{"nbformat":4,"nbformat_minor":0,"metadata":{"colab":{"name":"Exploring Chronicle's Datalake (BigQuery)","provenance":[],"collapsed_sections":["jV0teq1GcKM8","QyRgTNT4VE0c","PskCEQhukEAk","U8_aus31cqdg"],"toc_visible":true},"kernelspec":{"name":"python3","display_name":"Python 3"},"language_info":{"name":"python"}},"cells":[{"cell_type":"markdown","source":["# Chronicle Data Lake"],"metadata":{"id":"QJm0mraVVBOX"}},{"cell_type":"markdown","source":["## Overview\n","This Notebook is an interactive tutorial focused on learning Chronicle's Data Lake. The Chronicle Data Lake is a Google managed instance of [GCP BigQuery](https://cloud.google.com/bigquery/) and commonly used for:\n","
\n","How long is data retained in the Chronicle Datalake?\n","Six months.\n","
\n","\n","\n","Can I keep data longer than six months?\n","Yes, but you need to backup and export the data into your own BigQuery instance, e.g., a scheduled query / backup and restore.\n","
\n","\n","
\n","Can I Join my datasets against the Chronicle Datalake?\n","Yes.\n","
\n","\n","\n","Can I backup a specific Datalake table?\n","\n","Yes, you can follow instructions here on different ways to backup a Datalake table - [exporting-data](https://cloud.google.com/bigquery/docs/exporting-data)\n","
\n","\n","\n","Can I backup the Data Lake dataset?\n","\n","Yes, you can follow instructions here - [copying datasets](https://cloud.google.com/bigquery/docs/copying-datasets)\n","
\n","\n"],"metadata":{"id":"9lqT_n8CCAGs"}},{"cell_type":"markdown","source":["---"],"metadata":{"id":"qkNnuoMDw32v"}},{"cell_type":"markdown","source":["# Data Lake Dataset & Tables Overview\n","\n","The Chronicle Data Lake provides a default BigQuery Dataset named `datalake`. Run the below SQL to list all the available Tables in the `datalake` Dataset :"],"metadata":{"id":"TUYuKagXw-fp"}},{"cell_type":"code","source":["sql_list_dataset_schema = \"\"\"\n","SELECT \n"," table_name,\n"," FORMAT_DATE(\"%F\",creation_time) AS creation_time\n","FROM \n"," datalake.INFORMATION_SCHEMA.TABLES\n","ORDER BY\n"," table_name ASC;\n","\"\"\""],"metadata":{"id":"KIjXRizzs0w1"},"execution_count":null,"outputs":[]},{"cell_type":"code","source":["run_query(sql_list_dataset_schema)"],"metadata":{"colab":{"base_uri":"https://localhost:8080/","height":363},"id":"VKFrSeoMtAGE","outputId":"87ec5e17-6aae-4fcb-8320-955a5b02fd5a"},"execution_count":null,"outputs":[{"output_type":"execute_result","data":{"text/plain":[" table_name creation_time\n","0 entity_enum_value_to_name_mapping 2022-02-03\n","1 entity_graph 2022-02-02\n","2 ingestion_metrics 2022-04-19\n","3 ingestion_stats 2021-10-05\n","4 ioc_matches 2021-10-05\n","5 job_metadata 2021-10-05\n","6 rule_detections 2021-10-05\n","7 udm_enum_value_to_name_mapping 2021-10-05\n","8 udm_events 2021-10-05\n","9 udm_events_aggregates 2021-10-15"],"text/html":["\n","\n"," | table_name | \n","creation_time | \n","
---|---|---|
0 | \n","entity_enum_value_to_name_mapping | \n","2022-02-03 | \n","
1 | \n","entity_graph | \n","2022-02-02 | \n","
2 | \n","ingestion_metrics | \n","2022-04-19 | \n","
3 | \n","ingestion_stats | \n","2021-10-05 | \n","
4 | \n","ioc_matches | \n","2021-10-05 | \n","
5 | \n","job_metadata | \n","2021-10-05 | \n","
6 | \n","rule_detections | \n","2021-10-05 | \n","
7 | \n","udm_enum_value_to_name_mapping | \n","2021-10-05 | \n","
8 | \n","udm_events | \n","2021-10-05 | \n","
