Parsers and Generated Fields

Tag Fields Created by Parser f5networks-bigip
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser f5networks-bigip
Vendor FieldCPS FieldDescription
`event.category[]`Arraylog.syslog.appname, log.syslog.msgid
`event.type[]`Arraylog.syslog.msgid, Vendor.message
`host.ip[]`ArrayVendor.host
`observer.ip[]`ArrayVendor.bigip_mgmt_ip, Vendor.manage_ip_addr
`rule.name[]`ArrayVendor.violations, Vendor.acl_rule_name
`threat.group.alias[]`ArrayVendor.threat_campaign_names
`threat.technique.name[]`ArrayVendor.attack_type
`threat.technique.subtechnique.id[]`ArrayVendor.sig_ids
`threat.technique.subtechnique.name[]`ArrayVendor.sig_names
`user.roles[]`ArrayVendor.message
`event.duration`CalculatedVendor.req_elapsed_time
`log.syslog.facility.code`Calculatedlog.syslog.priority
`network.bytes`CalculatedVendor.bytes_in, Vendor.bytes_out
`event.outcome`ConditionalVendor.action, Vendor.status, etc.
`network.type`Conditionalclient.address, destination.address, etc.
`client.address`CopiedVendor.ip_client
`client.geo.country_iso_code`CopiedVendor.client_ip_geo_location
`client.ip`CopiedVendor.client_ip, client.address
`client.port`CopiedVendor.client_port
`destination.address`CopiedVendor.dest_ip, Vendor.dest_fqdn
`destination.bytes`CopiedVendor.bytes_out
`destination.ip`CopiedVendor.dest_ip, destination.address
`destination.nat.ip`CopiedVendor.translated_dest_ip
`destination.nat.port`CopiedVendor.translated_dest_port
`destination.port`CopiedVendor.dest_port
`device.id`CopiedVendor.device_id
`device.manufacturer`CopiedVendor.device_vendor
`dns.question.class`CopiedVendor.question_class
`dns.question.name`CopiedVendor.question_name
`dns.question.registered_domain`CopiedVendor.wideip
`dns.question.type`CopiedVendor.question_type
`event.id`CopiedVendor.support_id
`event.reason`CopiedVendor.drop_reason, Vendor.anomalies
`host.hostname`CopiedVendor.hostname
`http.request.body.bytes`CopiedVendor.bytes_in
`http.request.body.content`CopiedVendor.req
`http.request.method`CopiedVendor.method, Vendor.http_method
`http.request.mime_type`CopiedVendor.http_content_type
`http.request.referrer`CopiedVendor.http_class, Vendor.http_referrer
`http.response.body.bytes`CopiedVendor.bytes_out
`http.response.body.content`CopiedVendor.resp
`http.response.status_code`CopiedVendor.resp_code
`log.level`Copiedlog.syslog.severity.name, Vendor.severity
`network.forwarded_ip`CopiedVendor.x_fwd_hdr_val
`network.protocol`CopiedVendor.ip_protocol, Vendor.http_protocol_indication
`network.transport`CopiedVendor.message
`network.vlan.id`CopiedVendor.dest_vlan
`network.vlan.name`CopiedVendor.vlan
`observer.hostname`CopiedVendor.hostname
`observer.ingress.zone`CopiedVendor.context_name
`observer.product`CopiedVendor.device_product
`observer.version`CopiedVendor.device_version
`process.pid`CopiedVendor.pid
`rule.category`CopiedVendor.acl_policy_name
`rule.id`CopiedVendor.acl_rule_uuid
`rule.ruleset`CopiedVendor.enforced_by, Vendor.acl_policy_type
`server.address`CopiedVendor.node, server.ip
`server.ip`Copiedserver.address
`source.address`CopiedVendor.source_fqdn, Vendor.src_ip
`source.bytes`CopiedVendor.bytes_in
`source.geo.country_iso_code`CopiedVendor.src_geo, Vendor.geo_info
`source.ip`CopiedVendor.source_ip, source.address
`source.nat.ip`CopiedVendor.translated_source_ip
`source.nat.port`CopiedVendor.translated_source_port
`source.port`CopiedVendor.source_port, Vendor.src_port
`source.user.group.name`CopiedVendor.source_user_group
`source.user.name`CopiedVendor.source_user
`url.original`CopiedVendor.http_url
`url.path`CopiedVendor.http_uri, Vendor.client_request_uri
`user.name`CopiedVendor.username, user.name, Vendor.user
`user_agent.original`CopiedVendor.http_user_agent, user_agent.original
`client.domain`ExtractedVendor.message
`error.code`ExtractedVendor.message
`error.message`ExtractedVendor.message
`file.name`Extractedfile.path
`file.path`ExtractedVendor.message
`geo.continent_code`ExtractedVendor.message
`geo.country_iso_code`ExtractedVendor.message
`geo.region_name`ExtractedVendor.message
`http.version`ExtractedVendor.req, Vendor.http_version
