このページでは、新しいユニバーサル形式を含むトランザクションイベント形式のリファレンスと、従来の形式1から形式4までの形式を提供します。
詳細については、トランザクション イベント フィールド リファレンスを参照してください。
トランザクションイベントユニバーサル
フィールドのリストが固定されたトランザクションイベントフォーマットが何度か進化した後、完全にカスタマイズ可能で常に進化し続ける「トランザクションイベントユニバーサル」と呼ばれるフォーマットに移行します。
今回の変更により、イベントをエクスポートする際に、すべてのお客様が関心のあるフィールドを選択できるようになります。
Transaction Events Universalは197のフィールドを備えて導入され、今後徐々に拡張されていく予定です。新しいフィールドを追加した際に本番環境への影響を避けるため、今後はすべてのトランザクションイベントのエクスポートにおいて、フィールドのリストを定義することを必須とします。
トランザクションイベント ユニバーサルトランジション
Netskope Security Cloudの機能は、段階的にTransaction Events Universalに移行されます。
- SkopeIT: トランザクションイベントユニバーサルのみ
- イベントストリーミングクライアント:
- ほとんどのテナントは Transaction Events Universal を使用しており、Legacy Format を使用しているテナントはわずかです。
- 新しい構成は TE Universal を使用します。
- すべてのTEユニバーサルフィールドがサポートされています
- ログをクラウドに直接ストリーミングする:
- ほとんどのテナントは Transaction Events Universal を使用しており、Legacy Format を使用しているテナントはわずかです。
- 新しい構成は TE Universal を使用します。
- 注:現在、許可されるフィールドリストを拡張し、すべてのTE Universalフィールドを含めるように作業を進めています。
- Advanced Analytics :トランザクションイベントユニバーサルへの移行が進行中です。
- Splunk TA with PubSubLight (サポート終了): レガシー形式のみ
- PubSubLight サブスクリプション付きCloud Exchange (サポート終了): レガシー形式のみ
- Cloud Exchangeとクラウドへのログストリーミング機能:
- ほとんどのテナントは Transaction Events Universal を使用しており、Legacy Format を使用しているテナントはわずかです。
- 新しい構成は TE Universal を使用します。
- 注:現在、許可されるフィールドリストを拡張し、すべてのTE Universalフィールドを含めるように作業を進めています。
トランザクション イベント ユニバーサル キーの改善
影響を与えることなく、オンデマンドで新しいフィールドを追加することで将来の進化をサポートすることに加えて、既存のデータの標準化を完了しました。
標準化されたフィールドコンテンツ:
- xc-authn-user / cs-username は、ユーザーが認証されていない場合、ユーザーの IP アドレスを含めなくなりました。
ユーザーIPは、c-ip、x-cs-userip、およびx--src-ipで引き続き利用可能です。
ユーザーが認証されていない場合、xc-authn-user / cs-username には次の値が含まれます。- 認証なし:設定済みの認証バイパスがクライアントのリクエストと一致しました。
- 保留中:このリクエストは認証が必要なため、IDPにリダイレクトされます。このリクエストはまだ認証されていません。
- 例外:POPはこのリクエストを認証できませんでした。
- 複数値(リスト)フィールドはすべてセミコロン(;)区切り文字で区切られるようになりました。複数値を持つフィールドの全リストは以下のとおりです。
- x-other-category ( previous separator was 、 ) および x-policy-categories
- x-ssl-ポリシー-カテゴリ
- x-cs-app-instance-tag ( previous separator was ,) および x-cs-app-instance-tags
- x-cs-app-tags (previous separator was ,)
- x-cs-access-proxy
- x-tp-result
- x-tp-engine
- x-tp-malware-name
- x-tp-severity
- x-c-authz-groups
- x-rsファイル-md5
- x-rsファイル-sha256
- 日時フィールドはエポックタイムとYYYY-MM-DD hh:mm:ssに標準化されています。
- リクエスト開始時刻 (UTC/GMT タイムゾーン)
- x-cs-timestamp: エポック形式
- date: YYYY-MM-DD
- 時刻: hh:mm:ss
- ユーザーの現地時間
- x-c-timezone: Timezone offset in string (eq +01:00)
- xc-local-timestamp: ローカルタイムゾーンのエポック形式
- xc-local-time: ローカルタイムゾーンの YYYY-MM-DD hh:mm:ss 形式
- リモートサーバー証明書の開始時刻 (UTC/GMT タイムゾーン)
- xr-cert-開始: エポック形式
- x-r-cert-startdate: YYYY-MM-DD hh:mm:ss format (previous format was MMM d HH:mm:ss yyyy z)
- リモートサーバー証明書の有効期限(UTC/GMTタイムゾーン)
- xr-cert-end: エポック形式
- x-r-cert-enddate: YYYY-MM-DD hh:mm:ss format (previous format was MMM d HH:mm:ss yyyy z)
- リクエスト開始時刻 (UTC/GMT タイムゾーン)
削除されたフィールド(エクスポート時には常に空になります):
- x-category-id: いつも空です。 x-categoryでカテゴリを識別します
- x-other-category-id: 今は常に空です。カテゴリを識別するために x-policy-categories を使用してください
