Parsers and Generated Fields
Tag Fields Created by Parser forcepoint-dlp
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser forcepoint-dlp
| Vendor Field | CPS Field | Description |
|---|---|---|
| `event.category[]` | Array | None |
| `event.type[]` | Array | Vendor.act |
| `agent.name` | Copied | Vendor.name |
| `agent.version` | Copied | Vendor.device.version |
| `destination.domain` | Copied | Vendor.destinationHosts |
| `event.action` | Copied | Vendor.sourceServiceName |
| `event.id` | Copied | Vendor.eventId |
| `event.risk_score` | Copied | Vendor.riskScore |
| `host.risk.calculated_score` | Copied | Vendor.riskScore (indirect) |
| `rule.name` | Copied | Vendor.msg |
| `source.address` | Copied | Vendor.sourceIp |
| `source.domain` | Copied | Vendor.sourceHost |
| `source.ip` | Copied | Vendor.sourceIp (indirect) |
| `threat.indicator.confidence` | Copied | Vendor.severityType |
| `threat.indicator.description` | Copied | Vendor.caseDescription |
| `threat.indicator.sightings` | Copied | Vendor.numberOfIncidents |
| `user.email` | Copied | Vendor.duser |
| `file.extension` | Extracted | Vendor.fname (indirect) |
| `file.name` | Extracted | Vendor.fname |
| `file.size` | Extracted | Vendor.fname |
| `user.domain` | Extracted | Vendor.loginName |
| `user.name` | Extracted | Vendor.loginName |
| `event.severity` | Mapped | Vendor.severity |
| `@timestamp` | Parsed | Vendor.caseDateAndTime |
| `agent.type` | Static | None |
| `ecs.version` | Static | None |
| `event.dataset` | Static | None |
| `event.kind` | Static | Vendor.riskScore, Vendor.eventId |
| `event.module` | Static | None |
| `file.type` | Static | None |
| Vendor.name | agent.name | |
| Vendor.device.version | agent.version | |
| Vendor.sourceServiceName | event.action | |
| Vendor.eventId | event.id | |
| Vendor.riskScore | event.risk_score | |
| event.risk_score | host.risk.calculated_score | |
| Vendor.msg | rule.name | |
| Vendor.sourceIp | source.address | |
| Vendor.severityType | threat.indicator.confidence | |
| Vendor.caseDescription | threat.indicator.description | |
| Vendor.numberOfIncidents | threat.indicator.sightings | |
| Vendor.duser | user.email | |
| Vendor.loginName | user.name |