Parsers and Generated Fields

Tag Fields Created by Parser aws-vpcflow
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser aws-vpcflow
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayVendor.action
`destination.address`CopiedVendor.dstaddr
`destination.ip`CopiedVendor.dstaddr (indirect)
`destination.port`CopiedVendor.dstport
`event.action`CopiedVendor.action
`event.end`CopiedVendor.end
`event.start`CopiedVendor.start
`network.bytes`CopiedVendor.bytes
`network.iana_number`CopiedVendor.protocol
`network.packets`CopiedVendor.packets
`source.address`CopiedVendor.srcaddr
`source.ip`CopiedVendor.srcaddr (indirect)
`source.port`CopiedVendor.srcport
`cloud.account.id`FormattedVendor.account-id
`observer.ingress.interface.id`FormattedVendor.interface-id
`error.message`LowercaseVendor.log-status
`event.outcome`MappedVendor.action
`@timestamp`ParsedVendor.start
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.dstaddrdestination.address 
destination.addressdestination.ip 
Vendor.dstportdestination.port 
Vendor.actionevent.action 
Vendor.endevent.end 
Vendor.startevent.start 
Vendor.bytesnetwork.bytes 
Vendor.protocolnetwork.iana_number 
Vendor.packetsnetwork.packets 
Vendor.typenetwork.type 
Vendor.srcaddrsource.address 
source.addresssource.ip 
Vendor.srcportsource.port