9 | \n","udm_events_aggregates | \n","2021-10-15 | \n","
Table | \n","Description | \n","Partitioned? | \n","
---|---|---|
entity_graph | \n","Export of UDM context data, e.g., Assets, IOCs, Resources, Users. | \n","Yes | \n","
entity_enum_value_to_name_mapping | \n","Lookup table for normalized values in the entity_graph table. | \n","No | \n","
ingestion_metrics | \n","Telemetry relating to log sources, both Chronicle SAS, Chronicle API, and Chronicle Forwarder related. This is the latest and recommended way for getting insights into your Chronicle log sources (over the prior ingestion_stats table). | \n","No | \n","
ingestion_stats | \n","Telemetry relating to log sources, both Chronicle SAS, Chronicle API, and Chronicle Forwarder related. | \n","No | \n","
ioc_matches | \n","IOC matches for types of IP or Domain, for both Chronicle default customer (3rd party) CTI sources. | \n","No | \n","
job_metadata | \n","Audits export of UDM Event and Entity data to BigQuery. Not really very useful. | \n","No | \n","
rule_detections | \n","Export of Detection Engine detections. Both Live rules and Retro Hunts will populate this table. | \n","No | \n","
udm_enum_value_to_name_mapping | \n","Lookup table for normalized values in the udm_events table. | \n","No | \n","
udm_events | \n","Export of UDM Event data. Note, this is not enabled by default and requires a support request in order to enable this table. Retains 6 months worth of UDM Event data. | \n","Yes | \n","
udm_events_aggregates | \n","An aggregate summary table for Authentication activity. Used by the embedded Looker dashboard 'User Signin Overview'. | \n","Yes | \n","
\n"," | userid | \n","count | \n","first_observed | \n","last_observed | \n","
---|---|---|---|---|
0 | \n","system:cluster-autoscaler | \n","4577842 | \n","2022-03-12 06:00:00+00:00 | \n","2022-04-20 14:59:58+00:00 | \n","
1 | \n","system:snapshot-controller | \n","1459099 | \n","2021-10-22 17:00:02+00:00 | \n","2022-04-20 14:59:55+00:00 | \n","
2 | \n","system:node:gk3-gke-p-cdf-03-default-pool-2130... | \n","20838 | \n","2022-03-12 06:00:03+00:00 | \n","2022-03-14 17:04:59+00:00 | \n","
3 | \n","system:serviceaccount:kube-system:service-acco... | \n","4 | \n","2022-03-28 19:24:03+00:00 | \n","2022-03-28 19:24:03+00:00 | \n","
4 | \n","system:gke-common-webhooks | \n","690433 | \n","2022-03-12 06:00:12+00:00 | \n","2022-04-20 14:59:54+00:00 | \n","
... | \n","... | \n","... | \n","... | \n","... | \n","
75 | \n","system:node:gk3-gke-p-cdf-02-default-pool-e7f2... | \n","24993 | \n","2021-10-22 17:00:05+00:00 | \n","2021-10-25 15:59:50+00:00 | \n","
76 | \n","system:node:gk3-gke-p-cdf-03-default-pool-606d... | \n","25020 | \n","2021-10-22 17:00:00+00:00 | \n","2021-10-25 15:59:27+00:00 | \n","
77 | \n","system:kube-controller-manager | \n","3632760 | \n","2021-10-22 17:00:00+00:00 | \n","2022-04-20 14:59:57+00:00 | \n","
78 | \n","system:node:gk3-gke-p-cdf-02-default-pool-6cc5... | \n","526 | \n","2022-03-28 17:12:25+00:00 | \n","2022-03-28 18:39:22+00:00 | \n","
79 | \n","system:managed-certificate-controller | \n","6913565 | \n","2021-10-22 17:00:01+00:00 | \n","2022-04-20 14:59:55+00:00 | \n","
80 rows × 4 columns
\n","\n"," | userid | \n","event_type | \n","count | \n","first_observed | \n","last_observed | \n","
---|---|---|---|---|---|
0 | \n","admin | \n","USER_LOGIN | \n","189 | \n","2021-10-02 10:18:03+00:00 | \n","2022-03-30 08:34:55+00:00 | \n","
