如何使用Jolt规范遍历数组并完成指定JSON转换
Jolt转换:遍历数组生成独立JSON对象
输入JSON
{ "c2": [ "142.11.242.31:443", "192.119.110.73:443" ] }
期望输出JSON
{ "iocs": [ { "ioc": { "ioc_type": "sha256", "value": "test value" }, "metadata": { "meta": { "tags": [ "tag1", "tag2", "tag3" ] }, "source": "test", "datetime_observed": "test" } }, { "ioc": { "ioc_type": "ip", "value": "142.11.242.31:443" }, "metadata": { "meta": { "tags": [ "tag1", "tag2", "tag3" ] }, "source": "test", "datetime_observed": "test" } }, { "ioc": { "ioc_type": "ip", "value": "192.119.110.73:443" }, "metadata": { "meta": { "tags": [ "tag1", "tag2", "tag3" ] }, "source": "test", "datetime_observed": "test" } } ] }
当前使用的Jolt Spec
[ { "operation": "default", "spec": { "ioc_data": { "iocs": [ { "ioc": { "ioc_type": "sha256", "value": "test value" }, "metadata": { "meta": { "tags": [ "tag1", "tag2", "tag3" ] }, "source": "test", "datetime_observed": "date" } } ] } } }, { "operation": "shift", "spec": { "c2": "c2", "ioc_data": { "*": "&" } } } ]
解决方案
要实现遍历c2数组为每个元素生成独立对象,调整Jolt Spec即可,以下是修正后的版本:
[ // 初始化sha256类型的IOC,作为结果数组的第一个元素 { "operation": "default", "spec": { "iocs": [ { "ioc": { "ioc_type": "sha256", "value": "test value" }, "metadata": { "meta": { "tags": ["tag1", "tag2", "tag3"] }, "source": "test", "datetime_observed": "test" } } ] } }, // 遍历c2数组,为每个元素生成ip类型的IOC对象并追加到iocs数组 { "operation": "shift", "spec": { "iocs": { "*": "iocs[]" }, "c2": { "*": { "@": "iocs[#2].ioc.value", "#ip": "iocs[#2].ioc.ioc_type", "#tag1": "iocs[#2].metadata.meta.tags[0]", "#tag2": "iocs[#2].metadata.meta.tags[1]", "#tag3": "iocs[#2].metadata.meta.tags[2]", "#test": "iocs[#2].metadata.source", "#test": "iocs[#2].metadata.datetime_observed" } } } } ]
逻辑说明
- default操作:先创建
iocs数组并写入初始的sha256类型IOC对象,占据数组索引0的位置。 - shift操作:
- 保留初始的
iocs数组内容,映射到最终的iocs数组中。 - 遍历
c2数组,每个元素对应生成iocs数组的新元素:@将当前数组元素的值映射到ioc.value。#ip直接指定ioc_type为固定值ip。- 用
#符号写入metadata的固定字段值(tags、source、datetime_observed)。 #2用于确定目标数组的位置:从索引1开始,依次追加c2数组的元素对应的对象。
- 保留初始的
内容的提问来源于stack exchange,提问作者PuN1sh3r
相关产品推荐
相关产品推荐

