云日志服务 LTS-创建结构化配置(推荐):请求示例
请求示例
创建 CTS 系统模板
POST https://{endpoint}/v3/{project_id}/lts/struct/template { "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "code", "is_analysis" : true }, { "field_name" : "event_type", "is_analysis" : true }, { "field_name" : "project_id", "is_analysis" : true }, { "field_name" : "record_time", "is_analysis" : false }, { "field_name" : "resource_id", "is_analysis" : true }, { "field_name" : "resource_name", "is_analysis" : true }, { "field_name" : "resource_type", "is_analysis" : false }, { "field_name" : "service_type", "is_analysis" : true }, { "field_name" : "source_ip", "is_analysis" : false }, { "field_name" : "time", "is_analysis" : false }, { "field_name" : "trace_id", "is_analysis" : false }, { "field_name" : "trace_name", "is_analysis" : true }, { "field_name" : "trace_rating", "is_analysis" : true }, { "field_name" : "trace_type", "is_analysis" : true }, { "field_name" : "tracker_name", "is_analysis" : true }, { "field_name" : "user.domain.id", "is_analysis" : true }, { "field_name" : "user.domain.name", "is_analysis" : true }, { "field_name" : "user.id", "is_analysis" : true }, { "field_name" : "user.name", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "CTS", "template_id" : "", "quick_analysis" : false }
创建ELB系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "msec", "is_analysis" : false }, { "field_name" : "access_log_topic_id", "is_analysis" : false }, { "field_name" : "time_iso8601", "is_analysis" : false }, { "field_name" : "log_ver", "is_analysis" : true }, { "field_name" : "remote_addr", "is_analysis" : true }, { "field_name" : "remote_port", "is_analysis" : false }, { "field_name" : "status", "is_analysis" : false }, { "field_name" : "request_method", "is_analysis" : false }, { "field_name" : "scheme", "is_analysis" : true }, { "field_name" : "host", "is_analysis" : true }, { "field_name" : "router_request_uri", "is_analysis" : true }, { "field_name" : "server_protocol", "is_analysis" : true }, { "field_name" : "request_length", "is_analysis" : true }, { "field_name" : "bytes_sent", "is_analysis" : false }, { "field_name" : "body_bytes_sent", "is_analysis" : false }, { "field_name" : "request_time", "is_analysis" : false }, { "field_name" : "upstream_status", "is_analysis" : false }, { "field_name" : "upstream_connect_time", "is_analysis" : false }, { "field_name" : "upstream_header_time", "is_analysis" : false }, { "field_name" : "upstream_response_time", "is_analysis" : false }, { "field_name" : "upstream_addr", "is_analysis" : false }, { "field_name" : "http_user_agent", "is_analysis" : false }, { "field_name" : "http_referer", "is_analysis" : false }, { "field_name" : "http_x_forwarded_for", "is_analysis" : false }, { "field_name" : "lb_name", "is_analysis" : false }, { "field_name" : "listener_name", "is_analysis" : false }, { "field_name" : "listener_id", "is_analysis" : false }, { "field_name" : "pool_name", "is_analysis" : false }, { "field_name" : "member_name", "is_analysis" : false }, { "field_name" : "tenant_id", "is_analysis" : false }, { "field_name" : "eip_address", "is_analysis" : false }, { "field_name" : "eip_port", "is_analysis" : false }, { "field_name" : "upstream_addr_priv", "is_analysis" : false }, { "field_name" : "certificate_id", "is_analysis" : false }, { "field_name" : "ssl_protocol", "is_analysis" : false }, { "field_name" : "ssl_cipher", "is_analysis" : false }, { "field_name" : "sni_domain_name", "is_analysis" : false }, { "field_name" : "tcpinfo_rtt", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "ELB", "template_id" : "", "quick_analysis" : false }
创建自定义模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "date", "is_analysis" : true }, { "field_name" : "num", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "custom", "template_name" : "regexTemplate", "template_id" : "47629e46-287d-478c-8888-xxxxxxxxxxxx", "quick_analysis" : false }
