↳ Source GitHubConnecteur

Corelight Connector Exporter

Description

The [Corelight](https://corelight.com/) data connector enables incident responders and threat hunters who use Microsoft Sentinel to work faster and more effectively. The data connector enables ingestion of events from [Zeek](https://zeek.org/) and [Suricata](https://suricata.io/) via Corelight Sensors into Microsoft Sentinel using the Azure Monitor Logs Ingestion API. Events are sent by the Corelight Sensor to a Data Collection Endpoint (DCE) and routed into dedicated `Corelight_v3_*_CL` tables by per-log-type Data Collection Rules (DCRs).
Statut déclaré
1
Auteur / éditeur déclaré
Corelight

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

corelight_amqpcorelight_analyzercorelight_anomalycorelight_asset_classificationcorelight_bacnetcorelight_bacnet_device_controlcorelight_bacnet_discoverycorelight_bacnet_propertycorelight_brokercorelight_bsap_ip_headercorelight_bsap_ip_rdbcorelight_bsap_ip_unknowncorelight_bsap_serial_headercorelight_bsap_serial_rdbcorelight_bsap_serial_rdb_extcorelight_bsap_serial_unknowncorelight_capture_losscorelight_cipcorelight_cip_identitycorelight_cip_iocorelight_clustercorelight_configcorelight_conncorelight_conn_aggcorelight_conn_longcorelight_conn_redcorelight_corelight_ad_admin_sharescorelight_corelight_ad_ew_servers_servicescorelight_corelight_ad_exe_filescorelight_corelight_ad_ftp_connectionscorelight_corelight_ad_http_user_agentscorelight_corelight_ad_ns_servers_servicescorelight_corelight_ad_ntlm_authcorelight_corelight_ad_rdpcorelight_corelight_ad_ssh_clientscorelight_corelight_ad_ssh_connectionscorelight_corelight_burstcorelight_corelight_license_capacitycorelight_corelight_metrics_diskcorelight_corelight_metrics_ifacecorelight_corelight_metrics_memorycorelight_corelight_metrics_systemcorelight_corelight_metrics_zeek_doctorcorelight_corelight_overall_capture_losscorelight_corelight_pipeline_testcorelight_corelight_profilingcorelight_cotpcorelight_dataredcorelight_dce_rpccorelight_dgacorelight_dhcpcorelight_dnp3corelight_dnp3_controlcorelight_dnp3_objectscorelight_dnscorelight_dns_aggcorelight_dns_redcorelight_dpdcorelight_ecat_aoe_infocorelight_ecat_arp_infocorelight_ecat_coe_infocorelight_ecat_dev_infocorelight_ecat_foe_infocorelight_ecat_log_addresscorelight_ecat_registerscorelight_ecat_soe_infocorelight_encrypted_dnscorelight_enipcorelight_enip_debugcorelight_enip_list_identitycorelight_etc_vizcorelight_filescorelight_files_aggcorelight_files_redcorelight_first_seencorelight_ftpcorelight_genacorelight_generic_dns_tunnelscorelight_generic_icmp_tunnelscorelight_genisyscorelight_httpcorelight_http2corelight_http_aggcorelight_http_redcorelight_icmp_specific_tunnelscorelight_intelcorelight_ipseccorelight_irccorelight_iso_cotpcorelight_kerberoscorelight_known_certscorelight_known_devicescorelight_known_domainscorelight_known_hostscorelight_known_namescorelight_known_remotescorelight_known_servicescorelight_known_userscorelight_ldapcorelight_ldap_searchcorelight_loaded_scriptscorelight_local_subnetscorelight_local_subnets_djcorelight_local_subnets_graphscorelight_local_subnets_neighborcorelight_log4shellcorelight_logschemacorelight_modbuscorelight_modbus_detailedcorelight_modbus_mask_write_registercorelight_modbus_read_device_identificationcorelight_modbus_read_write_multiple_registerscorelight_mqtt_connectcorelight_mqtt_publishcorelight_mqtt_subscribecorelight_mysqlcorelight_net_perfcorelight_netcontrolcorelight_netcontrol_dropcorelight_netcontrol_shuntcorelight_noticecorelight_notice_alarmcorelight_ntlmcorelight_ntpcorelight_ocspcorelight_opcua_binarycorelight_opcua_binary_activate_sessioncorelight_opcua_binary_activate_session_client_software_certcorelight_opcua_binary_activate_session_locale_idcorelight_opcua_binary_aggregate_filtercorelight_opcua_binary_browsecorelight_opcua_binary_browse_descriptioncorelight_opcua_binary_browse_request_continuation_pointcorelight_opcua_binary_browse_response_referencescorelight_opcua_binary_browse_resultcorelight_opcua_binary_close_sessioncorelight_opcua_binary_create_monitored_itemscorelight_opcua_binary_create_monitored_items_create_itemcorelight_opcua_binary_create_sessioncorelight_opcua_binary_create_session_discoverycorelight_opcua_binary_create_session_endpointscorelight_opcua_binary_create_session_user_tokencorelight_opcua_binary_create_subscriptioncorelight_opcua_binary_data_change_filtercorelight_opcua_binary_diag_info_detailcorelight_opcua_binary_event_filtercorelight_opcua_binary_event_filter_attribute_operandcorelight_opcua_binary_event_filter_attribute_operand_browse_pathscorelight_opcua_binary_event_filter_element_operandcorelight_opcua_binary_event_filter_literal_operandcorelight_opcua_binary_event_filter_select_clausecorelight_opcua_binary_event_filter_simple_attribute_operandcorelight_opcua_binary_event_filter_simple_attribute_operand_browse_pathscorelight_opcua_binary_event_filter_where_clausecorelight_opcua_binary_event_filter_where_clause_elementscorelight_opcua_binary_get_endpointscorelight_opcua_binary_get_endpoints_descriptioncorelight_opcua_binary_get_endpoints_discoverycorelight_opcua_binary_get_endpoints_locale_idcorelight_opcua_binary_get_endpoints_profile_uricorelight_opcua_binary_get_endpoints_user_tokencorelight_opcua_binary_opensecure_channelcorelight_opcua_binary_readcorelight_opcua_binary_read_nodes_to_readcorelight_opcua_binary_read_resultscorelight_opcua_binary_status_code_detailcorelight_opcua_binary_variant_array_dimscorelight_opcua_binary_variant_datacorelight_opcua_binary_variant_data_valuecorelight_opcua_binary_variant_extension_objectcorelight_opcua_binary_variant_metadatacorelight_opcua_binary_writecorelight_openflowcorelight_packet_filtercorelight_pecorelight_postgresqlcorelight_printcorelight_profinetcorelight_profinet_dce_rpccorelight_profinet_debugcorelight_quiccorelight_radiuscorelight_rdpcorelight_rediscorelight_reportercorelight_rfbcorelight_s7commcorelight_s7comm_known_devicescorelight_s7comm_pluscorelight_s7comm_read_szlcorelight_s7comm_upload_downloadcorelight_signaturescorelight_sipcorelight_smartpcapcorelight_smartpcap_statscorelight_smb_filescorelight_smb_mappingcorelight_smtpcorelight_smtp_linkscorelight_snmpcorelight_sockscorelight_softwarecorelight_specific_dns_tunnelscorelight_ssdpcorelight_sshcorelight_sslcorelight_ssl_aggcorelight_ssl_redcorelight_statscorelight_steppingcorelight_stuncorelight_stun_natcorelight_suricata_corelightcorelight_suricata_evecorelight_suricata_statscorelight_suricata_zeek_statscorelight_syslogcorelight_tdscorelight_tds_rpccorelight_tds_sql_batchcorelight_telemetrycorelight_telnetcorelight_traceroutecorelight_tunnelcorelight_unknown_smartpcapcorelight_util_statscorelight_vpncorelight_websocketcorelight_weirdcorelight_weird_aggcorelight_weird_redcorelight_weird_statscorelight_wireguardcorelight_x509corelight_x509_redcorelight_yara_corelightcorelight_yara_error_corelightcorelight_zeek_doctor

Permissions déclarées

read and write permissions are required.
Workspace
Workspace
read and write permissions to Data Collection Rules and Data Collection Endpoints are required. [See the documentation to learn more about the Logs Ingestion API](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview).
