Cisco Stealthwatch 샘플 이벤트 메시지

이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.

중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.

Syslog 프로토콜을 사용할 때 Cisco Stealthwatch 샘플 메시지

샘플 1: 다음 샘플 이벤트 메시지는 감시된 포트가 활성 상태임을 표시합니다.

<134>Sep 12 14:03:02 cisco.stealthwatch.test StealthWatch[4969]: LEEF:2.0|Lancope|Stealthwatch|6.8|13|0x7C|src=10.243.54.38|dst=10.100.11.12|dstPort=784|proto=6|msg=A watched port number has become active.|fullmessage=IANA-Unassigned (784/tcp) from 10.100.11.12|start=2019-09-12T14:02:30Z|end=|cat=Watch Port Active|alarmID=3X-1F6B-86U2-YUUR-7|sourceHG=Country|targetHG=Catch All|sourceHostSnapshot=https://10.36.52.20/test-page/test.html#/host/10.243.54.38|targetHostSnapshot=https://10.36.52.20/landing-page/abc.html#/host/10.100.11.12|flowCollectorName=flow|flowCollectorIP=10.20.25.23|domain=abcd.ab.example.test|exporterName=|exporterIPAddress =|exporterInfo=|targetUser=|targetHostname=|sourceUser=|alarmStatus=ACTIVE|alarmSev=Major
표 1. Cisco Stealthwatch 샘플 이벤트 메시지에서 강조표시된 값
QRadar 필드 이름 이벤트 페이로드에서 강조표시된 필드 및 값
이벤트 ID 13
이벤트 카테고리 Watch Port Active
소스 IP src
대상 IP dst
대상 포트 dstPort
프로토콜 proto

샘플 2: 다음 샘플 이벤트 메시지는 의심스러운 활동이 있음을 표시합니다.

<134>Sep 12 13:19:27 cisco.stealthwatch.test StealthWatch[4969]: LEEF:2.0|Lancope|Stealthwatch|6.8|99|0x7C|src=10.10.10.10|dst=10.237.198.232|dstPort=80|proto=6|msg=The host has been observed doing something bad to another host.|fullmessage=Source Host is http (80/tcp) client to target.host.name (10.237.198.232)|start=2019-09-05T08:48:34Z|end=2019-09-05T08:48:34Z|cat=Anomaly|alarmID=3Y-13Y1-QJJ2-YYA9-U|sourceHG=Department, Inside|targetHG=target, Outside|sourceHostSnapshot=https://10.10.10.20/some/path|targetHostSnapshot=https://10.10.10.20/some/path|flowCollectorName=Collector|flowCollectorIP=10.10.10.20|domain=Corporate Domain|exporterName=exporter.host.name|exporterIPAddress =10.20.30.40|exporterInfo=exporter.host.name (10.20.30.40)|targetUser=admin|targetHostname=www.host.test|sourceUser=admin|alarmStatus=ACTIVE|alarmSev=Critical
표 2. Cisco Stealthwatch 샘플 이벤트 메시지에서 강조표시된 값
QRadar 필드 이름 이벤트 페이로드에서 강조표시된 필드 및 값
이벤트 ID 99
이벤트 카테고리 Anomaly
소스 IP src
대상 IP dst
대상 포트 dstPort
프로토콜 proto