Skip to content

Latest commit

 

History

History
30 lines (23 loc) · 904 Bytes

8d53d23e-ca67-477d-9e9e-697194abe6c9.md

File metadata and controls

30 lines (23 loc) · 904 Bytes

Mappings: Suricata IDS

Input Requirements

Legacy Parser Grok Patterns
SURICATA_NOPORT_IDS

Record Output

Output Value
Vendor OISF
Product Suricata IDS
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action None The static text observed is populated in this schema field.
description event_name
dstDevice_ip dst_ip
ipProtocol ip_proto
normalizedSeverity event_priority This is a lookup field. More info to come in the catalog later...
srcDevice_ip src_ip
threat_name event_msg
threat_ruleType None The static text intrusion is populated in this schema field.
timestamp timestamp We expect the orginal record value of timestamp is in the format yyyy-MM-dd'T'HH:mm:ssZ