Skip to content

Latest commit

 

History

History
40 lines (33 loc) · 1.01 KB

256df1c8-7090-4499-a46e-289f7ee8a5f7.md

File metadata and controls

40 lines (33 loc) · 1.01 KB

Mappings: FireEye CMS DM

Input Requirements

Input Value
Vendor FireEye
Product CMS
Log Format CEF
Event ID Regex Pattern DM

Record Output

Output Value
Vendor FireEye
Product Central Management System
Record Type NetworkDNS

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description None The static text CMS Domain Match is populated in this schema field.
device_ip src
dns_queryDomain cs5
dstDevice_ip dst
dstDevice_mac dmac
ipProtocol proto
normalizedSeverity None The static text 3 is populated in this schema field.
srcDevice_hostname shost
srcDevice_ip src
srcDevice_mac smac
srcPort spt
threat_name sname
threat_referenceUrl cs4
threat_ruleType None The static text direct is populated in this schema field.
threat_signalName sname
timestamp rt We expect the orginal record value of rt is in the format MMM dd yyyy HH:mm:ss zzz