Skip to content

Latest commit

 

History

History
269 lines (269 loc) · 31.3 KB

p_parsers.md

File metadata and controls

269 lines (269 loc) · 31.3 KB
Old Parser Name New-Scale Parser Name
packetfence-system-info-1 packetfence-p-kv-app-notification-status
packetfence-system-info-2 packetfence-p-kv-app-notification-role
packetfence-system-info-3 packetfence-p-kv-app-notification-fromswitchip
packetfence-system-info-4 packetfence-p-str-app-notification-line
packetfence-system-info-5 packetfence-p-str-app-notification-connectiontypeiswirelessmacauth
packetfence-system-info-6 packetfence-p-str-app-notification-cantfindprovisionerfor
palo-alto-app-activity pan-gp-cef-app-activity-success-msg
palo-alto-app-activity-1 pan-aperture-csv-app-activity-success-monitoring
palo-alto-app-activity-2 pan-aperture-csv-app-activity-success-adminaudit
palo-alto-app-login-1 pan-aperture-csv-app-login-success-signin
palo-alto-cortex-xdr-alert pan-cortex-kv-alert-trigger-success-true
palo-alto-cortex-xdr-system-info pan-cortex-cef-endpoint-notification-success-cortexxdragent
palo-alto-dlp-alert pan-aperture-kv-alert-trigger-success-incident
palo-alto-dlp-alert-1 pan-aperture-csv-alert-trigger-success-policyviolation
palo-alto-file-operations pan-aperture-csv-file-success-activitymonitoring
palo-alto-logout-1 pan-aperture-csv-app-logout-success-signout
palo-alto-networks-leef-setip pan-gp-leef-vpn-login-success-globalprotect-6
palo-alto-networks-leef-system-info pan-gp-leef-app-activity-system
palo-alto-networks-leef-vpn-login pan-gp-leef-vpn-login-success-userloginsucceeded
palo-alto-networks-setip pan-gp-csv-vpn-login-success-ssltunnel
palo-alto-networks-twistlock-system-info pan-prisma-kv-app-activity-success-twistlock
paloalto-app-activity pan-gp-cef-app-activity-success-gatewayhipcheck
paloalto-app-activity-1 pan-gp-cef-app-activity-success-gatewayhipreport
paloalto-app-activity-2 pan-gp-cef-app-activity-success-gatewaygetconfig
paloalto-app-activity-3 pan-gp-cef-app-activity-success-portalgetconfig
paloalto-app-activity-4 pan-gp-cef-app-activity-success-gatewayhipcheck-1
paloalto-app-activity-5 pan-gp-cef-app-activity-success-gatewayhipreport-1
paloalto-app-activity-6 pan-gp-cef-app-activity-success-gatewaygetconfig-1
paloalto-app-activity-7 pan-gp-cef-app-activity-success-portalgetconfig-1
paloalto-firewall-alert-1 pan-ngfw-json-alert-trigger-success-threat
paloalto-firewall-allow pan-ngfw-csv-network-traffic-success-allow
paloalto-firewall-allow-1 pan-ngfw-json-network-traffic-success-allow
paloalto-firewall-allow-2 pan-ngfw-csv-network-traffic-success-end
paloalto-firewall-allow-3 pan-ngfw-str-network-traffic-success-trafficallow
paloalto-firewall-deny pan-ngfw-csv-network-traffic-fail-panorama
paloalto-firewall-deny-1 pan-ngfw-csv-network-traffic-fail-tcp
paloalto-firewall-drop pan-ngfw-csv-network-traffic-fail-drop
paloalto-firewall-drop-1 pan-ngfw-str-network-traffic-fail-trafficdrop
paloalto-firewall-traffic-deny pan-ngfw-json-network-traffic-fail-drop
paloalto-firewall-traffic-drop pan-ngfw-json-network-traffic-fail-deny
paloalto-firewall-traffic-drop-1 pan-ngfw-json-network-traffic-fail-actiondrop
paloalto-network-connection pan-ngfw-csv-network-traffic-success-connection
paloalto-ngfw-network-connection pan-ngfw-json-network-traffic-fail-decryption
paloalto-ngfw-source-stopped pan-ngfw-str-alert-trigger-success-paseries
paloalto-system-event pan-gp-sk4-configuration-modify-gatewayconfigrelease
paloalto-system-event-1 pan-gp-cef-app-notification-success-globalprotect
paloalto-vpn-end pan-gp-sk4-vpn-logout-success-gatewaylogout
paloalto-vpn-end-1 pan-gp-cef-vpn-logout-success-gatewaylogout
