You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Splunk_Deploiement/apps/trackme/lookups/trackme_cim_regex_v2.csv

16 KiB

1datamodelfieldvalidation_regex
2UBA_Authenticationaction^(success|failure|unknown|added)$
3UBA_Badgefailure_reason.*
4UBA_Badgeobject_name.*
5UBA_Badgeobject_type.*
6UBA_Badgesite_name.*
7UBA_Badgevendor.*
8UBA_Cloudchange_type^(download|preview|delete|create|edit)$
9UBA_Cloudobject^[^\/]+\.[a-zA-Z0-9]+$
10UBA_Cloudobject_path\/.*\/.*
11UBA_Cloudobject_type^(file|folder|document|image)$
12UBA_Cloudparent_category.*
13UBA_Databaseaction_name^[A-Za-z\s]+$
14UBA_Databasecommand_name^[A-Za-z\s]+$
15UBA_Databasecommits^\d+$
16UBA_Databasecpu_used^\d+$
17UBA_Databaseelapsed_time^\d+$
18UBA_Databaseeventtype.*
19UBA_Databaseinstance_name^[A-Za-z\s]+$
20UBA_Databaseobject.*
21UBA_Databasequery/^\s*(SELECT|INSERT|UPDATE|DELETE|FROM|WHERE|AND|OR|ORDER BY|GROUP BY|HAVING|JOIN|INNER JOIN|LEFT JOIN|RIGHT JOIN|OUTER JOIN|ON|VALUES|SET|LIMIT)\b.*/gm
22UBA_Databaserecords_affected^\d+$
23UBA_Databasetables_hit.*
24UBA_Databasetablespace_name.*
25UBA_Databasevendor.*
26UBA_DHCPlease_duration^\d+(:?\.\d{1,6})?$
27UBA_DLPaction^(allowed|blocked)$
28UBA_DLPdest_path\/.*\/.*
29UBA_DLPdlp_status.*
30UBA_DLPmatch_count.*
31UBA_DLPpolicy.*
32UBA_DLPprevention_status.*
33UBA_DLPrecipient\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
34UBA_DLPrestricted^(yes|no)$
35UBA_DLPsender\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
36UBA_DLPserial_number^\d+$
37UBA_DLPsrc_path\/.*\/.*
38UBA_DLPsubject.*
39UBA_DLPvendor.*
40UBA_DNSanswer^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$
41UBA_DNSmessage_type.*
42UBA_DNSquery^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$
43UBA_DNSquery_type\b(Query|IQuery|Status|Notify|Update|unknown|A|MX|NS|PTR)\b
44UBA_DNSrecord_type^(A|DNAME|MX|NS|PTR)$
45UBA_DNSttl^\d+$
46UBA_Emailaction\b(delivered|blocked|quarantined|deleted|unknown)\b
47UBA_Emailrecipient\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
48UBA_Emailsubject.*
49UBA_Endpoint_Filesystemaction\b(?:allowed|blocked)\b
50UBA_Endpoint_FilesystemalarmCategories\b(?:Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|Local|Signature|Behavior|FlightRisk|DataDestruction|Allowed|PeerGroup|Incoming|Internal|Outgoing|Blocked|Blacklisted|Beaconing|Outlier|UnusualActivity|ExternalAlarm|ExternalAttack|SuspiciousPattern|SuspiciousDownload|WebShell|UnusualResourceAccess|RuleBased|NetworkConnection|DataDeletion|CloudStorage|ExternalScan|ApplicationLog|External|Network|EndPoint|AD|Firewall|IPS|CloudData|Correlation|Printer|Badge|RareUser|RareProcess|RareDevice|RareDomain|RareNetwork|RareApplication|RareLocation|Unknown|CIS|Reconnaissance|ActionsonObjectives|Delivery|Installation|Exploitation|ValidAccounts|NetworkSniffing|AccountManipulation|ExploitationofVulnerability|SystemInformationDiscovery|DataStaged|EmailCollection|CommonlyUsedPort|StandardNon-ApplicationLayer|ExfiltrationOverAlternativeProtocol|StandardApplicationLayerProtocol|ExfiltrationOverCommandandControlChannel|PowerShell|Scripting|CredentialDumping|Command-LineInterface|DisablingSecurityTools|ModifyRegistry|NewService|NodifyExistingService|RegistryRunKeys\/StartFolder|AppInitDLLs|AuthenticationPackage|ScheduledTask|WebService|Third-partySoftware|AccountDiscovery|RemoteDesktopProtocol|PasstheHash|IndicatorRemovalonHost|Masquerading|WindowsManagementInstrumentation|ChangeDefaultFileAssociation|ApplicationShimming|LocalPortMonitor|AccessibilityFeatures|Rundll32|CreateAccount|PR|ID|RS|DE)\b
