Parsers and Generated Fields

Tag Fields Created by Parser claroty-ctd
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser claroty-ctd
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.event_class_id
`event.type[]`ArrayVendor.event_class_id
`event.kind`ConditionalVendor.event_class_id
`file.path`ConditionalVendor.ext.CtdFilePath
`message`ConditionalVendor.ext.CtdMessage
`vulnerability.id`ConditionalVendor.ext.CtdCveId
`vulnerability.score.base`ConditionalVendor.ext.CtdCveScore
`destination.domain`CopiedVendor.ext.CtdDestinationHost
`destination.mac`CopiedVendor.ext.CtdDestinationMac
`source.domain`CopiedVendor.ext.CtdSourceHost
`source.mac`CopiedVendor.ext.CtdSourceMac
`destination.ip`DirectVendor.ext.CtdDestinationIp
`source.ip`DirectVendor.ext.CtdSourceIp
`log.syslog.appname`ExtractedNone
`log.syslog.hostname`ExtractedNone
`log.syslog.msgid`ExtractedNone
`log.syslog.priority`ExtractedNone
`log.syslog.procid`ExtractedNone
`log.syslog.structured_data`ExtractedNone
`event.severity`MappedVendor.severity
`log.level`MappedVendor.severity
`ecs.version`StaticNone
`event.module`StaticNone
Vendor.ext.CtdDestinationIpdestination.ip 
Vendor.ext.CtdFilePathfile.path 
Vendor.ext.CtdSourceIpsource.ip 
Vendor.ext.CtdCveIdvulnerability.id