Cisco Cisco Firepower Management Center 2000 Entwickleranleitung
4-56
FireSIGHT eStreamer Integration Guide
Chapter 4 Understanding Discovery & Connection Data Structures
Host Discovery and Connection Data Blocks
Series 1 Primitive Data Blocks
Both series 1 and series 2 blocks include a set of primitives that encapsulate lists of variable-length
blocks as well as variable-length strings and BLOBs within messages. These primitive blocks have the
standard series 1 block header discussed above. These primitives appear only within other series 1 data
blocks. Any number can be included in a given block type. For details on the structure of the primitive
blocks, see the following:
blocks as well as variable-length strings and BLOBs within messages. These primitive blocks have the
standard series 1 block header discussed above. These primitives appear only within other series 1 data
blocks. Any number can be included in a given block type. For details on the structure of the primitive
blocks, see the following:
•
•
•
•
Host Discovery and Connection Data Blocks
For the list of block types in host discovery and connection events, see
. The
block types in user events are described in
. These are all Series 1 data blocks.
Each entry in the table below contains a link to the subsection where the data block is defined. For each
block type, the status (current or legacy) is indicated. A current data block is the latest version. A legacy
data block is one that is used for an older version of the product, and the message format can still be
requested from eStreamer.
block type, the status (current or legacy) is indicated. A current data block is the latest version. A legacy
data block is one that is used for an older version of the product, and the message format can still be
requested from eStreamer.
Table 4-27
Host Discovery and Connection Data Block Types
Type
Content
Data Block Status
Description
0
String
Current
Contains string data. See
for more information.
1
Sub-Server
Current
Contains information about a sub-server detected on
a server. See
a server. See
for
more information.
4
Protocol
Current
Contains protocol data. See
for more information.
7
Integer Data
Current
Contains integer (numeric) data. See
for more
information.
8
Vulnerability
Current
Contains vulnerability data. See
for more
information.
10
BLOB
Current
Contains a raw block of binary data and is used
specifically for banners. See
specifically for banners. See
for more information.
11
List
Current
Contains a list of other data blocks. See
for more information.
14
VLAN
Current
Contains VLAN information. See
for more information.