Parsers and Generated Fields

Tag Fields Created by Parser akamai-asec
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser akamai-asec
Vendor FieldCPS FieldDescription
source.addressclient.addressCopies source address to client address
source.ipclient.ipCopies source IP to client IP
Vendor.httpMessage.requestIdevent.idMaps request ID to event ID
Vendor.httpMessage.requestIdhttp.request.idMaps HTTP request ID
Vendor.httpMessage.methodhttp.request.methodMaps HTTP method (GET, POST, etc.)
Vendor.httpMessage.byteshttp.response.bytesMaps HTTP response size in bytes
Vendor.httpMessage.statushttp.response.status_codeMaps HTTP status code
Vendor.httpMessage.protocolnetwork.protocol, Extracted using regex pattern `/^(?<network.protocol>\S+)\/(?<http.version>\S+)$/`
Vendor.attackData.clientIPsource.addressMaps client IP address
Vendor.geo.citysource.geo.city_nameMaps city name
Vendor.geo.countrysource.geo.country_iso_codeMaps country code
source.geo.country_iso_code,source.geo.region_iso_codeFormatted as "{country}-{region}" when both fields exist
source.addresssource.ipCopies source.address to source.ip
Vendor.httpMessage.tlstls.version_protocol, Extracted using regex pattern `/^(?<tls.version_protocol>\S+?)[vV](?<tls.version>\S+)$/`
Vendor.httpMessage.hosturl.domainConverted to lowercase
Vendor.httpMessage.pathurl.pathMaps URL path
Vendor.httpMessage.porturl.portMaps URL port
Vendor.httpMessage.queryurl.queryMaps URL query string