Parsers and Generated Fields

Tag Fields Created by Parser veeam-veeamdataplatform
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser veeam-veeamdataplatform
Source FieldCPS FieldDescriptionMapping
ts@timestampEvent timestampParsed from ts field using parseTimestamp()
Noneecs.versionECS schema versionStatic value: 9.2.0
Vendor.Operationevent.actionAction performed in the eventDirect assignment from Vendor.Operation
event.idevent.category[]Event categorizationArray populated based on event.id conditions
Vendor.instanceId, Vendor.predefined_alarm_idevent.idUnique event identifierConditional assignment from Vendor.instanceId or Vendor.predefined_alarm_id
Vendor.predefined_alarm_idevent.kindEvent kind classificationConditional assignment based on Vendor.predefined_alarm_id presence
Vendor.predefined_alarm_idevent.moduleSource moduleConditional assignment: vbr or veeamone
Vendor.JobResultCodeevent.outcomeEvent outcome statusMapped from Vendor.JobResultCode values
Vendor.Severityevent.severityEvent severity levelMapped from Vendor.Severity values
Noneevent.type[]Event type classificationArray with static value: info
Vendor.VbrHostName, log.syslog.hostnamehost.nameHost nameConditional assignment from Vendor.VbrHostName or log.syslog.hostname
@rawstringlog.syslog.appnameSyslog application nameExtracted from syslog header using regex
@rawstringlog.syslog.hostnameSyslog hostnameExtracted from syslog header using regex
@rawstringlog.syslog.msgidSyslog message IDExtracted from syslog header using regex
@rawstringlog.syslog.prioritySyslog priorityExtracted from syslog header using regex
@rawstringlog.syslog.procidSyslog process IDExtracted from syslog header using regex
@rawstringlog.syslog.structured_dataSyslog structured dataExtracted from syslog header using regex
@rawstringlog.syslog.versionSyslog versionExtracted from syslog header using regex
Vendor.Description, Vendor.alarm_detailsmessageEvent messageConditional assignment from Vendor.Description or Vendor.alarm_details
Noneobserver.typeObserver typeStatic value: dataprotection
Vendor.FullUserNameuser.domainUser domainExtracted from Vendor.FullUserName using regex
Vendor.FullUserNameuser.nameUsernameExtracted from Vendor.FullUserName using regex or direct assignment