Parsers and Generated Fields
Tag Fields Created by Parser purestorage-flasharray
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser purestorage-flasharray
| Source Field | CPS Field | Description | Mapping |
|---|---|---|---|
| Vendor.syslog.timestamp | @timestamp | Event timestamp | Parsed from syslog timestamp using MMM [ ]d HH:mm:ss format |
| None | ecs.version | ECS schema version | Static value: 9.3.0 |
| Vendor.Code | error.code | Error code | Copied from Vendor.Code |
| Vendor.ErrorMessage | error.message | Error message content | Copied from Vendor.ErrorMessage |
| Vendor.Action | event.action | Action performed | Copied from Vendor.Action |
| log.logger | event.category[] | Event category classification | Array populated based on log.logger conditions |
| Vendor.UTCTime | event.created | Event creation timestamp | Copied from Vendor.UTCTime |
| Vendor.MessageID | event.id | Unique event identifier | Copied from Vendor.MessageID |
| None | event.kind | Event classification | Static value: event |
| None | event.module | Module identifier | Static value: flasharray |
| Vendor.ErrorMessage, Vendor.AlertID | event.reason | Event reason | Coalesced from error.message or Vendor.AlertID |
| Vendor.SeverityText | event.severity | Event severity level | Mapped from Vendor.SeverityText using severity levels |
| event.action | event.type[] | Event type classification | Array populated based on event.action conditions |
| log.syslog.hostname | host.hostname | Host identifier | Lowercase conversion of log.syslog.hostname |
| @rawstring | log.logger | Logger name | Extracted from syslog message using regex |
| @rawstring | log.syslog.hostname | Syslog hostname | Extracted from syslog message using regex |
| @rawstring | log.syslog.priority | Syslog priority | Extracted from syslog message using regex |
| @rawstring | log.syslog.procid | Process ID | Extracted from syslog message using regex |
| Vendor.Host, Vendor.ArrayName | observer.hostname | Observer hostname | Coalesced from Vendor.Host or Vendor.ArrayName |
| Vendor.User | user.name | Username | Copied from Vendor.User |