Parsers and Generated Fields

Tag Fields Created by Parser dell-isilon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser dell-isilon
Vendor FieldCPS FieldDescription
client.ipclient.addressClient address from IP
Vendor.clientIPAddrclient.ipClient IP address
Vendor.operationevent.actionOperation type (converted to lowercase)
Vendor.ntStatusevent.outcomeMaps "SUCCESS" to "success", "FAILD*" or "ERROR" to "failure"
Vendor.inodefile.inodeFile inode number
Vendor.filenamefile.pathFile path
Vendor.syslog.applog.syslog.appnameSyslog application name
Vendor.syslog.hostlog.syslog.hostnameSyslog hostname
Vendor.syslog.prioritylog.syslog.prioritySyslog priority
Vendor.syslog.pidlog.syslog.procidSyslog process ID
Vendor.protocolnetwork.protocolProtocol name (converted to lowercase)
Vendor.userSIDuser.idUser SID
Vendor.usernameuser.nameUsername