云日志服务 LTS-创建结构化配置(推荐):请求示例

时间:2023-12-15 10:06:59

请求示例

  • 创建 CTS 系统模板

    POST https://{endpoint}/v3/{project_id}/lts/struct/template
    
    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "code",
        "is_analysis" : true
      }, {
        "field_name" : "event_type",
        "is_analysis" : true
      }, {
        "field_name" : "project_id",
        "is_analysis" : true
      }, {
        "field_name" : "record_time",
        "is_analysis" : false
      }, {
        "field_name" : "resource_id",
        "is_analysis" : true
      }, {
        "field_name" : "resource_name",
        "is_analysis" : true
      }, {
        "field_name" : "resource_type",
        "is_analysis" : false
      }, {
        "field_name" : "service_type",
        "is_analysis" : true
      }, {
        "field_name" : "source_ip",
        "is_analysis" : false
      }, {
        "field_name" : "time",
        "is_analysis" : false
      }, {
        "field_name" : "trace_id",
        "is_analysis" : false
      }, {
        "field_name" : "trace_name",
        "is_analysis" : true
      }, {
        "field_name" : "trace_rating",
        "is_analysis" : true
      }, {
        "field_name" : "trace_type",
        "is_analysis" : true
      }, {
        "field_name" : "tracker_name",
        "is_analysis" : true
      }, {
        "field_name" : "user.domain.id",
        "is_analysis" : true
      }, {
        "field_name" : "user.domain.name",
        "is_analysis" : true
      }, {
        "field_name" : "user.id",
        "is_analysis" : true
      }, {
        "field_name" : "user.name",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "CTS",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建ELB系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "msec",
        "is_analysis" : false
      }, {
        "field_name" : "access_log_topic_id",
        "is_analysis" : false
      }, {
        "field_name" : "time_iso8601",
        "is_analysis" : false
      }, {
        "field_name" : "log_ver",
        "is_analysis" : true
      }, {
        "field_name" : "remote_addr",
        "is_analysis" : true
      }, {
        "field_name" : "remote_port",
        "is_analysis" : false
      }, {
        "field_name" : "status",
        "is_analysis" : false
      }, {
        "field_name" : "request_method",
        "is_analysis" : false
      }, {
        "field_name" : "scheme",
        "is_analysis" : true
      }, {
        "field_name" : "host",
        "is_analysis" : true
      }, {
        "field_name" : "router_request_uri",
        "is_analysis" : true
      }, {
        "field_name" : "server_protocol",
        "is_analysis" : true
      }, {
        "field_name" : "request_length",
        "is_analysis" : true
      }, {
        "field_name" : "bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "body_bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "request_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_status",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_connect_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_header_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_response_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_addr",
        "is_analysis" : false
      }, {
        "field_name" : "http_user_agent",
        "is_analysis" : false
      }, {
        "field_name" : "http_referer",
        "is_analysis" : false
      }, {
        "field_name" : "http_x_forwarded_for",
        "is_analysis" : false
      }, {
        "field_name" : "lb_name",
        "is_analysis" : false
      }, {
        "field_name" : "listener_name",
        "is_analysis" : false
      }, {
        "field_name" : "listener_id",
        "is_analysis" : false
      }, {
        "field_name" : "pool_name",
        "is_analysis" : false
      }, {
        "field_name" : "member_name",
        "is_analysis" : false
      }, {
        "field_name" : "tenant_id",
        "is_analysis" : false
      }, {
        "field_name" : "eip_address",
        "is_analysis" : false
      }, {
        "field_name" : "eip_port",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_addr_priv",
        "is_analysis" : false
      }, {
        "field_name" : "certificate_id",
        "is_analysis" : false
      }, {
        "field_name" : "ssl_protocol",
        "is_analysis" : false
      }, {
        "field_name" : "ssl_cipher",
        "is_analysis" : false
      }, {
        "field_name" : "sni_domain_name",
        "is_analysis" : false
      }, {
        "field_name" : "tcpinfo_rtt",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "ELB",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建自定义模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "date",
        "is_analysis" : true
      }, {
        "field_name" : "num",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "custom",
      "template_name" : "regexTemplate",
      "template_id" : "47629e46-287d-478c-8888-xxxxxxxxxxxx",
      "quick_analysis" : false
    }
