Cisco Cisco Firepower Management Center 4000 Guia Do Programador

Página de 536
 
B-7
FireSIGHT eStreamer Integration Guide
 
Appendix B      Understanding Legacy Data Structures
  Legacy Intrusion Data Structures
Byt
e
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Header Version (1)
Message Type (4)
Message Length
Record Type (208)
Record Length
eStreamer Server Timestamp (in events, only if bit 23 is set)
Reserved for Future Use (in events, only if bit 23 is set)
 Device ID
Event ID
Event Second
Event Microsecond
Rule ID (Signature ID)
Generator ID
Rule Revision
Classification ID
Priority ID
Source IPv6 Address
Source IPv6 Address, continued
Source IPv6 Address, continued
Source IPv6 Address, continued
Destination IPv6 Address
Destination IPv6 Address, continued
Destination IPv6 Address, continued
Destination IPv6 Address, continued
Source Port/ICMP Type
Destination Port/ICMP Code
IP Protocol ID
Impact Flags
Impact
Blocked