Parsers and Generated Fields

Tag Fields Created by Parser trellix-fireeyenx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser trellix-fireeyenx
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayNone
`host.ip[]`ArrayVendor.dvc
`host.mac[]`ArrayVendor.dvcmac
`destination.address`CopiedVendor.dst (indirect)
`destination.ip`CopiedVendor.dst
`destination.port`CopiedVendor.dpt
`event.action`CopiedVendor.act
`host.name`CopiedVendor.dvchost
`source.address`CopiedVendor.src (indirect)
`source.ip`CopiedVendor.src
`source.port`CopiedVendor.spt
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`destination.mac`TransformedVendor.dmac
`source.mac`TransformedVendor.smac
destination.ipdestination.address 
Vendor.dstdestination.ip 
Vendor.dptdestination.port 
Vendor.actevent.action 
Vendor.dvchosthost.name 
source.ipsource.address 
Vendor.srcsource.ip 
Vendor.sptsource.port