Parsers and Generated Fields

Tag Fields Created by Parser cloudflare-one
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser cloudflare-one
Vendor FieldCPS FieldDescription
__tmp_event@rawstring  
`event.category[]`Arrayevent.dataset
`event.type[]`Arrayevent.dataset, Vendor.Action, Vendor.HTTPStatusCode, Vendor.EdgeResponseStatus
`host.ip[]`ArrayVendor.DeviceIPv4Address, Vendor.DeviceIPv6Address
`event.duration`CalculatedVendor.HTTPResponseEndMs, Vendor.HTTPRequestStartMs
`network.bytes`Calculatedsource.bytes, destination.bytes
`client.address`CopiedVendor.IPAddress, Vendor.ClientIP, Vendor.ClientAddress, Vendor.HTTPClientIPAddress, Vendor.ISPIPv4Address
`client.as.number`CopiedVendor.ClientASN, Vendor.HTTPClientIPASN
`client.as.organization.name`CopiedVendor.HTTPClientIPASO
`client.bytes`CopiedVendor.NetworkSentBPS
`client.domain`CopiedVendor.ClientRequestHost
`client.geo.city_name`CopiedVendor.HTTPClientIPCity, Vendor.ISPIPv4City
`client.geo.country_iso_code`CopiedVendor.HTTPClientIPCountryISO, Vendor.ISPIPv4CountryISO
`client.geo.postal_code`CopiedVendor.HTTPClientIPZip, Vendor.ISPIPv4Zip
`client.geo.region_iso_code`CopiedVendor.HTTPClientIPStateISO, Vendor.ISPIPv4StateISO
`client.port`CopiedVendor.ClientSrcPort
`cloud.account.id`CopiedVendor.AccountID
`destination.address`CopiedVendor.DstIP, Vendor.DestinationIP, Vendor.OriginIP, Vendor.IPDestinationAddress, Vendor.RemoteIP, Vendor.DestAddr
`destination.bytes`CopiedVendor.BytesReceived
`destination.domain`CopiedVendor.SNI
`destination.port`CopiedVendor.DstPort, Vendor.DestinationPort, Vendor.OriginPort, Vendor.RemotePort
`device.id`Copiedhost.id
`dns.answers[].data`CopiedVendor.RData[].data
`dns.answers[].type`CopiedVendor.RData[].type
`dns.question.name`CopiedVendor.QueryName
`dns.question.type`CopiedVendor.QueryTypeName, Vendor.QueryType
`email.from.address[]`CopiedVendor.event.from, Vendor.From
`email.message_id`CopiedVendor.event.message_id, Vendor.MessageID
`email.reply_to.address[]`CopiedVendor.event.replyto
`email.sender.address`CopiedVendor.event.envelope_from
`email.subject`CopiedVendor.event.subject, Vendor.Subject
`email.to.address[]`CopiedVendor.event.to[], Vendor.To[]
`error.message`CopiedVendor.Error
`event.action`CopiedVendor.Action, Vendor.SecurityAction, Vendor.ActionType, Vendor.ConnectionCloseReason, Vendor.ResolverDecision
`event.end`CopiedVendor.HTTPResponseEndMs
`event.id`CopiedVendor.SessionID, Vendor.event.alert_id, Vendor.AlertID
`event.provider`CopiedVendor.Interface
`event.reason`CopiedVendor.PurposeJustificationPrompt, Vendor.event.alert_reasons, Vendor.AlertReasons
`event.risk_score`CopiedVendor.WAFAttackScore
`event.start`CopiedVendor.HTTPRequestStartMs
`file.extension`CopiedVendor.BlockedFileType
`file.hash.sha256`CopiedVendor.BlockedFileHash
`file.name`CopiedVendor.BlockedFileName
`file.size`CopiedVendor.BlockedFileSize
`host.id`CopiedVendor.DeviceID
`host.name`CopiedVendor.DeviceName, Vendor.Hostname, Vendor.TracerouteDestinationHostname
`host.os.family`CopiedVendor.DeviceType
`host.os.type`CopiedVendor.ClientPlatform
`host.os.version`CopiedVendor.OSVersion, Vendor.ClientVersion
`http.request.method`CopiedVendor.HTTPMethod, Vendor.ClientRequestMethod, Vendor.Event.Request.Method, Vendor.Method
