Parsers and Generated Fields
Tag Fields Created by Parser akamai-asec
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser akamai-asec
| Vendor Field | CPS Field | Description |
|---|---|---|
| `event.category[]` | Array | None |
| `event.type[]` | Array | event.action, http.response.status_code |
| `client.address` | Copied | source.address (indirect) |
| `client.as.number` | Copied | source.as.number (indirect) |
| `client.geo.city_name` | Copied | source.geo.city_name (indirect) |
| `client.geo.country_iso_code` | Copied | source.geo.country_iso_code (indirect) |
| `client.geo.region_iso_code` | Copied | source.geo.region_iso_code (indirect) |
| `client.ip` | Copied | source.ip (indirect) |
| `destination.address` | Copied | Vendor.httpMessage.host |
| `destination.domain` | Copied | destination.address (indirect) |
| `destination.port` | Copied | Vendor.httpMessage.port |
| `event.action` | Copied | Vendor.attackData.ruleActions.decoded |
| `event.id` | Copied | Vendor.httpMessage.requestId |
| `http.request.id` | Copied | Vendor.httpMessage.requestId |
| `http.request.method` | Copied | Vendor.httpMessage.method |
| `http.response.bytes` | Copied | Vendor.httpMessage.bytes |
| `http.response.status_code` | Copied | Vendor.httpMessage.status |
| `network.bytes` | Copied | Vendor.httpMessage.bytes |
| `rule.category` | Copied | Vendor.attackData.ruleTags.decoded |
| `rule.id` | Copied | Vendor.attackData.rules.decoded |
| `rule.name` | Copied | Vendor.attackData.ruleMessages.decoded |
| `rule.version` | Copied | Vendor.attackData.ruleVersions.decoded |
| `server.address` | Copied | destination.address (indirect) |
| `server.domain` | Copied | destination.domain (indirect) |
| `server.port` | Copied | destination.port (indirect) |
| `source.address` | Copied | Vendor.attackData.clientIP |
| `source.as.number` | Copied | Vendor.geo.asn |
| `source.geo.city_name` | Copied | Vendor.geo.city |
| `source.geo.country_iso_code` | Copied | Vendor.geo.country |
| `url.domain` | Copied | Vendor.httpMessage.host |
| `url.path` | Copied | Vendor.httpMessage.path |
| `url.port` | Copied | Vendor.httpMessage.port |
| `url.query` | Copied | Vendor.httpMessage.query |
| `http.request.bytes` | Extracted | Vendor.httpMessage.requestHeaders.Content-Length |
| `http.request.mime_type` | Extracted | Vendor.httpMessage.requestHeaders.Content-Type |
| `http.request.referrer` | Extracted | Vendor.httpMessage.requestHeaders.Referer |
| `http.response.mime_type` | Extracted | Vendor.httpMessage.responseHeaders.Content-Type |
| `http.version` | Extracted | Vendor.httpMessage.protocol |
| `network.protocol` | Extracted | Vendor.httpMessage.protocol |
| `tls.version_protocol` | Extracted | Vendor.httpMessage.tls |
| `tls.version` | Extracted | Vendor.httpMessage.tls |
| `user_agent.original` | Extracted | Vendor.httpMessage.requestHeaders.User-Agent |
| `source.geo.region_iso_code` | Formatted | source.geo.country_iso_code, Vendor.geo.regionCode |
| `@timestamp` | Parsed | Vendor.httpMessage.start |
| `network.type` | Set | source.address (indirect) |
| `source.ip` | Set | source.address (indirect) |
| `ecs.version` | Static | None |
| `event.kind` | Static | None |
| `event.module` | Static | None |
| `event.outcome` | Static | None |
| source.address | client.address | |
| source.as.number | client.as.number | |
| source.geo.city_name | client.geo.city_name | |
| source.geo.country_iso_code | client.geo.country_iso_code | |
| source.geo.region_iso_code | client.geo.region_iso_code | |
| source.ip | client.ip | |
| destination.address | destination.domain | |
| Vendor.httpMessage.port | destination.port | |
| Vendor.attackData.ruleActions.decoded | event.action | |
| Vendor.httpMessage.requestId | event.id | |
| Vendor.httpMessage.requestId | http.request.id | |
| Vendor.httpMessage.method | http.request.method | |
| Vendor.httpMessage.bytes | http.response.bytes | |
| Vendor.httpMessage.status | http.response.status_code | |
| Vendor.httpMessage.bytes | network.bytes | |
| Vendor.attackData.ruleTags.decoded | rule.category | |
| Vendor.attackData.rules.decoded | rule.id | |
| Vendor.attackData.ruleMessages.decoded | rule.name | |
| Vendor.attackData.ruleVersions.decoded | rule.version | |
| destination.address | server.address | |
| destination.domain | server.domain | |
| destination.port | server.port | |
| Vendor.geo.asn | source.as.number | |
| Vendor.geo.city | source.geo.city_name | |
| Vendor.geo.country | source.geo.country_iso_code | |
| source.address | source.ip | |
| Vendor.httpMessage.path | url.path | |
| Vendor.httpMessage.port | url.port | |
| Vendor.httpMessage.query | url.query |