您好,登錄后才能下訂單哦!
alienvault庫的報警、事件表結(jié)構(gòu)
作為OSSIM數(shù)據(jù)庫開發(fā)者,以下alienvault庫的報警、事件表結(jié)構(gòu),需要了解。
Field | Type | Allow Null | Default Value |
---|---|---|---|
backlog_id | binary(16) | No | |
event_id | binary(16) | No | |
corr_engine_ctx | binary(16) | No | |
timestamp | timestamp | Yes | |
status | enum('open','closed') | Yes | 'open' |
plugin_id | int(11) | No | |
plugin_sid | int(11) | No | |
protocol | int(11) | Yes | |
src_ip | varbinary(16) | Yes | |
dst_ip | varbinary(16) | Yes | |
src_port | int(11) | Yes | |
dst_port | int(11) | Yes | |
risk | int(11) | Yes | |
efr | int(11) | No | 0 |
similar | varchar(40) | No | '0000000000000000000000000000000000000000' |
stats | mediumtext | No | |
removable | tinyint(1) | No | 0 |
in_file | tinyint(1) | No | 0 |
Field | Type | Allow Null | Default Value |
---|---|---|---|
group_id | varchar(255) | No | |
description | text | No | |
status | enum('open','closed') | No | |
timestamp | timestamp | No | CURRENT_TIMESTAMP |
owner | varchar(64) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id_alarm | binary(16) | No | |
id_host | binary(16) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | int(11) | No | |
name | varchar(128) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id_alarm | binary(16) | No | |
id_net | binary(16) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id_alarm | binary(16) | No | |
id_tag | int(11) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
sid | int(11) | No | |
engine_id | binary(16) | No | '\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0' |
kingdom | int(11) | No | |
category | int(11) | No | |
subcategory | text | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | int(10) UNSIGNED | No | |
ctx | binary(16) | No | |
name | varchar(64) | No | |
ip | varbinary(16) | No | |
port | int(11) | No | 3306 |
user | varchar(64) | No | |
pass | varchar(64) | No | |
icon | mediumblob | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | int(11) | No | |
name | varchar(64) | No | |
class | int(11) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | binary(16) | No | |
agent_ctx | binary(16) | No | |
timestamp | timestamp | No | CURRENT_TIMESTAMP |
tzone | float | No | 0 |
sensor_id | binary(16) | Yes | |
interface | varchar(32) | No | |
type | int(11) | No | |
plugin_id | int(11) | No | |
plugin_sid | int(11) | No | |
protocol | int(11) | Yes | |
src_ip | varbinary(16) | Yes | |
dst_ip | varbinary(16) | Yes | |
src_port | int(11) | Yes | |
dst_port | int(11) | Yes | |
event_condition | int(11) | Yes | |
value | text | Yes | |
time_interval | int(11) | Yes | |
absolute | tinyint(4) | Yes | |
priority | int(11) | Yes | 1 |
reliability | int(11) | Yes | 1 |
asset_src | int(11) | Yes | 1 |
asset_dst | int(11) | Yes | 1 |
risk_a | int(11) | Yes | 0 |
risk_c | int(11) | Yes | 0 |
alarm | tinyint(4) | Yes | 0 |
filename | varchar(256) | Yes | |
username | varchar(64) | Yes | |
password | varchar(64) | Yes | |
userdata1 | varchar(1024) | Yes | |
userdata2 | varchar(1024) | Yes | |
userdata3 | varchar(1024) | Yes | |
userdata4 | varchar(1024) | Yes | |
userdata5 | varchar(1024) | Yes | |
userdata6 | varchar(1024) | Yes | |
userdata7 | varchar(1024) | Yes | |
userdata8 | varchar(1024) | Yes | |
userdata9 | varchar(1024) | Yes | |
rulename | text | Yes | |
rep_prio_src | int(10) UNSIGNED | Yes | |
rep_prio_dst | int(10) UNSIGNED | Yes | |
rep_rel_src | int(10) UNSIGNED | Yes | |
