Tomcat_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (6 columns)

Source: KQL validation test schema

Column Name Type
_ResourceId string
_SubscriptionId string
Computer string
RawData string
TimeGenerated datetime
Type string

Solutions (3)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
[Deprecated] Apache Tomcat
Custom logs via AMA

Content Items Using This Table (23)

Analytic Rules (10)

In solution Tomcat:

Analytic Rule Selection Criteria
Tomcat - Commands in URI
Tomcat - Known malicious user agent
Tomcat - Multiple client errors from single IP address
Tomcat - Multiple empty requests from same IP
Tomcat - Multiple server errors from single IP address
Tomcat - Put file and get file from same IP address
Tomcat - Request from localhost IP address
Tomcat - Request to sensitive files
Tomcat - Server errors after multiple requests from same IP
Tomcat - Sql injection patterns

Hunting Queries (11)

In solution Tomcat:

Hunting Query Selection Criteria
Tomcat - Abnormal request size
Tomcat - Catalina errors
Tomcat - Rare URLs requested
Tomcat - Rare files requested
Tomcat - Rare user agents with client errors
Tomcat - Rare user agents with server errors
Tomcat - Request to forbidden file
Tomcat - Top URLs client errors
Tomcat - Top URLs server errors
Tomcat - Top files with error requests
Tomcat - Uncommon user agent strings

Workbooks (2)

In solution OracleWebLogicServer:

Workbook Selection Criteria
OracleWorkbook

In solution Tomcat:

Workbook Selection Criteria
Tomcat

Parsers Using This Table (2)

Other Parsers (2)

Parser Solution Selection Criteria
TomcatEvent Tomcat
TomcatEvent Tomcat ⚠️

⚠️ Parsers marked with ⚠️ are not listed in their Solution JSON file.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index