Parsers and Generated Fields

Tag Fields Created by Parser cisco-ise
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ise
Vendor FieldCPS FieldDescription
host.ip[0];client.ip 
Vendor.AdminIPAddressclient.ip  
Vendor.DestinationPortclient.port  
Vendor.Detailevent.reason  
Vendor.FailureReasonevent.reason  
log.syslog.hostnameobserver.name 
Vendor.IpAddresssource.ip  
Tag Fields Created by Parser cisco-ise-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-ise-syslog
Vendor FieldCPS FieldDescription
Vendor.AdminIPAddress;client.ip 
host.ip;client.ip 
Vendor.DestinationPortclient.port 
Vendor.Detail;event.reason 
Vendor.FailureReason;event.reason 
Vendor.DestinationIPAddress;host.ip 
Vendor.IpAddress;host.ip 
Vendor.EPMacAddresshost.mac 
Vendor.EndPointMACAddresshost.mac 
log.syslog.hostnameobserver.name 
Vendor.IpAddresssource.ip