1 | \n","admin_1823127835827_altostrat_co | \n","USER_LOGIN | \n","120 | \n","2021-10-02 07:04:23+00:00 | \n","2022-03-30 12:15:53+00:00 | \n","
\n"," | userid | \n","event_type | \n","count | \n","day | \n","
---|---|---|---|---|
0 | \n","admin | \n","USER_LOGIN | \n","10 | \n","2022-03-30 | \n","
1 | \n","admin | \n","USER_LOGIN | \n","22 | \n","2022-03-29 | \n","
2 | \n","admin | \n","USER_LOGIN | \n","24 | \n","2022-03-28 | \n","
3 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-27 | \n","
4 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-26 | \n","
5 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-25 | \n","
6 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-24 | \n","
7 | \n","admin | \n","USER_LOGIN | \n","12 | \n","2022-03-23 | \n","
8 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-22 | \n","
9 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-21 | \n","
10 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-20 | \n","
11 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-19 | \n","
12 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-18 | \n","
13 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-17 | \n","
14 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-16 | \n","
15 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-15 | \n","
16 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-14 | \n","
17 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-13 | \n","
18 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2022-03-12 | \n","
19 | \n","admin | \n","USER_LOGIN | \n","6 | \n","2021-10-18 | \n","
20 | \n","admin | \n","USER_LOGIN | \n","1 | \n","2021-10-07 | \n","
21 | \n","admin | \n","USER_LOGIN | \n","15 | \n","2021-10-05 | \n","
22 | \n","admin | \n","USER_LOGIN | \n","8 | \n","2021-10-04 | \n","
23 | \n","admin | \n","USER_LOGIN | \n","1 | \n","2021-10-02 | \n","
\n"," | avg_logins_per_day | \n","
---|---|
0 | \n","7.875 | \n","
\n"," | principal_ip | \n","traffic_out_mb | \n","traffic_in_mb | \n","
---|---|---|---|
0 | \n","[\"172.16.164.3\"] | \n","6849.0 | \n","1202.0 | \n","
1 | \n","[\"172.16.166.3\"] | \n","3467.0 | \n","230.0 | \n","
2 | \n","[\"10.166.0.3\"] | \n","953.0 | \n","36.0 | \n","
3 | \n","[\"10.164.0.9\"] | \n","608.0 | \n","755.0 | \n","
4 | \n","[\"10.166.0.11\"] | \n","458.0 | \n","567.0 | \n","
5 | \n","[\"10.164.0.26\"] | \n","122.0 | \n","53.0 | \n","
6 | \n","[\"10.164.0.28\"] | \n","74.0 | \n","3.0 | \n","
7 | \n","[\"172.16.164.4\"] | \n","16.0 | \n","21.0 | \n","
8 | \n","[\"172.16.166.4\"] | \n","13.0 | \n","16.0 | \n","
\n"," | hostname | \n","count | \n","first_observed | \n","last_observed | \n","
---|---|---|---|---|
0 | \n","win-jb-01.ad.1823127835827.altostrat.com | \n","24673 | \n","2022-03-12 06:05:45+00:00 | \n","2022-04-20 14:49:54+00:00 | \n","
\n"," | hostname | \n","count | \n","first_observed | \n","last_observed | \n","interval_duration | \n","
---|---|---|---|---|---|
0 | \n","win-jb-01.ad.1823127835827.altostrat.com | \n","24722 | \n","2022-03-12 06:05:45+00:00 | \n","2022-04-20 16:59:27+00:00 | \n","-39 | \n","
\n"," | hostname | \n","count | \n","creation_time | \n","last_observed | \n","interval_duration | \n","
---|---|---|---|---|---|
0 | \n","win-jb-01.ad.1823127835827.altostrat.com | \n","24722 | \n","2022-03-12 | \n","2022-04-20 | \n","-39 | \n","
\n"," | log_type | \n","normalized_events | \n","error_events | \n","
