Parsers and Generated Fields

Tag Fields Created by Parser zscaler-privateaccess
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-privateaccess
Source FieldCPS Field
Vendor.TotalBytesRxclient.bytes
Vendor.Cityclient.geo.city_name
Vendor.ClientCountryCodeclient.geo.country_iso_code
Vendor.CountryCodeclient.geo.country_iso_code
Vendor.ClientLatitudeclient.geo.location.lat
Vendor.Latitudeclient.geo.location.lat
Vendor.ClientLongitudeclient.geo.location.lon
Vendor.Longitudeclient.geo.location.lon
Vendor.AuditNewValue.remoteIP;client.ip
Vendor.AuditOldValue.remoteIP;client.ip
Vendor.ClientPublicIPclient.ip
Vendor.ClientPublicIpclient.ip
Vendor.PublicIPclient.ip
Vendor.DefRouteGWclient.nat.ip
Vendor.ClientPortclient.port
Vendor.ClientPublicPortclient.port
Vendor.AuditOperationTypeevent.action
Vendor.RequestIDevent.id
Vendor.ConnectionReasonevent.reason
Vendor.InternalReasonevent.reason
Vendor.AuditNewValue.idgroup.id
Vendor.AuditOldValue.idgroup.id
Vendor.AuditNewValue.namegroup.name
Vendor.AuditOldValue.namegroup.name
Vendor.CPUUtilizationhost.cpu.usage
Vendor.Host;host.ip[0]
Vendor.Platformhost.os.platform
Vendor.RequestBodySizehttp.request.body.bytes
Vendor.RequestSizehttp.request.body.bytes
Vendor.Methodhttp.request.method
Vendor.ResponseBodySizehttp.response.body.bytes
Vendor.ResponseSizehttp.response.body.bytes
Vendor.StatusCodehttp.response.status_code
Vendor.ProtocolVersionhttp.version
Vendor.TotalBytesProcessednetwork.bytes
Vendor.AuditNewValue.cityCountryobserver.geo.city_name
Vendor.AuditOldValue.cityCountryobserver.geo.city_name
Vendor.AuditNewValue.location;observer.geo.country_name
Vendor.AuditOldValue.location;observer.geo.country_name
Vendor.AuditNewValue.latitudeobserver.geo.location.lat
Vendor.AuditOldValue.latitudeobserver.geo.location.lat
Vendor.Latitudeobserver.geo.location.lat
Vendor.AuditNewValue.longitudeobserver.geo.location.lon
Vendor.AuditOldValue.longitudeobserver.geo.location.lon
Vendor.Longitudeobserver.geo.location.lon
Vendor.PublicIPobserver.ip[0]
Vendor.PrivateIPobserver.ip[1]
Vendor.Platformobserver.os.platform
Vendor.CustomerIDorganization.id
Vendor.Customerorganization.name
Vendor.Versionpackage.version
Vendor.AuditNewValue.domainOrIpAddressserver.address
Vendor.AuditOldValue.domainOrIpAddressserver.address
Vendor.TotalBytesTxserver.bytes
Vendor.ZENCountryCodeserver.geo.country_iso_code
Vendor.ZENLatitudeserver.geo.location.lat
Vendor.ZENLongitudeserver.geo.location.lon
Vendor.ServerIPserver.ip
server.address;server.ip
Vendor.ApplicationPortserver.port
Vendor.ServerPortserver.port
Vendor.ModifiedByuser.id
Vendor.NameIDuser.name
Vendor.Useruser.name
Vendor.Usernameuser.name
Vendor.AuditNewValue.emailuser.target.email
Vendor.AuditOldValue.emailuser.target.email
Vendor.AuditNewValue.iduser.target.id
Vendor.AuditOldValue.iduser.target.id
Vendor.AuditNewValue.name;user.target.name
Vendor.AuditOldValue.name;user.target.name
Vendor.AuditNewValue.roles[0].nameuser.target.roles[0]
Vendor.AuditNewValue.roles[1].nameuser.target.roles[1]
Vendor.AuditNewValue.roles[2].nameuser.target.roles[2]
Vendor.AuditNewValue.roles[3].nameuser.target.roles[3]
Vendor.AuditNewValue.roles[4].name;user.target.roles[4]
Vendor.UserAgentuser_agent.original
Vendor.AuditNewValue.subjectAlternateNamesx509.alternative_names
Vendor.AuditOldValue.subjectAlternateNamesx509.alternative_names
Vendor.AuditNewValue.commonNamex509.issuer.common_name
Vendor.AuditNewValue.commonName;x509.issuer.common_name
Vendor.AuditOldValue.commonNamex509.issuer.common_name
Vendor.AuditOldValue.commonName;x509.issuer.common_name
Vendor.CertificateCNx509.issuer.common_name
Vendor.AuditNewValue.issuedTo;x509.issuer.distinguished_name
Vendor.AuditOldValue.issuedTo;x509.issuer.distinguished_name
Vendor.AuditNewValue.expirationTimeInSecondsx509.not_after
Vendor.AuditOldValue.expirationTimeInSecondsx509.not_after
Vendor.AuditNewValue.creationTimeInSecondsx509.not_before
Vendor.AuditOldValue.creationTimeInSecondsx509.not_before
Tag Fields Created by Parser zscaler-zpa-app-connector-status-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-app-connector-status-json
Source FieldCPS Field
Vendor.TotalBytesRxclient.bytes
Vendor.DefRouteGWclient.nat.ip
Vendor.CPUUtilizationhost.cpu.usage
Vendor.Latitudeobserver.geo.location.lat
Vendor.Longitudeobserver.geo.location.lon
Vendor.PublicIPobserver.ip[0]
Vendor.PrivateIPobserver.ip[1]
Vendor.Platformobserver.os.platform
Vendor.Customerorganization.name
Vendor.Versionpackage.version
Vendor.TotalBytesTxserver.bytes
