Parsers and Generated Fields

Tag Fields Created by Parser aruba-clearpass
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aruba-clearpass
Vendor FieldCPS FieldDescription
Vendor.DescriptionVendor.NADExtracts Network Access Device information
Vendor.DescriptionVendor.deviceExtracts device information for ReadDeviceInfo events
Vendor.DescriptionVendor.session_idExtracts session ID from Description field for session events
Vendor.Descriptionclient.ipExtracts client IP from Description field for login events
Vendor.Endpoint.IP-Addressclient.ipClient IP address using format function
Vendor.Endpoint.MAC-Addressclient.macClient MAC address using format function
Vendor.Descriptionerror.messageExtracts error messages for failed events
Vendor.Actionevent.actionAction taken in the event
Vendor.eventIdevent.idDirect mapping of event identifier
Vendor.Descriptionfile.nameExtracts filename for backup events
Vendor.RADIUS.Acct-NAS-IP-Addressobserver.ipObserver IP address from RADIUS accounting
Vendor.RADIUS.Acct-NAS-Portobserver.portObserver port from RADIUS accounting
Vendor.swVersionobserver.versionObserver software version
Vendor.Descriptionserver.addressExtracts server address for AD connection events
Vendor.CppmNode.CPPM-Nodeserver.ipServer IP address using format function
Vendor.RADIUS.Acct-Framed-IP-Addresssource.ipSource IP address from RADIUS accounting
Vendor.TACACS.Request-Typesource.ipSource IP address from TACACS when available
Vendor.WEBAUTH.Host-IP-Addresssource.ipSource IP address from web authentication
Vendor.Descriptionsource.ip,Extracts source IP and port for trap events
Vendor.Common.Username;user.name 
Vendor.Descriptionuser.nameExtracts username from Description field for login events
Vendor.Endpoint.Usernameuser.nameUsername from endpoint when RADIUS not available
Vendor.Endpoint.Username;user.name 
Vendor.RADIUS.Acct-Usernameuser.nameUsername from RADIUS accounting when available
Vendor.Common.Usernameuser.name,Extracts domain and username when in format domain/username
Vendor.Descriptionuser.roleExtracts user role from Description field for login events