Parsers and Generated Fields

Tag Fields Created by Parser trellix-fireeyenx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser trellix-fireeyenx
Vendor FieldCPS FieldDescription
Vendor.dstdestination.addressDestination address (same as IP)
destination.ipdestination.address 
Vendor.dstdestination.ipDestination IP address
Vendor.dmacdestination.macDestination MAC address (formatted with dashes and uppercase)
Vendor.dptdestination.portDestination port number
Vendor.actevent.actionDirect mapping of action field
Vendor.dvchost.ip[0]Device IP address (array format)
Vendor.dvcmachost.mac[0]Device MAC address (formatted with dashes and uppercase)
Vendor.dvchosthost.nameDevice hostname
Vendor.srcsource.addressSource address (same as IP)
source.ipsource.address 
Vendor.srcsource.ipSource IP address
Vendor.smacsource.macSource MAC address (formatted with dashes and uppercase)
Vendor.sptsource.portSource port number