Mappings: Cisco Meraki IDS Alert - C2C
Input | Value |
---|---|
Vendor | Cisco |
Product | Meraki |
Log Format | JSON |
Event ID Regex Pattern | IDS Alert |
Output | Value |
---|---|
Vendor | Cisco Systems |
Product | Meraki |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
description | message | |
dstDevice_ip | destIp | This is a split field. More info to come in the catalog later... |
dstPort | destIp | This is a split field. More info to come in the catalog later... |
ipProtocol | protocol | |
normalizedAction | blocked | This is a lookup field. More info to come in the catalog later... |
normalizedSeverity | priority | This is a lookup field. More info to come in the catalog later... |
severity | priority | |
srcDevice_ip | srcIp | This is a split field. More info to come in the catalog later... |
srcPort | srcIp | This is a split field. More info to come in the catalog later... |
success | blocked | |
threat_name | message | |
threat_ruleType | None | The static text intrusion is populated in this schema field. |