Parsers and Generated Fields

Tag Fields Created by Parser cisco-firepower
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-firepower
Vendor FieldCPS FieldDescription
InitiatorBytesdestination.bytesNumber of bytes from initiator
Vendor.InitiatorBytesdestination.bytes  
DstIPdestination.ipDestination IP address
Vendor.DstIPdestination.ip  
NAT_ResponderIPdestination.nat.ipNAT destination IP
Vendor.NAT_ResponderIPdestination.nat.ip  
NAT_ResponderPortdestination.nat.portNAT destination port
Vendor.NAT_ResponderPortdestination.nat.port  
InitiatorPacketsdestination.packetsNumber of packets from initiator
Vendor.InitiatorPacketsdestination.packets  
DstPortdestination.portDestination port number
Vendor.DstPortdestination.port  
DeviceUUIDdevice.idDevice UUID
Vendor.DeviceUUIDdevice.id  
DNS_TTLdns.answers[0].ttlDNS record TTL
Vendor.DNS_TTLdns.answers[0].ttl  
DNSQuerydns.question.nameDNS query name
Vendor.DNSQuerydns.question.name  
DNSRecordTypedns.question.typeDNS record type
Vendor.DNSRecordTypedns.question.type  
DNSResponseTypedns.response_codeDNS response code
Vendor.DNSResponseTypedns.response_code  
Vendor.AccessControlRuleActionevent.action  
Vendor.AccessControlRuleReasonevent.reason  
Vendor.EventPriorityevent.severity  
Vendor.FirstPacketSecondevent.start  
ArchiveSHA256file.hash.sha256Archive SHA256 hash
FileSHA256file.hash.sha256File SHA256 hash
ArchiveFileNamefile.nameArchive file name
FileNamefile.nameFile name
Vendor.ArchiveFileNamefile.name  
Vendor.FileNamefile.name  
InstanceIDhost.idInstance ID
Vendor.InstanceIDhost.id  
HTTPRefererhttp.request.referrerHTTP referrer
Vendor.HTTPRefererhttp.request.referrer  
HTTPResponsehttp.response.status_codeHTTP response code
Vendor.HTTPResponsehttp.response.status_code  
WebApplicationnetwork.applicationWeb application name
Vendor.WebApplicationnetwork.application  
source.bytesnetwork.bytes 
destination.packetsnetwork.packets 
ApplicationProtocolnetwork.protocolApplication protocol
Protocolnetwork.transportTransport protocol
EgressInterfaceobserver.egress.interface.aliasEgress interface name
Vendor.EgressInterfaceobserver.egress.interface.alias  
EgressVRFobserver.egress.vlan.nameEgress VRF name
Vendor.EgressVRFobserver.egress.vlan.name  
EgressZoneobserver.egress.zoneEgress security zone
Vendor.EgressZoneobserver.egress.zone  
log.syslog.hostnameobserver.hostname 
IngressInterfaceobserver.ingress.interface.aliasIngress interface name
Vendor.IngressInterfaceobserver.ingress.interface.alias  
IngressVRFobserver.ingress.vlan.nameIngress VRF name
Vendor.IngressVRFobserver.ingress.vlan.name  
IngressZoneobserver.ingress.zoneIngress security zone
Vendor.IngressZoneobserver.ingress.zone  
DetectionTyperule.categoryDetection type
Vendor.DetectionTyperule.category  
AccessControlRuleReasonrule.descriptionAccess control rule reason
Vendor.AccessControlRuleReasonrule.description  
AccessControlRuleNamerule.nameAccess control rule name
Vendor.AccessControlRuleNamerule.name  
ACPolicyrule.rulesetAccess control policy name
Vendor.ACPolicyrule.ruleset  
ResponderBytessource.bytesNumber of bytes from responder
Vendor.ResponderBytessource.bytes  
SrcIPsource.ipSource IP address
Vendor.SrcIPsource.ip 
NAT_InitiatorIPsource.nat.ipNAT source IP
Vendor.NAT_InitiatorIPsource.nat.ip  
NAT_InitiatorPortsource.nat.portNAT source port
Vendor.NAT_InitiatorPortsource.nat.port  
ResponderPacketssource.packetsNumber of packets from responder
Vendor.ResponderPacketssource.packets  
SrcPortsource.portSource port number
Vendor.SrcPortsource.port  
SSLCipherSuitetls.cipherSSL cipher suite
Vendor.SSLCipherSuitetls.cipher  
SSLCertificatetls.client.certificateSSL certificate
Vendor.SSLCertificatetls.client.certificate  
SSLServerNametls.client.server_nameSSL server name
Vendor.SSLServerNametls.client.server_name  
SSLVersiontls.versionSSL/TLS version
Vendor.SSLVersiontls.version  
url.originalurl.full 
URLurl.originalOriginal URL
Vendor.URLurl.original  
user.nameuser.email 
Useruser.idUser ID
Vendor.Useruser.id  
Clientuser_agent.nameClient name
Vendor.Clientuser_agent.name  
UserAgentuser_agent.originalUser agent string
Vendor.UserAgentuser_agent.original  
ClientVersionuser_agent.versionClient version
Vendor.ClientVersionuser_agent.version