  • 创建VPC系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "version",
        "is_analysis" : false
      }, {
        "field_name" : "project_id",
        "is_analysis" : true
      }, {
        "field_name" : "interface_id",
        "is_analysis" : false
      }, {
        "field_name" : "srcaddr",
        "is_analysis" : true
      }, {
        "field_name" : "dstaddr",
        "is_analysis" : true
      }, {
        "field_name" : "srcport",
        "is_analysis" : false
      }, {
        "field_name" : "dstport",
        "is_analysis" : false
      }, {
        "field_name" : "protocol",
        "is_analysis" : false
      }, {
        "field_name" : "packets",
        "is_analysis" : false
      }, {
        "field_name" : "bytes",
        "is_analysis" : false
      }, {
        "field_name" : "start",
        "is_analysis" : false
      }, {
        "field_name" : "end",
        "is_analysis" : false
      }, {
        "field_name" : "action",
        "is_analysis" : true
      }, {
        "field_name" : "log_status",
        "is_analysis" : true
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "VPC",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建APIG系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "my_remote_addr",
        "is_analysis" : false
      }, {
        "field_name" : "request_id",
        "is_analysis" : false
      }, {
        "field_name" : "api_id",
        "is_analysis" : false
      }, {
        "field_name" : "user_name",
        "is_analysis" : true
      }, {
        "field_name" : "app_id",
        "is_analysis" : true
      }, {
        "field_name" : "time_local",
        "is_analysis" : false
      }, {
        "field_name" : "request_time",
        "is_analysis" : false
      }, {
        "field_name" : "request_method",
        "is_analysis" : false
      }, {
        "field_name" : "scheme",
        "is_analysis" : true
      }, {
        "field_name" : "host",
        "is_analysis" : true
      }, {
        "field_name" : "router_uri",
        "is_analysis" : true
      }, {
        "field_name" : "server_protocol",
        "is_analysis" : true
      }, {
        "field_name" : "status",
        "is_analysis" : true
      }, {
        "field_name" : "bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "request_length",
        "is_analysis" : false
      }, {
        "field_name" : "http_user_agent",
        "is_analysis" : false
      }, {
        "field_name" : "http_x_forwarded_for",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_addr",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_uri",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_status",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_connect_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_header_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_response_time",
        "is_analysis" : false
      }, {
        "field_name" : "region_id",
        "is_analysis" : false
      }, {
        "field_name" : "all_upstream_response_time",
        "is_analysis" : false
      }, {
        "field_name" : "errorType",
        "is_analysis" : false
      }, {
        "field_name" : "auth_type",
        "is_analysis" : false
      }, {
        "field_name" : "access_model1",
        "is_analysis" : false
      }, {
        "field_name" : "access_model2",
        "is_analysis" : false
      }, {
        "field_name" : "inner_time",
        "is_analysis" : false
      }, {
        "field_name" : "proxy_protocol_vni",
        "is_analysis" : false
      }, {
        "field_name" : "proxy_protocol_vpce_id",
        "is_analysis" : false
      }, {
        "field_name" : "proxy_protocol_addr",
        "is_analysis" : false
      }, {
        "field_name" : "body_bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "api_name",
        "is_analysis" : false
      }, {
        "field_name" : "app_name",
        "is_analysis" : false
      }, {
        "field_name" : "provider_app_id",
        "is_analysis" : false
      }, {
        "field_name" : "provider_app_name",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log1",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log2",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log3",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log4",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log5",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log6",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log7",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log8",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log9",
        "is_analysis" : false
      }, {
        "field_name" : "custom_data_log10",
        "is_analysis" : false
      }, {
        "field_name" : "response_source",
        "is_analysis" : false
      }, {
        "field_name" : "start_time",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "APIG",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建DDS系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",
      "demo_fields" : [ {