`http.request.referrer`CopiedVendor.Referer, Vendor.ClientRequestReferer
`http.response.body.bytes`CopiedVendor.HTTPResponseBodyBytes
`http.response.status_code`CopiedVendor.HTTPStatusCode, Vendor.EdgeResponseStatus, Vendor.Event.Response.Status
`log.level`CopiedVendor.Level
`message`CopiedVendor.SignatureMessage, Vendor.Message
`network.direction`CopiedVendor.Direction
`network.protocol`CopiedVendor.Protocol, Vendor.ClientRequestScheme
`network.transport`CopiedVendor.Transport, Vendor.Protocol, Vendor.QueryTCP
`network.type`CopiedVendor.HTTPServerIPVersion
`network.vlan.id`CopiedVendor.VirtualNetworkID
`observer.egress.interface.name`CopiedVendor.Offramp
`observer.name`CopiedVendor.host
`process.end`CopiedVendor.SessionEndDatetime
`process.start`CopiedVendor.SessionStartDatetime
`process.tty`CopiedVendor.PTY
`rule.category`CopiedVendor.PostureCheckType
`rule.description`CopiedVendor.WAFRuleMessage
`rule.id`CopiedVendor.PolicyID, Vendor.TriggeredRuleID
`rule.name`CopiedVendor.PostureCheckName, Vendor.PolicyName
`server.address`CopiedVendor.event.smtp_helo_server_name, Vendor.ServerAddress, Vendor.HTTPServerIPAddress
`server.as.number`CopiedVendor.event.smtp_helo_server_ip_as_number, Vendor.HTTPServerIPASN
`server.as.organization.name`CopiedVendor.HTTPServerIPASO
`server.bytes`CopiedVendor.NetworkReceivedBPS
`server.geo.city_name`CopiedVendor.HTTPServerIPCity
`server.geo.country_iso_code`CopiedVendor.HTTPServerIPCountryISO
`server.geo.postal_code`CopiedVendor.HTTPServerIPZip
`server.geo.region_iso_code`CopiedVendor.HTTPServerIPStateISO
`service.id`CopiedVendor.AppUUID
`source.address`CopiedVendor.SrcIP, Vendor.SourceIP, Vendor.ActorIP, Vendor.ActorIPAddress, Vendor.IPSourceAddress, Vendor.LocalIP, Vendor.SrcAddr
`source.bytes`CopiedVendor.BytesSent
`source.geo.city_name`CopiedVendor.ColoCity
`source.geo.country_iso_code`CopiedVendor.Country, Vendor.ClientCountry
`source.geo.region_name`CopiedVendor.ColoCode
`source.port`CopiedVendor.SrcPort, Vendor.SourcePort, VendorLocalPort
`threat.indicator.description`Copiedevent.reason
`tls.cipher`CopiedVendor.ClientSSLCipher, Vendor.ClientTLSCipher
`tls.client.server_name`CopiedVendor.SNI
`tls.server.issuer`CopiedVendor.OriginTLSCertificateIssuer
`tls.version_protocol`CopiedVendor.ClientSSLProtocol
`url.original`CopiedVendor.URL, Vendor.AssetLink, Vendor.HTTPURL, Vendor.Event.Request.URL
`user.email`CopiedVendor.Email, Vendor.ActorEmail, Vendor.UserEmail
`user.id`CopiedVendor.UserID, Vendor.ActorID, Vendor.UserUID
`user.name`CopiedVendor.Username
`user_agent.original`CopiedVendor.UserAgent, Vendor.ClientRequestUserAgent, Vendor.Event.Request.Headers.User-Agent
`user_agent.version`CopiedVendor.ClientVersion
`vulnerability.description`CopiedVendor.FindingTypeDisplayName
`vulnerability.severity`CopiedVendor.FindingTypeSeverity
`event.outcome`DeterminedVendor.ActionResult, Vendor.Allowed, Vendor.HTTPStatusCode, Vendor.EdgeResponseStatus, Vendor.ConnectionCloseReason, Vendor.ClientResponseCode, Vendor.Exceptions
`client.ip`Extractedclient.address
`destination.ip`Extracteddestination.address
`email.attachments[].file.hash.md5`ExtractedVendor.event.attachments[].md5, Vendor.Attachments[].Md5
`email.attachments[].file.hash.sha1`ExtractedVendor.event.attachments[].sha1, Vendor.Attachments[].Sha1
