Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dhcp-client
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dhcp-client
Source FieldCPS FieldDescriptionMapping
None@timestampEvent timestampInherited from log ingestion
Vendor.EventData.IP_Name, Vendor.EventData.FQDNName (indirect)client.addressClient address identifierCopied from source.address
Vendor.EventData.FQDNName (indirect)client.domainClient domain nameCopied from source.domain
Vendor.EventData.IP_Name (indirect)client.ipClient IP addressCopied from source.ip
Noneecs.versionECS schema versionStatic value: "9.2.0"
Vendor.EventData.ErrorTypeerror.codeError type codeCopied from Vendor.EventData.ErrorType
Vendor.EventData.operationerror.messageError operation messageCopied from Vendor.EventData.operation
Noneevent.category[]Event categoriesArray populated with ["network","configuration"]
Vendor.EventIDevent.codeWindows event IDCopied from Vendor.EventID
Vendor.TimeCreatedevent.createdEvent creation timestampCopied from Vendor.TimeCreated
Noneevent.datasetDataset identifierStatic value: "windows.dhcp-client"
Vendor.EventRecordIdevent.idUnique event identifierCopied from Vendor.EventRecordId
Noneevent.kindEvent categorizationStatic value: "event"
Noneevent.moduleSource module identifierStatic value: "windows"
Vendor.ProviderNameevent.providerEvent provider nameCopied from Vendor.ProviderName
Vendor.Levelevent.severityEvent severity level (0-95 scale)Mapped from Vendor.Level using severity scale
Noneevent.type[]Event type classificationArray populated with ["info"]
Vendor.Computerhost.hostnameNormalized hostnameLowercase transformation of Vendor.Computer
Vendor.Computerhost.nameHost computer nameCopied from Vendor.Computer
Nonenetwork.protocolNetwork protocol usedStatic value: "dhcp"
Vendor.ProviderNamenetwork.typeNetwork type (ipv4/ipv6)Conditional based on Vendor.ProviderName pattern matching
Vendor.ProcessIDprocess.pidProcess identifierCopied from Vendor.ProcessID
Vendor.ThreadIDprocess.thread.idProcess thread identifierCopied from Vendor.ThreadID
Vendor.EventData.IP_Name, Vendor.EventData.FQDNNamesource.addressSource address identifierCoalesced from source.ip or source.domain
Vendor.EventData.FQDNNamesource.domainSource domain nameLowercase transformation of Vendor.EventData.FQDNName
Vendor.EventData.IP_Namesource.ipSource IP addressCopied from Vendor.EventData.IP_Name with validation
Vendor.UserIDuser.idUser identifierCopied from Vendor.UserID