Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dns
Source FieldCPS Field
Vendor.RemoteIPclient.ip
client.ip;destination.ip
server.ip;destination.ip
Vendor.Flagsdns.header_flags[0]
Vendor.PacketIDdns.id
Vendor.Opcodedns.op_code
Vendor.QuestionNamedns.question.name
Vendor.QuestionTypedns.question.type
Vendor.ResponseCodedns.response_code
Vendor.EventReceivedTimeevent.created
Vendor.XIDevent.id
Vendor.SourceModuleNameevent.module
Vendor.Protocolnetwork.transport
Vendor.ThreadIDprocess.thread.id
Vendor.RemoteIPserver.ip
client.ip;source.ip
server.ip;source.ip
Tag Fields Created by Parser windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser windows-dns
Source FieldCPS Field
Vendor.RemoteIPclient.ip
Vendor.RemoteIP;destination.ip
Vendor.Flagsdns.header_flags
Vendor.PacketIDdns.id
Vendor.Opcodedns.op_code
Vendor.QuestionNamedns.question.name
Vendor.QuestionTypedns.question.type
Vendor.ResponseCodedns.response_code
Vendor.EventReceivedTimeevent.created
Vendor.XIDevent.id
Vendor.SourceModuleNameevent.module
Vendor.Protocolnetwork.transport
Vendor.ThreadIDprocess.thread.id
Vendor.RemoteIPserver.ip
Vendor.RemoteIP;source.ip