---|---|---|---|
0 | \n","GCP_CLOUDAUDIT | \n","8312725 | \n","0 | \n","
1 | \n","GCP_FIREWALL | \n","3032316 | \n","0 | \n","
2 | \n","GCP_DNS | \n","2838899 | \n","0 | \n","
3 | \n","WINEVTLOG | \n","169318 | \n","0 | \n","
4 | \n","WINDOWS_SYSMON | \n","41456 | \n","0 | \n","
5 | \n","GCP_CLOUD_NAT | \n","38688 | \n","0 | \n","
6 | \n","WORKSPACE_ACTIVITY | \n","28544 | \n","0 | \n","
7 | \n","NIX_SYSTEM | \n","2718 | \n","0 | \n","
8 | \n","POWERSHELL | \n","2461 | \n","0 | \n","
9 | \n","GCP_SECURITYCENTER | \n","2138 | \n","0 | \n","
10 | \n","WINDOWS_DEFENDER_AV | \n","766 | \n","0 | \n","
11 | \n","GCP_BIGQUERY_CONTEXT | \n","707 | \n","0 | \n","
12 | \n","GCP_COMPUTE_CONTEXT | \n","399 | \n","0 | \n","
13 | \n","GCP_LOADBALANCING | \n","388 | \n","0 | \n","
14 | \n","GCP_IAM_ANALYSIS | \n","368 | \n","0 | \n","
15 | \n","GCP_IAM_CONTEXT | \n","247 | \n","0 | \n","
16 | \n","GCP_STORAGE_CONTEXT | \n","228 | \n","0 | \n","
17 | \n","WORKSPACE_USERS | \n","132 | \n","0 | \n","
18 | \n","GCP_DLP_CONTEXT | \n","108 | \n","0 | \n","
19 | \n","WINDOWS_AD | \n","58 | \n","0 | \n","
20 | \n","UDM | \n","17 | \n","0 | \n","
21 | \n","CATCH_ALL | \n","10 | \n","0 | \n","
22 | \n","FORWARDER_HEARTBEAT | \n","0 | \n","0 | \n","
\n"," | ip | \n","
---|---|
0 | \n","[10.99.1.3] | \n","
1 | \n","[10.99.1.67] | \n","
2 | \n","[10.99.1.67] | \n","
3 | \n","[10.99.1.3] | \n","
4 | \n","[10.99.1.67] | \n","
\n"," | principal_ip | \n","target_ip | \n","port | \n","count | \n","
---|---|---|---|---|
0 | \n","172.16.164.3 | \n","169.254.169.254 | \n","53 | \n","306836 | \n","
1 | \n","172.16.166.3 | \n","169.254.169.254 | \n","53 | \n","46497 | \n","
2 | \n","10.164.0.15 | \n","10.99.1.2 | \n","53 | \n","16423 | \n","
3 | \n","10.164.0.15 | \n","10.99.0.194 | \n","53 | \n","16133 | \n","
4 | \n","10.164.0.12 | \n","10.99.1.2 | \n","53 | \n","15660 | \n","
5 | \n","10.164.0.14 | \n","10.99.0.194 | \n","53 | \n","15550 | \n","
6 | \n","10.164.0.14 | \n","10.99.1.2 | \n","53 | \n","15248 | \n","
7 | \n","10.164.0.12 | \n","10.99.0.194 | \n","53 | \n","15132 | \n","
8 | \n","10.166.0.10 | \n","10.105.128.6 | \n","53 | \n","12167 | \n","
9 | \n","10.166.0.8 | \n","10.105.128.6 | \n","53 | \n","12102 | \n","
\n"," | principal_ip | \n","target_ip | \n","port | \n","count | \n","
---|---|---|---|---|
0 | \n","[\"172.16.164.3\"] | \n","[\"169.254.169.254\"] | \n","53 | \n","306836 | \n","
1 | \n","[\"172.16.166.3\"] | \n","[\"169.254.169.254\"] | \n","53 | \n","46497 | \n","
2 | \n","[\"10.164.0.15\"] | \n","[\"10.99.1.2\"] | \n","53 | \n","16423 | \n","
3 | \n","[\"10.164.0.15\"] | \n","[\"10.99.0.194\"] | \n","53 | \n","16133 | \n","
4 | \n","[\"10.164.0.12\"] | \n","[\"10.99.1.2\"] | \n","53 | \n","15660 | \n","
5 | \n","[\"10.164.0.14\"] | \n","[\"10.99.0.194\"] | \n","53 | \n","15550 | \n","
6 | \n","[\"10.164.0.14\"] | \n","[\"10.99.1.2\"] | \n","53 | \n","15248 | \n","
7 | \n","[\"10.164.0.12\"] | \n","[\"10.99.0.194\"] | \n","53 | \n","15132 | \n","
8 | \n","[\"10.166.0.10\"] | \n","[\"10.105.128.6\"] | \n","53 | \n","12167 | \n","
9 | \n","[\"10.166.0.8\"] | \n","[\"10.105.128.6\"] | \n","53 | \n","12102 | \n","
\n"," | vendor_name | \n","product_event_type | \n","product_log_id | \n","key | \n","value | \n","
---|---|---|---|---|---|
0 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","eue5R_TRjiPtdcKnerniVEtzCy10bcCIj2-WRhZP5BU/Is... | \n","DEVICE_TYPE | \n","MAC | \n","