        "field_name" : "time",
        "is_analysis" : false
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      }, {
        "field_name" : "server_addr",
        "is_analysis" : false
      }, {
        "field_name" : "role",
        "is_analysis" : false
      }, {
        "field_name" : "client_addr",
        "is_analysis" : false
      }, {
        "field_name" : "client_type",
        "is_analysis" : false
      }, {
        "field_name" : "user",
        "is_analysis" : false
      }, {
        "field_name" : "db",
        "is_analysis" : false
      }, {
        "field_name" : "command_name",
        "is_analysis" : false
      }, {
        "field_name" : "command_type",
        "is_analysis" : false
      }, {
        "field_name" : "command_keys",
        "is_analysis" : false
      }, {
        "field_name" : "command_param",
        "is_analysis" : false
      }, {
        "field_name" : "use_time",
        "is_analysis" : false
      }, {
        "field_name" : "extend",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP"
      } ],
      "template_type" : "built_in",
      "template_name" : "DDS_AUDIT",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建DDS错误日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "severity",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "raw_message",
        "is_analysis" : true
      }, {
        "field_name" : "instance_id",
        "is_analysis" : true
      }, {
        "field_name" : "node_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "MONGODB_ERROR",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建DDS慢日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "namespace",
        "is_analysis" : false
      }, {
        "field_name" : "database",
        "is_analysis" : true
      }, {
        "field_name" : "collection",
        "is_analysis" : true
      }, {
        "field_name" : "operate_type",
        "is_analysis" : false
      }, {
        "field_name" : "docs_scanned",
        "is_analysis" : false
      }, {
        "field_name" : "docs_returned",
        "is_analysis" : false
      }, {
        "field_name" : "n_deleted",
        "is_analysis" : true
      }, {
        "field_name" : "n_matched",
        "is_analysis" : true
      }, {
        "field_name" : "n_modified",
        "is_analysis" : true
      }, {
        "field_name" : "n_inserted",
        "is_analysis" : true
      }, {
        "field_name" : "cost_time",
        "is_analysis" : true
      }, {
        "field_name" : "lock_time",
        "is_analysis" : false
      }, {
        "field_name" : "whole_message",
        "is_analysis" : false
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      }, {
        "field_name" : "node_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "MONGODB_SLOW",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建GAUSSDB_OPENGAUSS_AUDIT系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",
      "demo_fields" : [ {
        "field_name" : "username",
        "is_analysis" : false
      }, {
        "field_name" : "client_conninfo",
        "is_analysis" : false
      }, {
        "field_name" : "instanceId",
        "is_analysis" : false
      }, {
        "field_name" : "detail_info",
        "is_analysis" : false
      }, {
        "field_name" : "thread_id",
        "is_analysis" : false
      }, {
        "field_name" : "result",
        "is_analysis" : false
      }, {
        "field_name" : "database",
        "is_analysis" : false
      }, {
        "field_name" : "local_port",
        "is_analysis" : false
      }, {
        "field_name" : "userid",
        "is_analysis" : false
      }, {
        "field_name" : "nodeId",
        "is_analysis" : false
      }, {
        "field_name" : "node_name",
        "is_analysis" : false
      }, {
        "field_name" : "object_name",
        "is_analysis" : false
      }, {
        "field_name" : "time",
        "is_analysis" : false
      }, {
        "field_name" : "type",
        "is_analysis" : false
      }, {
        "field_name" : "remote_port",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP"
      } ],
      "template_type" : "built_in",
      "template_name" : "GAUSSDB_OPENGAUSS_AUDIT",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建NGINX系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",
      "demo_fields" : [ {
        "field_name" : "remote_addr",
        "is_analysis" : false
      }, {
        "field_name" : "remote_user",
        "is_analysis" : false
      }, {
        "field_name" : "time_local",
        "is_analysis" : false
      }, {
        "field_name" : "request_method",
        "is_analysis" : false
      }, {
        "field_name" : "scheme",
        "is_analysis" : false
      }, {
        "field_name" : "host",
        "is_analysis" : false
      }, {
        "field_name" : "request_uri",
        "is_analysis" : false
      }, {
        "field_name" : "server_protocol",
        "is_analysis" : false
      }, {
        "field_name" : "status",
        "is_analysis" : false
