Mappings: Cisco StealthWatch
Input | Value |
---|---|
Vendor | Lancope |
Product | Stealthwatch |
Log Format | LEEF |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | Cisco Systems |
Product | Stealthwatch |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
description | fullmessage | |
dstDevice_hostname | targetHostname | |
dstDevice_ip | dst | |
dstPort | dstPort | |
ipProtocol | proto | |
severity | alarmSev | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | src | |
threat_referenceUrl | sourceHostSnapshot | |
timestamp | start | We expect the orginal record value of start is in the format yyyy-MM-dd'T'HH:mm:ssZ |