Parsers and Generated Fields

Tag Fields Created by Parser island-enterprisebrowser
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser island-enterprisebrowser
Vendor FieldCPS FieldDescription
Vendor.actionevent.actionFor admin actions
Vendor.message.typeevent.actionAction type
Vendor.actionevent.action  
Vendor.message.typeevent.action  
Vendor.message.sourceevent.category[0]For network events
Vendor.message.verdictevent.outcomeFor blocked verdicts
Vendor.hostnamehost.hostnameHostname in lowercase
Vendor.message.ruleIdrule.idID of the rule that triggered
Vendor.message.ruleNamerule.nameName of the rule that triggered
Vendor.message.sourceIpsource.ipSource IP address for network events
Vendor.message.sourceIpsource.ip  
Vendor.message.publicIpsource.nat.ipPublic/NAT IP address
Vendor.message.publicIpsource.nat.ip  
url.hosturl.domainDomain extracted from URL and converted to lowercase
url.hosturl.domain  
Vendor.message.topLevelUrlurl.originalOriginal URL for parsing
Vendor.message.topLevelUrlurl.original  
Vendor.message.emailuser.emailUser email address
Vendor.message.emailuser.email  
Vendor.message.userIduser.idUser identifier
Vendor.message.userIduser.id  
Vendor.message.userNameuser.nameUsername
Vendor.message.userNameuser.name  
Vendor.message.entityIduser.target.idTarget user ID for admin actions
Vendor.message.entityIduser.target.id  
Vendor.message.entityNameuser.target.nameTarget user name for admin actions
Vendor.message.entityNameuser.target.name