云日志服务 LTS-创建结构化配置(推荐):请求示例

时间:2023-11-01 16:16:13

请求示例

  • 系统模板: CTS
    {    "log_group_id": "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",    "log_stream_id": "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",    "demo_fields": [        {            "field_name": "code"        },        {            "field_name": "event_type"        },        {            "field_name": "project_id"        },        {            "field_name": "record_time"        },        {            "field_name": "resource_id"        },        {            "field_name": "resource_name"        },        {            "field_name": "resource_type"        },        {            "field_name": "service_type"        },        {            "field_name": "source_ip"        },        {            "field_name": "time"        },        {            "field_name": "trace_id"        },        {            "field_name": "trace_name"        },        {            "field_name": "trace_rating"        },        {            "field_name": "trace_type"        },        {            "field_name": "tracker_name"        },        {            "field_name": "user.domain.id"        },        {            "field_name": "user.domain.name"        },        {            "field_name": "user.id"        },        {            "field_name": "user.name"        }    ],    "tag_fields": [        {            "field_name": "hostIP"        }    ],    "template_type": "built_in",    "template_name": "CTS",    "template_id": "",    "quick_analysis": false}
  • 系统模板:ELB
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",    "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",    "demo_fields" : [ {      "field_name" : "msec",      "is_analysis" : false    }, {      "field_name" : "access_log_topic_id",      "is_analysis" : false    }, {      "field_name" : "time_iso8601",      "is_analysis" : false    }, {      "field_name" : "log_ver",      "is_analysis" : true    }, {      "field_name" : "remote_addr",      "is_analysis" : true    }, {      "field_name" : "remote_port",      "is_analysis" : false    }, {      "field_name" : "status",      "is_analysis" : false    }, {      "field_name" : "request_method",      "is_analysis" : false    }, {      "field_name" : "scheme",      "is_analysis" : true    }, {      "field_name" : "host",      "is_analysis" : true    }, {      "field_name" : "router_request_uri",      "is_analysis" : true    }, {      "field_name" : "server_protocol",      "is_analysis" : true    }, {      "field_name" : "request_length",      "is_analysis" : true    }, {      "field_name" : "bytes_sent",      "is_analysis" : false    }, {      "field_name" : "body_bytes_sent",      "is_analysis" : false    }, {      "field_name" : "request_time",      "is_analysis" : false    }, {      "field_name" : "upstream_status",      "is_analysis" : false    }, {      "field_name" : "upstream_connect_time",      "is_analysis" : false    }, {      "field_name" : "upstream_header_time",      "is_analysis" : false    }, {      "field_name" : "upstream_response_time",      "is_analysis" : false    }, {      "field_name" : "upstream_addr",      "is_analysis" : false    }, {      "field_name" : "http_user_agent",      "is_analysis" : false    }, {      "field_name" : "http_referer",      "is_analysis" : false    }, {      "field_name" : "http_x_forwarded_for",      "is_analysis" : false    }, {      "field_name" : "lb_name",      "is_analysis" : false    }, {      "field_name" : "listener_name",      "is_analysis" : false    }, {      "field_name" : "listener_id",      "is_analysis" : false    }, {      "field_name" : "pool_name",      "is_analysis" : false    }, {      "field_name" : "member_name",      "is_analysis" : false    }, {      "field_name" : "tenant_id",      "is_analysis" : false    }, {      "field_name" : "eip_address",      "is_analysis" : false    }, {      "field_name" : "eip_port",      "is_analysis" : false    }, {      "field_name" : "upstream_addr_priv",      "is_analysis" : false    }, {      "field_name" : "certificate_id",      "is_analysis" : false    }, {      "field_name" : "ssl_protocol",      "is_analysis" : false    }, {      "field_name" : "ssl_cipher",      "is_analysis" : false    }, {      "field_name" : "sni_domain_name",      "is_analysis" : false    }, {      "field_name" : "tcpinfo_rtt",      "is_analysis" : false    } ],     "tag_fields": [        {            "field_name": "hostIP",            "is_analysis": true        }    ],   "template_type" : "built_in",    "template_name" : "ELB",    "template_id" : "",    "quick_analysis" : false  }
