Parsers and Generated Fields

Tag Fields Created by Parser zscaler-internetaccess
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-internetaccess
Vendor FieldCPS FieldDescription
message@rawstring  
`dns.answers[]`ArrayVendor.dns_resp
`event.category[]`ArrayVendor.sourcetype
`event.type[]`ArrayVendor.sourcetype, Vendor.action, Vendor.threatname
`http.request.referrer`Base64Vendor.refererURL
`url.original`Base64Vendor.url
`client.port`CopiedVendor.clt_sport
`destination.domain`CopiedVendor.hostname
`destination.geo.country_name`CopiedVendor.destcountry
`dns.question.name`CopiedVendor.dns_req
`dns.question.type`CopiedVendor.dns_reqtype
`event.action`CopiedVendor.action
`event.id`CopiedVendor.recordid
`event.reason`CopiedVendor.reason
`event.risk_score`CopiedVendor.riskscore
`file.directory`CopiedVendor.filesource
`file.hash.md5`CopiedVendor.bamd5, Vendor.filemd5
`file.name`CopiedVendor.filename
`file.owner`CopiedVendor.owner
`file.type`CopiedVendor.filetype
`group.name`CopiedVendor.company
`host.hostname`CopiedVendor.devicehostname
`host.name`CopiedVendor.devicehostname
`http.request.bytes`CopiedVendor.requestsize
`http.request.method`CopiedVendor.requestmethod
`http.request.mime_type`CopiedVendor.contenttype
`http.response.bytes`CopiedVendor.responsesize
`http.response.status_code`CopiedVendor.status
`network.application`CopiedVendor.nwapp
`network.transport`CopiedVendor.proto
`network.type`CopiedVendor.tunneltype
`rule.ruleset`CopiedVendor.ruletype
`source.geo.name`CopiedVendor.location
`url.domain`CopiedVendor.hostname
`url.full`CopiedVendor.fullurl
`url.path`ExtractedVendor.url
`user.domain`ExtractedVendor.user, Vendor.elogin, Vendor.login, Vendor.adminid
`user.name`ExtractedVendor.user, Vendor.elogin, Vendor.login, Vendor.adminid
`destination.bytes`MappedVendor.inbytes, Vendor.rxbytes
`destination.ip`MappedVendor.srv_dip, Vendor.sdip, Vendor.serverip, Vendor.destinationip
`destination.port`MappedVendor.srv_dport, Vendor.sdport, Vendor.destinationport
`event.severity`MappedVendor.severity
`file.extension`MappedVendor.filesubtype, Vendor.filetypename
`network.protocol`MappedVendor.protocol, Vendor.nwsvc
`rule.name`MappedVendor.rulelabel, Vendor.rulename, Vendor.policy, Vendor.threatname
`source.bytes`MappedVendor.outbytes, Vendor.txbytes
`source.ip`MappedVendor.clt_sip, Vendor.csip, Vendor.ClientIP, Vendor.sourceip, Vendor.clientip
`source.port`MappedVendor.csport, Vendor.sourceport, Vendor.clt_sport
`@timestamp`ParsedVendor.datetime, Vendor.time
`file.mtime`ParsedVendor.lastmodtime
`event.original.hash.sha256`SHA256@rawstring
`event.dataset`SetVendor.sourcetype
`event.original`Set@rawstring
`event.outcome`SetVendor.result
`network.direction`SetVendor.policydirection
`source.nat.ip`SetVendor.ClientIP, Vendor.clientpublicIP
`user.email`SetVendor.user, Vendor.elogin, Vendor.login, Vendor.adminid
`ecs.version`StaticNone
`event.kind`StaticVendor.threatname
`event.module`StaticNone
`user_agent.original`URLVendor.useragent
Vendor.clt_sportclient.port 
Vendor.inbytesdestination.bytes 
Vendor.rxbytesdestination.bytes 
Vendor.destcountrydestination.geo.country_name 
Vendor.destinationipdestination.ip 
Vendor.sdipdestination.ip 
Vendor.serveripdestination.ip 
Vendor.srv_dipdestination.ip 
Vendor.destinationportdestination.port 
Vendor.sdportdestination.port 
Vendor.srv_dportdestination.port 
Vendor.dns_reqdns.question.name 
Vendor.dns_reqtypedns.question.type 
Vendor.actionevent.action 
Vendor.actiontakenevent.action 
Vendor.eventevent.action 
Vendor.recordidevent.id 
Vendor.eventreasonevent.reason 
Vendor.reasonevent.reason 
Vendor.riskscoreevent.risk_score 
Vendor.filesourcefile.directory 
Vendor.filesubtypefile.extension 
Vendor.filetypenamefile.extension 
Vendor.filenamefile.name 
Vendor.ownerfile.owner 
Vendor.filetypefile.type 
Vendor.companygroup.name 
Vendor.requestsizehttp.request.bytes 
Vendor.requestmethodhttp.request.method 
Vendor.contenttypehttp.request.mime_type 
Vendor.refererURLhttp.request.referrer 
Vendor.responsesizehttp.response.bytes 
Vendor.statushttp.response.status_code 
Vendor.nwappnetwork.application 
Vendor.policyrule.name 
Vendor.rulelabelrule.name 
Vendor.rulenamerule.name 
Vendor.threatnamerule.name 
Vendor.ruletyperule.ruleset 
Vendor.outbytessource.bytes 
Vendor.txbytessource.bytes 
Vendor.locationsource.geo.name 
Vendor.ClientIPsource.ip 
Vendor.clientipsource.ip 
Vendor.clt_sipsource.ip 
Vendor.csipsource.ip 
Vendor.sourceipsource.ip 
Vendor.csportsource.port 
Vendor.sourceportsource.port 
Vendor.hostnameurl.domain 
Vendor.fullurlurl.full 
Vendor.urlurl.original