创建VPC系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "version", "is_analysis" : false }, { "field_name" : "project_id", "is_analysis" : true }, { "field_name" : "interface_id", "is_analysis" : false }, { "field_name" : "srcaddr", "is_analysis" : true }, { "field_name" : "dstaddr", "is_analysis" : true }, { "field_name" : "srcport", "is_analysis" : false }, { "field_name" : "dstport", "is_analysis" : false }, { "field_name" : "protocol", "is_analysis" : false }, { "field_name" : "packets", "is_analysis" : false }, { "field_name" : "bytes", "is_analysis" : false }, { "field_name" : "start", "is_analysis" : false }, { "field_name" : "end", "is_analysis" : false }, { "field_name" : "action", "is_analysis" : true }, { "field_name" : "log_status", "is_analysis" : true } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "VPC", "template_id" : "", "quick_analysis" : false }
创建APIG系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "my_remote_addr", "is_analysis" : false }, { "field_name" : "request_id", "is_analysis" : false }, { "field_name" : "api_id", "is_analysis" : false }, { "field_name" : "user_name", "is_analysis" : true }, { "field_name" : "app_id", "is_analysis" : true }, { "field_name" : "time_local", "is_analysis" : false }, { "field_name" : "request_time", "is_analysis" : false }, { "field_name" : "request_method", "is_analysis" : false }, { "field_name" : "scheme", "is_analysis" : true }, { "field_name" : "host", "is_analysis" : true }, { "field_name" : "router_uri", "is_analysis" : true }, { "field_name" : "server_protocol", "is_analysis" : true }, { "field_name" : "status", "is_analysis" : true }, { "field_name" : "bytes_sent", "is_analysis" : false }, { "field_name" : "request_length", "is_analysis" : false }, { "field_name" : "http_user_agent", "is_analysis" : false }, { "field_name" : "http_x_forwarded_for", "is_analysis" : false }, { "field_name" : "upstream_addr", "is_analysis" : false }, { "field_name" : "upstream_uri", "is_analysis" : false }, { "field_name" : "upstream_status", "is_analysis" : false }, { "field_name" : "upstream_connect_time", "is_analysis" : false }, { "field_name" : "upstream_header_time", "is_analysis" : false }, { "field_name" : "upstream_response_time", "is_analysis" : false }, { "field_name" : "region_id", "is_analysis" : false }, { "field_name" : "all_upstream_response_time", "is_analysis" : false }, { "field_name" : "errorType", "is_analysis" : false }, { "field_name" : "auth_type", "is_analysis" : false }, { "field_name" : "access_model1", "is_analysis" : false }, { "field_name" : "access_model2", "is_analysis" : false }, { "field_name" : "inner_time", "is_analysis" : false }, { "field_name" : "proxy_protocol_vni", "is_analysis" : false }, { "field_name" : "proxy_protocol_vpce_id", "is_analysis" : false }, { "field_name" : "proxy_protocol_addr", "is_analysis" : false }, { "field_name" : "body_bytes_sent", "is_analysis" : false }, { "field_name" : "api_name", "is_analysis" : false }, { "field_name" : "app_name", "is_analysis" : false }, { "field_name" : "provider_app_id", "is_analysis" : false }, { "field_name" : "provider_app_name", "is_analysis" : false }, { "field_name" : "custom_data_log1", "is_analysis" : false }, { "field_name" : "custom_data_log2", "is_analysis" : false }, { "field_name" : "custom_data_log3", "is_analysis" : false }, { "field_name" : "custom_data_log4", "is_analysis" : false }, { "field_name" : "custom_data_log5", "is_analysis" : false }, { "field_name" : "custom_data_log6", "is_analysis" : false }, { "field_name" : "custom_data_log7", "is_analysis" : false }, { "field_name" : "custom_data_log8", "is_analysis" : false }, { "field_name" : "custom_data_log9", "is_analysis" : false }, { "field_name" : "custom_data_log10", "is_analysis" : false }, { "field_name" : "response_source", "is_analysis" : false }, { "field_name" : "start_time", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "APIG", "template_id" : "", "quick_analysis" : false }
