Parsers and Generated Fields

Tag Fields Created by Parser microsoft-sysmon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-sysmon
Vendor FieldCPS FieldDescription
Vendor.EventData.DestinationIpdestination.ip  
Vendor.EventData.DestinationPortdestination.port  
Vendor.EventData.QueryNamedns.question.name  
Vendor.EventData.ID;error.code 
Vendor.EventData.Signedfile.code_signature.exists  
Vendor.EventData.SignatureStatusfile.code_signature.status  
Vendor.EventData.Signaturefile.code_signature.subject_name  
Vendor.EventData.PipeNamefile.name  
Vendor.EventData.Devicefile.path  
Vendor.EventData.ImageLoadedfile.path  
Vendor.EventData.TargetFilenamefile.path  
Vendor.EventData.Companyfile.pe.company  
Vendor.EventData.Descriptionfile.pe.description  
Vendor.EventData.FileVersionfile.pe.file_version  
Vendor.EventData.Hashes.IMPHASHfile.pe.imphash 
Vendor.EventData.OriginalFileNamefile.pe.original_file_name  
Vendor.EventData.Productfile.pe.product  
Vendor.EventData.DestinationPortNamenetwork.protocol  
Vendor.EventData.SourcePortNamenetwork.protocol  
Vendor.EventData.Protocolnetwork.transport  
Vendor.EventData.CommandLineprocess.command_line  
Vendor.EventData.ProcessGuidprocess.entity_id  
Vendor.EventData.SourceProcessGUIDprocess.entity_id  
Vendor.EventData.SourceProcessGuidprocess.entity_id  
Vendor.EventData.Destinationprocess.executable  
Vendor.EventData.Imageprocess.executable  
Vendor.EventData.SourceImageprocess.executable  
Vendor.EventData.ParentCommandLineprocess.parent.command_line  
Vendor.EventData.ParentProcessGuidprocess.parent.entity_id  
Vendor.EventData.ParentImageprocess.parent.executable  
Vendor.EventData.ParentProcessIdprocess.parent.pid  
Vendor.EventData.Companyprocess.pe.company  
Vendor.EventData.Descriptionprocess.pe.description  
Vendor.EventData.FileVersionprocess.pe.file_version  
Vendor.EventData.Hashes.IMPHASHprocess.pe.imphash  
Vendor.EventData.OriginalFileNameprocess.pe.original_file_name  
Vendor.EventData.Productprocess.pe.product  
Vendor.EventData.ProcessIdprocess.pid  
Vendor.EventData.SourceProcessIdprocess.pid  
Vendor.EventData.SourceThreadIdprocess.thread.id  
Vendor.EventData.CurrentDirectoryprocess.working_directory  
Vendor.EventData.TargetObjectregistry.path  
rename(Vendor.EventData.RuleName)rule.name  
Vendor.EventData.SourceIpsource.ip  
Vendor.EventData.SourcePortsource.port  
Vendor.winlog.user.identifieruser.id 
Tag Fields Created by Parser sysmon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser sysmon
Vendor FieldCPS FieldDescription
Vendor.EventData.DestinationIpdestination.ip 
Vendor.EventData.DestinationPortdestination.port 
Vendor.EventData.QueryNamedns.question.name 
Vendor.EventData.ID;error.code 
Vendor.EventData.Signedfile.code_signature.signed 
Vendor.EventData.SignatureStatusfile.code_signature.status 
Vendor.EventData.Signaturefile.code_signature.subject_name 
Vendor.EventData.PipeNamefile.name 
Vendor.EventData.Device;file.path 
Vendor.EventData.ImageLoadedfile.path 
Vendor.EventData.TargetFilename;file.path 
Vendor.EventData.Company;file.pe.company 
Vendor.EventData.Description;file.pe.description 
Vendor.EventData.FileVersion;file.pe.file_version 
Vendor.EventData.Hashes.IMPHASHfile.pe.imphash 
Vendor.EventData.OriginalFileName;file.pe.original_file_name 
Vendor.EventData.Product;file.pe.product 
Vendor.EventData.DestinationPortName;network.protocol 
Vendor.EventData.SourcePortNamenetwork.protocol 
Vendor.EventData.Protocolnetwork.transport 
Vendor.EventData.CommandLineprocess.command_line 
Vendor.EventData.ProcessGuidprocess.entity_id 
Vendor.EventData.SourceProcessGUIDprocess.entity_id 
Vendor.EventData.SourceProcessGuid;process.entity_id 
Vendor.EventData.Destinationprocess.executable 
Vendor.EventData.Image;process.executable 
Vendor.EventData.SourceImage;process.executable 
Vendor.EventData.ParentCommandLineprocess.parent.command_line 
Vendor.EventData.ParentProcessGuidprocess.parent.entity_id 
Vendor.EventData.ParentImageprocess.parent.executable 
Vendor.EventData.ParentProcessIdprocess.parent.pid 
Vendor.EventData.Company;process.pe.company 
Vendor.EventData.Description;process.pe.description 
Vendor.EventData.FileVersion;process.pe.file_version 
Vendor.EventData.Hashes.IMPHASHprocess.pe.imphash 
Vendor.EventData.OriginalFileName;process.pe.original_file_name 
Vendor.EventData.Product;process.pe.product 
Vendor.EventData.ProcessId;process.pid 
Vendor.EventData.SourceProcessIdprocess.pid 
Vendor.EventData.SourceThreadIdprocess.thread.id 
Vendor.EventData.CurrentDirectoryprocess.working_directory 
Vendor.EventData.TargetObjectregistry.path 
Vendor.EventData.RuleName;rule.name 
Vendor.EventData.SourceIpsource.ip 
Vendor.EventData.SourcePortsource.port 
Vendor.winlog.user.identifieruser.id