Cisco Cisco Firepower Management Center 4000 Entwickleranleitung

Seite von 536
 
4-63
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures
  Host Discovery and Connection Data Blocks
String Data Block
The String data block is used for sending string data in series 1 blocks. It commonly appears within other 
series 1 data blocks to describe, for example, operating system or server names. 
Empty string data blocks (string data blocks containing no string data) have a block length value of 
8
 
and are followed by zero bytes of string data. An empty string data block is returned when there is no 
content for the string value, as might happen, for example, in the OS vendor string field in an Operating 
System data block when the vendor of the operating system is unknown.
The String data block has a block type of 0 in the series 1 group of blocks.
140
Full  Host  Profile Legacy
Contains complete host profile information. See 
 for more 
information. Supersedes data block 135.
141
IP Range 
Specification
Current
Contains IP address range specifications. See 
more information. It supersedes block 61.
142
Scan Results
Current
Contains information about a vulnerability and is 
used within Add Scan Result events. See 
. It supersedes block 
102.
143
Host IP
Current
Contains a host’s IP address and last seen 
information. See 
 for more information.
144
Connection 
Statistics
Legacy
Contains information for connection events in 5.2.x. 
See 
 for more information. It supersedes block 
type 137.
146
Attribute 
Address
Current
Contains the host attribute address for 5.2+. See 
more information. It supersedes block type 38.
140
Full  Host  Profile Current
Contains complete host profile information. See 
 for more 
information. Supersedes data block 135.
152
Connection 
Statistics
Legacy
Contains information for connection events in 5.3+. 
See 
 for more information. It supersedes 
block type 144.
154
Connection 
Statistics
Current
Contains information for connection events in 5.3+. 
See 
 for more information. It supersedes 
block type 152.
Table 4-27
Host Discovery and Connection Data Block Types (continued)
Type
 Content
Data Block Status
Description