Parsers and Generated Fields

Tag Fields Created by Parser cisco-umbrella
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-umbrella
Vendor FieldCPS FieldDescription
Vendor.aws_regioncloud.region 
Vendor.csv_row;csvData 
Vendor.destination_ipdestination.addressDestination IP mapping
Vendor.destinationdestination.domainDestination domain mapping
Vendor.destination_ipdestination.ip 
Vendor.destination_portdestination.port 
Vendor.domaindns.question.nameDNS domain name mapping
Vendor.query_typedns.question.typeDNS query type mapping
Vendor.response_codedns.response_codeDNS response code mapping
Vendor.certificate_errorserror.messageCertificate error messages
Vendor.actionevent.actionAction taken, converted to lowercase
Vendor.idevent.id 
Vendor.unique_event_idevent.id 
@s3.object.keyeventType 
Vendor.event_typeeventType 
Vendor.sha256file.hash.sha256SHA256 hash mapping
Vendor.content_typefile.mime_type 
Vendor.filenamefile.nameFilename mapping
Vendor.namefile.name 
Vendor.ownerfile.owner 
Vendor.file_sizefile.size 
Vendor.request_sizehttp.request.bytesRequest size in bytes
Vendor.request_methodhttp.request.methodHTTP method mapping
Vendor.content_typehttp.request.mime_typeContent type mapping
Vendor.refererhttp.request.referrerHTTP referrer mapping
Vendor.response_body_sizehttp.response.body.bytesResponse body size
Vendor.response_sizehttp.response.bytesResponse size in bytes
Vendor.status_codehttp.response.status_codeHTTP status code mapping
Vendor.signature_messagemessage 
Vendor.applicationnetwork.application 
Vendor.packet_sizenetwork.bytesPacket size mapping
Vendor.directionnetwork.directionNetwork traffic direction
Vendor.ip_protocolnetwork.transport 
Vendor.protocolnetwork.transportNetwork protocol mapping
Vendor.origin_ids;observer.egress.interface.id 
Vendor.origin_ids;observer.ingress.interface.id 
Vendor.session_idprocess.entity_id 
Vendor.attack_classificationrule.category 
Vendor.signature_methodrule.description 
Vendor.firewall_rule_idrule.id 
Vendor.rule_idrule.idRule ID mapping
Vendor.signature_idrule.id 
Vendor.rulerule.name 
Vendor.ruleset_idrule.uuidRule UUID mapping
Vendor.signature_list_idrule.uuid 
Vendor.internal_client_ipsource.addressClient IP address mapping
Vendor.internal_ipsource.addressDirect mapping for internal IP address
Vendor.data_centersource.geo.name 
Vendor.source_ipsource.ip 
source.address;source.ip 
Vendor.external_client_ipsource.nat.ipExternal client IP mapping
Vendor.external_ipsource.nat.ipNAT IP mapping
Vendor.source_portsource.port 
Vendor.urlurl.originalURL mapping
Vendor.emailuser.email 
Vendor.useruser.name 
Vendor.user_agentuser_agent.originalUser agent string mapping
Vendor.cvesvulnerability.reference