Parsers and Generated Fields

Tag Fields Created by Parser darktrace-detect
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser darktrace-detect
Vendor FieldCPS FieldDescription
Vendor.modelevent.actionEvent action for Antigena events
Vendor.codeidevent.codeEvent code for Antigena events
Vendor.creationTimeevent.created 
Vendor.endevent.endEvent end time for Antigena events
Vendor.periods[0].endevent.endEvent end time
Vendor.codeuuidevent.idEvent ID for Antigena events
Vendor.idevent.idEvent identifier for AI Analyst events
Vendor.uuidevent.idEvent identifier for audit events
Vendor.messageevent.reason 
Vendor.reasonevent.reasonEvent reason for Antigena events
Vendor.titleevent.reasonEvent title/reason
Vendor.typeevent.reasonEvent reason for audit events
Vendor.aiaScoreevent.risk_scoreAI Analyst score
Vendor.priorityevent.risk_score 
Vendor.scoreevent.risk_score 
Vendor.model.priorityevent.severity 
Vendor.periods[0].startevent.startEvent start time
Vendor.startevent.startEvent start time for Antigena events
Vendor.breachUrlevent.url 
Vendor.incidentEventUrlevent.urlEvent URL
Vendor.urlevent.urlEvent URL for Antigena events
Vendor.device.hostnamehost.hostname 
Vendor.device.hostname;host.hostname 
Vendor.hostname;host.hostname 
Vendor.device.hostnamehost.hostname/host.ip[0]Hostname or IP based on format
Vendor.device.didhost.idDevice identifier
Vendor.device.iphost.ip[0]Device IP address
Vendor.device.ip6host.ip[1]Device IPv6 address
Vendor.device.macaddresshost.mac[0]Device MAC address
Vendor.device.oshost.os.typeHost OS type for Antigena events
Vendor.device.typenamehost.typeDevice type
Vendor.pdidprocess.pidProcess ID for Antigena events
Vendor.model.created.byrule.author[0]Model creator
Vendor.action_familyrule.categoryRule category for Antigena events
Vendor.model.categoryrule.categoryModel category
Vendor.inhibitorrule.descriptionRule description for Antigena events
Vendor.model.descriptionrule.description 
Vendor.modelrule.name 
Vendor.model.namerule.name 
Vendor.model.uuidrule.uuid 
Vendor.model.versionrule.version 
Vendor.descriptionsource.ipSource IP extracted from description for login events
Vendor.sourceIPsource.ipSource IP address
Vendor.activityIdthreat.group.idThreat group identifier
Vendor.usernameuser.nameUsername for audit events
Vendor.username;user.name