Parsers and Generated Fields

Tag Fields Created by Parser dlp-cef
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser dlp-cef
Source FieldCPS Field
Vendor.nameagent.name
Vendor.device.versionagent.version
Vendor.sourceServiceNameevent.action
Vendor.eventIdevent.id
Vendor.riskScoreevent.risk_score
Vendor.severityevent.severity
Vendor.riskScorerisk.calculated_score
Vendor.msgrule.name
Vendor.sourceIpsource.address
Vendor.sourceIp;source.ip
Vendor.severityTypethreat.indicator.confidence
Vendor.caseDescriptionthreat.indicator.description
Vendor.numberOfIncidentsthreat.indicator.sightings
Vendor.duseruser.email
Vendor.loginNameuser.name
Tag Fields Created by Parser forcepoint-dlp
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser forcepoint-dlp
Source FieldCPS Field
Vendor.nameagent.name
Vendor.device.versionagent.version
Vendor.sourceServiceNameevent.action
Vendor.eventIdevent.id
Vendor.riskScoreevent.risk_score
Vendor.severityevent.severity
event.risk_scorehost.risk.calculated_score
Vendor.msgrule.name
Vendor.sourceIpsource.address
source.address;source.ip
Vendor.severityTypethreat.indicator.confidence
Vendor.caseDescriptionthreat.indicator.description
Vendor.numberOfIncidentsthreat.indicator.sightings
Vendor.duseruser.email
Vendor.loginNameuser.name