Parsers and Generated Fields

Tag Fields Created by Parser tausight-ephi
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser tausight-ephi
Vendor FieldCPS FieldDescription
Vendor.clipboardActivity.destProcessInfo.userNamedestination.user.nameDestination user for clipboard activity
Vendor.clipboardActivity.destProcessInfo.userNamedestination.user.name  
Vendor.deviceAttached.usbDevice.deviceIddevice.idUSB device identifier
Vendor.encryptionChanged.tauDeviceIddevice.idDevice ID for encryption changes
Vendor.deviceAttached.usbDevice.deviceIddevice.id  
Vendor.deviceAttached.usbDevice.manufacturerdevice.manufacturerUSB device manufacturer
Vendor.encryptionChanged.logicalDisk.driveInfo.manufacturerdevice.manufacturerDrive manufacturer for encryption changes
Vendor.deviceAttached.usbDevice.manufacturerdevice.manufacturer  
Vendor.encryptionChanged.logicalDisk.driveInfo.modeldevice.model.nameDrive model for encryption changes
Vendor.encryptionChanged.logicalDisk.driveInfo.serialNumberdevice.serial_numberDrive serial number for encryption changes
Vendor.sequenceNumberevent.sequence 
Vendor.fileCopied.destinationFileInfo.fileExtensionfile.extension  
Vendor.fileDeleted.fileInfo.fileExtensionfile.extension  
Vendor.fileInspected.fileInfo.fileExtensionfile.extension  
Vendor.fileIoActivity.fileOpened.fileExtensionfile.extension  
Vendor.fileCopied.destinationFileInfo.groupNamefile.group  
Vendor.fileDeleted.fileInfo.groupNamefile.group  
Vendor.fileInspected.fileInfo.groupNamefile.group  
Vendor.fileCopied.destinationFileInfo.ownerNamefile.owner  
Vendor.fileDeleted.fileInfo.ownerNamefile.owner  
Vendor.fileInspected.fileInfo.ownerNamefile.owner  
Vendor.fileCopied.destinationFilenamefile.path  
Vendor.fileDeleted.filenamefile.path  
Vendor.fileInspected.filenamefile.path  
Vendor.fileIoActivity.fileOpened.filenamefile.path  
Vendor.fileInspected.fileInfo.fileSizefile.size  
Vendor.deviceAttached.networkAdapter.ipAddresshost.ipNetwork adapter IP address
Vendor.deviceAttached.networkAdapter.macAddresshost.macNetwork adapter MAC address (formatted with hyphens)
Vendor.clipboardActivity.srcProcessInfo.processNameprocess.executable  
Vendor.fileIoActivity.fileOpened.processInfo.processNameprocess.name  
Vendor.clipboardActivity.srcProcessInfo.processIdprocess.pid  
Vendor.fileIoActivity.fileOpened.processInfo.processIdprocess.pid  
Vendor.clipboardActivity.srcProcessInfo.userNamesource.user.nameSource user for clipboard activity
Vendor.clipboardActivity.srcProcessInfo.userNamesource.user.name