Parsers and Generated Fields

Tag Fields Created by Parser deception
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser deception
Source FieldLogScale Repository Field
Vendor.web.useragent.name
Vendor.web.statuscode
Vendor.idevent.id
Vendor.web.methodhttp.request.method
Vendor.linux.commandline
Vendor.network.protocolnetwork.protocol
Vendor.linux.processprocess.name
Vendor.linux.pidprocess.pid
Vendor.linux.userprocess.user.name
Vendor.scorescore
threat.indicator.ipsource.ip
threat.indicator.portsource.port
Vendor.attacker.namethreat.indicator.name
Vendor.attacker.portthreat.indicator.port
Vendor.typethreat.indicator.type
Vendor.ssl.ciphertls.cipher
Vendor.ssl.versiontls.version
Vendor.web.hosturl.domain
Vendor.web.uriurl.full
Vendor.web.schemeurl.scheme