创建DDS系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000", "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000", "demo_fields" : [ { "field_name" : "time", "is_analysis" : false }, { "field_name" : "instance_id", "is_analysis" : false }, { "field_name" : "server_addr", "is_analysis" : false }, { "field_name" : "role", "is_analysis" : false }, { "field_name" : "client_addr", "is_analysis" : false }, { "field_name" : "client_type", "is_analysis" : false }, { "field_name" : "user", "is_analysis" : false }, { "field_name" : "db", "is_analysis" : false }, { "field_name" : "command_name", "is_analysis" : false }, { "field_name" : "command_type", "is_analysis" : false }, { "field_name" : "command_keys", "is_analysis" : false }, { "field_name" : "command_param", "is_analysis" : false }, { "field_name" : "use_time", "is_analysis" : false }, { "field_name" : "extend", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP" } ], "template_type" : "built_in", "template_name" : "DDS_AUDIT", "template_id" : "", "quick_analysis" : false }
创建DDS错误日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "severity", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "raw_message", "is_analysis" : true }, { "field_name" : "instance_id", "is_analysis" : true }, { "field_name" : "node_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "MONGODB_ERROR", "template_id" : "", "quick_analysis" : false }
创建DDS慢日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "namespace", "is_analysis" : false }, { "field_name" : "database", "is_analysis" : true }, { "field_name" : "collection", "is_analysis" : true }, { "field_name" : "operate_type", "is_analysis" : false }, { "field_name" : "docs_scanned", "is_analysis" : false }, { "field_name" : "docs_returned", "is_analysis" : false }, { "field_name" : "n_deleted", "is_analysis" : true }, { "field_name" : "n_matched", "is_analysis" : true }, { "field_name" : "n_modified", "is_analysis" : true }, { "field_name" : "n_inserted", "is_analysis" : true }, { "field_name" : "cost_time", "is_analysis" : true }, { "field_name" : "lock_time", "is_analysis" : false }, { "field_name" : "whole_message", "is_analysis" : false }, { "field_name" : "instance_id", "is_analysis" : false }, { "field_name" : "node_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "MONGODB_SLOW", "template_id" : "", "quick_analysis" : false }
创建GAUSSDB_OPENGAUSS_AUDIT系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000", "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000", "demo_fields" : [ { "field_name" : "username", "is_analysis" : false }, { "field_name" : "client_conninfo", "is_analysis" : false }, { "field_name" : "instanceId", "is_analysis" : false }, { "field_name" : "detail_info", "is_analysis" : false }, { "field_name" : "thread_id", "is_analysis" : false }, { "field_name" : "result", "is_analysis" : false }, { "field_name" : "database", "is_analysis" : false }, { "field_name" : "local_port", "is_analysis" : false }, { "field_name" : "userid", "is_analysis" : false }, { "field_name" : "nodeId", "is_analysis" : false }, { "field_name" : "node_name", "is_analysis" : false }, { "field_name" : "object_name", "is_analysis" : false }, { "field_name" : "time", "is_analysis" : false }, { "field_name" : "type", "is_analysis" : false }, { "field_name" : "remote_port", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP" } ], "template_type" : "built_in", "template_name" : "GAUSSDB_OPENGAUSS_AUDIT", "template_id" : "", "quick_analysis" : false }
