Parsers and Generated Fields

Tag Fields Created by Parser aruba-clearpass
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aruba-clearpass
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.Category
`event.type[]`ArrayVendor.Action, Vendor.Category
`event.action`CopiedVendor.Action
`event.id`CopiedVendor.eventId
`observer.version`CopiedVendor.swVersion
`event.outcome`DeterminedVendor.Action
`client.ip`ExtractedVendor.Endpoint.IP-Address, Vendor.Description
`client.mac`ExtractedVendor.Endpoint.MAC-Address
`error.message`ExtractedVendor.Description
`file.name`ExtractedVendor.Description
`observer.ip`ExtractedVendor.RADIUS.Acct-NAS-IP-Address
`observer.port`ExtractedVendor.RADIUS.Acct-NAS-Port
`server.address`ExtractedVendor.Description
`server.ip`ExtractedVendor.CppmNode.CPPM-Node
`source.ip`ExtractedVendor.RADIUS.Acct-Framed-IP-Address, Vendor.TACACS.Request-Type, Vendor.WEBAUTH.Host-IP-Address, Vendor.Description
`source.port`ExtractedVendor.Description
`user.domain`ExtractedVendor.Common.Username
`user.name`ExtractedVendor.RADIUS.Acct-Username, Vendor.Endpoint.Username, Vendor.Common.Username, Vendor.Description
`user.role`ExtractedVendor.Description
`@timestamp`Parsed@timestamp
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.Actionevent.action 
Vendor.eventIdevent.id 
Vendor.swVersionobserver.version