- x-cs-domain-fronted-sni: 今は常に空です。 このフィールドは、ドメインフロント保護(HTTP GETで受信したSNIとホスト名の不一致を検出する)に関するフィードバックを提供するために設計されましたが、顧客がx-cs-sniと比較する必要があったため、直感的ではありませんでした。その代わりに、ドメインフロンティングの検出を識別するために、x-cs-ssl-fronting-errorを導入しました。x-cs-sni は、受信した SNI でも使用できます。
フィールド名の標準化(推奨フィールド名へのスムーズな移行を可能にするため、すべてのフィールドが利用可能です):
- c-ip、x-cs-userip、および x-ポリシー-src-ip は同じ値です。推奨フィールドは x-ポリシー-src-ip です。
- s-ip と x-ポリシー-dst-ip は同じ値です。推奨フィールドは x-ポリシー-dst-ip です。
- cs-usernameとxc-authn-userの値が同じ場合、推奨フィールドはxc-authn-userです。
- cs-dnsとcs-hostの値が同じ場合、推奨フィールドはcs-hostです。
- cs-uri は x-cs-uri-path と cs-uri-query を連結したものです。x-cs-uri-path と cs-uri-query は別々のフィールドでエクスポートするか、 完全な URL には x-cs-url を使用することをお勧めします。
- xs-countryとxr-countryは同じ値なので、推奨フィールドはxr-countryです。
- x-s-latitude and x-r-latitude have the same value, recommended field is x-r-latitude
- x-s-longitude and x-r-longitude have the same value, recommended field is x-r-longitude
- xs-locationとxr-locationの値が同じ場合、推奨フィールドはxr-locationです。
- xs-regionとxr-regionの値は同じですが、推奨フィールドはxr-regionです。
- xs-zipcodeとxr-zipcodeは同じ値なので、推奨フィールドはxr-zipcodeです。
- x-other-category と x-policy-categories は同じ値です。推奨フィールドは x-policy-categories です。
- x-cs-app-instance-tag と x-cs-app-instance-tags は同じ値ですが、推奨フィールドは x-cs-app-instance-tags です。
補足事項:
- Warning: sc-bytesにはリモートサーバーのトラフィックは含まれなくなりました。このデータはrs-bytesに移行しました。総帯域幅の計算にsc-bytesを使用している顧客は、ロジックを更新しないと、報告されるデータが低下する可能性があります。sc-bytes には、W3C ELFF 標準で定義されている POP to Client バイトが含まれるようになりました。
フォーマットごとの動作変更
このセクションでは、各レガシーフォーマットバージョンにおける具体的な動作変更について説明します。
ご注意ください。変更されるのはフィールドの内容のみで、フィールド名はすべて変更されておらず、すべて利用可能です。同じフィールドリストを使用してTE Universalに移行する場合、以下の変更が適用されます。現在使用しているエクスポート形式に基づいて確認してください。
フォーマット1からユニバーサルへ
- x-other-category: 区切り文字が , から ; に変更されました
- cs-username: IP は、認証されていない状態で使用される場合はもう使用されません。新しい値は、未認証、保留中、および例外です。
- x-category-id: 削除されました。常に空になります。 代わりに x-category を使用してください
- x-other-category-id: 削除されました。常に空になります。 代わりに x-other-category を使用してください
- x-cs-domain-fronted-sni: 削除されました。常に空になります。代わりに x-cs-ssl-fronting-error を追加することを検討してください。
- sc-bytesにはリモートサーバーのトラフィックは含まれなくなりました。このデータはrs-bytesに移行しました。総帯域幅の計算にsc-bytesを使用している顧客は、ロジックを更新しないと、報告されるデータが低下する可能性があります。
フォーマット2からユニバーサルへ
- x-other-category: 区切り文字が , から ; に変更されました
- cs-username: IP は、認証されていない状態で使用される場合はもう使用されません。新しい値は、未認証、保留中、および例外です。
- x-category-id: 削除されました。常に空になります。 代わりに x-category を使用してください
- x-other-category-id: 削除されました。常に空になります。 代わりに x-other-category を使用してください
- x-cs-domain-fronted-sni: 削除されました。常に空になります。代わりに x-cs-ssl-fronting-error を使用してください。
- x-r-cert-startdate: YYYY-MM-DD hh:mm:ss format
- x-r-cert-enddate: YYYY-MM-DD hh:mm:ss format
- sc-bytesにはリモートサーバーのトラフィックは含まれなくなりました。このデータはrs-bytesに移行しました。総帯域幅の計算にsc-bytesを使用している顧客は、ロジックを更新しないと、報告されるデータが低下する可能性があります。
フォーマット3からユニバーサルへ
- x-other-category: 区切り文字が , から ; に変更されました
- cs-username: IP は、認証されていない状態で使用される場合はもう使用されません。新しい値は、未認証、保留中、および例外です。
- x-category-id: 削除されました。常に空になります。 代わりに x-category を使用してください
