Parsers and Generated Fields

Tag Fields Created by Parser cisco-ios
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ios
Source FieldCPS FieldDescriptionMapping
_ts, _tz@timestampEvent timestampParsed from _ts field using various timestamp formats
messageclient.addressClient addressExtracted from message using regex patterns
client.addressclient.ipClient IP addressCopied from client.address after CIDR validation
messageclient.macClient MAC addressExtracted and normalized from message
messagedestination.addressDestination addressExtracted from message using regex patterns
destination.addressdestination.ipDestination IP addressCopied from destination.address after CIDR validation
messagedestination.macDestination MAC addressExtracted and normalized from message
messagedestination.portDestination port numberExtracted from message using regex patterns
Noneecs.versionECS schema versionStatic value: 9.2.0
messageerror.codeError codeSet based on error type
messageerror.messageError messageExtracted from error events
message, Vendor.eventActionevent.actionAction performedExtracted from message or set based on event type
Vendor.eventCodeevent.category[]Event categorizationArray populated based on event type conditions
event.module, Vendor.ios.facilityevent.datasetDataset identifierFormatted from event.module and Vendor.ios.facility
Noneevent.kindEvent kind classificationStatic value: event
Noneevent.moduleModule identifierStatic value: ios
Vendor.eventCode, message patternsevent.outcomeEvent outcome statusSet based on event success/failure conditions
messageevent.reasonReason for eventExtracted from message using regex patterns
Vendor.ios.message_count, Vendor.ios.sequenceevent.sequenceEvent sequence numberCopied from Vendor.ios.message_count or Vendor.ios.sequence
Vendor.eventCodeevent.type[]Event type classificationArray populated based on event conditions
messagefile.nameFile nameExtracted from file-related error messages
messagehost.mac[]Host MAC addressesArray populated from normalized MAC address
log.syslog.severity.codelog.levelLog severity levelMapped from log.syslog.severity.code
@rawstringlog.syslog.hostnameSyslog hostnameExtracted from syslog header
@rawstringlog.syslog.prioritySyslog priority valueExtracted from syslog header
@rawstringlog.syslog.severity.codeSyslog severity codeExtracted from syslog priority with alphanumeric remapping
source.ip, destination.ip, network.transport, source.port, destination.portnetwork.community_idNetwork community IDGenerated using communityId function
messagenetwork.iana_numberIANA protocol numberExtracted from message using regex patterns
source.packetsnetwork.packetsTotal network packetsCopied from source.packets
messagenetwork.protocolNetwork protocolExtracted from message for specific event types
messagenetwork.transportNetwork transport protocolExtracted from message and normalized to lowercase
source.address, client.addressnetwork.typeNetwork typeSet based on IP address format (ipv4/ipv6)
messagenetwork.vlan.idVLAN identifierExtracted from message using regex patterns
message, Vendor.ingress_interfaceobserver.ingress.interface.nameIngress interface nameExtracted from message or copied from Vendor field
@rawstringobserver.ip[0]Observer IP addressExtracted from specific log patterns
Noneobserver.productObserver product nameStatic value: ios
messageprocess.command_lineExecuted command lineExtracted from CFGLOG_LOGGEDCMD events
messageprocess.nameProcess nameExtracted from SYSTEM_MSG events
messageprocess.pidProcess IDExtracted from SYSTEM_MSG events
Vendor.sgacl_namerule.nameRule nameCopied from Vendor.sgacl_name
messageserver.addressServer addressExtracted from message using regex patterns
server.addressserver.ipServer IP addressCopied from server.address after CIDR validation
messageserver.portServer port numberExtracted from message using regex patterns
messagesource.addressSource addressExtracted from message using regex patterns
source.addresssource.ipSource IP addressCopied from source.address after CIDR validation
Vendor.macsource.macSource MAC addressNormalized from Vendor.mac field
messagesource.packetsNumber of source packetsExtracted from message using regex patterns
messagesource.portSource port numberExtracted from message using regex patterns
user.namesource.user.nameSource usernameCopied from user.name
messageuser.nameUsernameExtracted from message using regex patterns
messagevlan.idVLAN identifierExtracted from message using regex patterns