Parsers and Generated Fields

Tag Fields Created by Parser radware-alteon
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser radware-alteon
Source FieldCPS FieldDescriptionMapping
__timestamp@timestampEvent timestamp with timezone supportExtracted using parseTimestamp() or findTimestamp() based on format
Vendor.keys.WAFObservedIP, Vendor.keys.SrcIpclient.addressClient addressCoalesced from WAFObservedIP or SrcIp, converted to lowercase
client.addressclient.domainClient domain nameAssigned from client.address if not valid IP
client.addressclient.ipClient IP addressAssigned from client.address if valid IP
Vendor.keys.DstIPdestination.addressDestination addressCopied from Vendor.keys.DstIP, converted to lowercase
destination.addressdestination.domainDestination domain nameAssigned from destination.address if not valid IP
destination.addressdestination.ipDestination IP addressAssigned from destination.address if valid IP
Vendor.keys.DstPortdestination.portDestination port numberCopied from Vendor.keys.DstPort
Noneecs.versionECS schema versionStatic value: 9.2.0
Vendor.message, http.response.status_codeevent.category[]Event category arrayArray populated based on message content and HTTP status
Noneevent.kindEvent categorizationStatic value: event
Noneevent.moduleEvent module identifierStatic value: alteon
http.response.status_code, Vendor.messageevent.outcomeEvent outcome determinationConditional based on HTTP status code and message patterns
Vendor.messageevent.reasonReason for event occurrenceExtracted from message using regex pattern
Vendor.message, http.response.status_codeevent.type[]Event type arrayArray populated based on message content and HTTP status
Vendor.messagehost.ip[]Host IP addresses arrayArray populated from message extraction
Vendor.keys.Methodhttp.request.methodHTTP request methodCopied from Vendor.keys.Method
Vendor.keys.ResponseCodehttp.response.status_codeHTTP response status codeCopied from Vendor.keys.ResponseCode
__remaining, Vendor.messagelog.syslog.appnameSyslog application nameExtracted from __remaining and Vendor.message using regex patterns
__remaininglog.syslog.hostnameSyslog hostname fieldExtracted from __remaining using regex pattern
__remaininglog.syslog.msgidSyslog message IDExtracted from __remaining using regex pattern
__tmplog.syslog.prioritySyslog priority valueExtracted from @rawstring using regex pattern
__remaininglog.syslog.procidSyslog process IDExtracted from __remaining using regex pattern
Vendor.messagelog.syslog.severity.nameSyslog severity level nameExtracted from Vendor.message using regex pattern
__tmplog.syslog.versionSyslog version numberExtracted from @rawstring using regex pattern
Vendor.messagenetwork.applicationNetwork applicationExtracted from Vendor.message using regex patterns
Vendor.messagenetwork.protocolNetwork protocolExtracted from Vendor.message using regex patterns
Vendor.keys.DstIPserver.addressServer addressCopied from Vendor.keys.DstIP, converted to lowercase
server.address, Vendor.messageserver.domainServer domain nameAssigned from server.address if not valid IP or extracted from message
server.addressserver.ipServer IP addressAssigned from server.address if valid IP
Vendor.keys.DstPort, Vendor.messageserver.portServer port numberCopied from Vendor.keys.DstPort or extracted from message
Vendor.keys.WAFObservedIP, Vendor.keys.SrcIpsource.addressSource addressCoalesced from WAFObservedIP or SrcIp, converted to lowercase
source.addresssource.domainSource domain nameAssigned from source.address if not valid IP
source.addresssource.ipSource IP addressAssigned from source.address if valid IP
url.originalurl.domainURL domain nameParsed from url.original and converted to lowercase
url.originalurl.fullFull URLCopied from url.original
Vendor.keys.URLurl.originalOriginal URLCopied from Vendor.keys.URL
url.originalurl.pathURL path componentParsed from url.original using parseUri()
url.originalurl.queryURL query parametersParsed from url.original using parseUri()
Vendor.keys.CWSIDuser.full_nameFull name from CWSID fieldExtracted from Vendor.keys.CWSID using regex pattern
Vendor.keys.CWSIDuser.idUser ID from catrecid portionExtracted from Vendor.keys.CWSID using regex pattern
Vendor.keys.CWSID, Vendor.messageuser.nameUsername from various sourcesExtracted from Vendor.keys.CWSID and Vendor.message using regex patterns
Vendor.keys.UserAgentuser_agent.originalOriginal user agent stringCopied from Vendor.keys.UserAgent