Deprecated Parsers
CrowdStrike maintains a number of default parsers. When a parser is marked deprecated, we no longer maintain and update that parser. We strongly recommend using the latest version of default parsers for your data connector. Using a deprecated parser won’t stop data ingestion but can result in deteriorated detection coverage.
To ensure best detection coverage for your environment, follow these steps:
-
Ensure that all correlation rules, dashboards, scheduled searches, and saved queries running in your environment that use the
#type=<parser_name>field are updated to use CPS compliant parser fields#Vendor=<vendor_name> | #event.module=<product_name>. For example, if you have a saved query that uses the#type=vectra-ecs, update this query to use the fields#Vendor=vectra | #event.module=braininstead. If a vendor supports more than one product, you can run queries for multiple products that use the same parser. For example, to get results for multiple Akamai products that are using theakamai-zerotrustparser, run this query:#Vendor=akamai | #event.module=eaa OR #event.module=sia OR #event.module=mfa OR #event.module=guardicore.- Tip: To look up
#Vendorand#event.modulefields for a parser, go to Next-Gen SIEM > Log management > Advanced event search and searchgroupBy(#Vendor). Use the vendor value returned and search for#Vendor=<vendor_value> | groupby(#event.module). For example, to get the#VendorCPS field for the Vectra AI parser, search forgroupBy(vectra)which returns the valuevectraand to get the#event.modulefield values, search#Vendor=vectra | groupBy(#event.module).
- Tip: To look up
-
Ensure that your data connectors are using the latest parsers. To update your connector, see Edit a connection. To see the default parser for each connector, see Third-Party Data Sources.
This table lists deprecated parsers and the corresponding default parsers we recommend for your data connectors:
| Deprecated parser | Default parser (Recommended) |
|---|---|
| 1password | 1password-enterprise |
| abnormal_security_ecs | abnormal-emailsecurity |
| alteon-syslog | radware-alteon |
| apm-syslog | f5networks-bigip |
| asec-json | akamai-asec |
| asimily-iomt-json | asimily-iomt |
| azuread-ecs | microsoft-azure-ad |
| cef-latest | claroty-ctd |
| centrix-iot-json | armis-centrixiot |
| cisco-ise-syslog | cisco-ise |
| cisco_seg_ecs | cisco-seg |
| ciscoasa-ecs | cisco-asa |
| ciscoumbrella | cisco-umbrella |
| citrix-netscaler-syslog, citrix-netscaler-waf-cef | citrix-netscaler-adc |
| clearpass-syslog | aruba-clearpass |
| cloudflareone-ecs | cloudflare-one |
| cloudtrail | aws-cloudtrail |
| corelight-ecs | corelight-ids |
| corelight-json | corelight-ids |
| cwaf-cef | imperva-cloudwaf |
| deception | zscaler-deception |
| dlp-cef | forcepoint-dlp |
| duo-activity-json, duo-admin-json, duo-authentication-json, duo-telephony-json, duo-trustmonitor-json | cisco-duo |
| extrahop-ecs | extrahop-revealx360 |
| fireeye-nx | trellix-fireeye-nx |
| firepower-syslog | cisco-firepower |
| forgerock-ecs | forgerock-identity |
| fortimail | fortinet-fortimail |
| fortinet-ecs | fortinet-fortigate |
| fsx-xml | aws-fsx |
| Google_Chrome_Enterprise | google-chrome-enterprise |
| guardduty-json | aws-guardduty |
| haproxy-syslog | haproxy |
| isilon-syslog | dell-isilon |
| island | island-enterprisebrowser |
| menlo-ecs | menlo-msip |
| microsoft_defender | microsoft-defendero365-graphapi |
| mimecast-ecs | mimecast-emailsecurity |
| ms-defender-graph-ecs | microsoft-defendero365-graphapi |
| ms-defender-stream-ecs | microsoft-defendero365-eventhubs |
| microsoft-windows-dhcpserver | microsoft-windows-dhcp-server |
| netskope-ecs | netskope-sse |
| nozomi-syslog | nozomi-ids |
| obsidian-json | obsidian-securitydata |
| okta-ecs | okta-sso |
| onelogin-json | oneidentity-onelogin |
| paloalto-ecs | paloalto-ngfw |
| paloalto-firewall-syslog | paloalto-ngfw |
| pfsense-syslog | netgate-pfsense |
| ping-ecs | pingidentity-pingone |
| prisma-sd-wan | paloalto-prisma-sdwan |
| proofpoint-tap-ecs | proofpoint-tap |
| rubrik-json | rubrik-securitycloud |
| s3access-space-delimited | aws-s3serveraccess |
| skyhigh-ecs | skyhigh-sse |
| srx-syslog | juniper-srx |
| syslog-utc | broadcom-proxysg |
| syslog-utc | cisco-ios |
| syslog-utc | infoblox-nios |
| sysmon | microsoft-sysmon |
| tausight-json | tausight-ephi |
| umbrella | cisco-umbrella |
| vectra-ecs | vectra-brain |
| vmware-esxi-ecs | vmware-esxi |
| vpcflow_default | aws-vpcflow |
| waf-json | aws-waf |
| windows-dhcp-client | microsoft-windows-dhcp-client |
| windows-dhcp-server-csv | microsoft-windows-dhcp-server |
| windows-dns | microsoft-windows-dns |
| zerotrust-json | cloudflare-one |
| zscalernss-dns, zscalernss-fw, zscalernss-tunnel, zscalernss-web | zscaler-internetaccess |
| zscaler-ecs | zscaler-internetaccess |
| zscaler-zpa-app-connector-status-json, zscaler-zpa-app-protection-json, zscaler-zpa-audit-json, zscaler-zpa-browser-access-json, zscaler-zpa-user-activity-json, zscaler-zpa-user-status-json | zscaler-privateaccess |
| ai_analyst_alert-syslog, model_breach_alert-syslog, system_status_alert-syslog | darktrace-detect |