Parsers and Generated Fields

Tag Fields Created by Parser zscaler-privateaccess
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-privateaccess
Vendor FieldCPS FieldDescription
LogTimestamp@timestampTimestamp parsing from log entry
TotalBytesRxclient.bytesTotal bytes received by client
Vendor.TotalBytesRxclient.bytes 
Vendor.TotalBytesTxclient.bytes 
Vendor.Cityclient.geo.city_name 
CountryCodeclient.geo.country_iso_codeClient's country code
Vendor.ClientCountryCodeclient.geo.country_iso_code 
Vendor.CountryCodeclient.geo.country_iso_code 
Latitudeclient.geo.location.latClient's latitude
Vendor.ClientLatitudeclient.geo.location.lat 
Vendor.Latitudeclient.geo.location.lat 
Longitudeclient.geo.location.lonClient's longitude
Vendor.ClientLongitudeclient.geo.location.lon 
Vendor.Longitudeclient.geo.location.lon 
PublicIPclient.ipClient's public IP address
Vendor.ClientPublicIPclient.ip 
Vendor.ClientPublicIpclient.ip 
Vendor.PublicIPclient.ip 
DefRouteGWclient.nat.ipDefault route gateway IP
Vendor.DefRouteGWclient.nat.ip 
Vendor.ClientPortclient.port 
Vendor.ClientPublicPortclient.port 
AuditOperationTypeevent.actionType of audit operation
Vendor.AuditOperationTypeevent.action 
RequestIDevent.idRequest identifier
Vendor.RequestIDevent.id 
InternalReasonevent.reasonReason for event outcome
Vendor.ConnectionReasonevent.reason 
Vendor.InternalReasonevent.reason 
Vendor.AuditNewValue.idgroup.id 
Vendor.AuditOldValue.idgroup.id 
Vendor.AuditNewValue.namegroup.name 
Vendor.AuditOldValue.namegroup.name 
CPUUtilizationhost.cpu.usageCPU utilization percentage
Vendor.CPUUtilizationhost.cpu.usage 
Hostnamehost.hostnameSystem hostname
Platformhost.os.platformOperating system platform
Vendor.Platformhost.os.platform 
RequestSizehttp.request.body.bytesSize of HTTP request body
Vendor.RequestBodySizehttp.request.body.bytes 
Vendor.RequestSizehttp.request.body.bytes 
Methodhttp.request.methodHTTP request method
Vendor.Methodhttp.request.method 
ResponseSizehttp.response.body.bytesSize of HTTP response body
Vendor.ResponseBodySizehttp.response.body.bytes 
Vendor.ResponseSizehttp.response.body.bytes 
StatusCodehttp.response.status_codeHTTP response status code
Vendor.StatusCodehttp.response.status_code 
Vendor.ProtocolVersionhttp.version 
Vendor.TotalBytesProcessednetwork.bytes 
Vendor.TotalBytesTxnetwork.bytes 
Protocolnetwork.protocolNetwork protocol used
Vendor.AuditNewValue.cityCountryobserver.geo.city_name 
Vendor.AuditOldValue.cityCountryobserver.geo.city_name 
Latitudeobserver.geo.location.latObserver latitude
Vendor.AuditNewValue.latitudeobserver.geo.location.lat 
Vendor.AuditOldValue.latitudeobserver.geo.location.lat 
Vendor.Latitudeobserver.geo.location.lat 
Longitudeobserver.geo.location.lonObserver longitude
Vendor.AuditNewValue.longitudeobserver.geo.location.lon 
Vendor.AuditOldValue.longitudeobserver.geo.location.lon 
Vendor.Longitudeobserver.geo.location.lon 
PrivateIPobserver.ip[]Observer private IP address
PublicIPobserver.ip[]Observer public IP address
Platformobserver.os.platformObserver operating system platform
Vendor.Platformobserver.os.platform 
CustomerIDorganization.idCustomer organization ID
Vendor.CustomerIDorganization.id 
Customerorganization.nameCustomer organization name
Vendor.Customerorganization.name 
Vendor.Versionpackage.version 
Versionpackage.versionSoftware version
Hostserver.addressServer hostname/address
Vendor.AuditNewValue.domainOrIpAddressserver.address 
Vendor.AuditOldValue.domainOrIpAddressserver.address 
TotalBytesTxserver.bytesTotal bytes transmitted by server
Vendor.TotalBytesTxserver.bytes 
Vendor.ZENCountryCodeserver.geo.country_iso_code 
Vendor.ZENLatitudeserver.geo.location.lat 
Vendor.ZENLongitudeserver.geo.location.lon 
ServerIPserver.ipServer IP address
Vendor.ServerIPserver.ip 
ServerPortserver.portServer port number
Vendor.ApplicationPortserver.port 
Vendor.ServerPortserver.port 
CertificateCNtls.client.x509.issuer.common_name[]Certificate common name
Vendor.AuditNewValue.expirationTimeInSecondstls.client.x509.not_after 
Vendor.AuditOldValue.expirationTimeInSecondstls.client.x509.not_after 
Vendor.AuditNewValue.creationTimeInSecondstls.client.x509.not_before 
Vendor.AuditOldValue.creationTimeInSecondstls.client.x509.not_before 
ModifiedByuser.idUser ID who modified the resource
Vendor.ModifiedByuser.id 
Useruser.nameUsername who performed the action
Usernameuser.nameUser associated with the event
Vendor.NameIDuser.name 
Vendor.Useruser.name 
Vendor.Usernameuser.name 
AuditNewValue.emailuser.target.emailTarget user email address
Vendor.AuditNewValue.emailuser.target.email 
Vendor.AuditOldValue.emailuser.target.email 
Vendor.AuditNewValue.iduser.target.id 
Vendor.AuditOldValue.iduser.target.id 
AuditNewValue.roles[].nameuser.target.roles[]Target user roles
UserAgentuser_agent.originalUser agent string
Vendor.UserAgentuser_agent.original