Parsers and Generated Fields

Tag Fields Created by Parser deception
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser deception
Source FieldCPS Field
Vendor.idevent.id
Vendor.scoreevent.risk_score
Vendor.web.methodhttp.request.method
Vendor.web.statushttp.response.status_code
Vendor.network.protocolnetwork.protocol
Vendor.linux.command_lineprocess.command_line
Vendor.linux.process_nameprocess.name
Vendor.linux.pidprocess.pid
Vendor.linux.userprocess.user.name
threat.indicator.ipsource.ip
threat.indicator.portsource.port
Vendor.attacker.namethreat.indicator.name
Vendor.attacker.portthreat.indicator.port
Vendor.typethreat.indicator.type
Vendor.ssl.ciphertls.cipher
Vendor.ssl.versiontls.version
Vendor.web.hosturl.domain
Vendor.web.uriurl.full
Vendor.web.schemeurl.scheme
Vendor.web.user_agent.stringuser_agent.name
Tag Fields Created by Parser zscaler-deception
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-deception
Source FieldCPS Field
Vendor.idevent.id
Vendor.scoreevent.risk_score
Vendor.web.methodhttp.request.method
Vendor.web.statushttp.response.status_code
Vendor.network.protocolnetwork.protocol
Vendor.linux.command_lineprocess.command_line
Vendor.linux.process_nameprocess.name
Vendor.linux.pidprocess.pid
Vendor.linux.userprocess.user.name
threat.indicator.ipsource.ip
threat.indicator.portsource.port
Vendor.attacker.namethreat.indicator.name
Vendor.attacker.portthreat.indicator.port
Vendor.typethreat.indicator.type
Vendor.ssl.ciphertls.cipher
Vendor.ssl.versiontls.version
Vendor.web.hosturl.domain
Vendor.web.uriurl.full
Vendor.web.schemeurl.scheme
Vendor.web.user_agent.stringuser_agent.name