Data Collection Rules
Subscription
Microsoft Entra ID application
Permission to register an application in Microsoft Entra ID and create a client secret. Typically requires the Application Developer role or higher.
Azure role assignment
Permission to assign the **Monitoring Metrics Publisher** role on the deployed Data Collection Rules. Typically requires the Owner or User Access Administrator role on the target resource group.
Corelight Sensor access
Administrative access to the Corelight Sensor (or Fleet Manager) to configure the Microsoft Sentinel export.

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

>**NOTE:** This data connector depends on a parser based on a Kusto Function to work as expected [**Corelight**](https://aka.ms/sentinel-Corelight-parser) which is deployed with the Microsoft Sentinel Solution.
1. Deploy the Corelight data collection resources
Deploy the ARM template that creates the Data Collection Endpoint (DCE), the `Corelight_v3_*_CL` tables, and one Data Collection Rule (DCR) per Corelight log type in your workspace. Use the button below to deploy the connector resources into the same subscription and resource group as your Microsoft Sentinel workspace. [![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://aka.ms/sentinel-CorelightExporter-azuredeploy) When prompted, supply: | Parameter | Value | | --- | --- | | `workspace` | The **name** of your Log Analytics workspace (not the ID). Maximum **18 characters** -- see the note below | | `workspace-location` | The Azure region of the workspace | | `resourceId` | The full resource ID of the workspace | The deployment creates: - One Data Collection Endpoint named `dce-corelight-<workspace>` - One custom table per Corelight log type, named `Corelight_v3_<log_type>_CL` - One Data Collection Rule per log type, named `dcr-corelight-<workspace>-<log_type>`, each tagged with `corelight-log-type` > **IMPORTANT:** The workspace name must be **18 characters or fewer**. Each Data Collection Rule is named `dcr-corelight-<workspace>-<log_type>` and Azure limits resource names to 64 characters. The longest Corelight log type is 32 characters, so a longer workspace name makes some rule names exceed the limit and the deployment fails preflight validation with `'Name' must be between 1 and 64 characters`. If your workspace name is longer, deploy Microsoft Sentinel on a workspace with a shorter name. > **NOTE:** The deployment can take several minutes to complete because a large number of tables and rules are created. Wait for it to finish before continuing.
2. Register a Microsoft Entra ID application
The Corelight Sensor authenticates to the Logs Ingestion API with a Microsoft Entra ID application. Create the application and a client secret, then record the values. #### Create the application 1. In the Azure portal, go to **Microsoft Entra ID** > **App registrations** > **New registration**. 2. Enter a name, for example `Corelight Sentinel Connector`. 3. Under **Supported account types**, select **Accounts in this organizational directory only**. 4. Leave **Redirect URI** empty and select **Register**. 5. On the application **Overview** page, copy the **Application (client) ID** and the **Directory (tenant) ID**. #### Create a client secret 1. On the application page, go to **Certificates & secrets** > **Client secrets** > **New client secret**. 2. Enter a description, choose an expiry, and select **Add**. 3. Copy the secret **Value** immediately. It is shown only once and cannot be retrieved later. You now have the **Tenant ID**, **Client ID**, and **Client Secret** required by the Corelight Sensor. For more information, see [Register an application with Microsoft Entra ID](https://learn.microsoft.com/entra/identity-platform/quickstart-register-app).
3. Grant the application permission to send data
Assign the **Monitoring Metrics Publisher** role so the application can publish to the Data Collection Rules created in step 1. Assign the role once at the **resource group** scope so it covers every Corelight Data Collection Rule in a single assignment. 1. Go to the resource group that contains the deployed DCE and DCRs. 2. Select **Access control (IAM)** > **Add** > **Add role assignment**. 3. On the **Role** tab, search for and select **Monitoring Metrics Publisher**. 4. On the **Members** tab, choose **User, group, or service principal**, then select the application you registered in step 2. 5. Select **Review + assign**. > **NOTE:** Role assignments can take a few minutes to take effect. If the sensor reports authorization errors immediately after assignment, wait and retry.
