<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I think it can do it with &amp;quot;X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/original-client-ip/m-p/2698342#M1027063</link>
    <description>&lt;P&gt;I think it can do it with "X-Forwarded-For" header but not "Original Client IP" header.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/firesight/531/PDFs/FireSIGHT-System-eStreamer-Integration-Guide-5-3-1.pdf &amp;nbsp;page 77 of the pdf shows the detail on the Extra Data&amp;nbsp;records and XFF for IPv4 and IPv6.&lt;/P&gt;
&lt;P&gt;my understanding is that estreamer will only send it if the SIEM is requesting "Extra Data" from Sourcefire.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2015 16:00:06 GMT</pubDate>
    <dc:creator>jmoorhouse</dc:creator>
    <dc:date>2015-11-04T16:00:06Z</dc:date>
    <item>
      <title>Original Client IP</title>
      <link>https://community.cisco.com/t5/network-security/original-client-ip/m-p/2698341#M1027062</link>
      <description>&lt;DIV id="caseSummaryDescription" style="margin: 0px; padding: 0px; font-family: Arial, Helvetica; font-size: 12px; word-break: break-all; line-height: normal; background-color: rgb(241, 244, 247);"&gt;We send Discovery Events, Intrusion Event Packet Data, Intrusion Events &amp;amp; Intrusion Event Extra Data using the estreamer client into our SIEM tool.&lt;BR /&gt;&lt;BR /&gt;I cannot find the "Original Client IP" address field in my SIEM. Does the streamer client actually send this field?&lt;/DIV&gt;&lt;DIV style="margin: 0px; padding: 0px; font-family: Arial, Helvetica; font-size: 12px; word-break: break-all; line-height: normal; background-color: rgb(241, 244, 247);"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="margin: 0px; padding: 0px; font-family: Arial, Helvetica; font-size: 12px; word-break: break-all; line-height: normal; background-color: rgb(241, 244, 247);"&gt;I have it enabled in the HTTP pre-processor policy but don't see it listed as an option and I see the field populated in the Intrusion Events tab.&lt;/DIV&gt;</description>
      <pubDate>Tue, 26 Mar 2019 01:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/original-client-ip/m-p/2698341#M1027062</guid>
      <dc:creator>gordonwright</dc:creator>
      <dc:date>2019-03-26T01:15:46Z</dc:date>
    </item>
    <item>
      <title>I think it can do it with "X</title>
      <link>https://community.cisco.com/t5/network-security/original-client-ip/m-p/2698342#M1027063</link>
      <description>&lt;P&gt;I think it can do it with "X-Forwarded-For" header but not "Original Client IP" header.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/firesight/531/PDFs/FireSIGHT-System-eStreamer-Integration-Guide-5-3-1.pdf &amp;nbsp;page 77 of the pdf shows the detail on the Extra Data&amp;nbsp;records and XFF for IPv4 and IPv6.&lt;/P&gt;
&lt;P&gt;my understanding is that estreamer will only send it if the SIEM is requesting "Extra Data" from Sourcefire.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 16:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/original-client-ip/m-p/2698342#M1027063</guid>
      <dc:creator>jmoorhouse</dc:creator>
      <dc:date>2015-11-04T16:00:06Z</dc:date>
    </item>
  </channel>
</rss>

