
下午好,我是OSIM助手,
我可以帮你把字段统一成 OSIM 标准格式(支持SQL、SPL、ESQL等格式),请提供你的字段信息,
并试试看这样提问:
我可以帮你把现有日志中不合理的内容进行映射并优化,解决业务字段不规范问题,请提供你的日志信息
帮我做好字段映射,时间戳转换成标准 ISO 格式,另外"queryStatus"不变,并把queryStatus的0/1转换成success/fail:{{DATA}}
{
"startTime": 1776391206029,
"queryStatus": "1",
"deviceReceiptTime": "1776391206000",
"machineCode": "EE4C882EAF4F4CD39126385A78367CAD",
"netId": "7effcbb7-0c7a-4da9-bde1-32d06166acae",
"dataType": "traffic",
"transProtocol": "TCP",
"deviceSendProductName": "ASICSAM",
"name": "ENIP通信",
"logSessionId": "1213085933437085",
"destGeoRegion": "局域网",
"catOutcome": "Attempt",
"logType": "enip",
"commandType": "Send Unit Data",
"collectorReceiptTime": "2026-04-17 10:00:06",
"appProtocol": "enip",
"dataSubType": "enipTraffic",
"destSecurityZone": "inner_886da035-c033-46b8-8ce8-b31e03db7ab2_1537173568979",
"destMacAddress": "00-0C-29-09-13-9A",
"baas_src_asset_uptime": 1776391206000,
"destPort": "44818",
"destGeoCountry": "局域网",
"deviceProductType": "入侵检测系统",
"destHostAssetId": "asset_397b97b0-2c0d-44e9-8015-e67d33c43706_1776045049869",
"startTime": "2026-04-17 10:00:06",
"interfaceName": "enp4s0",
"direction": "00",
"severity": "1",
"destOrgId": "7effcbb7-0c7a-4da9-bde1-32d06166acae",
"srcSecurityZone": "inner_886da035-c033-46b8-8ce8-b31e03db7ab2_1537173568979",
"deviceVersion": "V3.0R25C03SPC158",
"@timestamp": "2026-04-17T02:00:06.000Z",
"baas_engineInfo": "info:172.24.0.94,flink-ailpha-etl-taskmanager-1-1",
"endTime": "2026-04-17 10:00:06",
"srcMacAddress": "00-0C-29-DF-7C-B8",
"srcGeoRegion": "局域网"
}{{/DATA}}
或点击下方 推荐案例,生成同款场景对话


推荐案例

