Cisco Cisco Firepower Management Center 4000 Guía Del Desarrollador

Descargar
Página de 536
 
B-70
FireSIGHT eStreamer Integration Guide
 
Appendix B      Understanding Legacy Data Structures 
  Legacy Discovery Data Structures
Legacy Host Profile Data Blocks
See the following section for more information:
  •
Host Profile Data Block for 5.0 - 5.0.2
The following diagram shows the format of a Host Profile data block in versions 5.0 to 5.0.2. The Host 
Profile data block also does not include a host criticality value, but does include a VLAN presence 
indicator. In addition, a Host Profile data block can convey a NetBIOS name for the host. This Host 
Profile data block has a block type of 91.
Note
An asterisk(*) next to a block type field in the following diagram indicates the message may contain zero 
or more instances of the series 1 data block.
Username
string
The user name for the user.
User ID
uint32
Identification number of the user.
Application  ID
uint32
The application ID for the application protocol used in the connection 
that the login information was derived from.
String Block 
Type
uint32
Initiates a String data block containing the email address for the user. 
This value is always 
0
.
String Block 
Length
uint32
Number of bytes in the email address String data block, including 
eight bytes for the block type and length fields, plus the number of 
bytes in the email address.
Email
string
The email address for the user.
Table B-16
User Login Information Data Block Fields 5.0 - 5.0.2 (continued)
Field
Data Type
Description
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Host Profile Block Type (91)
Host Profile Block Length
IP Address
Server 
Fingerprints
Hops
Primary/Secondary
Generic List Block Type (31)
Generic List Block Type, continued
Generic List Block Length
Generic List Block Length, continued
Server Fingerprint Data Blocks*