1 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","eue5R_TRjiPtdcKnerniVEtzCy10bcCIj2-WRhZP5BU/Is... | \n","DEVICE_MODEL | \n","MacBook Pro | \n","
2 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","HEJqifBMU2gYmfdZWFOH0h_Rp9I6ZaonX6CbHXUVaDg/1g... | \n","DEVICE_TYPE | \n","MAC | \n","
3 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","HEJqifBMU2gYmfdZWFOH0h_Rp9I6ZaonX6CbHXUVaDg/1g... | \n","DEVICE_MODEL | \n","MacBook Pro | \n","
4 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","0Gsen51N5R4F9HqJd4orBtsS9tovxg64orHsRiegiVY/rq... | \n","DEVICE_TYPE | \n","MAC | \n","
5 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","0Gsen51N5R4F9HqJd4orBtsS9tovxg64orHsRiegiVY/rq... | \n","DEVICE_MODEL | \n","MacBook Pro | \n","
6 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","0Gsen51N5R4F9HqJd4orBtsS9tovxg64orHsRiegiVY/aE... | \n","DEVICE_TYPE | \n","MAC | \n","
7 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","0Gsen51N5R4F9HqJd4orBtsS9tovxg64orHsRiegiVY/aE... | \n","DEVICE_MODEL | \n","MacBook Pro | \n","
8 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","0Gsen51N5R4F9HqJd4orBtsS9tovxg64orHsRiegiVY/RY... | \n","DEVICE_TYPE | \n","MAC | \n","
9 | \n","Google Workspace | \n","DEVICE_SYNC_EVENT | \n","0Gsen51N5R4F9HqJd4orBtsS9tovxg64orHsRiegiVY/RY... | \n","DEVICE_MODEL | \n","MacBook Pro | \n","
\n"," | hostname | \n","asset_ip_address | \n","feed_log_type | \n","ioc_type | \n","category | \n","count | \n","
---|---|---|---|---|---|---|
0 | \n","None | \n","10.166.0.3 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","16504 | \n","
1 | \n","None | \n","10.164.0.27 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","13501 | \n","
2 | \n","win-dc-01 | \n","None | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","12997 | \n","
3 | \n","None | \n","10.164.0.3 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","12555 | \n","
4 | \n","None | \n","10.166.0.5 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","12119 | \n","
5 | \n","lin-jb-02 | \n","None | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","8773 | \n","
6 | \n","win-dc-02 | \n","None | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","8045 | \n","
7 | \n","None | \n","10.164.0.26 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Target of a DDoS | \n","7755 | \n","
8 | \n","lin-mgmt-01 | \n","None | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","6642 | \n","
9 | \n","win-dc-01 | \n","None | \n","ET_PRO_IOC | \n","IOC_TYPE_DOMAIN | \n","Malware Command and Control Server | \n","5911 | \n","
\n"," | asset | \n","feed_log_type | \n","ioc_type | \n","category | \n","count | \n","
---|---|---|---|---|---|
0 | \n","10.166.0.3 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","16504 | \n","
1 | \n","10.164.0.27 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","13501 | \n","
2 | \n","win-dc-01 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","12997 | \n","
3 | \n","10.164.0.3 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","12555 | \n","
4 | \n","10.166.0.5 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","12119 | \n","
5 | \n","lin-jb-02 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","8773 | \n","
6 | \n","win-dc-02 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","8045 | \n","
7 | \n","10.164.0.26 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Target of a DDoS | \n","7755 | \n","
