Parsers and Generated Fields

Tag Fields Created by Parser haproxy
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser haproxy
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayVendor.status_code, Vendor.bind_name
`event.dataset`ConditionallyVendor.bind_name, Vendor.status_code, Vendor.client_ip
`event.outcome`ConditionallyVendor.status_code, Vendor.bind_name
`client.address`CopiedVendor.client_ip (indirect)
`client.ip`CopiedVendor.client_ip (indirect)
`client.port`CopiedVendor.client_port (indirect)
`destination.bytes`CopiedVendor.BytesRead
`error.message`CopiedVendor.message
`host.name`Copiedlog.syslog.hostname
`http.request.method`CopiedVendor.method
`http.response.bytes`CopiedVendor.bytes_read
`http.response.status_code`CopiedVendor.status_code
`observer.name`Copiedlog.syslog.hostname
`process.name`Copiedlog.syslog.appname
`process.pid`Copiedlog.syslog.procid
`server.bytes`CopiedVendor.BytesRead (indirect)
`service.name`CopiedVendor.frontend
`source.address`CopiedVendor.client_ip
`source.ip`CopiedVendor.client_ip (indirect)
`source.port`CopiedVendor.client_port
`error.code`ExtractedVendor.message
`http.version`ExtractedVendor.protocol
`log.syslog.appname`ExtractedNone
`log.syslog.hostname`ExtractedNone
`log.syslog.priority`ExtractedNone
`log.syslog.procid`ExtractedNone
`message`ExtractedNone
`network.protocol`ExtractedVendor.protocol
`tls.version_protocol`ExtractedVendor.ssl_version
`tls.version`ExtractedVendor.ssl_version
`@timestamp`ParsedNone
`url.domain`ParsedVendor.path
`url.path`ParsedVendor.path
`url.query`ParsedVendor.path
`tls.established`SetVendor.tls
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.http.actconnVendor.actconn 
Vendor.http.backend_queueVendor.backend_queue 
Vendor.http.beconnVendor.beconn 
Vendor.http.bytes_readVendor.bytes_read 
Vendor.http.feconnVendor.feconn 
Vendor.http.retriesVendor.retries 
Vendor.http.src_connVendor.src_conn 
Vendor.http.srv_queueVendor.srv_queue 
Vendor.http.termination_stateVendor.termination_state 
source.addressclient.address 
source.portclient.port 
Vendor.BytesReaddestination.bytes 
log.syslog.hostnamehost.name 
Vendor.methodhttp.request.method 
Vendor.bytes_readhttp.response.bytes 
Vendor.status_codehttp.response.status_code 
log.syslog.hostnameobserver.name 
log.syslog.appnameprocess.name 
log.syslog.procidprocess.pid 
destination.bytesserver.bytes 
Vendor.frontendservice.name 
Vendor.client_portsource.port 
url.hosturl.domain