Parsers and Generated Fields

Tag Fields Created by Parser duo-activity-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-activity-json
Source FieldLogScale Repository Field
Vendor.accessagent.name
Vendor.accessagent.os.name
Vendor.accessagent.os.version
Vendor.accessagent.version
Vendor.actionevent.action
Vendor.activityevent.id
Vendor.accessname
Vendor.accesssource.ip
Vendor.accesssource.port
Vendor.actor.details.group.nameuser.group.name
Vendor.actor.keyuser.id
Vendor.actor.nameuser.name
Tag Fields Created by Parser duo-admin-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-admin-json
Source FieldLogScale Repository Field
Vendor.actionevent.action
Vendor.description.emailuser.changes.email
Vendor.description.realnameuser.changes.name
Vendor.description.emailuser.email
Vendor.usernameuser.name
Vendor.objectuser.target.name
Tag Fields Created by Parser duo-authentication-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-authentication-json
Source FieldLogScale Repository Field
Vendor.accessagent.name
Vendor.accessagent.os.name
Vendor.accessagent.os.version
Vendor.accessagent.version
Vendor.reasonevent.reason
Vendor.accessname
Vendor.accesssource.ip
Vendor.accesssource.port
Vendor.emailsource.user.email
Vendor.user.groupsource.user.group.name
Vendor.user.keysource.user.id
Vendor.user.namesource.user.name
Tag Fields Created by Parser duo-telephony-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-telephony-json
Source FieldLogScale Repository Field
Vendor.contextevent.action
Vendor.telephonyevent.id
Tag Fields Created by Parser duo-trustmonitor-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser duo-trustmonitor-json
Source FieldLogScale Repository Field
Vendor.surfacedagent.name
Vendor.surfacedagent.os.name
Vendor.surfacedagent.os.version
Vendor.surfacedagent.version
Vendor.enableddestination.user.id
Vendor.enableddestination.user.name
Vendor.sekeyevent.id
Vendor.surfacedevent.reason
Vendor.surfacedname
Vendor.surfacedsource.ip
Vendor.surfacedsource.user.email
Vendor.enabledsource.user.id
Vendor.surfacedsource.user.id
Vendor.enabledsource.user.name
Vendor.surfacedsource.user.name
Vendor.triageurl.original