Parsers and Generated Fields

Tag Fields Created by Parser paloalto-prisma-sdwan
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser paloalto-prisma-sdwan
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.zbfw_classification_rules, Vendor.flow_event, error.code, Vendor.MSG, log.syslog.appname
`event.type[]`ArrayVendor.zbfw_classification_rules, Vendor.flow_event, Vendor.MSG, log.syslog.appname
`network.bytes`Calculatedsource.bytes, destination.bytes
`network.packets`Calculatedsource.packets, destination.packets
`destination.address`CoalescedVendor.dst_ip, Vendor.DST_IP, Vendor.REMOTE_IP
`destination.bytes`CoalescedVendor.bytes_recvd, Vendor.BYTES_SENT
`destination.packets`CoalescedVendor.pkts_sent, Vendor.PKTS_SENT
`destination.port`CoalescedVendor.dst_port, Vendor.DST_PORT
`log.level`CoalescedVendor.Severity, Vendor.SEVERITY
`observer.hostname`CoalescedVendor.CLOUDGENIX_HOST, Vendor.ION_HOST
`source.address`CoalescedVendor.src_ip, Vendor.SRC_IP
`source.bytes`CoalescedVendor.bytes_sent, Vendor.BYTES_RECVD
`source.packets`CoalescedVendor.pkts_sent, Vendor.PKTS_RECVD
`source.port`CoalescedVendor.src_port, Vendor.SRC_PORT
`user.name`CoalescedVendor.user, Vendor.USER
`client.ip`Conditionalclient.address
`destination.ip`Conditionaldestination.address
`event.dataset`ConditionalVendor.STATUS, Vendor.FACILITY
`event.outcome`ConditionalVendor.STATUS, Vendor.MSG, log.syslog.appname
`event.severity`Conditionallog.level
`server.ip`Conditionalserver.address
`source.ip`Conditionalsource.address
`client.address`Copiedsource.address
`client.bytes`Copiedsource.bytes
`client.packets`Copiedsource.packets
`client.port`Copiedsource.port
`destination.domain`CopiedVendor.REMOTE_HOSTNAME
`error.code`CopiedVendor.CODE
`event.created`CopiedVendor.DEVICE_TIME
`event.id`CopiedVendor.IDENTIFIER
`event.reason`CopiedVendor.REASON
`host.name`CopiedVendor.DeviceName
`log.syslog.facility.name`CopiedVendor.FACILITY
`log.syslog.severity.name`CopiedVendor.SEVERITY
`network.application`CopiedVendor.app_name
`network.transport`CopiedVendor.protocol_name
`process.name`CopiedVendor.PROCESS_NAME
`process.pid`CopiedVendor.ProcessID
`server.address`Copieddestination.address
`server.bytes`Copieddestination.bytes
`server.domain`Copieddestination.domain
`server.packets`Copieddestination.packets
`server.port`Copieddestination.port
`source.domain`CopiedVendor.NAME
`event.action`ExtractedVendor.MSG, Vendor.zbfw_classification_rules
`log.syslog.appname`Extracted@rawstring, Vendor.MSG
`log.syslog.hostname`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.procid`Extracted@rawstring
`log.syslog.version`Extracted@rawstring
`observer.ip[0]`Extracted@rawstring
`@timestamp`ParsedVendor.event_time, __ts, Vendor.DEVICE_TIME
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.zbfw_classification_rules__tmp_zbfw_rules 
source.addressclient.address 
source.bytesclient.bytes 
source.packetsclient.packets 
source.portclient.port 
Vendor.REMOTE_HOSTNAMEdestination.domain 
Vendor.CODEerror.code 
Vendor.MSGevent.action 
Vendor.DEVICE_TIMEevent.created 
Vendor.IDENTIFIERevent.id 
Vendor.REASONevent.reason 
Vendor.DeviceNamehost.name 
Vendor.FACILITYlog.syslog.facility.name 
Vendor.SEVERITYlog.syslog.severity.name 
Vendor.app_namenetwork.application 
source.bytesnetwork.bytes 
source.packetsnetwork.packets 
Vendor.protocol_namenetwork.transport 
Vendor.PROCESS_NAMEprocess.name 
Vendor.ProcessIDprocess.pid 
destination.addressserver.address 
destination.bytesserver.bytes 
destination.domainserver.domain 
destination.portserver.port 
Vendor.NAMEsource.domain