Cisco Cisco Firepower Management Center 2000 Entwickleranleitung

Seite von 536
 
4-56
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures 
  Host Discovery and Connection Data Blocks
Series 1 Primitive Data Blocks
Both series 1 and series 2 blocks include a set of primitives that encapsulate lists of variable-length 
blocks as well as variable-length strings and BLOBs within messages. These primitive blocks have the 
standard series 1 block header discussed above. These primitives appear only within other series 1 data 
blocks. Any number can be included in a given block type. For details on the structure of the primitive 
blocks, see the following:
  •
  •
  •
  •
Host Discovery and Connection Data Blocks
For the list of block types in host discovery and connection events, see 
. The 
block types in user events are described in 
. These are all Series 1 data blocks. 
Each entry in the table below contains a link to the subsection where the data block is defined. For each 
block type, the status (current or legacy) is indicated. A current data block is the latest version. A legacy 
data block is one that is used for an older version of the product, and the message format can still be 
requested from eStreamer. 
Table 4-27
Host Discovery and Connection Data Block Types 
Type
 Content
Data Block Status
Description
0
String
Current
Contains string data. See 
 for more information.
1
Sub-Server
Current
Contains information about a sub-server detected on 
a server. See 
 for 
more information.
4
Protocol
Current
Contains protocol data. See 
 for more information.
7
Integer Data
Current
Contains integer (numeric) data. See 
 for more 
information.
8
Vulnerability
Current
Contains vulnerability data. See 
 for more 
information.
10
BLOB
Current
Contains a raw block of binary data and is used 
specifically for banners. See 
 for more information.
11
List
Current
Contains a list of other data blocks. See 
 for more information.
14
VLAN
Current
Contains VLAN information. See 
 for more information.