Parsers and Generated Fields

Tag Fields Created by Parser zscaler-privateaccess
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-privateaccess
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayNone
`host.ip[]`ArrayVendor.PublicIP, Vendor.PrivateIP
`observer.ip[]`ArrayVendor.PublicIP
`tls.client.x509.alternative_names[]`ArrayVendor.AuditNewValue.subjectAlternateNames, Vendor.AuditOldValue.subjectAlternateNames
`tls.client.x509.issuer.common_name[]`ArrayVendor.AuditNewValue.commonName, Vendor.AuditOldValue.commonName
`tls.client.x509.subject.common_name[]`ArrayVendor.CertificateCN
`user.target.roles[]`ArrayVendor.AuditNewValue.roles[], Vendor.AuditOldValue.roles[]
`host.network.egress.bytes`CalculatedVendor.TotalBytesTx, Vendor.TransmittedBytesToPublicSE, Vendor.TransmittedBytesToPrivateSE, Vendor.BytesTxInterface
`host.network.ingress.bytes`CalculatedVendor.TotalBytesRx, Vendor.ReceivedBytesFromPublicSE, Vendor.ReceivedBytesFromPrivateSE, Vendor.BytesRxInterface
`http.request.bytes`CalculatedVendor.RequestHdrSize, Vendor.RequestBodySize, Vendor.RequestSize
`http.response.bytes`CalculatedVendor.ResponseHdrSize, Vendor.ResponseBodySize, Vendor.ResponseSize
`network.bytes`CalculatedMultiple vendor byte fields
`client.address`Copiedsource.address
`client.bytes`CopiedVendor.TotalBytesTx, Vendor.ZENTotalBytesTxClient
`client.domain`Copiedsource.domain
`client.geo.city_name`CopiedVendor.City
`client.geo.country_iso_code`CopiedVendor.CountryCode, Vendor.ClientCountryCode
`client.geo.location.lat`CopiedVendor.Latitude, Vendor.ClientLatitude
`client.geo.location.lon`CopiedVendor.Longitude, Vendor.ClientLongitude
`client.ip`Copiedsource.ip
`client.nat.ip`CopiedVendor.ClientPrivateIp
`client.port`CopiedVendor.ClientPort, Vendor.ClientPublicPort
`destination.bytes`CopiedVendor.ZENTotalBytesRxClient
`destination.port`CopiedVendor.ServerPort, Vendor.ApplicationPort
`event.action`CopiedVendor.AuditOperationType
`event.created`CopiedVendor.CreationTime
`event.end`CopiedVendor.TimestampUnAuthentication, Vendor.TimestampResponseTransmitFinish, Vendor.TimestampConnectionEnd
`event.id`CopiedVendor.RequestID
`event.original`CopiedVendor.AuditOldValue
`event.reason`CopiedVendor.InternalReason, Vendor.ConnectionReason
`event.start`CopiedVendor.TimestampAuthentication, Vendor.TimestampRequestReceiveStart, Vendor.TimestampConnectionStart
`group.id`CopiedVendor.AuditNewValue.id, Vendor.AuditOldValue.id
`group.name`CopiedVendor.AuditNewValue.name, Vendor.AuditOldValue.name
`host.cpu.usage`CopiedVendor.CPUUtilization
`host.geo.country_iso_code`CopiedVendor.CountryCode
`host.geo.location.lat`CopiedVendor.Latitude
`host.geo.location.lon`CopiedVendor.Longitude
`host.hostname`CopiedVendor.Hostname
`host.name`CopiedVendor.Connector, Vendor.PrivateCloudController, Vendor.ServiceEdge, Vendor.PrivateSE
`host.network.egress.packets`CopiedVendor.PacketsTxInterface
`host.network.ingress.packets`CopiedVendor.PacketsRxInterface
`host.os.platform`CopiedVendor.Platform
`host.uptime`CopiedVendor.HostUpTime
`http.request.body.bytes`CopiedVendor.RequestBodySize
`http.request.method`CopiedVendor.Method
`http.response.body.bytes`CopiedVendor.ResponseBodySize
`http.response.mime_type`CopiedVendor.ContentType
`http.response.status_code`CopiedVendor.StatusCode
`http.version`CopiedVendor.ProtocolVersion
`network.application`CopiedVendor.Application
`network.forwarded_ip`CopiedVendor.XFF
`network.iana_number`CopiedVendor.IPProtocol
`network.protocol`CopiedVendor.Protocol, Vendor.InspectionProtocolConfig
`observer.geo.city_name`CopiedVendor.AuditNewValue.cityCountry, Vendor.AuditOldValue.cityCountry
`observer.geo.country_iso_code`CopiedVendor.CountryCode, Vendor.ZENCountryCode
`observer.geo.country_name`CopiedVendor.AuditNewValue.location, Vendor.AuditOldValue.location
`observer.geo.location.lat`CopiedVendor.Latitude, Vendor.ZENLatitude
`observer.geo.location.lon`CopiedVendor.Longitude, Vendor.ZENLongitude
