Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 747 Bytes

c1f966d9-4a30-4e67-a5ba-9630545f757f.md

File metadata and controls

30 lines (23 loc) · 747 Bytes

Mappings: Cisco Meraki Security Filtering Disposition Change - Custom Parser

Input Requirements

Input Value
Vendor Cisco
Product Meraki
Log Format JSON
Event ID Regex Pattern security_filtering_disposition_change

Record Output

Output Value
Vendor Cisco Systems
Product Meraki
Record Type Notification

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
device_hostname syslog_device_name
file_basename name
file_hash_sha256 sha256
threat_name disposition
timestamp syslog_timestamp We expect the orginal record value of syslog_timestamp is in the format epoch_float