Parsers and Generated Fields

Tag Fields Created by Parser cisco-meraki
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-meraki
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayNone
`host.ip[]`ArrayVendor.eventData.client_ip, Vendor.clientIp, Vendor.eventData.ip
`host.mac[]`ArrayVendor.clientMac, temp_mac
`observer.mac[]`Arraytemp_mac
`network.bytes`CalculatedVendor.sent, Vendor.recv
`client.address`CopiedVendor.clientDescription
`client.ip`CopiedVendor.client_ip, Vendor.clientIp, Vendor.eventData.client_ip, Vendor.eventData.ip
`client.mac`CopiedVendor.client_mac, Vendor.clientMac
`destination.as.number`CopiedVendor.eventData.local_as
`destination.mac`CopiedVendor.dst
`error.code`CopiedVendor.eventData.error_code
`error.message`CopiedVendor.eventData.desc
`event.duration`CopiedVendor.activeTime
`event.original`CopiedVendor.description, Vendor.message, syslog.message
`file.hash.sha256`CopiedVendor.sha256, Vendor.fileHash
`file.name`CopiedVendor.name
`file.size`CopiedVendor.fileSizeBytes
`file.type`CopiedVendor.fileType
`host.hostname`CopiedVendor.clientDescription
`host.id`CopiedVendor.clientId
`http.request.method`CopiedVendor.http_method
`network.application`CopiedVendor.application
`network.direction`CopiedVendor.direction
`network.forwarded_ip`CopiedVendor.forwarded_ip
`network.name`CopiedVendor.ssid, Vendor.networkId
`network.packets`CopiedVendor.flows
`network.protocol`CopiedVendor.protocol, network.protocol
`network.vlan.id`CopiedVendor.vlan_id, Vendor.eventData.vlan
`observer.name`CopiedVendor.deviceName
`observer.serial_number`CopiedVendor.deviceSerial
`rule.category`CopiedVendor.classification
`rule.description`CopiedVendor.message
`rule.id`CopiedVendor.signature
`rule.name`CopiedVendor.message
`rule.reference`CopiedVendor.ruleId
`server.ip`CopiedVendor.server, Vendor.original_server_ip
`server.mac`CopiedVendor.server_mac, Vendor.original_server_mac
`server.port`CopiedVendor.serverport
`source.as.number`CopiedVendor.eventData.remote_as
`source.ip`CopiedVendor.src, Vendor.srcIp, Vendor.translated_src_ip
`source.mac`CopiedVendor.mac, Vendor.src, Vendor.clientMac
`source.port`CopiedVendor.sport, Vendor.translated_port
`threat.indicator.description`CopiedVendor.message
`threat.indicator.ip`Copieddestination.ip
`url.original`CopiedVendor.url, Vendor.uri
`user.name`CopiedVendor.username, user.name
`user_agent.original`CopiedVendor.agent
`event.action`Derivedevent_subtype, Vendor.type, Vendor.eventType
`event.outcome`DerivedVendor.connectivity, Vendor.blocked, _outcome
`network.type`Determinedsource.ip
`destination.ip`ExtractedVendor.dst, Vendor.destIp, Vendor.eventData.router, destination.ip
`destination.port`ExtractedVendor.dport, Vendor.destIp, destination.port
`log.syslog.appname`Extracted@rawstring
`log.syslog.hostname`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.version`Extracted@rawstring
`network.transport`Extractednetwork.transport
`tls.version`Extractednetwork.transport
`event.severity`MappedVendor.priority
`@timestamp`Parsed@rawstring, Vendor.ts, Vendor.occurredAt
`server.address`ParsedVendor.url
`url.domain`Parsedurl.original
`url.path`Parsedurl.original
`url.query`Parsedurl.original
`url.scheme`Parsedurl.original
`action`StaticNone
`ecs.version`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.type`StaticNone
Vendor.eventData.channelVendor.channel 
Vendor.eventData.connection_statusVendor.connection_status 
Vendor.eventData.dnsVendor.dns 
Vendor.eventData.durationVendor.lease_duration 
Vendor.eventData.new_stateVendor.new_state 
Vendor.eventData.peer_contactVendor.peer_contact 
Vendor.eventData.peer_typeVendor.peer_type 
Vendor.eventData.rssiVendor.signal_strength 
Vendor.eventData.vpn_typeVendor.vpn_type 
Vendor.clientDescriptionclient.address 
Vendor.client_ipclient.ip 
Vendor.eventData.client_ipclient.ip 
Vendor.eventData.ipclient.ip 
Vendor.client_macclient.mac 
Vendor.eventData.local_asdestination.as.number 
Vendor.destinationdestination.ip 
Vendor.dstdestination.ip 
Vendor.eventData.peer_ipdestination.ip 
Vendor.eventData.routerdestination.ip 
Vendor.translated_dst_ipdestination.ip 
Vendor.dstdestination.mac 
Vendor.dportdestination.port 
Vendor.portdestination.port 
Vendor.eventData.error_codeerror.code 
Vendor.eventData.descerror.message 
Vendor.actionevent.action 
Vendor.eventTypeevent.action 
Vendor.typeevent.action 
Vendor.descriptionevent.original 
Vendor.messageevent.original 
Vendor.typeevent_subtype 
log.syslog.appnameevent_subtype 
Vendor.namefile.name 
Vendor.fileSizeBytesfile.size 
Vendor.fileTypefile.type 
Vendor.clientDescriptionhost.hostname 
Vendor.clientNamehost.hostname 
Vendor.clientIdhost.id 
Vendor.http_methodhttp.request.method 
Vendor.applicationnetwork.application 
Vendor.sentnetwork.bytes 
Vendor.directionnetwork.direction 
Vendor.forwarded_ipnetwork.forwarded_ip 
Vendor.networkIdnetwork.name 
Vendor.ssidnetwork.name 
Vendor.flowsnetwork.packets 
Vendor.protocolnetwork.protocol 
Vendor.eventData.vlannetwork.vlan.id 
Vendor.deviceNameobserver.name 
Vendor.deviceSerialobserver.serial_number 
Vendor.classificationrule.category 
Vendor.messagerule.description 
Vendor.signaturerule.id 
Vendor.messagerule.name 
Vendor.ruleIdrule.reference 
Vendor.url.hostserver.address 
Vendor.serverserver.ip 
Vendor.original_server_macserver.mac 
Vendor.server_macserver.mac 
Vendor.serverportserver.port 
Vendor.eventData.remote_assource.as.number 
Vendor.eventData.client_ipsource.ip 
Vendor.eventData.ipsource.ip 
Vendor.eventData.peer_ipsource.ip 
Vendor.srcsource.ip 
Vendor.srcIpsource.ip 
Vendor.translated_src_ipsource.ip 
Vendor.clientMacsource.mac 
Vendor.macsource.mac 
Vendor.srcsource.mac 
Vendor.sportsource.port 
destination.ipthreat.indicator.ip 
Vendor.uriurl.original 
Vendor.urlurl.original 
Vendor.usernameuser.name 
Vendor.agentuser_agent.original