Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dns
Vendor FieldCPS FieldDescription
`dns.header_flags[]`ArrayVendor.Flags
`client.ip`ConditionallyVendor.RemoteIP, Vendor.IP
`destination.ip`ConditionallyVendor.RemoteIP
`server.ip`ConditionallyVendor.RemoteIP
`source.ip`ConditionallyVendor.RemoteIP
`dns.id`CopiedVendor.PacketID
`dns.op_code`CopiedVendor.Opcode
`dns.question.type`CopiedVendor.QuestionType
`dns.response_code`CopiedVendor.ResponseCode
`event.created`CopiedVendor.EventReceivedTime
`event.id`CopiedVendor.XID
`network.transport`CopiedVendor.Protocol
`process.thread.id`CopiedVendor.ThreadID
`dns.type`DeterminedVendor.QR
`network.type`DeterminedVendor.RemoteIP
`error.reason`Extractederror.reason
`error.message`Mappeddns.response_code
`network.direction`MappedVendor.Direction
`@timestamp`Parsedtimestamp
`dns.question.name`ParsedVendor.QuestionName
`ecs.version`StaticNone
`event.category[]`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`event.type[]`StaticNone
Vendor.IPclient.ip 
Vendor.RemoteIPclient.ip 
Vendor.PacketIDdns.id 
Vendor.Opcodedns.op_code 
Vendor.QuestionNamedns.question.name 
Vendor.QuestionTypedns.question.type 
Vendor.ResponseCodedns.response_code 
Vendor.EventReceivedTimeevent.created 
Vendor.XIDevent.id 
Vendor.Protocolnetwork.transport 
Vendor.ThreadIDprocess.thread.id 
Vendor.RemoteIPserver.ip