Cisco Cisco Firepower Management Center 2000 Guida Dello Sviluppatore

Pagina di 726
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
469
Understanding Legacy Data Structures
Legacy Intrusion Data Structures
Appendix B
Rule Revision
uint32
Rule revision number.
Classification 
ID
uint32
Identification number of the event classification 
message.
Priority ID
uint32
Identification number of the priority associated 
with the event. 
Source IPv4 
Address
uint8[4]
Source IPv4 address used in the event, in 
address octets.
Destination 
IPv4 Address
uint8[4]
Destination IPv4 address used in the event, in 
address octets.
Source Port
uint16
The source port number if the event protocol 
type is TCP or UDP. 
Destination 
Port
uint16
The destination port number if the event protocol 
type is TCP or UDP. 
IP Protocol 
Number
uint8
IANA-specified protocol number. For example:
• 0 — IP
• 1 — ICMP
• 6 — TCP
• 17 — UDP
and so on. 
Intrusion Event (IPv4) Record Fields (Continued)
F
IELD
D
ATA
 T
YPE
D
ESCRIPTION