Parsers and Generated Fields

Tag Fields Created by Parser paloalto-prisma-sdwan
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser paloalto-prisma-sdwan
Source FieldCPS Field
Vendor.CLOUDGENIX_HOSTdestination.address
Vendor.REMOTE_HOSTNAMEdestination.address
observer.namedestination.address
Vendor.BYTES_SENTdestination.bytes
Vendor.bytes_recvddestination.bytes
Vendor.DST_IPdestination.ip
Vendor.REMOTE_IPdestination.ip
Vendor.dst_ipdestination.ip
Vendor.PKTS_SENTdestination.packets
Vendor.DST_PORTdestination.port
Vendor.dst_portdestination.port
Vendor.MSGevent.action
Vendor.DEVICE_TIMEevent.created
Vendor.IDENTIFIERevent.id
Vendor.REASONevent.reason
Vendor.SEVERITYevent.severity
Vendor.Severityevent.severity
Vendor.CLOUDGENIX_HOSThost.name
Vendor.FACILITYlog.syslog.facility.name
Vendor.SEVERITYlog.syslog.severity.name
source.bytesnetwork.bytes
source.packetsnetwork.packets
Vendor.PROTOCOL_NAMEnetwork.protocol
Vendor.protocol_namenetwork.transport
Vendor.CLOUDGENIX_HOST;observer.address
Vendor.ION_HOS;observer.address
Vendor.DeviceNameobserver.name
server.nameobserver.name
Vendor.ProcessIDprocess.id
Vendor.PROCESS_NAMEprocess.name
Vendor.app_name;process.name
Vendor.ION_HOSTserver.name
observer.nameserver.name
Vendor.NAMEsource.address
Vendor.BYTES_RECVDsource.bytes
Vendor.bytes_sentsource.bytes
Vendor.SRC_IPsource.ip
Vendor.src_ipsource.ip
Vendor.PKTS_RECVDsource.packets
Vendor.pkts_sentsource.packets
Vendor.SRC_PORTsource.port
Vendor.src_portsource.port
Vendor.USERuser.name
Vendor.useruser.name