4. Collect the values needed by the Corelight exporter
The Corelight exporter discovers the Data Collection Rules by tag. Collect the Data Collection Endpoint URI, the subscription ID, and confirm the DCR tag and stream name pattern. #### Data Collection Endpoint URI 1. Go to **Monitor** > **Settings** > **Data Collection Endpoints**. 2. Select `dce-corelight-<workspace>`. 3. On the **Overview** page, copy the **Logs ingestion** URI. It has the form `https://dce-corelight-<workspace>-<suffix>.<region>.ingest.monitor.azure.com`. #### Subscription ID Copy the ID of the subscription that contains the deployed Data Collection Endpoint and Data Collection Rules. 1. In the Azure portal, search for and open **Subscriptions**. 2. Select the subscription that contains the deployed resources. 3. On the **Overview** page, copy the **Subscription ID**. #### Data Collection Rule log type tag The deployment tags every Corelight Data Collection Rule with the log type it accepts. The exporter uses this tag to select the correct DCR for each log, so no immutable ID has to be entered manually. | Tag | Value | | --- | --- | | `corelight-log-type` | The Corelight log type, for example `conn`, `dns`, `http` | | `solution` | `Corelight` | To review the deployed rules and their log types in the portal, go to **Monitor** > **Settings** > **Data Collection Rules** and look for rules named `dcr-corelight-<workspace>-<log_type>`. You can also list them with the Azure CLI. Run the commands from **Azure Cloud Shell** in the portal, as described in the section below. ```bash az monitor data-collection rule list \ --resource-group <resource-group> \ --query "[?tags.solution=='Corelight'].{logType:tags.\"corelight-log-type\", name:name}" \ --output table ``` #### Running the Azure CLI commands from the Azure portal The Azure CLI commands in this connector can be run directly in the portal using Azure Cloud Shell, with no local installation required. 1. In the Azure portal, select the **Cloud Shell** icon (`>_`) in the top toolbar, or go to [https://shell.azure.com](https://shell.azure.com). 2. When prompted to choose an environment, select **Bash**. The commands below are written for Bash. 3. If this is your first time using Cloud Shell, follow the prompt to create or select a storage account. 4. Confirm you are in the correct subscription, and switch if needed: ```bash az account show --output table az account set --subscription "<subscription-name-or-id>" ``` 5. Add the Data Collection Rule commands, which ship in a CLI extension: ```bash az extension add --name monitor-control-service ``` 6. Paste the command you want to run, replacing `<resource-group>`, `<workspace>`, and `<log_type>` with your own values. > **NOTE:** The `az monitor data-collection rule` commands require the `monitor-control-service` extension. If you run them without it, Cloud Shell offers to install the extension automatically the first time. #### Stream names Each DCR declares a single stream, named after its destination table: ``` Custom-<table_name> ``` For most log types the table name follows the pattern `Corelight_v3_<log_type>_CL`. For example, the `conn` log type uses the stream `Custom-Corelight_v3_conn_CL` and lands in the table `Corelight_v3_conn_CL`. This is why the exporter **Stream Name** template is set to `Custom-Corelight_v3_$LOG_CL` in the next step. > **IMPORTANT:** A small number of log types with long names have a shortened table name, because Log Analytics limits table name length. For those log types the stream name is **not** `Custom-Corelight_v3_<log_type>_CL`, and the `$LOG` template does not resolve to the correct stream. See the list in step 5. To read the stream name directly from a rule, use the portal under **Monitor** > **Settings** > **Data Collection Rules** > select the rule > **JSON View**, or run: ```bash az monitor data-collection rule show \ --resource-group <resource-group> \ --name dcr-corelight-<workspace>-<log_type> \ --query "keys(streamDeclarations)" \ --output tsv ``` #### Data Collection Rule immutable IDs (reference only) The exporter resolves rules through the `corelight-log-type` tag, so immutable IDs are not required for configuration. If you need one for troubleshooting or for a direct Logs Ingestion API call, read it in the portal under **Monitor** > **Settings** > **Data Collection Rules** > select the rule > **JSON View** > `immutableId`, or run: ```bash az monitor data-collection rule show \ --resource-group <resource-group> \ --name dcr-corelight-<workspace>-conn \ --query immutableId \ --output tsv ```
5. Configure the Azure Sentinel exporter on the Corelight Sensor
Create an Azure Sentinel exporter on the Corelight Sensor or in Fleet Manager, using the values collected in the previous steps. The exporter is configured on the Corelight platform and is documented by Corelight.