      }, {
        "field_name" : "bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "body_bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "http_referer",
        "is_analysis" : false
      }, {
        "field_name" : "http_user_agent",
        "is_analysis" : false
      }, {
        "field_name" : "http_x_forwarded_for",
        "is_analysis" : false
      }, {
        "field_name" : "request_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_response_time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_addr",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_status",
        "is_analysis" : false
      }, {
        "field_name" : "request_length",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP"
      } ],
      "template_type" : "built_in",
      "template_name" : "NGINX",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建TOMCAT系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",
      "demo_fields" : [ {
        "field_name" : "remote_ip_address",
        "is_analysis" : false
      }, {
        "field_name" : "remote_logical_username",
        "is_analysis" : false
      }, {
        "field_name" : "remote_user_authenticated",
        "is_analysis" : false
      }, {
        "field_name" : "time_local",
        "is_analysis" : false
      }, {
        "field_name" : "scheme",
        "is_analysis" : false
      }, {
        "field_name" : "router_uri",
        "is_analysis" : false
      }, {
        "field_name" : "server_protocol",
        "is_analysis" : false
      }, {
        "field_name" : "status",
        "is_analysis" : false
      }, {
        "field_name" : "bytes_sent",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP"
      } ],
      "template_type" : "built_in",
      "template_name" : "TOMCAT",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建D CS 审计日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",
      "demo_fields" : [ {
        "field_name" : "time",
        "is_analysis" : false
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      }, {
        "field_name" : "server_addr",
        "is_analysis" : false
      }, {
        "field_name" : "role",
        "is_analysis" : false
      }, {
        "field_name" : "client_addr",
        "is_analysis" : false
      }, {
        "field_name" : "client_type",
        "is_analysis" : false
      }, {
        "field_name" : "user",
        "is_analysis" : false
      }, {
        "field_name" : "db",
        "is_analysis" : false
      }, {
        "field_name" : "command_name",
        "is_analysis" : false
      }, {
        "field_name" : "command_type",
        "is_analysis" : false
      }, {
        "field_name" : "command_keys",
        "is_analysis" : false
      }, {
        "field_name" : "command_param",
        "is_analysis" : false
      }, {
        "field_name" : "use_time",
        "is_analysis" : false
      }, {
        "field_name" : "extend",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP"
      } ],
      "template_type" : "built_in",
      "template_name" : "DCS_AUDIT",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建CFW攻击日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "source",
        "is_analysis" : false
      }, {
        "field_name" : "app",
        "is_analysis" : false
      }, {
        "field_name" : "direction",
        "is_analysis" : false
      }, {
        "field_name" : "dst_ip",
        "is_analysis" : true
      }, {
        "field_name" : "src_ip",
        "is_analysis" : true
      }, {
        "field_name" : "event_time",
        "is_analysis" : false
      }, {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "dst_port",
        "is_analysis" : false
      }, {
        "field_name" : "attack_rule_id",
        "is_analysis" : true
      }, {
        "field_name" : "index_day",
        "is_analysis" : true
      }, {
        "field_name" : "log_id",
        "is_analysis" : true
      }, {
        "field_name" : "src_port",
        "is_analysis" : true
      }, {
        "field_name" : "protocol",
        "is_analysis" : true
      }, {
        "field_name" : "packet",
        "is_analysis" : false
      }, {
        "field_name" : "level",
        "is_analysis" : false
      }, {
        "field_name" : "attack_type",
        "is_analysis" : false
      }, {
        "field_name" : "fw_instance_id",
        "is_analysis" : false
      }, {
        "field_name" : "action",
        "is_analysis" : false
      }, {
        "field_name" : "vsys",
        "is_analysis" : false
      }, {
        "field_name" : "attack_rule",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "CFW_ATTACK",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建CFW访问控制日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "app",
        "is_analysis" : false
      }, {
        "field_name" : "direction",
        "is_analysis" : false
      }, {
        "field_name" : "source-zone",
        "is_analysis" : false
      }, {
        "field_name" : "rule_id",
        "is_analysis" : true
      }, {
