My apologies ; I think I have picked a wrong message ; Here is the right one ; Don't know how I missed it, they all looked same ; This message has bytes_received and bytes_sent in it.
device_name="SFW" timestamp="2021-11-14T21:29:53-0600" device_model="SFVH" device_serial_id="C01001BQC8TFFFF" log_id="010101600001" log_type="Firewall" log_component="Firewall Rule" log_subtype="Allowed" log_version=1 severity="Information" duration=33 fw_rule_id="12" nat_rule_id="12" fw_rule_type="USER" web_policy_id=12 ips_policy_id=8 app_filter_policy_id=6 ether_type="Unknown (0x0000)" in_interface="Port1" out_interface="Port2" src_mac="10:BF:48:7D:FF:FF" dst_mac="00:50:56:9F:FF:FF" src_ip="192.168.2.121" src_country="R1" dst_ip="1.1.1.1" dst_country="AUS" protocol="ICMP" icmp_type=8 packets_sent=2 packets_received=2 bytes_sent=168 bytes_received=168 src_trans_ip="192.168.1.2" src_zone_type="LAN" src_zone="LAN" dst_zone_type="WAN" dst_zone="WAN" con_event="Stop" con_id="2171700160" hb_status="No Heartbeat" app_resolved_by="Signature" app_is_cloud="FALSE" qualifier="New" in_display_interface="Port1" out_display_interface="Port2"
Still no destination.bytes variable found in Kibana
- convert:
field: sophos.xg.recv_bytes
target_field: destination.bytes
type: long
Here is the corresponding full record that I see in Kibana, in JSON Format ;
{
"_index": "filebeat-7.15.1-2021.11.14-000001",
"_type": "_doc",
"_id": "5oekIX0ByPM67hqn4G-2",
"_version": 1,
"_score": 1,
"_source": {
"server": {
"ip": "1.1.1.1",
"mac": "00:50:56:9F:FF:FF"
},
"agent": {
"hostname": "ubu16",
"name": "ubu16",
"id": "9dfb5d58-4d2b-4eb2-a1e0-2589d8f95c80",
"type": "filebeat",
"ephemeral_id": "f8b595b3-d15f-488d-9022-5b86b38396a1",
"version": "7.15.1"
},
"log": {
"level": "informational",
"source": {
"address": "192.168.2.1:56779"
}
},
"destination": {
"geo": {
"continent_name": "Oceania",
"country_iso_code": "AU",
"country_name": "Australia",
"location": {
"lon": 143.2104,
"lat": -33.494
}
},
"as": {
"number": 13335,
"organization": {
"name": "CLOUDFLARENET"
}
},
"ip": "1.1.1.1",
"mac": "00:50:56:9F:FF:FF"
},
"rule": {
"id": "12"
},
"source": {
"ip": "192.168.2.121",
"mac": "10:BF:48:7D:FF:FF"
},
"fileset": {
"name": "xg"
},
"tags": [
"sophos-xg",
"forwarded"
],
"network": {
"transport": "icmp"
},
"input": {
"type": "udp"
},
"observer": {
"ingress": {
"interface": {
"name": "Port1"
}
},
"product": "XG",
"vendor": "Sophos",
"type": "firewall",
"egress": {
"interface": {
"name": "Port2"
}
}
},
"@timestamp": "2021-11-14T21:29:53.000-06:00",
"ecs": {
"version": "1.11.0"
},
"related": {
"hosts": [
"ubu16"
],
"ip": [
"192.168.2.121",
"1.1.1.1"
]
},
"sophos": {
"xg": {
"icmp_type": "8",
"device_model": "SFVH",
"in_display_interface": "Port1",
"web_policy_id": "12",
"out_display_interface": "Port2",
"con_id": "2171700160",
"bytes_received": "168",
"fw_rule_type": "USER",
"ips_policy_id": "8",
"src_trans_ip": "192.168.1.2",
"app_is_cloud": "FALSE",
"device_name": "SFW",
"log_type": "Firewall",
"packets_sent": "2 ",
"ether_type": "Unknown (0x0000)",
"packets_received": "2",
"nat_rule_id": "12",
"device_serial_id": "C01001BQC8TFFFF",
"app_filter_policy_id": "6",
"timestamp": "2021-11-14T21:29:53-0600",
"severity": "Information",
"dst_country": "AUS",
