Parsers and Generated Fields

Tag Fields Created by Parser cisco-umbrella
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-umbrella
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayVendor.action
`client.domain`Conditionalclient.address
`client.ip`Conditionalclient.address
`destination.ip`Conditionaldestination.address
`event.dataset`ConditionalNone
`network.type`ConditionalNone
`server.domain`Conditionalserver.address
`server.ip`Conditionalserver.address
`source.domain`Conditionalsource.address
`source.ip`Conditionalsource.address
`client.address`CopiedVendor.internal_ip, Vendor.internal_client_ip
`client.port`Copiedsource.port
`cloud.region`CopiedVendor.aws_region
`destination.address`CopiedVendor.destination_ip
`destination.domain`CopiedVendor.destination, Vendor.fqdns
`destination.port`CopiedVendor.destination_port
`dns.question.name`CopiedVendor.domain
`dns.question.type`CopiedVendor.query_type
`dns.response_code`CopiedVendor.response_code
`error.message`CopiedVendor.certificate_errors
`event.action`CopiedVendor.action
`event.id`CopiedVendor.id, Vendor.unique_event_id
`event.risk_score`CopiedVendor.amp_score
`file.hash.sha256`CopiedVendor.sha256
`file.mime_type`CopiedVendor.content_type
`file.name`CopiedVendor.filename, Vendor.name
`file.owner`CopiedVendor.owner
`file.size`CopiedVendor.file_size
`http.request.bytes`CopiedVendor.request_size
`http.request.method`CopiedVendor.request_method
`http.request.mime_type`CopiedVendor.content_type
`http.request.referrer`CopiedVendor.referer
`http.response.body.bytes`CopiedVendor.response_body_size
`http.response.bytes`CopiedVendor.response_size
`http.response.status_code`CopiedVendor.status_code
`message`CopiedVendor.signature_message
`network.application`CopiedVendor.application, Vendor.application_entity_name
`network.bytes`CopiedVendor.packet_size
`network.iana_number`CopiedVendor.protocol
`network.transport`CopiedVendor.ip_protocol
`observer.egress.interface.id`CopiedVendor.origin_ids
`observer.ingress.interface.id`CopiedVendor.origin_ids
`organization.id`CopiedVendor.organization_id
`rule.category`CopiedVendor.attack_classification
`rule.description`CopiedVendor.signature_method
`rule.id`CopiedVendor.rule_id, Vendor.signature_id, Vendor.firewall_rule_id
`rule.name`CopiedVendor.rule
`rule.ruleset`CopiedVendor.ruleset_id, Vendor.signature_list_id
`server.address`Copieddestination.address
`server.port`Copieddestination.port
`source.address`CopiedVendor.source_ip, Vendor.internal_ip
`source.geo.name`CopiedVendor.data_center
`source.nat.ip`CopiedVendor.egress_ip, Vendor.external_client_ip
`source.port`CopiedVendor.source_port
`threat.software.name`CopiedVendor.amp_malware_name
`url.original`CopiedVendor.url
`user_agent.original`CopiedVendor.user_agent
`vulnerability.id`CopiedVendor.cves
`user.email`ExtractedVendor.identity, Vendor.email
`user.full_name`ExtractedVendor.identity
`user.name`ExtractedVendor.identity, Vendor.user
`event.severity`MappedVendor.severity
`network.direction`MappedVendor.direction, Vendor.traffic_direction
`@timestamp`ParsedVendor.timestamp
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`threat.software.type`StaticVendor.amp_malware_name
@s3.object.key__eventType 
Vendor.event_type__eventType 
source.addressclient.address 
client.addressclient.ip 
source.portclient.port 
Vendor.aws_regioncloud.region 
Vendor.external_ipdestination.address 
destination.addressdestination.ip 
Vendor.domaindns.question.name 
Vendor.query_typedns.question.type 
Vendor.response_codedns.response_code 
Vendor.certificate_errorserror.message 
Vendor.idevent.id 
Vendor.unique_event_idevent.id 
Vendor.amp_scoreevent.risk_score 
Vendor.content_typefile.mime_type 
Vendor.filenamefile.name 
Vendor.namefile.name 
Vendor.ownerfile.owner 
Vendor.file_sizefile.size 
Vendor.request_sizehttp.request.bytes 
Vendor.request_methodhttp.request.method 
Vendor.content_typehttp.request.mime_type 
Vendor.refererhttp.request.referrer 
Vendor.response_body_sizehttp.response.body.bytes 
Vendor.response_sizehttp.response.bytes 
Vendor.status_codehttp.response.status_code 
Vendor.signature_messagemessage 
Vendor.applicationnetwork.application 
Vendor.application_entity_namenetwork.application 
Vendor.packet_sizenetwork.bytes 
Vendor.protocolnetwork.iana_number 
Vendor.organization_idorganization.id 
Vendor.attack_classificationrule.category 
Vendor.signature_methodrule.description 
Vendor.rule_idrule.id 
Vendor.rulerule.name 
Vendor.ruleset_idrule.ruleset 
Vendor.signature_list_idrule.ruleset 
destination.addressserver.address 
server.addressserver.ip 
destination.portserver.port 
Vendor.data_centersource.geo.name 
source.addresssource.ip 
Vendor.egress_ipsource.nat.ip 
Vendor.external_client_ipsource.nat.ip 
Vendor.source_portsource.port 
Vendor.amp_malware_namethreat.software.name 
Vendor.urlurl.original 
Vendor.emailuser.email 
Vendor.useruser.name 
Vendor.cvesvulnerability.id