Parsers and Generated Fields

Tag Fields Created by Parser aws-vpcflow
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-vpcflow
Vendor FieldCPS FieldDescription
Vendor.dstaddrdestination.address  
destination.addressdestination.ip 
Vendor.dstportdestination.port  
Vendor.actionevent.action  
Vendor.endevent.end  
Vendor.startevent.start  
Vendor.bytesnetwork.bytes  
Vendor.protocolnetwork.iana_number  
Vendor.packetsnetwork.packets  
Vendor.typenetwork.type  
Vendor.srcaddrsource.address  
source.addresssource.ip 
Vendor.srcportsource.port