Parsers and Generated Fields

Tag Fields Created by Parser paloalto-prisma-sdwan
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser paloalto-prisma-sdwan
Vendor FieldCPS FieldDescription
Vendor.CLOUDGENIX_HOSTdestination.address 
Vendor.REMOTE_HOSTNAMEdestination.address 
observer.namedestination.address 
Vendor.BYTES_SENTdestination.bytes 
Vendor.bytes_recvddestination.bytes 
Vendor.DST_IPdestination.ip 
Vendor.REMOTE_IPdestination.ip 
Vendor.dst_ipdestination.ip 
Vendor.PKTS_SENTdestination.packets 
Vendor.DST_PORTdestination.port 
Vendor.dst_portdestination.port 
Vendor.MSGevent.action 
Vendor.DEVICE_TIMEevent.created 
Vendor.IDENTIFIERevent.id 
Vendor.REASONevent.reason 
Vendor.SEVERITYevent.severity 
Vendor.Severityevent.severity 
Vendor.CLOUDGENIX_HOSThost.name 
Vendor.FACILITYlog.syslog.facility.name 
Vendor.SEVERITYlog.syslog.severity.name 
source.bytesnetwork.bytes 
source.packetsnetwork.packets 
Vendor.PROTOCOL_NAMEnetwork.protocol 
Vendor.protocol_namenetwork.transport 
Vendor.CLOUDGENIX_HOST;observer.hostname 
Vendor.ION_HOS;observer.hostname 
Vendor.DeviceNameobserver.name 
server.addressobserver.name 
Vendor.PROCESS_NAMEprocess.name 
Vendor.app_name;process.name 
Vendor.ProcessIDprocess.pid 
Vendor.ION_HOSTserver.address 
observer.nameserver.address 
Vendor.NAMEsource.address 
Vendor.BYTES_RECVDsource.bytes 
Vendor.bytes_sentsource.bytes 
Vendor.SRC_IPsource.ip 
Vendor.src_ipsource.ip 
Vendor.PKTS_RECVDsource.packets 
Vendor.pkts_sentsource.packets 
Vendor.SRC_PORTsource.port 
Vendor.src_portsource.port 
Vendor.USERuser.name 
Vendor.useruser.name