Parsers and Generated Fields

Tag Fields Created by Parser aws-fsx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-fsx
Source FieldCPS FieldDescriptionMapping
Vendor.Event.System.TimeCreated._SystemTime@timestampEvent timestampParsed from Vendor.Event.System.TimeCreated._SystemTime using parseTimestamp()
Vendor.Event.EventData.IpAddressclient.ipClient IP addressCopied from Vendor.Event.EventData.IpAddress
Vendor.Event.EventData.IpPortclient.portClient port numberCopied from Vendor.Event.EventData.IpPort
Noneecs.versionECS schema versionStatic value: 8.17.0
Vendor.Event.System.EventID (indirect)event.actionHuman readable event actionMapped based on event.id using match conditions
Noneevent.category[]Event category arrayArray populated with ["file"]
Vendor.Event.System.EventIDevent.idWindows event IDCopied from Vendor.Event.System.EventID
Noneevent.kindEvent categorizationStatic value: event
Noneevent.moduleEvent module identifierStatic value: fsx
Noneevent.type[]Event type arrayArray populated with ["info"]
Vendor.Event.EventData.ObjectName (indirect)file.extensionFile extensionExtracted from file.name using regex pattern
Vendor.Event.EventData.ObjectName (indirect)file.nameFile nameExtracted from file.path using regex pattern
Vendor.Event.EventData.ObjectNamefile.pathFile pathCopied from Vendor.Event.EventData.ObjectName
Vendor.Event.EventData.ObjectTypefile.typeFile object typeCopied from Vendor.Event.EventData.ObjectType
Vendor.Event.System.Execution._ProcessIDprocess.pidProcess identifierCopied from Vendor.Event.System.Execution._ProcessID
Vendor.Event.System.Execution._ThreadIDprocess.thread.idThread identifierCopied from Vendor.Event.System.Execution._ThreadID
Vendor.Event.EventData.SubjectDomainNameuser.domainUser domain nameTransformed from Vendor.Event.EventData.SubjectDomainName using lower()
Vendor.Event.EventData.SubjectUserSiduser.idUser security identifierCopied from Vendor.Event.EventData.SubjectUserSid
Vendor.Event.EventData.SubjectUserNameuser.nameUsernameCopied from Vendor.Event.EventData.SubjectUserName