eStreamer

Download 46
Last updated Feb 21, 2024

estreamer-events

Retrieve Firepower events in real time using the eStreamer protocol.

Syntax

estreamer-events [profile=PROFILE] window=WINDOW [bookmark=BOOKMARK] [raw=RAW]

Options

profile=PROFILE
Optional. Connect profile identifier
window=WINDOW
Required. e.g. 10m (to receive events for 10 minutes after executing the query)
bookmark=BOOKMARK
Optional. Date in the format yyyyMMddHHmmss. If not specified, only events that occur after the query execution will be retrieved.
raw=RAW
Optional. t or f. Specify 't' to output line field.

Output Fields

FieldTypeNameDescription
event_timeDateEvent Time
riskStringRiske.g. LOW, MEDIUM, HIGH
session_idLongSession ID
event_typeStringEvent Type
src_ipIP addressSource IP
src_portIntegerSource Port
dst_ipIP addressDestination IP
dst_portIntegerDestination Port
protocolStringProtocole.g. TCP, UDP
policyStringPolicy
actionStringAction
raw_actionStringOriginal Action
appStringApplication
clientStringClient
sent_bytesLongSent Bytes
rcvd_bytesLongReceived Bytes
sent_pktsLongSent Packets
rcvd_pktsLongReceived Packets
prefilter_policyStringPrefilter Policye.g. Default Prefilter Policy
firewall_policyStringFirewall Policy
firewall_ruleStringFirewall Rule
nap_policyStringNAP Policye.g. Balanced Security and Connectivity
dns_record_typeStringDNS Record Typee.g. a host address, text strings
dns_queryStringDNS Querye.g. 0.sourcefire.pool.ntp.org
dns_response_typeStringDNS Response Typee.g. No Error, Non-Existent Domain
device_uuidStringDevice UUID
src_ifaceStringSource Interface
first_packet_secondLongFirst Packet Second
instance_idLongInstance ID
client_app_detectorStringClient App Detector
end_timeDateEnd Time
durationLongDuration
dns_ttlLongDNS TTL
webappStringWeb Applicatione.g. Cisco
urlStringURLe.g. https://example.com
user_agentStringUser Agent
referenced_hostStringReferenced Host
event_secondLongEvent Second
file_directionStringFile Directione.g. Upload, Download
file_actionStringFile Actione.g. Detect
file_typeStringFile Typee.g. MSEXE
file_policyStringFile Policye.g. AMP-Policy
file_sandbox_statusStringFile Sandbox Statuse.g. File Size Is Too Small
ac_rule_reasonStringAccess Control Reason
file_countLongFile Count
intrusion_countLongIntrusion Count
event_microsecondLongEvent Microsecond
priority_idLongPriority IDe.g. 1: HIGH
generator_idLongGenerator ID
sidLongSignature ID
signature_revLongSignature Revision
impactLongImpact
signatureStringSignature
categoryStringClassification
intrusion_policyStringIntrusion Policy
inline_resultStringInline Result
http_hostStringHTTP Hostname
http_uriStringHTTP URIe.g. /inform
event_idLongEvent ID
packet_secondLongPacket Second
packet_microsecondLongPacket Microsecond
packet_lengthLongPacket Length
packet_link_type_idLongPacket Link Type ID
payloadBLOBPayload
lineStringEvent raw