Parsers and Generated Fields

Tag Fields Created by Parser aws-fsx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-fsx
Source FieldCPS Field
Vendor.Event.EventData.IpAddressclient.ip
Vendor.Event.EventData.IpPortclient.port
Vendor.Event.System.EventIDevent.id
Vendor.Event.EventData.ObjectNamefile.path
Vendor.Event.EventData.ObjectTypefile.type
Vendor.Event.System.Execution._ProcessIDprocess.pid
Vendor.Event.System.Execution._ThreadIDprocess.thread.id
Vendor.Event.EventData.SubjectUserSiduser.id
Vendor.Event.EventData.SubjectUserNameuser.name
Tag Fields Created by Parser fsx-xml
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fsx-xml
Source FieldCPS Field
Vendor.Event.EventData.IpAddressclient.ip
Vendor.Event.EventData.IpPortclient.port
Vendor.Event.System.EventIDevent.id
Vendor.Event.EventData.ObjectNamefile.path
Vendor.Event.EventData.ObjectTypefile.type
Vendor.Event.System.Execution._ProcessIDprocess.pid
Vendor.Event.System.Execution._ThreadIDprocess.thread.id
Vendor.Event.EventData.SubjectUserSiduser.id
Vendor.Event.EventData.SubjectUserNameuser.name