crowdsec/pkg/apiserver/tests/alert_ssh-bf.json
Thibault "bui" Koechlin d8dc01cd94
Revamp unit tests (#1368)
* Revamp unit tests
* Increase coverage
* Use go-acc to get cross packages coverage

Signed-off-by: Shivam Sandbhor <shivam.sandbhor@gmail.com>
2022-03-29 14:20:26 +02:00

275 lines
6 KiB
JSON

[
{
"capacity": 5,
"decisions": null,
"events": [
{
"meta": [
{
"key": "ASNOrg",
"value": "OVH SAS"
},
{
"key": "target_user",
"value": "root"
},
{
"key": "service",
"value": "ssh"
},
{
"key": "log_type",
"value": "ssh_failed-auth"
},
{
"key": "IsoCode",
"value": "FR"
},
{
"key": "ASNNumber",
"value": "16276"
},
{
"key": "source_ip",
"value": "91.121.79.195"
},
{
"key": "IsInEU",
"value": "true"
},
{
"key": "SourceRange",
"value": "91.121.72.0/21"
}
],
"timestamp": "2020-10-02T17:09:08Z"
},
{
"meta": [
{
"key": "ASNOrg",
"value": "OVH SAS"
},
{
"key": "target_user",
"value": "root"
},
{
"key": "service",
"value": "ssh"
},
{
"key": "source_ip",
"value": "91.121.79.195"
},
{
"key": "ASNNumber",
"value": "16276"
},
{
"key": "SourceRange",
"value": "91.121.72.0/21"
},
{
"key": "log_type",
"value": "ssh_failed-auth"
},
{
"key": "IsoCode",
"value": "FR"
},
{
"key": "IsInEU",
"value": "true"
}
],
"timestamp": "2020-10-02T17:09:08Z"
},
{
"meta": [
{
"key": "service",
"value": "ssh"
},
{
"key": "log_type",
"value": "ssh_failed-auth"
},
{
"key": "IsInEU",
"value": "true"
},
{
"key": "ASNOrg",
"value": "OVH SAS"
},
{
"key": "target_user",
"value": "root"
},
{
"key": "source_ip",
"value": "91.121.79.195"
},
{
"key": "IsoCode",
"value": "FR"
},
{
"key": "ASNNumber",
"value": "16276"
},
{
"key": "SourceRange",
"value": "91.121.72.0/21"
}
],
"timestamp": "2020-10-02T17:09:08Z"
},
{
"meta": [
{
"key": "SourceRange",
"value": "91.121.72.0/21"
},
{
"key": "target_user",
"value": "root"
},
{
"key": "IsoCode",
"value": "FR"
},
{
"key": "ASNNumber",
"value": "16276"
},
{
"key": "ASNOrg",
"value": "OVH SAS"
},
{
"key": "service",
"value": "ssh"
},
{
"key": "log_type",
"value": "ssh_failed-auth"
},
{
"key": "source_ip",
"value": "91.121.79.195"
},
{
"key": "IsInEU",
"value": "true"
}
],
"timestamp": "2020-10-02T17:09:08Z"
},
{
"meta": [
{
"key": "target_user",
"value": "root"
},
{
"key": "log_type",
"value": "ssh_failed-auth"
},
{
"key": "service",
"value": "ssh"
},
{
"key": "source_ip",
"value": "91.121.79.195"
},
{
"key": "IsoCode",
"value": "FR"
},
{
"key": "IsInEU",
"value": "true"
},
{
"key": "ASNNumber",
"value": "16276"
},
{
"key": "ASNOrg",
"value": "OVH SAS"
},
{
"key": "SourceRange",
"value": "91.121.72.0/21"
}
],
"timestamp": "2020-10-02T17:09:08Z"
},
{
"meta": [
{
"key": "IsoCode",
"value": "FR"
},
{
"key": "ASNNumber",
"value": "16276"
},
{
"key": "ASNOrg",
"value": "OVH SAS"
},
{
"key": "SourceRange",
"value": "91.121.72.0/21"
},
{
"key": "target_user",
"value": "root"
},
{
"key": "service",
"value": "ssh"
},
{
"key": "log_type",
"value": "ssh_failed-auth"
},
{
"key": "source_ip",
"value": "91.121.79.195"
},
{
"key": "IsInEU",
"value": "true"
}
],
"timestamp": "2020-10-02T17:09:08Z"
}
],
"events_count": 6,
"labels": null,
"leakspeed": "10s",
"message": "Ip 91.121.79.195 performed 'crowdsecurity/ssh-bf' (6 events over 30.18165ms) at 2020-10-26 09:50:32.055535505 +0100 CET m=+6.235529150",
"remediation": true,
"scenario": "crowdsecurity/ssh-bf",
"scenario_hash": "4441dcff07020f6690d998b7101e642359ba405c2abb83565bbbdcee36de280f",
"scenario_version": "0.1",
"simulated": false,
"source": {
"as_name": "OVH SAS",
"cn": "FR",
"ip": "91.121.79.195",
"latitude": 50.646,
"longitude": 3.0758,
"range": "91.121.72.0/21",
"scope": "Ip",
"value": "91.121.79.195"
},
"start_at": "2020-10-26T09:50:32.025353849+01:00",
"stop_at": "2020-10-26T09:50:32.055534398+01:00"
}
]