Parsers and Generated Fields
Tag Fields Created by Parser cisco-ise
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser cisco-ise
Vendor Field | CPS Field | Description |
---|---|---|
`event.category[]` | Array | Vendor.category, Vendor.code |
`event.type[]` | Array | Vendor.category, Vendor.code |
`host.ip[]` | Array | Vendor.DestinationIPAddress, Vendor.Remote-Address, Vendor.IpAddress |
`host.mac[]` | Array | Vendor.EndPointMACAddress, Vendor.EPMacAddress |
`user.full_name` | Concatenated | Vendor.Firstname, Vendor.Lastname |
`client.ip` | Copied | Vendor.Remote-Address, Vendor.AdminIPAddress, host.ip[0] |
`client.port` | Copied | Vendor.DestinationPort |
`event.reason` | Copied | Vendor.FailureReason, Vendor.AD-Error-Details, Vendor.Detail |
`network.protocol` | Copied | Vendor.Protocol |
`observer.name` | Copied | log.syslog.hostname |
`server.ip` | Copied | Vendor.Device IP Address |
`server.port` | Copied | Vendor.Device Port |
`service.name` | Copied | Vendor.Service-Type |
`source.ip` | Copied | Vendor.IpAddress |
`user.name` | Copied | Vendor.UserName, Vendor.OriginalUserName, Vendor.User-Name, Vendor.User, Vendor.AdminName |
`event.outcome` | Determined | Vendor.code, message analysis |
`event.action` | Extracted | Vendor.category, Vendor.log.message.description |
`event.id` | Extracted | Vendor.event.id |
`event.sequence` | Extracted | Vendor.event.sequence |
`log.syslog.hostname` | Extracted | syslog hostname |
`log.syslog.priority` | Extracted | syslog priority |
`log.syslog.severity.name` | Extracted | Vendor.log.syslog.severity.name |
`@timestamp` | Parsed | event.created, @timestamp |
`event.created` | Parsed | log.syslog timestamp |
`process.command_line` | Parsed | Vendor.CmdSet |
`ecs.version` | Static | None |
`event.dataset` | Static | None |
`event.kind` | Static | None |
`event.module` | Static | None |
`observer.type` | Static | None |
Vendor.DestinationPort | client.port | |
log.syslog.hostname | observer.name | |
Vendor.IpAddress | source.ip |