Parsers and Generated Fields

Tag Fields Created by Parser cisco-ise
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ise
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.category, Vendor.code
`event.type[]`ArrayVendor.category, Vendor.code
`tls.client.x509.issuer.country[]`ArrayVendor.Issuer - Country
`tls.client.x509.issuer.locality[]`ArrayVendor.Issuer - Location
`tls.client.x509.issuer.organization[]`ArrayVendor.Issuer - Organization
`tls.client.x509.issuer.organizational_unit[]`ArrayVendor.Issuer - Organization Unit
`tls.client.x509.issuer.state_or_province[]`ArrayVendor.Issuer - State or Province
`tls.client.x509.subject.common_name[]`ArrayVendor.Subject - Common Name
`tls.client.x509.subject.organizational_unit[]`ArrayVendor.Subject - Organization Unit
`user.full_name`ConcatenatedVendor.Firstname, Vendor.Lastname
`client.address`CopiedVendor.IpAddress, Vendor.AdminIPAddress, Vendor.DestinationIPAddress, Vendor.Remote-Address, Vendor.Framed-IP-Address
`client.domain`CopiedVendor.NetworkDeviceName, Vendor.AD-Host-DNS-Domain
`client.mac`CopiedVendor.EndPointMACAddress, Vendor.EPMacAddress
`client.port`CopiedVendor.DestinationPort, client.address
`event.reason`CopiedVendor.AD-Error-Details, Vendor.FailureReason, Vendor.Detail, Vendor.Failure Reason
`event.sequence`CopiedVendor.log.segment.number
`network.protocol`CopiedVendor.Protocol
`observer.name`Copiedlog.syslog.hostname
`server.address`CopiedVendor.EndpointNADAddress, Vendor.PsnHostName, Vendor.Device IP Address
`server.port`CopiedVendor.Device Port
`service.name`CopiedVendor.ISEServiceName, Vendor.Service-Argument
`tls.cipher`CopiedVendor.TLSCipher
`tls.version`CopiedVendor.TLSVersion
`user.email`CopiedVendor.EmailAddress
`user.group.name`CopiedVendor.AD-Groups-Names
`user.name`CopiedVendor.UserName, Vendor.OriginalUserName, Vendor.User, Vendor.AdminName, Vendor.User-Name, Vendor.AD-User-SamAccount-Name, Vendor.AD-User-Qualified-Name
`event.outcome`DeterminedVendor.AuthenticationStatus, Vendor.log.message.description, Vendor.FailureReason, Vendor.Response.AcctReply-Status
`client.ip`Extractedclient.address
`event.action`ExtractedVendor.category, Vendor.log.message.description, Vendor.Action
`event.dataset`ExtractedVendor.category
`event.id`Extractedevent.id
`log.syslog.hostname`Extractedsyslog hostname
`log.syslog.priority`Extractedsyslog priority
`log.syslog.severity.name`ExtractedVendor.log.syslog.severity.name
`server.domain`Extractedserver.address
`server.ip`Extractedserver.address
`user.domain`Extracteduser.name, Vendor.AD-User-DNS-Domain
`@timestamp`Parsedevent.created, @timestamp
`event.created`Parsedsyslog timestamp
`process.command_line`ParsedVendor.CmdSet
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.type`StaticNone
Vendor.Response__tmpResponse 
Vendor.DestinationPortclient.port 
Vendor.log.segment.numberevent.sequence 
log.syslog.hostnameobserver.name 
Vendor.TLSCiphertls.cipher 
Vendor.TLSVersiontls.version 
Vendor.EmailAddressuser.email