Parsers and Generated Fields

Tag Fields Created by Parser cisco-ios
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ios
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.eventCode
`event.type[]`ArrayVendor.eventCode
`destination.ip`Copieddestination.address
`event.sequence`CopiedVendor.ios.message_count, Vendor.ios.sequence
`network.packets`Copiedsource.packets
`rule.name`CopiedVendor.sgacl_name
`source.ip`Copiedsource.address
`source.user.name`Copieduser.name
`client.ip`Extractedmessage
`client.mac`Extractedmessage
`destination.address`Extractedmessage
`destination.mac`Extractedmessage
`destination.port`Extractedmessage
`event.action`Extractedmessage, Vendor.eventAction
`event.reason`Extractedmessage
`host.mac`Extractedmessage
`log.syslog.hostname`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.severity.code`Extracted@rawstring
`network.iana_number`Extractedmessage
`network.transport`Extractedmessage
`observer.ingress.interface.name`Extractedmessage, Vendor.ingress_interface
`observer.ip[0]`Extracted@rawstring
`process.command_line`Extractedmessage
`server.ip`Extractedmessage
`server.port`Extractedmessage
`source.address`Extractedmessage
`source.packets`Extractedmessage
`source.port`Extractedmessage
`user.name`Extractedmessage
`vlan.id`Extractedmessage
`event.dataset`Formattedevent.module, Vendor.ios.facility
`network.community_id`Generatedsource.ip, destination.ip, network.transport, source.port, destination.port
`log.level`Mappedlog.syslog.severity.code
`source.mac`NormalizedVendor.mac
`@timestamp`Parsed_ts, _tz
`event.outcome`SetVendor.eventCode, message patterns
`network.type`Setsource.ip
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.product`StaticNone
Vendor.Sourceclient.ip 
destination.addressdestination.ip 
Vendor.actionevent.action 
Vendor.Reasonevent.reason 
source.packetsnetwork.packets 
Vendor.protocolnetwork.transport 
Vendor.ingress_interfaceobserver.ingress.interface.name 
Vendor.sgacl_namerule.name 
Vendor.localportserver.port 
source.addresssource.ip 
user.namesource.user.name 
Vendor.useruser.name