Parsers and Generated Fields

Tag Fields Created by Parser obsidian-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser obsidian-json
Source FieldLogScale Repository Field
Vendor.riskVendor.severity
Vendor.eventevent.action
Vendor.humanReadableDescription.plainevent.action
Vendor.summaryevent.action
Vendor.datetimeevent.created
Vendor.driftevent.created
Vendor.eventDatetimeevent.created
Vendor.idevent.id
Vendor.integrationevent.id
Vendor.eventevent.reason
Vendor.humanReadableDescription.plainevent.reason
Vendor.transitionevent.reason
Vendor.configevent.url
Vendor.urlsevent.url
Vendor.actors[0].namename
Vendor.labels.username[0].valuename
Vendor.intelligenceCatalogReference.mitreProperties.namethreat.feed.reference
Vendor.severitythreat.indicator.confidence
Vendor.intelligenceCatalogReference.mitreProperties.descriptionthreat.indicator.description
Vendor.namethreat.indicator.name
Vendor.intelligenceCatalogReference.mitreProperties.urlthreat.indicator.reference
Vendor.service.namethreat.software.name
Vendor.intelligenceCatalogReference.taxonomy.tactic.namethreat.tactic.name
Vendor.intelligenceCatalogReference.taxonomy.technique.namethreat.technique.name
Vendor.relatedTargetEmails[0]user.email
Vendor.targets[0].iduser.id