Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 892 Bytes

ba2d72de-8d25-4e0f-a4f7-85d263c62b7e.md

File metadata and controls

34 lines (27 loc) · 892 Bytes

Mappings: Cisco Meraki L7 Firewall - Custom Parser

Input Requirements

Input Value
Vendor Cisco
Product Meraki
Log Format JSON
Event ID Regex Pattern l7_firewall

Record Output

Output Value
Vendor Cisco Systems
Product Meraki
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action decision
device_hostname syslog_device_name
dstDevice_ip dst
dstPort dport
ipProtocol protocol
normalizedAction decision This is a lookup field. More info to come in the catalog later...
srcDevice_ip src
srcPort sport
success decision This is a lookup field. More info to come in the catalog later...
timestamp syslog_timestamp We expect the orginal record value of syslog_timestamp is in the format epoch_float