QRadar eStreamer Fields
The following table is intended to show the fields that can be parsed when sending Firepower eStreamer connection events to QRadar. For more information on how to configure Cisco Firepower eStreamer and QRadar please refer to the vendor documentation.
Note: The following fields were taken from RAW output before being compiled. I have given brief descriptions next to the most common fields as an example.
Description |
|
Field |
Description |
|
flowStatistics.initiatorIPAddress |
Flow initiator IP |
|
flowStatistics.dnsTTL |
|
flowStatistics.responderIPAddress |
Flow responder IP |
|
flowStatistics.managedDevice.managedDeviceId |
Provides the FTD's device ID |
flowStatistics.originalClientIPAddress |
|
|
flowStatistics.managedDevice.name |
Provides the FTD's device hostname |
flowStatistics.policyRevision |
|
|
flowStatistics.ingressSecurityZone.securityZoneUUID |
|
flowStatistics.ruleId |
Matched rule ID |
|
flowStatistics.ingressSecurityZone.securityZoneName |
|
flowStatistics.ruleAction |
Rule action |
|
flowStatistics.egressSecurityZone.securityZoneUUID |
|
flowStatistics.tunnelRuleId |
|
|
flowStatistics.egressSecurityZone.securityZoneName |
Egress Interface Security Zone |
flowStatistics.ruleReason |
|
|
flowStatistics.ingressInterface.interfaceUUID |
Ingress Interface Security Zone |
flowStatistics.initiatorPort |
Flow initiator port |
|
flowStatistics.ingressInterface.interfaceName |
Ingress Interface Name |
flowStatistics.responderPort |
Flow responder port |
|
flowStatistics.egressInterface.interfaceUUID |
|
flowStatistics.tcpFlags |
|
|
flowStatistics.egressInterface.interfaceName |
Egress Interface Name |
flowStatistics.protocol |
Flow initiator protocol |
|
flowStatistics.user.userId |
|
flowStatistics.netFlowIPAddress |
|
|
flowStatistics.user.protocolRef |
|
flowStatistics.instanceId |
|
|
flowStatistics.user.userName |
|
flowStatistics.connectionCounter |
|
|
flowStatistics.urlCategoryRef |
|
flowStatistics.firstPacketTimestamp |
First Packet Seen Time |
|
flowStatistics.urlReputation.urlReputationId |
|
flowStatistics.lastPacketTimestamp |
Last Packet Seen Time |
|
flowStatistics.urlReputation.reputationName |
|
flowStatistics.packetsSent |
Number of Packets Sent |
|
flowStatistics.webApp.applicationId |
|
flowStatistics.packetsReceived |
Number of Packets Received |
|
flowStatistics.webApp.webApplicationName |
|
flowStatistics.bytesSent |
Total Bytes Sent |
|
flowStatistics.initiatorCountry.geolocation.countryCode |
Geolocation fields |
flowStatistics.bytesReceived |
Total Bytes Received |
|
flowStatistics.initiatorCountry.geolocation.countryName |
|
flowStatistics.initiatorPacketsDropped |
|
|
flowStatistics.responderCountry.geolocation.countryCode |
|
flowStatistics.responderPacketsDropped |
|
|
flowStatistics.responderCountry.geolocation.countryName |
|
flowStatistics.initiatorBytesDropped |
|
|
flowStatistics.originalClientCountryRef |
|
flowStatistics.responderBytesDropped |
|
|
flowStatistics.IOCRef |
|
flowStatistics.qosAppliedInterface |
|
|
flowStatistics.securityContextRef |
|
flowStatistics.qosRuleId |
|
|
flowStatistics.sslPolicyRef |
|
flowStatistics.applicationProtocolId |
|
|
flowStatistics.sslCertificateFingerprintRef |
|
flowStatistics.clientAppId |
|
|
flowStatistics.sslCiperSuite.sslCipherId |
|
flowStatistics.clientAppURL |
|
|
flowStatistics.sslCiperSuite.sslCipherSuiteName |
|
flowStatistics.netbiosName |
|
|
flowStatistics.sslVersion.sslVersionId |
|
flowStatistics.clientAppVersion |
|
|
flowStatistics.sslVersion.sslVersionName |
|
flowStatistics.monitorRule1 |
|
|
flowStatistics.sslServerCertificateStatus.sslServerCertificateStatus |
|
flowStatistics.monitorRule2 |
|
|
flowStatistics.sslServerCertificateStatus.sslServerCertificateStatusDescription |
|
flowStatistics.monitorRule3 |
|
|
flowStatistics.sslActualAction.sslActualAction |
|
flowStatistics.monitorRule4 |
|
|
flowStatistics.sslActualAction.description |
|
flowStatistics.monitorRule5 |
|
|
flowStatistics.sslExpectedActionRef |
|
flowStatistics.monitorRule6 |
|
|
flowStatistics.sslFlowStatus.sslFlowStatus |
|
flowStatistics.monitorRule7 |
|
|
flowStatistics.sslFlowStatus.description |
|
flowStatistics.monitorRule8 |
|
|
flowStatistics.sslURLCategoryRef |
|
flowStatistics.securityIntelligenceSrcOrDest |
|
|
flowStatistics.securityGroupRef |
|
flowStatistics.securityIntelligenceLayer |
|
|
flowStatistics.sinkholeRef |
|
flowStatistics.fileEventCount |
|
|
flowStatistics.securityIntelligenceList1Ref |
|
flowStatistics.intrusionEventCount |
|
|
flowStatistics.securityIntelligenceList2Ref |
|
flowStatistics.sourceAutonomousSystem |
|
|
|
|
flowStatistics.destinationAutonomousSystem |
|
|
|
|
flowStatistics.snmpIn |
|
|
|
|
flowStatistics.snmpOut |
|
|
|
|
flowStatistics.sourceTOS |
|
|
|
|
flowStatistics.destinationTOS |
|
|
|
|
flowStatistics.sourceMask |
|
|
|
|
flowStatistics.destinationMask |
|
|
|
|
flowStatistics.vlanId |
|
|
|
|
flowStatistics.referencedHost |
|
|
|
|
flowStatistics.userAgent |
|
|
|
|
flowStatistics.httpReferrer |
|
|
|
|
flowStatistics.sslRuleId |
|
|
|
|
flowStatistics.sslFlowError |
|
|
|
|
flowStatistics.sslFlowMessages |
|
|
|
|
flowStatistics.sslFlowFlags |
|
|
|
|
flowStatistics.sslServerNames |
|
|
|
|
flowStatistics.sslSessionId |
|
|
|
|
flowStatistics.sslSessionIdLength |
|
|
|
|
flowStatistics.sslTicketId |
|
|
|
|
flowStatistics.sslTicketIdLength |
|
|
|
|
flowStatistics.networkAnalysisPolicyRevision |
|
|
|
|
flowStatistics.endpointProfileId |
|
|
|
|
flowStatistics.locationIPv6Address |
|
|
|
|
flowStatistics.httpResponse |
|
|
|
|
flowStatistics.dnsRecordType |
|
|
|
|
flowStatistics.dnsQuery |
|
|
|
|
flowStatistics.dnsResponseType |
|
|
|
|