Azure-Sentinel/Sample Data/CEF/CiscoFirepowerEStreamerCONN...

7.9 KiB

1TenantIdSourceSystemTimeGenerated [UTC]ReceiptTimeDeviceVendorDeviceProductDeviceEventClassIDLogSeverityOriginalLogSeverityDeviceActionSimplifiedDeviceActionComputerCommunicationDirectionDeviceFacilityDestinationPortDestinationIPDeviceAddressDeviceNameMessageProtocolSourcePortSourceIPRemoteIPRemotePortMaliciousIPThreatSeverityIndicatorThreatTypeThreatDescriptionThreatConfidenceReportReferenceLinkMaliciousIPLongitudeMaliciousIPLatitudeMaliciousIPCountryDeviceVersionActivityApplicationProtocolEventCountDestinationDnsDomainDestinationServiceNameDestinationTranslatedAddressDestinationTranslatedPortDeviceDnsDomainDeviceExternalIDDeviceInboundInterfaceDeviceNtDomainDeviceOutboundInterfaceDevicePayloadIdProcessNameDeviceTranslatedAddressDestinationHostNameDestinationMACAddressDestinationNTDomainDestinationProcessIdDestinationUserPrivilegesDestinationProcessNameDeviceTimeZoneDestinationUserIDDestinationUserNameDeviceMacAddressProcessIDExternalIDFileCreateTimeFileHashFileIDFileModificationTimeFilePathFilePermissionFileTypeFileNameFileSizeReceivedBytesOldFileCreateTimeOldFileHashOldFileIDOldFileModificationTimeOldFileNameOldFilePathOldFilePermissionOldFileSizeOldFileTypeSentBytesRequestURLRequestClientApplicationRequestContextRequestCookiesRequestMethodSourceHostNameSourceMACAddressSourceNTDomainSourceDnsDomainSourceServiceNameSourceTranslatedAddressSourceTranslatedPortSourceProcessIdSourceUserPrivilegesSourceProcessNameSourceUserIDSourceUserNameEventTypeDeviceCustomIPv6Address1DeviceCustomIPv6Address1LabelDeviceCustomIPv6Address2DeviceCustomIPv6Address2LabelDeviceCustomIPv6Address3DeviceCustomIPv6Address3LabelDeviceCustomIPv6Address4DeviceCustomIPv6Address4LabelDeviceCustomFloatingPoint1DeviceCustomFloatingPoint1LabelDeviceCustomFloatingPoint2DeviceCustomFloatingPoint2LabelDeviceCustomFloatingPoint3DeviceCustomFloatingPoint3LabelDeviceCustomFloatingPoint4DeviceCustomFloatingPoint4LabelDeviceCustomNumber1DeviceCustomNumber1LabelDeviceCustomNumber2DeviceCustomNumber2LabelDeviceCustomNumber3DeviceCustomNumber3LabelDeviceCustomString1DeviceCustomString1LabelDeviceCustomString2DeviceCustomString2LabelDeviceCustomString3DeviceCustomString3LabelDeviceCustomString4DeviceCustomString4LabelDeviceCustomString5DeviceCustomString5LabelDeviceCustomString6DeviceCustomString6LabelDeviceCustomDate1DeviceCustomDate1LabelDeviceCustomDate2DeviceCustomDate2LabelFlexDate1FlexDate1LabelFlexNumber1FlexNumber1LabelFlexNumber2FlexNumber2LabelFlexString1FlexString1LabelFlexString2FlexString2LabelAdditionalExtensionsStartTime [UTC]EndTime [UTC]Type_ResourceId
20a18deaa-a6c8-49ba-8cc9-74d5915fd2aeOpsManager10/15/2020, 6:38:45.828 PM1590028071000CiscoFirepowerRNA:1003:13AllowAllow8013.107.4.52ftd65313310.1.8.20nullnullnull6.0CONNECTION STATISTICSHTTPnullnull1insideoutsidenull111915nullnullnullnullhttp://www.msftconnecttest.com/connecttest.txtWeb browsernullnullUnknownnullnullnullnullnullnullnullnulldCloud Access PolicyfwPolicyDefault InspectfwRuleinsideingressZoneoutsideegressZonesecIntelCategorynullnullbytesOut=88;end=1590031675000;reason=N/A;start=15900280710001/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog/subscriptions/08e3a9d7-7798-47c4-9d89-d38857c5bfe7/resourcegroups/csta1/providers/microsoft.compute/virtualmachines/encoreconnector