`observer.name`CopiedVendor.Connector, Vendor.Exporter, Vendor.ClientZEN, Vendor.ZEN, Vendor.PrivateCloudController, Vendor.ServiceEdge, Vendor.PrivateSE
`observer.os.platform`CopiedVendor.Platform
`observer.version`CopiedVendor.Version
`organization.id`CopiedVendor.CustomerID
`organization.name`CopiedVendor.Customer
`rule.name`CopiedVendor.InspectionPolicy, Vendor.Policy
`rule.ruleset`CopiedVendor.InspectionProfile
`server.address`Copieddestination.address
`server.bytes`Copieddestination.bytes, Vendor.TotalBytesRx
`server.domain`Copieddestination.domain
`server.ip`Copieddestination.ip
`server.port`Copieddestination.port
`service.name`CopiedVendor.Application
`service.node.name`CopiedVendor.PrivateCloudController
`service.version`CopiedVendor.Version
`source.bytes`CopiedVendor.ZENTotalBytesTxClient, Vendor.TotalBytesTx
`source.geo.city_name`CopiedVendor.City
`source.geo.country_iso_code`CopiedVendor.CountryCode, Vendor.ClientCountryCode
`source.geo.location.lat`CopiedVendor.Latitude, Vendor.ClientLatitude
`source.geo.location.lon`CopiedVendor.Longitude, Vendor.ClientLongitude
`source.nat.ip`CopiedVendor.ClientPrivateIp, Vendor.PrivateIP
`source.port`CopiedVendor.ClientPort, Vendor.ClientPublicPort
`tls.client.x509.issuer.distinguished_name`CopiedVendor.AuditNewValue.issuedTo, Vendor.AuditOldValue.issuedTo
`tls.client.x509.not_after`CopiedVendor.AuditNewValue.expirationTimeInSeconds, Vendor.AuditOldValue.expirationTimeInSeconds
`tls.client.x509.not_before`CopiedVendor.AuditNewValue.creationTimeInSeconds, Vendor.AuditOldValue.creationTimeInSeconds
`url.original`CopiedVendor.URL
`user.email`CopiedVendor.UserID, Vendor.User, Vendor.NameID
`user.id`CopiedVendor.ModifiedBy, Vendor.NameID
`user.name`CopiedVendor.Username, Vendor.User, Vendor.NameID
`user.target.email`CopiedVendor.AuditNewValue.email, Vendor.AuditOldValue.email
`user.target.id`CopiedVendor.AuditNewValue.id, Vendor.AuditOldValue.id
`user.target.name`CopiedVendor.AuditNewValue.displayName, Vendor.AuditOldValue.displayName
`user_agent.original`CopiedVendor.UserAgent
`event.dataset`DeterminedVendor.sourcetype
`event.outcome`DeterminedVarious status fields
`network.transport`Determinednetwork.iana_number
`destination.address`ExtractedVendor.Destination, Vendor.Domain, Vendor.Host
`destination.domain`Extracteddestination.address
`destination.ip`Extracteddestination.address
`source.address`ExtractedVendor.ClientPublicIp, Vendor.PublicIP, Vendor.AuditOldValue.remoteIP, Vendor.AuditNewValue.remoteIP
`source.domain`Extractedsource.address
`source.ip`Extractedsource.address
`url.domain`Extractedurl.full
`url.full`FormattedVendor.Protocol, Vendor.Host, Vendor.URL
`@timestamp`ParsedVendor.LogTimestamp, Vendor.ModifiedTime, Vendor.CreationTime
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
source.addressclient.address 
source.bytesclient.bytes 
source.domainclient.domain 
source.geo.city_nameclient.geo.city_name 
source.geo.country_iso_codeclient.geo.country_iso_code 
source.geo.location.latclient.geo.location.lat 
source.geo.location.lonclient.geo.location.lon 
source.ipclient.ip 
source.nat.ipclient.nat.ip 
source.portclient.port 
Vendor.ZENTotalBytesRxClientdestination.bytes 
Vendor.ApplicationPortdestination.port 
Vendor.ServerPortdestination.port 
Vendor.AuditOperationTypeevent.action 
Vendor.CreationTimeevent.created 
Vendor.TimestampConnectionEndevent.end 
Vendor.TimestampResponseTransmitFinishevent.end 
Vendor.TimestampUnAuthenticationevent.end 
Vendor.RequestIDevent.id 
Vendor.AuditOldValueevent.original 
Vendor.ConnectionReasonevent.reason 
Vendor.InternalReasonevent.reason 
Vendor.TimestampAuthenticationevent.start 
Vendor.TimestampConnectionStartevent.start 
Vendor.TimestampRequestReceiveStartevent.start 
Vendor.AuditNewValue.idgroup.id 
Vendor.AuditOldValue.idgroup.id 
Vendor.AuditNewValue.namegroup.name 
Vendor.AuditOldValue.namegroup.name 
