Parsers and Generated Fields

Tag Fields Created by Parser island-enterprisebrowser
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser island-enterprisebrowser
Source FieldCPS FieldDescriptionMapping
Action type for admin actionsVendor.action event.action
Hostname converted to lowercaseVendor.hostname host.hostname
Direct assignment of user email addressVendor.message.email user.email
Target user ID for admin actionsVendor.message.entityId user.target.id
Target user name for admin actionsVendor.message.entityName user.target.name
Public/NAT IP addressVendor.message.publicIp source.nat.ip
ID of the rule that triggeredVendor.message.ruleId rule.id
Name of the rule that triggeredVendor.message.ruleName rule.name
Category and type for network eventsVendor.message.source != AdminAction event.category[0] = "network", event.type[0] = "access"
Category and type for admin actionsVendor.message.source = AdminAction event.category[0] = "iam", event.type[0] = "admin"
Source IP address for network eventsVendor.message.sourceIp source.ip
Original URL for parsingVendor.message.topLevelUrl url.original
Action type for network eventsVendor.message.type event.action
Direct assignment of user identifierVendor.message.userId user.id
Username for network eventsVendor.message.userName user.name
Outcome for allowed verdictsVendor.message.verdict = Allowed event.outcome = "success"
Outcome for blocked verdictsVendor.message.verdict = Blocked event.outcome = "failure"
Domain extracted from URL and converted to lowercaseurl.host url.domain