paloalto-vpn-login pan-gp-sk4-vpn-login-portalauth
paloalto-vpn-login-1 pan-gp-sk4-vpn-login-gatewayprelogin
paloalto-vpn-login-2 pan-gp-sk4-vpn-login-portalprelogin
paloalto-vpn-login-3 pan-gp-sk4-vpn-login-gatewayconnected
paloalto-vpn-login-4 pan-gp-cef-vpn-login-gatewayregister
paloalto-vpn-login-5 pan-gp-cef-vpn-login-gatewayprelogin
paloalto-vpn-login-6 pan-gp-cef-vpn-login-portalprelogin
paloalto-vpn-login-7 pan-gp-cef-vpn-login-portalauth
paloalto-vpn-login-8 pan-gp-cef-vpn-login-gatewayconnected
paloalto-vpn-start pan-gp-sk4-vpn-login-gatewayauth
paloalto-vpn-start-1 pan-gp-cef-vpn-login-gatewayauth
paloalto-web-activity pan-ngfw-csv-http-session-webbrowsing
paloalto-web-activity-1 pan-ngfw-json-http-session-webbrowsing
pam-account-switch-1 ca-pamsc-kv-user-switch-success-0023
pam-account-switch-2 ca-pamsc-kv-user-switch-success-0016
pam-app-login ca-pamsc-kv-app-login-success-sso
pam-auth-failed ca-pamsc-csv-endpoint-login-fail-ldap
pam-auth-failed-1 ca-pamsc-csv-endpoint-login-fail-baduserid
pam-auth-successful ca-pamsc-csv-endpoint-login-success-loggedin
pam-event-1 ca-pamsc-kv-app-activity-admin
pam-event-2 ca-pamsc-kv-app-authentication-connection
pam-event-3 ca-pamsc-kv-app-activity-get
pam-event-4 ca-pamse-str-app-login-transactionlogin
pam-event-5 ca-pamsc-kv-app-logout-protocol
pam-event-6 ca-pamsc-kv-app-activity-put
pam-event-7 ca-pamsc-kv-app-activity-sessionrecording-1
pam-event-8 ca-pamsc-kv-app-activity-system
pam-logout ca-pamsc-kv-app-logout-success-logout
pam-logout-1 ca-pamsc-kv-app-logout-success-conntimedout
pam-logout-2 ca-pamsc-kv-app-logout-success-connclosed
pam-logout-3 ca-pamsc-kv-app-logout-success-connterminated
pam-remote-logon ca-pamsc-kv-rdp-traffic-success-connection
pam-system-info ca-pamsc-kv-app-activity-sessionrecording
pam360-app-login-ad manageengine-pam360-str-app-login-success-userloggedin
pam360-remote-session-ended manageengine-pam360-str-app-activity-success-sessionended
pam360-remote-session-started manageengine-pam360-str-endpoint-login-success-sessionstarted
pan-alert pan-wildfire-csv-alert-trigger-success-threadwildfire
pan-alert-1 pan-wildfire-csv-alert-trigger-success-wildfirevirus
pan-auth-failed pan-gp-csv-endpoint-authentication-fail-authenticationfailed
pan-auth-failed-1 pan-gp-csv-endpoint-authentication-fail-authfail
pan-auth-server-down pan-ngfw-csv-app-notification-serverdown
pan-auth-successful pan-gp-csv-endpoint-authentication-success-authsuccess
pan-auth-successful-1 pan-gp-csv-vpn-login-useridlogin
pan-auth-successful-2 pan-gp-csv-endpoint-authentication-success-panoramaauthsuccess
pan-authentication-userid-login pan-gp-csv-vpn-login-success-login-1
pan-azure-auth-attempt pan-gp-csv-app-authentication-authprofileazure
pan-azure-auth-successful pan-gp-csv-endpoint-login-success-system
pan-cef-alert pan-wildfire-kv-alert-trigger-success-wildfirethreat
pan-cef-alert-1 pan-wildfire-cef-alert-trigger-success-filethreat
pan-cef-alert-2 pan-wildfire-cef-alert-trigger-success-panos
pan-cef-alert-3 pan-wildfire-cef-alert-trigger-success-wildfirevirusthreat
pan-cef-alert-4 pan-wildfire-cef-alert-trigger-scan
pan-cef-alert-5 pan-wildfire-cef-alert-trigger-success-compliantrequest
pan-cef-alert-6 pan-wildfire-cef-alert-trigger-success-threat
pan-cef-alert-7 pan-wildfire-cef-alert-trigger-success-lsardeleteaccess
pan-config-change pan-ngfw-csv-configuration-modify-success-config
pan-data-alert pan-ngfw-csv-alert-trigger-success-data
pan-failed-vpn-login pan-ngfw-json-vpn-login-fail-failure
pan-file-alert pan-ngfw-json-alert-trigger-success-threatalert
pan-flood-alert pan-ngfw-csv-alert-trigger-success-flood
