Parsers and Generated Fields

Tag Fields Created by Parser asec-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser asec-json
Source FieldLogScale Repository Field
source.addressclient.address
source.ipclient.ip
Vendor.geo.countrycode
Vendor.httpMessage.statuscode
Vendor.httpMessage.requestIdevent.id
Vendor.httpMessage.requestIdhttp.request.id
Vendor.httpMessage.methodhttp.request.method
Vendor.httpMessage.byteshttp.response.bytes
Vendor.geo.cityname
Vendor.attackData.clientIPsource.address
source.addresssource.ip
Vendor.httpMessage.pathurl.path
Vendor.httpMessage.porturl.port
Vendor.httpMessage.queryurl.query