Parsers and Generated Fields

Tag Fields Created by Parser aruba-clearpass
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aruba-clearpass
Vendor FieldCPS FieldDescription
Vendor.Endpoint.IP-Addressclient.ipDirect mapping
Vendor.Endpoint.MAC-Addressclient.macDirect mapping
Vendor.eventIdevent.idDirect mapping
Vendor.eventIdevent.id  
Vendor.RADIUS.Acct-NAS-IP-Addressobserver.ipDirect mapping
Vendor.RADIUS.Acct-NAS-Portobserver.portDirect mapping
Vendor.swVersionobserver.versionDirect mapping
Vendor.CppmNode.CPPM-Nodeserver.ipDirect mapping
Vendor.RADIUS.Acct-Framed-IP-Addresssource.ipDirect mapping
Vendor.Common.Username;user.name 
Vendor.Endpoint.Usernameuser.nameWhen Endpoint.Username exists
Vendor.RADIUS.Acct-Usernameuser.nameWhen RADIUS.Acct-Username exists
Vendor.Endpoint.Usernameuser.name  
Vendor.Common.Usernameuser.name, user.domainExtracts domain and username when in format domain/username
Tag Fields Created by Parser clearpass-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser clearpass-syslog
Vendor FieldCPS FieldDescription
Vendor.eventIdevent.id 
Vendor.Endpoint.Username;user.name