Parsers and Generated Fields

Tag Fields Created by Parser firepower-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser firepower-syslog
Source FieldLogScale Repository Field
Vendor.DNSResponseTypecode
Vendor.InitiatorBytesadestination.bytes
Vendor.DstIPdestination.ip
Vendor.NATdestination.nat.ip
Vendor.NATdestination.nat.port
Vendor.InitiatorPacketsdestination.packets
Vendor.DstPortdestination.port
Vendor.DeviceUUIDdevice.id
Vendor.DNSdns.answers.ttl
Vendor.DNSQuerydns.question.name
Vendor.AccessControlRuleActionevent.action
Vendor.mnemonicevent.code
Vendor.AccessControlRuleReasonevent.reason
Vendor.EventPriorityevent.severity
Vendor.FirstPacketSecondevent.start
Vendor.ArchiveFileNamefile.name
Vendor.FileNamefile.name
Vendor.InstanceIDhost.id
Vendor.SSLServerNamename
source.bytesnetwork.bytes
destination.packetsnetwork.packets
Vendor.EgressInterfaceobserver.egress.interface.alias
Vendor.EgressZoneobserver.egress.zone
log.syslog.hostnameobserver.hostname
Vendor.IngressInterfaceobserver.ingress.interface.alias
Vendor.IngressZoneobserver.ingress.zone
Vendor.AccessControlRuleNamerule.name
Vendor.ResponderBytessource.bytes
Vendor.SrcIPsource.ip
Vendor.NATsource.nat.ip
Vendor.NATsource.nat.port
Vendor.ResponderPacketssource.packets
Vendor.SrcPortsource.port
Vendor.SSLCipherSuitetls.cipher
Vendor.SSLCertificatetls.client.certificate
Vendor.SSLVersiontls.version
url.originalurl.full
Vendor.URLurl.original
user.nameuser.email
Vendor.Useruser.id