Cisco Cisco Firepower Management Center 2000 Entwickleranleitung

Seite von 536
 
4-53
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures
  Metadata for Discovery Events
New Operating System Messages
The New OS event message has a standard discovery event header (as documented in 
) followed by an Operating System Fingerprint data block (as documented in 
This event uses the following format:
Identity Conflict and Identity Timeout System Messages
The Identity Conflict and Identity Timeout event messages each have a standard discovery event header 
(as documented in 
) followed by an Identity data block (as 
documented in 
). The Identity data block is block type 94 in series 1. 
These messages are generated when there are conflicts or timeouts in a fingerprint source identity. 
This event uses the following format:
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Discovery Event Header
Operating System Fingerprint Data Block
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Discovery Event Header
Identity Data Block