CiscoSecurity / fp-05-firepower-cli

Public Repo for an eStreamer CLI project
10 stars 8 forks source link

OCSF - Incorrect mappings for "Other" enumerations #22

Open floydtree opened 7 months ago

floydtree commented 7 months ago

Hey team, wanted to flag a few incorrect mappings in this transformation file Example snippet from your repo - Screenshot 2024-03-01 at 11 54 25

All the Other values seem to be incorrectly mapped to -1, that's not compliant with OCSF's definitions. Other values should be mapped to 99

For reference, here's a snippet of of activity_id in the Network Activity event class in OCSF.

Screenshot 2024-03-01 at 11 49 57

It appears there are a few more occurrences of the same issue in that mapping file. It would be great if all the occurrences can be rectified.