8 | \n","lin-mgmt-01 | \n","ET_PRO_IOC | \n","IOC_TYPE_IP | \n","Observed serving executables | \n","6642 | \n","
9 | \n","win-dc-01 | \n","ET_PRO_IOC | \n","IOC_TYPE_DOMAIN | \n","Malware Command and Control Server | \n","5911 | \n","
\n"," | count | \n","field_path | \n","
---|---|---|
0 | \n","20 | \n","backstory.Resource.ResourceType | \n","
1 | \n","20 | \n","backstory.SecurityResult.SecurityCategory | \n","
2 | \n","10 | \n","backstory.Asset.AssetType | \n","
3 | \n","9 | \n","backstory.EntityMetadata.EntityType | \n","
4 | \n","7 | \n","backstory.Noun.Platform | \n","
5 | \n","7 | \n","backstory.SecurityResult.ProductSeverity | \n","
6 | \n","6 | \n","backstory.Id.Namespace | \n","
7 | \n","6 | \n","backstory.SecurityResult.Action | \n","
8 | \n","5 | \n","backstory.Vulnerability.Severity | \n","
9 | \n","5 | \n","backstory.Permission.PermissionType | \n","
10 | \n","5 | \n","backstory.Authentication.AuthenticationStatus | \n","
11 | \n","4 | \n","backstory.Status | \n","
12 | \n","4 | \n","backstory.Relation.Relationship | \n","
13 | \n","4 | \n","backstory.Asset.DeploymentStatus | \n","
14 | \n","4 | \n","backstory.Cloud.CloudEnvironment | \n","
15 | \n","4 | \n","backstory.SecurityResult.ThreatStatus | \n","
16 | \n","4 | \n","backstory.SecurityResult.ProductPriority | \n","
17 | \n","4 | \n","backstory.SecurityResult.ProductConfidence | \n","
18 | \n","3 | \n","backstory.Verdict | \n","
19 | \n","3 | \n","backstory.Role.Type | \n","
20 | \n","3 | \n","backstory.User.Role | \n","
21 | \n","3 | \n","backstory.Reputation | \n","
22 | \n","3 | \n","backstory.Relation.Directionality | \n","
23 | \n","3 | \n","backstory.SecurityResult.AlertState | \n","
24 | \n","1 | \n","google.protobuf.NullValue | \n","
\n"," | count | \n","vendor_name | \n","product_name | \n","enum_name | \n","
---|---|---|---|---|
0 | \n","204 | \n","Google Cloud | \n","Google Cloud BigQuery | \n","RESOURCE | \n","
1 | \n","100 | \n","Google Compute Engine | \n","GCP_COMPUTE_CONTEXT | \n","ASSET | \n","
2 | \n","91 | \n","Cloud Identity | \n","USER | \n","|
3 | \n","86 | \n","Google Cloud IAM | \n","Google Cloud IAM ANALYSIS | \n","USER | \n","
4 | \n","48 | \n","Microsoft | \n","Windows Active Directory | \n","USER | \n","
5 | \n","36 | \n","Access Context Manager | \n","USER | \n","|
6 | \n","24 | \n","Google Compute Engine | \n","GCP_STORAGE_CONTEXT | \n","RESOURCE | \n","
7 | \n","24 | \n","Google Cloud | \n","GCP_STORAGE_CONTEXT | \n","RESOURCE | \n","
\n"," | context_entity_type | \n","context_vendor | \n","context_product | \n","collected_timestamp | \n","interval_start_timestamp | \n","interval_end_timestamp | \n","interval_duration | \n","user_first_name | \n","user_last_name | \n","user_id | \n","user_email | \n","product_entity_id | \n","user_asset_hostname | \n","user_asset_id | \n","user_asset_ip | \n","
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
0 | \n","USER | \n","Google Cloud Platform | \n","GCP IAM ANALYSIS | \n","2022-04-18 03:34:52+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","2022-04-21 00:00:00+00:00 | \n","24 | \n","None | \n","None | \n","102520959283965001184 | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","
1 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","2022-04-21 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","|
