Parsers and Generated Fields

Tag Fields Created by Parser sysmon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser sysmon
Source FieldLogScale Repository Field
Vendor.EventData.DestinationIpdestination.ip
Vendor.EventData.DestinationPortdestination.port
Vendor.EventData.CurrentDirectorydirectory
Vendor.EventData.QueryNamedns.question.name
Vendor.EventData.IDerror.code
Vendor.EventData.PipeNamefile.name
Vendor.EventData.Devicefile.path
Vendor.EventData.ImageLoadedfile.path
Vendor.EventData.TargetFilenamefile.path
Vendor.EventData.Companyfile.pe.company
Vendor.EventData.Descriptionfile.pe.description
Vendor.EventData.Hashes.IMPHASHfile.pe.imphash
Vendor.EventData.Productfile.pe.product
Vendor.EventData.ParentProcessGuidid
Vendor.EventData.ProcessGuidid
Vendor.EventData.SourceProcessGUIDid
Vendor.EventData.SourceProcessGuidid
Vendor.EventData.CommandLineline
Vendor.EventData.ParentCommandLineline
Vendor.EventData.OriginalFileNamename
Vendor.EventData.Signaturename
Vendor.EventData.DestinationPortNamenetwork.protocol
Vendor.EventData.SourcePortNamenetwork.protocol
Vendor.EventData.Protocolnetwork.transport
Vendor.EventData.Destinationprocess.executable
Vendor.EventData.Imageprocess.executable
Vendor.EventData.SourceImageprocess.executable
Vendor.EventData.ParentImageprocess.parent.executable
Vendor.EventData.ParentProcessIdprocess.parent.pid
Vendor.EventData.Companyprocess.pe.company
Vendor.EventData.Descriptionprocess.pe.description
Vendor.EventData.Hashes.IMPHASHprocess.pe.imphash
Vendor.EventData.Productprocess.pe.product
Vendor.EventData.ProcessIdprocess.pid
Vendor.EventData.SourceProcessIdprocess.pid
Vendor.EventData.SourceThreadIdprocess.thread.id
Vendor.EventData.TargetObjectregistry.path
Vendor.EventData.RuleNamerule.name
Vendor.EventData.Signedsignature.signed
Vendor.EventData.SignatureStatussignature.status
Vendor.EventData.SourceIpsource.ip
Vendor.EventData.SourcePortsource.port
Vendor.winlog.user.identifieruser.id
Vendor.EventData.FileVersionversion