Parsers and Generated Fields

Tag Fields Created by Parser aws-fsx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-fsx
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayNone
`client.ip`CopiedVendor.Event.EventData.IpAddress
`client.port`CopiedVendor.Event.EventData.IpPort
`event.id`CopiedVendor.Event.System.EventID
`file.path`CopiedVendor.Event.EventData.ObjectName
`file.type`CopiedVendor.Event.EventData.ObjectType
`process.pid`CopiedVendor.Event.System.Execution._ProcessID
`process.thread.id`CopiedVendor.Event.System.Execution._ThreadID
`user.id`CopiedVendor.Event.EventData.SubjectUserSid
`user.name`CopiedVendor.Event.EventData.SubjectUserName
`file.extension`ExtractedVendor.Event.EventData.ObjectName (indirect)
`file.name`ExtractedVendor.Event.EventData.ObjectName (indirect)
`event.action`MappedVendor.Event.System.EventID (indirect)
`@timestamp`ParsedVendor.Event.System.TimeCreated._SystemTime
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`user.domain`TransformedVendor.Event.EventData.SubjectDomainName
Vendor.Event.EventData.IpAddressclient.ip 
Vendor.Event.EventData.IpPortclient.port 
Vendor.Event.System.EventIDevent.id 
Vendor.Event.EventData.ObjectNamefile.path 
Vendor.Event.EventData.ObjectTypefile.type 
Vendor.Event.System.Execution._ProcessIDprocess.pid 
Vendor.Event.System.Execution._ThreadIDprocess.thread.id 
Vendor.Event.EventData.SubjectUserSiduser.id 
Vendor.Event.EventData.SubjectUserNameuser.name