- x-other-category-id: 削除されました。常に空になります。 代わりに x-other-category を使用してください
- x-cs-domain-fronted-sni: 削除されました。常に空になります。代わりに x-cs-ssl-fronting-error を使用してください。
- xr-cert-startdate: YYYY-MM-DD hh:mm:ss形式(以前の形式は MMM d HH:mm:ss yyyy z でした)
- xr-cert-enddate: YYYY-MM-DD hh:mm:ss形式(以前の形式は MMM d HH:mm:ss yyyy z)
- x-cs-app-instance-tag: 区切り文字が , から ; に変更されました
- x-cs-app-tags: 区切り文字が , から ; に変更されました
- sc-bytesにはリモートサーバーのトラフィックは含まれなくなりました。このデータはrs-bytesに移行しました。総帯域幅の計算にsc-bytesを使用している顧客は、ロジックを更新しないと、報告されるデータが低下する可能性があります。
フォーマット4からユニバーサルへ
- x-other-category: 区切り文字が , から ; に変更されました
- cs-username: IP は、認証されていない状態で使用される場合はもう使用されません。新しい値は、未認証、保留中、および例外です。
- x-category-id: 削除されました。常に空になります。 代わりに x-category を使用してください
- x-other-category-id: 削除されました。常に空になります。 代わりに x-other-category を使用してください
- x-cs-domain-fronted-sni: 削除されました。常に空になります。代わりに x-cs-ssl-fronting-error を使用してください。
- xr-cert-startdate: YYYY-MM-DD hh:mm:ss形式(以前の形式は MMM d HH:mm:ss yyyy z でした)
- xr-cert-enddate: YYYY-MM-DD hh:mm:ss形式(以前の形式は MMM d HH:mm:ss yyyy z)
- x-cs-app-instance-tag: 区切り文字が , から ; に変更されました
- x-cs-app-tags: 区切り文字が , から ; に変更されました
トランザクションイベントのレガシーフォーマット1~フォーマット4
このセクションでは、各フォーマットで使用可能なフィールドのリファレンスを提供します。
Format 1
#フィールド: date time time-taken cs-bytes sc-bytes bytes c-ip s-ip cs-username cs-method cs-uri-scheme cs-uri-query cs-user-agent cs-content-type sc-status sc-content-type cs-dns cs-host cs-uri cs-uri-port cs-referer x-cs-session-id x-cs-access-method x-cs-app xs-country xs-latitude xs-longitude xs-location xs-region xs-zipcode xc-country xc-latitude xc-longitude xc-location xc-region xc-zipcode xc-os xc-browser xc-browser-version xc- x-cs-site x-cs-timestamp x-cs-page-id x-cs-userip x-cs-traffic-type x-cs-tunnel-id x-category x-other-category x-type x-server-ssl-err x-client-ssl-err x-transaction-id x-request-id x-cs-sni x-cs-domain-fronted-sni x-category-id x-other-category-id x-sr-headers-name x-sr-headers-value
Format 2
フォーマット2は、以下の斜体で示されたフィールドが追加されている点を除いて、フォーマット1と同じです。
#フィールド: date time time-taken cs-bytes sc-bytes bytes c-ip s-ip cs-username cs-method cs-uri-scheme cs-uri-query cs-user-agent cs-content-type sc-status sc-content-type cs-dns cs-host cs-uri cs-uri-port cs-referer x-cs-session-id x-cs-access-method x-cs-app xs-country xs-latitude xs-longitude xs-location xs-region xs-zipcode xc-country xc-latitude xc-longitude xc-location xc-region xc-zipcode xc-os xc-browser xc-browser-version xc- x-cs-site x-cs-timestamp x-cs-page-id x-cs-userip x-cs-traffic-type x-cs-tunnel-id x-category x-other-category x-type x-server-ssl-err x-client-ssl-err x-transaction-id x-request-id x-cs-sni x-cs-domain-fronted-sni x-category-id x-other-category-id x-sr-headers-name x-sr-headers-value x-cs-ssl-ja3 x-sr-ssl-ja3s x-ssl-bypass x-ssl-bypass-reason xr-cert-subject-cn xr-cert-issuer-cn xr-cert-startdate xr-cert-enddate xr-cert-valid xr-cert-expired xr-cert-untrusted-root xr-cert-incomplete-chain xr-cert-self-signed xr-cert-revoked