Parsers and Generated Fields

Tag Fields Created by Parser zscaler-internetaccess
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-internetaccess
Source FieldLogScale Repository Field
Vendor.cltclient.port
Vendor.statuscode
Vendor.inbytesdestination.bytes
Vendor.rxbytesdestination.bytes
Vendor.destinationipdestination.ip
Vendor.sdipdestination.ip
Vendor.serveripdestination.ip
Vendor.srvdestination.ip
Vendor.destinationportdestination.port
Vendor.sdportdestination.port
Vendor.srvdestination.port
Vendor.dnsdns.answers.name
Vendor.dnsdns.question.name
Vendor.dnsdns.question.type
Vendor.actionevent.action
Vendor.actiontakenevent.action
Vendor.eventevent.action
Vendor.recordidevent.id
Vendor.eventreasonevent.reason
Vendor.reasonevent.reason
Vendor.filesourcefile.directory
Vendor.filesubtypefile.extension
Vendor.filetypenamefile.extension
Vendor.filenamefile.name
Vendor.ownerfile.owner
Vendor.filetypefile.type
Vendor.companygroup.name
Vendor.requestsizehttp.request.bytes
Vendor.requestmethodhttp.request.method
Vendor.refererURLhttp.request.referrer
Vendor.responsesizehttp.response.bytes
Vendor.destcountryname
Vendor.policyrule.name
Vendor.rulelabelrule.name
Vendor.rulenamerule.name
Vendor.ruletyperule.ruleset
Vendor.riskscorescore
Vendor.outbytessource.bytes
Vendor.txbytessource.bytes
Vendor.locationsource.geo.name
Vendor.ClientIPsource.ip
Vendor.clientipsource.ip
Vendor.cltsource.ip
Vendor.csipsource.ip
Vendor.sourceipsource.ip
Vendor.ClientIPsource.nat.ip
Vendor.csportsource.port
Vendor.sourceportsource.port
Vendor.contenttypetype
Vendor.fullurlurl.full
Vendor.urlurl.original
Vendor.adminiduser.email
Vendor.eloginuser.email
Vendor.loginuser.email
Vendor.useruser.email
Vendor.eloginuser.name
Vendor.useruser.name