Parsers and Generated Fields

Tag Fields Created by Parser fireeye-nx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fireeye-nx
Source FieldLogScale Repository Field
destination.ipdestination.address
Vendor.dstdestination.ip
Vendor.dptdestination.port
Vendor.actevent.action
Vendor.dvchost.ip[0]
Vendor.dvchosthost.name
source.ipsource.address
Vendor.srcsource.ip
Vendor.sptsource.port