51UBA_Endpoint_Filesystemeventtype.*
52UBA_Endpoint_Portaction\b(?:allowed|blocked)\b
53UBA_Endpoint_PortalarmCategories\b(Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|L
54UBA_Endpoint_Portcpu_load_percent^\d+$
55UBA_Endpoint_Portcreation_time^\d+$
56UBA_Endpoint_Porteventtype.*
57UBA_Endpoint_Portmem_used^\d+$
58UBA_Endpoint_Portos.*
59UBA_Endpoint_Portstate.*
60UBA_Endpoint_Processesaction\b(?:allowed|blocked)\b
61UBA_Endpoint_ProcessesalarmCategories\b(Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|L
62UBA_Endpoint_Processeseventtype.*
63UBA_Endpoint_Processesparent_process_exec^[^\/]+\.[a-zA-Z0-9]+$
64UBA_Endpoint_Processesparent_process_guid^[^\n\r]+$
65UBA_Endpoint_Processesparent_process_name^[^\/]+\.[a-zA-Z0-9]+$
66UBA_Endpoint_Processesparent_process_path\/.*\/.*
67UBA_Endpoint_Processesprocess\/.*\/.*
68UBA_Endpoint_Processesprocess_current_directory/^\/(?:[a-zA-Z0-9_]+\/?)+$
69UBA_Endpoint_Processesprocess_exec^[^\/]+\.[a-zA-Z0-9]+$
70UBA_Endpoint_Processesprocess_guid..*
71UBA_Endpoint_Processesprocess_integrity_level.*
72UBA_Endpoint_Processesprocess_path\/.*\/.*
73UBA_Endpoint_Registryaction\b(?:allowed|blocked)\b
74UBA_Endpoint_RegistryalarmCategories\b(Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|L
75UBA_Endpoint_Registryeventtype.*
76UBA_Endpoint_Registryregistry_hive.*
77UBA_Endpoint_Registryregistry_key_name.*
78UBA_Endpoint_Registryregistry_path^\\[a-zA-Z]+(?:\\[a-zA-Z]+)*(?:\\[a-zA-Z0-9]+(?:-[a-zA-Z0-9]+)*)*\\{[0-9A-Fa-f]{8}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{12}}\\[a-zA-Z0-9_]+$
79UBA_Endpoint_Registryregistry_value_data.*
80UBA_Endpoint_Registryregistry_value_name.*
81UBA_Endpoint_Registryregistry_value_text.*
82UBA_Endpoint_Registryregistry_value_type.*
83UBA_Endpoint_Registrystatus\b(?:failure|success)\b
84UBA_Endpoint_Servicesaction\b(?:allowed|blocked)\b
85UBA_Endpoint_ServicesalarmCategories\b(Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|L
86UBA_Endpoint_Servicesdescription\b\w+(?:[.-]\w+)*\b
87UBA_Endpoint_Serviceseventtype.*
88UBA_Endpoint_Servicesservice_dll^[^\/]+\.[a-zA-Z0-9]+$
89UBA_Endpoint_Servicesservice_dll_path\/.*\/.*
90UBA_Endpoint_Servicesservice_dll_signature_exists^[a-zA-Z\s_]+$
91UBA_Endpoint_Servicesservice_dll_signature_verified^[a-zA-Z\s_]+$
92UBA_Endpoint_Servicesservice_exec^[^\/]+\.[a-zA-Z0-9]+$
93UBA_Endpoint_Servicesservice_name.*
94UBA_Endpoint_Servicesservice_path\/.*\/.*
95UBA_Endpoint_Servicesstart_mode.*
96UBA_Endpoint_Servicesstatus\b(?:critical|started|stopped|warning|failure|success)\b
97UBA_External_Alarmaction\b(?:allowed|blocked|deferred)\b
98UBA_External_AlarmalarmCategories\b(Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|L
99UBA_External_Alarmdest_zone^[a-zA-Z\s_]+$
100UBA_External_Alarmsignature or eventtype^[a-zA-Z\s_]+$
101UBA_External_Alarmsrc_zone.*
102UBA_External_Alarmurl^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$
103UBA_Firewallaction^(allowed|blocked|dropped|teardown|delivered|quarantined|deleted|unknown|deferred|added)$
104UBA_Firewalldest_zone^[a-zA-Z\s_]+$
105UBA_Firewallsrc_zone^[a-zA-Z\s_]+$
106UBA_Firewallurl^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$
