Parsers and Generated Fields

Tag Fields Created by Parser tausight-ephi
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser tausight-ephi
Source FieldCPS Field
Vendor.clipboardActivity.destProcessInfo.userNamedestination.user.name
Vendor.deviceAttached.usbDevice.deviceIddevice.id
Vendor.deviceAttached.usbDevice.manufacturerdevice.manufacturer
Vendor.fileCopied.destinationFileInfo.fileExtensionfile.extension
Vendor.fileDeleted.fileInfo.fileExtensionfile.extension
Vendor.fileInspected.fileInfo.fileExtensionfile.extension
Vendor.fileIoActivity.fileOpened.fileExtensionfile.extension
Vendor.fileCopied.destinationFileInfo.groupNamefile.group
Vendor.fileDeleted.fileInfo.groupNamefile.group
Vendor.fileInspected.fileInfo.groupNamefile.group
Vendor.fileCopied.destinationFileInfo.ownerNamefile.owner
Vendor.fileDeleted.fileInfo.ownerNamefile.owner
Vendor.fileInspected.fileInfo.ownerNamefile.owner
Vendor.fileCopied.destinationFilenamefile.path
Vendor.fileDeleted.filenamefile.path
Vendor.fileInspected.filenamefile.path
Vendor.fileIoActivity.fileOpened.filenamefile.path
Vendor.fileInspected.fileInfo.fileSizefile.size
Vendor.clipboardActivity.srcProcessInfo.processNameprocess.executable
Vendor.fileIoActivity.fileOpened.processInfo.processNameprocess.name
Vendor.clipboardActivity.srcProcessInfo.processIdprocess.pid
Vendor.fileIoActivity.fileOpened.processInfo.processIdprocess.pid
Vendor.clipboardActivity.srcProcessInfo.userNamesource.user.name
Tag Fields Created by Parser tausight-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser tausight-json
Source FieldCPS Field
Vendor.clipboardActivity.destProcessInfo.userNamedestination.user.name
Vendor.deviceAttached.usbDevice.deviceIddevice.id
Vendor.deviceAttached.usbDevice.manufacturerdevice.manufacturer
Vendor.fileCopied.destinationFileInfo.fileExtensionfile.extension
Vendor.fileDeleted.fileInfo.fileExtensionfile.extension
Vendor.fileInspected.fileInfo.fileExtensionfile.extension
Vendor.fileIoActivity.fileOpened.fileExtensionfile.extension
Vendor.fileCopied.destinationFileInfo.groupNamefile.group
Vendor.fileDeleted.fileInfo.groupNamefile.group
Vendor.fileInspected.fileInfo.groupNamefile.group
Vendor.fileCopied.sourceFileInfo.fileExtensionfile.old.extension
Vendor.fileCopied.sourceFileInfo.groupNamefile.old.group
Vendor.fileCopied.sourceFileInfo.ownerNamefile.old.owner
Vendor.fileCopied.sourceFilenamefile.old.path
Vendor.fileCopied.destinationFileInfo.ownerNamefile.owner
Vendor.fileDeleted.fileInfo.ownerNamefile.owner
Vendor.fileInspected.fileInfo.ownerNamefile.owner
Vendor.fileCopied.destinationFilenamefile.path
Vendor.fileDeleted.filenamefile.path
Vendor.fileInspected.filenamefile.path
Vendor.fileIoActivity.fileOpened.filenamefile.path
Vendor.fileInspected.fileInfo.fileSizefile.size
Vendor.clipboardActivity.srcProcessInfo.processNameprocess.executable
Vendor.fileIoActivity.fileOpened.processInfo.processIdprocess.id
Vendor.fileIoActivity.fileOpened.processInfo.processNameprocess.name
Vendor.clipboardActivity.srcProcessInfo.processIdprocess.pid
Vendor.clipboardActivity.srcProcessInfo.userNamesource.user.name