Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 1.06 KB

1c55b073-ace7-4aa3-a260-c0d922beceee.md

File metadata and controls

36 lines (29 loc) · 1.06 KB

Mappings: Cisco Meraki IDS Alerted

Input Requirements

Legacy Parser Grok Patterns
CISCO_MERAKI_SECURITY_EVENT_IDS_ALERTED

Record Output

Output Value
Vendor Cisco Systems
Product Meraki
Record Type Notification

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action decision
device_hostname device_name
device_mac dmac
dstDevice_ip dst_ip
dstPort dport
ipProtocol protocol
normalizedSeverity severity This is a lookup field. More info to come in the catalog later...
severity priority
srcDevice_ip src_ip
srcPort sport
success decision This is a lookup field. More info to come in the catalog later...
threat_identifier signature
threat_name message
threat_ruleType None The static text intrusion is populated in this schema field.
timestamp timestamp We expect the orginal record value of timestamp is in the format epoch_float