Parsers and Generated Fields

Tag Fields Created by Parser cisco-firepower
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-firepower
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.mnemonic
`event.type[]`ArrayVendor.mnemonic
`network.bytes`Calculatedsource.bytes, destination.bytes
`network.packets`Calculatedsource.packets, destination.packets
`event.outcome`ConditionalVendor.mnemonic
`destination.bytes`CopiedVendor.InitiatorBytes
`destination.nat.ip`CopiedVendor.NAT_ResponderIP
`destination.nat.port`CopiedVendor.NAT_ResponderPort
`destination.packets`CopiedVendor.InitiatorPackets
`device.id`CopiedVendor.DeviceUUID
`dns.answers[0].ttl`CopiedVendor.DNS_TTL
`dns.question.name`CopiedVendor.DNSQuery
`dns.question.type`CopiedVendor.DNSRecordType
`dns.response_code`CopiedVendor.DNSResponseType
`event.action`CopiedVendor.AccessControlRuleAction
`event.reason`CopiedVendor.AccessControlRuleReason
`event.start`CopiedVendor.FirstPacketSecond
`network.application`CopiedVendor.WebApplication
`network.protocol`CopiedVendor.ApplicationProtocol
`network.transport`CopiedVendor.Protocol
`observer.egress.vlan.name`CopiedVendor.EgressVRF
`observer.hostname`Copiedlog.syslog.hostname
`observer.ingress.vlan.name`CopiedVendor.IngressVRF
`source.bytes`CopiedVendor.ResponderBytes
`source.nat.ip`CopiedVendor.NAT_InitiatorIP
`source.nat.port`CopiedVendor.NAT_InitiatorPort
`source.packets`CopiedVendor.ResponderPackets
`tls.cipher`CopiedVendor.SSLCipherSuite
`tls.client.certificate`CopiedVendor.SSLCertificate
`tls.client.server_name`CopiedVendor.SSLServerName
`tls.version`CopiedVendor.SSLVersion
`url.full`Copiedurl.original
`url.original`CopiedVendor.URL
`user.id`Copied 
`@timestamp`Extracted@rawstring
`client.ip`ExtractedVendor.message
`destination.address`ExtractedVendor.message
`destination.ip`ExtractedVendor.message, Vendor.DstIP
`destination.port`ExtractedVendor.message, Vendor.DstPort
`network.direction`ExtractedVendor.message
`observer.egress.interface.alias`ExtractedVendor.message, Vendor.EgressInterface
`observer.egress.zone`ExtractedVendor.message, Vendor.EgressZone
`observer.ingress.interface.alias`ExtractedVendor.message, Vendor.IngressInterface
`observer.ingress.zone`ExtractedVendor.message, Vendor.IngressZone
`source.ip`ExtractedVendor.message, Vendor.SrcIP
`source.mac`ExtractedVendor.message
`source.port`ExtractedVendor.message, Vendor.SrcPort
`event.severity`MappedVendor.EventPriority
`url.domain`Parsedurl.original
`ecs.version`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.type`StaticNone
Vendor.InitiatorBytesdestination.bytes 
Vendor.DstIPdestination.ip 
Vendor.NAT_ResponderIPdestination.nat.ip 
Vendor.NAT_ResponderPortdestination.nat.port 
Vendor.InitiatorPacketsdestination.packets 
Vendor.DstPortdestination.port 
Vendor.DeviceUUIDdevice.id 
Vendor.DNS_TTLdns.answers[0].ttl 
Vendor.DNSQuerydns.question.name 
Vendor.DNSRecordTypedns.question.type 
Vendor.DNSResponseTypedns.response_code 
Vendor.AccessControlRuleActionevent.action 
Vendor.AccessControlRuleReasonevent.reason 
Vendor.FirstPacketSecondevent.start 
Vendor.ArchiveFileNamefile.name 
Vendor.FileNamefile.name 
Vendor.InstanceIDhost.id 
Vendor.HTTPRefererhttp.request.referrer 
Vendor.HTTPResponsehttp.response.status_code 
Vendor.WebApplicationnetwork.application 
source.bytesnetwork.bytes 
destination.packetsnetwork.packets 
Vendor.EgressInterfaceobserver.egress.interface.alias 
Vendor.EgressVRFobserver.egress.vlan.name 
Vendor.EgressZoneobserver.egress.zone 
log.syslog.hostnameobserver.hostname 
Vendor.IngressInterfaceobserver.ingress.interface.alias 
Vendor.IngressVRFobserver.ingress.vlan.name 
Vendor.IngressZoneobserver.ingress.zone 
Vendor.DetectionTyperule.category 
Vendor.AccessControlRuleReasonrule.description 
Vendor.AccessControlRuleNamerule.name 
Vendor.ACPolicyrule.ruleset 
Vendor.ResponderBytessource.bytes 
Vendor.SrcIPsource.ip 
Vendor.NAT_InitiatorIPsource.nat.ip 
Vendor.NAT_InitiatorPortsource.nat.port 
Vendor.ResponderPacketssource.packets 
Vendor.SrcPortsource.port 
Vendor.SSLCipherSuitetls.cipher 
Vendor.SSLCertificatetls.client.certificate 
Vendor.SSLServerNametls.client.server_name 
Vendor.SSLVersiontls.version 
url.hosturl.domain  
url.originalurl.full 
Vendor.URLurl.original 
user.nameuser.email 
Vendor.Useruser.id 
Vendor.Clientuser_agent.name 
Vendor.UserAgentuser_agent.original 
Vendor.ClientVersionuser_agent.version