Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 904 Bytes

9cd7d33e-bc90-4b12-8bc6-1c5da6e753aa.md

File metadata and controls

35 lines (28 loc) · 904 Bytes

Mappings: Cisco Meraki Firewall - Custom Parser

Input Requirements

Input Value
Vendor Cisco
Product Meraki
Log Format JSON
Event ID Regex Pattern firewall

Record Output

Output Value
Vendor Cisco Systems
Product Meraki
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action verdict
device_hostname syslog_device_name
dstDevice_ip dst
dstPort dport
ipProtocol protocol
normalizedAction verdict This is a lookup field. More info to come in the catalog later...
srcDevice_ip src
srcDevice_mac mac
srcPort sport
success verdict This is a lookup field. More info to come in the catalog later...
timestamp syslog_timestamp We expect the orginal record value of syslog_timestamp is in the format epoch_float