Parsers and Generated Fields
Tag Fields Created by Parser akamai-asec
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser akamai-asec
Vendor Field | CPS Field | Description |
---|---|---|
`client.address` | Copied | source.address (indirect) |
`client.ip` | Copied | source.ip (indirect) |
`event.id` | Copied | Vendor.httpMessage.requestId |
`http.request.id` | Copied | Vendor.httpMessage.requestId |
`http.request.method` | Copied | Vendor.httpMessage.method |
`http.response.bytes` | Copied | Vendor.httpMessage.bytes |
`http.response.status_code` | Copied | Vendor.httpMessage.status |
`source.address` | Copied | Vendor.attackData.clientIP |
`source.geo.city_name` | Copied | Vendor.geo.city |
`source.geo.country_iso_code` | Copied | Vendor.geo.country |
`source.ip` | Copied | source.address (indirect) |
`url.domain` | Copied | Vendor.httpMessage.host |
`url.path` | Copied | Vendor.httpMessage.path |
`url.port` | Copied | Vendor.httpMessage.port |
`url.query` | Copied | Vendor.httpMessage.query |
`http.version` | Extracted | Vendor.httpMessage.protocol |
`network.protocol` | Extracted | Vendor.httpMessage.protocol |
`tls.version_protocol` | Extracted | Vendor.httpMessage.tls |
`tls.version` | Extracted | Vendor.httpMessage.tls |
`source.geo.region_iso_code` | Formatted | source.geo.country_iso_code, Vendor.geo.regionCode |
`@timestamp` | Parsed | Vendor.httpMessage.start |
`ecs.version` | Static | None |
`event.category[]` | Static | None |
`event.kind` | Static | None |
`event.module` | Static | None |
`event.type[]` | Static | None |
source.address | client.address | |
source.ip | client.ip | |
Vendor.httpMessage.requestId | event.id | |
Vendor.httpMessage.requestId | http.request.id | |
Vendor.httpMessage.method | http.request.method | |
Vendor.httpMessage.bytes | http.response.bytes | |
Vendor.httpMessage.status | http.response.status_code | |
Vendor.attackData.clientIP | source.address | |
Vendor.geo.city | source.geo.city_name | |
Vendor.geo.country | source.geo.country_iso_code | |
source.address | source.ip | |
Vendor.httpMessage.path | url.path | |
Vendor.httpMessage.port | url.port | |
Vendor.httpMessage.query | url.query |