Cisco Cisco Firepower Management Center 4000 Entwickleranleitung
4-63
FireSIGHT eStreamer Integration Guide
Chapter 4 Understanding Discovery & Connection Data Structures
Host Discovery and Connection Data Blocks
String Data Block
The String data block is used for sending string data in series 1 blocks. It commonly appears within other
series 1 data blocks to describe, for example, operating system or server names.
series 1 data blocks to describe, for example, operating system or server names.
Empty string data blocks (string data blocks containing no string data) have a block length value of
8
and are followed by zero bytes of string data. An empty string data block is returned when there is no
content for the string value, as might happen, for example, in the OS vendor string field in an Operating
System data block when the vendor of the operating system is unknown.
content for the string value, as might happen, for example, in the OS vendor string field in an Operating
System data block when the vendor of the operating system is unknown.
The String data block has a block type of 0 in the series 1 group of blocks.
140
Full Host Profile Legacy
Contains complete host profile information. See
for more
information. Supersedes data block 135.
141
IP Range
Specification
Specification
Current
Contains IP address range specifications. See
more information. It supersedes block 61.
142
Scan Results
Current
Contains information about a vulnerability and is
used within Add Scan Result events. See
used within Add Scan Result events. See
. It supersedes block
102.
143
Host IP
Current
Contains a host’s IP address and last seen
information. See
information. See
for more information.
144
Connection
Statistics
Statistics
Legacy
Contains information for connection events in 5.2.x.
See
See
for more information. It supersedes block
type 137.
146
Attribute
Address
Address
Current
Contains the host attribute address for 5.2+. See
more information. It supersedes block type 38.
140
Full Host Profile Current
Contains complete host profile information. See
for more
information. Supersedes data block 135.
152
Connection
Statistics
Statistics
Legacy
Contains information for connection events in 5.3+.
See
See
for more information. It supersedes
block type 144.
154
Connection
Statistics
Statistics
Current
Contains information for connection events in 5.3+.
See
See
for more information. It supersedes
block type 152.
Table 4-27
Host Discovery and Connection Data Block Types (continued)
Type
Content
Data Block Status
Description