Mappings: Suricata IDS
Legacy Parser Grok Patterns |
---|
SURICATA_NOPORT_IDS |
Output | Value |
---|---|
Vendor | OISF |
Product | Suricata IDS |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | None | The static text observed is populated in this schema field. |
description | event_name | |
dstDevice_ip | dst_ip | |
ipProtocol | ip_proto | |
normalizedSeverity | event_priority | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | src_ip | |
threat_name | event_msg | |
threat_ruleType | None | The static text intrusion is populated in this schema field. |
timestamp | timestamp | We expect the orginal record value of timestamp is in the format yyyy-MM-dd'T'HH:mm:ssZ |