  • 自定义模板
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",    "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",    "demo_fields" : [ {      "field_name" : "date",      "is_analysis" : true    }, {      "field_name" : "num",      "is_analysis" : false    } ],    "tag_fields" : [ {      "field_name" : "hostIP",      "is_analysis" : true    } ],    "template_type" : "custom",    "template_name" : "regexTemplate",    "template_id" : "47629e46-287d-478c-8888-xxxxxxxxxxxx",    "quick_analysis" : false  }
  • 系统模板:VPC
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",    "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",    "demo_fields" : [ {      "field_name" : "version",      "is_analysis" : false    }, {      "field_name" : "project_id",      "is_analysis" : true    }, {      "field_name" : "interface_id",      "is_analysis" : false    }, {      "field_name" : "srcaddr",      "is_analysis" : true    }, {      "field_name" : "dstaddr",      "is_analysis" : true    }, {      "field_name" : "srcport",      "is_analysis" : false    }, {      "field_name" : "dstport",      "is_analysis" : false    }, {      "field_name" : "protocol",      "is_analysis" : false    }, {      "field_name" : "packets",      "is_analysis" : false    }, {      "field_name" : "bytes",      "is_analysis" : false    }, {      "field_name" : "start",      "is_analysis" : false    }, {      "field_name" : "end",      "is_analysis" : false    }, {      "field_name" : "action",      "is_analysis" : true    }, {      "field_name" : "log_status",      "is_analysis" : true    } ],     "tag_fields": [        {            "field_name": "hostIP",            "is_analysis": true        }    ],   "template_type" : "built_in",    "template_name" : "VPC",    "template_id" : "",    "quick_analysis" : false  }
  • 系统模板:APIG
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",    "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",    "demo_fields" : [ {      "field_name" : "my_remote_addr",      "is_analysis" : false    }, {      "field_name" : "request_id",      "is_analysis" : false    }, {      "field_name" : "api_id",      "is_analysis" : false    }, {      "field_name" : "user_name",      "is_analysis" : true    }, {      "field_name" : "app_id",      "is_analysis" : true    }, {      "field_name" : "time_local",      "is_analysis" : false    }, {      "field_name" : "request_time",      "is_analysis" : false    }, {      "field_name" : "request_method",      "is_analysis" : false    }, {      "field_name" : "scheme",      "is_analysis" : true    }, {      "field_name" : "host",      "is_analysis" : true    }, {      "field_name" : "router_uri",      "is_analysis" : true    }, {      "field_name" : "server_protocol",      "is_analysis" : true    }, {      "field_name" : "status",      "is_analysis" : true    }, {      "field_name" : "bytes_sent",      "is_analysis" : false    }, {      "field_name" : "request_length",      "is_analysis" : false    }, {      "field_name" : "http_user_agent",      "is_analysis" : false    }, {      "field_name" : "http_x_forwarded_for",      "is_analysis" : false    }, {      "field_name" : "upstream_addr",      "is_analysis" : false    }, {      "field_name" : "upstream_uri",      "is_analysis" : false    }, {      "field_name" : "upstream_status",      "is_analysis" : false    }, {      "field_name" : "upstream_connect_time",      "is_analysis" : false    }, {      "field_name" : "upstream_header_time",      "is_analysis" : false    }, {      "field_name" : "upstream_response_time",      "is_analysis" : false    }, {      "field_name" : "region_id",      "is_analysis" : false    }, {      "field_name" : "all_upstream_response_time",      "is_analysis" : false    }, {      "field_name" : "errorType",      "is_analysis" : false    }, {      "field_name" : "auth_type",      "is_analysis" : false    }, {      "field_name" : "access_model1",      "is_analysis" : false    }, {      "field_name" : "access_model2",      "is_analysis" : false    }, {      "field_name" : "inner_time",      "is_analysis" : false    }, {      "field_name" : "proxy_protocol_vni",      "is_analysis" : false    }, {      "field_name" : "proxy_protocol_vpce_id",      "is_analysis" : false    }, {      "field_name" : "proxy_protocol_addr",      "is_analysis" : false    }, {      "field_name" : "body_bytes_sent",      "is_analysis" : false    }, {      "field_name" : "api_name",      "is_analysis" : false    }, {      "field_name" : "app_name",      "is_analysis" : false    }, {      "field_name" : "provider_app_id",      "is_analysis" : false    }, {      "field_name" : "provider_app_name",      "is_analysis" : false    }, {      "field_name" : "custom_data_log1",      "is_analysis" : false    }, {      "field_name" : "custom_data_log2",      "is_analysis" : false    }, {      "field_name" : "custom_data_log3",      "is_analysis" : false    }, {      "field_name" : "custom_data_log4",      "is_analysis" : false    }, {      "field_name" : "custom_data_log5",      "is_analysis" : false    }, {      "field_name" : "custom_data_log6",      "is_analysis" : false    }, {      "field_name" : "custom_data_log7",      "is_analysis" : false    }, {      "field_name" : "custom_data_log8",      "is_analysis" : false    }, {      "field_name" : "custom_data_log9",      "is_analysis" : false    }, {      "field_name" : "custom_data_log10",      "is_analysis" : false    }, {      "field_name" : "response_source",      "is_analysis" : false    } ],     "tag_fields": [        {            "field_name": "hostIP",            "is_analysis": true        }    ],   "template_type" : "built_in",    "template_name" : "APIG",    "template_id" : "",    "quick_analysis" : false  }
  • DDS审计日志
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",    "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",    "demo_fields" : [ {      "field_name" : "time",      "is_analysis" : false    }, {      "field_name" : "instance_id",      "is_analysis" : false    }, {      "field_name" : "server_addr",      "is_analysis" : false    }, {      "field_name" : "role",      "is_analysis" : false    }, {      "field_name" : "client_addr",      "is_analysis" : false    }, {      "field_name" : "client_type",      "is_analysis" : false    }, {      "field_name" : "user",      "is_analysis" : false    }, {      "field_name" : "db",      "is_analysis" : false    }, {      "field_name" : "command_name",      "is_analysis" : false    }, {      "field_name" : "command_type",      "is_analysis" : false    }, {      "field_name" : "command_keys",      "is_analysis" : false    }, {      "field_name" : "command_param",      "is_analysis" : false    }, {      "field_name" : "use_time",      "is_analysis" : false    }, {      "field_name" : "extend",      "is_analysis" : false    }],    "tag_fields": [        {            "field_name": "hostIP"        }    ],   "template_type" : "built_in",    "template_name" : "DDS_AUDIT",    "template_id" : "",    "quick_analysis" : false  }
  • DDS错误日志
    {     "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",     "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",     "demo_fields" : [ {       "field_name" : "log_type",       "is_analysis" : false     }, {       "field_name" : "severity",       "is_analysis" : false     }, {       "field_name" : "log_time",       "is_analysis" : false     }, {       "field_name" : "raw_message",       "is_analysis" : true     }, {       "field_name" : "instance_id",       "is_analysis" : true     }, {       "field_name" : "node_id",       "is_analysis" : false     } ],      "tag_fields": [         {             "field_name": "hostIP",             "is_analysis": true         }     ],    "template_type" : "built_in",     "template_name" : "MONGODB_ERROR",     "template_id" : "",     "quick_analysis" : false   } 
  • DDS慢日志
