Parsers and Generated Fields
Tag Fields Created by Parser island-enterprisebrowser
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser island-enterprisebrowser
| Vendor Field | CPS Field | Description |
|---|---|---|
| Vendor.action | event.action | Action type for admin actions |
| Vendor.message.type | event.action | Action type for network events |
| Vendor.message.source | event.category[0] | Category and type for network events |
| Vendor.message.verdict | event.outcome | Outcome for blocked verdicts |
| Vendor.hostname | host.hostname | Hostname converted to lowercase |
| Vendor.message.ruleId | rule.id | ID of the rule that triggered |
| Vendor.message.ruleName | rule.name | Name of the rule that triggered |
| Vendor.message.sourceIp | source.ip | Source IP address for network events |
| Vendor.message.publicIp | source.nat.ip | Public/NAT IP address |
| url.host | url.domain | Domain extracted from URL and converted to lowercase |
| url.host | url.domain | |
| Vendor.message.topLevelUrl | url.original | Original URL for parsing |
| Vendor.message.email | user.email | Direct assignment of user email address |
| Vendor.message.userId | user.id | Direct assignment of user identifier |
| Vendor.message.userName | user.name | Username for network events |
| Vendor.message.entityId | user.target.id | Target user ID for admin actions |
| Vendor.message.entityName | user.target.name | Target user name for admin actions |