"log_component": "Firewall Rule",
"log_subtype": "Allowed",
"dst_zone_type": "WAN",
"hb_status": "No Heartbeat",
"message_id": "00001",
"bytes_sent": "168",
"dst_zone": "WAN",
"src_zone_type": "LAN",
"con_event": "Stop",
"src_country": "R1",
"src_zone": "LAN",
"app_resolved_by": "Signature",
"qualifier": "New",
"log_version": "1"
}
},
"service": {
"type": "sophos"
},
"host": {
"name": "ubu16"
},
"client": {
"ip": "192.168.2.121",
"mac": "10:BF:48:7D:FF:FF"
},
"event": {
"severity": "6",
"original": "device_name=\"SFW\" timestamp=\"2021-11-14T21:29:53-0600\" device_model=\"SFVH\" device_serial_id=\"C01001BQC8TFFEB\" log_id=\"010101600001\" log_type=\"Firewall\" log_component=\"Firewall Rule\" log_subtype=\"Allowed\" log_version=1 severity=\"Information\" duration=33 fw_rule_id=\"12\" nat_rule_id=\"12\" fw_rule_type=\"USER\" web_policy_id=12 ips_policy_id=8 app_filter_policy_id=6 ether_type=\"Unknown (0x0000)\" in_interface=\"Port1\" out_interface=\"Port2\" src_mac=\"10:BF:48:7D:ED:22\" dst_mac=\"00:50:56:9F:39:33\" src_ip=\"192.168.2.121\" src_country=\"R1\" dst_ip=\"1.1.1.1\" dst_country=\"AUS\" protocol=\"ICMP\" icmp_type=8 packets_sent=2 packets_received=2 bytes_sent=168 bytes_received=168 src_trans_ip=\"192.168.1.2\" src_zone_type=\"LAN\" src_zone=\"LAN\" dst_zone_type=\"WAN\" dst_zone=\"WAN\" con_event=\"Stop\" con_id=\"2171700160\" hb_status=\"No Heartbeat\" app_resolved_by=\"Signature\" app_is_cloud=\"FALSE\" qualifier=\"New\" in_display_interface=\"Port1\" out_display_interface=\"Port2\"",
"code": "010101600001",
"timezone": "-06:00",
"kind": "event",
"module": "sophos",
"start": "2021-11-14T21:29:53.000-06:00",
"duration": 33000000000,
"ingested": "2021-11-15T03:29:53.331782895Z",
"action": "allowed",
"end": "2021-11-14T21:30:26.000-06:00",
"category": [
"network"
],
"dataset": "sophos.xg",
"outcome": "success"
}
},
"fields": {
"rule.id": [
"12"
],
"event.category": [
"network"
],
"sophos.xg.bytes_sent": [
"168"
],
"sophos.xg.app_resolved_by": [
"Signature"
],
"client.mac": [
"10:BF:48:7D:FF:FF"
],
"server.ip": [
"1.1.1.1"
],
"observer.egress.interface.name": [
"Port2"
],
"sophos.xg.src_zone_type": [
"LAN"
],
"observer.ingress.interface.name": [
"Port1"
],
"sophos.xg.con_id": [
2171700160
],
"destination.mac": [
"00:50:56:9F:FF:FF"
],
"service.type": [
"sophos"
],
"observer.vendor": [
"Sophos"
],
"sophos.xg.log_version": [
"1"
],
"sophos.xg.log_type": [
"Firewall"
],
"sophos.xg.src_trans_ip": [
"192.168.1.2"
],
"source.ip": [
"192.168.2.121"
],
"log.level": [
"informational"
],
"agent.name": [
"ubu16"
],
"host.name": [
"ubu16"
],
"event.kind": [
"event"
],
"sophos.xg.dst_zone_type": [
"WAN"
],
"sophos.xg.bytes_received": [
"168"
],
"event.outcome": [
"success"
],
"event.severity": [
6
],
"sophos.xg.src_zone": [
"LAN"
],
"event.original": [