`email.attachments[].file.hash.sha256`ExtractedVendor.event.attachments[].sha256, Vendor.Attachments[].Sha256
`email.attachments[].file.mime_type`ExtractedVendor.event.attachments[].content_type_computed, Vendor.Attachments[].ContentTypeComputed
`email.attachments[].file.name`ExtractedVendor.event.attachments[].name, Vendor.Attachments[].Name
`event.dataset`Extracted@s3.object.key, various Vendor fields
`http.request.mime_type`ExtractedVendor.Headers.Content-Type
`http.response.mime_type`ExtractedVendor.Headers.Content-Type
`http.version`ExtractedVendor.HTTPVersion
`server.domain`Extractedserver.address
`server.ip`Extractedserver.address
`source.ip`Extractedsource.address
`tls.version`ExtractedVendor.ClientTLSVersion
`dns.response_code`MappedVendor.RCode, Vendor.ClientResponseCode
`event.severity`Mappedevent.risk_score, Vendor.FindingTypeSeverity
`threat.indicator.confidence`Mappedevent.risk_score
`@timestamp`ParsedVendor.Datetime, Vendor.When, Vendor.CreatedAt, Vendor.DetectedTimestamp, Vendor.Timestamp, Vendor.SessionStartTime, Vendor.EdgeStartTimestamp, Vendor.time, Vendor.EventTimestampMs, Vendor.ActionTimestamp
`dns.resolved_ip`ParsedVendor.ResolvedIPs
`url.domain`Parsedurl.original, Vendor.AppDomain
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
x.data__dnsanswers 
x.type__dnsanswers 
x.ContentTypeComputed_emailattachments 
x.Md5_emailattachments 
x.Name_emailattachments 
x.Sha1_emailattachments 
x.Sha256_emailattachments 
x.content_type_computed_emailattachments 
x.md5_emailattachments 
x.name_emailattachments 
x.sha1_emailattachments 
x.sha256_emailattachments 
Vendor.ClientIPclient.address 
Vendor.HTTPClientIPAddressclient.address 
Vendor.IPclient.address 
Vendor.ISPIPv4Addressclient.address 
Vendor.ClientASNclient.as.number 
Vendor.HTTPClientIPASNclient.as.number 
Vendor.HTTPClientIPASOclient.as.organization.name 
Vendor.NetworkSentBPSclient.bytes 
Vendor.ClientRequestHostclient.domain 
Vendor.HTTPClientIPCityclient.geo.city_name 
Vendor.ISPIPv4Cityclient.geo.city_name 
Vendor.ClientCountryclient.geo.country_iso_code 
Vendor.ClientIPCountryclient.geo.country_iso_code 
Vendor.HTTPClientIPCountryISOclient.geo.country_iso_code 
Vendor.ISPIPv4CountryISOclient.geo.country_iso_code 
Vendor.HTTPClientIPZipclient.geo.postal_code 
Vendor.ISPIPv4Zipclient.geo.postal_code 
Vendor.HTTPClientIPStateISOclient.geo.region_iso_code 
Vendor.ISPIPv4StateISOclient.geo.region_iso_code 
Vendor.ColoCodeclient.geo.region_name 
Vendor.ClientPortclient.port 
Vendor.ClientSrcPortclient.port 
Vendor.AccountIDcloud.account.id 
Vendor.DestAddrdestination.address 
Vendor.DstIPdestination.address 
Vendor.IPDestinationAddressdestination.address 
Vendor.RemoteIPdestination.address 
Vendor.DestinationASNdestination.as.number 
Vendor.BytesReceiveddestination.bytes 
Vendor.DestinationPortdestination.port 
Vendor.RemotePortdestination.port 
Vendor.DeviceIDdevice.id 
Vendor.QueryNamedns.question.name 
Vendor.QueryTypedns.question.type 
Vendor.QueryTypeNamedns.question.type 
Vendor.ClientResponseCodedns.response_code 
Vendor.MessageIDemail.message_id 
Vendor.event.message_idemail.message_id 
Vendor.Subjectemail.subject 
Vendor.event.subjectemail.subject 
Vendor.Errorerror.message 
