Parsers and Generated Fields

Tag Fields Created by Parser okta-sso
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser okta-sso
Vendor FieldCPS FieldDescription
Vendor.published@timestampEvent timestamp
Vendor.securityContext.asOrgclient.as.organization.nameAS organization name
Vendor.securityContext.domainclient.domain,Domain name
Vendor.client.geographicalContext.cityclient.geo.city_nameClient city location
Vendor.client.geographicalContext.countryclient.geo.country_nameClient country location
Vendor.client.geographicalContext.geolocation.latclient.geo.location.latClient latitude
Vendor.client.geographicalContext.geolocation.lonclient.geo.location.lonClient longitude
Vendor.client.geographicalContext.stateclient.geo.region_nameClient state location
Vendor.client.ipAddressclient.ip 
Vendor.client.ipAddressclient.ip,Client IP address
Vendor.actor.displayNameclient.user.full_name 
Vendor.actor.displayNameclient.user.full_name,User display name
Vendor.actor.idclient.user.id 
Vendor.actor.idclient.user.id,User ID
user.nameclient.user.name 
Vendor.eventTypeevent.actionEvent type from Okta
Vendor.uuidevent.idUnique event identifier
Vendor.outcome.resultevent.outcomeMaps SUCCESS/ALLOW to "success", FAILURE/DENY to "failure", empty/null to "unknown"
Vendor.outcome.reasonevent.reasonReason for the outcome
Vendor.severityevent.severityMaps DEBUG to 10, INFO to 30, WARN to 50, ERROR to 70, FATAL to 90
Vendor.displayMessagemessageHuman-readable message
client.ipsource.ip 
client.user.full_namesource.user.full_name 
client.user.idsource.user.id 
user.namesource.user.name 
client.user.full_nameuser.full_name 
Vendor.actor.alternateIduser.name 
Vendor.actor.alternateIduser.name,User identifier
Vendor.target[].detailEntry.emailAddressuser.target.emailTarget user email when type is User
__out[0]user.target.email  
Vendor.target[].displayNameuser.target.full_nameTarget user display name when type is User
__out[0]user.target.full_name  
Vendor.target[].iduser.target.group.idTarget group ID when type is UserGroup
__out[0]user.target.group.id  
Vendor.target[].displayNameuser.target.group.nameTarget group name when type is UserGroup
__out[0]user.target.group.name  
Vendor.target[].iduser.target.idTarget user ID when type is User
__out[0]user.target.id  
Vendor.target[].alternateIduser.target.nameTarget user alternate ID when type is User
__out[0]user.target.name  
Vendor.client.userAgent.rawUserAgentuser_agent.originalRaw user agent string