Parsers and Generated Fields

Tag Fields Created by Parser infoblox-nios
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser infoblox-nios
Vendor FieldCPS FieldDescription
`dns.resolved_ip[]`Arraymessage
`event.category[]`ArrayVendor.service_name, event.action
`event.type[]`ArrayVendor.service_name, event.action
`host.ip[]`Arrayhost.domain
`client.domain`Extractedmessage
`client.ip`Extractedmessage
`client.mac`Extractedmessage
`client.port`Extractedmessage
`dns.question.class`Extractedmessage
`dns.question.name`Extractedmessage
`dns.question.response_code`Extractedmessage
`dns.question.type`Extractedmessage
`event.action`Extractedmessage
`host.domain`Extracted@rawstring
`interface.name`Extractedmessage
`log.syslog.priority`Extracted@rawstring
`log.syslog.timestamp`Extracted@rawstring
`message`Extracted@rawstring
`network.transport`Extractedmessage
`process.id`Extracted@rawstring
`server.ip`Extractedmessage
`user.name`ExtracteduserName
`@timestamp`Parsedlog.syslog.timestamp
`dns.answers[].class`Parsedmessage
`dns.answers[].data`Parsedmessage
`dns.answers[].name`Parsedmessage
`dns.answers[].ttl`Parsedmessage
`dns.answers[].type`Parsedmessage
`ecs.version`StaticNone
`event.dataset`StaticVendor.service_name
`event.kind`StaticNone
`event.module`StaticNone
`event.outcome`Staticevent.action