Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 919 Bytes

8a6aef8b-8983-4798-8539-bb86b4d7d271.md

File metadata and controls

37 lines (30 loc) · 919 Bytes

Mappings: Firepower Snort Alerts

Input Requirements

Input Value
Vendor Cisco
Product Firepower
Log Format JSON
Event ID Regex Pattern ^\d+:\d+:\d+$

Record Output

Output Value
Vendor Cisco Systems
Product Firepower
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action None The static text observed is populated in this schema field.
device_hostname srcHost
device_ip srcIP
dstDevice_ip dstIP
dstPort dstPort
ipProtocol protocol
normalizedSeverity priority This is a lookup field. More info to come in the catalog later...
severity priority
srcDevice_ip srcIP
srcPort srcPort
threat_category classification
threat_name message
threat_ruleType None The static text intrusion is populated in this schema field.