Parsers and Generated Fields

Tag Fields Created by Parser fireeye-nx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fireeye-nx
Vendor FieldCPS FieldDescription
destination.ipdestination.address 
Vendor.dstdestination.ip 
Vendor.dptdestination.port 
Vendor.actevent.action 
Vendor.dvchost.ip[0] 
Vendor.dvchosthost.name 
source.ipsource.address 
Vendor.srcsource.ip 
Vendor.sptsource.port 
Tag Fields Created by Parser trellix-fireeyenx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser trellix-fireeyenx
Vendor FieldCPS FieldDescription
destination.ipdestination.address 
Vendor.dstdestination.ip  
Vendor.dptdestination.port  
Vendor.actevent.action  
Vendor.dvchosthost.name  
source.ipsource.address 
Vendor.srcsource.ip  
Vendor.sptsource.port