Parsers and Generated Fields

Tag Fields Created by Parser dlp-cef
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser dlp-cef
Source FieldLogScale Repository Field
Vendor.nameagent.name
Vendor.device.versionagent.version
Vendor.sourceServiceNameevent.action
Vendor.eventIdevent.id
Vendor.severityevent.severity
Vendor.msgrule.name
Vendor.riskScorescore
Vendor.sourceIpsource.address
Vendor.sourceIpsource.ip
Vendor.severityTypethreat.indicator.confidence
Vendor.caseDescriptionthreat.indicator.description
Vendor.numberOfIncidentsthreat.indicator.sightings
Vendor.duseruser.email
Vendor.loginNameuser.name