创建NGINX系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000", "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000", "demo_fields" : [ { "field_name" : "remote_addr", "is_analysis" : false }, { "field_name" : "remote_user", "is_analysis" : false }, { "field_name" : "time_local", "is_analysis" : false }, { "field_name" : "request_method", "is_analysis" : false }, { "field_name" : "scheme", "is_analysis" : false }, { "field_name" : "host", "is_analysis" : false }, { "field_name" : "request_uri", "is_analysis" : false }, { "field_name" : "server_protocol", "is_analysis" : false }, { "field_name" : "status", "is_analysis" : false }, { "field_name" : "bytes_sent", "is_analysis" : false }, { "field_name" : "body_bytes_sent", "is_analysis" : false }, { "field_name" : "http_referer", "is_analysis" : false }, { "field_name" : "http_user_agent", "is_analysis" : false }, { "field_name" : "http_x_forwarded_for", "is_analysis" : false }, { "field_name" : "request_time", "is_analysis" : false }, { "field_name" : "upstream_response_time", "is_analysis" : false }, { "field_name" : "upstream_addr", "is_analysis" : false }, { "field_name" : "upstream_status", "is_analysis" : false }, { "field_name" : "request_length", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP" } ], "template_type" : "built_in", "template_name" : "NGINX", "template_id" : "", "quick_analysis" : false }
创建TOMCAT系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000", "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000", "demo_fields" : [ { "field_name" : "remote_ip_address", "is_analysis" : false }, { "field_name" : "remote_logical_username", "is_analysis" : false }, { "field_name" : "remote_user_authenticated", "is_analysis" : false }, { "field_name" : "time_local", "is_analysis" : false }, { "field_name" : "scheme", "is_analysis" : false }, { "field_name" : "router_uri", "is_analysis" : false }, { "field_name" : "server_protocol", "is_analysis" : false }, { "field_name" : "status", "is_analysis" : false }, { "field_name" : "bytes_sent", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP" } ], "template_type" : "built_in", "template_name" : "TOMCAT", "template_id" : "", "quick_analysis" : false }
创建D CS 审计日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000", "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000", "demo_fields" : [ { "field_name" : "time", "is_analysis" : false }, { "field_name" : "instance_id", "is_analysis" : false }, { "field_name" : "server_addr", "is_analysis" : false }, { "field_name" : "role", "is_analysis" : false }, { "field_name" : "client_addr", "is_analysis" : false }, { "field_name" : "client_type", "is_analysis" : false }, { "field_name" : "user", "is_analysis" : false }, { "field_name" : "db", "is_analysis" : false }, { "field_name" : "command_name", "is_analysis" : false }, { "field_name" : "command_type", "is_analysis" : false }, { "field_name" : "command_keys", "is_analysis" : false }, { "field_name" : "command_param", "is_analysis" : false }, { "field_name" : "use_time", "is_analysis" : false }, { "field_name" : "extend", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP" } ], "template_type" : "built_in", "template_name" : "DCS_AUDIT", "template_id" : "", "quick_analysis" : false }
创建CFW攻击日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "source", "is_analysis" : false }, { "field_name" : "app", "is_analysis" : false }, { "field_name" : "direction", "is_analysis" : false }, { "field_name" : "dst_ip", "is_analysis" : true }, { "field_name" : "src_ip", "is_analysis" : true }, { "field_name" : "event_time", "is_analysis" : false }, { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "dst_port", "is_analysis" : false }, { "field_name" : "attack_rule_id", "is_analysis" : true }, { "field_name" : "index_day", "is_analysis" : true }, { "field_name" : "log_id", "is_analysis" : true }, { "field_name" : "src_port", "is_analysis" : true }, { "field_name" : "protocol", "is_analysis" : true }, { "field_name" : "packet", "is_analysis" : false }, { "field_name" : "level", "is_analysis" : false }, { "field_name" : "attack_type", "is_analysis" : false }, { "field_name" : "fw_instance_id", "is_analysis" : false }, { "field_name" : "action", "is_analysis" : false }, { "field_name" : "vsys", "is_analysis" : false }, { "field_name" : "attack_rule", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "CFW_ATTACK", "template_id" : "", "quick_analysis" : false }
