Parsers and Generated Fields

Tag Fields Created by Parser microsoft-sysmon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-sysmon
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.EventID
`event.type[]`ArrayVendor.EventID
`destination.domain`CopiedVendor.EventData.DestinationHostname
`destination.ip`CopiedVendor.EventData.DestinationIp
`destination.port`CopiedVendor.EventData.DestinationPort
`dns.question.name`CopiedVendor.EventData.QueryName
`error.code`CopiedVendor.EventData.ID
`file.code_signature.exists`CopiedVendor.EventData.Signed
`file.code_signature.status`CopiedVendor.EventData.SignatureStatus
`file.code_signature.subject_name`CopiedVendor.EventData.Signature
`file.hash.md5`CopiedVendor.EventData.Hashes.MD5
`file.hash.sha1`CopiedVendor.EventData.Hashes.SHA1
`file.hash.sha256`CopiedVendor.EventData.Hashes.SHA256
`file.name`CopiedVendor.EventData.PipeName
`file.path`CopiedVendor.EventData.TargetFilename, Vendor.EventData.Device, Vendor.EventData.ImageLoaded
`file.pe.company`CopiedVendor.EventData.Company
`file.pe.description`CopiedVendor.EventData.Description
`file.pe.file_version`CopiedVendor.EventData.FileVersion
`file.pe.imphash`CopiedVendor.EventData.Hashes.IMPHASH
`file.pe.original_file_name`CopiedVendor.EventData.OriginalFileName
`file.pe.product`CopiedVendor.EventData.Product
`network.transport`CopiedVendor.EventData.Protocol
`process.command_line`CopiedVendor.EventData.CommandLine
`process.entity_id`CopiedVendor.EventData.ProcessGuid, Vendor.EventData.SourceProcessGuid
`process.executable`CopiedVendor.EventData.Image, Vendor.EventData.SourceImage, Vendor.EventData.Destination
`process.hash.md5`CopiedVendor.EventData.Hashes.MD5
`process.hash.sha1`CopiedVendor.EventData.Hashes.SHA1
`process.hash.sha256`CopiedVendor.EventData.Hashes.SHA256
`process.parent.command_line`CopiedVendor.EventData.ParentCommandLine
`process.parent.entity_id`CopiedVendor.EventData.ParentProcessGuid
`process.parent.executable`CopiedVendor.EventData.ParentImage
`process.parent.pid`CopiedVendor.EventData.ParentProcessId
`process.pe.company`CopiedVendor.EventData.Company
`process.pe.description`CopiedVendor.EventData.Description
`process.pe.file_version`CopiedVendor.EventData.FileVersion
`process.pe.imphash`CopiedVendor.EventData.Hashes.IMPHASH
`process.pe.original_file_name`CopiedVendor.EventData.OriginalFileName
`process.pe.product`CopiedVendor.EventData.Product
`process.pid`CopiedVendor.EventData.ProcessId, Vendor.EventData.SourceProcessId
`process.thread.id`CopiedVendor.EventData.SourceThreadId
`process.working_directory`CopiedVendor.EventData.CurrentDirectory
`registry.path`CopiedVendor.EventData.TargetObject
`rule.name`CopiedVendor.EventData.RuleName
`source.domain`CopiedVendor.EventData.SourceHostname
`source.ip`CopiedVendor.EventData.SourceIp
`source.port`CopiedVendor.EventData.SourcePort
`user.id`CopiedVendor.winlog.user.identifier
`dns.answers.data[]`ExtractedVendor.EventData.QueryResults
`process.name`Extractedprocess.executable
`process.parent.name`Extractedprocess.parent.executable
`registry.hive`ExtractedVendor.EventData.TargetObject
`registry.key`ExtractedVendor.EventData.TargetObject
`registry.value`ExtractedVendor.EventData.TargetObject
`user.domain`ExtractedVendor.EventData.User
`user.name`ExtractedVendor.EventData.User
`dns.answers.type[]`MappedVendor.EventData.QueryResults
`@timestamp`ParsedVendor.TimeCreated
`ecs.version`StaticNone
`event.action`StaticVendor.EventID
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`file.code_signature.valid`StaticVendor.EventData.SignatureStatus
`network.direction`StaticVendor.EventData.Initiated
`network.protocol`StaticVendor.EventData.DestinationPortName, Vendor.EventData.SourcePortName
`network.type`StaticVendor.EventData.SourceIsIpv6
Vendor.EventData.DestinationIpdestination.ip 
Vendor.EventData.DestinationPortdestination.port 
Vendor.EventData.QueryNamedns.question.name 
Vendor.EventData.Signedfile.code_signature.exists 
Vendor.EventData.SignatureStatusfile.code_signature.status 
Vendor.EventData.Signaturefile.code_signature.subject_name 
Vendor.EventData.PipeNamefile.name 
Vendor.EventData.ImageLoadedfile.path 
Vendor.EventData.Hashes.IMPHASHfile.pe.imphash 
Vendor.EventData.SourcePortNamenetwork.protocol 
Vendor.EventData.Protocolnetwork.transport 
Vendor.EventData.CommandLineprocess.command_line 
Vendor.EventData.ProcessGuidprocess.entity_id 
Vendor.EventData.SourceProcessGUIDprocess.entity_id 
Vendor.EventData.Destinationprocess.executable 
Vendor.EventData.ParentCommandLineprocess.parent.command_line 
Vendor.EventData.ParentProcessGuidprocess.parent.entity_id 
Vendor.EventData.ParentImageprocess.parent.executable 
Vendor.EventData.ParentProcessIdprocess.parent.pid 
Vendor.EventData.Hashes.IMPHASHprocess.pe.imphash 
Vendor.EventData.SourceProcessIdprocess.pid 
Vendor.EventData.SourceThreadIdprocess.thread.id 
Vendor.EventData.CurrentDirectoryprocess.working_directory 
Vendor.EventData.TargetObjectregistry.path 
Vendor.EventData.SourceIpsource.ip 
Vendor.EventData.SourcePortsource.port 
Vendor.winlog.user.identifieruser.id