Cisco Cisco Firepower Management Center 2000 Guida Dello Sviluppatore
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
469
Understanding Legacy Data Structures
Legacy Intrusion Data Structures
Appendix B
Rule Revision
uint32
Rule revision number.
Classification
ID
uint32
Identification number of the event classification
message.
Priority ID
uint32
Identification number of the priority associated
with the event.
Source IPv4
Address
uint8[4]
Source IPv4 address used in the event, in
address octets.
Destination
IPv4 Address
uint8[4]
Destination IPv4 address used in the event, in
address octets.
Source Port
uint16
The source port number if the event protocol
type is TCP or UDP.
Destination
Port
uint16
The destination port number if the event protocol
type is TCP or UDP.
IP Protocol
Number
uint8
IANA-specified protocol number. For example:
• 0 — IP
• 0 — IP
• 1 — ICMP
• 6 — TCP
• 17 — UDP
and so on.
and so on.
Intrusion Event (IPv4) Record Fields (Continued)
F
IELD
D
ATA
T
YPE
D
ESCRIPTION