    {     "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",     "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",     "demo_fields" : [ {       "field_name" : "log_type",       "is_analysis" : false     }, {       "field_name" : "log_time",       "is_analysis" : false     }, {       "field_name" : "namespace",       "is_analysis" : false     }, {       "field_name" : "database",       "is_analysis" : true     }, {       "field_name" : "collection",       "is_analysis" : true     }, {       "field_name" : "operate_type",       "is_analysis" : false     }, {       "field_name" : "docs_scanned",       "is_analysis" : false     }, {       "field_name" : "docs_returned",       "is_analysis" : false     }, {       "field_name" : "n_deleted",       "is_analysis" : true     }, {       "field_name" : "n_matched",       "is_analysis" : true     }, {       "field_name" : "n_modified",       "is_analysis" : true     }, {       "field_name" : "n_inserted",       "is_analysis" : true     }, {       "field_name" : "cost_time",       "is_analysis" : true     }, {       "field_name" : "lock_time",       "is_analysis" : false     }, {       "field_name" : "whole_message",       "is_analysis" : false     }, {       "field_name" : "instance_id",       "is_analysis" : false     }, {       "field_name" : "node_id",       "is_analysis" : false     } ],      "tag_fields": [         {             "field_name": "hostIP",             "is_analysis": true         }     ],    "template_type" : "built_in",     "template_name" : "MONGODB_SLOW",     "template_id" : "",     "quick_analysis" : false   } 
  • GAUSSDB_OPENGAUSS_AUDIT
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",    "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",    "demo_fields" : [ {      "field_name" : "username",      "is_analysis" : false    }, {      "field_name" : "client_conninfo",      "is_analysis" : false    }, {      "field_name" : "instanceId",      "is_analysis" : false    }, {      "field_name" : "detail_info",      "is_analysis" : false    }, {      "field_name" : "thread_id",      "is_analysis" : false    }, {      "field_name" : "result",      "is_analysis" : false    }, {      "field_name" : "database",      "is_analysis" : false    }, {      "field_name" : "local_port",      "is_analysis" : false    }, {      "field_name" : "userid",      "is_analysis" : false    }, {      "field_name" : "nodeId",      "is_analysis" : false    }, {      "field_name" : "node_name",      "is_analysis" : false    }, {      "field_name" : "object_name",      "is_analysis" : false    }, {      "field_name" : "time",      "is_analysis" : false   }, {      "field_name" : "type",      "is_analysis" : false    }, {      "field_name" : "remote_port",      "is_analysis" : false    }],      "tag_fields": [        {            "field_name": "hostIP"        }    ],   "template_type" : "built_in",    "template_name" : "GAUSSDB_OPENGAUSS_AUDIT",    "template_id" : "",    "quick_analysis" : false  }
  • NGINX
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",    "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",    "demo_fields" : [ {      "field_name" : "remote_addr",      "is_analysis" : false    }, {      "field_name" : "remote_user",      "is_analysis" : false    }, {      "field_name" : "time_local",      "is_analysis" : false    }, {      "field_name" : "request_method",      "is_analysis" : false    }, {      "field_name" : "scheme",      "is_analysis" : false    }, {      "field_name" : "host",      "is_analysis" : false    }, {      "field_name" : "request_uri",      "is_analysis" : false    }, {      "field_name" : "server_protocol",      "is_analysis" : false    }, {      "field_name" : "status",      "is_analysis" : false    }, {      "field_name" : "bytes_sent",      "is_analysis" : false    }, {      "field_name" : "body_bytes_sent",      "is_analysis" : false    }, {      "field_name" : "http_referer",      "is_analysis" : false    }, {      "field_name" : "http_user_agent",      "is_analysis" : false   }, {      "field_name" : "http_x_forwarded_for",      "is_analysis" : false    }, {      "field_name" : "request_time",      "is_analysis" : false    }, {      "field_name" : "upstream_response_time",      "is_analysis" : false    }, {      "field_name" : "upstream_addr",      "is_analysis" : false    }, {      "field_name" : "upstream_status",      "is_analysis" : false    }, {      "field_name" : "request_length",      "is_analysis" : false    }],    "tag_fields": [        {            "field_name": "hostIP"        }    ],   "template_type" : "built_in",    "template_name" : "NGINX",    "template_id" : "",    "quick_analysis" : false  }
