Parsers and Generated Fields

Tag Fields Created by Parser darktrace-detect
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser darktrace-detect
Vendor FieldCPS FieldDescription
`email.from.address[]`ArrayVendor.from
`email.to.address[]`ArrayVendor.recipients[]
`event.category[]`Arrayevent.dataset
`event.type[]`Arrayevent.dataset, Vendor.inhibitor, Vendor.reason
`host.ip[]`ArrayVendor.device.ip, Vendor.device.ip6, Vendor.ip_address, Vendor.hostname, Vendor.dvc
`rule.author[]`ArrayVendor.model.created.by
`threat.tactic.name[]`ArrayVendor.mitreTactics[]
`threat.technique.id[]`ArrayVendor.mitreTechniques[].techniqueID, Vendor.mitreId
`threat.technique.name[]`ArrayVendor.mitreTechniques[].technique
`destination.address`CopiedVendor.dst
`destination.mac`CopiedVendor.mac
`email.direction`CopiedVendor.direction
`email.subject`CopiedVendor.subject
`event.action`CopiedVendor.type, Vendor.model
`event.code`CopiedVendor.codeid
`event.created`CopiedVendor.creationTime
`event.end`CopiedVendor.periods[0].end, Vendor.end
`event.id`CopiedVendor.id, Vendor.uuid, Vendor.codeuuid
`event.reason`CopiedVendor.title, Vendor.description, Vendor.message, Vendor.reason, Vendor.name
`event.risk_score`CopiedVendor.aiaScore, Vendor.score, Vendor.anomaly_score, Vendor.priority
`event.start`CopiedVendor.periods[0].start, Vendor.start
`event.url`CopiedVendor.incidentEventUrl, Vendor.breachUrl, Vendor.url, Vendor.darktraceUrl
`group.id`CopiedVendor.currentGroup
`host.hostname`CopiedVendor.device.hostname, Vendor.hostname
`host.id`CopiedVendor.device.did
`host.name`CopiedVendor.dvchost
`host.type`CopiedVendor.device.typename
`http.request.method`CopiedVendor.method
`http.response.status_code`CopiedVendor.status
`message`CopiedVendor.name
`process.pid`CopiedVendor.pdid
`rule.category`CopiedVendor.model.category, Vendor.action_family
`rule.description`CopiedVendor.model.description, Vendor.inhibitor
`rule.name`CopiedVendor.model.name, Vendor.model
`rule.uuid`CopiedVendor.model.uuid
`rule.version`CopiedVendor.model.version
`source.ip`CopiedVendor.sourceIP, Vendor.ip
`threat.group.id`CopiedVendor.activityId, Vendor.currentGroup
`user.name`CopiedVendor.username
`email.message_id`ExtractedVendor.message_id
`event.dataset`ExtractedVendor.summariser, Vendor.model.name, Vendor.alert_name, Vendor.ms_ts, Vendor.iris-event-type, Vendor.device.product, Vendor.direction
`log.syslog.appname`Extracted@rawstring
`log.syslog.hostname`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`event.outcome`MappedVendor.reason, http.response.status_code, Vendor.inhibitor
`event.severity`MappedVendor.aiaScore, Vendor.score, Vendor.model.priority, Vendor.priority, Vendor.severity
`@timestamp`Parsedts, Vendor.createdAt, Vendor.time, Vendor.last_updated, Vendor.ms_ts, Vendor.start
`email.attachments[].file.hash.sha1`ParsedVendor.attachment_sha1s[]
`email.attachments[].file.hash.sha256`ParsedVendor.attachment_sha256s[]
`ecs.version`StaticNone
`event.kind`StaticVendor.category, Vendor.status
`event.module`StaticNone
`observer.type`StaticNone
`host.mac[0]`TransformedVendor.device.macaddress, Vendor.deviceMacAddress, host.mac
`host.os.type`TransformedVendor.device.os
Vendor.dstdestination.address 
Vendor.macdestination.mac 
Vendor.directionemail.direction 
Vendor.subjectemail.subject 
Vendor.modelevent.action 
Vendor.typeevent.action 
Vendor.codeidevent.code 
Vendor.creationTimeevent.created 
Vendor.endevent.end 
Vendor.periods[0].endevent.end 
Vendor.codeuuidevent.id 
Vendor.idevent.id 
Vendor.uuidevent.id 
Vendor.descriptionevent.reason 
Vendor.messageevent.reason 
Vendor.nameevent.reason 
Vendor.reasonevent.reason 
Vendor.titleevent.reason 
Vendor.aiaScoreevent.risk_score 
Vendor.anomaly_scoreevent.risk_score 
Vendor.priorityevent.risk_score 
Vendor.scoreevent.risk_score 
Vendor.periods[0].startevent.start 
Vendor.startevent.start 
Vendor.breachUrlevent.url 
Vendor.darktraceUrlevent.url 
Vendor.incidentEventUrlevent.url 
Vendor.urlevent.url 
Vendor.device.hostnamehost.hostname 
Vendor.device.didhost.id 
Vendor.deviceMacAddresshost.mac 
Vendor.dvchosthost.name 
Vendor.device.typenamehost.type 
Vendor.methodhttp.request.method 
Vendor.namemessage 
Vendor.pdidprocess.pid 
Vendor.action_familyrule.category 
Vendor.model.categoryrule.category 
Vendor.inhibitorrule.description 
Vendor.model.descriptionrule.description 
Vendor.modelrule.name 
Vendor.model.namerule.name 
Vendor.model.uuidrule.uuid 
Vendor.model.versionrule.version 
Vendor.ipsource.ip 
Vendor.activityIdthreat.group.id 
x.techniqueIDthreat.technique.id 
x.techniquethreat.technique.name 
Vendor.usernameuser.name