Mappings: Check Point SmartDefenseIPS
Input | Value |
---|---|
Vendor | Check Point |
Product | SmartDefenseIPS |
Log Format | CEF |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | CheckPoint |
Product | IPS |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | act | |
device_ip | origin | |
dstDevice_ip | dst | |
dstPort | destinationServiceName | |
file_basename | fileId | |
ipProtocol | proto | |
severity | severity | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | src | |
srcDevice_natIp | c6a1 | |
srcPort | spt | |
threat_name | reason |