Parsers and Generated Fields

Tag Fields Created by Parser f5networks-bigip
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser f5networks-bigip
Vendor FieldCPS FieldDescription
Vendor.ip_clientclient.address 
Vendor.client_ip_geo_locationclient.geo.country_iso_codeClient geo location for ASM Bot Defense
client.addressclient.ip 
Vendor.client_portclient.portClient port for ASM Bot Defense
Vendor.dest_fqdndestination.addressDestination FQDN
Vendor.dest_ipdestination.address 
Vendor.dns_server_ipdestination.address 
Vendor.vipdestination.address 
Vendor.dest_geodestination.geo.country_iso_codeDestination geographic location
Vendor.dest_ipdestination.ipDestination IP for ASM Bot Defense
destination.addressdestination.ip 
Vendor.translated_dest_ipdestination.nat.ipTranslated destination IP
Vendor.translated_dest_portdestination.nat.portTranslated destination port
Vendor.dest_portdestination.portDestination port for ASM Bot Defense
Vendor.device_iddevice.idDevice ID
Vendor.device_vendordevice.manufacturerDevice manufacturer for ASM Bot Defense
Vendor.question_classdns.question.class 
Vendor.question_namedns.question.name 
Vendor.wideipdns.question.registered_domain 
Vendor.question_typedns.question.type 
Vendor.actionevent.actionAction taken
Vendor.req_elapsed_timeevent.duration 
Vendor.support_idevent.id 
Vendor.new_request_statusevent.outcomeMaps to success/failure based on accepted/denied
Vendor.anomaliesevent.reasonEvent reason for ASM Bot Defense
Vendor.drop_reasonevent.reasonReason for dropping traffic
Vendor.severityevent.severityEvent severity based on mapping
Vendor.hostnamehost.hostnameHost hostname for ASM Bot Defense
Vendor.hosthost.ip[]Host information as array
Vendor.bytes_inhttp.request.body.bytes 
Vendor.reqhttp.request.body.contentHTTP request content
Vendor.http_methodhttp.request.methodHTTP method
Vendor.methodhttp.request.methodHTTP method
Vendor.http_content_typehttp.request.mime_type 
Vendor.http_classhttp.request.referrerHTTP class
Vendor.http_referrerhttp.request.referrer 
Vendor.bytes_outhttp.response.body.bytes 
Vendor.resphttp.response.body.contentHTTP response content
Vendor.http_statushttp.response.status_code 
Vendor.resp_codehttp.response.status_codeHTTP response code
Vendor.http_versionhttp.version 
Vendor.severitylog.levelLog level
log.syslog.severity.namelog.level 
log.syslog.prioritylog.syslog.facility.code 
Vendor.bytes_innetwork.bytes 
Vendor.dns_lennetwork.bytes 
Vendor.x_fwd_hdr_valnetwork.forwarded_ipX-Forwarded-For header value
Vendor.http_protocol_indicationnetwork.protocolNetwork protocol for ASM Bot Defense
Vendor.ip_protocolnetwork.protocolIP protocol
Vendor.dest_vlannetwork.vlan.idDestination VLAN ID
Vendor.vlannetwork.vlan.nameVLAN name
Vendor.hostnameobserver.hostnameObserver hostname
Vendor.context_nameobserver.ingress.zone 
Vendor.bigip_mgmt_ipobserver.ip[]Observer IP address as array
Vendor.manage_ip_addrobserver.ip[]Management IP address as array
Vendor.device_productobserver.productObserver product name
Vendor.device_versionobserver.versionObserver version
Vendor.acl_policy_namerule.categoryACL policy name
Vendor.acl_rule_uuidrule.idACL rule UUID
Vendor.acl_rule_namerule.nameACL rule name
Vendor.violationsrule.nameViolations as array
Vendor.acl_policy_typerule.rulesetACL policy type
Vendor.enforced_byrule.rulesetEnforcement mechanism
Vendor.nodeserver.address 
server.addressserver.ip 
Vendor.node_portserver.port 
Vendor.source_fqdnsource.addressSource FQDN
Vendor.src_ipsource.addressSource address
Vendor.geo_infosource.geo.country_iso_code 
Vendor.src_geosource.geo.country_iso_codeSource geographic location
Vendor.client_ipsource.ipClient IP address for ASM Bot Defense
Vendor.source_ipsource.ipSource IP address
source.addresssource.ip 
Vendor.translated_source_ipsource.nat.ipTranslated source IP
Vendor.translated_source_portsource.nat.portTranslated source port
Vendor.source_portsource.portSource port number
Vendor.src_portsource.portSource port
Vendor.source_user_groupsource.user.group.nameSource user group
Vendor.source_usersource.user.nameSource username
Vendor.threat_campaign_namesthreat.group.aliasThreat campaign names as array
Vendor.attack_typethreat.technique.nameAttack type as array
Vendor.sig_idsthreat.technique.subtechnique.idSignature IDs as array
Vendor.sig_namesthreat.technique.subtechnique.nameSignature names as array
Vendor.http_urlurl.original 
Vendor.client_request_uriurl.pathURL path for ASM Bot Defense
Vendor.http_uriurl.path 
Vendor.useruser.nameUsername
Vendor.usernameuser.name 
Vendor.http_requestuser_agent.originalUser agent extraction from HTTP request
Vendor.http_user_agentuser_agent.originalUser agent string