ApacheHTTPServer_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (8 columns)

Source: KQL validation test schema

Column Name Type
_ItemId string
_ResourceId string
Computer string
ItemId string
RawData string
ResourceId string
TimeGenerated datetime
Type string

Solutions (2)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
[Deprecated] Apache HTTP Server
Custom logs via AMA

Content Items Using This Table (21)

Analytic Rules (10)

In solution ApacheHTTPServer:

Analytic Rule Selection Criteria
Apache - Apache 2.4.49 flaw CVE-2021-41773
Apache - Command in URI
Apache - Known malicious user agent
Apache - Multiple client errors from single IP
Apache - Multiple server errors from single IP
Apache - Private IP in URL
Apache - Put suspicious file
Apache - Request from private IP
Apache - Request to sensitive files
Apache - Requests to rare files

Hunting Queries (10)

In solution ApacheHTTPServer:

Hunting Query Selection Criteria
Apache - Rare URLs requested
Apache - Rare files requested
Apache - Rare user agents
Apache - Rare user agents with client errors
Apache - Requests to unexisting files
Apache - Top Top files requested
Apache - Top URLs with client errors
Apache - Top URLs with server errors
Apache - Top files requested with errors
Apache - Unexpected Post Requests

Workbooks (1)

In solution ApacheHTTPServer:

Workbook Selection Criteria
ApacheHTTPServer

Parsers Using This Table (3)

ASIM Parsers (1)

Parser Schema Product Selection Criteria
ASimWebSessionApacheHTTPServer WebSession Apache HTTP Server

Other Parsers (2)

Parser Solution Selection Criteria
ApacheHTTPServer ApacheHTTPServer
ApacheHTTPServer ApacheHTTPServer ⚠️

⚠️ Parsers marked with ⚠️ are not listed in their Solution JSON file.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index