Skip to content

Releases: CiscoSecurity/fp-05-microsoft-sentinel-connector

v5.2.2 - Syntax in Default Cache File

02 Feb 21:22
0a6e84a
Compare
Choose a tag to compare

v5.2.1 - FMC 7.2 IDS Diposition Expansion and CEF Failure for IDS Events

Expanded disposition definitions for IDS events for 7.2, this addresses a bug that would cause the CEF adapter to fail due to values that were provided outside of the eStreamer specification

v5.2.2
Corrected Syntax error in default cache values

v5.1.6 Project Sync

01 Sep 17:23
12328e6
Compare
Choose a tag to compare

Syncing with core cli project at v5.1.6 for more information on release(s) please view the main project at https://github.com/CiscoSecurity/fp-05-firepower-cli

v5.1.0 - Fixed Malware events for 7.x

28 Apr 00:51
af1a1ee
Compare
Choose a tag to compare

Fixed an issue with malware and file events, record types 500 and 502. This effects 6.x and 7.x FMC versions. The issue was a bug within the Splunk adapter that did not convert the fileAnalysisStatus field properly.

Additionally, 7.0x requests for the newer event format for malware events were not implemented, still requesting the old format, now version 7 for malware events will retrieve block type 79 in the estreamer guide, which includes ingress and egress network routing information for malware and file events.

eStreamer 7.1 guide
https://www.cisco.com/c/en/us/td/docs/security/firepower/710/api/estreamer/EventStreamerIntegrationGuide.pdf

v5.0.0 - FMC 7.1 Support (Intrusion and Connection Events)

05 Feb 00:09
359205a
Compare
Choose a tag to compare

Implemented support for intrusion and connection events for new FMC 7.0/7.1 releases

Python3 - Initial Stable Release

21 Oct 18:23
a87943a
Compare
Choose a tag to compare

Initial release supporting Python3

Initial Stable Release

21 Oct 18:22
af341e7
Compare
Choose a tag to compare

Supports Python 2.7 - Reformatted CEF message outputs for Intrusion Events

Initial Stable Release

28 Sep 17:28
51fe3ea
Compare
Choose a tag to compare

Initial release of eNcore support for Microsoft Sentinel