Cisco Cisco Firepower Management Center 4000 Guia Do Programador

Página de 536
 
3-7
FireSIGHT eStreamer Integration Guide
 
Chapter 3      Understanding Intrusion and Correlation Data Structures
  Intrusion Event and Metadata Record Types
Source IP Address
Source IP Address, continued
Source IP Address, continued
Source IP Address, continued
Destination IP Address
Destination IP Address, continued
Destination IP Address, continued
Destination IP Address, continued
Source Port or ICMP Type
Destination Port or ICMP Code
IP Protocol ID
Impact Flags
Impact
Blocked
MPLS Label
VLAN ID
Pad
Policy UUID
Policy UUID, continued
Policy UUID, continued
Policy UUID, continued
User ID
Web Application ID
Client Application ID
Application Protocol ID
Access Control Rule ID
Access Control Policy UUID
Access Control Policy UUID, continued
Access Control Policy UUID, continued
Access Control Policy UUID, continued
Interface Ingress UUID
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31