cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3954
Views
5
Helpful
2
Replies

Cisco_Firepower_Estreamer event types

Hi Community,

 

I have Cisco_Firepower_Estreamer and forwarded all the logs in to my SIEM (QRadar). from there I have identified below event type. Can someone please help me on clear these events activities.

 

Event type -  IOC_STATE_RECORD (what this means)

iocState.value= (have different values) like 51, 52, 16, 2. What this means ? any reference link to get idea 

recordType=IOC_STATE_RECORD 

eventType=HOST_IOC_SET_TYPE for all events this event type is same.

detectionEngineRef= 1,0,4,etc. what this meant any reference link to get idea on this.

 

 

 

 

 

2 Replies 2

Event details for FMC 6.1.0

ioc.png

MSS_PROOF
Level 1
Level 1

Can you provide us with official documentation for this issue?