DLP Push Security Events

Secure Access KeyTypeDescription
specversionstringThe version of the Push Security Event schema.
typestringThe type of the security event.
sourcestringThe unique label that describes the source of the security event.
orgidintegerThe unique identifier of the organization.
integrationidstringThe unique identifier of the integration.
idstringThe unique identifier for the push security event.
timestringThe date and time when the system sent the event. The system formats the timestamp in the ISO 8601 format.
datacontenttypestringThe type of the content in the push security event.
dataobjectThe properties of the data for the push security events.

data

Secure Access KeyTypeDescription
eventsarrayThe list of push security event messages.

data.events

Secure Access KeyOCSF KeyTypeDescription
activity_idintegerThe unique identifier of the activity that triggered the security event.
category_uidintegerThe unique identifier of the security event category.
cisco_event_idEvent IDstringThe unique identifier of the security event.
cisco_event_typestringThe type of the security event.
cisco_organization_idOrganization IDnumberThe unique identifier of the organization.
cisco_dlp_metadataobjectThe properties of the Cisco DLP metadata.
cisco_originsarrayThe list of the origins.
class_uidintegerThe unique identifier of the class.
dst_endpointobjectThe properties of the destination.
metadataobjectThe metadata for the security event.
policyobjectThe properties of the components and profiles for the access rules in the Access policy.
severity_idnumberThe unique identifier of the severity.
timeTimestringThe date and time when the system recorded the security event. The system formats the timestamp in milliseconds since the Unix Epoch.
type_uidintegerThe unique identifier of the type for the security event.

data.events.cisco_dlp_metadata

Secure Access KeyOCSF KeyTypeDescription
actionActionstringThe label that describes the action taken by the system for the application.
application_nameApplication NamestringThe name of the application.
content_typeContent TypestringThe type of the content associated with the application.
destination_protocolDestination ProtocolstringThe protocol of the application.
destination_urlDestinationstringThe URL of the application.
event_typeEvent TypestringThe type of the event observed by the system.
file_nameFile NamestringThe name of the file associated with the application.
owner_emailOwner EmailstringThe email address associated with the owner of the application.
severitySeveritystringThe descriptive label of the severity.
taac_profile_idTaac Profile IDstringThe identifier of the profile associated with the application.
taac_tenant_idTaac Tenant IDstringThe identifier of the tenant associated with the application.
traffic_directionTraffic DirectionstringThe direction of the traffic flow.
unique_event_idstringThe unique identifier of the event.

data.events.cisco_origins

Secure Access KeyOCSF KeyTypeDescription
idintegerThe unique identifier of the endpoint.
typestringThe type of the endpoint.

data.events.dst_endpoint

Secure Access KeyOCSF KeyTypeDescription
namestringThe hostname of the destination.

data.events.metadata

Secure Access KeyOCSF KeyTypeDescription
correlation_idstringThe unique identifier of the correlation.
productobjectThe properties of the product.
versionstringThe version of the product.

data.events.metadata.product

Secure Access KeyOCSF KeyTypeDescription
namestringThe name of the product.

data.events.policy

Secure Access KeyOCSF KeyTypeDescription
dataobjectThe properties of the data in the organization's Access policy.
nameRule NamestringThe name of the rule in the Access policy.

data.events.policy.data

Secure Access KeyOCSF KeyTypeDescription
application_category_nameApplication Category NamestringThe name of the application category.
classificationClassification NamestringThe classification of the application.
classifier_nameClassifier NamestringThe name of the classifier.
file_hashFile HashstringThe hash of the file associated with the application.
file_labelFile LabelstringThe label of the file associated with the application.
file_sizeFile SizenumberThe size of the file associated with the application.
private_resource_group_namestringThe name of the private resource group.
private_resource_namePrivate Resource NamestringThe name of the private resource.