Mappings: Cisco Meraki Firewall - Custom Parser
Input | Value |
---|---|
Vendor | Cisco |
Product | Meraki |
Log Format | JSON |
Event ID Regex Pattern | firewall |
Output | Value |
---|---|
Vendor | Cisco Systems |
Product | Meraki |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | verdict | This is a lookup field. More info to come in the catalog later... |
device_hostname | syslog_device_name | |
dstDevice_ip | dst | |
dstPort | dport | |
ipProtocol | protocol | |
normalizedAction | verdict | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | src | |
srcDevice_mac | mac | |
srcPort | sport | |
success | verdict | This is a lookup field. More info to come in the catalog later... |
timestamp | syslog_timestamp | We expect the orginal record value of syslog_timestamp is in the format epoch_float |