Parsers and Generated Fields

Tag Fields Created by Parser okta-sso
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser okta-sso
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.eventType, Vendor.debugContext.debugData.threatSuspected
`event.type[]`ArrayVendor.eventType
`rule.id`CoalescedVendor.PolicyRule.id, Vendor.Rule.id
`rule.name`CoalescedVendor.PolicyRule.displayName, Vendor.Rule.displayName
`client.user.full_name`ConditionallyVendor.actor.displayName, Vendor.actor.type
`client.as.number`CopiedVendor.securityContext.asNumber
`client.as.organization.name`CopiedVendor.securityContext.asOrg
`client.geo.city_name`CopiedVendor.client.geographicalContext.city
`client.geo.country_name`CopiedVendor.client.geographicalContext.country
`client.geo.location.lat`CopiedVendor.client.geographicalContext.geolocation.lat
`client.geo.location.lon`CopiedVendor.client.geographicalContext.geolocation.lon
`client.geo.region_name`CopiedVendor.client.geographicalContext.state
`client.ip`CopiedVendor.client.ipAddress
`client.user.id`CopiedVendor.actor.id
`client.user.name`CopiedVendor.actor.alternateId
`event.action`CopiedVendor.eventType
`event.id`CopiedVendor.uuid
`message`CopiedVendor.displayMessage
`network.application`CopiedVendor.AppInstance.displayName
`rule.ruleset`CopiedVendor.PolicyEntity.displayName
`source.ip`Copiedclient.ip
`source.user.full_name`Copiedclient.user.full_name
`source.user.id`Copiedclient.user.id
`source.user.name`CopiedVendor.actor.alternateId
`transaction.id`CopiedVendor.transaction.id
`user.email`Copieduser.name
`user.full_name`Copiedclient.user.full_name
`user.name`CopiedVendor.actor.alternateId
`user_agent.name`CopiedVendor.client.userAgent.browser
`user_agent.original`CopiedVendor.client.userAgent.rawUserAgent
`user.target.email`ExtractedVendor.target[].detailEntry.emailAddress
`user.target.full_name`ExtractedVendor.target[].displayName
`user.target.group.id`ExtractedVendor.target[].id
`user.target.group.name`ExtractedVendor.target[].displayName
`user.target.id`ExtractedVendor.target[].id
`user.target.name`ExtractedVendor.target[].alternateId
`user_agent.os.name`ExtractedVendor.client.userAgent.os
`user_agent.os.version`ExtractedVendor.client.userAgent.os
`client.domain`LowercasedVendor.securityContext.domain
`source.domain`LowercasedVendor.securityContext.domain
`event.outcome`MapsVendor.outcome.result
`event.severity`MapsVendor.severity
`@timestamp`ParsedVendor.published, Vendor.errorSummary
`ecs.version`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.type`StaticNone
`event.reason`UsesVendor.outcome.reason, message
Vendor.securityContext.asNumberclient.as.number 
Vendor.securityContext.asOrgclient.as.organization.name 
Vendor.client.geographicalContext.cityclient.geo.city_name 
Vendor.client.geographicalContext.countryclient.geo.country_name 
Vendor.client.geographicalContext.geolocation.latclient.geo.location.lat 
Vendor.client.geographicalContext.geolocation.lonclient.geo.location.lon 
Vendor.client.geographicalContext.stateclient.geo.region_name 
Vendor.client.ipAddressclient.ip 
Vendor.actor.displayNameclient.user.full_name 
Vendor.actor.alternateIdclient.user.name 
Vendor.eventTypeevent.action 
Vendor.uuidevent.id 
Vendor.displayMessagemessage 
Vendor.AppInstance.displayNamenetwork.application 
Vendor.PolicyEntity.displayNamerule.ruleset 
client.ipsource.ip 
client.user.full_namesource.user.full_name 
client.user.idsource.user.id 
Vendor.actor.alternateIdsource.user.name 
Vendor.transaction.idtransaction.id 
client.user.full_nameuser.full_name 
Vendor.actor.alternateIduser.name 
Vendor.client.userAgent.browseruser_agent.name 
Vendor.client.userAgent.rawUserAgentuser_agent.original