Parsers and Generated Fields

Tag Fields Created by Parser cisco-ise
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ise
Source FieldCPS FieldDescriptionMapping
event.created, @timestamp@timestampEvent timestamp with timezone supportParsed from timestamp fields using multiple format patterns
source.addressclient.addressClient address for network connectionMapped from source.address
source.domainclient.domainClient domainMapped from source.domain
source.ipclient.ipClient IP addressMapped from source.ip
source.portclient.portClient port numberMapped from source.port
Vendor.DestinationIPAddress, Vendor.PsnHostNamedestination.addressDestination address of network exchangeCopied from destination IP or PSN hostname
destination.addressdestination.domainDestination domainExtracted from destination.address if not IP
destination.addressdestination.ipDestination IP addressExtracted from destination.address if valid IP
Vendor.DestinationPortdestination.portDestination port numberCopied from destination port
Noneecs.versionECS schema versionStatic value: 9.3.0
Vendor.category, Vendor.log.message.description, Vendor.Actionevent.actionAction performedExtracted from category or message description, converted to lowercase
Vendor.category, Vendor.codeevent.category[]Event categorizationArray populated based on event codes and categories
syslog timestampevent.createdSyslog message creation timeParsed from syslog header timestamp
Vendor.categoryevent.datasetDataset identifier based on ISE categoryExtracted from category and converted to lowercase
event.idevent.idEvent identifier from ISEExtracted from syslog message
Noneevent.kindEvent classificationStatic value: event
Noneevent.moduleModule identifierStatic value: ise
Vendor.AuthenticationStatus, Vendor.log.message.description, Vendor.FailureReason, Vendor.Response.AcctReply-Statusevent.outcomeSuccess, failure, or unknown outcomeDetermined by authentication status and message content
Vendor.AD-Error-Details, Vendor.FailureReason, Vendor.Detail, Vendor.Failure Reasonevent.reasonReason for event or failureCopied from failure reason or error details
Vendor.log.segment.numberevent.sequenceEvent sequence numberCopied from log segment number
Vendor.category, Vendor.codeevent.type[]Event type classificationArray populated based on event codes and categories
Vendor.AD-Host-DNS-Domainhost.domainHost domain nameCopied from AD host domain
Vendor.Framed-IP-Addresshost.ip[]Host IP addresses for authenticated endpointsArray populated from framed IP address
Vendor.EndPointMACAddress, Vendor.EPMacAddresshost.mac[]Host MAC addresses in uppercase with hyphensArray populated from MAC address fields with formatting
syslog hostnamelog.syslog.hostnameHostname from syslogExtracted from syslog header
syslog prioritylog.syslog.prioritySyslog priority valueExtracted from syslog priority field
Vendor.log.syslog.severity.namelog.syslog.severity.nameSeverity level nameExtracted from ISE message
Vendor.Protocolnetwork.protocolNetwork protocolCopied from protocol field, converted to lowercase
log.syslog.hostnameobserver.nameObserver nameCopied from syslog hostname
Noneobserver.typeObserver type identifierStatic value: nac
Vendor.CmdSetprocess.command_lineCommand line from TACACS logsParsed from command set with filtering and formatting
destination.addressserver.addressServer address for network connectionMapped from destination.address
destination.domainserver.domainServer domainMapped from destination.domain
destination.ipserver.ipServer IP addressMapped from destination.ip
destination.portserver.portServer port numberMapped from destination.port
Vendor.ISEServiceName, Vendor.Service-Argumentservice.nameService nameCopied from ISE service name or service argument
Vendor.AdminIPAddress, Vendor.Device IP Address, Vendor.EndpointNADAddress, Vendor.NAS-IP-Address, Vendor.IpAddresssource.addressSource address of network exchangeCopied from multiple IP address fields with priority order
Vendor.NetworkDeviceName, source.addresssource.domainSource domainCopied from network device name or extracted from address
source.addresssource.ipSource IP addressExtracted from source.address if valid IP
source.address, Vendor.Device Portsource.portSource port numberExtracted from address or copied from device port
Vendor.TLSCiphertls.cipherTLS cipher suiteCopied from TLS cipher field
Vendor.Issuer - Countrytls.client.x509.issuer.country[]Certificate issuer countryArray populated from issuer country
Vendor.Issuer - Locationtls.client.x509.issuer.locality[]Certificate issuer localityArray populated from issuer location
Vendor.Issuer - Organizationtls.client.x509.issuer.organization[]Certificate issuer organizationArray populated from issuer organization
Vendor.Issuer - Organization Unittls.client.x509.issuer.organizational_unit[]Certificate issuer organizational unitArray populated from issuer organizational unit
Vendor.Issuer - State or Provincetls.client.x509.issuer.state_or_province[]Certificate issuer state or provinceArray populated from issuer state or province
Vendor.Subject - Common Nametls.client.x509.subject.common_name[]Certificate subject common nameArray populated from subject common name
Vendor.Subject - Organization Unittls.client.x509.subject.organizational_unit[]Certificate subject organizational unitArray populated from subject organizational unit
Vendor.TLSVersiontls.versionTLS protocol versionCopied from TLS version field
user.name, Vendor.AD-User-DNS-Domainuser.domainUser domainExtracted from user.name or AD domain field
Vendor.EmailAddressuser.emailUser email addressCopied from email address field, converted to lowercase
Vendor.Firstname, Vendor.Lastnameuser.full_nameFull user nameConcatenated from first and last name
Vendor.AD-Groups-Namesuser.group.nameUser group nameCopied from AD groups field
Vendor.UserName, Vendor.OriginalUserName, Vendor.User, Vendor.AdminName, Vendor.User-Name, Vendor.AD-User-SamAccount-Name, Vendor.AD-User-Qualified-Nameuser.nameUsernameCopied from various user fields, converted to lowercase with domain extraction