107UBA_Firewallvendor_action\b\w+(?:[.-]\w+)*\b
108UBA_Host AVaction\b(?:allowed|blocked)\b
109UBA_Host AValarmCategories\b(?:Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|Local|Signature|Behavior|FlightRisk|DataDestruction|Allowed|PeerGroup|Incoming|Internal|Outgoing|Blocked|Blacklisted|Beaconing|Outlier|UnusualActivity|ExternalAlarm|ExternalAttack|SuspiciousPattern|SuspiciousDownload|WebShell|UnusualResourceAccess|RuleBased|NetworkConnection|DataDeletion|CloudStorage|ExternalScan|ApplicationLog|External|Network|EndPoint|AD|Firewall|IPS|CloudData|Correlation|Printer|Badge|RareUser|RareProcess|RareDevice|RareDomain|RareNetwork|RareApplication|RareLocation|Unknown|CIS|Reconnaissance|ActionsonObjectives|Delivery|Installation|Exploitation|ValidAccounts|NetworkSniffing|AccountManipulation|ExploitationofVulnerability|SystemInformationDiscovery|DataStaged|EmailCollection|CommonlyUsedPort|StandardNon-ApplicationLayer|ExfiltrationOverAlternativeProtocol|StandardApplicationLayerProtocol|ExfiltrationOverCommandandControlChannel|PowerShell|Scripting|CredentialDumping|Command-LineInterface|DisablingSecurityTools|ModifyRegistry|NewService|NodifyExistingService|RegistryRunKeys\/StartFolder|AppInitDLLs|AuthenticationPackage|ScheduledTask|WebService|Third-partySoftware|AccountDiscovery|RemoteDesktopProtocol|PasstheHash|IndicatorRemovalonHost|Masquerading|WindowsManagementInstrumentation|ChangeDefaultFileAssociation|ApplicationShimming|LocalPortMonitor|AccessibilityFeatures|Rundll32|CreateAccount|PR|ID|RS|DE)\b
110UBA_Host AVeventtype\b\w+(?:[.-]\w+)*\b
111UBA_Host AVurl^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$
112UBA_IDS_IPSaction\b(?:allowed|blocked)\b
113UBA_IDS_IPSalarmCategories\b(Exfiltration|Info|InsiderThreat|MalwareActivity|MalwareInstall|MalwarePersistence|PolicyViolation|ProductAttack|ReducedVisibility|SystemAttack|MalformedTraffic|AccountTakeover|Enumeration|LateralMovement|Vulnerability|Recon|InitialAccess|Execution|Persistence|PrivilegeEscalation|DefenseEvasion|CredentialAccess|Discovery|Collection|CommandAndControl|Infection|DenialOfService|LossOfControl|BruteForce|L
114UBA_IDS_IPSeventtype.*
115UBA_Printerdata_type.*
116UBA_Printerdriver_process.*
117UBA_Printeroperation.*
118UBA_Printerpage_printed^\d+$
119UBA_Printerparameters^\d+$
120UBA_Printerprint_processor.*
121UBA_Printerprinter.*
122UBA_Printerpriority^\d+$
123UBA_Printerstatus.*
124UBA_Printersubmitted_time.*
125UBA_Printertotal_pages^\d+$
126UBA_Printertype.*
127UBA_Web_Proxyaction\b(?:allowed|blocked)\b
128UBA_Web_Proxyresponse_time^\d+$
129UBA_Web_Proxystatus^\d+$
130UBA_Web_Proxyurl^(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$
131UBA_HR_DatamemberOf.*
132UBA_HR_Datagroups.*
133UBA_HR_Datal^[A-Za-z\s.'-]+$
134UBA_HR_Datacity^[A-Za-z\s.'-]+$
135UBA_HR_Dataco^[A-Za-z\s.'-]+$
136UBA_HR_Datacountry^[A-Za-z\s.'-]+$
137UBA_HR_DatadepartingUser^(true|false)$
138UBA_HR_DatadisplayName^[A-Za-z\s.'-]+$
139UBA_HR_DatadomainLoginId^[a-zA-Z0-9\/\\@]+$
140UBA_HR_Datamail\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
141UBA_HR_Dataemail\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
142UBA_HR_DataemployeeType.*
143UBA_HR_DataaccountExpires.*
144UBA_HR_DatapreferredName.*
145UBA_HR_DatagivenName.*
146UBA_HR_Datafirstname.*
147UBA_HR_DatahighRiskUser^(true|false)$
