Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dhcp-client
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dhcp-client
Vendor FieldCPS FieldDescription
N/Aevent.category[0]Static assignment to "network"
N/Aevent.category[1]Static assignment to "configuration"
Vendor.EventRecordIdevent.idMaps event record ID to standard event ID field
N/Aevent.kindStatic assignment to "event"
N/Aevent.type[0]Static assignment to "info"
N/Anetwork.protocolStatic assignment to "dhcp"
Vendor.ProviderNamenetwork.typeSets to "ipv6" if provider name contains "-Dhcpv6-"
Vendor.ProcessIDprocess.pidMaps process ID to standard process ID field
Vendor.UserIDuser.idMaps user ID to standard user ID field
Tag Fields Created by Parser windows-dhcp-client
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser windows-dhcp-client
Vendor FieldCPS FieldDescription
Vendor.EventRecordIdevent.id 
Vendor.ProcessIDprocess.pid 
Vendor.UserIDuser.id