Parsers and Generated Fields

Tag Fields Created by Parser zoom-qss
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zoom-qss
Source FieldCPS FieldDescriptionMapping
Static value event- event.kind
Maps session if event contains session, network if IP address present, else sessionevent event.category[]
User's email addressparticipant.email user.email
Participant user IDparticipant_user_id user.id
MAC address of devicepayload.object.participant.data.mac_addr host.mac
PC hostnamepayload.object.participant.pc_name host.hostname
User ID from payloadpayload.object.user.id user.id
Username from payloadpayload.object.user.name user.name