rep_rel_dst | int(10) UNSIGNED | Yes | |
rep_act_src | varchar(64) | Yes | |
rep_act_dst | varchar(64) | Yes | |
src_hostname | varchar(64) | Yes | |
dst_hostname | varchar(64) | Yes | |
src_mac | binary(6) | Yes | |
dst_mac | binary(6) | Yes | |
src_host | binary(16) | Yes | |
dst_host | binary(16) | Yes | |
src_net | binary(16) | Yes | |
dst_net | binary(16) | Yes | |
refs | int(11) | Yes |
Field | Type | Allow Null | Default Value |
---|---|---|---|
event_id | binary(16) | No | |
data_payload | text | Yes | |
binary_data | blob | Yes |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | binary(16) | No | |
ctx | binary(16) | No | |
hostname | varchar(128) | No | |
fqdns | varchar(255) | No | |
asset | smallint(6) | No | |
threshold_c | int(11) | No | |
threshold_a | int(11) | No | |
alert | int(11) | No | |
persistence | int(11) | No | |
nat | varchar(15) | Yes | |
rrd_profile | varchar(64) | Yes | |
descr | varchar(255) | Yes | |
lat | varchar(255) | Yes | '0' |
lon | varchar(255) | Yes | '0' |
icon | mediumblob | Yes | |
country | varchar(64) | Yes | |
external_host | tinyint(1) | No | 0 |
permissions | binary(8) | No | '\0\0\0\0\0\0\0\0' |
av_component | tinyint(1) | No | 0 |
created | datetime | Yes | |
updated | datetime | Yes |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | int(11) | No | |
uuid | binary(16) | No | |
ctx | binary(16) | No | |
title | varchar(512) | No | |
date | datetime | No | 0000-00-00 00:00:00 |
ref | enum('Alarm','Alert','Event','Metric','Anomaly','Vulnerability','Custom') | No | 'Alarm' |
type_id | varchar(64) | No | '0' |
priority | int(11) | No | |
status | enum('Open','Assigned','Studying','Waiting','Testing','Closed') | No | 'Open' |
last_update | datetime | No | 0000-00-00 00:00:00 |
in_charge | varchar(64) | No | |
submitter | varchar(64) | No | |
event_start | datetime | No | 0000-00-00 00:00:00 |
event_end | datetime | No | 0000-00-00 00:00:00 |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | int(11) | No | |
incident_id | int(11) | No | |
src_ips | varchar(255) | No | |
src_ports | varchar(255) | No | |
dst_ips | varchar(255) | No | |
dst_ports | varchar(255) | No | |
backlog_id | binary(16) | No | |
event_id | binary(16) | No | |
alarm_group_id | binary(16) | Yes |
Field | Type | Allow Null | Default Value |
---|---|---|---|
id | int(11) | No | |
incident_id | int(11) | No | |
anom_type | enum('mac','service','os') | No | 'mac' |
ip | varchar(255) | No | |
data_orig | varchar(255) | No | |
data_new | varchar(255) | No |
Field | Type | Allow Null | Default Value |
---|---|---|---|
plugin_ctx | binary(16) | No | |
plugin_id | int(11) | No | |
sid | int(11) | No | |
class_id | int(11) | Yes | |
reliability | int(11) | Yes | 1 |
priority | int(11) | Yes | 1 |
name | varchar(512) | No | |
aro | decimal(11,4) | No | 0.0000 |
subcategory_id | int(11) | Yes | |
category_id | int(11) | Yes |
通常我們一個線上OSSIM系統(tǒng),另一個開發(fā)系統(tǒng),現(xiàn)在要把開發(fā)系統(tǒng)更新到線上,但是開發(fā)系統(tǒng)的數(shù)據(jù)庫結(jié)構(gòu)與線上的略有差異,所以需要找出兩個數(shù)據(jù)庫的表結(jié)構(gòu)差異,數(shù)據(jù)庫表結(jié)構(gòu)的差異。我們利用mysqldump和diff兩個命令組合完成。
導(dǎo)出表結(jié)構(gòu)
mysqldump -uroot -p -d alienvault >/home/db1.sql
mysqldump -uroot -p -d alienvault >/home/db2.sql
比較
diff db1.sql db2.sql>diff
免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點不代表本網(wǎng)站立場,如果涉及侵權(quán)請聯(lián)系站長郵箱:is@yisu.com進(jìn)行舉報,并提供相關(guān)證據(jù),一經(jīng)查實,將立刻刪除涉嫌侵權(quán)內(nèi)容。