Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 1.12 KB

ee6f31c0-b462-44ae-9eb5-4318ba441025.md

File metadata and controls

36 lines (29 loc) · 1.12 KB

Mappings: Cisco Meraki IDS Alert - C2C

Input Requirements

Input Value
Vendor Cisco
Product Meraki
Log Format JSON
Event ID Regex Pattern IDS Alert

Record Output

Output Value
Vendor Cisco Systems
Product Meraki
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description message
dstDevice_ip destIp This is a split field. More info to come in the catalog later...
dstPort destIp This is a split field. More info to come in the catalog later...
ipProtocol protocol
normalizedAction blocked This is a lookup field. More info to come in the catalog later...
normalizedSeverity priority This is a lookup field. More info to come in the catalog later...
severity priority
srcDevice_ip srcIp This is a split field. More info to come in the catalog later...
srcPort srcIp This is a split field. More info to come in the catalog later...
success blocked
threat_name message
threat_ruleType None The static text intrusion is populated in this schema field.