CiscoUmbrellaFileEvent_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (23 columns)

Source: Connector definition

Column Name Type Description
ArchiveDepth string The level (if any) at which the file was nested in an archive file.
ArchiveFileName string The name of the archive file involved with the activity.
ArchiveSha string The SHA-256 checksum hash of the archive file.
AwsRegion string The AWS region where Secure Access stores your logs.
Direction string The traffic direction of the file event. Valid values are: UNKNOWN, UPLOAD, DOWNLOAD.
Disposition string The status of the files proxied and scanned by Cisco Advanced Malware Protection (AMP) as part of the File Inspection feature. Valid values are: CLEAN, MALWARE, UNKNOWN.
DlpStatus string The verdict of the DLP scanning service.
EnforcedBy string The Secure Access component or service that enforced the policy or control related to this event (e.g., Firewall, Web Proxy).
FileAction string The action taken on a file in a remote browser isolation session.
FileName string The name of the file involved with the activity.
FileSize string The size of the file in bytes.
FileStaticAnalysis string The status of the file static sample analysis.
FileTypeId string The type of file. For example, PDF or MSEXE.
FirewallEventId string The ID of the firewall event. Populated only for traffic handled by Cisco Secure Firewall.
FtdEnforcementId string The unique identifier of the enforcement action taken by a Firepower Threat Defense (FTD) device integrated with Secure Access.
FtdEnforcementName string The name or type of enforcement action taken by a FTD device integrated with Secure Access (e.g., Malware Block, URL Category Block).
OrganizationId string The Secure Access organization ID.
RetentionPolicy string The number of days that AWS S3 stores your Secure Access File Events log.
Sha256 string The SHA-256 checksum hash of the file.
ThreatName string Name of the threat identified for files with MALWARE disposition.
ThreatScore string The threat score most recently associated with this file. This is a value from 0 to 100.
TimeGenerated datetime
Timestamp string The date and time of the request transaction, expressed as a UTC-formatted string.

Solutions (1)

This table is used by the following solutions:

Connectors (3)

This table is ingested by the following connectors:

Connector Selection Criteria
Cisco Umbrella (via Codeless Connector Framework)
Cisco Cloud Security
Cisco Cloud Security (using elastic premium plan)

Content Items Using This Table (21)

Analytic Rules (10)

GitHub Only:

Analytic Rule Selection Criteria
Cisco Cloud Security - Connection to Unpopular Website Detected
Cisco Cloud Security - Connection to non-corporate private network
Cisco Cloud Security - Crypto Miner User-Agent Detected
Cisco Cloud Security - Empty User Agent Detected
Cisco Cloud Security - Hack Tool User-Agent Detected
Cisco Cloud Security - Rare User Agent Detected
Cisco Cloud Security - Request Allowed to harmful/malicious URI category
Cisco Cloud Security - Request to blocklisted file type
Cisco Cloud Security - URI contains IP address
Cisco Cloud Security - Windows PowerShell User-Agent Detected

Hunting Queries (10)

In solution CiscoUmbrella:

Hunting Query Selection Criteria
Cisco Cloud Security - 'Blocked' User-Agents.
Cisco Cloud Security - Anomalous FQDNs for domain
Cisco Cloud Security - DNS Errors.
Cisco Cloud Security - DNS requests to unreliable categories.
Cisco Cloud Security - High values of Uploaded Data
Cisco Cloud Security - Higher values of count of the Same BytesIn size
Cisco Cloud Security - Possible connection to C2.
Cisco Cloud Security - Possible data exfiltration
Cisco Cloud Security - Proxy 'Allowed' to unreliable categories.
Cisco Cloud Security - Requests to uncategorized resources

Workbooks (1)

In solution CiscoUmbrella:

Workbook Selection Criteria
CiscoUmbrella

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
Cisco_Umbrella CiscoUmbrella

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index