Parsers and Generated Fields
Tag Fields Created by Parser f5networks-bigip
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser f5networks-bigip
Source Field | CPS Field |
---|---|
Vendor.ip_client | client.address |
client.address | client.ip |
destination.address | client.ip |
server.address | client.ip |
source.address | client.ip |
Vendor.dest_ip | destination.address |
Vendor.dest_port | destination.port |
Vendor.device_id | device.id |
Vendor.host | host.ip[0] |
Vendor.req | http.request.body.content |
Vendor.method | http.request.method |
Vendor.http_class | http.request.referrer |
Vendor.resp | http.response.body.content |
Vendor.resp_code | http.response.status_code |
log.syslog.severity.name | log.level |
Vendor.severity | log.level |
log.syslog.priority | log.syslog.facility.code |
Vendor.bytes_in | network.bytes |
Vendor.x_fwd_hdr_val | network.forwarded_ip |
Vendor.manage_ip_addr | observer.ip[0] |
Vendor.violations | rule.name |
Vendor.enforced_by | rule.ruleset |
Vendor.src_ip | source.address |
Vendor.geo_info | source.geo.country_iso_code |
Vendor.src_port | source.port |
Vendor.threat_campaign_names | threat.group.alias |
Vendor.attack_type | threat.technique.name |
Vendor.sig_ids | threat.technique.subtechnique.id |
Vendor.sig_names | threat.technique.subtechnique.name |
Vendor.username | user.name |