Parsers and Generated Fields

Tag Fields Created by Parser asimily-iomt
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser asimily-iomt
Source FieldCPS FieldDescriptionMapping
Vendor.dateTime@timestampTimestamp when event was sent from Asimily to LogScaleParsed from Vendor.dateTime using parseTimestamp()
Vendor.manufacturerdevice.manufacturerDevice manufacturer nameCopied from Vendor.manufacturer
Vendor.deviceModeldevice.model.identifierDevice model nameCopied from Vendor.deviceModel
Noneecs.versionECS schema versionStatic value: 8.17.0
Noneevent.category[]Event category classificationArray populated with static value "vulnerability"
Vendor.alertIdevent.idAlert identifierCopied from Vendor.alertId
Noneevent.kindEvent kind classificationStatic value: event
Noneevent.moduleModule identifierStatic value: iomt
Vendor.contextevent.reasonDescription of the anomaly eventCopied from Vendor.context
Noneevent.type[]Event type classificationArray populated with static value "info"
Vendor.ipAddresshost.ip[]IP address of the deviceArray populated with Vendor.ipAddress
Vendor.macAddresshost.mac[0]MAC address of the deviceTransformed from Vendor.macAddress (replace colons with dashes, uppercase)
Vendor.oshost.os.nameOperating system of the deviceCopied from Vendor.os