Parsers and Generated Fields

Tag Fields Created by Parser rubrik-securitycloud
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser rubrik-securitycloud
Source FieldCPS FieldDescriptionMapping
User identifierauditUserId user.id
UsernameauditUserName user.name
Error code when errorId existserrorCode error.code
Error identifier when presenterrorId error.id
Error message when errorId existserrorReason error.message
Name of the event actioneventName event.action
Event identifierid event.id
Severity mapping: info/low->10, warning->30, medium->50, high->70, critical->90severity event.severity
Status mapping: success->success, fail->failure, others->unknownstatus event.outcome