        "field_name" : "protocol",
        "is_analysis" : true
      }, {
        "field_name" : "dst_ip",
        "is_analysis" : false
      }, {
        "field_name" : "src_ip",
        "is_analysis" : false
      }, {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "hit_time",
        "is_analysis" : true
      }, {
        "field_name" : "log-id",
        "is_analysis" : true
      }, {
        "field_name" : "dst_port",
        "is_analysis" : true
      }, {
        "field_name" : "destination-zone",
        "is_analysis" : true
      }, {
        "field_name" : "index_day",
        "is_analysis" : true
      }, {
        "field_name" : "log_id",
        "is_analysis" : false
      }, {
        "field_name" : "src_port",
        "is_analysis" : false
      }, {
        "field_name" : "fw_instance_id",
        "is_analysis" : false
      }, {
        "field_name" : "action",
        "is_analysis" : false
      }, {
        "field_name" : "vsys",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "CFW_AC CES S",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建CFW流量日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "dst_port",
        "is_analysis" : false
      }, {
        "field_name" : "app",
        "is_analysis" : false
      }, {
        "field_name" : "to_c_pkts",
        "is_analysis" : false
      }, {
        "field_name" : "dst_ip",
        "is_analysis" : true
      }, {
        "field_name" : "to_c_bytes",
        "is_analysis" : true
      }, {
        "field_name" : "end_time",
        "is_analysis" : false
      }, {
        "field_name" : "src_ip",
        "is_analysis" : false
      }, {
        "field_name" : "index_day",
        "is_analysis" : false
      }, {
        "field_name" : "bytes",
        "is_analysis" : true
      }, {
        "field_name" : "log-id",
        "is_analysis" : true
      }, {
        "field_name" : "vsys",
        "is_analysis" : true
      }, {
        "field_name" : "suffix",
        "is_analysis" : true
      }, {
        "field_name" : "packets",
        "is_analysis" : true
      }, {
        "field_name" : "direction",
        "is_analysis" : false
      }, {
        "field_name" : "protocol",
        "is_analysis" : false
      }, {
        "field_name" : "to_s_bytes",
        "is_analysis" : false
      }, {
        "field_name" : "to_s_pkts",
        "is_analysis" : false
      }, {
        "field_name" : "src_port",
        "is_analysis" : false
      }, {
        "field_name" : "start_time",
        "is_analysis" : false
      }, {
        "field_name" : "fw_instance_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "CFW_FLOW",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建MYSQL错误日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "severity",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "raw_message",
        "is_analysis" : true
      }, {
        "field_name" : "node_id",
        "is_analysis" : true
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "MYSQL_ERROR",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建MYSQL慢日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "start_time",
        "is_analysis" : false
      }, {
        "field_name" : "user",
        "is_analysis" : false
      }, {
        "field_name" : "host",
        "is_analysis" : false
      }, {
        "field_name" : "query_time",
        "is_analysis" : true
      }, {
        "field_name" : "lock_time",
        "is_analysis" : true
      }, {
        "field_name" : "rows_sent",
        "is_analysis" : false
      }, {
        "field_name" : "rows_examined",
        "is_analysis" : false
      }, {
        "field_name" : "command_text",
        "is_analysis" : false
      }, {
        "field_name" : "database",
        "is_analysis" : true
      }, {
        "field_name" : "log_type",
        "is_analysis" : true
      }, {
        "field_name" : "log_time",
        "is_analysis" : true
      }, {
        "field_name" : "operate_type",
        "is_analysis" : true
      }, {
        "field_name" : "node_id",
        "is_analysis" : true
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "MYSQL_SLOW",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建POSTGRESQL慢日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "execute_time",
        "is_analysis" : false
      }, {
        "field_name" : "user",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : true
      }, {
        "field_name" : "database",
        "is_analysis" : true
      }, {
        "field_name" : "statement",
        "is_analysis" : false
      }, {
        "field_name" : "host",
        "is_analysis" : false
      }, {
        "field_name" : "log_timestamp",
        "is_analysis" : false
      }, {
        "field_name" : "operate_type",
        "is_analysis" : true
      }, {
        "field_name" : "node_id",
        "is_analysis" : true
      }, {
        "field_name" : "instance_id",
        "is_analysis" : true
