Parsers and Generated Fields

Tag Fields Created by Parser rubrik-securitycloud
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser rubrik-securitycloud
Source FieldCPS FieldDescriptionMapping
Noneecs.versionECS schema versionStatic value: 9.3.0
Vendor.errorCodeerror.codeError code identifierCopied from Vendor.errorCode when errorId exists
Vendor.errorIderror.idError identifierCopied from Vendor.errorId when present
Vendor.errorReasonerror.messageError message descriptionCopied from Vendor.errorReason when errorId exists
Vendor.eventNameevent.actionName of the event actionCopied from Vendor.eventName
Noneevent.category[]Event category classificationStatic array value: vulnerability
Vendor.idevent.idUnique event identifierCopied from Vendor.id
Noneevent.kindEvent kind classificationStatic value: event
Noneevent.moduleModule name for the event sourceStatic value: securitycloud
Vendor.statusevent.outcomeEvent outcome based on status (success/failure/unknown)Mapped from Vendor.status using conditional logic
Vendor.severityevent.severityNumeric severity level based on text severityMapped from Vendor.severity using conditional logic
Noneevent.type[]Event type classificationStatic array value: info
Vendor.auditUserIduser.idUser identifierCopied from Vendor.auditUserId
Vendor.auditUserNameuser.nameUsernameCopied from Vendor.auditUserName