"device_name=\"SFW\" timestamp=\"2021-11-14T21:29:53-0600\" device_model=\"SFVH\" device_serial_id=\"C01001BQC8TFFFF\" log_id=\"010101600001\" log_type=\"Firewall\" log_component=\"Firewall Rule\" log_subtype=\"Allowed\" log_version=1 severity=\"Information\" duration=33 fw_rule_id=\"12\" nat_rule_id=\"12\" fw_rule_type=\"USER\" web_policy_id=12 ips_policy_id=8 app_filter_policy_id=6 ether_type=\"Unknown (0x0000)\" in_interface=\"Port1\" out_interface=\"Port2\" src_mac=\"10:BF:48:7D:FF:FF\" dst_mac=\"00:50:56:9F:FF:FF\" src_ip=\"192.168.2.121\" src_country=\"R1\" dst_ip=\"1.1.1.1\" dst_country=\"AUS\" protocol=\"ICMP\" icmp_type=8 packets_sent=2 packets_received=2 bytes_sent=168 bytes_received=168 src_trans_ip=\"192.168.1.2\" src_zone_type=\"LAN\" src_zone=\"LAN\" dst_zone_type=\"WAN\" dst_zone=\"WAN\" con_event=\"Stop\" con_id=\"2171700160\" hb_status=\"No Heartbeat\" app_resolved_by=\"Signature\" app_is_cloud=\"FALSE\" qualifier=\"New\" in_display_interface=\"Port1\" out_display_interface=\"Port2\""
],
"sophos.xg.dst_zone": [
"WAN"
],
"sophos.xg.qualifier": [
"New"
],
"sophos.xg.device_name": [
"SFW"
],
"destination.geo.continent_name": [
"Oceania"
],
"fileset.name": [
"xg"
],
"sophos.xg.ether_type": [
"Unknown (0x0000)"
],
"input.type": [
"udp"
],
"client.ip": [
"192.168.2.121"
],
"agent.hostname": [
"ubu16"
],
"tags": [
"sophos-xg",
"forwarded"
],
"event.code": [
"010101600001"
],
"agent.id": [
"9dfb5d58-4d2b-4eb2-a1e0-2589d8f95c80"
],
"sophos.xg.message_id": [
"00001"
],
"ecs.version": [
"1.11.0"
],
"observer.type": [
"firewall"
],
"log.source.address": [
"192.168.2.1:56779"
],
"sophos.xg.packets_received": [
"2"
],
"agent.version": [
"7.15.1"
],
"related.hosts": [
"ubu16"
],
"event.start": [
"2021-11-15T03:29:53.000Z"
],
"destination.geo.country_name": [
"Australia"
],
"server.mac": [
"00:50:56:9F:39:33"
],
"sophos.xg.timestamp": [
"2021-11-15T03:29:53.000Z"
],
"sophos.xg.device_serial_id": [
"C01001BQC8TFFEB"
],
"sophos.xg.src_country": [
"R1"
],
"sophos.xg.con_event": [
"Stop"
],
"sophos.xg.nat_rule_id": [
"12"
],
"event.end": [
"2021-11-15T03:30:26.000Z"
],
"sophos.xg.out_display_interface": [
"Port2"
],
"destination.geo.location": [
{
"coordinates": [
143.2104,
-33.494
],
"type": "Point"
}
],
"sophos.xg.app_filter_policy_id": [
"6"
],
"agent.type": [
"filebeat"
],
"source.mac": [
"10:BF:48:7D:ED:22"
],
"event.module": [
"sophos"
],
"related.ip": [
"192.168.2.121",
"1.1.1.1"
],
"sophos.xg.icmp_type": [
"8"
],
"sophos.xg.severity": [
"Information"
],
"observer.product": [
"XG"
],
"event.timezone": [
"-06:00"
],
"sophos.xg.packets_sent": [
"2 "
],
"sophos.xg.fw_rule_type": [
"USER"
],
"sophos.xg.web_policy_id": [
"12"
],
"sophos.xg.app_is_cloud": [
"FALSE"
],
"destination.as.number": [
13335
],
"sophos.xg.hb_status": [
"No Heartbeat"
],
"destination.as.organization.name.text": [
"CLOUDFLARENET"
],
"destination.ip": [
"1.1.1.1"
],
"network.transport": [
"icmp"
],
"event.duration": [
33000000000
],
"sophos.xg.dst_country": [
"AUS"
],
"event.action": [
"allowed"
],
"sophos.xg.ips_policy_id": [
8
],
"event.ingested": [
"2021-11-15T03:29:53.331Z"
],
"@timestamp": [
"2021-11-15T03:29:53.000Z"
],
"destination.geo.country_iso_code": [
"AU"
],
"sophos.xg.in_display_interface": [
"Port1"
],
"sophos.xg.log_subtype": [
"Allowed"
],
"agent.ephemeral_id": [
"f8b595b3-d15f-488d-9022-5b86b38396a1"
],
"sophos.xg.log_component": [
"Firewall Rule"
],
"event.dataset": [
"sophos.xg"
],
"sophos.xg.device_model": [
"SFVH"
],
"destination.as.organization.name": [
"CLOUDFLARENET"
]
}
}
I do not know how to do a POST, I will go through forum posts on how to complete a POST and and figure out how to complete one and let you know my result. Should that POST go to filebeat or to elastic-search?