pan-fw-packet-logs pan-ngfw-kv-network-traffic-success-packetlog
pan-leef-network-alert pan-ngfw-leef-alert-trigger-success-syslogintegration
pan-logout pan-ngfw-csv-app-logout-logout
pan-ngfw-system-auth pan-ngfw-csv-app-authentication-success-general
pan-packet-network-connection pan-ngfw-csv-network-traffic-packet
pan-proxy pan-ngfw-csv-http-session-9999
pan-remote-logon pan-ngfw-csv-endpoint-login-success-system
pan-spyware-alert pan-ngfw-json-alert-trigger-success-spyware
pan-system pan-ngfw-csv-app-notification-system
pan-system-conn-status pan-ngfw-csv-app-notification-connstatus
pan-system-dhcp pan-ngfw-csv-dhcp-traffic-generalinformational
pan-system-dnsproxy pan-ngfw-csv-app-activity-dnsproxy
pan-system-event-1 pan-tesm-csv-policy-modify-success-agent
pan-system-event-2 pan-tesm-csv-app-notification-success-heartbeat
pan-system-event-3 pan-tesm-csv-service-state-modify-success-statuschange
pan-system-event-4 pan-tesm-csv-service-start-success-servicealive
pan-system-event-5 pan-tesm-csv-endpoint-stop-success-shutdown
pan-system-event-6 pan-tesm-csv-app-notification-success-validationfailed
pan-system-general pan-ngfw-csv-app-activity-general
pan-system-globalprotect pan-ngfw-csv-app-activity-globalprotect
pan-system-ha pan-ngfw-csv-app-activity-ha
pan-system-info pan-tesm-csv-alert-trigger-hipmatch
pan-system-info-1 pan-panorama-kv-app-activity-panoramaver
pan-system-ntpd pan-ngfw-csv-app-time-modify-ntpd
pan-system-ras pan-ngfw-csv-configuration-load-ras
pan-system-routing pan-ngfw-csv-configuration-routing-modify-success-routing
pan-system-satd pan-ngfw-csv-configuration-load-satd
pan-system-sslmgr pan-ngfw-csv-configuration-load-sslmgr
pan-system-tls pan-ngfw-csv-app-notification-success-systemtls
pan-system-url-filtering pan-ngfw-csv-app-notification-urlfiltering
pan-system-userid pan-ngfw-csv-app-notification-userid
pan-system-vpn pan-ngfw-csv-vpn-authentication-systemvpn
pan-system-wildfire pan-ngfw-csv-app-activity-wildfire
pan-traps-alert pan-tesm-str-alert-trigger-success-trapsagent
pan-url-alert pan-ngfw-csv-alert-trigger-success-url
pan-virus-alert pan-ngfw-mix-alert-trigger-success-virus
pan-virus-alert-1 pan-ngfw-json-alert-trigger-success-resetserver
pan-vpn-login-1 pan-ngfw-json-vpn-login-success-userid
pan-vpn-login-2 pan-gp-cef-vpn-login-success-loginuserid
pan-vpn-login-failed pan-gp-csv-vpn-login-fail-registfail
pan-vpn-logout pan-gp-csv-vpn-logout-success-logout
pan-vpn-logout-1 pan-ngfw-json-vpn-logout-success-logout
pan-vpn-logout-2 pan-gp-cef-vpn-logout-success-logoutuserid
pan-vulnerability-alert pan-ngfw-json-alert-trigger-success-vulnerability-1
pan-vulnerability-alert-2 pan-ngfw-json-alert-trigger-success-vulnerability-2
pan-wildfire-alert-1 pan-wildfire-json-alert-trigger-success-wildfire
paxton-badge-access paxton-net2door-kv-physical-location-access-paxtonnet2
pensando-flow-create amd-p-csv-network-session-flowcreate
pensando-flow-delete amd-p-csv-network-notification-success-flowdelete
perforce-app-activity perforce-p-str-app-activity-appactivity
perforce-app-activity-1 perforce-p-str-app-activity-success-sarver
pfsense-network-connection-failed pfsense-p-csv-network-traffic-fail-block
pfsense-network-connection-successful pfsense-p-csv-network-traffic-success-match
pgsql-db-query postgresql-p-json-database-query-success-databasequery
physical-badge-access amag-sac-kv-physical-location-access-eventcode
physical-badge-access-1 amag-sac-kv-physical-location-access-datetimeoftxn
physical-badge-access-2 badge-b-kv-physical-location-access-personname
physical-badge-access-3 siemens-s-kv-physical-location-access-direction
