Parsers and Generated Fields

Tag Fields Created by Parser zscaler-deception
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-deception
Vendor FieldCPS FieldDescription
Vendor.decoy.client.nameclient.addressDecoy client name
Vendor.network.orig_ip_bytesclient.bytes 
Vendor.network.orig_pktsclient.packets 
Vendor.network.durationevent.durationDuration of network event
Vendor.idevent.id 
Vendor.idevent.id, trace.idEvent identifier
Vendor.scoreevent.risk_scoreRisk score of event
Vendor.severityevent.severityEvent severity
Vendor.threat.alert.severityevent.severityAlert severity
Vendor.recon.bytes_senthttp.request.bytes 
Vendor.recon.methodhttp.request.method 
Vendor.web.methodhttp.request.methodHTTP request method
Vendor.recon.statushttp.response.status_code 
Vendor.web.statushttp.response.status_codeHTTP response status code
Vendor.decoy.network_namenetwork.nameNetwork name
Vendor.network.protocolnetwork.protocolNetwork protocol used
Vendor.recon.schemenetwork.protocol 
Vendor.decoy.appliance.nameobserver.nameAppliance name
Vendor.linux.command_lineprocess.command_lineLinux process command line
Vendor.linux.process_nameprocess.nameLinux process name
Vendor.linux.pidprocess.pidLinux process ID
Vendor.linux.userprocess.user.nameLinux username
Vendor.decoy.nameserver.addressDecoy server name
Vendor.recon.server_nameserver.address 
Vendor.network.resp_ip_bytesserver.bytes 
Vendor.decoy.ip;server.ip 
Vendor.network.resp_pktsserver.packets 
Vendor.decoy.portserver.port 
threat.indicator.ipsource.ip 
threat.indicator.portsource.port 
Vendor.abuseip.ipAddress;threat.indicator.ip 
Vendor.attacker.ipthreat.indicator.ipIP address extracted from format "x.x.x.x [hostname]"
Vendor.attacker.namethreat.indicator.nameName of attacker
Vendor.attacker.portthreat.indicator.portPort number of attacker
Vendor.typethreat.indicator.typeType of threat indicator
Vendor.mitre_idsthreat.technique.idMITRE ATT&CK technique IDs
Vendor.ssl.ciphertls.cipherSSL/TLS cipher used
Vendor.ssl.versiontls.versionSSL/TLS version
Vendor.idtrace.id 
Vendor.recon.hosturl.domain 
Vendor.web.hosturl.domainWeb host domain
Vendor.web.uriurl.fullFull URL
Vendor.recon.request_uriurl.path 
Vendor.recon.uriurl.path 
Vendor.web.request_uriurl.path 
Vendor.web.schemeurl.schemeURL scheme (http/https)
Vendor.recon.user_agent.stringuser_agent.name 
Vendor.web.user_agent.stringuser_agent.nameUser agent string
Vendor.recon.user_agent.patchuser_agent.version