`log.syslog.appname`Extracted@rawstring
`log.syslog.hostname`Extracted@rawstring
`log.syslog.msgid`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.procid`Extracted@rawstring
`log.syslog.severity.code`Extracted@rawstring
`log.syslog.severity.name`Extracted@rawstring
`observer.ingress.vlan.id`ExtractedVendor.message
`process.command_line`ExtractedVendor.message
`process.name`ExtractedVendor.message
`server.domain`ExtractedVendor.message
`server.port`ExtractedVendor.message, Vendor.node_port
`tls.cipher`ExtractedVendor.message
`tls.version_protocol`ExtractedVendor.message
`tls.version`ExtractedVendor.message
`url.domain`ExtractedVendor.http_host
`url.port`ExtractedVendor.http_host
`url.scheme`ExtractedVendor.http_referrer
`user.email`ExtractedVendor.message
`user_agent.name`Extracteduser_agent.original
`user_agent.version`Extracteduser_agent.original
`event.severity`MappedVendor.severity
`@timestamp`ParsedVendor.timestamp, _ts
`dns.answers[]`ParsedVendor.answer
`ecs.version`StaticNone
`event.action`Staticlog.syslog.msgid, Vendor.message
`event.dataset`Staticlog.syslog.appname, log.syslog.msgid
`event.kind`StaticVendor.attack_type
`event.module`StaticNone
`observer.vendor`StaticNone
`threat.framework`StaticNone
Vendor.ip_clientclient.address 
Vendor.client_ip_geo_locationclient.geo.country_iso_code 
client.addressclient.ip 
Vendor.client_portclient.port 
Vendor.dest_fqdndestination.address 
Vendor.dest_ipdestination.address 
Vendor.dns_server_ipdestination.address 
Vendor.vipdestination.address 
Vendor.dest_geodestination.geo.country_iso_code 
Vendor.dest_ipdestination.ip 
destination.addressdestination.ip 
Vendor.translated_dest_ipdestination.nat.ip 
Vendor.translated_dest_portdestination.nat.port 
Vendor.dest_portdestination.port 
Vendor.device_iddevice.id 
Vendor.device_vendordevice.manufacturer 
Vendor.question_classdns.question.class 
Vendor.question_namedns.question.name 
Vendor.wideipdns.question.registered_domain 
Vendor.question_typedns.question.type 
Vendor.actionevent.action 
Vendor.req_elapsed_timeevent.duration 
Vendor.support_idevent.id 
Vendor.anomaliesevent.reason 
Vendor.bytes_inhttp.request.body.bytes 
Vendor.reqhttp.request.body.content 
Vendor.http_methodhttp.request.method 
Vendor.methodhttp.request.method 
Vendor.http_content_typehttp.request.mime_type 
Vendor.http_classhttp.request.referrer 
Vendor.http_referrerhttp.request.referrer 
Vendor.bytes_outhttp.response.body.bytes 
Vendor.resphttp.response.body.content 
Vendor.http_statushttp.response.status_code 
Vendor.resp_codehttp.response.status_code 
Vendor.http_versionhttp.version 
Vendor.severitylog.level 
log.syslog.severity.namelog.level 
log.syslog.prioritylog.syslog.facility.code 
Vendor.bytes_innetwork.bytes 
Vendor.dns_lennetwork.bytes 
Vendor.x_fwd_hdr_valnetwork.forwarded_ip 
Vendor.ip_protocolnetwork.protocol 
Vendor.dest_vlannetwork.vlan.id 
Vendor.vlannetwork.vlan.name 
Vendor.hostnameobserver.hostname 
Vendor.context_nameobserver.ingress.zone 
Vendor.device_productobserver.product 
Vendor.device_versionobserver.version 
Vendor.pidprocess.pid 
Vendor.acl_policy_namerule.category 
Vendor.acl_rule_uuidrule.id 
Vendor.acl_rule_namerule.name 
Vendor.violationsrule.name 
Vendor.acl_policy_typerule.ruleset 
Vendor.enforced_byrule.ruleset 
Vendor.nodeserver.address 
server.addressserver.ip 
Vendor.node_portserver.port 
Vendor.src_ipsource.address 
Vendor.geo_infosource.geo.country_iso_code 
Vendor.src_geosource.geo.country_iso_code 
Vendor.source_ipsource.ip 
source.addresssource.ip 
Vendor.translated_source_ipsource.nat.ip 
Vendor.translated_source_portsource.nat.port 
Vendor.source_portsource.port 
Vendor.src_portsource.port 
Vendor.source_user_groupsource.user.group.name 
Vendor.source_usersource.user.name 
Vendor.threat_campaign_namesthreat.group.alias 
Vendor.attack_typethreat.technique.name 
Vendor.sig_idsthreat.technique.subtechnique.id 
Vendor.sig_namesthreat.technique.subtechnique.name 
Vendor.http_urlurl.original 
Vendor.http_uriurl.path 
Vendor.useruser.name 
Vendor.usernameuser.name