Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dns
Vendor FieldCPS FieldDescription
Vendor.IPclient.ipClient IP address for socket failures
Vendor.RemoteIPclient.ip 
client.ip;destination.ip 
server.ip;destination.ip 
Vendor.Flagsdns.header_flags[]DNS header flags as array
Vendor.PacketIDdns.idDNS packet identifier
Vendor.Opcodedns.op_codeDNS operation code
Vendor.QuestionNamedns.question.nameDNS question name
Vendor.QuestionTypedns.question.typeDNS question type
Vendor.ResponseCodedns.response_codeDNS response code
error.reasonerror.reasonError reason for socket failures
Vendor.EventReceivedTimeevent.createdTimestamp when event was received
Vendor.XIDevent.idTransaction ID of the DNS query
Vendor.Directionnetwork.directionDirection of packet (Snd=outbound, Rcv=inbound)
Vendor.Protocolnetwork.transportProtocol used (UDP/TCP)
Vendor.ThreadIDprocess.thread.idThread ID of the DNS server process
Vendor.RemoteIPserver.ip 
client.ip;source.ip 
server.ip;source.ip 
Vendor.RemoteIPsource.ip/destination.ip/client.ip/server.ipIP address mapping depends on direction and DNS type