxMau+zZzB9Rb9bUyd/FLbvb+8v8ue+0wuJdBNmzLBe9I63vLSkLJjC9Adk6yr1cRcCw6zH+R1wIpn6Ly93VENEYdGqpeFRq+ZNjrfvAQNxjpnqyQy2/90uQSL9LL4M22lFyvaiCMDiXIBAhwOwdNPl1I+8MvRGnyq1DU/viaTKjBU9QGyKZ81uhhltKQ7kPU3a+YbgyD5jM+E/gX3LdnKpebbZd13K781TsYlF5SXWZT6noSrUd2n5MXl5839D2KuVnbW0qIWRkLVXhEA9oO2hz8SQ3p7e7fSvMZl1S039nUVvbwIZf+tSMx4uLy8y8RFgT0B5x4OAs6jIZcTvH6rA/qUHE89PWZAy1BHyV2/RsuRS7OHxIl9fj2g6UI5rBY6ZN2sglWZPez0VbRulgrWnhRnOlypoQAZpX+GgWw494j5Ny4M8cNYZ51Pt1vQ1F9p7bVFrKD0U/Q4qvY5KmoqpUymOxWKUkmq8GmEaLhSwPGOoCGV7VYhX1yH8byJ6BsTgwvgTz/nti5bsjrn39+geU5BkB2q+zgxJNQXu/ACVMraSAfK9hXcyowZ7rzKTTVJFTL8Co8QtsQyHM6UQvoMcMn8Q5f+SDejNVAq9H7w76aY/PIrIKSN9t6WgpGfRPTHDvHAp8Sbv/evP7+h78aL9Jf1ShAW6T/PqDm784efEdXoMlr8lYyWptG+MiKMynvJddj0B8Y/IjkVsZW+fE1+WdH7kvy44/knwlTGss5cJv8oi/Jfxf2f7oPckM2mfJNdAulKuHJ2rpyCQWjQkwou8mrAXvkpLJ4baj1doVjIsiyVlzatnImiigejgK0Vpny09b6oKmBcSoQY8TUWKWdZi1XXutwv1hQwUt/MGJIETJVjSzdCyMAkedyFpSjvcmLmzdiADlFLDBchx1ho5FdWAlFy6fyzgV0iOF/AqnAas4iVkcwhfsfRlvYP/etEHbPPrVrjVZN2207Ib+ppduaoc3JJVHaGWNWkRuAeg/TnsSL95UwTSsGxhQLXhZlrqjr21byzECCphYveek42LMLF1zbhgpntG/43mXExcEr7sxuX6PomOGpCFcdC7hrDQYdKsg0qmdgu4/t5YTRmZKeHp0TPhNuNyd0llDQUPCvyxM/QqUskKtw3pkGfGgnqzFB6f60gZivIPASVipMLXjOzIYnbc4bPlD7n4Ru5mRuxvOOt869AeGst6eutVrCE/JfI8LoxcuUi0eI0btVnXF0eXZ6GXRfRqVjD69qpbc1XoJP5FeXBtE8DffHJ/9UoSGOpnvMlbppyjfrr6wNdq/noGV+Ql7//AtZIt8roJJQIeK+gtANQk3J2n9ElqDBg6WWCKDGEiW3ykU2mfjoauLXzcTIXc0Rtg28+0PpEhmHWU3A5lIJNVttB+KmXA+0WEJ+JmxONWXWM9Fd6hXij05zSRoZcnrEhs98tKI2dUG3D9TnDCLsiF2iRVE5JVPJNoyg6XJUpqFk3VIrKUON1ccoZPA5KMYa3UI0lsqS6pJIpSsq+J+x/F6lqyh/ypDlcDCLVDMZPEn3YtIa6w6ZV4JPITThijgdmZLliIK93u7C2Jx+lh0EcclUVQuw0QMw6kSlqMBbzbfEYK/eTNtHOshXbu3ocR47ypsnc/T4VUraeaJtWtenpsp5WWc5lY/E+LdtN7q0bHcg/1Qyd7eFHWLRrd6qmD69dtDMbyCist3oU2Lh1obLRxagTa+cotyVBxbZ34cethXQVGSuy/SY0iWU+d7BkGQTninTrdjqGG2mTffBfnx9+FppVZ0g1AaL8g0DSTVXXq2vGmH5d5aDJrSuRVv9su5lU1FJZ7HSXEIEhndae9Ej5XE1hNtnhqil9JExS6t62zMYMHarORSHt88awubcWTeqBHNC3jfGopnUB+puJbUjebnUwoGbtFOATacO7wUcQxPCTW4X9LzTMAUNkvkDQZ1qXfIFL51mg+chLsiuWkF2vcW8OJG3NddHo3C9nz4WdOtOIrdi5Yk1Tug5fc0htdVEkkR8owk3fdSF89JJ406enQyW7NLJVJNaAlUDRe6hEDv+p74qqEF+aaA52lFyp9uforV8XFJDEIly5Nwgcj+kZmpCpWCDoRlk2qyyGV7fWZUD17rIgGpd5NCe65SiaBPo6+RQM+hKvVfkcUzILfMx+sYMnst7vTmHis19cu2QYMH6gdjqhpDaEURZpNXuwxVr04jcYacRK0o1lqkKXnkcOuMFs7LVdHBCqAws2DAgRw4ILEBzm7N0ZAdh7eqhCLAX2dnl8slbvDjoHehf6a7SBduYUuMDsFO+Nnzi2q0P5oz1VAm6cv5spsgGdC5GXq4LJloXVRmCLFG8g9l8rE34vGml9y1BpcnvVyE1lps2IWDbr4brtzs0ViVpamzofTyyUB90WMly3ZC+u7ujXXgaYYt8rYvuKYpkU4Hm7L6yKErbEarYdhDWr2TrboYXS/5+D0hbgCxxJMdeuaUm/3iE7jVtaFdN/gEsbkc7xPLXgg/YHRpB70DMS/qcveq+GV7IUPUfxEzwcs1pl1sslSWUzEPHi3gCrVCzok1UeRSh3h7Eewv1Y/RM2ZB92HTfd61G8RFX/JXgbJX79uyQC5eIQGiuLfvTBPpo6kbkzJuOM/BjI4AMOqJ34lRJC7e5NdYOoQvp/XXrfqi0LI37Dz6qVLQIxRrA7Hmc/eidQsIytywYC1zCshfqRyXEWs0njYWehBjm6IepQU5b7z9/cdFhappM2K3HqfBsbSt3MQ0Nwe38Io9MX3+LGLdYAeYY1jYcNOucL70AfUKuALo+/Sd0BtjKO2S6T5VucRjAbsGESTC+z7//fq9vhdJkotUSZwCEnwZd05tdo/2kL8pLqm1qN10HOLVHJdwpNagOPdadUqLs1MZcV0rVEAKKud7iUxlGhLXZRXq9aPiZD28F8dFrAoBJSBGFuSRSye801ICWzK7sBxMZkZW3j35sgJbX415xH2Frwz8DypbczoOy7GU9OccFJ1htIomS382U+/uOlwCVlCKiOGakm/aCga8QAYekmhIclMLBnHTTpXwQM4r5gU1d74DxmS/na4wzYnzJqE+2KYP4DYynhInG2PZAhn8Mtgm/wo3byVATHfwbTvHF346rQEfXfvwNi1v0vi1TPqXs2T7Dy2F5jlgQaoxiHP2lbjei9iRu2Dt+A28IJfV8ZTijgpTc3LwktcaZKC8JWPYsrihTTQ+pvbznQ+/rbDStwII2pKYGu3gZbOTgexEwVVVOiqmNoP2wtAYs26nu+ffgsTS+3h5meJi8+GaqqpvhHcywbZQsuSzVMuTTMiUZ1PZll0kxyowBmdNGiBX50lDhnZ9lb5oY0t0uJNTI09X3eqZSl3aQ7lTCd1zeQBlqgdpEdGrQOxUMFPebbzrUTni5a+PEoCtEVlHXn+zk3RLbCLTo/X71WHj9XgfPK7katuvpgs5+SGGm0QgjLtawJmLrz/9uTfvHxJr2lIv8d7wj+VdcrbvGGsqGAWkjRxB3txnQnIoi8ppme0SucMlWbd5+H3sPoHthRv0CwG7MQS0HUniMw+ruoZtTM+9uKM7PG74PDZv7zN+2xqYrMzxrIW21CHOEdMucGM3ct7p/DytNiZPnknDMuWskE0C1+xE2wlujFgoIg7dTt4Wd+6MPXvg1wz5PT/rFYqqa9Caj9h+sUDaq7/F6LbhuzLE9fX1tBBEY9/gdJ0AauRJnfnXfk3HcU+otuOyu8Y593st8cU4+eEnzfGvkqS/6dbi9iOvV3gH9GL78nvv54hxZGkreOjEx9B5sRuR8GqAn4cQfIicLltzEjdSFWeXsZb8Z1Q0F2l5d2OnHlt74PuKpcaw/6xYmF+d7NdlU/rk9mqxD7LUs1xrtCTnz9Zmh36nwv9itzSKCevMTP3wT3HGTxnaVm8p2j1EjBRjPGeUflKUiC6o5nYhBFaBvysAlqQUdEQQGpMnaH2VjQ/uqql/5xEkqp2G09YXc7fPVq4vLbR2ahJax3qMwVpd94EDBO9dCriMtHklyIS254jNJUViMHNFa6ZzNa58N5Jc7pJet7qawqyP+1SHSu8t4ykoVOTgffr8mXDLRlODEWRhk675+Qp6/vaVVLeANju51ei6CRel9EveLYGTu6LFNdE6tn5Y4ZtzcOJX7ALzuUYrXc2N+CE/DR25udoRcreazGeh8I+ziLPvcjwUEHFA7nWswcyVKd3q8rT4yaXQj9H4Ez8Iw9h6k8vOPXsd40TXjuDiPl5HcOTrPVFUXR867wl0JuVc4xtX790wz+c6hoyTWp05x3IwqGzZmpQW19JGyxvqYd9JSaew84OR6i9/IlDiqyyXVj5OhN+yq76QrDQ+RI2KkNfJzJ0QpeU9Z2085rtw6EXRUO0bJ71oFVe+WQt7WTD7UWgM1yXODjaW2SaU4d/4oysWjmR1u8Ym6Jbx8Nf5+uZe1OQaGDqNPg8bH/i44LOJXt33HMk/fGxzy8+HcvUOeMy5VkyrG2asjMbPkd8pJ0pROh4FH9qfEgHN3Ztw4EqdCOLlHTMMYGDNtBHnr1idMlWDckWib/cYtCy5LuE3MAMGNPUzzfKBswYXRFNMtEhPQGN+sqOYCM3giHjwff5czQpGJ37nvRimTGc6hmvjmQo+kEYfVyfMun7MGbepQdOslzIBlQUVYJ8S3HZ5ejBQZejfX8D3OnVDila8uySv4qvyn3S8pl4aUYCkXESfDRDW2970R0pQ4em5m67GlXR4b4jH+kFqoapEtm+eUlDClIQQUOl+2MfyQrem04gVoQVdYyGVVeFzJ88iNdL9Aqzt8G6ZtFbj31RvLbYONGUmUsLVtMGzY9NDrmjSK1fPvMJoa0wyyiqmqcvcpzzE689AJ7yX71loteOn9Z20XuQrMaCJUqdjhgcb7e8t+5WKtNbJ+Xl5cNbitMenpcWR9u3peWf8PNTnQ73Qwef9bTUIAJn67ap6vce45JhT7nb+6vCAXA4Wqj0a2rrWhumQ3BgkLu7pq2FlSQ/o+/rCQWx1X7r2IKCaqzF3xNai421Y6Ai7E4TKiHs3Td0vwIYMjVJ73XMChdNgn0HbxED7jZRfKGXHiVamtxkEZeIKXP52S19FdNzmfqXa69+Un3z2nDURhssYtsKbvRfCpXxOIlbe2XZh2JW4cwRES9YqXmw6RrrqSLigXdBjIIJ0rnGB95RS0Hpm04O/QIb7+dHG3YKxUoQGUD8AOSArpBobPTkYkIq+KSVOWq+T+GV4VSeuAenAbA4c1Ot/ppUoPUXOVsMvBVoldYZpjFCRw089e9T1XaVNy21XWrfuiBYxig+3WFRtelKzDC7uJ9FliqTm4OJpVfvb5LXkeaiU+N8LpyhMusIAD88De3tbKuE++IN8NHQ1yOwpzI9VSbhhCBliDzSwWm9BHJm0yegQX3HZa6Flb5f4hlCa9gxllK/Jp1FwTfKLpYxTlh4U3WMwlqSiXU00r2JmOUVONU3vz90nYUC4vcVnyQZU+OXrdFrCXdRZBiuzRvjBVwDEil4W02TfuAyzJb41EU/K9KkGQ51wuTr59SbhiL8nE/Qfcf6ikYmW4Ofk2Hl+0rC6mgg4m56fWoTY1/LNLgouirwvl5KodfqWmOxs1WJUVU//TScCzbYNgQLuDHEVoUaWVu1uYfX7/B9VArn0C8Lfffn7/x+nHt99+63NuF1RTPnoml0rfpCxZ3nvB/mgX7EfYRp1gVKZWIkLNTtouJd1zQJl7LlYZTJip0iANZykFSM+VlAHjKr0XJBIfSAW0WFI+HE78YO8A9j5PDdRdn9Ql6qaZZLoUdlIaq1NXvmO9djaHWP8tTfaOtjUf+Zykhxa7rAeDDVSaUGyyrnsJ9S4OxJSPOppaUrM5Yg8lNdqNKELmdnlPXCgf3E/w/o4Lh3zQ/z8OV12rzH7y36McsbLnow+I7ETyUQ5HG8fdhZ9SR0ja2tjZnl363HYZ7W2WHfbJfIFut8HJ3R+ZbltW82PEw7Doa0q5cLxum7lcBplxcd6vbcNOXM4ctDCLtDAYzypsc64LpyIeQM8hideYbh2qj85UVTVy2xM1wE4e1rjpodh9gFv7bxDXqTvczGGa9UNxu6Ky/FcVj5qtcbPU8kMkw4OxGy68gZxpTM0ZV8myRI9lwSP2S6rlMOjw1FE3sqoLlUsYX314f0l+937UdVJqHJEvR00luPqPd+RLA3qkd2sjZKFhu1Nn3uSGnkN0RT62RWfRtK5OS2cJH9I+UJV6jIADWh/kONoH1UaCYw+GW6Yf0EAF1VWG3XJgM7gXaJ2wALkD2pTJptJuwEzb7WoDdEnttlb4ULgTkGxeUZ2qrKSDu6rpYHzxg6NPlA3SqZLALObJzwKDadoCqg7wdIatljKAVZN/ZIBa0+STMHzHqeTHC4PuBU/94ITObRU41TM50rKgDAejpC8/cbCNTGi89wBPZvXiJ3lr58nfdyYLZnVRmqR913vQHeTDIk93ALwQNLnEkAXIGZcJiyKHoHPkRstiWpgltyy5/JDFVKiloVX63JU+bGkX+aBniLowWXCZU5xwWYOuJqtkCe8D2DW7yQN8QUWOs8LrotbKqiJ9SAqhL34q0OOYHrbIdjeFmhVlDmY7wOnz35gsKnpbWJvKbbAJ2J1oARkehYrLTEhzmQ/pWphCTESROiy6Afv7jMCTdwbvwU7dC7EPO3VVbx/2zxlh/5IR9j9lhP0/MsL+ax7YVtWCTiCHSOmgpzfPZFE1ApXvySrDO9kCr28y6CVVI/isqvNo307LpGKWOgkpQOY5lBIDX1h634gsjE9IzLCDRrM81qQDnMeaNCvT1BlmkTLZlVVnMVWtss70gNsMIsQq6wyzXLDRrMkCvJH8VlKpDLAMh3Dxi+NKpkdh8Yuq7RxomcGtpqq6YCKDD9sBzhAkQbh6srLp3aIOsskCuW6KDDENprnljIoMBUSmoDOQbJUw66oPW1Kx+hPKSQ68FwW2Ac0C2beDyYO1T6zNAn0yqxe/5PFBm2LC7V+zNBpjpkg7K24LsFbJRbXJcs0RKjCdvsrNeB9/sllbPcBg597Pn9454oGj2pcFuO8mn66DXA/2lAvIYcOYYppjE/k0ZXH2JuAcuoEpeI1JikUWUcfrxU+lsfWgmX8i2EazLLAFn0IOM8ago7mCkicrGN2EzWWeU1KpshFgmMrB7QCczzLIJlWbJbVJZ/73oMcyyJMA1jDjxmqa3hOyhp1B49NQ52K1zsZrg53IdSb56jPz/RHPAN1qoFUGRdKXAuVCO59yvZwrbgo/YTY99BXVNMsBL0cKYVNAXvj59qnhcmOpTD7nuDR20uhUwwJbqOBnBeWA2iTHNb0e3dYkpwaLkxum6YddH9ppYBfMGS3L1HeAl6nDqm3roAxvEa8KppWqsnQlcoAzmGm8KvIkR4aORznYXN8kb89Um/QtS3ltas0TAxXUctskzz4TXEK6FjtrqCbpRJ0OLhbfpndrCeW7nhZToZI/5x3wDCn/zuZNLnUc0AwSx9nQGVBNnpsg1CzL0ZWzLBe4Vjq1AKsmzSzHNau4YTnEQmWyHNgccyAkWGyulBxuchnuG0CnzvjzUFOn48nlMrUFkqWiTPkB0MktUZVeM1Kaz4rIPK4Hw11K0OnfrLrwQ3mTg006mXoN1o94zXLIMhRuhpk4qYVBAJtaGtSFdyQlR5ca435ZsHmqOv8BaLitefJAQA26mmkq7aDnbgrIyyyA0z+9vhPZp09bU0ATANZqVlBTJxwY0AetaWqoGqjIod9pYMgH33U0E/D0THaQ07Zw7UFWusyAcXpHpsngGzbeN5whH8BA6kQAP/A4g3Fi4Ev6AxBr0JoMagZTyvBZBsFr6tReNqNZjnugWZlckTaaxbriJgBs043Y6sNsTPKumgsmUxdKRKfFPhSob9KZmnw7s+mPlQeaPqLXzfRMDXdVJ+/W2pSTLHnojRYZ3sLGgC5KnrrqPcvYijYylIMNlhlLq9Te4EXBpbF0mkEzWHBtc6jhi1pmaN1klW5kSjdrrC1apKPoaWMV+dhIMli6yx7JOCzvMxW8JGcaSm7JGdVl6GZosP17HB0/OSsjl8YmhCIYHKJPsL8BU4LESnW6fAgu83HubVULtYLBYMG9/JuqJllT7zueMcdD7zPCeWcaZnBLKrrdaGEdi5WzZnsYSHYkBTc4nKFdPWw9NlAipqlrpS0ZNh4lZDmnlnBLag3TsaPwgLTc+wyhiDE+WB0dCoTL0Nl9pC+04DL3RP4eqm61Pp6GWDUDOwd9sv68matm8KIRImEBuhtHZBWpqTZA3oOlOBHc31XaseD5OzUzry592esLch5GfL0kdh6ZUoTNgD9CGH2MaEvyAewf3Eow8X0eHuoszJviyO7uFuHinlgDVLP5CZc8ih/O3D1Cf+0t8YmzMDAZ4pWgjcRZv7MG57i2TdzjDdy3+rXvoCl/O+6Opq4Jd5hfPGLsu40oEtY03a3zKi5LruHW4q0YcxccYxr1iEBaD677gBOqpRiZeIndczOOA8f+uQYs0fClAWN3NO0+PFv5/r3yvcqAY3n8ql5ib3ukurzTTXfKLpw8Rhgb2/g5dmg3b6KUp5z9v3++oVvs4rwVCrh2/Gyg1ZAuifeeR9g9LhNqgPh07Q4bMrhV3S6FbzwOvrIbBd9hrrRvXx9lIyHUEAOA487o7nlVmkpD2RHG+w46TPulJaq960PDGo0T0HYhXYOuuFc3joX0ekk/mIMvuIAZEAELEIQaw2fSb9x6Xn/86GNL5keU37j+jpM+eZRJzw6zRvIvDWyPSaTxy9fD97COiYdNQWk1Gl76C8mUlIC5FWTJ7XxMUBASqQzpNHYNB5UX3du0cOxEedI9UULNOKOCOAxGTB/E4nGxw6VGxjQ+Hu/q+crE0eulsy3VVlZr6geeCk5NMVfZbQJvxHXmGs5SWQ81clKxP4In3g+A+EvjsMU3LQxiYQKoPjkVRjlDfOO+nWOwnPwWvnFCTuWq+9cAukVb3khLaHnCVFU3FnRcDGdx4zvC8pln32zvBc5Y3NgQbv/evP7+h7862/e8tx0tx76Joh3OaZE2YnZXxw1dgSb/1PnkzKuABiIXv/Wp63/yn3m5xnnj1O/cjwOTl/fJtmfbA1PcOifkw+/Xbx3toME7T9BfWnLDNNRUspXTKoN6JrZzQQhy6CW5fv+GXEj74+uX5OLD+dv/fEM+XUj7y0/k+XK+IhK4nYMmbK5MGJWmtAZm8VM//PK//tuLZ1GOgJ1nlHHb/ECZelLR+Dgek/n03fOaX/mzeNEiFb/i5dNCui+b9mB+YMO4Oz/wMXy3FNO1dfKZa9tQQd6dfogi+6eSkM+XddjJ+D9Kwkmctw7dr0aEIiH7hSduwVN8g3fsw4xaWNJHGJGOp/uSnJalRj+tP+UxdLqnl1X1oXHOh8ZCLs7eX/pXaTQ8VlFzxOjHhlPJa6rh7SYXlw6VEe+X4+GBkyCS8NCtPc7DVhMr/HSt4wqIHrq0LLn7MBXrgG1vln/8nTviAXAmIV5wFW74+eYRGKCyzrXOotfd9Umj5EPA8FJp24nkgdAtMcCGG8Dtar/kNUfmvaeHy1n7mLRkvR9jvISY3XgsL27ADi1faoxi3Kmc3m800HGIk8uayhmcdKYTU3LKZ42GkkxWCBNkiVlDcTlTH9h6YFA0OqItRxedZuh3IBLq/v0SruQOAA2VslCEzO70eUbpWVtKU9DCp+JnAF1bnQf4NMORmGaoFhY5rkOu/id1BqbSsmg9cfnU8m0L3tFxsr1a35nwCBrsWzsHLcGS61UNL8mn9hl7hw6wH8ll6wAbvAS/j2lq7aieIygTI6Zxi3Twi78kVIioMlGvP4gJblRjYt4CtHsDubSKGIuPOZfk08WoQGGYIJtNXiUX2Q6oqjOMfXOANZjUGb0ObIYSF/8ipk5FR397Bmz9aIVCgJwlnxSJODvlI6MWOqKBepWHil4ARhKG6QRTQsmvSi+pLodzugk5nWGylybU3fhbzKWbgF0CyLjqmbhr4n1j3MpS0Q/VeWQItozHzIgBhVyGPFdMS6i4dWIpjNiIk7gQVB4jjn8HB2WbINJzUQ4I3HRZriMpC2fBztCA3Xx5UkcqgWEXgkW6fnB3i9hTbTlrBNUE+0WTFonnb2/fvFMzNZ3Gp78DK+wcsm/vBrLXbkF/G3t4v3V4O3RPGzsHaUOy+CjapknZOeFuCT1+yXHUPxnQowirxjJ1XE6HJccRvmoYA2NGcMbO44c1Rzss8QTxIk7FnSm9IpHChAFuxxBOGzjCFo5OKmGAz9RKunfFya2Ycth9kQwUpU2qFun60Y28m5T4rqVYMyA4lB09wQ+zpQ9zSQy3TUR+EiwugCCiA9Q5NYSWqnavi50D10Qt5XrLPOMsvVVSVSN5tTiTw3Dfov64SoRT7rksnfxR2nQMoORXLoCcBsROBmy4i7NXdoT5OzmaMN7R/yjpCqMsuApZC2m5EKMxwoiU9e4PYITP17sK9RqpOTGeEDpROasHIsRPYE4XXDWoXTJV1VpVfCRDEY6N3FtJJwKLyKbkbDduXC46sZMRyW0MN7ROEkVgA8Okw2UOQDCyfodf7t3tvbLr+zZ67NZllo202+VsqTX6EsvAC3aIWX8nLQjf4xlI0Jy1JCFDMNFvO7WA2zk+tbHZbiQge8J+ODFWjwc/W5oOabv1aDS93k1TUC/8WhnpipqmnRFueQXGyXWv7WmoYTSIFHYhWVOIvRuBjQcfuA36jkfrkN7dj3a0frwbTT8UJtmQ0zuTFhzG+ygc0IYUrwXCHYTB10vd673U6aPunb9oSWjT+3cuWS/V4wiQPXK8EyBf73H8cf+WpRptcJwtu5t81EeVICnv2B3kx1GPY0raBoexU+qxBG3LT528cqex86ICO1ePECWhG55k4tEIHxvdcOylpFVWr9OOqM5HJYK/1iGy41xm8oT858nP339Pnr87P718Qc65sVzOGm7mUGIpfBQXoWYqe1+gXZEwzJadejzCNuMHRzLGtMrsVdxV/+l2NYZBd2PQI59s6PN9rgvDtP+u7rfn+EOcYjFTKmNt0teZYlSk6k63RchHWvLG+BWI0sTwiguqvXhyYtPdIYbvery8Cu+54eUxO430M+U/uYPQehG3+mKuL3m+OotTueuuY1gjVBr2/L/BSYS/GZyF4LiBXllGGXdlKp0zMWAQskFWKz2jkv+5I6ta5jsKd2X2AZzun6kRdk+5jtaSZur686tbDl8L3+LL9y7ayGr+Daiwc0Y1kFpDqSouabTgrieeLqnlIK3