Parsers and Generated Fields
Tag Fields Created by Parser cisco-duo
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser cisco-duo
| Source Field | CPS Field | Description | Mapping |
|---|---|---|---|
| Browser name (activity/authentication logs) | Vendor.access_device.browser | Â | user_agent.name |
| Browser version (activity/authentication logs) | Vendor.access_device.browser_version | Â | user_agent.version |
| Access device hostname (activity/authentication logs) | Vendor.access_device.hostname | Â | source.domain |
| Access device IP (authentication logs) | Vendor.access_device.ip | Â | source.ip |
| Access device IP address (activity logs) | Vendor.access_device.ip.address | Â | source.ip |
| City name from access device (activity/authentication logs) | Vendor.access_device.location.city | Â | source.geo.city_name |
| Country name from access device (activity/authentication logs) | Vendor.access_device.location.country | Â | source.geo.country_name |
| State/region from access device (activity/authentication logs) | Vendor.access_device.location.state | Â | source.geo.region_name |
| Operating system name (activity/authentication logs) | Vendor.access_device.os | Â | user_agent.os.name |
| Operating system version (activity/authentication logs) | Vendor.access_device.os_version | Â | user_agent.os.version |
| Access device port (activity logs) | Vendor.access_device.port | Â | source.port |
| Administrator log action | Vendor.action | Â | event.action |
| Activity log action name (coalesced with Vendor.action) | Vendor.action.name | Â | event.action |
| Activity log event identifier | Vendor.activity_id | Â | event.id |
| Actor email (activity logs) | Vendor.actor.details.email | Â | user.email |
| Actor group name (activity logs) | Vendor.actor.details.group.name | Â | user.group.name |
| Actor user key (activity logs) | Vendor.actor.key | Â | user.id |
| Actor username (activity logs) | Vendor.actor.name | Â | user.name |
| Network application (lowercased, authentication logs) | Vendor.applications | Â | network.application |
| Telephony log context | Vendor.context | Â | event.action |
| User email (for non-user_/bypass_ events) | Vendor.description.email | Â | user.email |
| Error message (administrator logs) | Vendor.description.error | Â | error.message |
| Target user roles (for user_/bypass_ events) | Vendor.description.groups[].name | Â | user.target.roles[] |
| Client hostname (administrator logs) | Vendor.description.hostname | Â | source.domain |
| Client IP address (administrator logs) | Vendor.description.ip_address | Â | source.ip |
| Target real name (for user_/bypass_ events) | Vendor.description.realname | Â | user.target.full_name |
| Target username (for user_/bypass_ events) | Vendor.description.uname | Â | user.target.name |
| Original user agent string (administrator logs) | Vendor.description.user_agent | Â | user_agent.original |
| User email (authentication logs) | Vendor.email | Â | user.email |
| Effective user ID (who enabled) | Vendor.enabled_by.key | Â | user.effective.id |
| Effective user name (who enabled) | Vendor.enabled_by.name | Â | user.effective.name |
| Target user ID (enabled for) | Vendor.enabled_for.key | Â | user.target.id |
| Target user name (enabled for) | Vendor.enabled_for.name | Â | user.target.name |
| Authentication log event type | Vendor.event_type | Â | event.action |
| Host/observer name (authentication/administrator logs) | Vendor.host | Â | observer.name |
| User name (for non-user_/bypass_ events) | Vendor.object | Â | user.name |
| Activity log result (SUCCESS/FAILURE) | Vendor.outcome.result | Â | event.outcome |
| Authentication failure reason | Vendor.reason | Â | event.reason |
| Authentication result (success/denied/fraud) | Vendor.result | Â | event.outcome |
| TrustMonitor event identifier | Vendor.sekey | Â | event.id |
| TrustMonitor browser name | Vendor.surfaced_auth.access_device.browser | Â | user_agent.name |
| TrustMonitor browser version | Vendor.surfaced_auth.access_device.browser_version | Â | user_agent.version |
| TrustMonitor access device hostname | Vendor.surfaced_auth.access_device.hostname | Â | source.domain |
| TrustMonitor access device IP | Vendor.surfaced_auth.access_device.ip | Â | source.ip |
| TrustMonitor city name | Vendor.surfaced_auth.access_device.location.city | Â | source.geo.city_name |
| TrustMonitor country name | Vendor.surfaced_auth.access_device.location.country | Â | source.geo.country_name |
| TrustMonitor state/region | Vendor.surfaced_auth.access_device.location.state | Â | source.geo.region_name |
| TrustMonitor operating system | Vendor.surfaced_auth.access_device.os | Â | user_agent.os.name |
| TrustMonitor OS version | Vendor.surfaced_auth.access_device.os_version | Â | user_agent.os.version |
| TrustMonitor user email | Vendor.surfaced_auth.email | Â | user.email |
| TrustMonitor authentication reason | Vendor.surfaced_auth.reason | Â | event.reason |
| TrustMonitor authentication result | Vendor.surfaced_auth.result | Â | event.outcome |
| TrustMonitor user key | Vendor.surfaced_auth.user.key | Â | user.id |
| TrustMonitor username | Vendor.surfaced_auth.user.name | Â | user.name |
| Target email (when target.type = user) | Vendor.target.details.email | Â | user.target.email |
| Target real name (when target.type = user) | Vendor.target.details.realname | Â | user.target.full_name |
| Target username (when target.type = user) | Vendor.target.details.uname | Â | user.target.name |
| Target key as email (when target.type = user) | Vendor.target.key | Â | user.target.email |
| Telephony log event identifier | Vendor.telephony_id | Â | event.id |
| TrustMonitor triage event URI (also mapped to url.original) | Vendor.triage_event_uri | Â | url.original |
| TrustMonitor event type | Vendor.type | Â | event.action |
| User group roles (authentication logs) | Vendor.user.groups[] | Â | user.roles[] |
| User key/ID (authentication logs) | Vendor.user.key | Â | user.id |
| Username (authentication logs) | Vendor.user.name | Â | user.name |
| Administrator full name | Vendor.username | Â | user.full_name |