Parsers and Generated Fields

Tag Fields Created by Parser clicksBlocked-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser clicksBlocked-json
Source FieldCPS Field
Vendor.clickIPdestination.ip
Vendor.GUIDemail.local_id
Vendor.messageIDemail.message_id
Vendor.idevent.id
Vendor.senderIPsource.ip
url.hosturl.domain
Vendor.urlurl.full
Vendor.userAgentuser_agent.original
Tag Fields Created by Parser clicksPermitted-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser clicksPermitted-json
Source FieldCPS Field
Vendor.clickIPdestination.ip
Vendor.GUIDemail.local_id
Vendor.messageIDemail.message_id
Vendor.idevent.id
Vendor.senderIPsource.ip
url.hosturl.domain
Vendor.urlurl.full
Vendor.userAgentuser_agent.original
Tag Fields Created by Parser messagesBlocked-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser messagesBlocked-json
Source FieldCPS Field
Vendor.messageParts[0].contentTypeemail.attachments[0].file.mime_type
Vendor.messageParts[0].filenameemail.attachments[0].file.name
Vendor.messageParts[1].contentTypeemail.attachments[1].file.mime_type
Vendor.messageParts[1].filenameemail.attachments[1].file.name
Vendor.messageParts[2].contentTypeemail.attachments[2].file.mime_type
Vendor.messageParts[2].filenameemail.attachments[2].file.name
Vendor.messageParts[3].contentTypeemail.attachments[3].file.mime_type
Vendor.messageParts[3].filenameemail.attachments[3].file.name
Vendor.messageParts[4].contentTypeemail.attachments[4].file.mime_type
Vendor.messageParts[4].filenameemail.attachments[4].file.name
Vendor.GUIDemail.local_id
Vendor.messageIDemail.message_id
Vendor.subjectemail.subject
Vendor.xmaileremail.x_mailer
Vendor.idevent.id
Vendor.senderIPsource.ip
Tag Fields Created by Parser messagesDelivered-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser messagesDelivered-json
Source FieldCPS Field
Vendor.messageParts[0].contentTypeemail.attachments[0].file.mime_type
Vendor.messageParts[0].filenameemail.attachments[0].file.name
Vendor.messageParts[1].contentTypeemail.attachments[1].file.mime_type
Vendor.messageParts[1].filenameemail.attachments[1].file.name
Vendor.messageParts[2].contentTypeemail.attachments[2].file.mime_type
Vendor.messageParts[2].filenameemail.attachments[2].file.name
Vendor.messageParts[3].contentTypeemail.attachments[3].file.mime_type
Vendor.messageParts[3].filenameemail.attachments[3].file.name
Vendor.messageParts[4].contentTypeemail.attachments[4].file.mime_type
Vendor.messageParts[4].filenameemail.attachments[4].file.name
Vendor.GUIDemail.local_id
Vendor.messageIDemail.message_id
Vendor.subjectemail.subject
Vendor.xmaileremail.x_mailer
Vendor.idevent.id
Vendor.senderIPsource.ip