Cisco Cisco Firepower Management Center 2000 Entwickleranleitung

Seite von 536
C H A P T E R
 
5-1
FireSIGHT eStreamer Integration Guide
 
5
Understanding Host Data Structures
This chapter describes the format of the Full Host Profile data block that conveys a set of data describing 
a single host. The eStreamer server generates and sends these blocks on request for host data. For 
information about the client request procedure, the message structure, and the delivery method, see 
.
eStreamer uses the series 1 data block structure to package these Full Host profile blocks. For the general 
structure of series 1 blocks, see 
. The Full Host Profile data block 
contains a number of encapsulated blocks which are individually described in the subsections where they 
are defined in 
.
See the following sections for more information about current and legacy Full Host Profile data blocks:
  •
 describes the current Full Host Profile data block 
structure.
  •
 describes the legacy Full Host Profile data 
block structure for versions 5.0 - 5.0.2.
Full Host Profile Data Block 5.3+
The Full Host Profile data block for version 5.3+ contains a full set of data describing one host. It has 
the format shown in the graphic below and explained in the following table. Note that, except for List 
data blocks, the graphic does not show the fields of the encapsulated data blocks. These encapsulated 
data blocks are described separately in 
. The Full Host Profile data block a block type value of 149. It supersedes the prior version, 
which has a block type of 140.
Note
An asterisk (*) next to a block name in the following diagram indicates that multiple instances of the 
data block may occur.