  • TOMCAT
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",    "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",    "demo_fields" : [ {      "field_name" : "remote_ip_address",      "is_analysis" : false    }, {      "field_name" : "remote_logical_username",      "is_analysis" : false    }, {      "field_name" : "remote_user_authenticated",      "is_analysis" : false    }, {      "field_name" : "time_local",      "is_analysis" : false    }, {      "field_name" : "scheme",      "is_analysis" : false    }, {      "field_name" : "router_uri",      "is_analysis" : false    }, {      "field_name" : "server_protocol",      "is_analysis" : false    }, {      "field_name" : "status",      "is_analysis" : false    }, {      "field_name" : "bytes_sent",      "is_analysis" : false    }],     "tag_fields": [        {            "field_name": "hostIP"        }    ],   "template_type" : "built_in",    "template_name" : "TOMCAT",    "template_id" : "",    "quick_analysis" : false  }
  • D CS 审计日志
    {    "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",    "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",    "demo_fields" : [ {      "field_name" : "time",      "is_analysis" : false    }, {      "field_name" : "instance_id",      "is_analysis" : false    }, {      "field_name" : "server_addr",      "is_analysis" : false    }, {      "field_name" : "role",      "is_analysis" : false    }, {      "field_name" : "client_addr",      "is_analysis" : false    }, {      "field_name" : "client_type",      "is_analysis" : false    }, {      "field_name" : "user",      "is_analysis" : false    }, {      "field_name" : "db",      "is_analysis" : false    }, {      "field_name" : "command_name",      "is_analysis" : false    }, {      "field_name" : "command_type",      "is_analysis" : false    }, {      "field_name" : "command_keys",      "is_analysis" : false    }, {      "field_name" : "command_param",      "is_analysis" : false    }, {      "field_name" : "use_time",      "is_analysis" : false    }, {      "field_name" : "extend",      "is_analysis" : false    }],    "tag_fields": [        {            "field_name": "hostIP"        }    ],   "template_type" : "built_in",    "template_name" : "DCS_AUDIT",    "template_id" : "",    "quick_analysis" : false  }
  • CFW攻击日志
    {     "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",     "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",     "demo_fields" : [ {       "field_name" : "source",       "is_analysis" : false     }, {       "field_name" : "app",       "is_analysis" : false     }, {       "field_name" : "direction",       "is_analysis" : false     }, {       "field_name" : "dst_ip",       "is_analysis" : true     }, {       "field_name" : "src_ip",       "is_analysis" : true     }, {       "field_name" : "event_time",       "is_analysis" : false     }, {       "field_name" : "log_type",       "is_analysis" : false     }, {       "field_name" : "dst_port",       "is_analysis" : false     }, {       "field_name" : "attack_rule_id",       "is_analysis" : true     }, {       "field_name" : "index_day",       "is_analysis" : true     }, {       "field_name" : "log_id",       "is_analysis" : true     }, {       "field_name" : "src_port",       "is_analysis" : true     }, {       "field_name" : "protocol",       "is_analysis" : true     }, {       "field_name" : "packet",       "is_analysis" : false     }, {       "field_name" : "level",       "is_analysis" : false     }, {       "field_name" : "attack_type",       "is_analysis" : false     }, {       "field_name" : "fw_instance_id",       "is_analysis" : false     }, {       "field_name" : "action",       "is_analysis" : false     }, {       "field_name" : "vsys",       "is_analysis" : false     }, {       "field_name" : "attack_rule",       "is_analysis" : false     } ],      "tag_fields": [         {             "field_name": "hostIP",             "is_analysis": true         }     ],    "template_type" : "built_in",     "template_name" : "CFW_ATTACK",     "template_id" : "",     "quick_analysis" : false   } 
support.huaweicloud.com/api-lts/lts_api_1076.html