Parsers and Generated Fields

Tag Fields Created by Parser cisco-umbrella
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cisco-umbrella
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayVendor.action
`event.dataset`ConditionalNone
`source.ip`Conditionalsource.address
`cloud.region`CopiedVendor.aws_region
`destination.address`CopiedVendor.destination_ip
`destination.domain`CopiedVendor.destination
`destination.ip`CopiedVendor.destination_ip
`destination.port`CopiedVendor.destination_port
`dns.question.name`CopiedVendor.domain
`dns.question.type`CopiedVendor.query_type
`dns.response_code`CopiedVendor.response_code
`error.message`CopiedVendor.certificate_errors
`event.action`CopiedVendor.action
`event.id`CopiedVendor.id, Vendor.unique_event_id
`file.hash.sha256`CopiedVendor.sha256
`file.mime_type`CopiedVendor.content_type
`file.name`CopiedVendor.filename, Vendor.name
`file.owner`CopiedVendor.owner
`file.size`CopiedVendor.file_size
`http.request.bytes`CopiedVendor.request_size
`http.request.method`CopiedVendor.request_method
`http.request.mime_type`CopiedVendor.content_type
`http.request.referrer`CopiedVendor.referer
`http.response.body.bytes`CopiedVendor.response_body_size
`http.response.bytes`CopiedVendor.response_size
`http.response.status_code`CopiedVendor.status_code
`message`CopiedVendor.signature_message
`network.application`CopiedVendor.application
`network.bytes`CopiedVendor.packet_size
`network.transport`CopiedVendor.protocol, Vendor.ip_protocol
`observer.egress.interface.id`CopiedVendor.origin_ids
`observer.ingress.interface.id`CopiedVendor.origin_ids
`process.entity_id`CopiedVendor.session_id
`rule.category`CopiedVendor.attack_classification
`rule.description`CopiedVendor.signature_method
`rule.id`CopiedVendor.rule_id, Vendor.signature_id, Vendor.firewall_rule_id
`rule.name`CopiedVendor.rule
`rule.uuid`CopiedVendor.ruleset_id, Vendor.signature_list_id
`source.address`CopiedVendor.internal_ip, Vendor.internal_client_ip
`source.geo.name`CopiedVendor.data_center
`source.nat.ip`CopiedVendor.external_ip, Vendor.external_client_ip
`source.port`CopiedVendor.source_port
`url.original`CopiedVendor.url
`user.email`CopiedVendor.email
`user.name`CopiedVendor.user
`user_agent.original`CopiedVendor.user_agent
`vulnerability.reference`CopiedVendor.cves
`@timestamp`ExtractedVendor.timestamp
`network.direction`MappedVendor.direction
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.aws_regioncloud.region 
Vendor.destinationdestination.domain 
Vendor.destination_ipdestination.ip 
Vendor.destination_portdestination.port 
Vendor.domaindns.question.name 
Vendor.query_typedns.question.type 
Vendor.response_codedns.response_code 
Vendor.certificate_errorserror.message 
Vendor.idevent.id 
Vendor.unique_event_idevent.id 
@s3.object.keyeventType 
Vendor.event_typeeventType 
Vendor.content_typefile.mime_type 
Vendor.filenamefile.name 
Vendor.namefile.name 
Vendor.ownerfile.owner 
Vendor.file_sizefile.size 
Vendor.request_sizehttp.request.bytes 
Vendor.request_methodhttp.request.method 
Vendor.content_typehttp.request.mime_type 
Vendor.refererhttp.request.referrer 
Vendor.response_body_sizehttp.response.body.bytes 
Vendor.response_sizehttp.response.bytes 
Vendor.status_codehttp.response.status_code 
Vendor.signature_messagemessage 
Vendor.applicationnetwork.application 
Vendor.packet_sizenetwork.bytes 
Vendor.ip_protocolnetwork.transport 
Vendor.protocolnetwork.transport 
Vendor.session_idprocess.entity_id 
Vendor.attack_classificationrule.category 
Vendor.signature_methodrule.description 
Vendor.firewall_rule_idrule.id 
Vendor.rule_idrule.id 
Vendor.signature_idrule.id 
Vendor.rulerule.name 
Vendor.ruleset_idrule.uuid 
Vendor.signature_list_idrule.uuid 
Vendor.data_centersource.geo.name 
Vendor.source_ipsource.ip 
Vendor.external_client_ipsource.nat.ip 
Vendor.external_ipsource.nat.ip 
Vendor.source_portsource.port 
Vendor.urlurl.original 
Vendor.emailuser.email 
Vendor.useruser.name 
Vendor.user_agentuser_agent.original 
Vendor.cvesvulnerability.reference