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "POSTGRESQL_SLOW",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建POSTGRESQL错误日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "severity",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "raw_message",
        "is_analysis" : true
      }, {
        "field_name" : "node_id",
        "is_analysis" : true
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "POSTGRESQL_ERROR",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建SQLSERVER错误日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-000000000000",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047--000000000000",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "severity",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "raw_message",
        "is_analysis" : false
      }, {
        "field_name" : "node_id",
        "is_analysis" : false
      }, {
        "field_name" : "instance_id",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP"
      } ],
      "template_type" : "built_in",
      "template_name" : "SQLSERVER_ERROR",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建GAUSSDB_REDIS慢日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "instance_id",
        "is_analysis" : false
      }, {
        "field_name" : "node_id",
        "is_analysis" : false
      }, {
        "field_name" : "database",
        "is_analysis" : false
      }, {
        "field_name" : "log_type",
        "is_analysis" : true
      }, {
        "field_name" : "operate_type",
        "is_analysis" : true
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "cost_time",
        "is_analysis" : false
      }, {
        "field_name" : "whole_message",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "GAUSSDB_REDIS_SLOW",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建GAUSSDB_MYSQL慢日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "start_time",
        "is_analysis" : false
      }, {
        "field_name" : "user",
        "is_analysis" : false
      }, {
        "field_name" : "host",
        "is_analysis" : false
      }, {
        "field_name" : "query_time",
        "is_analysis" : true
      }, {
        "field_name" : "lock_time",
        "is_analysis" : true
      }, {
        "field_name" : "rows_sent",
        "is_analysis" : false
      }, {
        "field_name" : "rows_examined",
        "is_analysis" : false
      }, {
        "field_name" : "command_text",
        "is_analysis" : false
      }, {
        "field_name" : "database",
        "is_analysis" : false
      }, {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "operate_type",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "GAUSSDB_MYSQL_SLOW",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建GAUSSDB_MYSQL错误日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "log_type",
        "is_analysis" : false
      }, {
        "field_name" : "severity",
        "is_analysis" : false
      }, {
        "field_name" : "log_time",
        "is_analysis" : false
      }, {
        "field_name" : "raw_message",
        "is_analysis" : true
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "GAUSSDB_MYSQL_ERROR",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建CDN系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "request_time",
        "is_analysis" : false
      }, {
        "field_name" : "domain",
        "is_analysis" : false
      }, {
        "field_name" : "method",
        "is_analysis" : false
      }, {
        "field_name" : "scheme",
        "is_analysis" : true
      }, {
        "field_name" : "uri",
        "is_analysis" : true
      }, {
        "field_name" : "uri_param",
        "is_analysis" : false
      }, {
        "field_name" : "client_ip",
        "is_analysis" : false
      }, {
        "field_name" : "client_port",
        "is_analysis" : true
      }, {
        "field_name" : "refer_protocol",
        "is_analysis" : true
      }, {
        "field_name" : "refer_domain",
        "is_analysis" : false
      }, {
        "field_name" : "refer_uri",
        "is_analysis" : true
      }, {
        "field_name" : "refer_param",
        "is_analysis" : true
      }, {
        "field_name" : "request_size",
        "is_analysis" : false
      }, {
        "field_name" : "response_time",
        "is_analysis" : false
      }, {
        "field_name" : "response_size",
        "is_analysis" : true
      }, {
        "field_name" : "http_code",
        "is_analysis" : false
      }, {
        "field_name" : "response_range",
        "is_analysis" : true
      }, {
        "field_name" : "request_range",
        "is_analysis" : false
      }, {
        "field_name" : "request_body_bytes",
        "is_analysis" : true
      }, {
        "field_name" : "content_type",
        "is_analysis" : true
      }, {
        "field_name" : "hit_info",
        "is_analysis" : true
      }, {
        "field_name" : "user_agent",
        "is_analysis" : false
      }, {
        "field_name" : "uuid",
        "is_analysis" : true
      }, {
        "field_name" : "via_info",
        "is_analysis" : true
      }, {