创建CFW访问控制日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "app", "is_analysis" : false }, { "field_name" : "direction", "is_analysis" : false }, { "field_name" : "source-zone", "is_analysis" : false }, { "field_name" : "rule_id", "is_analysis" : true }, { "field_name" : "protocol", "is_analysis" : true }, { "field_name" : "dst_ip", "is_analysis" : false }, { "field_name" : "src_ip", "is_analysis" : false }, { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "hit_time", "is_analysis" : true }, { "field_name" : "log-id", "is_analysis" : true }, { "field_name" : "dst_port", "is_analysis" : true }, { "field_name" : "destination-zone", "is_analysis" : true }, { "field_name" : "index_day", "is_analysis" : true }, { "field_name" : "log_id", "is_analysis" : false }, { "field_name" : "src_port", "is_analysis" : false }, { "field_name" : "fw_instance_id", "is_analysis" : false }, { "field_name" : "action", "is_analysis" : false }, { "field_name" : "vsys", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "CFW_AC CES S", "template_id" : "", "quick_analysis" : false }
创建CFW流量日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "dst_port", "is_analysis" : false }, { "field_name" : "app", "is_analysis" : false }, { "field_name" : "to_c_pkts", "is_analysis" : false }, { "field_name" : "dst_ip", "is_analysis" : true }, { "field_name" : "to_c_bytes", "is_analysis" : true }, { "field_name" : "end_time", "is_analysis" : false }, { "field_name" : "src_ip", "is_analysis" : false }, { "field_name" : "index_day", "is_analysis" : false }, { "field_name" : "bytes", "is_analysis" : true }, { "field_name" : "log-id", "is_analysis" : true }, { "field_name" : "vsys", "is_analysis" : true }, { "field_name" : "suffix", "is_analysis" : true }, { "field_name" : "packets", "is_analysis" : true }, { "field_name" : "direction", "is_analysis" : false }, { "field_name" : "protocol", "is_analysis" : false }, { "field_name" : "to_s_bytes", "is_analysis" : false }, { "field_name" : "to_s_pkts", "is_analysis" : false }, { "field_name" : "src_port", "is_analysis" : false }, { "field_name" : "start_time", "is_analysis" : false }, { "field_name" : "fw_instance_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "CFW_FLOW", "template_id" : "", "quick_analysis" : false }
创建MYSQL错误日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "severity", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "raw_message", "is_analysis" : true }, { "field_name" : "node_id", "is_analysis" : true }, { "field_name" : "instance_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "MYSQL_ERROR", "template_id" : "", "quick_analysis" : false }
创建MYSQL慢日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "start_time", "is_analysis" : false }, { "field_name" : "user", "is_analysis" : false }, { "field_name" : "host", "is_analysis" : false }, { "field_name" : "query_time", "is_analysis" : true }, { "field_name" : "lock_time", "is_analysis" : true }, { "field_name" : "rows_sent", "is_analysis" : false }, { "field_name" : "rows_examined", "is_analysis" : false }, { "field_name" : "command_text", "is_analysis" : false }, { "field_name" : "database", "is_analysis" : true }, { "field_name" : "log_type", "is_analysis" : true }, { "field_name" : "log_time", "is_analysis" : true }, { "field_name" : "operate_type", "is_analysis" : true }, { "field_name" : "node_id", "is_analysis" : true }, { "field_name" : "instance_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "MYSQL_SLOW", "template_id" : "", "quick_analysis" : false }
