Parsers and Generated Fields

Tag Fields Created by Parser dell-isilon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser dell-isilon
Source FieldCPS FieldDescriptionMapping
@rawstring@timestampEvent timestampParsed from syslog timestamp using parseTimestamp()
client.ipclient.addressClient addressCopied from client.ip
Vendor.clientIPAddrclient.ipClient IP addressCopied from Vendor.clientIPAddr
Noneecs.versionECS schema versionStatic value: 9.1.0
Vendor.operationevent.actionFile system operation performedCopied from Vendor.operation (converted to lowercase)
Noneevent.category[]Event category classificationArray populated with static value "file"
Noneevent.kindEvent kind classificationStatic value: event
Noneevent.moduleModule nameStatic value: isilon
Vendor.ntStatusevent.outcomeOperation result statusMapped based on Vendor.ntStatus conditions
Noneevent.type[]Event type classificationArray populated with static value "info"
Vendor.inodefile.inodeFile inode numberCopied from Vendor.inode
Vendor.filenamefile.pathFile pathCopied from Vendor.filename
Vendor.syslog.applog.syslog.appnameSyslog application nameCopied from Vendor.syslog.app
Vendor.syslog.hostlog.syslog.hostnameSyslog hostnameCopied from Vendor.syslog.host
Vendor.syslog.prioritylog.syslog.prioritySyslog priority valueCopied from Vendor.syslog.priority
Vendor.syslog.pidlog.syslog.procidSyslog process IDCopied from Vendor.syslog.pid
Vendor.protocolnetwork.protocolNetwork protocol usedCopied from Vendor.protocol (converted to lowercase)
Vendor.userSIDuser.idUser security identifierCopied from Vendor.userSID
Vendor.usernameuser.nameUsernameCopied from Vendor.username