Parsers and Generated Fields

Tag Fields Created by Parser nozomi-ids
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser nozomi-ids
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.msg
`event.type[]`ArrayVendor.msg
`observer.ip[]`ArrayVendor.dvc
`threat.tactic.id[]`ArrayVendor.Mitre_attack_techniques
`threat.tactic.name[]`ArrayVendor.Mitre_attack_tactics
`destination.address`CopiedVendor.dhost
`destination.ip`CopiedVendor.dst
`destination.port`CopiedVendor.dpt
`device.manufacturer`CopiedVendor.device.vendor
`event.action`CopiedVendor.Name
`event.id`CopiedVendor.Id
`event.reason`CopiedVendor.event_class_id
`event.risk_score`CopiedVendor.Risk
`event.start`CopiedVendor.start
`log.syslog.appname`CopiedVendor.app
`network.transport`CopiedVendor.proto
`observer.hostname`CopiedVendor.dvchost
`observer.os.name`CopiedVendor.device.product
`observer.os.version`CopiedVendor.device.version
`observer.vendor`CopiedVendor.device.vendor
`observer.version`CopiedVendor.n2os_schema
`rule.category`CopiedVendor.trigger_type
`rule.id`CopiedVendor.trigger_id
`rule.name`CopiedVendor.event_class_id
`source.address`CopiedVendor.shost
`source.ip`CopiedVendor.src
`source.port`CopiedVendor.dpt
`client.ip`ExtractedVendor.msg
`file.hash.md5`ExtractedVendor.msg
`file.name`ExtractedVendor.msg
`file.path`ExtractedVendor.msg
`log.syslog.hostname`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.version`Extracted@rawstring
`network.protocol`ExtractedVendor.msg
`process.name`ExtractedVendor.msg
`server.address`ExtractedVendor.msg
`server.ip`ExtractedVendor.msg
`threat.software.name`ExtractedVendor.msg
`threat.technique.name`ExtractedVendor.msg
`url.domain`ExtractedVendor.msg
`url.original`ExtractedVendor.msg
`user.domain`ExtractedVendor.suser, @rawstring
`user.name`ExtractedVendor.suser, @rawstring
`event.severity`MappedVendor.severity
`@timestamp`ParsedVendor.syslog.timestamp
`event.outcome`SetVendor.msg
`ecs.version`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`destination.mac`TransformedVendor.dmac
`source.mac`TransformedVendor.smac
Vendor.dhostdestination.address 
Vendor.dstdestination.ip 
Vendor.dptdestination.port 
Vendor.device.vendordevice.manufacturer 
Vendor.Nameevent.action 
Vendor.Idevent.id 
Vendor.event_class_idevent.reason 
Vendor.Riskevent.risk_score 
Vendor.startevent.start 
Vendor.applog.syslog.appname 
Vendor.protonetwork.transport 
Vendor.dvchostobserver.hostname 
Vendor.device.productobserver.os.name 
Vendor.device.versionobserver.os.version 
Vendor.device.vendorobserver.vendor 
Vendor.n2os_schemaobserver.version 
Vendor.trigger_typerule.category 
Vendor.trigger_idrule.id 
Vendor.shostsource.address 
Vendor.srcsource.ip 
Vendor.dptsource.port