Zmx4v6DGpfUcflVjf+hHqTAfXXZ1nTnDVVFtshrQmdbdYPWKzoyBs7iJRp1CCphbKIllS2Y7z4YTPr+2KXfDsUqsFL7vmYeFztK5F0FQHByM0/3HP2qZOG1dw1kTy8khUdkuGXn92NUJmdHgoZk4uuI+ez7cV95EWcJ3SmXIo+H01T7hFnan3pV4l9CxCqNdRUWOlhhirtJf4DloFluJqz/BTJ+5Tz+LUV7wsBRxPyr3H9e4q5yLb25N7B8m5djzGcci9DKv1OgzJVRudfUlqQd2WufdZaQKS6VU95uXHVMgj2JN3yKDTnW35mzKWvKdszuWISVfSTJLjm21ef5KY6V9rcOLD6Ue+yZk5Ie9KWpPP+A+vH5VK+rrTvw8fTzKnC3CakwCqyZcG9IpgD0JTK2mg1ajixamO3gK/cxx5GXrgMQdZ87YLpPTk+75843i2JB0B1fUB+hiao94VU5zylNdhtn3G29bSG02MnG0YHl5uiG6kjNqx5mX38vjIs28jNVJjFyAWwcLMvxGULLks1dIQUwPjU87cb17G6gRDnuzwgjjyPL7rnBvyHDvCgmTrZwhDly963CKNxHf8HcwoW5FPZrPxbReBrbYLaZNn17oVjmCwj7z2fVMLUcFaNTxk7kUccLzrAxCp/t+oNMVyniH7NsnOr1CPdef16nWEYqQwetDCdw4g9jh5vWOkhgzf4HpvZd1bJH28C+iQmuM47LqAweberBMy/TYMdijekGJ/8TOWDaQcCTha4YYklzDlMvjqUThhV7+K1iNNBxG7gwrFMuG2dsBsqX+pBWPns81Ne+ilNNKbsvNhW0vZvDpyC/z1qshwMrCO+tuRZcjLhMt0E8SS3g1HMhYV5n08I0KqX7aD2+LbaK/L+yNTOwdY53379mBdU92eKffjl2tSlnM+aKVO3O1wtqxPfr8TeTb5zBLf1kLpVb4N/5upqfyXvR1jWkQ2u6i36nnsaXJs+dsrhL6HtkdTiQZUtf3Wd1M1egoKkFar+hDRUapmMnAu3OmMhzWdtQ17yhEQR1/dcdx7eKaqmspVdx/x2uE4fW+vLEC7Z6jgcqriSgE1N7lrhPbIjy0rssVsCXm7ok+/5MoR+LURYkX+o6GCTzmU5Bzrnr1zMIrKEiYFU+qGP1LQ/Q+YEL/+2n6mYkybT95tdh0OrxuLKveBI0z33/WP3RJhyk5wR3uf/Am5XtWe9LXnwDHH7+D45mmYFkmbyW6h7XDwjgj9zMTa1m4jcwxXXadcbmLnPYu10q23H0PMH9+NbHmvV07i49Tyos47h2gHK9zKez33LZpaqUyayCZSbh23H6SmNu6aZLKgJmW0vwdYh3L6xJAbLRJucw9qwl3pjNGi0am8IT2YBnRBZ+lsyjXo5M/TJuik6Y+boMOpzyBY4NaCRNUqvXHi4Cc7zZ2iN9ewlSqTWqPySxyjlnBD5l7jsqhevQp/PwsovAp/CXlNMbc/FaDj2XmBnEeMnnti+sFz9Lj2Rq0NyCnDQDRnUnE5Ba1H4q5Duo9CV1/x38v6qHv2CEi2fYmnvW2IXCkMa6usVyqyxNGO31sft3fH7hoziHX/R/8OwwSt8YGfvJ6DPo4/wunsIePp+RmOfnxBznD9OGqg7ZGapYzw+Qx0GP4JG1mYO5rzQtbQcY+RvQ13iz4zvU7RO3ea/3moV/L+rVHiu02u+J9xbw2/ySRTLv79LZEwU5b7Dazn1IxMgDLs2G2FelvpFx8fLui2OtsEqEGCy9YZaxunt/U38YQUw2fHqKjY7G/UTT28Hh207KQJN6ZJrnQiZEyWyuete1gMBTEErbP6QAeb0peeb93i5AqD07uk01EyJLrO4CGK/PwKUzt3P0Y96XkYkveXnjtwHBehxohikfNF3w6pBkd2FJmycEePNsnbNJpcgPkNBIs6U3ODb9bjSvoPEsrWn4jBeJ3S5OLq9N/fX5JL906R3+XI9JU1tpkqqQ/B9nqp4tiiGGJzYDfmICfy3YRw3h5ksaFzXb/OrkUYpoGGEYRrKbhDywXNB00hH0HJ9Xh0XUFGjQbE2VLbHG3CZx/LBRW89AcxgsS2IDxaV+tdghA5dgMrsy22E538NoE0Mey5tbUpOM6gzQIatzIHQxh9AreJz2Rb+aI0t6s9N4qpqsraJ+6OeHs8gkMoXoK/5BrEtqWZ2sWyFFQWxjzWwFu3spfhfwRq2xqtKLa+1LioFT9GWnUMYY8BQQwQqbg1gGxlcyrloHFG7nZTYVVEZCRme6S2zd3DEmYe/vHu9EN4915tLd89KFbpbd9/8p5t3NwUCyWaXAw4bec4yzDnppuM3Y7zbSS3hjz3SJgX2K0DC3vbibpb4AkiHaVGNJmk2buA6yfJbUgXONksOliAxkyBaSMIU5JBbZ2hfOX3cKS9wnKZU/p6xjuDvR2h7RCtlbZEOf7+9q+nsRTcKNtTnzulZ8dPsNwuMNhwsU6ob3YSbRTzb29/v7y4JO/pbcVl2Y31jm+ro+3oaZgbQxRHyApkDKjbRVanPsVLFpOnZ/sqx2J6vILNxy7Cb0nOrnZsOMuCVL44D116AxY7MRTH25RH7hXQUlz9l68b7gpzZDnUJFPfbvSXOBP6kbIbw7hqtOK7oG7li3tfEtNEUtSpIX8zVis5+5eJoOxGcGOh/Nur8LOX3W+5nAKL/2rKNSypiCoydCJ63yFUlsQoMnIsNcy4sXrlLPtjCoua2nlo1t/hQLZxGCCJTqljoekLoX29FlO614W80yc7zEFavfrL/w0AAP//w/8Rig==" + return "eJzsfV1zGzmS4Pv8Clw/nO0JNz3t/tgb3+xeaCX3tm5tt9ayuzcuJqICRCVJjFBAGUCRYv/6CyRQxSILRUoUQMl754duWyITmQkgkd/5LbmB9RtScaaVUTP7J0IstwLekPe9H5VgmOa15Uq+If/yJ0LI5tfkvSobAX8iZMZBlOYN/tr9+ZZIWkEP+KSEGcgSdEFt3X2MELuu4Q2Za9X0f6pBADXwhkzB0t7PS5jRRtgCl3tDZlQY2Pr1ANf2j8eUzJQmXM7BWC7nPUIuAnbk7NPVpPfFXbr6tAlq7Oe6pBY+8Qq2PtLS5X6584s9OLo/nxaA3yJUlsTyCshzLsnnT+cviF0AoQK0JStqcHXS4PLlBuMoohqMEksos6LJJVktOFsgmsZS2xiiZjtIswWVcyiJVeTZx4DVswPYc8l4CdJellHcb2C9Unr3d3dA/zLAJZcXLaJnDtGD6Czd6ZlTBzs9Tj3gDjENwm2wY9hRCF7b4dY+EEfWaO3Y5vYYWs5tIX4AQWoMn0soP6l0iP26kqC3ztsBJPwJTYfAdQ2MzzgYxKDPo517MCFXyhg+FUCWVDRgCNXwhjz7LG+kWslnL8mzD7By/7uUV1rNNRjzDK/ZnW8ME47FM85wN5LT6MHel6ifnay+UoZbvgT3g0+62fz7AEUlWNAVl3kICpu2tcidyPug7NmSckGnAkk6q63733sqVlTjT66BNZrb9RVoo6QE0f/hJ/8MuR99lisqLZTXambb7/5qF6APccYuNFD7M624WH+gI/L9yLvuIJMZgj70wkwp+zf3hqdF4bMB7XWDXUGI27IfJ1g68c5gUqqKcpkWswuEiSs9BDVen5Wlu+FRzHh9P6Qurwj14NwjgKLCPcv3RYrS0jE+5du2eWIbt6UPwo4x1Uib/qDhXqbCEqR1F3xdJ3583dcdku1Cd0TH0XOlnSZVU5GWdR1Yck8GtkhKsCulbyZcWtAzymAitxFUS9Arza2TdrqBgfEwRPt4M+FDj4aAGOkQI6sFaMDfWU1nM87IghoyBZBETQ3oZV8V72SjofcgZtcSOkDK0D7ZqIHWnWmxRd746mPr7zeBKjPfORD7VrjHOfu04MZ9jnDjzhIKV0Zr2wT+a7oiFRhD5+7f1BKmKnBizwvhwSl9p+bkApgqQccJ8bD4LlLHkrO5gSBt4UhLDDggnJn7geVBqVXSgrSoznJpLJW2RcPEdZOhvXkXBA9Zo4gd9zih6UltMD0pMWCM094W3BpCyQewv3Mr3YsYdn8SEauBWLNQjSiJhCVoMoXu3NVUGyDvwVKHGiUzrareUs/fqbl5dUXZDVjzYqgpcA3MivVLYgPelHwELyz8CZc9NCdxTwMsQRzBSaHk7v3c4uQF1BoYKi8OkxJmXEJJlBSIlnV6LaloHceqMvMi2YXZs8fvwz2/vPjOq9/+xqPxvtHe4ZYyS4Sa+/3Sg41A6jjq9v604OfcdtRUW84aQTV+P2zsZPRkDEAfdVJiJ2MAefykjG7J8rR78vr/78n+PXGr5tmQh11fNf1HgYTsbsuTwW5JjxF62VHTYFSjWaa39+Fsy3X/H4YZugsrkPYpIkebktsC/WZPET2QVq+fImILp1M9RcS4PA6xvBpTKzme7kkrgR4jPfKybQZQprShRvSamJ3Z+2DrFnDYDPSQgZLwMCtiRw8ZQD9gRYxzUQ59PyfgYt8zFGWfZ9eAzETsIxEO3pt97BRqdSP5lwY2arTu6A8/Wm8btedKMvc4UKueumU7Im6WPK847HP3fCsu1h7Id2pO3i5BWnKNwpk0mAhASa0hCKoB6TN+CyUxYB2QrS9vr2HGDZZ2EwawH2ywdJswAH2vTRl6AtP7l447mAO67sGT+/FgoUwmfbV/Ln9RxvZFpNg9kQZkyeW8/aWJHZueD+nr4e8gwnUX7u4Pi/UZe3m1/KELiY1d913mDqi36mtl7vKn3Oz96f9d9tphcC+DbNiVC96R1veWlYSSOV+C7JxkX68i4Fh0nP8irwVSPkXl7+uIaIw6NFS9LjR8ybDX/eAhbjDSPV0jl9/6pckVXqSXwZttKfm0roEwOpQgUyDA7QI0+Xwp7Xc/EaXJz0JR+/1rMqUGT1EbIJvxeaOHWUpDuo9Rd79iujEMms/4TOBfcN+eq1xutn3WcbvyV+9gUHpFdZlNqetJtB7ZfU5eXv22pe9RzM3a3VJCzNpYqMIjGtB20BbgT6rxzHP/VprPuaSi/c62tnKAD7n0rz2JEZdXv/0UYUFAf8CJh7Ogw2jI5RSvz+agDhXHY1+fBdAS9Eli17/gUuTy4iFRUo9vP1iKYI6LlT5pJ5tgRXY/G20VrcuNooUXxZku50oIYFbpr1EAO+49Qs6NO3PcEOZZ59P9thTVd2pXbSF7GP0ELb6KTZ+Kqlopg8lulZJkuh5sGiEavjRgrANoeFWLddgn92EsfwLKFsTwEsjzvxC70A15/eOPL7A8xwDIbpU9nHgSyusdOGFqJQ3kYwX7ak4F5kx3PoWmmoZqGV6FR2gXAnlOp2oJPWb4JN7hKx/Em7EaaDV6f9hXc2wemVVQ8mZXT0vBqG9immPnWOAzwu3fm9d/+e6vxov0VzUK0Bbpvw+o+buzB9/RNWjymryVjNamET6y4kzKe8n1GPQHBj8iuZWxVb5/Tf7ZkfuSfP89+WfClMZyDtwmv+hL8t+F/Z/ug9yQbaZ8E91CqUp4srauXEHBqBBTym7yasAeOaksXhtqvV3hmAiyrBWXtq2ciSKKh6MArVWm/LSNPmhqYJwKxBgxNVZpp1nLtdc63C+WVPDSH4wYUoTMVCNL98IIQOS5nAfl6GDy4vaNGEBOEQsM12FP2GhkF9ZC0fKpvHMBHWL4H0AqsJqziNURTOH+h9EW9s99K4Tds0/tRqNVs3bbJuQXtXJbM7Q5uSRKO2PMKnIDUB9g2pN48b4SpmnFwJhiycuizBV1fdtKnjlI0NTiJS8dB3t24ZJr21DhjPYt37uMuDh4xZ3Z7WsUHTM8FeGqYwF3rcGgQwWZRvUcbPexg5wwOlPS06NzwmfC7eeEzhIKGgr+TXniR6iUBXIdzjvTgA/tdD0mKN2fNhDzFQRewkqFqQXPmdnwpM15wwdq/5PQzZzMzXje8da5NyCc9fbUtVZLeEL+a0QYvXiZcfEIMXq3qjOOrs7ProLuy6h07OFVrfSuxkvwifzq0iCap+H++OyfKjTE0XSPuVK3Tflm85WNwe71HLTMJ+T1jz+RFfK9AioJFSLuKwjdINSMbPxHZAUaPFhqiQBqLFFyp1xkm4mPriZ+3UyM3NUcYdvAu9+VLpFxmNUEbCGVUPP1biBuxvVAiyXkR8IWVFNmPRPdpV4j/ug0l6SRIadHbPnMRytqUxd0+0B9ziDCntglWhSVUzKVbMMImq5GZRpK1h21kjLUWH2MQgafg2Ks0S1EY6ksqS6JVLqigv8Ry+9VuorypwxZDkezSDXTwZN0LyZtsO6QeSX4DEITrojTkSlZjijYm+0ujM3pZ9lDEJdMVbUAGz0Ao05Uigq81XxHDPbqzbR9pIN87daOHuexo7x9MkePX6WkXSTapk19aqqcl02WU/lIjH/bdqNLy3YH8g8lc3db2CMW3eqtiunTawfN/AYiKtuNPiMWbm24fGQJ2vTKKcp9eWCR/X3oYVsDTUXmpkyPKV1Cme8dDEk24Zky3YqtjtFm2nQf7MfXh6+VVtUEoTZYlG8YSKq58mp91QjLv7UcNKF1Ldrql00vm4pKOo+V5hIiMLzT2oseKY+rIdw+M0StpI+MWVrVu57BgLFbzaE4vH3WELbgzrpRJZgJed8Yi2ZSH6i7ldSO5OVSC0du0l4BNps5vJdwCk0IN7ld0PNOwww0SOYPBHWqdcmXvHSaDZ6HuCC7bgXZpx3mxYm8rbk+GYWb/fSxoFt3ErkVa0+scULP6WsOqZ0mkiTiG0246aMunJdOGnfybDJYsksnU01qCVQNFLmHQuz4n/qqoAb5pYHmZEfJnW5/ijbycUUNQSTKkXODyH2XmqkJlYIthmaQafPKZnh951UOXOsiA6p1kUN7rlOKom2gr5NDzaAr9V6RxzEhd8zH6BszeC7v9eYcKzYPybVjggWbB2KnG0JqRxBlkVa7D1esTSNyh51GrCjVWKYqeOVx6IwXzMpWs8EJoTKwYMuAHDkgsATNbc7SkT2EtauHIsBeZGefyydv8eKgd6B/pbtKF2xjSo0PwM74xvCJa7c+mDPWUyXoyvmzmSIb0LkYebkpmGhdVGUIskTxDmbzqTbht20rvW8JKk1+vQ6psdy0CQG7fjVcv92hsSpJU2ND79ORhfqgw0qWm4b03d0d7cLTCFvka110T1Ekmwo0Z/eVRVHaTlDFtoewfiVbdzO8WPL3e0DaEmSJIzkOyi01/ccjdK9pQ7tq+g9gcTvaIZa/FnzA7tAIeg9iXtLn7FX3zfBChqr/IGaCl2tBu9xiqSyhZBE6XsQTaIWaF22iyqMI9fYg3luon6Jnypbsw6b7vms1io+44q8EZ+vct2ePXLhCBEJzbdmfJtBHUzciZ950nIEfGwFk0BG9E6dKWrjNrbF2CF1K76/b9EOlZWncf/BRpaJFKNYA5sDj7EfvFBJWuWXBWOASVr1QPyoh1mo+bSz0JMQwRz9MDXLaev/5i4sOU9Nkwm4zToVna1u5j2loCO7mF3lk+vpbxLjFCjDHsLbhoNnkfOkl6Am5Buj69E/oHLCVd8h0nynd4jCA3YIJk2B8n3///V7fCqXJVKsVzgAIPw26pje7RvtJX5ZXVNvUbroOcGqPSrhTalAdeqo7pUTZqY25rpSqIQQUc73FZzKMCGuzi/Rm0fAzH94K4qPXBACTkCIKc0mkkt9qqAEtmX3ZDyYyIitvH/3YAC2vx73iPsLWhn8GlK24XQRl2ct6coELTrHaRBIlv50r9/c9LwEqKUVEccxIN+0FA18hAg5JNSM4KIWDmXTTpXwQM4r5kU1d74DxuS/na4wzYnzJqE+2KYP4DYynhInG2PZAhn8Mtgm/wo3byVATHfwbTvHF346rQCfXfvwNi1v0vi1TPqXs2SHDy2F5gVgQaoxiHP2lbjei9iRu2Dt+A28IJfVibTijgpTc3LwktcaZKC8JWPYsrihTTY+pvbznQ+/rbDStwII2pKYGu3gZbOTgexEwVVVOiqmtoP2wtAYs26vu+ffgsTS+3h5meJi8+GaqqpvhHcywbZSsuCzVKuTTMiUZ1PZll0kxyowBmbNGiDX50lDhnZ9lb5oY0t0uJNTI09X3eqZSl/aQ7lTCd1zeQBlqgdpEdGrQOxUMFPebbzrUJrzct3Fi0BUiq6jrT3byboldBFr0fr1+LLx+rYPnlVwP2/V0QWc/pDDTaIQRF2tYE7H153+/pv19Yk17xkX+O96R/DOu1l1jDWXDgLSRI4i72wxoTkUReU2zPSLXuGSrNu++j70H0L0wo34BYDfmqJYDKTzGYXX30C2oWXQ3FOfnDd+Hhi185m9bY9OVGZ63kHZahDlCumUmRjP3re7fw0pT4uS5JBxz7hrJBFDtfoSN8DaohQLC4O3UbWHn4eiDF37NsM/Tk36xmKqmvcmo/QcrlI3qe7xeS64bc2pPX18bQQTGPX6nCZBGrsS5X933ZBz3lHoLLrtrvGOf9zJfXpAPXtI83xl56ot+HW4v4nq1d0A/hi+/536+vECWhpK3TkwMvQfbETmfBuhJmPhD5GTBipu4kbo065y97LejuqFA26sLe/3Y0hvfJzw1jvXn3cLk8uKgJpvKP3dAk3WIvZblRqOdkHNfnxn6nQr/i/3aLCKotz/x3TfBHTdtbFe5qWz3GDVSgPGcUf5BWSmypJrTqRhUAfqmDFySWtARQWBAmqz9UbY2tK+q+pUnTlI5DaOtL+Run69fXV7t6tAktIz1HoWxuuwjBwreuRZyE2nxSJJLack1n0uKwmLkiNZK52xe+2wgv9whvWp1N4VdHfGvDpHeXcZTVqrIwfnw6yfCJRNNCU6chUG27usT8vztLa1qAW9wdK/TcxEsSu9J3C+CkbmTxzbRObV5WuKYcXPjVO4j8LpHKV7PjfkhPA0fubnZE3K1ms/noPONsIuz7Ld+LCDggNrpQoNZKFG60+Nt9ZFJo1uh9xN4Foax9yCVn3/0OsaLrhnH5UW8jOTO0Xmmqro4cd4V7krIvcIxrt6/Z5rptw4dJbE+dYbjZlTZsDErLailj5Q11se8k5ZKY+cBJ9db/EamxFFdrqh+nAy9YVd9J11peIgcESOtkZ87IUrJe8rafspx5daJoJPaMUp+2yqoer8U8rZm8qHWGqhJnhtsLLVNKsW580dRLh7N7HCLT9Ut4eWr8ffLvazNKTB0GH0eND72d8FhEb+67TuWefre4JBfDOfuHfOccamaVDHOXh2JmSe/U06SpnQ6DDyyPyQGnLsz49aROBPCyT1iGsbAmFkjyFu3PmGqBOOORNvsN25ZcFnCbWIGCG7scZrnA2ULLoymmG6RmILG+GZFNReYwRPx4Pn4u5wTikz81n03SpnMcA7V1DcXeiSNOKxOnnf5nDVoU4eiWy9hBiwLKsImIb7t8PRipMjQu7mG73HuhBKvfHVJXsFX5T/tfkm5NKQES7mIOBmmqrG9742QpsTJczNbjy3t8tgQj/GH1EJVi2zZPGekhBkNIaDQ+bKN4YdsTacVL0ELusZCLqvC40qeR26k+wVa3eHbMGurwL2v3lhuG2zMSKKEbWyDYcOmh17XpFGsnn+H0dSYZpBVTFWVu095jtG5h054L9m31mrJS+8/a7vIVWBGE6FKxY4PNN7fW/YzFxutkfXz8uKqwW2NSU+PI+vb1fPK+n+o6ZF+p6PJ+99qGgIw8dtV83yNcy8wodjv/PXVJbkcKFR9NLJ1rQ3VJfsxSFjY1VXDzpMa0vfxh4Xc6rhy70VEMVVl7oqvQcXdrtIRcCEOlxH1aJG+W4IPGZyg8rznAg6lwz6BtouH8Dkvu1DOiBOvSm01DsrAE7z86ZS8ju66yflMtdO9rz777jltIAqTNW6BNX0vgk/9mkKsvLXtwrQvceMEjpCoV7zcdoh01ZV0Sbmgw0AG6VzhBOsrZ6D1yKQFf4eO8fWni7sFY6UKDaB8AHZAUkg3MHw+GZGIvCqmTVmuk/tneFUkrQPqwW0MHNfofK+XKj1EzVXCLgc7JXaFaU5RkMBNP3vV91ylTcltV1m36YsWMIoNtttUbHhRsgkv7CfSZ4ml5uDyZFb5+W9vyfNQK/FbI5yuPOUCCzgwD+ztba2M++QL8u3Q0SB3ozA3Uq3kliFkgDXYzGK5DX1k0iajJ3DB7aaFnrdV7h9CadI7mFO2Jp9HzTXBp5o+RlF+WHiLxVySinI507SCvekYNdU4tTd/n4Qt5fIKlyUfVOmTozdtAXtZZxGkyAHtC1MFHCNyWUjbfeM+wIr80kg0Jd+rEgR5zuVy8ueXhCv2kkzdf8D9h0oq1oabyZ/j8UXL6mIm6GByfmodalvDP78iuCj6ulBOrtvhV2q2t1GDVVkx9T+dBjzbNggGtDvIUYSWVVq5u4PZb+9/pxrIJ58A/Oc///b+97OPb//8Z59zu6Sa8tEzuVL6JmXJ8sEL9nu7YD/CNuoEozK1EhFqdtJ2KemeA8rcc7HOYMLMlAZpOEspQHqupAwYV+m9IJH4QCqgxYry4XDiB3sHsPd5aqDu+qQuUTfNNNOlsNPSWJ268h3rtbM5xPpvabJ3tK35yOckPbbYZTMYbKDShGKTTd1LqHdxIGZ81NHUkprNEXssqdFuRBEyd8t74kL56H6C93dcOOSD/v9xuOpGZfaT/x7liJU9H31AZC+Sj3I42jjuPvyUOkHS1tbO9uzS57bLaG+z7LBP5gt0uw1O7uHIdNuymp8iHoZFXzPKheN128zlKsiMy4t+bRt24nLmoIV5pIXBeFZhm3NdOBXxCHqOSbzGdOtQfXSuqqqRu56oAXbyuMZND8XuA9zaf4O4Tt3hZo7TrB+K2zWV5b+qeNRsg5ullh8jGR6M3XDhLeRMY2rOuEqWJXoqCx6xX1Eth0GHp466kVVdqFzC+PrD+yvyq/ejbpJS44h8OWkqwfV/vCNfGtAjvVsbIQsNu5068yY39Byia/KxLTqLpnV1WjpL+JD2garUYwQc0Poox9EhqDYSHHsw3DL9gAYqqK4y7JYDm8G9QOuEBcgd0KZMNpV2C2babldboEtqd7XCh8KdgmSLiupUZSUd3HVNB+OLHxx9omyQTpUEZrFIfhYYzNIWUHWAZ3NstZQBrJr+IwPUmiafhOE7TiU/Xhh0L3jqByd0bqvAqZ7JkZYFZTgYJX35iYNtZELjvQd4Oq+XP8hbu0j+vjNZMKuL0iTtu96D7iAfF3m6A+CloMklhixAzrlMWBQ5BJ0jN1oWs8KsuGXJ5YcsZkKtDK3S5670YUu7zAc9Q9SFyYLLnOKEyxp0NV0nS3gfwK7ZTR7gSypynBVeF7VWVhXpQ1IIfflDgR7H9LBFtrsp1LwoczDbAU6f/8ZkUdHbwtpUboNtwO5EC8jwKFRcZkKay3xI18IUYiqK1GHRLdh/yQg8eWfwHuzUvRD7sFNX9fZh/5gR9k8ZYf9TRtj/IyPsv+aBbVUt6BRyiJQOenrzTBZVI1D5nq4zvJMt8Pomg15SNYLPqzqP9u20TCrmqZOQAmSeQykx8IWl943IwviExAw7aDTLY006wHmsSbM2TZ1hFimTXVl1FlPVKutMD7jNIEKsss4wywUbzZoswBvJbyWVygDLcAiXPzmuZHoUlj+p2i6AlhncaqqqCyYy+LAd4AxBEoSrp2ub3i3qIJsskOumyBDTYJpbzqjIUEBkCjoHydYJs676sCUV6z+gnObAe1lgG9AskH07mDxY+8TaLNCn83r5Ux4ftCmm3P41S6MxZoq0s+J2AGuVXFSbLNccoQLT6avcjPfxJ5u11QMMduH9/OmdIx44qn1ZgPtu8uk6yPVgz7iAHDaMKWY5NpHPUhZnbwPOoRuYgteYpFhkEXW8Xv5QGlsPmvkngm00ywJb8BnkMGMMOporKHmygtFt2FzmOSWVKhsBhqkc3A7A+TyDbFK1WVGbdOZ/D3osgzwJYA1zbqym6T0hG9gZND4NdS5W62y8NtiJXGeSrz4z3x/xDNCtBlplUCR9KVAutPMp16uF4qbwE2bTQ19TTbMc8HKkEDYF5KWfb58aLjeWyuRzjktjp41ONSywhQp+VlAOqE1yXNPr0W1NcmqwOLlhln7Y9bGdBvbBnNOyTH0HeJk6rNq2DsrwFvGqYFqpKktXIgc4g5nGqyJPcmToeJSDzfVN8vZMtUnfspTXptY8MVBBLbdN8uwzwSWka7GzgWqSTtTp4GLxbXq3llC+62kxEyr5c94Bz5Dy72ze5FLHAc0gcZwNnQHV5LkJQs2zHF05z3KBa6VTC7Bq2sxzXLOKG5ZDLFQmy4HNMQdCgsXmSsnhJpfhvgF06ow/DzV1Op5crVJbIFkqypQfAJ3cElXpNSOl+byIzON6MNyVBJ3+zaoLP5Q3Odikk6k3YP2I1yyHLEPhZpiJk1oYBLCppUFdeEdScnSpMe6XBVukqvMfgIbbmicPBNSgq7mm0g567qaAvMoCOP3T6zuRff68MwU0AWCt5gU1dcKBAX3QmqaGqoGKHPqdBoZ88F1HMwFPz2QHOW0L1x5kpcsMGKd3ZJoMvmHjfcMZ8gEMpE4E8AOPMxgnBr6kPwCxBq3JoGYwpQyfZxC8pk7tZTOa5bgHmpXJFWmjWawrbgLANt2IrT7MxiTvqrlkMnWhRHRa7EOB+iadqcm3c5v+WHmg6SN63UzP1HDXdfJurU05zZKH3miR4S1sDOii5Kmr3rOMrWgjQznYYJmxtErtDV4WXBpLZxk0gyXXNocavqxlhtZNVulGpnSzxtqiRTqKnjVWkY+NJIOlu+yRjMPyfqOCl+RcQ8ktOae6DN0MDbZ/j6PjJ2dl5NLYhFAEg0P0CfY3YEqQWKlOlw/BZT7Ova1qodYwGCx4kH8z1SRr6n3HM+Z46H1GOO9MwxxuSUV3Gy1sYrFy3uwOA8mOpOAGhzO0q4etxwZKxDR1rbQlw8ajhKwW1BJuSa1hNnYUHpCWe58hFDHGB6ujQ4FwGTq7j/SFFlzmnsjfQ9Wt1sfTEKvmYBegJ5vPm4VqBi8aIRKWoLtxRFaRmmoD5D1YihPB/V2lHQuev1Nz8+rKl72+IBdhxNdLYheRKUXYDPgjhNHHiLYkH8D+zq0EE9/n4aHOwrwZjuzubhEu7ok1QDVbTLjkUfxw5u4J+mvviE+chYHJEK8EbSTO+p03OMe1beIeb+C+0699D03523F3NHVNuMP84hFj321EkbCm6W6dV3FZ8gluLd6KMXfBKaZRjwikzeC6DzihWoqRiZfYPTfjOHDsn2vAEg1fGjB2T9Pu47OV798r36sMOJbHr+ol9q5Hqss73Xan7MPJY4Sxsa2fY4d28yZKecrZ/4fnG7rFLi9aoYBrx88GWg3pknjveYTd4zKlBohP1+6wIYNb1e1S+Mbj4Cu7UfAd5kr79vVRNhJCDTEAOO6M7p9Xpak0lJ1gvO+gw7RfWqLauzk0rNE4AW0f0jXoint141RIb5b0gzn4kguYAxGwBEGoMXwu/cZt5vXHjz62ZH5E+Y3r7znp00eZ9OwwayT/0sDumEQav3w9fI/rmHjcFJRWo+Glv5BMSQmYW0FW3C7GBAUhkcqQTmPXcFR50b1NC8dOlCfdEyXUnDMqiMNgxPRBLB4XO1xqZEzj4/GuXqxNHL1eOttK7WS1pn7gqeDUFAuV3SbwRlxnruEslc1QIycV+yN44v0AiL80Dlt808IgFiaA6smZMMoZ4lv37QKD5eSX8I0JOZPr7l8D6BZteSMtoeWEqapuLOi4GM7ixneE5TPPvtndC5yxuLUh3P69ef2X7/7qbN+L3na0HPsminY4p0XaiNldHTd0DZr8U+eTM68CGohc/Nanrv/Jf+blBuetU793P45MXj4k257tDkxx60zIh18/vXW0gwbvPEF/ackN01BTydZOqwzqmdjNBSHIoZfk0/s35FLa71+/JJcfLt7+5xvy+VLan34gz1eLNZHA7QI0YQtlwqg0pTUwi5/67qf/9d9ePItyBOwio4zb5QfK1ElF4+N4TObTd89rfu3P4mWLVPyKl08L6b5sOoD5kQ3j7vzAx/DdUUw31slvXNuGCvLu7EMU2T+UhHy+rONOxv9REiZx3jp0vxoRioQcFp64BU/xDd6zD3NqYUUfYUQ6nu4rclaWGv20/pTH0OmeXlbVx8Y5HxoLuTx/f+VfpdHwWEXNCaMfW04lr6mGt5tcXjlURrxfjodHToJIwkO39jgPW02s8NO1TisgeujSsuTuw1RsAra9Wf7xd+6EB8CZhHjBVbjhF9tHYIDKJtc6i1531yeNkg8BwyulbSeSB0K3xAAbbgC368OS15yY954eLuftY9KS9X6M8RJiduOpvLgBO7R8qTGKcadyer/RQMchTi5rKucw6UwnpuSMzxsNJZmuESbIErOG4nKmPrL1wKBodERbji46y9DvQCTU/fslXMkdABoqZaEImd3p84zSs7aUpqCFT8XPALq2Og/wWYYjMctQLSxyXIdc/U/qDEylZdF64vKp5bsWvKNjsrta35nwCBrsW7sALcGST+saXpLP7TP2Dh1g35Or1gE2eAl+HdPU2lE9J1AmRkzjFungF39JqBBRZaLefBAT3KjGxLwlaPcGcmkVMRYfcy7J58tRgcIwQTabvEoush1QVWcY++YAazCpM3od2AwlLv5FTJ2Kjv72DNj60QqFADlPPikScXbKR0YtdEQD9SoPFb0AjCQM0wlmhJKflV5RXQ7ndBNyNsdkL02ou/G3mEs3BbsCkHHVM3HXxPvGuJWloh+q88gQbBmPmREDCrkMea6YllBx68RSGLERJ3EpqDxFHP8ODso2QaTnohwQuO2y3ERSls6CnaMBu/3ypI5UAsMuBMt0/eDuFrGn2nLWCKoJ9osmLRLP396+eafmajaLT38HVtgFZN/eLWQ/uQX9bezh/dbh7dA9a+wCpA3J4qNomyZl54S7JfT4JcdR/2xAjyKsGsvUaTkdlhxH+LphDIwZwRk7jx/XHO24xBPEizgVd670mkQKEwa4nUI4beEIOzg6qYQBPlMr6d4VJ7diymH3RTJQlLapWqbrRzfyblLiu5ZizYDgUHb0BD/Mjj7MJTHcNhH5SbC4AIKIDlAX1BBaqtq9LnYBXBO1kpst84yz9FZJVY3k1eJMDsN9i/rTKhFOueeydPJHadMxgJKfuQByFhCbDNhwF2ev7Ajzd3I0Ybyj/1HSFUZZcB2yFtJyIUZjhBEp690fwAifr3cd6jVSc2I8IXSqclYPRIifwoIuuWpQu2SqqrWq+EiGIpwaubeSTgUWkc3I+X7cuFx2YicjkrsYbmmdJIrAFoZJh8scgWBk/Q6/3Lvbe2U392302G3KLBtpd8vZUmv0JZaBF+wYs/5OWhC+x3OQoDlrSUKGYKLfbmoBtwt8amOz3UhAdsK+mxirx4OfLU3HtN16NJpe76cpqBd+rYx0RU3Tzgi3vALj5LrX9jTUMBpECruQrCnEwY3AxoMP3AZ9x6N1TO/uRzta39+Npu8Kk2zI6Z1JCw7jQxQOaEOKNwLhDsLg66Xu9UHq9En3zl+0JLTpwzuXrJfqaQTIATneCZCv9zh+f3jLUo02OM2W3U0+6pNKkJR37A7y46THMSVtg8PYKfVYgrbjp05eudPYRVGBXahHiJLQLU8y8WiEj41uOPZS0iqr12lPVOejEsFf6xDZcy4zeUL+c/LjX/5Cnr+7OLt6QS64sVzOG24WUGIpfBQXoeYqe1+gfZEwzJadeTzCNuMHRzLGtMrsVdxX/+l2NYZBd2PQI59s6PN9rgvDtP+u7rfn+EOcYjFTKmNt0jeZYlSk6k63Q8hHWvLG+BWI0sTwiguqvXhyYtPdIYbvery8Cu+54eUpO430M+U/u4PQehF3+mJuLnm+Ooszue+uY1gjVBr2/L/BSYS/GZyF4LiBXllGGXdlKp0zMWAQskFWKz2nkv+xJ6ta5jsKd2X2EZzun6kRds+4jtaSZur687NbDl8L3+LL9y7aymr+BaiwC0Y1kFpDqSouabTgrieerqjlIK05mB4v6CmpfUcflVjf+hHqTAfXXZ1nTnDVVFtshrQhdb9YPWGzoyBs7iJRZ1CCphbKIllS2Z7z4YTPz+2KXfDsSqslL7vmYeFztK5F0FQHByM0/3HP2rZOG1dwNkTy8kRUdkuGXn92PUJmdHgoZk4uuY+eL3YV95EWcJ3SmXIo+H01T7hFnan3pV4l9DxCqNdRUWOlhhirtJf4DloFluJqz/BTE/epZ3HqK16WAk4n5d7jeneVc5Ht7cm9o+RcOx7jNORehdV6HYbkuo3OviS1oG7L3PusNAHJ9Loe8/JjKuQJ7Mk7ZNDpzrb8RRlL3lO24HLEpCtpJsnxzS6vP0vM9K81OPHh9CPf5MxMyLuS1uQ3/IfXj0olfd3p34ePJ1nQJTjNSQDV5EsDek2wB6GplTTQalTx4lRHb4HfOY28DD3wmIOsedsFUnryfV++cTxbkk6A6uYAfQzNUe+KKU55yusw2z3jbWvprSZGzjYMDy83RDdSRu1Y87J7eXzk2beRGqmxCxCLYGHm3whKVlyWamWIqYHxGWfuNy9jdYIhT3Z4QRx5Ht9Nzg15jh1hQbLNM4Shyxc9bpFG4jv+DuaUrclns934tovAVruFtMmza90KJzDYR177vqmFqGCtGh4y9yIOON71AYhU/29VmmI5z5B922TnV6jHuvN69TpCMVIYPWjhO0cQe5q83jFSQ4ZvcL23su4tkj7eBXRIzWkcdl3AYHtvNgmZfhsGOxRvSHG4+BnLBlKOBBytcEOSS5hxGXz1KJywq19F65Gmg4jdUYVimXDbOGB21L/UgrHz2eamPfRSGulN2fmwraVsUZ24Bf5mVWQ4GVhH/e3IMuRlymW6CWJJ74YjGYsK8z6eESHVL9vBbfFttDfl/ZGpnQOs8759B7CuqW7PlPvxyw0pqwUftFIn7nY4W9Ynv9+JPJt8Zolva6H0Ot+G/83UVP7LwY4xLSLbXdRb9Tz2NDm2/O0VQj9A26OpRAOq2n7r+6kaPQUFSKtVfYzoKFUzHTgX7nTGw5rO2oYD5QiIo6/uOO09PFdVTeW6u4947XCcvrdXlqDdM1RwOVNxpYCam9w1Qgfkx44V2WK2grxd0WdfcuUI/NwIsSb/0VDBZxxKcoF1z945GEVlBdOCKXXDHyno/jtMiV9/Yz9TMabNJ+82uwmH141FlfvIEaaH7/rHbokwZSe4o71PfkI+rWtP+sZz4Jjjd3B88zTMiqTNZHfQdjh4R4R+ZmJta3eROYWrrlMut7HznsVa6dbbjyHmj+9GtrzXKyfxcWp5UeedQ7SHFW7lg577Fk2tVCZNZBspt47bD1JTG3dNMllQkzLa3wOsQzl9YsiNFgm3uQc14a50xmjR6FTekB5MA7qg83Q25QZ08udpG3TS9Mdt0OHUZxAscGtBomqV3jhx8JOd5k7RW2jYSZVJrVH5JU5RS7glcz/hsqhevQp/Pw8ovAp/CXlNMbc/FaDj2XmBnEeMnnti+sFz9Lj2Rq0NyCnDQDRnUnE5A61H4q5Duk9CV1/xP8j6qHv2BEi2fYlnvW2IXCkMa6usVyqyxMmO31sft3fH7hNmEOv+j/4dhgla4wM/eb0AfRp/hNPZQ8bT83Mc/fiCnOP6cdRA2xM1Sxnh8znoMPwTtrIw9zTnhayh4x4jexvuFn1mep2i9+40/+NYr+T9W6PEd5tc8z/i3hp+k0mmXP77WyJhriz3G1gvqBmZAGXYqdsK9bbSLz4+XNBtdbYJUIMEl50z1jZOb+tv4gkphs9PUVGx3d+om3r4aXTQspMm3JgmudKJkDFZKp+37mExFMQQtM7qAx1sSl96vnWLk2sMTu+TTifJkOg6g4co8vNrTO3c/xj1pOdxSN5feu7BcVyEGiOKZc4XfTekGhzZUWTKwh092iRv02hyAeY3ECzqTM0NvtmMK+k/SChbfyAG43VKk8vrs39/f0Wu3DtFfpUj01c22GaqpD4G208rFccWxRBbALsxRzmR7yaE8/Ygiw2d6/p1di3CMA00jCDcSME9Wi5oPmgK+QhKrsej6woyajQgzpba5mQTPvtYLqngpT+IESR2BeHJulrvE4TIsRtYm12xnejktwmkiWEvrK1NwXEGbRbQuJU5GMLoE7hNfC7byheluV0fuFFMVVXWPnF3xNvjERxC8RL8Fdcgdi3N1C6WlaCyMOaxBt66lb0M/z1Q29ZoRbH1pcZFrfgp0qpjCHsMCGKASMWtAWQrW1ApB40zcrebCqsiIiMx2xO1be4eljDz8Pd3Zx/Cu/dqZ/nuQbFK7/r+k/ds4+amWCrR5GLAWTvHWYY5N91k7HacbyO5NeS5R8K8wG4dWNjbTtTdAU8Q6Sg1oskkzd4FXD9LbkO6wGS76GAJGjMFZo0gTEkGtXWG8rXfw5H2CqtVTunrGe8M9naEtkO0VtoS5fj7y7+exVJwo2xPfe6Unp8+wXK3wGDLxTqlvtlJtFHMv7399eryiryntxWXZTfWO76tjraTp2FuDVEcISuQMaBuH1md+hQvWUyenu2rHIvZ6Qo2H7sIvyU5u9qx5SwLUvnyInTpDVjsxVCcblMeuVdAS3H1X75uuCvMkeVQk0x9u9Ff4kzoR8puDOOq0YrvgrqVL+59SUwTSVGnhvzNWK3k/F+mgrIbwY2F8m+vws9edr/lcgYs/qsZ17CiIqrI0KnofYdQWRKjyMix1DDnxuq1s+xPKSxqahehWX+HA9nFYYAkOqVOhaYvhPb1WkzpXhfyTp/sMAdp9fpP/zcAAP//faH2Mw==" }