创建POSTGRESQL慢日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "execute_time", "is_analysis" : false }, { "field_name" : "user", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : true }, { "field_name" : "database", "is_analysis" : true }, { "field_name" : "statement", "is_analysis" : false }, { "field_name" : "host", "is_analysis" : false }, { "field_name" : "log_timestamp", "is_analysis" : false }, { "field_name" : "operate_type", "is_analysis" : true }, { "field_name" : "node_id", "is_analysis" : true }, { "field_name" : "instance_id", "is_analysis" : true } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "POSTGRESQL_SLOW", "template_id" : "", "quick_analysis" : false }
创建POSTGRESQL错误日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "severity", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "raw_message", "is_analysis" : true }, { "field_name" : "node_id", "is_analysis" : true }, { "field_name" : "instance_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "POSTGRESQL_ERROR", "template_id" : "", "quick_analysis" : false }
创建SQLSERVER错误日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000", "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "severity", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "raw_message", "is_analysis" : false }, { "field_name" : "node_id", "is_analysis" : false }, { "field_name" : "instance_id", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP" } ], "template_type" : "built_in", "template_name" : "SQLSERVER_ERROR", "template_id" : "", "quick_analysis" : false }
创建GAUSSDB_REDIS慢日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "instance_id", "is_analysis" : false }, { "field_name" : "node_id", "is_analysis" : false }, { "field_name" : "database", "is_analysis" : false }, { "field_name" : "log_type", "is_analysis" : true }, { "field_name" : "operate_type", "is_analysis" : true }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "cost_time", "is_analysis" : false }, { "field_name" : "whole_message", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "GAUSSDB_REDIS_SLOW", "template_id" : "", "quick_analysis" : false }
创建GAUSSDB_MYSQL慢日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "start_time", "is_analysis" : false }, { "field_name" : "user", "is_analysis" : false }, { "field_name" : "host", "is_analysis" : false }, { "field_name" : "query_time", "is_analysis" : true }, { "field_name" : "lock_time", "is_analysis" : true }, { "field_name" : "rows_sent", "is_analysis" : false }, { "field_name" : "rows_examined", "is_analysis" : false }, { "field_name" : "command_text", "is_analysis" : false }, { "field_name" : "database", "is_analysis" : false }, { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "operate_type", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "GAUSSDB_MYSQL_SLOW", "template_id" : "", "quick_analysis" : false }
创建GAUSSDB_MYSQL错误日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "log_type", "is_analysis" : false }, { "field_name" : "severity", "is_analysis" : false }, { "field_name" : "log_time", "is_analysis" : false }, { "field_name" : "raw_message", "is_analysis" : true } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "GAUSSDB_MYSQL_ERROR", "template_id" : "", "quick_analysis" : false }
创建CDN系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "request_time", "is_analysis" : false }, { "field_name" : "domain", "is_analysis" : false }, { "field_name" : "method", "is_analysis" : false }, { "field_name" : "scheme", "is_analysis" : true }, { "field_name" : "uri", "is_analysis" : true }, { "field_name" : "uri_param", "is_analysis" : false }, { "field_name" : "client_ip", "is_analysis" : false }, { "field_name" : "client_port", "is_analysis" : true }, { "field_name" : "refer_protocol", "is_analysis" : true }, { "field_name" : "refer_domain", "is_analysis" : false }, { "field_name" : "refer_uri", "is_analysis" : true }, { "field_name" : "refer_param", "is_analysis" : true }, { "field_name" : "request_size", "is_analysis" : false }, { "field_name" : "response_time", "is_analysis" : false }, { "field_name" : "response_size", "is_analysis" : true }, { "field_name" : "http_code", "is_analysis" : false }, { "field_name" : "response_range", "is_analysis" : true }, { "field_name" : "request_range", "is_analysis" : false }, { "field_name" : "request_body_bytes", "is_analysis" : true }, { "field_name" : "content_type", "is_analysis" : true }, { "field_name" : "hit_info", "is_analysis" : true }, { "field_name" : "user_agent", "is_analysis" : false }, { "field_name" : "uuid", "is_analysis" : true }, { "field_name" : "via_info", "is_analysis" : true }, { "field_name" : "xforwordfor", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "CDN", "template_id" : "", "quick_analysis" : false }
