Parsers and Generated Fields

Tag Fields Created by Parser tausight-ephi
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser tausight-ephi
Source FieldCPS FieldDescriptionMapping
Destination user name for clipboard activityVendor.clipboardActivity.destProcessInfo.userName destination.user.name
Process ID for clipboard activityVendor.clipboardActivity.srcProcessInfo.processId process.pid
Process executable for clipboard activityVendor.clipboardActivity.srcProcessInfo.processName process.executable
Source user name for clipboard activityVendor.clipboardActivity.srcProcessInfo.userName source.user.name
USB device ID when presentVendor.deviceAttached.usbDevice.deviceId device.id
USB device manufacturer when presentVendor.deviceAttached.usbDevice.manufacturer device.manufacturer
Email sender address (converted to lowercase)Vendor.email.sender email.from.address[]
File extension for copied filesVendor.fileCopied.destinationFileInfo.fileExtension file.extension
File group for copied filesVendor.fileCopied.destinationFileInfo.groupName file.group
File owner for copied filesVendor.fileCopied.destinationFileInfo.ownerName file.owner
Destination file path for copied filesVendor.fileCopied.destinationFilename file.path
File extension for deleted filesVendor.fileDeleted.fileInfo.fileExtension file.extension
File group for deleted filesVendor.fileDeleted.fileInfo.groupName file.group
File owner for deleted filesVendor.fileDeleted.fileInfo.ownerName file.owner
File path for deleted filesVendor.fileDeleted.filename file.path
File extension for inspected filesVendor.fileInspected.fileInfo.fileExtension file.extension
File size for inspected filesVendor.fileInspected.fileInfo.fileSize file.size
File group for inspected filesVendor.fileInspected.fileInfo.groupName file.group
File owner for inspected filesVendor.fileInspected.fileInfo.ownerName file.owner
File path for inspected filesVendor.fileInspected.filename file.path
File extension for opened filesVendor.fileIoActivity.fileOpened.fileExtension file.extension
File path for opened filesVendor.fileIoActivity.fileOpened.filename file.path
Process ID for file I/O activityVendor.fileIoActivity.fileOpened.processInfo.processId process.pid
Process name for file I/O activityVendor.fileIoActivity.fileOpened.processInfo.processName process.name