Mappings: Cisco Meraki IDS Alerted
Legacy Parser Grok Patterns |
---|
CISCO_MERAKI_SECURITY_EVENT_IDS_ALERTED |
Output | Value |
---|---|
Vendor | Cisco Systems |
Product | Meraki |
Record Type | Notification |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | decision | |
device_hostname | device_name | |
device_mac | dmac | |
dstDevice_ip | dst_ip | |
dstPort | dport | |
ipProtocol | protocol | |
normalizedSeverity | severity | This is a lookup field. More info to come in the catalog later... |
severity | priority | |
srcDevice_ip | src_ip | |
srcPort | sport | |
success | decision | This is a lookup field. More info to come in the catalog later... |
threat_identifier | signature | |
threat_name | message | |
threat_ruleType | None | The static text intrusion is populated in this schema field. |
timestamp | timestamp | We expect the orginal record value of timestamp is in the format epoch_float |