Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 809 Bytes

5fe30e9a-1b2c-11e9-ab14-d663bd873d93.md

File metadata and controls

33 lines (26 loc) · 809 Bytes

Mappings: Cisco StealthWatch

Input Requirements

Input Value
Vendor Lancope
Product Stealthwatch
Log Format LEEF
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Cisco Systems
Product Stealthwatch
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description fullmessage
dstDevice_hostname targetHostname
dstDevice_ip dst
dstPort dstPort
ipProtocol proto
severity alarmSev This is a lookup field. More info to come in the catalog later...
srcDevice_ip src
threat_referenceUrl sourceHostSnapshot
timestamp start We expect the orginal record value of start is in the format yyyy-MM-dd'T'HH:mm:ssZ