Skip to content

Commit 16125ef

Browse files
authored
RA VPN - Secure Access push security events (#1161)
* adding new events * updating dataset
1 parent 3edb627 commit 16125ef

3 files changed

Lines changed: 18 additions & 1 deletion

File tree

datasets/cisco_secure_access/firewall/firewall.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,4 +30,4 @@ datasets:
3030
- name: smb
3131
path: /datasets/cisco_secure_access/firewall/smb.log
3232
source: cisco_cloud_security_addon
33-
sourcetype: cisco:cloud_security:firewall
33+
sourcetype: cisco:cloud_security:firewall
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Bhavin Patel, Splunk
2+
id: 8b2f4c1e-9a0d-4e8b-b7c3-1d2e3f4a5b6c
3+
date: '2026-04-27'
4+
description: |
5+
This dataset is based on the Cisco Secure Access RAVPN security event schema and the data here is generated from various simulated activities in a controlled lab environment.
6+
environment: custom
7+
directory: cisco_secure_access/ravpn
8+
mitre_technique:
9+
- T1110
10+
datasets:
11+
- name: ravpn_high_auth_failures
12+
path: /datasets/cisco_secure_access/ravpn/ravpn_high_auth_failures.log
13+
source: not_applicable
14+
sourcetype: cisco:secure_access:security_events_ravpn
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:97ad279dd45620c84cd4e51e25a5158c65d0d7a034e5f532bfc611fcff17391d
3+
size 47899

0 commit comments

Comments
 (0)