This documentation contains work-in-progress information for future Elastic Stack and Cloud releases. Use the version selector to view supported release docs. It also contains some Elastic Cloud serverless information. Check out our serverless docs for more details.
Autonomous System Fields
editAutonomous System Fields
editAn autonomous system (AS) is a collection of connected Internet Protocol (IP) routing prefixes under the control of one or more network operators on behalf of a single administrative entity or domain that presents a common, clearly defined routing policy to the internet.
Autonomous System Field Details
editField | Description | Level |
---|---|---|
Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet. type: long example: |
extended |
|
Organization name. type: keyword Multi-fields:
example: |
extended |
Field Reuse
editThe as
fields are expected to be nested at:
-
client.as
-
destination.as
-
server.as
-
source.as
-
threat.enrichments.indicator.as
-
threat.indicator.as
Note also that the as
fields are not expected to be used directly at the root of the events.