Skip to content

Latest commit

 

History

History
38 lines (31 loc) · 883 Bytes

82de581f-dd41-4acd-b62e-e3a8a33c0e72.md

File metadata and controls

38 lines (31 loc) · 883 Bytes

Mappings: Firepower File Malware Events

Input Requirements

Input Value
Vendor Cisco
Product Firepower
Log Format JSON
Event ID Regex Pattern ^430005$

Record Output

Output Value
Vendor Cisco Systems
Product Firepower
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action FileAction
device_ip SrcIP
dstDevice_ip DstIP
dstPort DstPort
file_hash_sha256 FileSHA256
file_size FileSize
ipProtocol Protocol
normalizedSeverity Priority This is a lookup field. More info to come in the catalog later...
severity Priority
srcDevice_ip SrcIP
srcPort SrcPort
threat_name ThreatName
threat_ruleType None The static text intrusion is populated in this schema field.
user_username User