Parsers and Generated Fields

Tag Fields Created by Parser claroty-ctd
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser claroty-ctd
Vendor FieldCPS FieldDescription
Vendor.ext.CtdDestinationHostdestination.domainDestination hostname (converted to lowercase)
Vendor.ext.CtdDestinationIpdestination.ipDestination IP address
Vendor.ext.CtdDestinationMacdestination.macDestination MAC address (reformatted with hyphens)
Vendor.event_class_idevent.category[]Event categorization (Alert*=threat, others=network)
Vendor.event_class_idevent.kindEvent classification (Alert*=alert, others=event)
Vendor.severityevent.severityNumeric severity (2=30, 5=50, 7=70, 10=90)
Vendor.event_class_idevent.type[]Event type (Alert*=indicator, others=info)
Vendor.ext.CtdFilePathfile.pathFile path (only for Insight events)
Vendor.severitylog.levelSeverity level mapping (2=low, 5=medium, 7=high, 10=critical)
Vendor.ext.CtdMessagemessageMessage content
Vendor.ext.CtdSourceHostsource.domainSource hostname (converted to lowercase)
Vendor.ext.CtdSourceIpsource.ipSource IP address
Vendor.ext.CtdSourceMacsource.macSource MAC address (reformatted with hyphens)
Vendor.ext.CtdCveIdvulnerability.idCVE identifier (only for Insight events)
Vendor.ext.CtdCveScorevulnerability.score.baseCVE score (only for Insight events)