Parsers and Generated Fields

Tag Fields Created by Parser zscaler-deception
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-deception
Vendor FieldCPS FieldDescription
Vendor.decoy.client.nameclient.addressDecoy client name
Vendor.network.orig_ip_bytesclient.bytes 
Vendor.network.orig_pktsclient.packets 
Vendor.network.durationevent.durationDuration of network event
Vendor.idevent.id 
Vendor.idevent.id,Event identifier
Vendor.descriptionevent.reasonDescription of the event
Vendor.scoreevent.risk_scoreRisk score of event
Vendor.recon.bytes_senthttp.request.bytes 
Vendor.recon.method,http.request.methodHTTP request method using coalesce function
Vendor.web.status,http.response.status_codeHTTP response status code using coalesce function
Vendor.severity,log.levelEvent severity level
Vendor.decoy.network_namenetwork.nameNetwork name
Vendor.network.protocolnetwork.protocolNetwork protocol used
Vendor.recon.schemenetwork.protocol 
Vendor.decoy.appliance.nameobserver.nameAppliance name
Vendor.linux.command_lineprocess.command_lineLinux process command line
Vendor.linux.process_nameprocess.nameLinux process name
Vendor.linux.pidprocess.pidLinux process ID
Vendor.linux.userprocess.user.nameLinux username
Vendor.decoy.name,server.addressDecoy server name using coalesce function
Vendor.network.resp_ip_bytesserver.bytes 
Vendor.decoy.ip;server.ip 
Vendor.network.resp_pktsserver.packets 
Vendor.decoy.portserver.port 
threat.indicator.ipsource.ip 
threat.indicator.portsource.port 
Vendor.abuseip.ipAddress;threat.indicator.ip 
Vendor.attacker.ipthreat.indicator.ipIP address extracted from format "x.x.x.x [hostname]"
Vendor.attacker.namethreat.indicator.nameName of attacker
Vendor.attacker.portthreat.indicator.portPort number of attacker
Vendor.typethreat.indicator.typeType of threat indicator
Vendor.mitre_idsthreat.technique.id MITRE ATT&CK technique IDs
Vendor.ssl.ciphertls.cipherSSL/TLS cipher used
Vendor.ssl.versiontls.versionSSL/TLS version
Vendor.idtrace.id 
Vendor.recon.host,url.domainWeb host domain using coalesce function
Vendor.web.uriurl.fullFull URL
Vendor.web.schemeurl.schemeURL scheme (http/https)
Vendor.usernameuser.full_name,Extracts both full name and username when in format "Name (username)"
Vendor.usernameuser.nameUsername when not "Unauthenticated"
Vendor.username;user.name 
Vendor.web.user_agent.string,user_agent.nameUser agent string using coalesce function
Vendor.recon.user_agent.patchuser_agent.version