Configure the exporter on the Corelight platform
Corelight documentation
The exporter is created and managed on the Corelight platform, using the sensor web interface or Fleet Manager. Follow Corelight's own documentation for the exporter creation steps, the supported sensor and Fleet Manager versions, enabling the dynamic exporter option, and uploading a private CA bundle if your deployment requires one: **[Corelight documentation: Azure Sentinel dynamic exporter](https://docs.corelight.cloud/sensor/export/azure-sentinel-dynamic-exporter.html)**
Before you begin
- Steps 1 to 4 of this connector are complete, and you have the Data Collection Endpoint URI, subscription ID, and application credentials. - The sensor or Fleet Manager can reach the Data Collection Endpoint over outbound HTTPS on port 443. If outbound traffic must traverse a proxy, have the proxy URL ready. - Your sensor runs a version that supports the Azure Sentinel dynamic exporter, and the dynamic exporter option is enabled. Corelight's documentation lists the required versions and the setting to enable.
Values to enter in the exporter
Enter these values when creating the Azure Sentinel exporter. Leave any setting not listed here at its Corelight default unless Corelight advises otherwise. | Corelight exporter setting | Value to use | | --- | --- | | Tenant ID | Step 2, application **Directory (tenant) ID** | | Client ID | Step 2, application **Application (client) ID** | | Client Secret | Step 2, client secret **Value** | | Subscription ID | Step 4, the subscription containing the DCE and DCRs | | Data Collection Endpoint | Step 4, the **Logs ingestion** URI | | DCR Log Type Tag | `corelight-log-type` | | Stream Name | `Custom-Corelight_v3_$LOG_CL` | > **IMPORTANT:** The exporter ships with the default stream name template `Custom-Corelight_v2_$LOG_CL`. This solution creates `v3` tables, so the template must be changed to `Custom-Corelight_v3_$LOG_CL`. Leaving the default in place sends events to streams that do not exist and the data is rejected. Use the exporter's log type filter to control which Zeek logs are exported. Enable only the log types you intend to ingest. > **NOTE:** Ingesting a large number of log types increases Microsoft Sentinel data ingestion cost. Review the [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/) page before enabling the full set.
Log types not covered by the stream name template
26 log types have a shortened table name because of the Log Analytics table name length limit, so `Custom-Corelight_v3_$LOG_CL` does not resolve to their stream. To ingest any of these, set the stream name explicitly from the value below rather than relying on the template. | Log type | Stream name | | --- | --- | | `modbus_read_device_identification` | `Custom-Corelight_v3_modbus_read_device_identificatio_CL` | | `modbus_read_write_multiple_registers` | `Custom-Corelight_v3_modbus_read_write_multiple_regis_CL` | | `opcua_binary_activate_session_client_software_cert` | `Custom-Corelight_v3_opcua_binary_activate_session_cl_CL` | | `opcua_binary_activate_session_locale_id` | `Custom-Corelight_v3_opcua_binary_activate_session_lo_CL` | | `opcua_binary_browse_request_continuation_point` | `Custom-Corelight_v3_opcua_binary_browse_request_cont_CL` | | `opcua_binary_browse_response_references` | `Custom-Corelight_v3_opcua_binary_browse_response_ref_CL` | | `opcua_binary_create_monitored_items` | `Custom-Corelight_v3_opcua_binary_cm_items_CL` | | `opcua_binary_create_monitored_items_create_item` | `Custom-Corelight_v3_opcua_binary_cm_create_item_CL` | | `opcua_binary_create_session_discovery` | `Custom-Corelight_v3_opcua_binary_create_session_disc_CL` | | `opcua_binary_create_session_endpoints` | `Custom-Corelight_v3_opcua_binary_create_session_endp_CL` | | `opcua_binary_create_session_user_token` | `Custom-Corelight_v3_opcua_binary_create_session_user_CL` | | `opcua_binary_event_