Skip to content

Commit d190f58

Browse files
committed
add file event dataset for cisco sfw
1 parent 217cc81 commit d190f58

File tree

3 files changed

+14
-1
lines changed

3 files changed

+14
-1
lines changed

datasets/cisco_secure_firewall_threat_defense/connection_event/connection_events.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,4 +7,4 @@ dataset:
77
sourcetypes:
88
- cisco:sfw:estreamer
99
references:
10-
- https://www.cisco.com/c/en/us/td/docs/security/firepower/741/api/FQE/secure_firewall_estreamer_fqe_guide_740.pdf
10+
- https://www.cisco.com/c/en/us/td/docs/security/firepower/741/api/FQE/secure_firewall_estreamer_fqe_guide_740.pdf
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:9fe21ea764d791a5c00a3a0f9d5e4853697b84183758d0ba167b81f5507b49e6
3+
size 3928
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
author: Nasreddine Bencherchali, Splunk
2+
id: 24d68f64-426a-4774-9282-e2d01f4ad5f3
3+
date: '2025-04-04'
4+
description: Generated datasets for Cisco Secure Firewall Threat Defense File Event EventType.
5+
dataset:
6+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/cisco_secure_firewall_threat_defense/file_event/file_events.log
7+
sourcetypes:
8+
- cisco:sfw:estreamer
9+
references:
10+
- https://www.cisco.com/c/en/us/td/docs/security/firepower/741/api/FQE/secure_firewall_estreamer_fqe_guide_740.pdf

0 commit comments

Comments
 (0)