Parsers and Generated Fields
Tag Fields Created by Parser rubrik-securitycloud
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser rubrik-securitycloud
| Vendor Field | CPS Field | Description |
|---|---|---|
| Vendor.errorCode | error.code | |
| errorCode | error.code | Error code when errorId exists |
| Vendor.errorId | error.id | |
| errorId | error.id | Error identifier when present |
| Vendor.errorReason | error.message | |
| errorReason | error.message | Error message when errorId exists |
| Vendor.eventName | event.action | |
| eventName | event.action | Name of the event action |
| Vendor.id | event.id | |
| id | event.id | Event identifier |
| status | event.outcome | Status mapping: success->success, fail->failure, others->unknown |
| severity | event.severity | Severity mapping: info/low->10, warning->30, medium->50, high->70, critical->90 |
| Vendor.auditUserId | user.id | |
| auditUserId | user.id | User identifier |
| Vendor.auditUserName | user.name | |
| auditUserName | user.name | Username |