Parsers and Generated Fields
Tag Fields Created by Parser cisco-ios
#Cps.version
#Vendor
#ecs.version
#event.dataset
#event.kind
#event.module
#event.outcome
#observer.type
Fields Identified by Parser cisco-ios
Vendor Field | CPS Field | Description |
---|---|---|
Vendor.crypto_cipher | - | Crypto cipher used |
Vendor.eventCode | - | Event code |
Vendor.hmac | - | HMAC algorithm |
Vendor.icmp.code | - | ICMP code |
Vendor.icmp.type | - | ICMP type |
Vendor.interface | - | Interface name |
Vendor.ios.action | - | Action taken |
Vendor.ios.facility | - | IOS facility name |
Vendor.ios.pim.group.ip | - | PIM group IP |
Vendor.ios.pim.source.ip | - | PIM source IP |
Vendor.ios.session.number | - | Session number |
Vendor.ios.session.type | - | Session type |
Vendor.session_id | - | Session ID |
Vendor.vlan | - | VLAN ID |
client.ip | - | Client IP address |
client.mac | - | Client MAC address |
destination.ip | - | Destination IP address |
destination.mac | - | Destination MAC address |
destination.port | - | Destination port |
event.action | - | Action taken |
event.reason | - | Reason for event |
host.mac | - | Host MAC address |
log.syslog.hostname | - | Device hostname |
log.syslog.priority | - | Syslog priority value |
log.syslog.severity.code | - | Severity code |
message | - | Raw message content |
network.iana_number | - | Protocol number |
network.transport | - | Transport protocol |
observer.ingress.interface.name | - | Interface name |
process.command_line | - | CLI command executed |
rule.name | - | Rule name |
server.ip | - | Server IP address |
server.port | - | Server port |
Vendor.Source | client.ip | |
destination.address | destination.ip | |
Vendor.action | event.action | |
Vendor.eventAction; | event.action | |
Vendor.Reason | event.reason | |
Vendor.ios.message_count | event.sequence | Message counter |
Vendor.ios.message_count; | event.sequence | |
Vendor.ios.sequence; | event.sequence | |
source.packets | network.packets | Number of packets |
Vendor.protocol | network.transport | |
Vendor.ingress_interface | observer.ingress.interface.name | |
Vendor.sgacl_name | rule.name | |
Vendor.localport | server.port | |
source.address | source.ip | Source IP address |
Vendor.mac | source.mac | Source MAC address (normalized to ECS format) |
user.name | source.user.name | Username |
Vendor.user | user.name |