ping-app-login pingidentity-pi-cef-app-login-success-pingfederate
ping-app-login-4 pingidentity-pi-str-app-login-success-ssosuccess
ping-auth-attempt-1 pingidentity-pi-str-app-authentication-success-authattempt
ping-auth-attempt-2 pingidentity-pi-str-app-authentication-success-oauth
ping-auth-failed-1 pingidentity-pi-cef-endpoint-authentication-fail-authnattemptfail
ping-auth-failed-2 pingidentity-pi-cef-endpoint-authentication-fail-failure-1
ping-auth-failed-4 pingidentity-pi-str-endpoint-login-fail-tid
ping-auth-failed-5 pingidentity-pi-str-endpoint-login-fail-oauth
ping-auth-successful-1 pingidentity-pi-str-endpoint-authentication-success-authnattemptsuccess
ping-auth-successful-2 pingidentity-pi-str-endpoint-authentication-success-oauthsuccess
ping-auth-successful-4 pingidentity-pi-str-endpoint-login-success-authn
ping-auth-successful-5 pingidentity-pi-str-endpoint-login-success-oauth
ping-auth-successful-6 pingidentity-pi-str-endpoint-authentication-success-authnsessioncreated
ping-auth-successful-7 pingidentity-pi-str-endpoint-authentication-success-authsessionused
ping-auth-successful-8 pingidentity-pi-str-endpoint-login-success-stssuccess
ping-authentication-attempt pingidentity-pi-json-app-authentication-success-pingid
ping-authentication-attempt-1 pingidentity-pi-json-app-authentication-success-user
ping-authentication-attempt-2 pingidentity-pi-json-app-authentication-fail-unsuccessattempt
ping-authentication-attempt-3 pingidentity-pi-sk4-app-authentication-success-queue
ping-authentication-attempt-4 pingidentity-pi-sk4-app-authentication-success-delivery
ping-authentication-failed pingidentity-pi-json-app-authentication-fail-user
ping-authentication-failed-1 pingidentity-pi-json-app-authentication-fail-pingid
ping-authentication-successful pingidentity-pi-json-vpn-authentication-success-policy
ping-authentication-successful-1 pingidentity-pi-json-vpn-authentication-success-pingid
ping-failed-app-login-4 pingidentity-pi-str-app-login-fail-ssofailure
ping-federate-auth pingidentity-pi-json-endpoint-authentication-success-fail-idp
ping-logout pingidentity-pi-kv-app-logout-success-slo
ping-logout-1 pingidentity-pi-kv-app-logout-success-authsessiondelete
ping-system-info-1 pingidentity-pi-kv-app-notification-success-requesthandler
ping-system-info-2 pingidentity-pi-kv-app-notification-success-aborthandler
ping-system-info-3 pingidentity-pi-kv-app-notification-success-asynchronousrequest
placeholder-NGCIM-2384 microsoft-o365-sk4-app-file-operationworkload
pmp-account-switch passwordmngrpro-p-str-user-switch-success-pwdretrieved
pmp-app-login passwordmngrpro-p-str-app-login-userloggedin
pmp-auth-failed passwordmngrpro-p-str-app-authentication-fail-authenticationfail
pmp-auth-successful passwordmngrpro-p-str-app-authentication-passwordapproved
pmp-logout passwordmngrpro-p-str-app-logout-userloggedout
pmp-password-change passwordmngrpro-p-str-user-password-modify-success-pwdchanged
pmp-system-info-1 passwordmngrpro-p-str-password-checkin-passwordcheckedin
pmp-system-info-2 passwordmngrpro-p-str-password-checkout-passwordcheckedout
pmp-system-info-3 passwordmngrpro-p-str-user-password-create-passwordrequested
pmp-system-info-4 passwordmngrpro-p-str-user-modify-settingchanged
pmp-system-info-5 passwordmngrpro-p-str-password-download-resourceexported
portox-nac-failed-logon portox-clear-cef-endpoint-login-fail-accessdenied
portox-nac-failed-logon-1 portox-clear-cef-endpoint-login-fail-authreject
portox-nac-failed-logon-2 portox-clear-cef-endpoint-login-fail-accountnotfound
portox-nac-failed-logon-3 portox-clear-cef-endpoint-login-fail-macbypassdenied
portox-nac-logon portox-clear-cef-endpoint-login-success-deviceauthsuccess
