Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dhcp-server
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dhcp-server
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.ID
`event.type[]`ArrayVendor.ID
`event.outcome`ConditionalVendor.ID, Vendor.Description
`error.code`CopiedVendor.Error_Code, Vendor.DnsRegError
`event.id`CopiedVendor.ID
`host.hostname`CopiedVendor.Host_Name
`source.address`CopiedVendor.Host_Name
`source.ip`CopiedVendor.IP_Address, Vendor.IPv6_Address
`source.mac`CopiedVendor.Mac_Address
`user.name`CopiedVendor.User_Name, Vendor.UserClass_Ascii
`@timestamp`ParsedVendor.Date, Vendor.Time
`ecs.version`StaticNone
`event.action`StaticVendor.ID
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`event.reason`StaticVendor.ID
`network.type`StaticNone
Vendor.DnsRegErrorerror.code 
Vendor.Error_Codeerror.code 
Vendor.IDevent.id