Parsers and Generated Fields

Tag Fields Created by Parser microsoft-windows-dns
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser microsoft-windows-dns
Vendor FieldCPS FieldDescription
`dns.header_flags[]`ArrayVendor.Flags
`event.category[]`ArrayNone
`event.type[]`ArrayNone
`client.address`ConditionallyVendor.RemoteIP, Vendor.IP
`destination.address`ConditionallyVendor.RemoteIP
`server.address`ConditionallyVendor.RemoteIP
`source.address`ConditionallyVendor.RemoteIP
`client.domain`Copiedclient.address
`client.ip`Copiedclient.address
`destination.domain`Copieddestination.address
`destination.ip`Copieddestination.address
`dns.answers[0].name`CopiedVendor.AnswerName
`dns.answers[0].type`CopiedVendor.AnswerType
`dns.id`CopiedVendor.PacketID
`dns.op_code`CopiedVendor.Opcode
`dns.question.type`CopiedVendor.QuestionType
`dns.response_code`CopiedVendor.ResponseCode
`event.created`CopiedVendor.EventReceivedTime
`event.id`CopiedVendor.XID
`network.transport`CopiedVendor.Protocol
`process.thread.name`CopiedVendor.ThreadID
`server.domain`Copiedserver.address
`server.ip`Copiedserver.address
`source.domain`Copiedsource.address
`source.ip`Copiedsource.address
`dns.type`DeterminedVendor.QR, dns.answers.type
`network.type`DeterminedVendor.RemoteIP
`error.reason`Extractederror.reason
`error.message`Mappeddns.response_code
`network.direction`MappedVendor.Direction
`@timestamp`Parsed__timestamp, __timestamp1
`dns.question.name`ParsedVendor.QuestionName
`process.thread.id`ParsedVendor.ThreadID
`ecs.version`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.RemoteIPclient.address 
Vendor.IPclient.ip 
Vendor.AnswerNamedns.answers[0].name 
Vendor.AnswerTypedns.answers[0].type 
Vendor.PacketIDdns.id 
Vendor.Opcodedns.op_code 
Vendor.QuestionNamedns.question.name 
Vendor.QuestionTypedns.question.type 
Vendor.ResponseCodedns.response_code 
Vendor.EventReceivedTimeevent.created 
Vendor.XIDevent.id 
Vendor.ThreadIDprocess.thread.name 
Vendor.RemoteIPserver.address