RAVPN Push Security Events

Secure Access KeyTypeDescription
specversionstringThe version of the Push Security Event schema.
typestringThe type of the security event.
sourcestringThe unique label that describes the source of the security event.
orgidintegerThe unique identifier of the organization.
integrationidstringThe unique identifier of the integration.
idstringThe unique identifier for the push security event.
timestringThe date and time when the system sent the event. The system formats the timestamp in the ISO 8601 format.
datacontenttypestringThe type of the content in the push security event.
dataobjectThe properties of the data for the push security events.

data

Secure Access KeyTypeDescription
eventsarrayThe list of push security event messages.

data.events

Secure Access KeyOCSF KeyTypeDescription
activity_idintegerThe unique identifier of the activity that triggered the security event.
category_uidintegerThe unique identifier of the security event category.
cisco_event_idEvent IDstringThe unique identifier of the security event.
cisco_event_typestringThe type of the security event.
cisco_organization_idOrganization IDnumberThe unique identifier of the organization.
cisco_asaobject
cisco_dtls_ipsec_tunnelobject
cisco_endpoint_postureobjectThe properties of the endpoint posture profile.
cisco_originobjectThe properties of the origin.
cisco_ravpn_metadataobjectThe properties of the Cisco metadata for the RAVPN connection.
cisco_ravpn_sessionobjectThe properties of the RAVPN session.
cisco_ssl_ike_tunnelobject
class_uidintegerThe unique identifier of the class.
cloudobjectThe properties of the cloud deployment.
deviceobjectThe properties of the device.
metadataobjectThe metadata for the security event.
policyobjectThe properties of the components and profiles for the access rules in the Access policy.
severity_idnumberThe unique identifier of the severity.
src_endpointobjectThe properties of the client endpoint.
timeTimestringThe date and time when the system recorded the security event. The system formats the timestamp in milliseconds since the Unix Epoch.
type_uidintegerThe unique identifier of the type for the security event.

data.events.cisco_asa

Secure Access KeyOCSF KeyTypeDescription
full_log_print_specifiersASA full log print specifiersstring
syslog_classASA syslog classstring
syslog_descriptorASA syslog Descriptorstring
syslog_idASA syslog IDstring
syslog_id_with_versionASA syslog ID with versionstring
syslog_severityASA syslog severitystring

data.events.cisco_dtls_ipsec_tunnel

Secure Access KeyOCSF KeyTypeDescription
bytes_receivedBytes ReceivednumberThe number of bytes received by the system on the network tunnel.
bytes_transmittedBytes TransmittednumberThe number of bytes transmitted by the system on the network tunnel.
cipher_suiteCipher SuitestringThe cipher suite supported on the network tunnel.
compressionCompression AlgorithmstringThe network compression algorithm used by the system on the network tunnel.
connection_timeoutConnection TimeoutstringThe connection timeout supported on the network tunnel.
connection_timeout_leftConnection Timeout LeftstringThe number of milliseconds left on the connection timeout.
destination_portDestination PortnumberThe port number of the destination.
dh_groupDH GroupstringThe label for the Diffie Hellman group.
encapsulationEncapsulationstringThe encapsulation supported for the messages on the IPsec tunnel.
encryptionEncryptionstringThe encryption supported for the messages on the IPsec tunnel.
filter_nameFilter NamestringThe name used to filter the traffic on the IPsec tunnel.
hashingHashingstringThe type of hash function used with the IPsec traffic.
idIDstringThe identifier of the Ipsec tunnel.
idle_timeoutIdle TimeoutstringThe idle timeout set for the IPsec tunnel.
idle_timeout_leftIdle Timeout LeftstringThe time remaining on the idle timeout for the IPsec tunnel.
ipv6_filter_nameIPv6 Filter NamestringThe IPv6 address used to filter for the name of the IPsec tunnel.
local_selectorLocal selectorstringThe local selector of the IPsec tunnel.
packets_receivedPackets ReceivednumberThe packets received on the IPsec tunnel.
packets_received_droppedPackets Received DroppednumberThe packets received on the IPsec tunnel and then dropped by the system.
packets_transmittedPackets TransmittednumberThe number of packets transmitted on the IPsec tunnel.
packets_transmitted_droppedPackets Transmitted DroppednumberThe number of packets transmitted on the IPsec tunnel and then dropped by the system.
pfs_groupPFS GroupstringThe Perfect Forward Secrecy (PFS) group used by the Internet Key Exchange (IKE) protocol with the IPsec tunnel.
prfPRF algorithmstringThe Pseudo-Random Function (PRF) (cryptographic algorithm) used by the system to generate secrets for the IPsec tunnel.
rekey_dataRekey datastringThe data transmitted before the system modifies the encryption key.
rekey_data_leftRekey data leftstringThe data remaining to be transmitted before the system modifies the encryption key.
rekey_intervalRekey IntervalstringThe time interval before the system modifies the the encryption key.
rekey_interval_leftRekey Interval LeftstringThe time remaining before the system modifies the the encryption key.
remote_selectorRemote SelectorstringThe label of the remote selector.
source_portSource PortnumberThe port number of the client endpoint.

data.events.cisco_endpoint_posture

Secure Access KeyOCSF KeyTypeDescription
dap_connection_typeDAP Connection TypestringThe type of the connection in use by the end user's device.
dap_record_nameDAP Record NamestringThe record name of connection in use by the end user's device.

