Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 857 Bytes

34fd7e6c-85ef-421c-ab4f-84f9a31b835b.md

File metadata and controls

35 lines (28 loc) · 857 Bytes

Mappings: Firepower Primary Detection Engine Intrusion Events

Input Requirements

Input Value
Vendor Cisco
Product Firepower
Log Format JSON
Event ID Regex Pattern Primary\ Detection Engine

Record Output

Output Value
Vendor Cisco Systems
Product Firepower
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_ip SrcIP
dstDevice_ip DstIP
dstPort DstPort
ipProtocol Protocol
normalizedSeverity Priority This is a lookup field. More info to come in the catalog later...
severity Priority
srcDevice_ip SrcIP
srcPort SrcPort
threat_category Classification
threat_name Message
threat_ruleType None The static text intrusion is populated in this schema field.