Skip to content

Commit

Permalink
Extract alert severity in dedicated field
Browse files Browse the repository at this point in the history
  • Loading branch information
TonioRyo committed Jan 14, 2025
1 parent db0dfff commit cf7a303
Show file tree
Hide file tree
Showing 10 changed files with 32 additions and 33 deletions.
5 changes: 5 additions & 0 deletions Netskope/netskope_events/_meta/fields.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
netskope.alerts.severity:
description: ''
name: netskope.alerts.severity
type: keyword

netskope.alerts.name:
description: The name of the alert
name: netskope.alerts.name
Expand Down
4 changes: 2 additions & 2 deletions Netskope/netskope_events/ingest/parser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -151,8 +151,8 @@ stages:
filter: "{{ parsed_event.message.severity_level|int(-1) == -1 }}"

- set:
netskope.events.severity.level: "{{parsed_event.message.severity}}"
filter: "{{ parsed_event.message.severity|int(-1) == -1 }}"
netskope.alerts.severity: "{{parsed_event.message.severity}}"
filter: "{{ parsed_event.message.severity|int(-1) == -1}}"

- set:
netskope.events.severity.id: "{{parsed_event.message.severity_level}}"
Expand Down
6 changes: 2 additions & 4 deletions Netskope/netskope_events/tests/test_dlp_alert.json
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@
},
"netskope": {
"alerts": {
"severity": "unknown",
"type": "DLP"
},
"dlp": {
Expand All @@ -85,10 +86,7 @@
"name": "LinkedIn",
"suite": "Linkedin App"
},
"ccl": "medium",
"severity": {
"level": "unknown"
}
"ccl": "medium"
}
},
"network": {
Expand Down
6 changes: 3 additions & 3 deletions Netskope/netskope_events/tests/test_dlp_incident.json
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,9 @@
}
},
"netskope": {
"alerts": {
"severity": "Low"
},
"dlp": {
"action": "useralert",
"forensic_id": "2222222222222222222",
Expand All @@ -68,9 +71,6 @@
"access_method": "Client",
"application": {
"name": "NextCloud"
},
"severity": {
"level": "Low"
}
}
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@
},
"netskope": {
"alerts": {
"severity": "unknown",
"type": "DLP"
},
"dlp": {
Expand All @@ -85,10 +86,7 @@
"name": "LinkedIn",
"suite": "Linkedin App"
},
"ccl": "medium",
"severity": {
"level": "unknown"
}
"ccl": "medium"
}
},
"network": {
Expand Down
6 changes: 2 additions & 4 deletions Netskope/netskope_events/tests/test_malware_alert.json
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@
},
"netskope": {
"alerts": {
"severity": "high",
"type": "Malware"
},
"events": {
Expand All @@ -65,10 +66,7 @@
"category": "n/a",
"name": "eicar"
},
"ccl": "unknown",
"severity": {
"level": "high"
}
"ccl": "unknown"
}
},
"network": {
Expand Down
8 changes: 4 additions & 4 deletions Netskope/netskope_events/tests/test_nspolicy_block.json
Original file line number Diff line number Diff line change
Expand Up @@ -52,16 +52,16 @@
}
},
"netskope": {
"alerts": {
"severity": "unknown"
},
"events": {
"access_method": "Client",
"application": {
"category": "General",
"name": "DNS Over HTTPS"
},
"ccl": "unknown",
"severity": {
"level": "unknown"
}
"ccl": "unknown"
}
},
"network": {
Expand Down
8 changes: 4 additions & 4 deletions Netskope/netskope_events/tests/test_nspolicy_log.json
Original file line number Diff line number Diff line change
Expand Up @@ -64,17 +64,17 @@
}
},
"netskope": {
"alerts": {
"severity": "unknown"
},
"events": {
"access_method": "Client",
"application": {
"category": "Collaboration",
"name": "Microsoft Office 365 Sharepoint Online",
"suite": "Office365"
},
"ccl": "excellent",
"severity": {
"level": "unknown"
}
"ccl": "excellent"
}
},
"network": {
Expand Down
8 changes: 4 additions & 4 deletions Netskope/netskope_events/tests/test_nspolicy_upload.json
Original file line number Diff line number Diff line change
Expand Up @@ -60,16 +60,16 @@
}
},
"netskope": {
"alerts": {
"severity": "unknown"
},
"events": {
"access_method": "Client",
"application": {
"category": "Remote Access",
"name": "App"
},
"ccl": "medium",
"severity": {
"level": "unknown"
}
"ccl": "medium"
}
},
"network": {
Expand Down
8 changes: 4 additions & 4 deletions Netskope/netskope_events/tests/test_user_alert.json
Original file line number Diff line number Diff line change
Expand Up @@ -54,16 +54,16 @@
}
},
"netskope": {
"alerts": {
"severity": "unknown"
},
"events": {
"access_method": "Client",
"application": {
"category": "Cloud Storage",
"name": "WeTransfer"
},
"ccl": "low",
"severity": {
"level": "unknown"
}
"ccl": "low"
}
},
"network": {
Expand Down

0 comments on commit cf7a303

Please sign in to comment.