Parsers and Generated Fields

Tag Fields Created by Parser nozomi-ids
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser nozomi-ids
Vendor FieldCPS FieldDescription
Vendor.dhostdestination.address  
Vendor.dstdestination.ip  
Vendor.dmacdestination.mac  
Vendor.dptdestination.port  
Vendor.device.vendordevice.manufacturer  
Vendor.label.Nameevent.action  
Vendor.Idevent.id  
Vendor.event_class_idevent.reason  
Vendor.Riskevent.risk_score  
Vendor.severityevent.severity  
Vendor.startevent.start  
Vendor.applog.syslog.appname  
Vendor.protonetwork.transport  
Vendor.dvchostobserver.hostname  
Vendor.dvcobserver.ip[0]  
Vendor.device.productobserver.os.name  
Vendor.device.versionobserver.os.version  
Vendor.n2os_schemaobserver.version  
Vendor.trigger_typerule.category  
Vendor.trigger_idrule.id  
Vendor.shostsource.address  
Vendor.srcsource.ip  
Vendor.smacsource.mac  
Vendor.dptsource.port  
Vendor.Mitre_attack_techniquesthreat.tactic.id[0]  
Vendor.Mitre_attack_tacticsthreat.tactic.name[0]  
Tag Fields Created by Parser nozomi-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser nozomi-syslog
Vendor FieldCPS FieldDescription
Vendor.dhostdestination.address 
Vendor.dstdestination.ip 
Vendor.dmacdestination.mac 
Vendor.dptdestination.port 
Vendor.device.vendordevice.manufacturer 
Vendor.label.Nameevent.action 
Vendor.Idevent.id 
Vendor.event_class_idevent.reason 
Vendor.Riskevent.risk_score 
Vendor.severityevent.severity 
Vendor.startevent.start 
Vendor.applog.syslog.appname 
Vendor.protonetwork.transport 
Vendor.dvchostobserver.address 
Vendor.dvcobserver.ip 
Vendor.device.productobserver.os.name 
Vendor.device.versionobserver.os.version 
Vendor.n2os_schemaobserver.version 
Vendor.trigger_typerule.category 
Vendor.trigger_idrule.id 
Vendor.shostsource.address 
Vendor.srcsource.ip 
Vendor.smacsource.mac 
Vendor.dptsource.port 
Vendor.Mitre_attack_techniquesthreat.tactic.id 
Vendor.Mitre_attack_tacticsthreat.tactic.name