Parsers and Generated Fields

Tag Fields Created by Parser zscaler-zpa-app-connector-status-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-app-connector-status-json
Source FieldLogScale Repository Field
Vendor.TotalBytesRxclient.bytes
Vendor.DefRouteGWclient.nat.ip
Vendor.CPUUtilizationhost.cpu.usage
Vendor.Latitudeobserver.geo.location.lat
Vendor.Longitudeobserver.geo.location.lon
Vendor.PublicIPobserver.ip[0]
Vendor.PrivateIPobserver.ip[1]
Vendor.Platformobserver.os.platform
Vendor.Customerorganization.name
Vendor.Versionpackage.version
Vendor.TotalBytesTxserver.bytes
Tag Fields Created by Parser zscaler-zpa-app-protection-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-app-protection-json
Source FieldLogScale Repository Field
Vendor.UserAgentagent.original
Vendor.ClientPublicIpclient.ip
Vendor.ClientPortclient.port
Vendor.StatusCodecode
Vendor.Hosthost.ip[0]
Vendor.RequestBodySizehttp.request.body.bytes
Vendor.Methodhttp.request.method
Vendor.ResponseBodySizehttp.response.body.bytes
Vendor.ProtocolVersionhttp.version
Vendor.TotalBytesProcessednetwork.bytes
Vendor.Customerorganization.name
Tag Fields Created by Parser zscaler-zpa-audit-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-audit-json
Source FieldLogScale Repository Field
Vendor.AuditNewValue.expirationTimeInSecondsafter
Vendor.AuditOldValue.expirationTimeInSecondsafter
Vendor.AuditNewValue.creationTimeInSecondsbefore
Vendor.AuditOldValue.creationTimeInSecondsbefore
Vendor.AuditNewValue.remoteIPclient.ip
Vendor.AuditOldValue.remoteIPclient.ip
Vendor.AuditOperationTypeevent.action
Vendor.RequestIDevent.id
Vendor.AuditNewValue.idgroup.id
Vendor.AuditOldValue.idgroup.id
Vendor.AuditNewValue.namegroup.name
Vendor.AuditOldValue.namegroup.name
Vendor.AuditNewValue.cityCountryname
Vendor.AuditNewValue.commonNamename
Vendor.AuditNewValue.issuedToname
Vendor.AuditNewValue.locationname
Vendor.AuditOldValue.cityCountryname
Vendor.AuditOldValue.commonNamename
Vendor.AuditOldValue.issuedToname
Vendor.AuditOldValue.locationname
Vendor.AuditNewValue.subjectAlternateNamesnames
Vendor.AuditOldValue.subjectAlternateNamesnames
Vendor.AuditNewValue.latitudeobserver.geo.location.lat
Vendor.AuditOldValue.latitudeobserver.geo.location.lat
Vendor.AuditNewValue.longitudeobserver.geo.location.lon
Vendor.AuditOldValue.longitudeobserver.geo.location.lon
Vendor.CustomerIDorganization.id
Vendor.AuditNewValue.domainOrIpAddressserver.address
Vendor.AuditOldValue.domainOrIpAddressserver.address
server.addressserver.ip
Vendor.ModifiedByuser.id
Vendor.Useruser.name
Vendor.AuditNewValue.emailuser.target.email
Vendor.AuditOldValue.emailuser.target.email
Vendor.AuditNewValue.iduser.target.id
Vendor.AuditOldValue.iduser.target.id
Vendor.AuditNewValue.nameuser.target.name
Vendor.AuditOldValue.nameuser.target.name
Vendor.AuditNewValue.roles[0].nameuser.target.roles[0]
Vendor.AuditNewValue.roles[1].nameuser.target.roles[1]
Vendor.AuditNewValue.roles[2].nameuser.target.roles[2]
Vendor.AuditNewValue.roles[3].nameuser.target.roles[3]
Vendor.AuditNewValue.roles[4].nameuser.target.roles[4]
Tag Fields Created by Parser zscaler-zpa-browser-access-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-browser-access-json
Source FieldLogScale Repository Field
Vendor.ClientPublicIpclient.ip
Vendor.ClientPublicPortclient.port
Vendor.StatusCodecode
Vendor.ConnectionReasonevent.reason
Vendor.RequestSizehttp.request.body.bytes
Vendor.Methodhttp.request.method
Vendor.ResponseSizehttp.response.body.bytes
Vendor.Customerorganization.name
Vendor.ApplicationPortserver.port
Vendor.NameIDuser.name
Tag Fields Created by Parser zscaler-zpa-user-activity-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-user-activity-json
Source FieldLogScale Repository Field
Vendor.ClientLatitudeclient.geo.location.lat
Vendor.ClientLongitudeclient.geo.location.lon
Vendor.ClientPublicIPclient.ip
Vendor.ClientCountryCodecode
Vendor.InternalReasonevent.reason
Vendor.Hosthost.ip[0]
Vendor.Customerorganization.name
Vendor.ServerIPserver.ip
Vendor.ServerPortserver.port
Vendor.Usernameuser.name
Tag Fields Created by Parser zscaler-zpa-user-status-json
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-zpa-user-status-json
Source FieldLogScale Repository Field
Vendor.TotalBytesRxclient.bytes
Vendor.Latitudeclient.geo.location.lat
Vendor.Longitudeclient.geo.location.lon
Vendor.PublicIPclient.ip
Vendor.CountryCodecode
Vendor.ZENCountryCodecode
Vendor.Platformhost.os.platform
Vendor.CertificateCNname
Vendor.Cityname
Vendor.Customerorganization.name
Vendor.TotalBytesTxserver.bytes
Vendor.ZENLatitudeserver.geo.location.lat
Vendor.ZENLongitudeserver.geo.location.lon
Vendor.Usernameuser.name