2 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","2022-04-21 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.demo.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","|
3 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","2022-04-21 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.altostrat.com.test-google-... | \n","None | \n","None | \n","None | \n","[] | \n","|
4 | \n","USER | \n","Google Cloud Platform | \n","GCP IAM ANALYSIS | \n","2022-04-17 03:51:42+00:00 | \n","2022-04-18 00:00:00+00:00 | \n","2022-04-18 03:34:36+00:00 | \n","3 | \n","None | \n","None | \n","102520959283965001184 | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","
5 | \n","USER | \n","Google Cloud Platform | \n","GCP IAM ANALYSIS | \n","2022-04-18 03:34:36+00:00 | \n","2022-04-18 03:34:36+00:00 | \n","2022-04-18 03:34:52+00:00 | \n","0 | \n","None | \n","None | \n","102520959283965001184 | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","
6 | \n","USER | \n","Google Cloud Platform | \n","GCP IAM ANALYSIS | \n","2022-04-18 03:34:52+00:00 | \n","2022-04-18 03:34:52+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","21 | \n","None | \n","None | \n","102520959283965001184 | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","
7 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-18 00:00:00+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","|
8 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-18 00:00:00+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.demo.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","|
9 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-18 00:00:00+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.altostrat.com.test-google-... | \n","None | \n","None | \n","None | \n","[] | \n","|
10 | \n","USER | \n","Google Cloud Platform | \n","GCP IAM ANALYSIS | \n","2022-04-18 03:34:52+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","24 | \n","None | \n","None | \n","102520959283965001184 | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","
11 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","|
12 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.demo.altostrat.com | \n","None | \n","None | \n","None | \n","[] | \n","|
13 | \n","USER | \n","Cloud Identity | \n","2022-04-13 12:49:21+00:00 | \n","2022-04-19 00:00:00+00:00 | \n","2022-04-20 00:00:00+00:00 | \n","24 | \n","Super | \n","User | \n","admin_1823127835827_altostrat_co | \n","admin@1823127835827.altostrat.com.test-google-... | \n","None | \n","None | \n","None | \n","[] | \n","
\n"," | count | \n","first_observed | \n","last_observed | \n","sip | \n","name | \n","
---|---|---|---|---|---|
0 | \n","192 | \n","2022-03-24 00:35:12+00:00 | \n","2022-03-30 14:34:31+00:00 | \n","10.166.0.3 | \n","settings-prod-neu-1.northeurope.cloudapp.azure... | \n","
1 | \n","191 | \n","2022-03-24 03:28:53+00:00 | \n","2022-03-30 10:22:13+00:00 | \n","10.166.0.3 | \n","settings-prod-neu-2.northeurope.cloudapp.azure... | \n","
2 | \n","102 | \n","2022-03-24 03:38:11+00:00 | \n","2022-03-30 13:41:38+00:00 | \n","10.166.0.3 | \n","wd-prod-ss-eu-north-2-fe.northeurope.cloudapp.... | \n","
3 | \n","102 | \n","2022-03-24 00:38:10+00:00 | \n","2022-03-30 12:39:26+00:00 | \n","10.166.0.3 | \n","wd-prod-ss-eu-north-1-fe.northeurope.cloudapp.... | \n","
4 | \n","98 | \n","2022-03-24 02:38:11+00:00 | \n","2022-03-30 14:41:39+00:00 | \n","10.166.0.3 | \n","wd-prod-ss-eu-west-2-fe.westeurope.cloudapp.az... | \n","
