Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dhcp-server
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dhcp-server
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.ID
`event.type[]`ArrayVendor.ID
`event.outcome`ConditionalVendor.ID, Vendor.Description
`client.address`Copiedsource.address
`client.ip`Copiedsource.ip
`client.mac`Copiedsource.mac
`error.code`CopiedVendor.Error_Code, Vendor.DnsRegError
`event.id`CopiedVendor.ID
`source.address`Copiedsource.ip, source.domain
`source.domain`CopiedVendor.Host_Name
`source.ip`CopiedVendor.IP_Address, Vendor.IPv6_Address
`source.mac`CopiedVendor.Mac_Address
`user.name`CopiedVendor.User_Name, Vendor.UserClass_Ascii
`@timestamp`ParsedVendor.Date, Vendor.Time
`ecs.version`StaticNone
`event.action`StaticVendor.ID
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`event.reason`StaticVendor.ID
`network.protocol`Staticnetwork.type
`network.transport`StaticNone
`network.type`StaticNone
source.addressclient.address 
source.ipclient.ip 
source.macclient.mac 
Vendor.DnsRegErrorerror.code 
Vendor.Error_Codeerror.code 
Vendor.IDevent.id