Parsers and Generated Fields

Tag Fields Created by Parser dlp-cef
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser dlp-cef
Vendor FieldCPS FieldDescription
Vendor.nameagent.name 
Vendor.device.versionagent.version 
Vendor.sourceServiceNameevent.action 
Vendor.eventIdevent.id 
Vendor.riskScoreevent.risk_score 
Vendor.severityevent.severity 
Vendor.riskScorerisk.calculated_score 
Vendor.msgrule.name 
Vendor.sourceIpsource.address 
Vendor.sourceIp;source.ip 
Vendor.severityTypethreat.indicator.confidence 
Vendor.caseDescriptionthreat.indicator.description 
Vendor.numberOfIncidentsthreat.indicator.sightings 
Vendor.duseruser.email 
Vendor.loginNameuser.name 
Tag Fields Created by Parser forcepoint-dlp
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser forcepoint-dlp
Vendor FieldCPS FieldDescription
Vendor.nameagent.name  
Vendor.device.versionagent.version  
Vendor.sourceServiceNameevent.action  
Vendor.eventIdevent.id  
Vendor.riskScoreevent.risk_score  
Vendor.severityevent.severity  
event.risk_scorehost.risk.calculated_score 
Vendor.msgrule.name  
Vendor.sourceIpsource.address  
source.address;source.ip 
Vendor.severityTypethreat.indicator.confidence  
Vendor.caseDescriptionthreat.indicator.description  
Vendor.numberOfIncidentsthreat.indicator.sightings  
Vendor.duseruser.email  
Vendor.loginNameuser.name