xr-cert-revocation-check xr-cert-mismatch x-cs-ssl-fronting-error x-cs-ssl-handshake-error x-sr-ssl-handshake-error x-sr-ssl-client-certificate-error x-sr-ssl-malformed-ssl xs-custom-signing-ca-error x-cs-ssl-engine-action x-cs-ssl-engine-action-reason x-sr-ssl-engine-action x-ssl-engine-action-reason x-ssl-ポリシー-src-ip x-ssl-ポリシー-dst-ip x-ssl-ポリシー-dst-host x-ssl-ポリシー-dst-host-source x-ssl-ポリシー-カテゴリ x-ssl-ポリシー-アクション x-ssl-ポリシー-名 x-cs-ssl-バージョン x-cs-ssl-cipher x-sr-ssl-version x-sr-ssl-cipher x-cs-src-ip-egress
Format 3
フォーマット3は、以下の斜体で示されたフィールドが追加されている点を除いて、フォーマット2と同じです。
#フィールド: date time time-taken cs-bytes sc-bytes bytes c-ip s-ip cs-username cs-method cs-uri-scheme cs-uri-query cs-user-agent cs-content-type sc-status sc-content-type cs-dns cs-host cs-uri cs-uri-port cs-referer x-cs-session-id x-cs-access-method x-cs-app xs-country xs-latitude xs-longitude xs-location xs-region xs-zipcode xc-country xc-latitude xc-longitude xc-location xc-region xc-zipcode xc-os xc-browser xc-browser-version xc- x-cs-site x-cs-timestamp x-cs-page-id x-cs-userip x-cs-traffic-type x-cs-tunnel-id x-category x-other-category x-type x-server-ssl-err x-client-ssl-err x-transaction-id x-request-id x-cs-sni x-cs-domain-fronted-sni x-category-id x-other-category-id x-sr-headers-name x-sr-headers-value x-cs-ssl-ja3 x-sr-ssl-ja3s x-ssl-bypass x-ssl-bypass-reason xr-cert-subject-cn xr-cert-issuer-cn xr-cert-startdate xr-cert-enddate xr-cert-valid xr-cert-expired xr-cert-untrusted-root xr-cert-incomplete-chain xr-cert-self-signed xr-cert-revoked xr-cert-revocation-check xr-cert-mismatch x-cs-ssl-fronting-error x-cs-ssl-handshake-error x-sr-ssl-handshake-error x-sr-ssl-client-certificate-error x-sr-ssl-malformed-ssl xs-custom-signing-ca-error x-cs-ssl-engine-action x-cs-ssl-engine-action-reason x-sr-ssl-engine-action x-ssl-engine-action-reason x-ssl-ポリシー-src-ip x-ssl-ポリシー-dst-ip x-ssl-ポリシー-dst-host x-ssl-ポリシー-dst-host-source x-ssl-ポリシー-カテゴリ x-ssl-ポリシー-アクション x-ssl-ポリシー-名 x-cs-ssl-バージョン x-cs-ssl-cipher x-sr-ssl-version x-sr-ssl-cipher x-cs-src-ip-egress xs-dp-name x-cs-src-ip x-cs-src-port x-cs-dst-ip x-cs-dst-port x-sr-src-ip x-sr-src-port x-sr-dst-ip x-sr-dst-port x-cs-ip-connect-xff x-cs-ip-xff x-cs-connect-host x-cs-connect-port x-cs-connect-user-agent x-cs-url x-cs-uri-path x-cs-http-version rs-status x-cs-app-category x-cs-app-cci x-cs-app-ccl x-cs-app-tags x-cs-app-suite x-cs-app-instance-id x-cs-app-instance-name x-cs-app-instance-tag x-cs-app-activity x-cs-app-from-user x-cs-app-to-user x-cs-app-object-type x-cs-app-object-name x-cs-app-object-id x-rs-file-type x-rs-file-category x-rs-file- language x-rs-file-size x-rs-file-md5 x-rs-file-sha256 x-error xc-local-time x-policy-action x-policy-name x-policy-src-ip x-policy-dst-ip x-policy-dst-host x-ポリシー-dst-host-source x-ポリシー-justification-type x-ポリシー-justification-reason x-sc-notification-name
Format 4