Vendor.typeerror.message 
Vendor.Actionevent.action 
Vendor.ActionTypeevent.action 
Vendor.Eventevent.action 
Vendor.SecurityActionevent.action 
Vendor.eventTypeevent.action 
Vendor.typeevent.action 
Vendor.HTTPResponseEndMsevent.end 
Vendor.AlertIDevent.id 
Vendor.event.alert_idevent.id 
Vendor.Interfaceevent.provider 
Vendor.BlockedFileReasonevent.reason 
Vendor.MitigationReasonevent.reason 
Vendor.PurposeJustificationPromptevent.reason 
Vendor.WAFAttackScoreevent.risk_score 
Vendor.HTTPRequestStartMsevent.start 
Vendor.BlockedFileTypefile.extension 
Vendor.BlockedFileSizefile.size 
Vendor.DeviceIDhost.id 
Vendor.DeviceIdhost.id 
Vendor.DeviceNamehost.name 
Vendor.Hosthost.name 
Vendor.Hostnamehost.name 
Vendor.TracerouteDestinationHostnamehost.name 
Vendor.DeviceTypehost.os.family 
Vendor.ClientPlatformhost.os.type 
Vendor.ClientVersionhost.os.version 
Vendor.OSVersionhost.os.version 
Vendor.Methodhttp.request.method 
Vendor.ClientRefererHosthttp.request.referrer 
Vendor.ClientRequestRefererhttp.request.referrer 
Vendor.Refererhttp.request.referrer 
Vendor.HTTPResponseBodyByteshttp.response.body.bytes 
Vendor.HTTPResponseHeaderByteshttp.response.headers.bytes 
Vendor.Levellog.level 
Vendor.Messagemessage 
Vendor.SignatureMessagemessage 
source.bytesnetwork.bytes 
Vendor.Directionnetwork.direction 
Vendor.IPProtocolnetwork.iana_number 
Vendor.VirtualNetworkIDnetwork.vlan.id 
Vendor.Offrampobserver.egress.interface.name 
Vendor.hostobserver.name 
Vendor.SessionEndDatetimeprocess.end 
Vendor.SessionStartDatetimeprocess.start 
Vendor.PTYprocess.tty 
Vendor.PostureCheckTyperule.category 
Vendor.Descriptionrule.description 
Vendor.WAFRuleMessagerule.description 
Vendor.PolicyIDrule.id 
Vendor.RuleIDrule.id 
Vendor.TriggeredRuleIDrule.id 
Vendor.WAFRuleIDrule.id 
Vendor.PolicyNamerule.name 
Vendor.PostureCheckNamerule.name 
Vendor.RuleNamerule.name 
Vendor.RulesetIDrule.ruleset 
Vendor.HTTPServerIPAddressserver.address 
Vendor.ServerAddressserver.address 
Vendor.HTTPServerIPASNserver.as.number 
Vendor.event.smtp_helo_server_ip_as_numberserver.as.number 
Vendor.HTTPServerIPASOserver.as.organization.name 
Vendor.NetworkReceivedBPSserver.bytes 
Vendor.HTTPServerIPCityserver.geo.city_name 
Vendor.HTTPServerIPCountryISOserver.geo.country_iso_code 
Vendor.HTTPServerIPZipserver.geo.postal_code 
Vendor.HTTPServerIPStateISOserver.geo.region_iso_code 
Vendor.event.smtp_helo_server_ipserver.ip 
Vendor.AppUUIDservice.id 
Vendor.IPSourceAddresssource.address 
Vendor.LocalIPsource.address 
Vendor.SourceInternalIPsource.address 
Vendor.SrcAddrsource.address 
Vendor.SrcIPsource.address 
Vendor.SourceASNsource.as.number 
Vendor.BytesSentsource.bytes 
Vendor.ColoCitysource.geo.city_name 
Vendor.ClientCountrysource.geo.country_iso_code 
Vendor.Countrysource.geo.country_iso_code 
Vendor.ColoCodesource.geo.region_name 
event.reasonthreat.indicator.description 
Vendor.SNItls.client.server_name 
Vendor.OriginTLSCertificateIssuertls.server.issuer 
Vendor.AssetLinkurl.original 
Vendor.HTTPURLurl.original 
Vendor.PageURLurl.original 
Vendor.ActorIDuser.id 
Vendor.Usernameuser.name 
Vendor.ClientVersionuser_agent.version 
Vendor.FindingTypeDisplayNamevulnerability.description 
Vendor.FindingTypeSeverityvulnerability.severity