Cisco Cisco Firepower Management Center 4000 Entwickleranleitung

Seite von 180
 
6-39
FireSIGHT System Database Access Guide
 
Chapter 6      Schema: Discovery Event and Network Map Tables
  rna_host_service_info
rna_host_service_info
The 
rna_host_service_info
 table contains detailed information about the servers detected on the hosts 
in your monitored network.
For more information, see the following sections:
  •
  •
  •
rna_host_service_info Fields
The following table describes the fields you can access in the 
rna_host_service_info
 table.
.
Table 6-36
rna_host_service_info Fields 
Field
Description
application_id
Field deprecated in Version 5.0. Returns blank for all queries.
application_protocol_id
An internal identifier for the detected application protocol, if available.
application_protocol_name
One of:
  •
the name of the application protocol, if a positive identification can be made
  •
pending
 if the system requires more data
  •
blank if there is no application information in the connection
business_relevance
An index (from 
1
 to 
5
) of the application’s relevance to business productivity where 
1
 is very low and 
5
 is very high.
business_relevance_
 
description
A description of business relevance (
very low
low
medium
high
very high
).
created_sec
The UNIX timestamp of the date and time the system first detected the application 
protocol.
host_id
ID number of the host.
ip_address
Field deprecated in Version 5.2. Returns 
null
 for all queries.
last_used_sec
The UNIX timestamp of the date and time the system last detected server activity.
port
The port used by the server.
protocol
The traffic protocol: 
TCP
 or 
UDP
.
risk
An index (from 
1
 to 
5
) of the application’s risk where 
1
 is very low risk and 
5
 is very 
high risk.
risk_description
A description of the risk (
very low
low
medium
high
very high
).
service_info_id
An internal identification number for the server.
service_name
Field deprecated in Version 5.0. Returns 
null
 for all queries.