Parsers and Generated Fields

Tag Fields Created by Parser microsoft-sysmon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-sysmon
Source FieldCPS Field
Vendor.EventData.DestinationIpdestination.ip
Vendor.EventData.DestinationPortdestination.port
Vendor.EventData.QueryNamedns.question.name
Vendor.EventData.ID;error.code
Vendor.EventData.Signedfile.code_signature.exists
Vendor.EventData.SignatureStatusfile.code_signature.status
Vendor.EventData.Signaturefile.code_signature.subject_name
Vendor.EventData.PipeNamefile.name
Vendor.EventData.Devicefile.path
Vendor.EventData.ImageLoadedfile.path
Vendor.EventData.TargetFilenamefile.path
Vendor.EventData.Companyfile.pe.company
Vendor.EventData.Descriptionfile.pe.description
Vendor.EventData.FileVersionfile.pe.file_version
Vendor.EventData.Hashes.IMPHASHfile.pe.imphash
Vendor.EventData.OriginalFileNamefile.pe.original_file_name
Vendor.EventData.Productfile.pe.product
Vendor.EventData.DestinationPortNamenetwork.protocol
Vendor.EventData.SourcePortNamenetwork.protocol
Vendor.EventData.Protocolnetwork.transport
Vendor.EventData.CommandLineprocess.command_line
Vendor.EventData.ProcessGuidprocess.entity_id
Vendor.EventData.SourceProcessGUIDprocess.entity_id
Vendor.EventData.SourceProcessGuidprocess.entity_id
Vendor.EventData.Destinationprocess.executable
Vendor.EventData.Imageprocess.executable
Vendor.EventData.SourceImageprocess.executable
Vendor.EventData.ParentCommandLineprocess.parent.command_line
Vendor.EventData.ParentProcessGuidprocess.parent.entity_id
Vendor.EventData.ParentImageprocess.parent.executable
Vendor.EventData.ParentProcessIdprocess.parent.pid
Vendor.EventData.Companyprocess.pe.company
Vendor.EventData.Descriptionprocess.pe.description
Vendor.EventData.FileVersionprocess.pe.file_version
Vendor.EventData.Hashes.IMPHASHprocess.pe.imphash
Vendor.EventData.OriginalFileNameprocess.pe.original_file_name
Vendor.EventData.Productprocess.pe.product
Vendor.EventData.ProcessIdprocess.pid
Vendor.EventData.SourceProcessIdprocess.pid
Vendor.EventData.SourceThreadIdprocess.thread.id
Vendor.EventData.CurrentDirectoryprocess.working_directory
Vendor.EventData.TargetObjectregistry.path
rename(Vendor.EventData.RuleName)rule.name
Vendor.EventData.SourceIpsource.ip
Vendor.EventData.SourcePortsource.port
Vendor.winlog.user.identifieruser.id
Tag Fields Created by Parser sysmon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser sysmon
Source FieldCPS Field
Vendor.EventData.DestinationIpdestination.ip
Vendor.EventData.DestinationPortdestination.port
Vendor.EventData.QueryNamedns.question.name
Vendor.EventData.ID;error.code
Vendor.EventData.Signedfile.code_signature.signed
Vendor.EventData.SignatureStatusfile.code_signature.status
Vendor.EventData.Signaturefile.code_signature.subject_name
Vendor.EventData.PipeNamefile.name
Vendor.EventData.Device;file.path
Vendor.EventData.ImageLoadedfile.path
Vendor.EventData.TargetFilename;file.path
Vendor.EventData.Company;file.pe.company
Vendor.EventData.Description;file.pe.description
Vendor.EventData.FileVersion;file.pe.file_version
Vendor.EventData.Hashes.IMPHASHfile.pe.imphash
Vendor.EventData.OriginalFileName;file.pe.original_file_name
Vendor.EventData.Product;file.pe.product
Vendor.EventData.DestinationPortName;network.protocol
Vendor.EventData.SourcePortNamenetwork.protocol
Vendor.EventData.Protocolnetwork.transport
Vendor.EventData.CommandLineprocess.command_line
Vendor.EventData.ProcessGuidprocess.entity_id
Vendor.EventData.SourceProcessGUIDprocess.entity_id
Vendor.EventData.SourceProcessGuid;process.entity_id
Vendor.EventData.Destinationprocess.executable
Vendor.EventData.Image;process.executable
Vendor.EventData.SourceImage;process.executable
Vendor.EventData.ParentCommandLineprocess.parent.command_line
Vendor.EventData.ParentProcessGuidprocess.parent.entity_id
Vendor.EventData.ParentImageprocess.parent.executable
Vendor.EventData.ParentProcessIdprocess.parent.pid
Vendor.EventData.Company;process.pe.company
Vendor.EventData.Description;process.pe.description
Vendor.EventData.FileVersion;process.pe.file_version
Vendor.EventData.Hashes.IMPHASHprocess.pe.imphash
Vendor.EventData.OriginalFileName;process.pe.original_file_name
Vendor.EventData.Product;process.pe.product
Vendor.EventData.ProcessId;process.pid
Vendor.EventData.SourceProcessIdprocess.pid
Vendor.EventData.SourceThreadIdprocess.thread.id
Vendor.EventData.CurrentDirectoryprocess.working_directory
Vendor.EventData.TargetObjectregistry.path
Vendor.EventData.RuleName;rule.name
Vendor.EventData.SourceIpsource.ip
Vendor.EventData.SourcePortsource.port
Vendor.winlog.user.identifieruser.id