Parsers and Generated Fields

Tag Fields Created by Parser okta-sso
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser okta-sso
Vendor FieldCPS FieldDescription
Vendor.published@timestampEvent timestamp
Vendor.securityContext.asOrgclient.as.organization.name 
Vendor.client.geographicalContext.cityclient.geo.city_name 
Vendor.client.geographicalContext.countryclient.geo.country_name 
Vendor.client.geographicalContext.geolocation.latclient.geo.location.lat 
Vendor.client.geographicalContext.geolocation.lonclient.geo.location.lon 
Vendor.client.geographicalContext.stateclient.geo.region_name 
Vendor.client.ipAddressclient.ip 
Vendor.actor.displayNameclient.user.full_name 
Vendor.actor.idclient.user.id 
user.nameclient.user.name 
Vendor.eventTypeevent.actionEvent type from Okta
Vendor.uuidevent.id 
Vendor.outcome.resultevent.outcomeMaps SUCCESS/ALLOW to "success", FAILURE/DENY to "failure", empty/null to "unknown"
Vendor.outcome.reasonevent.reason 
Vendor.displayMessagemessage 
Vendor.client.geographicalContext.citysource.geo.city_nameClient city location
Vendor.client.geographicalContext.countrysource.geo.country_nameClient country location
Vendor.client.geographicalContext.statesource.geo.region_nameClient state location
Vendor.client.ipAddresssource.ipClient IP address
client.ipsource.ip 
client.user.idsource.user.full_name 
client.user.idsource.user.id 
Vendor.client.user.idsource.user.id, source.user.full_nameClient user information
user.namesource.user.name 
client.user.full_nameuser.full_name 
Vendor.actor.alternateIduser.name 
Vendor.target[].emailuser.target.emailTarget user email when type is User
__out[0]user.target.email  
__out[0]user.target.full_name  
Vendor.target[].displayNameuser.target.full_name, user.target.nameTarget user display name when type is User
Vendor.target[].iduser.target.group.idTarget group ID when type is UserGroup
__out[0]user.target.group.id  
Vendor.target[].displayNameuser.target.group.nameTarget group name when type is UserGroup
__out[0]user.target.group.name  
Vendor.target[].iduser.target.idTarget user ID when type is User
__out[0]user.target.id  
__out[0]user.target.name  
Vendor.client.deviceuser_agent.device.nameDevice name
Vendor.client.userAgent.browseruser_agent.nameBrowser name
Vendor.client.userAgent.rawUserAgentuser_agent.originalRaw user agent string
Vendor.client.userAgent.osuser_agent.os.nameOperating system name