Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 758 Bytes

4d290a08-89cb-45b8-8504-954817ac4b9e.md

File metadata and controls

32 lines (25 loc) · 758 Bytes

Mappings: Cisco Meraki Flow Start_End - Custom Parser

Input Requirements

Input Value
Vendor Cisco
Product Meraki
Log Format JSON
Event ID Regex Pattern ip_flow_start|ip_flow_end

Record Output

Output Value
Vendor Cisco Systems
Product Meraki
Record Type NetworkFlow

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
dstDevice_ip dst_ip
dstDevice_natIp translated_dst_ip
dstPort dport
ipProtocol protocol
srcDevice_ip src_ip
srcDevice_natIp translated_src_ip
srcPort sport
timestamp syslog_timestamp We expect the orginal record value of syslog_timestamp is in the format epoch_float