        "field_name" : "xforwordfor",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "CDN",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建 SMN 系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "message_id",
        "is_analysis" : false
      }, {
        "field_name" : "project_id",
        "is_analysis" : false
      }, {
        "field_name" : "topic_urn",
        "is_analysis" : false
      }, {
        "field_name" : "subscriber_urn",
        "is_analysis" : true
      }, {
        "field_name" : "protocol_name",
        "is_analysis" : true
      }, {
        "field_name" : "endpoint",
        "is_analysis" : false
      }, {
        "field_name" : "status",
        "is_analysis" : false
      }, {
        "field_name" : "http_code",
        "is_analysis" : true
      }, {
        "field_name" : "create_time",
        "is_analysis" : true
      }, {
        "field_name" : "send_time",
        "is_analysis" : true
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "SMN",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建WAF访问日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "response_code",
        "is_analysis" : false
      }, {
        "field_name" : "scheme",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_addr",
        "is_analysis" : false
      }, {
        "field_name" : "body_bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_header_time",
        "is_analysis" : false
      }, {
        "field_name" : "connection_requests",
        "is_analysis" : false
      }, {
        "field_name" : "ssl_cipher",
        "is_analysis" : false
      }, {
        "field_name" : "hostid",
        "is_analysis" : false
      }, {
        "field_name" : "pid",
        "is_analysis" : false
      }, {
        "field_name" : "tls_version",
        "is_analysis" : false
      }, {
        "field_name" : "http_host",
        "is_analysis" : false
      }, {
        "field_name" : "process_time",
        "is_analysis" : false
      }, {
        "field_name" : "access_stream_id",
        "is_analysis" : false
      }, {
        "field_name" : "time_iso8601",
        "is_analysis" : false
      }, {
        "field_name" : "intel_crawler",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_status",
        "is_analysis" : false
      }, {
        "field_name" : "remote_ip",
        "is_analysis" : false
      }, {
        "field_name" : "request_time",
        "is_analysis" : false
      }, {
        "field_name" : "tenantid",
        "is_analysis" : false
      }, {
        "field_name" : "sip",
        "is_analysis" : false
      }, {
        "field_name" : "bytes_send",
        "is_analysis" : false
      }, {
        "field_name" : "projectid",
        "is_analysis" : false
      }, {
        "field_name" : "user_agent",
        "is_analysis" : false
      }, {
        "field_name" : "web_tag",
        "is_analysis" : false
      }, {
        "field_name" : "method",
        "is_analysis" : false
      }, {
        "field_name" : "bind_ip",
        "is_analysis" : false
      }, {
        "field_name" : "region_id",
        "is_analysis" : false
      }, {
        "field_name" : "remote_port",
        "is_analysis" : false
      }, {
        "field_name" : "ssl_ciphers_md5",
        "is_analysis" : false
      }, {
        "field_name" : "x_real_ip",
        "is_analysis" : false
      }, {
        "field_name" : "url",
        "is_analysis" : false
      }, {
        "field_name" : "x_forwarded_for",
        "is_analysis" : false
      }, {
        "field_name" : "sni",
        "is_analysis" : false
      }, {
        "field_name" : "args",
        "is_analysis" : false
      }, {
        "field_name" : "cdn_src_ip",
        "is_analysis" : false
      }, {
        "field_name" : "enterprise_project_id",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_connect_time",
        "is_analysis" : false
      }, {
        "field_name" : "engine_id",
        "is_analysis" : false
      }, {
        "field_name" : "request_length",
        "is_analysis" : false
      }, {
        "field_name" : "group_id",
        "is_analysis" : false
      }, {
        "field_name" : "requestid",
        "is_analysis" : false
      }, {
        "field_name" : "ssl_curves",
        "is_analysis" : false
      }, {
        "field_name" : "ssl_session_reused",
        "is_analysis" : false
      }, {
        "field_name" : "waf-time",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_response_time",
        "is_analysis" : false
      }, {
        "field_name" : "time",
        "is_analysis" : false
      }, {
        "field_name" : "waf_category",
        "is_analysis" : false
      }, {
        "field_name" : "eng_ip",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "WAF_ACCESS",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建WAF攻击日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "policy_id",
        "is_analysis" : false
      }, {
        "field_name" : "hport",
        "is_analysis" : false
      }, {