portox-nac-logon-1 portox-clear-cef-endpoint-login-success-guestauthsuccess
postfix-dlp-email unix-postfix-csv-app-notification-postfix
postfix-dlp-email-from postfix-postfix-kv-email-queue
postgresql-database-login postgresql-p-csv-database-login-success-authentication
powersentry-app-activity powersentry-ps-str-app-activity-primaryhost
powersentry-app-login powersentry-ps-str-app-login-success-sentry
powersentry-failed-login powersentry-ps-str-app-login-fail-loginunsuccessfull
powersentry-logout powersentry-ps-str-app-logout-success-loggedout
powershell-4104 microsoft-evpowershell-str-script-execute-success-4104
powershell-800 "microsoft-evdnsserver-xml-process-create-success-800
powershell-800-syslog microsoft-evdnsserver-kv-process-create-success-800-1
powershell-800-syslog-1 microsoft-evdnsserver-kv-process-create-success-800
powershell-process-created microsoft-windows-kv-process-create-success-available
powershell-process-created-1 microsoft-windows-kv-process-create-success-started
powershell-process-created-2 microsoft-evpowershell-kv-process-create-success-executing
pro-file-object procad-p-json-app-activity-appactivity
progress-db-remote-logon progress-pdatabase-str-endpoint-login-success-742
proofpoint-dlp-alert proofpoint-casb-json-alert-trigger-success-dataleakage
proofpoint-dlp-email-from proofpoint-tappod-json-email-send-receive-sendmailfrom
proofpoint-dlp-email-to proofpoint-tappod-json-email-send-receive-sendmailto
proofpoint-email proofpoint-tappod-json-email-send-receive-rcpts
proofpoint-email-1 proofpoint-tap-json-email-envelope
proofpoint-email-2 proofpoint-tap-json-email-receive-fail-emailreceived
proofpoint-email-3 proofpoint-tap-sk4-email-routedirection
proofpoint-email-4 proofpoint-tappod-json-email-receive-fail-emailreceived
proofpoint-email-5 proofpoint-tappod-sk4-email-receive-fail-emailreceived
proofpoint-email-6 proofpoint-tappod-leef-email-resolvestatus
proofpoint-m1 proofpoint-tappod-cef-email-send-receive-envfrom
proofpoint-m10 proofpoint-pep-kv-alert-trigger-urldefense
proofpoint-m11 proofpoint-pep-kv-email-receive-envrcpt
proofpoint-m12 proofpoint-pep-kv-email-send-sendmail
proofpoint-m13 proofpoint-pep-kv-app-notification-checksubmsg
proofpoint-m14 proofpoint-pep-kv-app-activity-cmd
proofpoint-m15 proofpoint-tappod-cef-email-send-receive-runfrom
proofpoint-m2 proofpoint-tappod-cef-email-send-receive-datarcpt
proofpoint-m3 proofpoint-tappod-cef-email-send-receive-msg
proofpoint-m4 proofpoint-tappod-cef-email-send-receive-attachment
proofpoint-m5 proofpoint-tappod-cef-email-send-receive-run
proofpoint-m6 proofpoint-tappod-cef-email-send-receive-datafrom
proofpoint-m7 proofpoint-pep-kv-smtp-start-session
proofpoint-m8 proofpoint-pep-kv-smtp-close-disconnect
proofpoint-m9 proofpoint-pep-kv-app-notification-judge
proofpoint-security-alert proofpoint-casb-json-alert-trigger-success-suspiciouslogin
proofpoint-security-alert-1 proofpoint-casb-json-alert-trigger-success-severity
proofpoint-system-info proofpoint-tappod-sk4-app-notification-success-hostnotfound
proofpoint-system-info-1 proofpoint-tappod-sk4-app-notification-success-userunknown
prowatch-badge-access "honeywell-pw-xml-physical-location-access-evntdat
prowatch-badge-access-1 honeywell-pw-json-physical-location-access-success-badgeno
prowatch-badge-access-3 honeywell-pw-csv-physical-location-access-success-exabeam
proxysg-auth-failed-1 proxysg-p-kv-endpoint-login-fail-invalidcreds
proxysg-auth-failed-2 symantec-wss-str-endpoint-login-fail-auth
pulsesecure-account-deleted juniper-ps-str-user-delete-success-modified
pulsesecure-vpn-login juniper-ps-str-vpn-login-success-login