Parsers and Generated Fields
Tag Fields Created by Parser tausight-ephi
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser tausight-ephi
| Source Field | CPS Field | Description | Mapping |
|---|---|---|---|
| Destination user name for clipboard activity | Vendor.clipboardActivity.destProcessInfo.userName | Â | destination.user.name |
| Process ID for clipboard activity | Vendor.clipboardActivity.srcProcessInfo.processId | Â | process.pid |
| Process executable for clipboard activity | Vendor.clipboardActivity.srcProcessInfo.processName | Â | process.executable |
| Source user name for clipboard activity | Vendor.clipboardActivity.srcProcessInfo.userName | Â | source.user.name |
| USB device ID when present | Vendor.deviceAttached.usbDevice.deviceId | Â | device.id |
| USB device manufacturer when present | Vendor.deviceAttached.usbDevice.manufacturer | Â | device.manufacturer |
| Email sender address (converted to lowercase) | Vendor.email.sender | Â | email.from.address[] |
| File extension for copied files | Vendor.fileCopied.destinationFileInfo.fileExtension | Â | file.extension |
| File group for copied files | Vendor.fileCopied.destinationFileInfo.groupName | Â | file.group |
| File owner for copied files | Vendor.fileCopied.destinationFileInfo.ownerName | Â | file.owner |
| Destination file path for copied files | Vendor.fileCopied.destinationFilename | Â | file.path |
| File extension for deleted files | Vendor.fileDeleted.fileInfo.fileExtension | Â | file.extension |
| File group for deleted files | Vendor.fileDeleted.fileInfo.groupName | Â | file.group |
| File owner for deleted files | Vendor.fileDeleted.fileInfo.ownerName | Â | file.owner |
| File path for deleted files | Vendor.fileDeleted.filename | Â | file.path |
| File extension for inspected files | Vendor.fileInspected.fileInfo.fileExtension | Â | file.extension |
| File size for inspected files | Vendor.fileInspected.fileInfo.fileSize | Â | file.size |
| File group for inspected files | Vendor.fileInspected.fileInfo.groupName | Â | file.group |
| File owner for inspected files | Vendor.fileInspected.fileInfo.ownerName | Â | file.owner |
| File path for inspected files | Vendor.fileInspected.filename | Â | file.path |
| File extension for opened files | Vendor.fileIoActivity.fileOpened.fileExtension | Â | file.extension |
| File path for opened files | Vendor.fileIoActivity.fileOpened.filename | Â | file.path |
| Process ID for file I/O activity | Vendor.fileIoActivity.fileOpened.processInfo.processId | Â | process.pid |
| Process name for file I/O activity | Vendor.fileIoActivity.fileOpened.processInfo.processName | Â | process.name |