Hi everyone,
This image shows the part of the document we are focusing on, extracted from the index populated through the integration with Trend Micro Vision One:
The complete document looks like this and includes the event.original
attribute, which is a complete JSON:
{
"_index": "\"***\"",
"_id": "\"***\"",
"_version": 1,
"_score": 0,
"_source": {
"agent": {
"name": "\"***\"",
"id": "\"***\"",
"ephemeral_id": "\"***\"",
"type": "\"***\"",
"version": "\"***\""
},
"trend_micro_vision_one": {
"alert": {
"impact_scope": {
"email_address_count": 0,
"entities": [
{
"provenance": [
"\"***\""
],
"managementScopeGroupId": "\"***\"",
"related_indicator_id": [
1,
2,
3,
4
],
"id": "\"***\"",
"type": "\"***\"",
"value": {
"name": "\"***\"",
"guid": "\"***\"",
"ips": [
"\"***\""
]
}
},
{
"provenance": [
"\"***\""
],
"managementScopeGroupId": "\"***\"",
"related_indicator_id": [
2,
4,
5,
6,
7,
8,
9,
10,
11,
12,
13,
14,
15,
16
],
"id": "\"***\"",
"type": "\"***\"",
"value": {
"account_value": "\"***\""
}
}
],
"desktop_count": 1,
"server_count": 0,
"account_count": 0
},
"description": "\"***\"",
"indicators": [
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\"",
"\"***\""
],
"id": 1,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\"",
"\"***\""
],
"id": 2,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\"",
"\"***\""
],
"id": 3,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\"",
"\"***\""
],
"id": 4,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 5,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 6,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 7,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 8,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 9,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 10,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 11,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 12,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 13,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 14,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 15,
"type": "\"***\"",
"value": "\"***\""
},
{
"provenance": [
"\"***\""
],
"field": "\"***\"",
"filter_id": [
"\"***\""
],
"related_entities": [
"\"***\""
],
"id": 16,
"type": "\"***\"",
"value": "\"***\""
}
],
"schema_version": "\"***\"",
"investigation_status": "\"***\"",
"alert_provider": "\"***\"",
"model": "\"***\"",
"matched_rule": [
{
"filter": [
{
"date": "\"***\"",
"name": "\"***\"",
"mitre_technique_id": [
"\"***\""
],
"id": "\"***\"",
"events": [
{
"date": "\"***\"",
"type": "\"***\"",
"uuid": "\"***\""
}
]
},
{
"date": "\"***\"",
"name": "\"***\"",
"mitre_technique_id": [
"\"***\""
],
"id": "\"***\"",
"events": [
{
"date": "\"***\"",
"type": "\"***\"",
"uuid": "\"***\""
}
]
}
],
"name": "\"***\"",
"id": "\"***\""
}
],
"created_date": "\"***\"",
"workbench_link": "\"***\""
}
},
"log": {
"level": "\"***\""
},
"elastic_agent": {
"id": "\"***\"",
"version": "\"***\"",
"snapshot": false
},
"url": {
"path": "\"***\"",
"fragment": "\"***\"",
"extension": "\"***\"",
"original": "\"***\"",
"scheme": "\"***\"",
"domain": "\"***\""
},
"tags": [
"\"***\"",
"\"***\"",
"\"***\""
],
"cloud": {
"availability_zone": "\"***\"",
"instance": {
"name": "\"***\"",
"id": "\"***\""
},
"provider": "\"***\"",
"service": {
"name": "\"***\""
},
"machine": {
"type": "\"***\""
}
},
"input": {
"type": "\"***\""
},
"@timestamp": "\"***\"",
"ecs": {
"version": "\"***\""
},
"related": {
"ip": [
"\"***\""
]
},
"data_stream": {
"namespace": "\"***\"",
"type": "\"***\"",
"dataset": "\"***\""
},
"event": {
"severity": 30,
"agent_id_status": "\"***\"",
"ingested": "\"***\"",
"original": "\"eventOriginalinJSON\"",
"created": "\"***\"",
"kind": "\"***\"",
"id": "\"***\"",
"category": [
"\"***\""
],
"type": [
"\"***\""
],
"dataset": "\"***\""
}
},
"fields": {
"elastic_agent.version": [
"\"***\""
],
"event.category": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.value.account_value": [
"\"***\""
],
"url.original.text": [
"\"***\""
],
"cloud.availability_zone": [
"\"***\""
],
"trend_micro_vision_one.alert.schema_version": [
"\"***\""
],
"trend_micro_vision_one.alert.description": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.value.guid": [
"\"***\""
],
"log.level": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.value.name": [
"\"***\""
],
"agent.name": [
"\"***\""
],
"trend_micro_vision_one.alert.indicators.id": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"event.agent_id_status": [
"\"***\""
],
"event.kind": [
"\"***\""
],
"url.fragment": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.email_address_count": [
0
],
"event.severity": [
30
],
"trend_micro_vision_one.alert.matched_rule.filter.id": [
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.matched_rule.filter.mitre_technique_id": [
"\"***\"",
"\"***\""
],
"event.original": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.provenance": [
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.matched_rule.id": [
"\"***\""
],
"trend_micro_vision_one.alert.matched_rule.name": [
"\"***\""
],
"trend_micro_vision_one.alert.model": [
"\"***\""
],
"url.extension": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.managementScopeGroupId": [
"\"***\"",
"\"***\""
],
"input.type": [
"\"***\""
],
"trend_micro_vision_one.alert.alert_provider": [
"\"***\""
],
"data_stream.type": [
"\"***\""
],
"trend_micro_vision_one.alert.created_date": [
"\"***\""
],
"tags": [
"\"***\"",
"\"***\"",
"\"***\""
],
"cloud.machine.type": [
"\"***\""
],
"cloud.provider": [
"\"***\""
],
"trend_micro_vision_one.alert.investigation_status": [
"\"***\""
],
"url.path": [
"\"***\""
],
"agent.id": [
"\"***\""
],
"cloud.service.name": [