148UBA_HR_DatahireDate.*
149UBA_HR_DatalastLogon.*
150UBA_HR_DatalastLogonTimestamp.*
151UBA_HR_Datasn.*
152UBA_HR_Datalastname.*
153UBA_HR_DatasAMAccountName^[a-zA-Z0-9_]+$
154UBA_HR_DataloginId^[a-zA-Z0-9_]+$
155UBA_HR_Datamanager.*
156UBA_HR_DatamanageremployeeId.*
157UBA_HR_Datainitials.*
158UBA_HR_DataMiddleName.*
159UBA_HR_Datadepartment.*
160UBA_HR_Dataou.*
161UBA_HR_DataonPerformanceImprovementPlan^(true|false)$
162UBA_HR_DataonPIP^(true|false)$
163UBA_HR_DatatelephoneNumber.*
164UBA_HR_Dataphone.*
165UBA_HR_Datast.*
166UBA_HR_Datastate.*
167UBA_HR_Datahrstatuscode.*
168UBA_HR_DatastreetAddress.*
169UBA_HR_Datastreet.*
170UBA_HR_DataterminatedUser^(true|false)$
171UBA_HR_DataterminationDate.*
172UBA_HR_Datatitle.*
173UBA_HR_Datatraveling^(true|false)$
174UBA_HR_DataUAC.*
175UBA_HR_Datastatus^(InActive|Active)$
176UBA_HR_DatapostalCode.*
177UBA_HR_Datazip.*
178UBA_DLP_Emailaction^(allowed|blocked)$
179UBA_DLP_Emaildest_path\/.*\/.*
180UBA_DLP_Emaildlp_status.*
181UBA_DLP_Emailmatch_count.*
182UBA_DLP_Emailpolicy.*
183UBA_DLP_Emailprevention_status.*
184UBA_DLP_Emailrecipient\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
185UBA_DLP_Emailrestricted^(yes|no)$
186UBA_DLP_Emailsender\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b
187UBA_DLP_Emailserial_number^\d+$
188UBA_DLP_Emailsrc_path\/.*\/.*
189UBA_DLP_Emailsubject.*
190UBA_DLP_Emailvendor.*
191UBA_Asset_Datahostname^[\w\.-]+$
192UBA_Asset_DatadenyListDeviceIr^(true|false)$
193UBA_Asset_DatadenyListUserIr^(true|false)$
194UBA_Asset_Dataasset_tag.*
195UBA_Asset_Databunit.*
196UBA_Asset_Datacity^[A-Za-z\s.'-]+$
197UBA_Asset_Datacost_center.*
198UBA_Asset_Datacountry.*
199UBA_Asset_Datacreated_by.*
200UBA_Asset_Datadepartment.*
201UBA_Asset_DatadeviceType.*
202UBA_Asset_Datadns.*
203UBA_Asset_Dataip^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$
204UBA_Asset_Datais_expected^(true|false)$
205UBA_Asset_Datalatitude.*
206UBA_Asset_Datalongitude.*
207UBA_Asset_Datamac^[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}$
208UBA_Asset_Datamanaged_by.*
209UBA_Asset_Dataos.*
210UBA_Asset_Dataowner.*
211UBA_Asset_Dataserial.*
212UBA_Asset_Datastatus.*
213UBA_Asset_Datasubstatus.*
214UBA_Asset_Datasys_created_on.*
215UBA_Asset_Datasys_updated_on.*
216*tag.*
217*severity^(critical|high|medium|low|informational)$
218*action^(success|failure|allowed|blocked|deferred)$
219*dest^[\w\.-]+$
220*src^[\w\.-]+$
221*dvc^[\w\.-]+$
222**_ip^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$
223**_port^\d{1,5}$
224**_mac^[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}:[a-f0-9]{2}$
225*direction^(inbound|outbound)$
226*bytes*^\d+$
227*duration^\d+(:?\.\d{1,6})?$
228*packets*^\d+$
229*protocol^[a-z0-9]+$
230*transport^[a-z0-9]+$
231*vendor_product^[\w\d\s\-:]+$
232*ids_type^(network|host|application)$
233*category^.{3,100}$
234*signature^.{3,100}$
235**user^[\w\/\\\-\.$]{1,30}$
236*app^[\w:\-\d\s]+$
237**_nt_domain^[\w\/\\\-\.$]{1,20}$
238*file_hash^[0-9a-fA-F]{32,512}$
239*file_name^.{1,255}$
240*date^[01]\d-[0123]\d-[12]\d{3}$
241*http_method^(?:GET|POST|HEAD|PUT|DELETE|OPTIONS|TRACE|CONNECT)$
242**_length^\d+$
243*channel^\d+$
244*url^(?:https?|ftp):\/{2}.+
245*http_referrer^(?:https?|ftp):\/{2}.+
246*http_content_type^\w+\/[\w\-\+\.]+$
247*cached^(?:true|false|1|0)$
248**_id^\d+$
249**_host^.{1,80}$