        "field_name" : "body_bytes_sent",
        "is_analysis" : false
      }, {
        "field_name" : "hostid",
        "is_analysis" : false
      }, {
        "field_name" : "rule",
        "is_analysis" : false
      }, {
        "field_name" : "engine_ip",
        "is_analysis" : false
      }, {
        "field_name" : "pid",
        "is_analysis" : false
      }, {
        "field_name" : "http_host",
        "is_analysis" : false
      }, {
        "field_name" : "process_time",
        "is_analysis" : false
      }, {
        "field_name" : "reqid",
        "is_analysis" : false
      }, {
        "field_name" : "time_iso8601",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_status",
        "is_analysis" : false
      }, {
        "field_name" : "hit_data",
        "is_analysis" : false
      }, {
        "field_name" : "attack_stream_id",
        "is_analysis" : false
      }, {
        "field_name" : "remote_ip",
        "is_analysis" : false
      }, {
        "field_name" : "attack",
        "is_analysis" : false
      }, {
        "field_name" : "tenantid",
        "is_analysis" : false
      }, {
        "field_name" : "host",
        "is_analysis" : false
      }, {
        "field_name" : "action",
        "is_analysis" : false
      }, {
        "field_name" : "backend.protocol",
        "is_analysis" : false
      }, {
        "field_name" : "backend.alive",
        "is_analysis" : false
      }, {
        "field_name" : "backend.port",
        "is_analysis" : false
      }, {
        "field_name" : "backend.host",
        "is_analysis" : false
      }, {
        "field_name" : "backend.weight",
        "is_analysis" : false
      }, {
        "field_name" : "backend.type",
        "is_analysis" : false
      }, {
        "field_name" : "id",
        "is_analysis" : false
      }, {
        "field_name" : "sip",
        "is_analysis" : false
      }, {
        "field_name" : "projectid",
        "is_analysis" : false
      }, {
        "field_name" : "web_tag",
        "is_analysis" : false
      }, {
        "field_name" : "attack-time",
        "is_analysis" : false
      }, {
        "field_name" : "method",
        "is_analysis" : false
      }, {
        "field_name" : "cookie",
        "is_analysis" : false
      }, {
        "field_name" : "level",
        "is_analysis" : false
      }, {
        "field_name" : "params",
        "is_analysis" : false
      }, {
        "field_name" : "x_real_ip",
        "is_analysis" : false
      }, {
        "field_name" : "url",
        "is_analysis" : false
      }, {
        "field_name" : "x_forwarded_for",
        "is_analysis" : false
      }, {
        "field_name" : "cdn_src_ip",
        "is_analysis" : false
      }, {
        "field_name" : "enterprise_project_id",
        "is_analysis" : false
      }, {
        "field_name" : "req_body",
        "is_analysis" : false
      }, {
        "field_name" : "engine_id",
        "is_analysis" : false
      }, {
        "field_name" : "group_id",
        "is_analysis" : false
      }, {
        "field_name" : "requestid",
        "is_analysis" : false
      }, {
        "field_name" : "multipart",
        "is_analysis" : false
      }, {
        "field_name" : "header",
        "is_analysis" : false
      }, {
        "field_name" : "location",
        "is_analysis" : false
      }, {
        "field_name" : "upstream_response_time",
        "is_analysis" : false
      }, {
        "field_name" : "time",
        "is_analysis" : false
      }, {
        "field_name" : "waf_category",
        "is_analysis" : false
      }, {
        "field_name" : "sport",
        "is_analysis" : false
      }, {
        "field_name" : "status",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "WAF_ATTACK",
      "template_id" : "",
      "quick_analysis" : false
    }
  • 创建DMS重平衡日志的系统模板

    {
      "log_group_id" : "17f23e52-a23d-46e0-8bc5-xxxxxxxxxxxx",
      "log_stream_id" : "b4d56d47-b4c4-453e-9047-xxxxxxxxxxxx",
      "demo_fields" : [ {
        "field_name" : "level",
        "is_analysis" : false
      }, {
        "field_name" : "timestamp",
        "is_analysis" : false
      }, {
        "field_name" : "message.leaderId",
        "is_analysis" : false
      }, {
        "field_name" : "message.generationId",
        "is_analysis" : false
      }, {
        "field_name" : "message.reason",
        "is_analysis" : false
      }, {
        "field_name" : "message.groupId",
        "is_analysis" : false
      }, {
        "field_name" : "message.coordinatorId",
        "is_analysis" : false
      }, {
        "field_name" : "message.type",
        "is_analysis" : false
      }, {
        "field_name" : "message.group",
        "is_analysis" : false
      } ],
      "tag_fields" : [ {
        "field_name" : "hostIP",
        "is_analysis" : true
      } ],
      "template_type" : "built_in",
      "template_name" : "DMS_REBALANCED",
      "template_id" : "",
      "quick_analysis" : false
    }
support.huaweicloud.com/api-lts/CreateStructConfig.html