Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dns
Vendor FieldCPS FieldDescription
Vendor.RemoteIPclient.ip 
client.ip;destination.ip 
server.ip;destination.ip 
Vendor.Flagsdns.header_flags[0]  
Vendor.PacketIDdns.id  
Vendor.Opcodedns.op_code  
Vendor.QuestionNamedns.question.name  
Vendor.QuestionTypedns.question.type  
Vendor.ResponseCodedns.response_code  
Vendor.EventReceivedTimeevent.created  
Vendor.XIDevent.id  
Vendor.SourceModuleNameevent.module  
Vendor.Protocolnetwork.transport 
Vendor.ThreadIDprocess.thread.id  
Vendor.RemoteIPserver.ip 
client.ip;source.ip 
server.ip;source.ip 
Tag Fields Created by Parser windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser windows-dns
Vendor FieldCPS FieldDescription
Vendor.RemoteIPclient.ip 
Vendor.RemoteIP;destination.ip 
Vendor.Flagsdns.header_flags 
Vendor.PacketIDdns.id 
Vendor.Opcodedns.op_code 
Vendor.QuestionNamedns.question.name 
Vendor.QuestionTypedns.question.type 
Vendor.ResponseCodedns.response_code 
Vendor.EventReceivedTimeevent.created 
Vendor.XIDevent.id 
Vendor.SourceModuleNameevent.module 
Vendor.Protocolnetwork.transport 
Vendor.ThreadIDprocess.thread.id 
Vendor.RemoteIPserver.ip 
Vendor.RemoteIP;source.ip