"\"***\""
],
"ecs.version": [
"\"***\""
],
"event.created": [
"\"***\""
],
"trend_micro_vision_one.alert.matched_rule.filter.name": [
"\"***\"",
"\"***\""
],
"agent.version": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.desktop_count": [
1
],
"trend_micro_vision_one.alert.indicators.field": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.value.ips": [
"\"***\""
],
"trend_micro_vision_one.alert.indicators.related_entities": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.account_count": [
0
],
"url.scheme": [
"\"***\""
],
"trend_micro_vision_one.alert.indicators.provenance": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"cloud.instance.id": [
"\"***\""
],
"agent.type": [
"\"***\""
],
"event.module": [
"\"***\""
],
"related.ip": [
"\"***\""
],
"trend_micro_vision_one.alert.indicators.filter_id": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"elastic_agent.snapshot": [
false
],
"trend_micro_vision_one.alert.impact_scope.server_count": [
0
],
"trend_micro_vision_one.alert.matched_rule.filter.events.uuid": [
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.indicators.value": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.related_indicator_id": [
1,
2,
3,
4,
2,
4,
5,
6,
7,
8,
9,
10,
11,
12,
13,
14,
15,
16
],
"trend_micro_vision_one.alert.matched_rule.filter.date": [
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.matched_rule.filter.events.date": [
"\"***\"",
"\"***\""
],
"elastic_agent.id": [
"\"***\""
],
"data_stream.namespace": [
"\"***\""
],
"trend_micro_vision_one.alert.matched_rule.filter.events.type": [
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.indicators.type": [
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\"",
"\"***\""
],
"trend_micro_vision_one.alert.workbench_link": [
"\"***\""
],
"event.ingested": [
"\"***\""
],
"url.original": [
"\"***\""
],
"@timestamp": [
"\"***\""
],
"data_stream.dataset": [
"\"***\""
],
"event.type": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.id": [
"\"***\"",
"\"***\""
],
"url.domain": [
"\"***\""
],
"agent.ephemeral_id": [
"\"***\""
],
"trend_micro_vision_one.alert.impact_scope.entities.type": [
"\"***\"",
"\"***\""
],
"event.id": [
"\"***\""
],
"event.dataset": [
"\"***\""
],
"cloud.instance.name": [
"\"***\""
]
}
}
Within this document, here is the specific content of the event.original
field:
{
"alertProvider": "\"***\"",
"createdDateTime": "\"***\"",
"description": "\"***\"",
"id": "\"***\"",
"impactScope": {
"accountCount": 0,
"cloudIdentityCount": 0,
"containerCount": 1,
"desktopCount": 1,
"emailAddressCount": 0,
"entities": [
{
"entityId": "\"***\"",
"entityType": "\"***\"",
"entityValue": {
"guid": "\"***\"",
"ips": [
"\"***\""
],
"name": "\"***\""
},
"managementScopeGroupId": "\"***\"",
"provenance": [
"\"***\""
],
"relatedEntities": [],
"relatedIndicatorIds": [
1,
2,
3,
4
]
},
{
"entityId": "\"***\"",
"entityType": "\"***\"",
"entityValue": "\"***\"",
"managementScopeGroupId": "\"***\"",
"provenance": [
"\"***\""
],
"relatedEntities": [],
"relatedIndicatorIds": [
2,
4,
5,
6,
7,
8,
9,
10,
11,
12,
13,
14,
15,
16
]
}
],
"serverCount": 0
},
"indicators": [
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 1,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\"",
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 2,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\"",
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 3,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\"",
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 4,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\"",
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 5,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 6,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 7,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 8,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 9,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 10,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 11,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 12,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 13,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 14,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"***\"",
"filterIds": [
"\"***\""
],
"id": 15,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"***\""
},
{
"field": "\"valueTobeExtract\"",
"filterIds": [
"\"***\""
],
"id": 16,
"provenance": [
"\"***\""
],
"relatedEntities": [
"\"***\""
],
"type": "\"***\"",
"value": "\"valueTobeExtract\""
}
],
"investigationResult": "\"***\"",
"investigationStatus": "\"***\"",
"matchedRules": [
{
"id": "\"***\"",
"matchedFilters": [
{
"id": "\"***\"",
"matchedDateTime": "\"***\"",
"matchedEvents": [
{
"matchedDateTime": "\"***\"",
"type": "\"***\"",
"uuid": "\"***\""
}
],
"mitreTechniqueIds": [
"\"***\""
],
"name": "\"***\""
},
{
"id": "\"***\"",
"matchedDateTime": "\"***\"",
"matchedEvents": [
{
"matchedDateTime": "\"***\"",
"type": "\"***\"",
"uuid": "\"***\""
}
],
"mitreTechniqueIds": [
"\"***\""
],
"name": "\"***\""
}
],
"name": "\"***\""
}
],
"model": "\"***\"",
"modelId": "\"***\"",
"modelType": "\"***\"",
"ownerIds": [],
"schemaVersion": "\"***\"",
"score": 30,
"severity": "\"***\"",
"status": "\"***\"",
"updatedDateTime": "\"***\"",
"workbenchLink": "\"***\""
}
My goal is to extract the values associated with the key valueToBeExtract
from this nested JSON (event.original
).
I also noticed that when I perform a search using KQL on the attribute trend_micro_vision_one.alert.indicators.value
, it only evaluates the first value in the JSON object, not the subsequent ones. I’m not sure why this happens.
Thanks in advance for any suggestions or help!