Parsers and Generated Fields
Tag Fields Created by Parser radware-alteon
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser radware-alteon
| Vendor Field | CPS Field | Description |
|---|---|---|
| `event.category[]` | Array | None |
| `event.type[]` | Array | None |
| `client.ip` | Conditional | Vendor.keys.WAFObservedIP, Vendor.keys.SrcIp |
| `event.outcome` | Conditional | http.response.status_code |
| `destination.ip` | Copied | server.ip |
| `destination.port` | Copied | server.port |
| `http.request.method` | Copied | Vendor.keys.Method |
| `http.response.status_code` | Copied | Vendor.keys.ResponseCode |
| `server.ip` | Copied | Vendor.keys.DstIP |
| `server.port` | Copied | Vendor.keys.DstPort |
| `source.ip` | Copied | client.ip |
| `url.full` | Copied | url.original |
| `url.original` | Copied | Vendor.keys.URL |
| `user_agent.original` | Copied | Vendor.keys.UserAgent |
| `@timestamp` | Extracted | log.syslog.timestamp |
| `log.syslog.appname` | Extracted | _remaining |
| `log.syslog.hostname` | Extracted | _remaining |
| `log.syslog.msgid` | Extracted | _remaining |
| `log.syslog.priority` | Extracted | @rawstring |
| `log.syslog.procid` | Extracted | _remaining |
| `log.syslog.severity.name` | Extracted | Vendor.message |
| `log.syslog.timestamp` | Extracted | _remaining |
| `log.syslog.version` | Extracted | @rawstring |
| `user.full_name` | Extracted | Vendor.keys.CWSID |
| `user.id` | Extracted | Vendor.keys.CWSID |
| `user.name` | Extracted | Vendor.keys.CWSID |
| `url.domain` | Parsed | url.original |
| `ecs.version` | Static | None |
| `event.kind` | Static | None |
| `event.module` | Static | None |
| Vendor.keys.SrcIp | client.ip | |
| Vendor.keys.WAFObservedIP | client.ip | |
| server.ip | destination.ip | |
| server.port | destination.port | |
| Vendor.keys.Method | http.request.method | |
| Vendor.keys.ResponseCode | http.response.status_code | |
| Vendor.keys.DstIP | server.ip | |
| Vendor.keys.DstPort | server.port | |
| client.ip | source.ip | |
| url.original | url.full | |
| Vendor.keys.URL | url.original | |
| Vendor.keys.UserAgent | user_agent.original |