创建 SMN 系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "message_id", "is_analysis" : false }, { "field_name" : "project_id", "is_analysis" : false }, { "field_name" : "topic_urn", "is_analysis" : false }, { "field_name" : "subscriber_urn", "is_analysis" : true }, { "field_name" : "protocol_name", "is_analysis" : true }, { "field_name" : "endpoint", "is_analysis" : false }, { "field_name" : "status", "is_analysis" : false }, { "field_name" : "http_code", "is_analysis" : true }, { "field_name" : "create_time", "is_analysis" : true }, { "field_name" : "send_time", "is_analysis" : true } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "SMN", "template_id" : "", "quick_analysis" : false }
创建WAF访问日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "response_code", "is_analysis" : false }, { "field_name" : "scheme", "is_analysis" : false }, { "field_name" : "upstream_addr", "is_analysis" : false }, { "field_name" : "body_bytes_sent", "is_analysis" : false }, { "field_name" : "upstream_header_time", "is_analysis" : false }, { "field_name" : "connection_requests", "is_analysis" : false }, { "field_name" : "ssl_cipher", "is_analysis" : false }, { "field_name" : "hostid", "is_analysis" : false }, { "field_name" : "pid", "is_analysis" : false }, { "field_name" : "tls_version", "is_analysis" : false }, { "field_name" : "http_host", "is_analysis" : false }, { "field_name" : "process_time", "is_analysis" : false }, { "field_name" : "access_stream_id", "is_analysis" : false }, { "field_name" : "time_iso8601", "is_analysis" : false }, { "field_name" : "intel_crawler", "is_analysis" : false }, { "field_name" : "upstream_status", "is_analysis" : false }, { "field_name" : "remote_ip", "is_analysis" : false }, { "field_name" : "request_time", "is_analysis" : false }, { "field_name" : "tenantid", "is_analysis" : false }, { "field_name" : "sip", "is_analysis" : false }, { "field_name" : "bytes_send", "is_analysis" : false }, { "field_name" : "projectid", "is_analysis" : false }, { "field_name" : "user_agent", "is_analysis" : false }, { "field_name" : "web_tag", "is_analysis" : false }, { "field_name" : "method", "is_analysis" : false }, { "field_name" : "bind_ip", "is_analysis" : false }, { "field_name" : "region_id", "is_analysis" : false }, { "field_name" : "remote_port", "is_analysis" : false }, { "field_name" : "ssl_ciphers_md5", "is_analysis" : false }, { "field_name" : "x_real_ip", "is_analysis" : false }, { "field_name" : "url", "is_analysis" : false }, { "field_name" : "x_forwarded_for", "is_analysis" : false }, { "field_name" : "sni", "is_analysis" : false }, { "field_name" : "args", "is_analysis" : false }, { "field_name" : "cdn_src_ip", "is_analysis" : false }, { "field_name" : "enterprise_project_id", "is_analysis" : false }, { "field_name" : "upstream_connect_time", "is_analysis" : false }, { "field_name" : "engine_id", "is_analysis" : false }, { "field_name" : "request_length", "is_analysis" : false }, { "field_name" : "group_id", "is_analysis" : false }, { "field_name" : "requestid", "is_analysis" : false }, { "field_name" : "ssl_curves", "is_analysis" : false }, { "field_name" : "ssl_session_reused", "is_analysis" : false }, { "field_name" : "waf-time", "is_analysis" : false }, { "field_name" : "upstream_response_time", "is_analysis" : false }, { "field_name" : "time", "is_analysis" : false }, { "field_name" : "waf_category", "is_analysis" : false }, { "field_name" : "eng_ip", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "WAF_ACCESS", "template_id" : "", "quick_analysis" : false }
