Parsers and Generated Fields
Tag Fields Created by Parser microsoft-windows-dhcp-client
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser microsoft-windows-dhcp-client
| Vendor Field | CPS Field | Description |
|---|---|---|
| `event.category[]` | Array | None |
| `event.type[]` | Array | None |
| `source.address` | Coalesced | Vendor.EventData.IP_Name, Vendor.EventData.FQDNName |
| `network.type` | Conditional | Vendor.ProviderName |
| `client.address` | Copied | Vendor.EventData.IP_Name, Vendor.EventData.FQDNName (indirect) |
| `client.domain` | Copied | Vendor.EventData.FQDNName (indirect) |
| `client.ip` | Copied | Vendor.EventData.IP_Name (indirect) |
| `error.code` | Copied | Vendor.EventData.ErrorType |
| `error.message` | Copied | Vendor.EventData.operation |
| `event.code` | Copied | Vendor.EventID |
| `event.created` | Copied | Vendor.TimeCreated |
| `event.id` | Copied | Vendor.EventRecordId |
| `event.provider` | Copied | Vendor.ProviderName |
| `host.name` | Copied | Vendor.Computer |
| `process.pid` | Copied | Vendor.ProcessID |
| `process.thread.id` | Copied | Vendor.ThreadID |
| `source.ip` | Copied | Vendor.EventData.IP_Name |
| `user.id` | Copied | Vendor.UserID |
| `@timestamp` | Inherited | None |
| `host.hostname` | Lowercase | Vendor.Computer |
| `source.domain` | Lowercase | Vendor.EventData.FQDNName |
| `event.severity` | Mapped | Vendor.Level |
| `ecs.version` | Static | None |
| `event.dataset` | Static | None |
| `event.kind` | Static | None |
| `event.module` | Static | None |
| `network.protocol` | Static | None |
| source.address | client.address | |
| source.domain | client.domain | |
| source.ip | client.ip | |
| Vendor.EventData.ErrorType | error.code | |
| Vendor.EventData.operation | error.message | |
| Vendor.EventID | event.code | |
| Vendor.TimeCreated | event.created | |
| Vendor.EventRecordId | event.id | |
| Vendor.ProviderName | event.provider | |
| Vendor.Computer | host.name | |
| Vendor.ProcessID | process.pid | |
| Vendor.ThreadID | process.thread.id | |
| Vendor.EventData.IP_Name | source.ip | |
| Vendor.UserID | user.id |