Parsers and Generated Fields

Tag Fields Created by Parser cisco-meraki
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-meraki
Vendor FieldCPS FieldDescription
Vendor.eventData.channelVendor.channel 
Vendor.eventData.connection_statusVendor.connection_status 
Vendor.eventData.dnsVendor.dns 
Vendor.eventData.durationVendor.lease_duration 
messageVendor.messageOriginal message
Vendor.eventData.new_stateVendor.new_state 
Vendor.eventData.peer_contactVendor.peer_contact 
Vendor.eventData.peer_typeVendor.peer_type 
Vendor.eventData.rssiVendor.signal_strength 
Vendor.eventData.vpn_typeVendor.vpn_type 
Vendor.clientDescriptionclient.address 
clientDescriptionclient.addressClient description
Vendor.client_ipclient.ip 
Vendor.eventData.client_ipclient.ip 
Vendor.eventData.ipclient.ip 
client_ipclient.ipClient IP address
eventData.client_ipclient.ipClient IP from event data
Vendor.client_macclient.mac 
clientMacclient.macClient MAC address in JSON format
client_macclient.macClient MAC address
Vendor.eventData.local_asdestination.as.number 
eventData.local_asdestination.as.numberLocal AS number
Vendor.destinationdestination.ip 
Vendor.dstdestination.ip 
Vendor.eventData.peer_ipdestination.ip 
Vendor.eventData.routerdestination.ip 
Vendor.translated_dst_ipdestination.ip 
destIpdestination.ipDestination IP with port extraction
dstdestination.ipDestination IP address
eventData.routerdestination.ipRouter IP address
translated_dst_ipdestination.ipTranslated destination IP for NAT events
Vendor.dstdestination.mac 
Vendor.dportdestination.port 
Vendor.portdestination.port 
dportdestination.portDestination port number
Vendor.eventData.error_codeerror.code 
eventData.error_codeerror.codeError code
Vendor.eventData.descerror.message 
eventData.descerror.messageError description
Vendor.actionevent.action 
Vendor.eventTypeevent.action 
Vendor.typeevent.action 
Vendor.descriptionevent.original 
Vendor.messageevent.original 
_outcomeevent.outcomeAuthentication outcome based on success/failure patterns
blockedevent.outcomeDetermines if event was blocked
priorityevent.severityMaps priority levels to severity values
Vendor.typeevent_subtype 
log.syslog.appnameevent_subtype 
fileHashfile.hash.sha256File hash
sha256file.hash.sha256SHA256 hash for files
Vendor.namefile.name 
namefile.nameFile name for security events
Vendor.fileSizeBytesfile.size 
fileSizeBytesfile.sizeFile size in bytes
Vendor.fileTypefile.type 
fileTypefile.typeFile type
Vendor.clientDescriptionhost.hostname 
Vendor.clientNamehost.hostname 
Vendor.clientIdhost.id 
Vendor.http_methodhttp.request.method 
http_methodhttp.request.methodHTTP method used
Vendor.applicationnetwork.application 
Vendor.sentnetwork.bytes 
Vendor.directionnetwork.direction 
directionnetwork.directionTraffic direction
Vendor.forwarded_ipnetwork.forwarded_ip 
forwarded_ipnetwork.forwarded_ipForwarded IP address
Vendor.networkIdnetwork.name 
Vendor.ssidnetwork.name 
networkIdnetwork.nameNetwork identifier
ssidnetwork.nameNetwork SSID
Vendor.flowsnetwork.packets 
Vendor.protocolnetwork.protocol 
protocolnetwork.protocolProtocol used
network.transportnetwork.transportNetwork transport protocol for VPN connections
Vendor.eventData.vlannetwork.vlan.id 
eventData.vlannetwork.vlan.idVLAN ID from event data
vlan_idnetwork.vlan.idVLAN ID
Vendor.deviceNameobserver.name 
deviceNameobserver.nameDevice name
Vendor.deviceSerialobserver.serial_number 
deviceSerialobserver.serial_numberDevice serial number
Vendor.classificationrule.category 
classificationrule.categoryAlert classification
Vendor.messagerule.description 
messagerule.descriptionAlert description
Vendor.signaturerule.id 
signaturerule.idSignature ID for IDS alerts
Vendor.messagerule.name 
messagerule.nameAlert message
Vendor.ruleIdrule.reference 
ruleIdrule.referenceRule reference ID
Vendor.url.hostserver.address 
url.hostserver.addressServer hostname from URL
Vendor.serverserver.ip 
serverserver.ipServer IP address
Vendor.original_server_macserver.mac 
Vendor.server_macserver.mac 
server_macserver.macServer MAC address
Vendor.serverportserver.port 
serverportserver.portServer port number
Vendor.eventData.remote_assource.as.number 
eventData.remote_assource.as.numberRemote AS number
Vendor.eventData.client_ipsource.ip 
Vendor.eventData.ipsource.ip 
Vendor.eventData.peer_ipsource.ip 
Vendor.srcsource.ip 
Vendor.srcIpsource.ip 
Vendor.translated_src_ipsource.ip 
eventData.ipsource.ipIP address from event data
eventData.peer_ipsource.ipBGP peer IP address
srcsource.ipSource IP address
srcIpsource.ipSource IP with port extraction
translated_src_ipsource.ipTranslated source IP for NAT events
Vendor.clientMacsource.mac 
Vendor.macsource.mac 
Vendor.srcsource.mac 
macsource.macSource MAC address
Vendor.sportsource.port 
sportsource.portSource port number
translated_portsource.port/destination.portTranslated port for NAT events
messagethreat.indicator.descriptionThreat description
fileHashthreat.indicator.file.hash.sha256Threat indicator file hash
destIpthreat.indicator.ipThreat indicator IP
destination.ipthreat.indicator.ip 
tls.versiontls.versionTLS version for VPN connections
Vendor.uriurl.original 
Vendor.urlurl.original 
uriurl.originalOriginal URI
urlurl.originalOriginal URL
Vendor.usernameuser.name 
usernameuser.nameUsername
Vendor.agentuser_agent.original 
agentuser_agent.originalUser agent string