data.events.cisco_origin

Secure Access KeyOCSF KeyTypeDescription
idOrigin IDintegerThe unique identifier of the endpoint.
typeOrigin TypestringThe type of the endpoint, for example: Networks or AD Computer.
user_idUser IDnumberThe identifier of the end user.

data.events.cisco_ravpn_metadata

Secure Access KeyOCSF KeyTypeDescription
anyconnect_versionAny Connect VersionstringThe version of the AnyConnect client on the device.
event_typeEvent TypestringThe type of the event observed on the device with the AnyConnect client.

data.events.cisco_ravpn_session

Secure Access KeyOCSF KeyTypeDescription
assigned_ipAssigned IPstringThe IPv4 address assigned to the RAVPN session.
assigned_ipv6Assigned IPv6stringThe IPv6 address assigned to the RAVPN session.
audit_session_idAudit Session IDstringThe identifier of the session for the audit log.
connected_atConnected AtnumberThe time and date when the client connected to the system.
disconnection_reasonDisconnection ReasonstringThe reason that explains why the session disconnected from the system.
durationDurationstringThe length of time that the client session was in progress.
idSession IDstringThe identifier of the client session.
inactivityInactivitystringThe time and date of the inactivity on the client session.
public_ipPublic IPstringThe public IPv4 address associated with the client session.
public_ipv6Public IPv6stringThe public IPv6 address associated with the client session.
redirect_aclRedirect ACLstringThe access control list used by the system to redirect traffic.
redirect_urlRedirect URLstringThe URL used by the system to redirect traffic.
security_group_tagSecurity Group TagstringThe security group tag associated with the client.
session_typeSession TypestringThe type of the client session.
vpn_profileVPN ProfilestringThe name of the VPN profile in use by the client session.
warning_reasonWarning ReasonstringThe reason that explains why the system recorded a warning about the client session.

data.events.cisco_ssl_ike_tunnel

Secure Access KeyOCSF KeyTypeDescription
bytes_receivedBytes ReceivednumberThe number of bytes received on the network tunnel.
bytes_transmittedBytes TransmittednumberThe number of bytes transmitted on the network tunnel.
cipher_suiteCipher SuitestringThe cipher suite supported on the network tunnel.
compressionCompression AlgorithmstringThe network compression algorithm used by the system on the network tunnel.
connection_timeoutConnection TimeoutstringThe connection timeout supported on the network tunnel.
connection_timeout_leftConnection Timeout LeftstringThe number of milliseconds left on the connection timeout.
destination_portDestination Portnumber
dh_groupDH GroupstringThe label for the Diffie Hellman group.
encapsulationEncapsulationstringThe encapsulation supported for the messages on the network tunnel.
encryptionEncryptionstringThe encryption supported for the messages on the network tunnel.
filter_nameFilter NamestringThe name used to filter the traffic on the network tunnel.
hashingHashingstringThe type of hash function used with the network traffic.
idIDstringThe identifier of the Ipsec tunnel.
idle_timeoutIdle TimeoutstringThe idle timeout set for the IPsec tunnel.
idle_timeout_leftIdle Timeout LeftstringThe time remaining on the idle timeout for the network tunnel.
ipv6_filter_nameIPv6 Filter NamestringThe IPv6 address used to filter for the name of the network tunnel.
local_selectorLocal selectorstringThe local selector of the network tunnel.
packets_receivedPackets ReceivednumberThe packets received on the network tunnel.
packets_received_droppedPackets Received DroppednumberThe packets received on the network tunnel and then dropped by the system.
packets_transmittedPackets TransmittednumberThe number of packets transmitted on the network tunnel.
packets_transmitted_droppedPackets Transmitted DroppednumberThe number of packets transmitted on the network tunnel and then dropped by the system.
pfs_groupPFS GroupstringThe Perfect Forward Secrecy (PFS) group used by the Internet Key Exchange (IKE) protocol with the network tunnel.
prfPRF algorithmstringThe Pseudo-Random Function (PRF) (cryptographic algorithm) used by the system to generate secrets for the network tunnel.
rekey_dataRekey datastringThe data transmitted before the system modifies the encryption key.
rekey_data_leftRekey data leftstringThe data remaining to be transmitted before the system modifies the encryption key.
rekey_intervalRekey IntervalstringThe time interval before the system modifies the the encryption key.
rekey_interval_leftRekey Interval LeftstringThe time remaining before the system modifies the the encryption key.
remote_selectorRemote SelectorstringThe label of the remote selector.
source_portSource PortnumberThe port number of the client endpoint.

data.events.cloud

Secure Access KeyOCSF KeyTypeDescription
regionAws RegionstringThe region where the system deployed the firewall service.

data.events.device

Secure Access KeyOCSF KeyTypeDescription
osOS VersionobjectThe properties of the operating system installed on the device.

data.events.device.os

Secure Access KeyOCSF KeyTypeDescription
versionstringThe version of the operating system installed on the device.

data.events.metadata

Secure Access KeyOCSF KeyTypeDescription
productobjectThe properties of the product.
versionstringThe version of the product.

data.events.metadata.product

Secure Access KeyOCSF KeyTypeDescription
namestringThe name of the product.

data.events.policy

Secure Access KeyOCSF KeyTypeDescription
dataobjectThe properties of the data in the organization's Access policy.

data.events.policy.data

Secure Access KeyOCSF KeyTypeDescription
failed_reasonsFailed Reasonsarray(string)The reason that describes the failure connecting to the destination.

data.events.src_endpoint

Secure Access KeyOCSF KeyTypeDescription
namestringThe hostname of the client endpoint.