Parsers and Generated Fields

Tag Fields Created by Parser clicksBlocked-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser clicksBlocked-json
Vendor FieldCPS FieldDescription
Vendor.clickIPdestination.ip  
Vendor.GUIDemail.local_id 
Vendor.messageIDemail.message_id  
Vendor.idevent.id  
Vendor.senderIPsource.ip  
url.hosturl.domain  
Vendor.urlurl.full  
Vendor.userAgentuser_agent.original 
Tag Fields Created by Parser clicksPermitted-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser clicksPermitted-json
Vendor FieldCPS FieldDescription
Vendor.clickIPdestination.ip  
Vendor.GUIDemail.local_id 
Vendor.messageIDemail.message_id  
Vendor.idevent.id  
Vendor.senderIPsource.ip  
url.hosturl.domain  
Vendor.urlurl.full  
Vendor.userAgentuser_agent.original 
Tag Fields Created by Parser messagesBlocked-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser messagesBlocked-json
Vendor FieldCPS FieldDescription
Vendor.messageParts[0].contentTypeemail.attachments[0].file.mime_type  
Vendor.messageParts[0].filenameemail.attachments[0].file.name  
Vendor.messageParts[1].contentTypeemail.attachments[1].file.mime_type  
Vendor.messageParts[1].filenameemail.attachments[1].file.name  
Vendor.messageParts[2].contentTypeemail.attachments[2].file.mime_type  
Vendor.messageParts[2].filenameemail.attachments[2].file.name  
Vendor.messageParts[3].contentTypeemail.attachments[3].file.mime_type  
Vendor.messageParts[3].filenameemail.attachments[3].file.name  
Vendor.messageParts[4].contentTypeemail.attachments[4].file.mime_type  
Vendor.messageParts[4].filenameemail.attachments[4].file.name  
Vendor.GUIDemail.local_id 
Vendor.messageIDemail.message_id  
Vendor.subjectemail.subject  
Vendor.xmaileremail.x_mailer  
Vendor.idevent.id  
Vendor.senderIPsource.ip  
Tag Fields Created by Parser messagesDelivered-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser messagesDelivered-json
Vendor FieldCPS FieldDescription
Vendor.messageParts[0].contentTypeemail.attachments[0].file.mime_type  
Vendor.messageParts[0].filenameemail.attachments[0].file.name  
Vendor.messageParts[1].contentTypeemail.attachments[1].file.mime_type  
Vendor.messageParts[1].filenameemail.attachments[1].file.name  
Vendor.messageParts[2].contentTypeemail.attachments[2].file.mime_type  
Vendor.messageParts[2].filenameemail.attachments[2].file.name  
Vendor.messageParts[3].contentTypeemail.attachments[3].file.mime_type  
Vendor.messageParts[3].filenameemail.attachments[3].file.name  
Vendor.messageParts[4].contentTypeemail.attachments[4].file.mime_type  
Vendor.messageParts[4].filenameemail.attachments[4].file.name  
Vendor.GUIDemail.local_id 
Vendor.messageIDemail.message_id  
Vendor.subjectemail.subject  
Vendor.xmaileremail.x_mailer  
Vendor.idevent.id  
Vendor.senderIPsource.ip