Parsers and Generated Fields

Tag Fields Created by Parser zoom-qss
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zoom-qss
Vendor FieldCPS FieldDescription
eventevent.category[]Maps "session" if event contains "session", "network" if IP address present, else "session"
-event.kindStatic value "event"
-event.type[]Static value "info"
Vendor.payload.object.participant.pc_namehost.hostname 
payload.object.participant.pc_namehost.hostnamePC hostname
payload.object.participant.data.mac_addrhost.macMAC address of device
Vendor.participant.emailuser.email 
participant.emailuser.emailUser's email address
Vendor.participant_user_iduser.id 
Vendor.payload.object.user.iduser.id 
participant_user_iduser.idParticipant user ID
payload.object.user.iduser.idUser ID from payload
Vendor.payload.object.user.nameuser.name 
payload.object.user.nameuser.nameUsername from payload