Parsers and Generated Fields

Tag Fields Created by Parser forcepoint-dlp
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser forcepoint-dlp
Vendor FieldCPS FieldDescription
Vendor.caseDateAndTime@timestampTimestamp for report data
Vendor.timeStamp@timestampTimestamp for event data
Vendor.nameagent.nameName of the agent
Vendor.nameagent.name  
Vendor.device.versionagent.versionVersion of the agent
Vendor.device.versionagent.version  
Vendor.destinationHostsdestination.domainDestination host domain when not "N/A"
Vendor.sourceServiceNameevent.actionAction performed in the event
Vendor.sourceServiceNameevent.action  
Vendor.eventIdevent.idUnique identifier for the event
Vendor.eventIdevent.id  
Vendor.riskScoreevent.risk_scoreRisk score for report events
Vendor.riskScoreevent.risk_score  
Vendor.severityevent.severityMapped severity based on numeric value
Vendor.actevent.type[1]Conditional mapping for denied actions
Vendor.fnamefile.name,File name and size extraction
Vendor.riskScorehost.risk.calculated_scoreRisk score mapped to host risk
event.risk_scorehost.risk.calculated_score 
Vendor.msgrule.nameName of the rule that triggered
Vendor.msgrule.name  
Vendor.sourceIpsource.address  
Vendor.sourceIpsource.address,Source IP address when not "N/A"
Vendor.sourceHostsource.domainSource host domain when not "N/A"
source.address;source.ip 
Vendor.severityTypethreat.indicator.confidenceConfidence level of the threat indicator
Vendor.severityTypethreat.indicator.confidence  
Vendor.caseDescriptionthreat.indicator.descriptionDescription of the threat indicator
Vendor.caseDescriptionthreat.indicator.description  
Vendor.numberOfIncidentsthreat.indicator.sightingsNumber of incidents related to the threat
Vendor.numberOfIncidentsthreat.indicator.sightings  
Vendor.loginNameuser.domainDomain extraction from username if in domain\user format
Vendor.duseruser.emailUser email address
Vendor.duseruser.email  
Vendor.loginNameuser.nameUsername
Vendor.loginNameuser.name