Cisco Cisco Firepower Management Center 4000 Entwickleranleitung

Seite von 536
 
4-105
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures
  Host Discovery and Connection Data Blocks
User Protocol List Data Block 4.7+
The User Protocol List data block is used to contain information about the source of the protocol data, 
the identification number for the user who added the data, and the lists of user protocol data blocks. The 
User Protocol List data block has a block type of 83 in the series 1 group of blocks. For more information 
on User Protocol data blocks, see 
.
The User Protocol List data block is used in user protocol messages, as documented in 
.
The following diagram shows the basic structure of a User Protocol List data block:
Source ID
uint32
Identification number that maps to the source that added or 
updated the attribute data. Depending on the source type, this may 
map to RNA, a user, a scanner, or a third-party application.
Source Type
uint32
Number that maps to the type of data source: 
  •
0
 if the user attribute value was provided by RNA 
  •
1
 if the user attribute value was provided by a user
  •
2
 if the user attribute value was provided by a third-party 
scanner
  •
3
 if the user attribute value was provided by a command line 
tool such as 
nmimport.pl
 or the Host Input API client
Attribute ID
uint32
Identification number of the updated attribute. 
BLOB Block Type
uint32
Initiates a BLOB data block. This value is always 
10
.
BLOB Block Length uint32
Number of bytes in the BLOB data block, including eight bytes 
for the BLOB block type and length fields, plus the length of the 
binary data that follows.
Value
variable
Contains the user attribute value, in binary format. 
Table 4-61
User Attribute Value Data Block Fields (continued)
Field
Number of 
Bytes
Description
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
User Protocol List Block Type (83)
User Protocol List Block Length
Source Type
Source ID