Parsers and Generated Fields

Tag Fields Created by Parser cisco-meraki
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-meraki
Source FieldCPS Field
Vendor.client_ipclient.ip
Vendor.client_ip;client.ip
Vendor.client_mac;client.mac
Vendor.dstdestination.ip
Vendor.translated_dst_ipdestination.ip
Vendor.dstdestination.mac
Vendor.dportdestination.port
Vendor.dport;destination.port
Vendor.translated_port;destination.port
Vendor.typeevent_subtype
Vendor.namefile.name
Vendor.http_methodhttp.request.method
Vendor.directionnetwork.direction
Vendor.forwarded_ipnetwork.forwarded_ip
Vendor.ssidnetwork.name
Vendor.protocolnetwork.protocol
Vendor.vlan_id;network.vlan.id
Vendor.original_server_ip;server.ip
Vendor.original_server_macserver.mac
Vendor.server_macserver.mac
Vendor.server_mac;server.mac
Vendor.srcsource.ip
Vendor.translated_src_ipsource.ip
Vendor.macsource.mac
Vendor.srcsource.mac
Vendor.sportsource.port
Vendor.sport;source.port
Vendor.translated_port;source.port
Vendor.urlurl.original
Vendor.usernameuser.name
Vendor.agentuser_agent.original