5 | \n","88 | \n","2022-03-24 00:38:10+00:00 | \n","2022-03-30 09:41:36+00:00 | \n","10.166.0.3 | \n","wd-prod-ss-eu-west-1-fe.westeurope.cloudapp.az... | \n","
6 | \n","49 | \n","2022-03-24 01:39:36+00:00 | \n","2022-03-30 11:20:14+00:00 | \n","10.166.0.3 | \n","onedscolprdaus02.australiasoutheast.cloudapp.a... | \n","
7 | \n","22 | \n","2022-03-24 02:07:08+00:00 | \n","2022-03-30 10:17:56+00:00 | \n","10.166.0.3 | \n","onedscolprdaus00.australiasoutheast.cloudapp.a... | \n","
8 | \n","9 | \n","2022-03-24 10:08:40+00:00 | \n","2022-03-30 10:09:21+00:00 | \n","10.166.0.3 | \n","storecatalogrevocation.storequality.microsoft.... | \n","
9 | \n","6 | \n","2022-03-24 04:29:47+00:00 | \n","2022-03-29 09:31:04+00:00 | \n","10.166.0.3 | \n","wd-prod-cp-eu-north-1-fe.northeurope.cloudapp.... | \n","
\n"," | count | \n","dip | \n","
---|---|---|
0 | \n","112292 | \n","10.99.1.2 | \n","
1 | \n","111446 | \n","10.99.0.194 | \n","
2 | \n","97233 | \n","10.105.128.66 | \n","
3 | \n","96658 | \n","10.105.128.6 | \n","
4 | \n","14102 | \n","10.99.0.67 | \n","
5 | \n","13848 | \n","10.99.0.6 | \n","
\n"," | total | \n","event_type | \n","day | \n","vendor_name | \n","product_name | \n","product_event_type | \n","principal_user | \n","principal_host | \n","target_user | \n","target_host | \n","
---|---|---|---|---|---|---|---|---|---|---|
0 | \n","2 | \n","USER_LOGIN | \n","2022-03-12 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4624 | \n","win-dc-01$ | \n","win-dc-01 | \n","admin | \n","None | \n","
1 | \n","2 | \n","USER_LOGIN | \n","2022-03-12 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4648 | \n","win-dc-01$ | \n","win-dc-01 | \n","admin | \n","localhost | \n","
2 | \n","2 | \n","USER_LOGIN | \n","2022-03-12 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4672 | \n","None | \n","win-dc-01.ad.1823127835827.altostrat.com | \n","admin | \n","None | \n","
3 | \n","2 | \n","USER_LOGIN | \n","2022-03-13 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4648 | \n","win-dc-01$ | \n","win-dc-01 | \n","admin | \n","localhost | \n","
4 | \n","2 | \n","USER_LOGIN | \n","2022-03-13 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4672 | \n","None | \n","win-dc-01.ad.1823127835827.altostrat.com | \n","admin | \n","None | \n","
... | \n","... | \n","... | \n","... | \n","... | \n","... | \n","... | \n","... | \n","... | \n","... | \n","... | \n","
179 | \n","14 | \n","USER_LOGIN | \n","2022-04-19 | \n","Google Workspace | \n","login | \n","login_success | \n","None | \n","62.163.105.47 | \n","c03siqfu3 | \n","None | \n","
180 | \n","2 | \n","USER_LOGIN | \n","2022-04-20 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4624 | \n","win-dc-01$ | \n","win-dc-01 | \n","admin | \n","None | \n","
181 | \n","2 | \n","USER_LOGIN | \n","2022-04-20 | \n","Google Workspace | \n","saml | \n","login_success | \n","None | \n","62.163.105.47 | \n","c03siqfu3 | \n","None | \n","
182 | \n","2 | \n","USER_LOGIN | \n","2022-04-20 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4672 | \n","None | \n","win-dc-01.ad.1823127835827.altostrat.com | \n","admin | \n","None | \n","
183 | \n","2 | \n","USER_LOGIN | \n","2022-04-20 | \n","Microsoft | \n","Microsoft-Windows-Security-Auditing | \n","4648 | \n","win-dc-01$ | \n","win-dc-01 | \n","admin | \n","localhost | \n","
184 rows × 10 columns
\n","[1] UDM event data is not enabled by default.
"],"metadata":{"id":"eWa6AmfmT1SY"}}]}