Parsers and Generated Fields

Tag Fields Created by Parser cisco-meraki
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-meraki
Vendor FieldCPS FieldDescription
messageVendor.messageOriginal message
Vendor.client_ipclient.ip 
Vendor.client_ip;client.ip 
client_ipclient.ipClient IP address
Vendor.client_macclient.mac 
Vendor.client_mac;client.mac 
client_macclient.macClient MAC address
Vendor.dstdestination.ip 
Vendor.translated_dst_ipdestination.ip 
dstdestination.ipDestination IP address
translated_dst_ipdestination.ipTranslated destination IP for NAT events
Vendor.dstdestination.mac 
Vendor.dportdestination.port 
Vendor.dport;destination.port 
Vendor.translated_port;destination.port 
dportdestination.portDestination port number
Vendor.typeevent_subtype 
log.syslog.appnameevent_subtype 
sha256file.hash.sha256SHA256 hash for files
Vendor.namefile.name 
namefile.nameFile name for security events
Vendor.http_methodhttp.request.method 
http_methodhttp.request.methodHTTP method used
Vendor.directionnetwork.direction 
directionnetwork.directionTraffic direction
Vendor.forwarded_ipnetwork.forwarded_ip 
forwarded_ipnetwork.forwarded_ipForwarded IP address
Vendor.ssidnetwork.name 
ssidnetwork.nameNetwork SSID
Vendor.protocolnetwork.protocol 
protocolnetwork.protocolProtocol used
Vendor.vlan_id;network.vlan.id 
vlan_idnetwork.vlan.idVLAN ID
Vendor.url.hostserver.address 
url.hostserver.addressServer hostname from URL
Vendor.original_server_ip;server.ip 
Vendor.serverserver.ip 
serverserver.ipServer IP address
Vendor.original_server_macserver.mac 
Vendor.server_macserver.mac 
Vendor.server_mac;server.mac 
server_macserver.macServer MAC address
Vendor.serverportserver.port 
serverportserver.portServer port number
Vendor.srcsource.ip 
Vendor.translated_src_ipsource.ip 
srcsource.ipSource IP address
translated_src_ipsource.ipTranslated source IP for NAT events
Vendor.macsource.mac 
Vendor.srcsource.mac 
macsource.macSource MAC address
Vendor.sportsource.port 
Vendor.sport;source.port 
Vendor.translated_port;source.port 
sportsource.portSource port number
translated_portsource.port/destination.portTranslated port for NAT events
Vendor.urlurl.original 
urlurl.originalOriginal URL
Vendor.usernameuser.name 
usernameuser.nameUsername
Vendor.agentuser_agent.original 
agentuser_agent.originalUser agent string