Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dhcp-server
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dhcp-server
Source FieldCPS FieldDescriptionMapping
Vendor.Date, Vendor.Time@timestampEvent timestampParsed from Vendor.Date and Vendor.Time using format MM/dd/yy HH:mm:ss
source.addressclient.addressClient addressCopied from source.address
source.ipclient.ipClient IP addressCopied from source.ip
source.macclient.macClient MAC addressCopied from source.mac
Noneecs.versionECS schema versionStatic value: 9.2.0
Vendor.Error_Code, Vendor.DnsRegErrorerror.codeError codeCopied from Vendor.Error_Code or Vendor.DnsRegError
Vendor.IDevent.actionEvent actionStatic value based on event ID
Vendor.IDevent.category[]Event categoriesArray populated based on event ID conditions
Noneevent.datasetDataset identifierStatic value: windows.dhcp-server
Vendor.IDevent.idEvent identifierCopied from Vendor.ID
Noneevent.kindEvent categorizationStatic value: event
Noneevent.moduleModule nameStatic value: windows
Vendor.ID, Vendor.Descriptionevent.outcomeEvent outcomeConditional assignment based on event ID or description
Vendor.IDevent.reasonEvent reason descriptionStatic value based on event ID
Vendor.IDevent.type[]Event typesArray populated based on event ID conditions
network.typenetwork.protocolNetwork protocolStatic value: dhcp or dhcpv6 based on network.type
Nonenetwork.transportNetwork transport protocolStatic value: udp
Nonenetwork.typeNetwork protocol typeStatic value: ipv4 or ipv6 based on log type
source.ip, source.domainsource.addressSource addressCopied from coalesce of source.ip or source.domain
Vendor.Host_Namesource.domainSource domain nameCopied from Vendor.Host_Name with lowercase transformation
Vendor.IP_Address, Vendor.IPv6_Addresssource.ipSource IP addressCopied from coalesce of Vendor.IP_Address or Vendor.IPv6_Address with CIDR validation
Vendor.Mac_Addresssource.macSource MAC addressCopied from Vendor.Mac_Address with uppercase and dash formatting
Vendor.User_Name, Vendor.UserClass_Asciiuser.nameUsernameCopied from coalesce of Vendor.User_Name or Vendor.UserClass_Ascii