ZTNA Push Security Events

Secure Access KeyTypeDescription
specversionstringThe version of the Push Security Event schema.
typestringThe type of the security event.
sourcestringThe unique label that describes the source of the security event.
orgidintegerThe unique identifier of the organization.
integrationidstringThe unique identifier of the integration.
idstringThe unique identifier for the push security event.
timestringThe date and time when the system sent the event. The system formats the timestamp in the ISO 8601 format.
datacontenttypestringThe type of the content in the push security event.
dataobjectThe properties of the data for the push security events.

data

Secure Access KeyTypeDescription
eventsarrayThe list of push security event messages.

data.events

Secure Access KeyOCSF KeyTypeDescription
activity_idintegerThe unique identifier of the activity that triggered the security event.
category_uidintegerThe unique identifier of the security event category.
cisco_event_idEvent IDstringThe unique identifier of the security event.
cisco_event_typestringThe type of the security event.
cisco_organization_idOrganization IDnumberThe unique identifier of the organization.
cisco_endpoint_postureobject
cisco_originsarrayThe list of the origins.
cisco_source_process_infoarrayThe list of the source process information for the transaction.
cisco_ztna_metadataobjectThe properties of the Cisco ZTNA metadata.
class_uidintegerThe unique identifier of the class.
metadataobjectThe metadata for the security event.
policyobjectThe properties of the components and profiles for the access rules in the Access policy.
severity_idnumberThe unique identifier of the severity.
src_endpointobjectThe properties of the client endpoint.
timeTimestringThe date and time when the system recorded the security event. The system formats the timestamp in milliseconds since the Unix Epoch.
type_uidintegerThe unique identifier of the type for the security event.

data.events.cisco_endpoint_posture

Secure Access KeyOCSF KeyTypeDescription
ad_joined_sidAD Joined SIDstringThe identifier of the AD device joined with the SID.
antimalware_agentsAntimalware Agentsarray(string)The label that describes the anti-malware agent.
client_browserClient BrowserstringThe descriptive label that identifies the client browser.
client_firewallClient FirewallstringThe descriptive label that identifies the client firewall.
client_geo_locationClient Geo LocationstringThe geographic location of the client.
client_ipClient IPstringThe IPv4 or IPv6 address of the client.
client_osClient OSstringThe operating system (OS) of the client.
disk_encryptionDisk EncryptionstringThe type of disk encryption enabled on the client.
duo_device_idDuo Device IDstringThe identifier of the DUO device.
system_passwordSystem PasswordstringThe adminstrative password of the client system.

data.events.cisco_origins

Secure Access KeyOCSF KeyTypeDescription
idintegerThe unique identifier of the endpoint.
typestringThe type of the endpoint.

data.events.cisco_source_process_info

Secure Access KeyOCSF KeyTypeDescription
process_idnumberThe identifier of the process.
process_namestringThe descriptive label for the process.
process_hashstringThe hash of the source process.
process_user_namestringThe name of the user for the source process in the transaction.

data.events.cisco_ztna_metadata

Secure Access KeyOCSF KeyTypeDescription
application_portApplication PortnumberThe port number used for the application.
application_protocolApplication ProtocolstringThe protocol used for the application.
applied_tndApplied TndstringThe detected trusted networks applied to the access rules in the policy.
detected_tndDetected Tndarray(string)The trusted network detected by the client.
egress_ipEgress IPstringThe IPv4 or IPv6 address associated with the egress of the traffic from the client system.
enforcement_pointEnforcement PointstringThe description of the point of enforcement.
ftd_enforcement_idFTD Enforcement IDnumberThe identifier of the Cisco Firepower Threat Defense (FTD) device.
ftd_enforcement_nameFTD Enforcement NamestringThe name of the Cisco Firepower Threat Defense (FTD) device.
headend_typeHeadend TypestringThe type of the headend for the tunnel to the system.
mdm_device_idMDM Device IDstringThe identifier of the Mobile Device Management (MDM) device.
mdm_is_compliantMDM Is CompliantbooleanSpecifies whether the MDM device is compliant.
mdm_is_managedMDM Is Managedboolean
mdm_last_updatedMDM Last UpdatednumberThe date and time when the system updated the MDM device.
mdm_sourceMDM SourcestringThe source of the MDM device.
requested_ip_fqdnRequested IP FQDNstringThe IP address for the fully-qualified domain name.
resolved_ipResolved IPstringThe IP address of the client.
secure_client_versionSecure Client VersionstringThe version of the Cisco Secure Client in use by the user device.
step_up_auth_resultStep Up Auth ResultstringThe result of the step-up authentication.
step_up_auth_token_lifeStep Up Auth Token LifenumberThe expiry of the step-up authentication used by the system.
step_up_auth_typeStep Up Auth TypestringThe type of the step-up authentication used by the system.
tunnel_typeTunnel TypestringThe type of the network tunnel.
verdictVerdictstringThe label of the verdict assigned to the destination.
zta_profile_idZTA Profile IDstringThe unique identifierof the Zero Trust profile.

data.events.metadata

Secure Access KeyOCSF KeyTypeDescription
correlation_idstringThe unique identifier of the correlation.
productobjectThe properties of the product.
versionstringThe version of the product.

data.events.metadata.product

Secure Access KeyOCSF KeyTypeDescription
namestringThe name of the product.

data.events.policy

Secure Access KeyOCSF KeyTypeDescription
dataobjectThe properties of the data in the organization's Access policy.
uidRule IDintegerThe unique identifier of the access rule in the Access policy that matches the network traffic.

data.events.policy.data

Secure Access KeyOCSF KeyTypeDescription
app_connector_group_idApp Connector Group IDnumberThe identifier of the resource connector group.
block_reasonBlock ReasonstringThe description that explains why the system blocked the network traffic.
posture_idPosture IDstringThe identifier of the posture profile.
private_app_group_idPrivate App Group IDnumberThe identifier of the private application group.
private_app_idPrivate App IDnumberThe identifier of the private application.
private_resource_group_idPrivate Resource Group IDstringThe identifier of the private resource group.
private_resource_idPrivate Resource IDstringThe identifier of the private resource.
ruleset_idRuleset IDnumberThe identifier of the access rule.

data.events.src_endpoint

Secure Access KeyOCSF KeyTypeDescription
namestringThe hostname of the client endpoint.