Parsers and Generated Fields
Tag Fields Created by Parser rubrik-securitycloud
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser rubrik-securitycloud
Vendor Field | CPS Field | Description |
---|---|---|
Vendor.errorCode | error.code | |
errorCode | error.code | Error code when errorId exists |
Vendor.errorId | error.id | |
errorId | error.id | Error identifier when present |
Vendor.errorReason | error.message | |
errorReason | error.message | Error message when errorId exists |
Vendor.eventName | event.action | |
eventName | event.action | Name of the event action |
Vendor.id | event.id | |
id | event.id | Event identifier |
status | event.outcome | Status mapping: success->success, fail->failure, others->unknown |
severity | event.severity | Severity mapping: info/low->10, warning->30, medium->50, high->70, critical->90 |
Vendor.auditUserId | user.id | |
auditUserId | user.id | User identifier |
Vendor.auditUserName | user.name | |
auditUserName | user.name | Username |