Cisco Cisco Firepower Management Center 4000 Guia Do Programador
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
117
Understanding Intrusion and Correlation Data Structures
Understanding Series 2 Data Blocks
Chapter 3
table below, the Data Block Status field indicates
whether the block is current (the latest version) or legacy (used in an older version
and can still be requested through eStreamer).
.
Series 2 Block Types
T
YPE
C
ONTENT
D
ATA
B
LOCK
S
TATUS
D
ESCRIPTION
0
String
Current
Encapsulates variable string data.
See
for more information.
1
BLOB
Current
Encapsulates binary data and is used
specifically for banners. See
on page 122 for more
information.
2
List
Current
Encapsulates a list of other data
blocks. See
page 123 for more information.
3
Generic List
Current
Encapsulates a list of other data
blocks. For deserialization, it is the
equivalent of the List data block. See
for more information.
4
Event Extra
Data
Current
Contains intrusion event extra data.
See
on page 89 for more
information.
5
Extra Data Type
Current
Contains extra data metadata. See
on page 91 for more information.
14
UUID String
Mapping
Current
Block used by various metadata
messages to map UUID values to
descriptive strings. See
15
Access Control
Policy Rule ID
Metadata
Current
Contains metadata for access
control rules. See