2022-11-18 13:19:06 -05:00
|
|
|
---
|
|
|
|
layout: default
|
|
|
|
title: Mappings APIs
|
|
|
|
parent: API tools
|
|
|
|
nav_order: 45
|
|
|
|
---
|
|
|
|
|
|
|
|
# Mappings APIs
|
|
|
|
|
|
|
|
The following APIs can be used for a number of tasks related to mappings, from creating to getting and updating mappings.
|
|
|
|
|
2023-07-25 17:03:50 -04:00
|
|
|
---
|
2022-11-18 13:19:06 -05:00
|
|
|
## Get Mappings View
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
This API returns a view of the fields contained in an index used as a log source.
|
2023-07-17 16:52:13 -04:00
|
|
|
|
|
|
|
### Request fields
|
|
|
|
|
|
|
|
The following fields are used to get field mappings.
|
|
|
|
|
|
|
|
Field | Type | Description
|
2023-08-03 20:04:58 -04:00
|
|
|
:--- | :--- |:---
|
|
|
|
`index_name` | String | The name of the index used for log ingestion.
|
|
|
|
`rule_topic` | String | The log type of the index.
|
2023-07-17 16:52:13 -04:00
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example request
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
GET /_plugins/_security_analytics/mappings/view
|
|
|
|
|
|
|
|
{
|
|
|
|
"index_name": "windows",
|
|
|
|
"rule_topic": "windows"
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example response
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
{
|
|
|
|
"properties": {
|
|
|
|
"windows-event_data-CommandLine": {
|
|
|
|
"path": "CommandLine",
|
|
|
|
"type": "alias"
|
|
|
|
},
|
|
|
|
"event_uid": {
|
|
|
|
"path": "EventID",
|
|
|
|
"type": "alias"
|
|
|
|
}
|
|
|
|
},
|
|
|
|
"unmapped_index_fields": [
|
|
|
|
"windows-event_data-CommandLine",
|
|
|
|
"unmapped_HiveName",
|
|
|
|
"src_ip",
|
|
|
|
"sha1",
|
|
|
|
"processPath",
|
|
|
|
"CallerProcessName",
|
|
|
|
"CallTrace",
|
|
|
|
"AuthenticationPackageName",
|
|
|
|
"AuditSourceName",
|
|
|
|
"AuditPolicyChanges",
|
|
|
|
"AttributeValue",
|
|
|
|
"AttributeLDAPDisplayName",
|
|
|
|
"ApplicationPath",
|
|
|
|
"Application",
|
|
|
|
"AllowedToDelegateTo",
|
|
|
|
"Address",
|
|
|
|
"Action",
|
|
|
|
"AccountType",
|
|
|
|
"AccountName",
|
|
|
|
"Accesses",
|
|
|
|
"AccessMask",
|
|
|
|
"AccessList"
|
|
|
|
]
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|
|
|
|
---
|
|
|
|
## Create Mappings
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example request
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
POST /_plugins/_security_analytics/mappings
|
|
|
|
|
|
|
|
{
|
|
|
|
"index_name": "windows",
|
|
|
|
"rule_topic": "windows",
|
|
|
|
"partial": true,
|
|
|
|
"alias_mappings": {
|
|
|
|
"properties": {
|
|
|
|
"event_uid": {
|
|
|
|
"type": "alias",
|
|
|
|
"path": "EventID"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example response
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
{
|
|
|
|
"acknowledged": true
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|
|
|
|
---
|
|
|
|
## Get Mappings
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example request
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
GET /_plugins/_security_analytics/mappings
|
|
|
|
```
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example response
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
{
|
|
|
|
"windows": {
|
|
|
|
"mappings": {
|
|
|
|
"properties": {
|
|
|
|
"windows-event_data-CommandLine": {
|
|
|
|
"type": "alias",
|
|
|
|
"path": "CommandLine"
|
|
|
|
},
|
|
|
|
"event_uid": {
|
|
|
|
"type": "alias",
|
|
|
|
"path": "EventID"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|
|
|
|
---
|
|
|
|
## Update Mappings
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example request
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
PUT /_plugins/_security_analytics/mappings
|
|
|
|
|
|
|
|
{
|
|
|
|
"index_name": "windows",
|
|
|
|
"field": "CommandLine",
|
|
|
|
"alias": "windows-event_data-CommandLine"
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|
2023-08-03 20:04:58 -04:00
|
|
|
#### Example response
|
2022-11-18 13:19:06 -05:00
|
|
|
|
|
|
|
```json
|
|
|
|
{
|
|
|
|
"acknowledged": true
|
|
|
|
}
|
|
|
|
```
|
|
|
|
|