Parsers and Generated Fields

Tag Fields Created by Parser purestorage-flashblade
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser purestorage-flashblade
Source FieldCPS FieldDescriptionMapping
Vendor.syslog.timestamp@timestampEvent timestampParsed from syslog timestamp using MMM [ ]d HH:mm:ss format
Noneecs.versionECS schema versionStatic value: 9.3.0
Vendor.ErrorMessageerror.messageError message descriptionCopied from Vendor.ErrorMessage
Vendor.SuggestedAction, Vendor.Action, Vendor.ACTIONevent.actionAction taken or suggestedCopied from Vendor.SuggestedAction or lowercase Vendor.Action or Vendor.ACTION
log.loggerevent.category[]Event categorizationArray populated based on log.logger conditions
Vendor.FirstSeenArray, Vendor.Time, Vendor.UTC_Time, Vendor.timeevent.createdEvent creation timeCopied from various timestamp fields using coalesce
Vendor.u_sidevent.hashEvent hash identifierCopied from lowercase Vendor.u_sid
Vendor.AlertID, Vendor.GUID, Vendor.EventID, Vendor.eidevent.idUnique event identifierCopied from various ID fields using coalesce
Noneevent.kindEvent classificationStatic value: event
Noneevent.moduleModule identifierStatic value: flashblade
Vendor.result, Vendor.SUCCESSevent.outcomeEvent outcome statusMapped from Vendor.result or Vendor.SUCCESS
Vendor.AlertMessage, Vendor.ErrorMessageevent.reasonEvent reason descriptionCopied from alert or error message using coalesce
Vendor.Knowledgebaseevent.referenceReference URL for more informationCopied from Vendor.Knowledgebase
Vendor.AuditIDevent.sequenceEvent sequence numberCopied from Vendor.AuditID
Vendor.SeverityTextevent.severityEvent severity levelMapped from Vendor.SeverityText to numeric values
Vendor.FirstSeenUTCevent.startEvent start timeCopied from Vendor.FirstSeenUTC
None, event.actionevent.type[]Event type classificationStatic value: info or conditional based on event.action
Vendor.fsfile.nameFile system nameCopied from Vendor.fs
Vendor.pathfile.pathFile pathCopied from Vendor.path
Vendor.f_typefile.typeFile typeCopied from Vendor.f_type
Vendor.Host, log.syslog.hostnamehost.hostnameHost identifierCopied from Vendor.Host or log.syslog.hostname, converted to lowercase
@rawstringlog.loggerLogger nameExtracted from syslog header using regex or static assignment
@rawstringlog.syslog.hostnameSyslog hostnameExtracted from syslog header using regex
@rawstringlog.syslog.prioritySyslog priority valueExtracted from syslog header using regex
Vendor.MessagemessageOriginal message contentCopied from Vendor.Message
Vendor.Hostobserver.hostnameObserver hostnameCopied from Vendor.Host
Vendor.DeviceIDobserver.serial_numberObserver device serial numberCopied from Vendor.DeviceID
Vendor.PurityVersionobserver.versionObserver software versionCopied from Vendor.PurityVersion
Vendor.Argumentsprocess.args[]Process arguments arraySplit from Vendor.Arguments by spaces
Vendor.Subcommandprocess.command_lineCommand line executedCopied from Vendor.Subcommand
Vendor.Commandprocess.nameProcess nameCopied from Vendor.Command
Vendor.FROMsource.addressSource addressCopied from lowercase Vendor.FROM
source.addresssource.domainSource domain nameCopied from source.address if not IP
Vendor.Location, Vendor.client_ip, source.addresssource.ipSource IP addressCopied from Vendor.Location, Vendor.client_ip, or source.address if IP
Vendor.User, Vendor.USERuser.nameUsernameCopied from Vendor.User or Vendor.USER