Parsers and Generated Fields

Tag Fields Created by Parser island-enterprisebrowser
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser island-enterprisebrowser
Vendor FieldCPS FieldDescription
Vendor.actionevent.actionAction type for admin actions
Vendor.message.typeevent.actionAction type for network events
Vendor.message.sourceevent.category[0]Category and type for network events
Vendor.message.verdictevent.outcomeOutcome for blocked verdicts
Vendor.hostnamehost.hostnameHostname converted to lowercase
Vendor.message.ruleIdrule.idID of the rule that triggered
Vendor.message.ruleNamerule.nameName of the rule that triggered
Vendor.message.sourceIpsource.ipSource IP address for network events
Vendor.message.publicIpsource.nat.ipPublic/NAT IP address
url.hosturl.domainDomain extracted from URL and converted to lowercase
url.hosturl.domain  
Vendor.message.topLevelUrlurl.originalOriginal URL for parsing
Vendor.message.emailuser.emailDirect assignment of user email address
Vendor.message.userIduser.idDirect assignment of user identifier
Vendor.message.userNameuser.nameUsername for network events
Vendor.message.entityIduser.target.idTarget user ID for admin actions
Vendor.message.entityNameuser.target.nameTarget user name for admin actions