Parsers and Generated Fields

Tag Fields Created by Parser nozomi-ids
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser nozomi-ids
Source FieldCPS Field
Vendor.dhostdestination.address
Vendor.dstdestination.ip
Vendor.dmacdestination.mac
Vendor.dptdestination.port
Vendor.device.vendordevice.manufacturer
Vendor.label.Nameevent.action
Vendor.Idevent.id
Vendor.event_class_idevent.reason
Vendor.Riskevent.risk_score
Vendor.severityevent.severity
Vendor.startevent.start
Vendor.applog.syslog.appname
Vendor.protonetwork.transport
Vendor.dvchostobserver.hostname
Vendor.dvcobserver.ip[0]
Vendor.device.productobserver.os.name
Vendor.device.versionobserver.os.version
Vendor.n2os_schemaobserver.version
Vendor.trigger_typerule.category
Vendor.trigger_idrule.id
Vendor.shostsource.address
Vendor.srcsource.ip
Vendor.smacsource.mac
Vendor.dptsource.port
Vendor.Mitre_attack_techniquesthreat.tactic.id[0]
Vendor.Mitre_attack_tacticsthreat.tactic.name[0]
Tag Fields Created by Parser nozomi-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser nozomi-syslog
Source FieldCPS Field
Vendor.dhostdestination.address
Vendor.dstdestination.ip
Vendor.dmacdestination.mac
Vendor.dptdestination.port
Vendor.device.vendordevice.manufacturer
Vendor.label.Nameevent.action
Vendor.Idevent.id
Vendor.event_class_idevent.reason
Vendor.Riskevent.risk_score
Vendor.severityevent.severity
Vendor.startevent.start
Vendor.applog.syslog.appname
Vendor.protonetwork.transport
Vendor.dvchostobserver.address
Vendor.dvcobserver.ip
Vendor.device.productobserver.os.name
Vendor.device.versionobserver.os.version
Vendor.n2os_schemaobserver.version
Vendor.trigger_typerule.category
Vendor.trigger_idrule.id
Vendor.shostsource.address
Vendor.srcsource.ip
Vendor.smacsource.mac
Vendor.dptsource.port
Vendor.Mitre_attack_techniquesthreat.tactic.id
Vendor.Mitre_attack_tacticsthreat.tactic.name