filter_attribute_operand` | `Custom-Corelight_v3_opcua_binary_event_filter_attrib_CL` | | `opcua_binary_event_filter_attribute_operand_browse_paths` | `Custom-Corelight_v3_opcua_bef_attr_operand_bpaths_CL` | | `opcua_binary_event_filter_element_operand` | `Custom-Corelight_v3_opcua_binary_event_filter_elemen_CL` | | `opcua_binary_event_filter_literal_operand` | `Custom-Corelight_v3_opcua_binary_event_filter_litera_CL` | | `opcua_binary_event_filter_select_clause` | `Custom-Corelight_v3_opcua_binary_event_filter_select_CL` | | `opcua_binary_event_filter_simple_attribute_operand` | `Custom-Corelight_v3_opcua_binary_event_filter_simple_CL` | | `opcua_binary_event_filter_simple_attribute_operand_browse_paths` | `Custom-Corelight_v3_opcua_bef_smpl_attr_bpaths_CL` | | `opcua_binary_event_filter_where_clause` | `Custom-Corelight_v3_opcua_bef_where_clause_CL` | | `opcua_binary_event_filter_where_clause_elements` | `Custom-Corelight_v3_opcua_bef_where_clause_elements_CL` | | `opcua_binary_get_endpoints_description` | `Custom-Corelight_v3_opcua_binary_get_endpoints_descr_CL` | | `opcua_binary_get_endpoints_discovery` | `Custom-Corelight_v3_opcua_binary_get_endpoints_disco_CL` | | `opcua_binary_get_endpoints_locale_id` | `Custom-Corelight_v3_opcua_binary_get_endpoints_local_CL` | | `opcua_binary_get_endpoints_profile_uri` | `Custom-Corelight_v3_opcua_binary_get_endpoints_profi_CL` | | `opcua_binary_get_endpoints_user_token` | `Custom-Corelight_v3_opcua_binary_get_endpoints_user_CL` | | `opcua_binary_variant_extension_object` | `Custom-Corelight_v3_opcua_binary_variant_extension_o_CL` |
Getting help
- For questions about the exporter itself, sensor or Fleet Manager configuration, supported versions, CA bundles, or exporter errors reported by the sensor, contact your Corelight TAM or SE, or Corelight support at [info@corelight.com](mailto:info@corelight.com). - If the exporter reports success but no data reaches the workspace, the issue is usually on the Azure side. Confirm the role assignment from step 3, the Data Collection Endpoint URI, and the stream name, then continue to step 6.
6. Verify data ingestion
Confirm that events from the Corelight Sensor are arriving in your workspace. Allow 5 to 15 minutes after configuring the exporter for the first events to appear, then run the following queries in **Logs**. Check which Corelight tables are receiving data: ```kusto union withsource=TableName Corelight_v3_*_CL | summarize EventCount = count(), LastReceived = max(TimeGenerated) by TableName | sort by LastReceived desc ``` Check connection events specifically: ```kusto Corelight_v3_conn_CL | take 10 ``` Confirm connectivity: ```kusto Corelight_v3_conn_CL | summarize LastLogReceived = max(TimeGenerated) | project IsConnected = LastLogReceived > ago(30m) ``` If no data appears, check the following on the Azure side: - The **Monitoring Metrics Publisher** role assignment from step 3 exists at the resource group scope and has taken effect. Role assignments can take several minutes to propagate. - The **Data Collection Endpoint** value in the exporter matches the **Logs ingestion** URI from step 4. - The exporter **Stream Name** template is `Custom-Corelight_v3_$LOG_CL` and not the `v2` default, and any log type listed in step 5 as having a shortened stream name is configured with its explicit stream name. - The **DCR Log Type Tag** is `corelight-log-type`, and the rules for the log types you enabled exist in the resource group. If the values above are correct and the sensor still reports export errors, contact Corelight support as described in step 5.

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
CorelightConnectorExporter
Autres fichiers source 2Solutions/Corelight/Data Connectors/CorelightExporter/CorelightConnectorExporter.jsonsource ↗Solutions/Corelight/Data/Solution_Corelight.jsonsolution-membership ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.