Tag Fields Created by Parser zscaler-zpa-app-protection-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-app-protection-json
Source FieldCPS Field
Vendor.ClientPublicIpclient.ip
Vendor.ClientPortclient.port
Vendor.Host;host.ip[0]
Vendor.RequestBodySizehttp.request.body.bytes
Vendor.Methodhttp.request.method
Vendor.ResponseBodySizehttp.response.body.bytes
Vendor.StatusCodehttp.response.status_code
Vendor.ProtocolVersionhttp.version
Vendor.TotalBytesProcessednetwork.bytes
Vendor.Customerorganization.name
Vendor.UserAgentuser_agent.original
Tag Fields Created by Parser zscaler-zpa-audit-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-audit-json
Source FieldCPS Field
Vendor.AuditNewValue.remoteIP;client.ip
Vendor.AuditOldValue.remoteIP;client.ip
Vendor.AuditOperationTypeevent.action
Vendor.RequestIDevent.id
Vendor.AuditNewValue.idgroup.id
Vendor.AuditOldValue.idgroup.id
Vendor.AuditNewValue.namegroup.name
Vendor.AuditOldValue.namegroup.name
Vendor.AuditNewValue.cityCountryobserver.geo.city_name
Vendor.AuditOldValue.cityCountryobserver.geo.city_name
Vendor.AuditNewValue.location;observer.geo.country_name
Vendor.AuditOldValue.location;observer.geo.country_name
Vendor.AuditNewValue.latitudeobserver.geo.location.lat
Vendor.AuditOldValue.latitudeobserver.geo.location.lat
Vendor.AuditNewValue.longitudeobserver.geo.location.lon
Vendor.AuditOldValue.longitudeobserver.geo.location.lon
Vendor.CustomerIDorganization.id
Vendor.AuditNewValue.domainOrIpAddressserver.address
Vendor.AuditOldValue.domainOrIpAddressserver.address
server.address;server.ip
Vendor.ModifiedByuser.id
Vendor.Useruser.name
Vendor.AuditNewValue.emailuser.target.email
Vendor.AuditOldValue.emailuser.target.email
Vendor.AuditNewValue.iduser.target.id
Vendor.AuditOldValue.iduser.target.id
Vendor.AuditNewValue.name;user.target.name
Vendor.AuditOldValue.name;user.target.name
Vendor.AuditNewValue.roles[0].nameuser.target.roles[0]
Vendor.AuditNewValue.roles[1].nameuser.target.roles[1]
Vendor.AuditNewValue.roles[2].nameuser.target.roles[2]
Vendor.AuditNewValue.roles[3].nameuser.target.roles[3]
Vendor.AuditNewValue.roles[4].name;user.target.roles[4]
Vendor.AuditNewValue.subjectAlternateNamesx509.alternative_names
Vendor.AuditOldValue.subjectAlternateNamesx509.alternative_names
Vendor.AuditNewValue.commonNamex509.issuer.common_name
Vendor.AuditNewValue.commonName;x509.issuer.common_name
Vendor.AuditOldValue.commonNamex509.issuer.common_name
Vendor.AuditOldValue.commonName;x509.issuer.common_name
Vendor.AuditNewValue.issuedTo;x509.issuer.distinguished_name
Vendor.AuditOldValue.issuedTo;x509.issuer.distinguished_name
Vendor.AuditNewValue.expirationTimeInSecondsx509.not_after
Vendor.AuditOldValue.expirationTimeInSecondsx509.not_after
Vendor.AuditNewValue.creationTimeInSecondsx509.not_before
Vendor.AuditOldValue.creationTimeInSecondsx509.not_before
Tag Fields Created by Parser zscaler-zpa-browser-access-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-browser-access-json
Source FieldCPS Field
Vendor.ClientPublicIpclient.ip
Vendor.ClientPublicPortclient.port
Vendor.ConnectionReasonevent.reason
Vendor.RequestSizehttp.request.body.bytes
Vendor.Methodhttp.request.method
Vendor.ResponseSizehttp.response.body.bytes
Vendor.StatusCodehttp.response.status_code
Vendor.Customerorganization.name
Vendor.ApplicationPortserver.port
Vendor.NameIDuser.name
Tag Fields Created by Parser zscaler-zpa-user-activity-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-user-activity-json
Source FieldCPS Field
Vendor.ClientCountryCodeclient.geo.country_iso_code
Vendor.ClientLatitudeclient.geo.location.lat
Vendor.ClientLongitudeclient.geo.location.lon
Vendor.ClientPublicIPclient.ip
Vendor.InternalReasonevent.reason
Vendor.Host;host.ip[0]
Vendor.Customerorganization.name
Vendor.ServerIPserver.ip
Vendor.ServerPortserver.port
Vendor.Usernameuser.name
Tag Fields Created by Parser zscaler-zpa-user-status-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-user-status-json
Source FieldCPS Field
Vendor.TotalBytesRxclient.bytes
Vendor.Cityclient.geo.city_name
Vendor.CountryCodeclient.geo.country_iso_code
Vendor.Latitudeclient.geo.location.lat
Vendor.Longitudeclient.geo.location.lon
Vendor.PublicIPclient.ip
Vendor.Platformhost.os.platform
Vendor.Customerorganization.name
Vendor.TotalBytesTxserver.bytes
Vendor.ZENCountryCodeserver.geo.country_iso_code
Vendor.ZENLatitudeserver.geo.location.lat
Vendor.ZENLongitudeserver.geo.location.lon
Vendor.Usernameuser.name
Vendor.CertificateCNx509.issuer.common_name