Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 860 Bytes

69d9ee44-29fc-497a-85d5-aed507a923db.md

File metadata and controls

37 lines (30 loc) · 860 Bytes

Mappings: Firepower Intrusion Events

Input Requirements

Input Value
Vendor Cisco
Product Firepower
Log Format JSON
Event ID Regex Pattern ^430001$

Record Output

Output Value
Vendor Cisco Systems
Product Firepower
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action InlineResult
device_ip SrcIP
dstDevice_ip DstIP
dstPort DstPort
ipProtocol Protocol
normalizedSeverity Priority This is a lookup field. More info to come in the catalog later...
severity Priority
srcDevice_ip SrcIP
srcPort SrcPort
threat_category Classification
threat_name Message
threat_ruleType None The static text intrusion is populated in this schema field.
user_username User