Parsers and Generated Fields

Tag Fields Created by Parser tausight-ephi
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser tausight-ephi
Vendor FieldCPS FieldDescription
Vendor.clipboardActivity.destProcessInfo.userNamedestination.user.nameDestination user name for clipboard activity
Vendor.deviceAttached.usbDevice.deviceIddevice.idUSB device ID when present
Vendor.encryptionChanged.tauDeviceIddevice.id 
Vendor.deviceAttached.usbDevice.manufacturerdevice.manufacturerUSB device manufacturer when present
Vendor.encryptionChanged.logicalDisk.driveInfo.manufacturerdevice.manufacturer 
Vendor.encryptionChanged.logicalDisk.driveInfo.modeldevice.model.name 
Vendor.encryptionChanged.logicalDisk.driveInfo.serialNumberdevice.serial_number 
Vendor.email.senderemail.from.address[]Email sender address (converted to lowercase)
Vendor.sequenceNumberevent.sequence 
Vendor.fileCopied.destinationFileInfo.fileExtensionfile.extensionFile extension for copied files
Vendor.fileDeleted.fileInfo.fileExtensionfile.extensionFile extension for deleted files
Vendor.fileInspected.fileInfo.fileExtensionfile.extensionFile extension for inspected files
Vendor.fileIoActivity.fileOpened.fileExtensionfile.extensionFile extension for opened files
Vendor.fileCopied.destinationFileInfo.groupNamefile.groupFile group for copied files
Vendor.fileDeleted.fileInfo.groupNamefile.groupFile group for deleted files
Vendor.fileInspected.fileInfo.groupNamefile.groupFile group for inspected files
Vendor.fileCopied.destinationFileInfo.ownerNamefile.ownerFile owner for copied files
Vendor.fileDeleted.fileInfo.ownerNamefile.ownerFile owner for deleted files
Vendor.fileInspected.fileInfo.ownerNamefile.ownerFile owner for inspected files
Vendor.fileCopied.destinationFilenamefile.pathDestination file path for copied files
Vendor.fileDeleted.filenamefile.pathFile path for deleted files
Vendor.fileInspected.filenamefile.pathFile path for inspected files
Vendor.fileIoActivity.fileOpened.filenamefile.pathFile path for opened files
Vendor.fileInspected.fileInfo.fileSizefile.sizeFile size for inspected files
Vendor.clipboardActivity.srcProcessInfo.processNameprocess.executableProcess executable for clipboard activity
Vendor.fileIoActivity.fileOpened.processInfo.processNameprocess.nameProcess name for file I/O activity
Vendor.clipboardActivity.srcProcessInfo.processIdprocess.pidProcess ID for clipboard activity
Vendor.fileIoActivity.fileOpened.processInfo.processIdprocess.pidProcess ID for file I/O activity
Vendor.clipboardActivity.srcProcessInfo.userNamesource.user.nameSource user name for clipboard activity