Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 734 Bytes

d6c9771e-aa44-4ffc-8688-72307bbff04y.md

File metadata and controls

35 lines (28 loc) · 734 Bytes

Mappings: Check Point SmartDefenseIPS

Input Requirements

Input Value
Vendor Check Point
Product SmartDefenseIPS
Log Format CEF
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor CheckPoint
Product IPS
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action act
device_ip origin
dstDevice_ip dst
dstPort destinationServiceName
file_basename fileId
ipProtocol proto
severity severity This is a lookup field. More info to come in the catalog later...
srcDevice_ip src
srcDevice_natIp c6a1
srcPort spt
threat_name reason