Cisco Cisco Firepower Management Center 2000 Entwickleranleitung

Seite von 536
 
4-115
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures
  Host Discovery and Connection Data Blocks
Client 
App V
ersion
String Block Type (0)
String Block Length
Client Application Version...
Monitor Rule 1
Monitor Rule 2
Monitor Rule 3
Monitor Rule 4
Monitor Rule 5
Monitor Rule 6
Monitor Rule 7
Monitor Rule 8
Sec. Int. Src/Dst
Sec. Int. Layer
File Event Count
Intrusion Event Count
Initiator Country
Responder Country
IOC Number
Source Autonomous System
Destination Autonomous System
SNMP In
SNMP Out
Source TOS
Destination TOS
Source Mask
Destination Mask
Security Context
Security Context, continued
Security Context, continued
Security Context, continued
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31