Parsers and Generated Fields

Tag Fields Created by Parser paloalto-prisma-sdwan
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser paloalto-prisma-sdwan
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.type, log.syslog.facility.name
`event.type[]`ArrayVendor.flow_event, event.action, log.syslog.appname
`network.bytes`Calculatedsource.bytes, destination.bytes
`network.packets`Calculatedsource.packets, destination.packets
`event.outcome`ConditionalmsgType, log.syslog.appname
`destination.address`CopiedVendor.REMOTE_HOSTNAME, Vendor.CLOUDGENIX_HOST, observer.name
`destination.bytes`CopiedVendor.bytes_recvd, Vendor.BYTES_SENT
`destination.ip`CopiedVendor.dst_ip, Vendor.DST_IP, Vendor.REMOTE_IP
`destination.packets`Copiedbytes_recvd, Vendor.PKTS_SENT
`destination.port`CopiedVendor.dst_port, Vendor.DST_PORT
`event.created`CopiedVendor.DEVICE_TIME
`event.id`CopiedVendor.IDENTIFIER
`event.reason`CopiedVendor.REASON, parsed from authentication messages
`event.severity`CopiedVendor.SEVERITY, Vendor.Severity
`host.name`CopiedVendor.CLOUDGENIX_HOST
`log.syslog.facility.name`CopiedVendor.FACILITY
`log.syslog.severity.name`CopiedVendor.SEVERITY
`network.protocol`CopiedVendor.PROTOCOL_NAME
`network.transport`CopiedVendor.protocol_name
`observer.hostname`CopiedVendor.CLOUDGENIX_HOST
`observer.name`CopiedVendor.ION_HOST, Vendor.DeviceName
`process.name`CopiedVendor.app_name, Vendor.PROCESS_NAME
`process.pid`CopiedVendor.ProcessID
`server.address`CopiedVendor.ION_HOST, observer.name
`source.address`CopiedVendor.NAME
`source.bytes`CopiedVendor.bytes_sent, Vendor.BYTES_RECVD
`source.ip`CopiedVendor.src_ip, Vendor.SRC_IP
`source.packets`CopiedVendor.pkts_sent, Vendor.PKTS_RECVD
`source.port`CopiedVendor.src_port, Vendor.SRC_PORT
`user.name`CopiedVendor.USER, Vendor.user
`event.action`ExtractedVendor.MSG, Vendor.flow_event, Vendor.zbfw_classification_rules
`host.ip`Extracted@rawstring
`log.level`Extracted@rawstring
`log.syslog.appname`Extracted@rawstring
`log.syslog.hostname`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.procid`Extracted@rawstring
`log.syslog.version`Extracted@rawstring
`@timestamp`ParsedVendor.event_time, ts, Vendor.DEVICE_TIME
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.CLOUDGENIX_HOSTdestination.address 
Vendor.REMOTE_HOSTNAMEdestination.address 
observer.namedestination.address 
Vendor.BYTES_SENTdestination.bytes 
Vendor.bytes_recvddestination.bytes 
Vendor.DST_IPdestination.ip 
Vendor.REMOTE_IPdestination.ip 
Vendor.dst_ipdestination.ip 
Vendor.PKTS_SENTdestination.packets 
Vendor.DST_PORTdestination.port 
Vendor.dst_portdestination.port 
Vendor.MSGevent.action 
Vendor.DEVICE_TIMEevent.created 
Vendor.IDENTIFIERevent.id 
Vendor.REASONevent.reason 
Vendor.SEVERITYevent.severity 
Vendor.Severityevent.severity 
Vendor.CLOUDGENIX_HOSThost.name 
Vendor.FACILITYlog.syslog.facility.name 
Vendor.SEVERITYlog.syslog.severity.name 
source.bytesnetwork.bytes 
source.packetsnetwork.packets 
Vendor.PROTOCOL_NAMEnetwork.protocol 
Vendor.protocol_namenetwork.transport 
Vendor.DeviceNameobserver.name 
server.addressobserver.name 
Vendor.PROCESS_NAMEprocess.name 
Vendor.ProcessIDprocess.pid 
Vendor.ION_HOSTserver.address 
observer.nameserver.address 
Vendor.NAMEsource.address 
Vendor.BYTES_RECVDsource.bytes 
Vendor.bytes_sentsource.bytes 
Vendor.SRC_IPsource.ip 
Vendor.src_ipsource.ip 
Vendor.PKTS_RECVDsource.packets 
Vendor.pkts_sentsource.packets 
Vendor.SRC_PORTsource.port 
Vendor.src_portsource.port 
Vendor.USERuser.name 
Vendor.useruser.name