Parsers and Generated Fields

Tag Fields Created by Parser ai_analyst_alert-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser ai_analyst_alert-syslog
Source FieldLogScale Repository Field
Vendor.periods[0].endevent.end
Vendor.idevent.id
Vendor.titleevent.reason
Vendor.periods[0].startevent.start
Vendor.incidentEventUrlevent.url
Vendor.aiaScorescore
Vendor.activityIdthreat.group.id
Tag Fields Created by Parser model_breach_alert-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser model_breach_alert-syslog
Source FieldLogScale Repository Field
Vendor.creationTimeevent.created
Vendor.model.priorityevent.severity
Vendor.breachUrlevent.url
Vendor.device.hostnamehost.hostname
Vendor.device.didhost.id
Vendor.device.iphost.ip[0]
Vendor.device.ip6host.ip[1]
Vendor.device.typenamehost.type
Vendor.device.hostnamerelated.ip[0]
Vendor.model.created.byrule.author
Vendor.model.categoryrule.category
Vendor.model.descriptionrule.description
Vendor.model.namerule.name
Vendor.model.uuidrule.uuid
Vendor.model.versionrule.version
Vendor.scorescore
Tag Fields Created by Parser system_status_alert-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser system_status_alert-syslog
Source FieldLogScale Repository Field
Vendor.uuidevent.id
Vendor.messageevent.reason
Vendor.urlevent.url
Vendor.hostnamehost.hostname
Vendor.iphost.ip[0]
Vendor.hostnamerelated.ip[0]
Vendor.priorityscore