Parsers and Generated Fields

Tag Fields Created by Parser zscaler-privateaccess
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser zscaler-privateaccess
Vendor FieldCPS FieldDescription
LogTimestamp@timestampTimestamp parsing from log entry
TotalBytesRxclient.bytesTotal bytes received by client
Vendor.TotalBytesRxclient.bytes 
Vendor.Cityclient.geo.city_name 
CountryCodeclient.geo.country_iso_codeClient's country code
Vendor.ClientCountryCodeclient.geo.country_iso_code 
Vendor.CountryCodeclient.geo.country_iso_code 
Latitudeclient.geo.location.latClient's latitude
Vendor.ClientLatitudeclient.geo.location.lat 
Vendor.Latitudeclient.geo.location.lat 
Longitudeclient.geo.location.lonClient's longitude
Vendor.ClientLongitudeclient.geo.location.lon 
Vendor.Longitudeclient.geo.location.lon 
PublicIPclient.ipClient's public IP address
Vendor.AuditNewValue.remoteIP;client.ip 
Vendor.AuditOldValue.remoteIP;client.ip 
Vendor.ClientPublicIPclient.ip 
Vendor.ClientPublicIpclient.ip 
Vendor.PublicIPclient.ip 
Vendor.DefRouteGWclient.nat.ip 
Vendor.ClientPortclient.port 
Vendor.ClientPublicPortclient.port 
Vendor.AuditOperationTypeevent.action 
Vendor.RequestIDevent.id 
Vendor.ConnectionReasonevent.reason 
Vendor.InternalReasonevent.reason 
Vendor.AuditNewValue.idgroup.id 
Vendor.AuditOldValue.idgroup.id 
Vendor.AuditNewValue.namegroup.name 
Vendor.AuditOldValue.namegroup.name 
Vendor.CPUUtilizationhost.cpu.usage 
Hostnamehost.hostnameSystem hostname
Platformhost.os.platformOperating system platform
Vendor.Platformhost.os.platform 
RequestSizehttp.request.body.bytesSize of HTTP request body
Vendor.RequestBodySizehttp.request.body.bytes 
Vendor.RequestSizehttp.request.body.bytes 
Methodhttp.request.methodHTTP request method
Vendor.Methodhttp.request.method 
ResponseSizehttp.response.body.bytesSize of HTTP response body
Vendor.ResponseBodySizehttp.response.body.bytes 
Vendor.ResponseSizehttp.response.body.bytes 
StatusCodehttp.response.status_codeHTTP response status code
Vendor.StatusCodehttp.response.status_code 
Vendor.ProtocolVersionhttp.version 
Vendor.TotalBytesProcessednetwork.bytes 
Protocolnetwork.protocolNetwork protocol used
Vendor.AuditNewValue.cityCountryobserver.geo.city_name 
Vendor.AuditOldValue.cityCountryobserver.geo.city_name 
Vendor.AuditNewValue.location;observer.geo.country_name 
Vendor.AuditOldValue.location;observer.geo.country_name 
Vendor.AuditNewValue.latitudeobserver.geo.location.lat 
Vendor.AuditOldValue.latitudeobserver.geo.location.lat 
Vendor.Latitudeobserver.geo.location.lat 
Vendor.AuditNewValue.longitudeobserver.geo.location.lon 
Vendor.AuditOldValue.longitudeobserver.geo.location.lon 
Vendor.Longitudeobserver.geo.location.lon 
Vendor.Platformobserver.os.platform 
Vendor.CustomerIDorganization.id 
Customerorganization.nameCustomer organization name
Vendor.Customerorganization.name 
Vendor.Versionpackage.version 
Hostserver.addressServer hostname/address
Vendor.AuditNewValue.domainOrIpAddressserver.address 
Vendor.AuditOldValue.domainOrIpAddressserver.address 
TotalBytesTxserver.bytesTotal bytes transmitted by server
Vendor.TotalBytesTxserver.bytes 
Vendor.ZENCountryCodeserver.geo.country_iso_code 
Vendor.ZENLatitudeserver.geo.location.lat 
Vendor.ZENLongitudeserver.geo.location.lon 
ServerIPserver.ipServer IP address
Vendor.ServerIPserver.ip 
server.address;server.ip 
ServerPortserver.portServer port number
Vendor.ApplicationPortserver.port 
Vendor.ServerPortserver.port 
CertificateCNtls.client.x509.issuer.common_name[]Certificate common name
Vendor.AuditNewValue.issuedTo;tls.client.x509.issuer.distinguished_name 
Vendor.AuditOldValue.issuedTo;tls.client.x509.issuer.distinguished_name 
Vendor.AuditNewValue.expirationTimeInSecondstls.client.x509.not_after 
Vendor.AuditOldValue.expirationTimeInSecondstls.client.x509.not_after 
Vendor.AuditNewValue.creationTimeInSecondstls.client.x509.not_before 
Vendor.AuditOldValue.creationTimeInSecondstls.client.x509.not_before 
Vendor.ModifiedByuser.id 
Usernameuser.nameUser associated with the event
Vendor.NameIDuser.name 
Vendor.Useruser.name 
Vendor.Usernameuser.name 
Vendor.AuditNewValue.emailuser.target.email 
Vendor.AuditOldValue.emailuser.target.email 
Vendor.AuditNewValue.iduser.target.id 
Vendor.AuditOldValue.iduser.target.id 
Vendor.AuditNewValue.name;user.target.name 
Vendor.AuditOldValue.name;user.target.name 
UserAgentuser_agent.originalUser agent string
Vendor.UserAgentuser_agent.original