Parsers and Generated Fields

Tag Fields Created by Parser cisco-umbrella
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-umbrella
Source FieldLogScale Repository Field
Vendor.useragent.original
Vendor.awscloud.region
Vendor.responsecode
Vendor.statuscode
Vendor.csvcsvData
Vendor.destinationdestination.domain
Vendor.destinationdestination.ip
Vendor.destinationdestination.port
Vendor.domaindns.question.name
Vendor.querydns.question.type
Vendor.certificateerror.message
Vendor.actionevent.action
Vendor.idevent.id
Vendor.uniqueevent.id
Vendor.eventeventType
Vendor.filenamefile.name
Vendor.namefile.name
Vendor.ownerfile.owner
Vendor.filefile.size
Vendor.requesthttp.request.bytes
Vendor.requesthttp.request.method
Vendor.refererhttp.request.referrer
Vendor.responsehttp.response.body.bytes
Vendor.responsehttp.response.bytes
Vendor.sessionid
Vendor.origininterface.id
Vendor.signaturemessage
Vendor.applicationnetwork.application
Vendor.packetnetwork.bytes
Vendor.ipnetwork.transport
Vendor.protocolnetwork.transport
Vendor.attackrule.category
Vendor.signaturerule.description
Vendor.firewallrule.id
Vendor.rulerule.id
Vendor.signaturerule.id
Vendor.rulerule.name
Vendor.rulesetrule.uuid
Vendor.signaturerule.uuid
Vendor.datasource.geo.name
Vendor.sourcesource.ip
source.addresssource.ip
Vendor.externalsource.nat.ip
Vendor.sourcesource.port
Vendor.contenttype
Vendor.urlurl.original
Vendor.emailuser.email
Vendor.useruser.name
Vendor.cvesvulnerability.reference