Parsers and Generated Fields

Tag Fields Created by Parser cisco-duo
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-duo
Source FieldCPS Field
Vendor.description.hostnameclient.address
Vendor.description.ip_addressclient.ip
Vendor.enabled_for.keydestination.user.id
Vendor.enabled_for.namedestination.user.name
Vendor.actionevent.action
Vendor.action.nameevent.action
Vendor.contextevent.action
Vendor.event_typeevent.action
Vendor.typeevent.action
Vendor.activity_idevent.id
Vendor.sekeyevent.id
Vendor.telephony_idevent.id
Vendor.reasonevent.reason
Vendor.surfaced_auth.reasonevent.reason
Vendor.applicationsnetwork.application
Vendor.access_device.hostnamesource.address
Vendor.surfaced_auth.access_device.hostnamesource.address
Vendor.access_device.location.citysource.geo.city_name
Vendor.surfaced_auth.access_device.location.citysource.geo.city_name
Vendor.access_device.location.countrysource.geo.country_name
Vendor.surfaced_auth.access_device.location.countrysource.geo.country_name
Vendor.access_device.location.statesource.geo.region_name
Vendor.surfaced_auth.access_device.location.statesource.geo.region_name
Vendor.access_device.ipsource.ip
Vendor.surfaced_auth.access_device.ipsource.ip
Vendor.access_device.portsource.port
Vendor.emailsource.user.email
Vendor.surfaced_auth.emailsource.user.email
Vendor.enabled_by.keysource.user.id
Vendor.surfaced_auth.user.keysource.user.id
Vendor.user.keysource.user.id
Vendor.enabled_by.namesource.user.name
Vendor.surfaced_auth.user.namesource.user.name
Vendor.user.namesource.user.name
url.domainurl.domain
Vendor.triage_event_uriurl.original
Vendor.description.emailuser.changes.email
Vendor.description.realnameuser.changes.name
Vendor.description.emailuser.email
Vendor.usernameuser.full_name
Vendor.actor.details.group.nameuser.group.name
Vendor.actor.keyuser.id
Vendor.actor.nameuser.name
Vendor.description.admin_emailuser.name
Vendor.description.unameuser.name
Vendor.objectuser.target.name
Vendor.access_device.browseruser_agent.name
Vendor.surfaced_auth.access_device.browseruser_agent.name
Vendor.description.user_agentuser_agent.original
Vendor.access_device.osuser_agent.os.name
Vendor.surfaced_auth.access_device.osuser_agent.os.name
Vendor.access_device.os_versionuser_agent.os.version
Vendor.surfaced_auth.access_device.os_versionuser_agent.os.version
Vendor.access_device.browser_versionuser_agent.version
Vendor.surfaced_auth.access_device.browser_versionuser_agent.version
Tag Fields Created by Parser duo-activity-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-activity-json
Source FieldCPS Field
Vendor.actionevent.action
Vendor.activity_idevent.id
Vendor.access_device.location.citysource.geo.city_name
Vendor.access_device.location.countrysource.geo.country_name
Vendor.access_device.location.statesource.geo.region_name
Vendor.access_device.ipsource.ip
Vendor.access_device.portsource.port
Vendor.access_device.browsersource.user_agent.name
Vendor.access_device.ossource.user_agent.os.name
Vendor.access_device.os_versionsource.user_agent.os.version
Vendor.access_device.browser_versionsource.user_agent.version
Vendor.actor.details.group.nameuser.group.name
Vendor.actor.keyuser.id
Vendor.actor.nameuser.name
Tag Fields Created by Parser duo-admin-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-admin-json
Source FieldCPS Field
Vendor.actionevent.action
Vendor.description.email;user.changes.email
Vendor.description.realnameuser.changes.name
Vendor.description.email;user.email
Vendor.usernameuser.name
Vendor.objectuser.target.name
Tag Fields Created by Parser duo-authentication-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-authentication-json
Source FieldCPS Field
Vendor.reasonevent.reason
Vendor.access_device.location.citysource.geo.city_name
Vendor.access_device.location.countrysource.geo.country_name
Vendor.access_device.location.statesource.geo.region_name
Vendor.access_device.ipsource.ip
Vendor.access_device.portsource.port
Vendor.emailsource.user.email
Vendor.user.groupsource.user.group.name
Vendor.user.keysource.user.id
Vendor.user.namesource.user.name
Vendor.access_device.browsersource.user_agent.name
Vendor.access_device.ossource.user_agent.os.name
Vendor.access_device.os_versionsource.user_agent.os.version
Vendor.access_device.browser_versionsource.user_agent.version
Tag Fields Created by Parser duo-telephony-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-telephony-json
Source FieldCPS Field
Vendor.contextevent.action
Vendor.telephony_idevent.id
Tag Fields Created by Parser duo-trustmonitor-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-trustmonitor-json
Source FieldCPS Field
Vendor.enabled_for.key;destination.user.id
Vendor.enabled_for.namedestination.user.name
Vendor.sekeyevent.id
Vendor.surfaced_auth.reasonevent.reason
Vendor.surfaced_auth.access_device.location.citysource.geo.city_name
Vendor.surfaced_auth.access_device.location.countrysource.geo.country_name
Vendor.surfaced_auth.access_device.location.statesource.geo.region_name
Vendor.surfaced_auth.access_device.ipsource.ip
Vendor.surfaced_auth.emailsource.user.email
Vendor.enabled_by.keysource.user.id
Vendor.surfaced_auth.user.keysource.user.id
Vendor.enabled_by.namesource.user.name
Vendor.surfaced_auth.user.namesource.user.name
Vendor.surfaced_auth.access_device.browsersource.user_agent.name
Vendor.surfaced_auth.access_device.ossource.user_agent.os.name
Vendor.surfaced_auth.access_device.os_versionsource.user_agent.os.version
Vendor.surfaced_auth.access_device.browser_versionsource.user_agent.version
Vendor.triage_event_uriurl.original