Parsers and Generated Fields

Tag Fields Created by Parser cisco-umbrella
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-umbrella
Source FieldCPS Field
Vendor.aws_regioncloud.region
Vendor.csv_row;csvData
Vendor.destinationdestination.domain
Vendor.destination_ipdestination.ip
Vendor.destination_portdestination.port
Vendor.domaindns.question.name
Vendor.query_typedns.question.type
Vendor.response_codedns.response_code
Vendor.certificate_errorserror.message
Vendor.actionevent.action
Vendor.actionevent.action
Vendor.idevent.id
Vendor.unique_event_idevent.id
@s3.object.keyeventType
Vendor.event_typeeventType
Vendor.content_typefile.mime_type
Vendor.filenamefile.name
Vendor.namefile.name
Vendor.ownerfile.owner
Vendor.file_sizefile.size
Vendor.request_sizehttp.request.bytes
Vendor.request_methodhttp.request.method
Vendor.content_typehttp.request.mime_type
Vendor.refererhttp.request.referrer
Vendor.response_body_sizehttp.response.body.bytes
Vendor.response_sizehttp.response.bytes
Vendor.status_codehttp.response.status_code
Vendor.signature_messagemessage
Vendor.applicationnetwork.application
Vendor.packet_sizenetwork.bytes
Vendor.ip_protocolnetwork.transport
Vendor.protocolnetwork.transport
Vendor.origin_ids;observer.egress.interface.id
Vendor.origin_ids;observer.ingress.interface.id
Vendor.session_idprocess.entity_id
Vendor.attack_classificationrule.category
Vendor.signature_methodrule.description
Vendor.firewall_rule_idrule.id
Vendor.rule_idrule.id
Vendor.signature_idrule.id
Vendor.rulerule.name
Vendor.ruleset_idrule.uuid
Vendor.signature_list_idrule.uuid
Vendor.data_centersource.geo.name
Vendor.source_ipsource.ip
source.address;source.ip
Vendor.external_client_ipsource.nat.ip
Vendor.external_ipsource.nat.ip
Vendor.source_portsource.port
Vendor.urlurl.original
Vendor.emailuser.email
Vendor.useruser.name
Vendor.user_agentuser_agent.original
Vendor.cvesvulnerability.reference