创建WAF攻击日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "policy_id", "is_analysis" : false }, { "field_name" : "hport", "is_analysis" : false }, { "field_name" : "body_bytes_sent", "is_analysis" : false }, { "field_name" : "hostid", "is_analysis" : false }, { "field_name" : "rule", "is_analysis" : false }, { "field_name" : "engine_ip", "is_analysis" : false }, { "field_name" : "pid", "is_analysis" : false }, { "field_name" : "http_host", "is_analysis" : false }, { "field_name" : "process_time", "is_analysis" : false }, { "field_name" : "reqid", "is_analysis" : false }, { "field_name" : "time_iso8601", "is_analysis" : false }, { "field_name" : "upstream_status", "is_analysis" : false }, { "field_name" : "hit_data", "is_analysis" : false }, { "field_name" : "attack_stream_id", "is_analysis" : false }, { "field_name" : "remote_ip", "is_analysis" : false }, { "field_name" : "attack", "is_analysis" : false }, { "field_name" : "tenantid", "is_analysis" : false }, { "field_name" : "host", "is_analysis" : false }, { "field_name" : "action", "is_analysis" : false }, { "field_name" : "backend.protocol", "is_analysis" : false }, { "field_name" : "backend.alive", "is_analysis" : false }, { "field_name" : "backend.port", "is_analysis" : false }, { "field_name" : "backend.host", "is_analysis" : false }, { "field_name" : "backend.weight", "is_analysis" : false }, { "field_name" : "backend.type", "is_analysis" : false }, { "field_name" : "id", "is_analysis" : false }, { "field_name" : "sip", "is_analysis" : false }, { "field_name" : "projectid", "is_analysis" : false }, { "field_name" : "web_tag", "is_analysis" : false }, { "field_name" : "attack-time", "is_analysis" : false }, { "field_name" : "method", "is_analysis" : false }, { "field_name" : "cookie", "is_analysis" : false }, { "field_name" : "level", "is_analysis" : false }, { "field_name" : "params", "is_analysis" : false }, { "field_name" : "x_real_ip", "is_analysis" : false }, { "field_name" : "url", "is_analysis" : false }, { "field_name" : "x_forwarded_for", "is_analysis" : false }, { "field_name" : "cdn_src_ip", "is_analysis" : false }, { "field_name" : "enterprise_project_id", "is_analysis" : false }, { "field_name" : "req_body", "is_analysis" : false }, { "field_name" : "engine_id", "is_analysis" : false }, { "field_name" : "group_id", "is_analysis" : false }, { "field_name" : "requestid", "is_analysis" : false }, { "field_name" : "multipart", "is_analysis" : false }, { "field_name" : "header", "is_analysis" : false }, { "field_name" : "location", "is_analysis" : false }, { "field_name" : "upstream_response_time", "is_analysis" : false }, { "field_name" : "time", "is_analysis" : false }, { "field_name" : "waf_category", "is_analysis" : false }, { "field_name" : "sport", "is_analysis" : false }, { "field_name" : "status", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "WAF_ATTACK", "template_id" : "", "quick_analysis" : false }
创建DMS重平衡日志的系统模板
{ "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx", "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx", "demo_fields" : [ { "field_name" : "level", "is_analysis" : false }, { "field_name" : "timestamp", "is_analysis" : false }, { "field_name" : "message.leaderId", "is_analysis" : false }, { "field_name" : "message.generationId", "is_analysis" : false }, { "field_name" : "message.reason", "is_analysis" : false }, { "field_name" : "message.groupId", "is_analysis" : false }, { "field_name" : "message.coordinatorId", "is_analysis" : false }, { "field_name" : "message.type", "is_analysis" : false }, { "field_name" : "message.group", "is_analysis" : false } ], "tag_fields" : [ { "field_name" : "hostIP", "is_analysis" : true } ], "template_type" : "built_in", "template_name" : "DMS_REBALANCED", "template_id" : "", "quick_analysis" : false }