Consistec Caplon

Consistec Caplon: Real-time monitoring for networks, services and security with deep packet inspection, anomaly, port scan and C&C detection as well as SLA/KPI monitoring and flexible alarms.

Global Fields (4)

FieldType
ngs.id
Unique identifier for the log entry.
string
ngs.createdAt
Timestamp when the event was created locally.
pdate
ngs.indexedAt
Timestamp when the log was indexed into the SIEM.
pdate
ngs.source
Origin or source system of the log.
string

Reference-Specific Fields (39)

FieldType
consistec.caplon.src.mac
Source MAC address of the device initiating the connection or event.
string
consistec.caplon.device_product
Model or product identifier of the Consistec Caplon device.
string
consistec.caplon.cipher
Name of the encryption cipher used for securing the communication.
string
consistec.caplon.hierarchy
Device hierarchy or segment within the network topology.
string
consistec.caplon.vlan
VLAN identifier associated with the traffic flow or event.
string
consistec.caplon.network.transport
Underlying transport protocol (e.g., Ethernet, MPLS) used for the packet flow.
string
consistec.caplon.instance
Instance name or identifier for this particular Caplon collector or session.
string
consistec.caplon.device_vendor
Manufacturer or vendor name of the device that generated the log.
string
consistec.caplon.event_name
Descriptive name of the event or alert category.
text_general
consistec.caplon.network.application
Application protocol or service detected in the traffic (e.g., HTTP, FTP).
string
consistec.caplon.dst.mac
Destination MAC address of the packet or session.
string
consistec.caplon.dst.layer
OSI layer at which the destination interaction occurred.
string
consistec.caplon.src.layer
OSI layer at which the source interaction occurred.
string
consistec.caplon.category
High-level classification of the event type.
text_general
consistec.caplon.count
Count of occurrences for this event type in the reporting interval.
plong
consistec.caplon.dst.port
Destination port number of the network packet or flow.
plong
consistec.caplon.src.port
Source port number of the network packet or flow.
plong
consistec.caplon.network.vlan_id
Numeric VLAN ID associated with the traffic.
plong
consistec.caplon.severity
Severity level of the event on a predefined scale (e.g., 1-5).
plong
consistec.caplon.back.bytes
Number of bytes in the return (back) direction of the flow.
plong
consistec.caplon.main.packets
Number of packets in the main (forward) direction of the flow.
plong
consistec.caplon.back.packets
Number of packets in the return (back) direction of the flow.
plong
consistec.caplon.main.bytes
Number of bytes in the main (forward) direction of the flow.
plong
consistec.caplon.device_version
Firmware or software version of the Caplon device.
string
consistec.caplon.end
Timestamp marking the end of the observed session or event.
pdate
consistec.caplon.start
Timestamp marking the start of the observed session or event.
pdate
consistec.caplon.timestamp
Exact event timestamp as recorded by the Caplon device.
pdate
consistec.caplon.domain
Network domain or zone in which the event occurred.
string
consistec.caplon.targetName
Name of the target host or service affected by the event.
string
consistec.caplon.dnsDomainName
DNS domain name associated with the client or server host.
string
consistec.caplon.nbDomainName
NetBIOS domain name associated with the host.
string
consistec.caplon.dnsTreeName
DNS tree or forest name in Active Directory environments.
string
consistec.caplon.hostname
Hostname of the device that generated the log entry.
string
consistec.caplon.dnsComputerName
DNS computer name resolution for the source device.
string
consistec.caplon.nbComputerName
NetBIOS computer name of the source device.
string
consistec.caplon.dst.ip
Destination IPv4 or IPv6 address of the packet or session.
string
consistec.caplon.src.ip
Source IPv4 or IPv6 address of the packet or session.
string
consistec.caplon.username
Authenticated username associated with the session, if available.
string
consistec.caplon.message
Free-form text message or description provided by the device for this event.
text_general

Sample Log Event

Below is a representative JSON log entry showing key fields as they’re emitted by the system. Depending on the context of the event, some fields may be omitted if they’re not applicable.