Mappings: Cisco Firepower CEF unknown ips-event
Input | Value |
---|---|
Vendor | Cisco |
Product | Firepower |
Log Format | CEF |
Event ID Regex Pattern | unknown |
Output | Value |
---|---|
Vendor | Cisco Systems |
Product | Firepower |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
dstDevice_ip | dst | |
dstPort | dpt | |
ipProtocol | proto | |
severity | cs4 | |
srcDevice_ip | src | |
srcPort | spt | |
threat_name | msg | |
timestamp | deviceCustomDate1 | We expect the orginal record value of deviceCustomDate1 is in the format EEE MMM dd HH:mm:ss yyyy zzz |