Cisco Cisco Firepower Management Center 2000 Entwickleranleitung

Seite von 536
 
3-55
FireSIGHT eStreamer Integration Guide
 
Chapter 3      Understanding Intrusion and Correlation Data Structures
  Understanding Series 2 Data Blocks
The following table describes the fields in the ICMP Code data block.
Access Control Policy Rule Reason Data Block
The eStreamer service uses the Access Control Rule Policy Rule Reason Data block to contain 
information about access control policy rule IDs. This data block has a block type of 21 in series 2.
The following diagram shows the structure of the Access Control Policy Rule ID metadata block.
Table 3-34
ICMP Code Data Block Fields 
Field
Data Type
Description
ICMP Code Data 
Block Type
uint32
Initiates a ICMP Code data block. This value is always 
20
.
ICMP Code Data 
Block Length
uint32
Total number of bytes in the ICMP Code data block, including eight 
bytes for the ICMP Code data block type and length fields, plus the 
number of bytes of data that follows. 
Code
uint16
The ICMP code of the event.
Type
uint16
The ICMP type of the event.
Protocol
uint16
IANA-specified protocol number. For example:
  •
0
 - IP
  •
1
 - ICMP
  •
6
 - TCP
  •
17
 - UDP
String Block Type
uint32
Initiates a String data block containing the description of the ICMP 
code. This value is always 
0
.
String Block 
Length
uint32
The number of bytes included in the name String data block, 
including eight bytes for the block type and header fields plus the 
number of bytes in the Description field.
Description
string
Description of the ICMP code for the event.
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Access Control Policy Rule Reason Data Block Type (21)
Access Control Policy Rule Reason Data Block Length
Description
Reason
String Block Type (0)
String Block Type (0), continued
String Block Length
String Block Length, continued
Description...