Parsers and Generated Fields

Tag Fields Created by Parser akamai-asec
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser akamai-asec
Source FieldCPS Field
source.addressclient.address
source.ipclient.ip
Vendor.httpMessage.requestIdevent.id
Vendor.httpMessage.requestIdhttp.request.id
Vendor.httpMessage.methodhttp.request.method
Vendor.httpMessage.byteshttp.response.bytes
Vendor.httpMessage.statushttp.response.status_code
Vendor.attackData.clientIPsource.address
Vendor.geo.citysource.geo.city_name
Vendor.geo.countrysource.geo.country_iso_code
source.addresssource.ip
Vendor.httpMessage.pathurl.path
Vendor.httpMessage.porturl.port
Vendor.httpMessage.queryurl.query
Tag Fields Created by Parser asec-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser asec-json
Source FieldCPS Field
source.addressclient.address
source.ipclient.ip
Vendor.httpMessage.requestIdevent.id
Vendor.httpMessage.requestIdhttp.request.id
Vendor.httpMessage.methodhttp.request.method
Vendor.httpMessage.byteshttp.response.bytes
Vendor.httpMessage.statushttp.response.status_code
Vendor.attackData.clientIPsource.address
Vendor.geo.citysource.geo.city_name
Vendor.geo.countrysource.geo.country_iso_code
source.addresssource.ip
Vendor.httpMessage.pathurl.path
Vendor.httpMessage.porturl.port
Vendor.httpMessage.queryurl.query