Vendor.CPUUtilizationhost.cpu.usage 
Vendor.CountryCodehost.geo.country_iso_code 
Vendor.Latitudehost.geo.location.lat 
Vendor.Longitudehost.geo.location.lon 
Vendor.Connectorhost.name 
Vendor.PrivateCloudControllerhost.name 
Vendor.PrivateSEhost.name 
Vendor.ServiceEdgehost.name 
host.hostnamehost.name 
Vendor.BytesTxInterfacehost.network.egress.bytes 
Vendor.TotalBytesTxhost.network.egress.bytes 
Vendor.TransmittedBytesToPublicSEhost.network.egress.bytes 
Vendor.PacketsTxInterfacehost.network.egress.packets 
Vendor.BytesRxInterfacehost.network.ingress.bytes 
Vendor.ReceivedBytesFromPublicSEhost.network.ingress.bytes 
Vendor.TotalBytesRxhost.network.ingress.bytes 
Vendor.PacketsRxInterfacehost.network.ingress.packets 
Vendor.Platformhost.os.platform 
Vendor.HostUpTimehost.uptime 
Vendor.RequestBodySizehttp.request.body.bytes 
Vendor.RequestHdrSizehttp.request.bytes 
Vendor.RequestSizehttp.request.bytes 
Vendor.Methodhttp.request.method 
Vendor.ResponseBodySizehttp.response.body.bytes 
Vendor.ResponseHdrSizehttp.response.bytes 
Vendor.ResponseSizehttp.response.bytes 
Vendor.ContentTypehttp.response.mime_type 
Vendor.StatusCodehttp.response.status_code 
Vendor.ProtocolVersionhttp.version 
Vendor.TotalBytesRxnetwork.bytes 
Vendor.ZENTotalBytesTxClientnetwork.bytes 
host.network.ingress.bytesnetwork.bytes 
Vendor.XFFnetwork.forwarded_ip 
Vendor.IPProtocolnetwork.iana_number 
Vendor.AuditNewValue.cityCountryobserver.geo.city_name 
Vendor.AuditOldValue.cityCountryobserver.geo.city_name 
Vendor.CountryCodeobserver.geo.country_iso_code 
Vendor.ZENCountryCodeobserver.geo.country_iso_code 
Vendor.AuditNewValue.latitudeobserver.geo.location.lat 
Vendor.AuditOldValue.latitudeobserver.geo.location.lat 
Vendor.Latitudeobserver.geo.location.lat 
Vendor.ZENLatitudeobserver.geo.location.lat 
Vendor.AuditNewValue.longitudeobserver.geo.location.lon 
Vendor.AuditOldValue.longitudeobserver.geo.location.lon 
Vendor.Longitudeobserver.geo.location.lon 
Vendor.ZENLongitudeobserver.geo.location.lon 
Vendor.ClientZENobserver.name 
Vendor.Connectorobserver.name 
Vendor.Exporterobserver.name 
Vendor.PrivateCloudControllerobserver.name 
Vendor.PrivateSEobserver.name 
Vendor.ServiceEdgeobserver.name 
Vendor.ZENobserver.name 
Vendor.Platformobserver.os.platform 
Vendor.Versionobserver.version 
Vendor.CustomerIDorganization.id 
Vendor.Customerorganization.name 
Vendor.InspectionPolicyrule.name 
Vendor.Policyrule.name 
Vendor.InspectionProfilerule.ruleset 
destination.addressserver.address 
Vendor.TotalBytesRxserver.bytes 
destination.bytesserver.bytes 
destination.domainserver.domain 
destination.ipserver.ip 
destination.portserver.port 
Vendor.Applicationservice.name 
Vendor.PrivateCloudControllerservice.node.name 
Vendor.Versionservice.version 
Vendor.TotalBytesTxsource.bytes 
Vendor.ZENTotalBytesTxClientsource.bytes 
Vendor.Citysource.geo.city_name 
Vendor.ClientCountryCodesource.geo.country_iso_code 
Vendor.CountryCodesource.geo.country_iso_code 
Vendor.ClientLatitudesource.geo.location.lat 
Vendor.Latitudesource.geo.location.lat 
Vendor.ClientLongitudesource.geo.location.lon 
Vendor.Longitudesource.geo.location.lon 
Vendor.AuditOldValue.remoteIPsource.ip 
Vendor.ClientPrivateIpsource.nat.ip 
Vendor.PrivateIPsource.nat.ip 
Vendor.ClientPortsource.port 
Vendor.ClientPublicPortsource.port 
Vendor.AuditOldValue.expirationTimeInSecondstls.client.x509.not_after 
Vendor.AuditOldValue.creationTimeInSecondstls.client.x509.not_before 
Vendor.URLurl.original 
Vendor.NameIDuser.email 
Vendor.UserIDuser.email 
Vendor.ModifiedByuser.id 
Vendor.Usernameuser.name 
Vendor.AuditNewValue.emailuser.target.email 
Vendor.AuditOldValue.emailuser.target.email 
Vendor.AuditNewValue.iduser.target.id 
Vendor.AuditOldValue.iduser.target.id 
Vendor.AuditNewValue.displayNameuser.target.name 
Vendor.AuditOldValue.displayNameuser.target.name 
roles.nameuser.target.roles 
Vendor.UserAgentuser_agent.original