30a18deaa-a6c8-49ba-8cc9-74d5915fd2aeOpsManager10/15/2020, 6:40:22.349 PM1590028071000CiscoFirepowerRNA:1003:13AllowAllow8013.107.4.52ftd65313310.1.8.20nullnullnull6.0CONNECTION STATISTICSHTTPnullnull1insideoutsidenull111915nullnullnullnullhttp://www.msftconnecttest.com/connecttest.txtWeb browsernullnullUnknownnullnullnullnullnullnullnullnulldCloud Access PolicyfwPolicyDefault InspectfwRuleinsideingressZoneoutsideegressZonesecIntelCategorynullnullbytesOut=88;end=1590031675000;reason=N/A;start=15900280710001/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog/subscriptions/08e3a9d7-7798-47c4-9d89-d38857c5bfe7/resourcegroups/csta1/providers/microsoft.compute/virtualmachines/encoreconnector
40a18deaa-a6c8-49ba-8cc9-74d5915fd2aeOpsManager10/15/2020, 6:42:23.451 PM1590028071000CiscoFirepowerRNA:1003:13AllowAllow8013.107.4.52ftd65313310.1.8.20nullnullnull6.0CONNECTION STATISTICSHTTPnullnull1insideoutsidenull111915nullnullnullnullhttp://www.msftconnecttest.com/connecttest.txtWeb browsernullnullUnknownnullnullnullnullnullnullnullnulldCloud Access PolicyfwPolicyDefault InspectfwRuleinsideingressZoneoutsideegressZonesecIntelCategorynullnullbytesOut=88;end=1590031675000;reason=N/A;start=15900280710001/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog/subscriptions/08e3a9d7-7798-47c4-9d89-d38857c5bfe7/resourcegroups/csta1/providers/microsoft.compute/virtualmachines/encoreconnector
50a18deaa-a6c8-49ba-8cc9-74d5915fd2aeOpsManager10/15/2020, 6:54:58.521 PM1590028071000CiscoFirepowerRNA:1003:13AllowAllow8013.107.4.52ftd65313310.1.8.20nullnullnull6.0CONNECTION STATISTICSHTTPnullnull1insideoutsidenull111915nullnullnullnullhttp://www.msftconnecttest.com/connecttest.txtWeb browsernullnullUnknownnullnullnullnullnullnullnullnulldCloud Access PolicyfwPolicyDefault InspectfwRuleinsideingressZoneoutsideegressZonesecIntelCategorynullnullbytesOut=88;end=1590031675000;reason=N/A;start=15900280710001/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog/subscriptions/08e3a9d7-7798-47c4-9d89-d38857c5bfe7/resourcegroups/csta1/providers/microsoft.compute/virtualmachines/encoreconnector
60a18deaa-a6c8-49ba-8cc9-74d5915fd2aeOpsManager10/15/2020, 6:59:08.009 PM1590028071000CiscoFirepowerRNA:1003:13AllowAllow8013.107.4.52ftd65313310.1.8.20nullnullnull6.0CONNECTION STATISTICSHTTPnullnull1insideoutsidenull111915nullnullnullnullhttp://www.msftconnecttest.com/connecttest.txtWeb browsernullnullUnknownnullnullnullnullnullnullnullnulldCloud Access PolicyfwPolicyDefault InspectfwRuleinsideingressZoneoutsideegressZonesecIntelCategorynullnullbytesOut=88;end=1590031675000;reason=N/A;start=15900280710001/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog/subscriptions/08e3a9d7-7798-47c4-9d89-d38857c5bfe7/resourcegroups/csta1/providers/microsoft.compute/virtualmachines/encoreconnector
70a18deaa-a6c8-49ba-8cc9-74d5915fd2aeOpsManager10/15/2020, 7:02:56.998 PM1590028071000CiscoFirepowerRNA:1003:13AllowAllow8013.107.4.52ftd65313310.1.8.20nullnullnull6.0CONNECTION STATISTICSHTTPnullnull1insideoutsidenull111915nullnullnullnullhttp://www.msftconnecttest.com/connecttest.txtWeb browsernullnullUnknownnullnullnullnullnullnullnullnulldCloud Access PolicyfwPolicyDefault InspectfwRuleinsideingressZoneoutsideegressZonesecIntelCategorynullnullbytesOut=88;end=1590031675000;reason=N/A;start=15900280710001/1/1970, 12:00:00.000 AM1/1/1970, 12:00:00.000 AMCommonSecurityLog/subscriptions/08e3a9d7-7798-47c4-9d89-d38857c5bfe7/resourcegroups/csta1/providers/microsoft.compute/virtualmachines/encoreconnector