フォーマット4は、以下の斜体で示されたフィールドが追加されている点を除いて、フォーマット3と同じです。
#フィールド: date time time-taken cs-bytes sc-bytes bytes c-ip s-ip cs-username cs-method cs-uri-scheme cs-uri-query cs-user-agent cs-content-type sc-status sc-content-type cs-dns cs-host cs-uri cs-uri-port cs-referer x-cs-session-id x-cs-access-method x-cs-app xs-country xs-latitude xs-longitude xs-location xs-region xs-zipcode xc-country xc-latitude xc-longitude xc-location xc-region xc-zipcode xc-os xc-browser xc-browser-version xc- x-cs-site x-cs-timestamp x-cs-page-id x-cs-userip x-cs-traffic-type x-cs-tunnel-id x-category x-other-category x-type x-server-ssl-err x-client-ssl-err x-transaction-id x-request-id x-cs-sni x-cs-domain-fronted-sni x-category-id x-other-category-id x-sr-headers-name x-sr-headers-value x-cs-ssl-ja3 x-sr-ssl-ja3s x-ssl-bypass x-ssl-bypass-reason xr-cert-subject-cn xr-cert-issuer-cn xr-cert-startdate xr-cert-enddate xr-cert-valid xr-cert-expired xr-cert-untrusted-root xr-cert-incomplete-chain xr-cert-self-signed xr-cert-revoked xr-cert-revocation-check xr-cert-mismatch x-cs-ssl-fronting-error x-cs-ssl-handshake-error x-sr-ssl-handshake-error x-sr-ssl-client-certificate-error x-sr-ssl-malformed-ssl xs-custom-signing-ca-error x-cs-ssl-engine-action x-cs-ssl-engine-action-reason x-sr-ssl-engine-action x-ssl-engine-action-reason x-ssl-ポリシー-src-ip x-ssl-ポリシー-dst-ip x-ssl-ポリシー-dst-host x-ssl-ポリシー-dst-host-source x-ssl-ポリシー-カテゴリ x-ssl-ポリシー-アクション x-ssl-ポリシー-名 x-cs-ssl-バージョン x-cs-ssl-cipher x-sr-ssl-version x-sr-ssl-cipher x-cs-src-ip-egress xs-dp-name x-cs-src-ip x-cs-src-port x-cs-dst-ip x-cs-dst-port x-sr-src-ip x-sr-src-port x-sr-dst-ip x-sr-dst-port x-cs-ip-connect-xff x-cs-ip-xff x-cs-connect-host x-cs-connect-port x-cs-connect-user-agent x-cs-url x-cs-uri-path x-cs-http-version rs-status x-cs-app-category x-cs-app-cci x-cs-app-ccl x-cs-app-tags x-cs-app-suite x-cs-app-instance-id x-cs-app-instance-name x-cs-app-instance-tag x-cs-app-activity x-cs-app-from-user x-cs-app-to-user x-cs-app-object-type x-cs-app-object-name x-cs-app-object-id x-rs-file-type x-rs-file-category x-rs-file- language x-rs-file-size x-rs-file-md5 x-rs-file-sha256 x-error xc-local-time x-policy-action x-policy-name x-policy-src-ip x-policy-dst-ip x-policy-dst-host x-ポリシー-dst-host-source x-ポリシー-justification-type x-ポリシー-justification-reason x-sc-notification-name sr-bytes rs-bytes x-action x-action-reason xc-authn-user xc-authn-source xc-authn-surrogate xc-authn-surrogate-status xc-authz-groups xc-authz-ou x-cs-xau x-cs-connect-xau xc-user-confidence-index xc-hostname xc-デバイス-uid xc-os-family xc-os-version xc-nsclient-version xc-nsclient-client-profile xc-nsclient-steering-profile xc-デバイス-classification x-cs-nsclient-tunnel-type x-cs-process x-cs-pid x-cs-parent-process x-cs-ppid x-tp-result x-tp-engine x-tp-マルウェア-name x-tp-severity x-sr-forward-dest x-ssl-ポリシー-issuer x-eip-ポリシー-name x-eip-ポリシー-フットプリント x-ポリシー-カテゴリ xc-timezone x-support

