Parsers and Generated Fields

Tag Fields Created by Parser fsx-xml
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fsx-xml
Source FieldLogScale Repository Field
Vendor.Event.EventData.IpAddressclient.ip
Vendor.Event.EventData.IpPortclient.port
Vendor.Event.System.EventIDevent.id
Vendor.Event.EventData.ObjectNamefile.path
Vendor.Event.EventData.ObjectTypefile.type
Vendor.Event.System.Execution.process.pid
Vendor.Event.System.Execution.process.thread.id
Vendor.Event.EventData.SubjectUserSiduser.id
Vendor.Event.EventData.SubjectUserNameuser.name