cisco firepower
October 17, 2024 · View on GitHub
Expression
product = cisco firepower
Fields
| Field | Core | Detection | Informational |
|---|---|---|---|
| src_ip | ✓ | ||
| fallback_user_name | |||
| user | ✓ |
Activity Types
| Activity Type | Field | Status | Core | Detection | Informational |
|---|---|---|---|---|---|
| alert-trigger | classification_name | ||||
| malware_file_name | |||||
| block_type | |||||
| bytes_in | |||||
| rule | |||||
| result | |||||
| src_ip | Legacy | ✓ | ✓ | ||
| egress_security_zone | |||||
| protocol | Legacy | ✓ | |||
| blocked | |||||
| ip_protocl_id | |||||
| file_type | |||||
| process_name | Legacy | ✓ | |||
| alert_id | Legacy | ✓ | |||
| hash_md5 | |||||
| app_protocol | |||||
| app_id | |||||
| dest_port | Legacy | ✓ | |||
| direction | |||||
| policy | |||||
| process | |||||
| ioc_number | |||||
| device_id | |||||
| alert_description | |||||
| impact | |||||
| record_type | |||||
| src_port | Legacy | ✓ | |||
| rule_id | |||||
| event_id | |||||
| bytes_out | |||||
| additional_info | |||||
| src_country | |||||
| user_id | |||||
| bytes | Legacy | ✓ | |||
| dest_ip | Legacy | ✓ | ✓ | ||
| dest_host | Legacy | ✓ | |||
| ingress_interface | |||||
| malware_url | |||||
| sensor | |||||
| user | Legacy | ✓ | |||
| connection_counter | |||||
| dest_country | |||||
| ingress_security_zone | |||||
| dns-request | src_interface | ✓ | |||
| dns_record_type | ✓ | ||||
| response_ttl | ✓ | ||||
| dest_interface | ✓ | ||||
| bytes_in | ✓ | ||||
| rule | ✓ | ||||
| protocol | ✓ | ||||
| bytes_out | ✓ | ||||
| bytes | Legacy | ✓ | |||
| action | ✓ | ||||
| dns_response_type | ✓ | ||||
| category | ✓ | ||||
| policy | ✓ | ||||
| dns-response | result | ✓ | |||
| src_interface | ✓ | ||||
| egress_zone | ✓ | ||||
| protocol | ✓ | ||||
| bytes_out | ✓ | ||||
| dest_interface | ✓ | ||||
| bytes_in | ✓ | ||||
| ingress_zone | ✓ | ||||
| alert_type | ✓ | ||||
| policy | ✓ | ||||
| endpoint-authentication | event_code | Default | ✓ | ||
| event_name | Default | ✓ | |||
| priority | Default | ✓ | |||
| http-session | src_interface | Default | ✓ | ||
| protocol | Default | ✓ | |||
| dest_interface | Default | ✓ | |||
| app_protocol | Default | ✓ | |||
| rule | Default | ✓ | |||
| priority | Default | ✓ | |||
| alert_name | Default | ✓ | |||
| policy | Default | ✓ | |||
| network-session | src_interface | Default | ✓ | ||
| egress_zone | Default | ✓ | |||
| responder_packets | Default | ✓ | |||
| packets_out | Default | ✓ | |||
| bytes_in | Default | ✓ | |||
| network_app | Default | ✓ | |||
| nap_policy | Default | ✓ | |||
| response_type | Default | ✓ | |||
| reputation | Default | ✓ | |||
| rule | Default | ✓ | |||
| result | Default | ✓ | |||
| tcp_flags | Default | ✓ | |||
| event_code | Default | ✓ | |||
| initiator_packets | Default | ✓ | |||
| connection_duration | Default | ✓ | |||
| app_protocol | Default | ✓ | |||
| action | Default | ✓ | |||
| policy | Default | ✓ | |||
| connection_type | Default | ✓ | |||
| device_id | Default | ✓ | |||
| dest_interface | Default | ✓ | |||
| packets_in | Default | ✓ | |||
| ingress_zone | Default | ✓ | |||
| url | Default | ✓ | |||
| bytes_out | Default | ✓ | |||
| additional_info | Default | ✓ | |||
| event_name | Default | ✓ | |||
| category | Default | ✓ | |||
| vpn-authentication | event_code | Default | ✓ | ||
| event_name | Default | ✓ | |||
| priority | Default | ✓ | |||
| vpn-login | group_name | Default | ✓ | ||
| event_code | Default | ✓ | |||
| priority | Default | ✓ |