Skip to main content
Version: 1.4.0

eStreamer

Cisco's event streaming protocol used by Firepower Management Center (FMC) to send events to export security event data, intrusion alerts, connection logs, and other network telemetry in real-time. It enables integration with external SIEMs and analytics platforms, providing deep visibility into network security events.

FieldDescription
eventTypeType of event (e.g., intrusion, connection, malware)
timestampTime the event occurred
sourceIPSource IP address
destinationIPDestination IP address
sourcePortSource port number
destinationPortDestination port number
protocolTransport protocol (TCP, UDP, etc.)
userIdentityAssociated user (if available)
deviceUUIDUnique identifier for the source device
applicationDetected application (e.g., HTTP, SSH)
threatScoreSeverity or risk rating of the event
signatureIDIdentifier for the security rule triggered
signatureNameDescription of the triggered security rule
malwareSHA256Hash of detected malware (if applicable)
fileNameName of the file involved in the event

eStreamer provides detailed security telemetry and integrates with SIEMs for real-time threat monitoring and forensic analysis.