Parsers and Generated Fields

Tag Fields Created by Parser cisco-duo
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-duo
Vendor FieldCPS FieldDescription
Vendor.access_device.hostnameclient.domainAccess device hostname (activity/authentication logs)
Vendor.description.hostnameclient.domainClient hostname (administrator logs)
Vendor.surfaced_auth.access_device.hostnameclient.domainTrustMonitor access device hostname
Vendor.access_device.location.cityclient.geo.city_nameCity name from access device (activity/authentication logs)
Vendor.surfaced_auth.access_device.location.cityclient.geo.city_nameTrustMonitor city name
Vendor.access_device.location.countryclient.geo.country_nameCountry name from access device (activity/authentication logs)
Vendor.surfaced_auth.access_device.location.countryclient.geo.country_nameTrustMonitor country name
Vendor.access_device.location.stateclient.geo.region_nameState/region from access device (activity/authentication logs)
Vendor.surfaced_auth.access_device.location.stateclient.geo.region_nameTrustMonitor state/region
Vendor.access_device.ipclient.ipAccess device IP (authentication logs)
Vendor.access_device.ip.addressclient.ipAccess device IP address (activity logs)
Vendor.description.ip_addressclient.ipClient IP address (administrator logs)
Vendor.surfaced_auth.access_device.ipclient.ipTrustMonitor access device IP
Vendor.access_device.portclient.portAccess device port (activity logs)
Vendor.description.errorerror.messageError message (administrator logs)
Vendor.actionevent.actionAdministrator log action
Vendor.action.nameevent.actionActivity log action name (coalesced with Vendor.action)
Vendor.contextevent.actionTelephony log context
Vendor.event_typeevent.actionAuthentication log event type
Vendor.typeevent.actionTrustMonitor event type
Vendor.activity_idevent.idActivity log event identifier
Vendor.sekeyevent.idTrustMonitor event identifier
Vendor.telephony_idevent.idTelephony log event identifier
Vendor.outcome.resultevent.outcomeActivity log result (SUCCESS/FAILURE)
Vendor.resultevent.outcomeAuthentication result (success/denied/fraud)
Vendor.surfaced_auth.resultevent.outcomeTrustMonitor authentication result
Vendor.reasonevent.reasonAuthentication failure reason
Vendor.surfaced_auth.reasonevent.reasonTrustMonitor authentication reason
Vendor.triage_event_urievent.urlTrustMonitor triage event URI
Vendor.applicationsnetwork.applicationNetwork application (lowercased, authentication logs)
Vendor.hostobserver.nameHost/observer name (authentication/administrator logs)
client.addresssource.address 
Vendor.access_device.hostnamesource.domainAccess device hostname (activity/authentication logs)
Vendor.description.hostnamesource.domainClient hostname (administrator logs)
Vendor.surfaced_auth.access_device.hostnamesource.domainTrustMonitor access device hostname
client.domainsource.domain 
Vendor.access_device.location.citysource.geo.city_nameCity name from access device (activity/authentication logs)
Vendor.surfaced_auth.access_device.location.citysource.geo.city_nameTrustMonitor city name
client.geo.city_namesource.geo.city_name 
Vendor.access_device.location.countrysource.geo.country_nameCountry name from access device (activity/authentication logs)
Vendor.surfaced_auth.access_device.location.countrysource.geo.country_nameTrustMonitor country name
client.geo.country_namesource.geo.country_name 
Vendor.access_device.location.statesource.geo.region_nameState/region from access device (activity/authentication logs)
Vendor.surfaced_auth.access_device.location.statesource.geo.region_nameTrustMonitor state/region
client.geo.region_namesource.geo.region_name 
Vendor.access_device.ipsource.ipAccess device IP (authentication logs)
Vendor.access_device.ip.addresssource.ipAccess device IP address (activity logs)
Vendor.description.ip_addresssource.ipClient IP address (administrator logs)
Vendor.surfaced_auth.access_device.ipsource.ipTrustMonitor access device IP
client.ipsource.ip 
Vendor.access_device.portsource.portAccess device port (activity logs)
url.hosturl.domain  
Vendor.triage_event_uriurl.originalTrustMonitor triage event URI (also mapped to url.original)
Vendor.enabled_by.keyuser.effective.idEffective user ID (who enabled)
Vendor.enabled_by.nameuser.effective.nameEffective user name (who enabled)
Vendor.actor.details.emailuser.emailActor email (activity logs)
Vendor.description.emailuser.emailUser email (for non-user_/bypass_ events)
Vendor.emailuser.emailUser email (authentication logs)
Vendor.surfaced_auth.emailuser.emailTrustMonitor user email
Vendor.usernameuser.full_nameAdministrator full name
Vendor.actor.details.group.nameuser.group.nameActor group name (activity logs)
Vendor.actor.keyuser.idActor user key (activity logs)
Vendor.surfaced_auth.user.keyuser.idTrustMonitor user key
Vendor.user.keyuser.idUser key/ID (authentication logs)
Vendor.actor.nameuser.nameActor username (activity logs)
Vendor.objectuser.nameUser name (for non-user_/bypass_ events)
Vendor.surfaced_auth.user.nameuser.nameTrustMonitor username
Vendor.user.nameuser.nameUsername (authentication logs)
Vendor.user.groups[]user.roles[]User group roles (authentication logs)
Vendor.description.emailuser.target.emailTarget email (for user_/bypass_ events)
Vendor.target.details.emailuser.target.emailTarget email (when target.type = "user")
Vendor.target.keyuser.target.emailTarget key as email (when target.type = "user")
Vendor.description.realnameuser.target.full_nameTarget real name (for user_/bypass_ events)
Vendor.target.details.realnameuser.target.full_nameTarget real name (when target.type = "user")
Vendor.enabled_for.keyuser.target.idTarget user ID (enabled for)
Vendor.description.unameuser.target.nameTarget username (for user_/bypass_ events)
Vendor.enabled_for.nameuser.target.nameTarget user name (enabled for)
Vendor.target.details.unameuser.target.nameTarget username (when target.type = "user")
x.nameuser.target.roles 
Vendor.description.groups[].nameuser.target.roles[]Target user roles (for user_/bypass_ events)
Vendor.access_device.browseruser_agent.nameBrowser name (activity/authentication logs)
Vendor.surfaced_auth.access_device.browseruser_agent.nameTrustMonitor browser name
Vendor.description.user_agentuser_agent.originalOriginal user agent string (administrator logs)
Vendor.access_device.osuser_agent.os.nameOperating system name (activity/authentication logs)
Vendor.surfaced_auth.access_device.osuser_agent.os.nameTrustMonitor operating system
Vendor.access_device.os_versionuser_agent.os.versionOperating system version (activity/authentication logs)
Vendor.surfaced_auth.access_device.os_versionuser_agent.os.versionTrustMonitor OS version
Vendor.access_device.browser_versionuser_agent.versionBrowser version (activity/authentication logs)
Vendor.surfaced_auth.access_device.browser_versionuser_agent.versionTrustMonitor browser version