Parsers and Generated Fields

Tag Fields Created by Parser cisco-ise
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ise
Source FieldCPS FieldDescriptionMapping
event.created, @timestamp@timestampEvent timestamp with timezone supportParsed from timestamp fields using multiple format patterns
Vendor.IpAddress, Vendor.AdminIPAddress, Vendor.DestinationIPAddress, Vendor.Remote-Address, Vendor.Framed-IP-Addressclient.addressClient addressCopied from multiple IP address fields
Vendor.NetworkDeviceName, Vendor.AD-Host-DNS-Domainclient.domainClient domainCopied from network device name or AD domain
client.addressclient.ipClient IP addressExtracted from client.address if valid IP
Vendor.EndPointMACAddress, Vendor.EPMacAddressclient.macClient MAC addressCopied from MAC address fields
Vendor.DestinationPort, client.addressclient.portClient port numberCopied from destination port or extracted from address
Noneecs.versionECS schema versionStatic value: 9.2.0
Vendor.category, Vendor.log.message.description, Vendor.Actionevent.actionAction performedExtracted from category or message description, converted to lowercase
Vendor.category, Vendor.codeevent.category[]Event categorizationArray populated based on event codes and categories
syslog timestampevent.createdSyslog message creation timeParsed from syslog header timestamp
Vendor.categoryevent.datasetDataset identifier based on ISE categoryExtracted from category and converted to lowercase
event.idevent.idEvent identifier from ISEExtracted from syslog message
Noneevent.kindEvent classificationStatic value: event
Noneevent.moduleModule identifierStatic value: ise
Vendor.AuthenticationStatus, Vendor.log.message.description, Vendor.FailureReason, Vendor.Response.AcctReply-Statusevent.outcomeSuccess, failure, or unknown outcomeDetermined by authentication status and message content
Vendor.AD-Error-Details, Vendor.FailureReason, Vendor.Detail, Vendor.Failure Reasonevent.reasonReason for event or failureCopied from failure reason or error details
Vendor.log.segment.numberevent.sequenceEvent sequence numberCopied from log segment number
Vendor.category, Vendor.codeevent.type[]Event type classificationArray populated based on event codes and categories
syslog hostnamelog.syslog.hostnameHostname from syslogExtracted from syslog header
syslog prioritylog.syslog.prioritySyslog priority valueExtracted from syslog priority field
Vendor.log.syslog.severity.namelog.syslog.severity.nameSeverity level nameExtracted from ISE message
Vendor.Protocolnetwork.protocolNetwork protocolCopied from protocol field, converted to lowercase
log.syslog.hostnameobserver.nameObserver nameCopied from syslog hostname
Noneobserver.typeObserver type identifierStatic value: nac
Vendor.CmdSetprocess.command_lineCommand line from TACACS logsParsed from command set with filtering and formatting
Vendor.EndpointNADAddress, Vendor.PsnHostName, Vendor.Device IP Addressserver.addressServer addressCopied from endpoint or device address fields
server.addressserver.domainServer domainExtracted from server.address if not IP
server.addressserver.ipServer IP addressExtracted from server.address if valid IP
Vendor.Device Portserver.portServer port numberCopied from device port
Vendor.ISEServiceName, Vendor.Service-Argumentservice.nameService nameCopied from ISE service name or service argument
Vendor.TLSCiphertls.cipherTLS cipher suiteCopied from TLS cipher field
Vendor.Issuer - Countrytls.client.x509.issuer.country[]Certificate issuer countryArray populated from issuer country
Vendor.Issuer - Locationtls.client.x509.issuer.locality[]Certificate issuer localityArray populated from issuer location
Vendor.Issuer - Organizationtls.client.x509.issuer.organization[]Certificate issuer organizationArray populated from issuer organization
Vendor.Issuer - Organization Unittls.client.x509.issuer.organizational_unit[]Certificate issuer organizational unitArray populated from issuer organizational unit
Vendor.Issuer - State or Provincetls.client.x509.issuer.state_or_province[]Certificate issuer state or provinceArray populated from issuer state or province
Vendor.Subject - Common Nametls.client.x509.subject.common_name[]Certificate subject common nameArray populated from subject common name
Vendor.Subject - Organization Unittls.client.x509.subject.organizational_unit[]Certificate subject organizational unitArray populated from subject organizational unit
Vendor.TLSVersiontls.versionTLS protocol versionCopied from TLS version field
user.name, Vendor.AD-User-DNS-Domainuser.domainUser domainExtracted from user.name or AD domain field
Vendor.EmailAddressuser.emailUser email addressCopied from email address field
Vendor.Firstname, Vendor.Lastnameuser.full_nameFull user nameConcatenated from first and last name
Vendor.AD-Groups-Namesuser.group.nameUser group nameCopied from AD groups field
Vendor.UserName, Vendor.OriginalUserName, Vendor.User, Vendor.AdminName, Vendor.User-Name, Vendor.AD-User-SamAccount-Name, Vendor.AD-User-Qualified-Nameuser.nameUsernameCopied from various user fields, converted to lowercase with domain extraction