Parsers and Generated Fields

Tag Fields Created by Parser checkpoint-ngfw
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser checkpoint-ngfw
Source FieldLogScale Repository Field
Vendor.webagent.name
Vendor.useragent.original
Vendor.receiveddestination.bytes
Vendor.serverdestination.bytes
destination.ipdestination.geo
Vendor.dstdestination.ip
Vendor.macdestination.mac
Vendor.xlatedstdestination.nat.ip
Vendor.xlatedportdestination.nat.port
Vendor.serverdestination.packets
Vendor.servicedestination.port
Vendor.servicedestination.service.name
Vendor.todestination.user.email
Vendor.usercheckdestination.user.id
Vendor.iddns.id
Vendor.domaindns.question.name
Vendor.dnsdns.question.type
Vendor.dnsdns.type
Vendor.emailemail.subject
Vendor.actionevent.action
Vendor.lastevent.end
Vendor.lastupdatetimeevent.end
Vendor.loguidevent.id
Vendor.sequencenumevent.sequence
Vendor.severityevent.severity
Vendor.firstevent.start
Vendor.startevent.start
Vendor.packetevent.url
Vendor.filefile.inode
Vendor.dlpfile.name
Vendor.filefile.name
Vendor.filefile.size
Vendor.filefile.type
Vendor.usergroup.name
Vendor.oshost.os.name
Vendor.oshost.os.version
Vendor.methodhttp.request.method
Vendor.referrerhttp.request.referrer
Vendor.emailid
Vendor.applicationname
Vendor.servicenetwork.application
Vendor.bytesnetwork.bytes
source.bytesnetwork.bytes
Vendor.ifdirnetwork.direction
Vendor.layernetwork.name
Vendor.packetsnetwork.packets
Vendor.protonumber
Vendor.clientobserver.egress.interface.name
Vendor.ifnameobserver.egress.interface.name
Vendor.outzoneobserver.egress.zone
Vendor.clientobserver.ingress.interface.name
Vendor.ifnameobserver.ingress.interface.name
Vendor.inzoneobserver.ingress.zone
Vendor.securityobserver.ingress.zone
Vendor.originobserver.ip[0]
Vendor.endpointobserver.ip[1]
Vendor.originobserver.name
Vendor.productobserver.product
Vendor.typeobserver.type
Vendor.updateobserver.version
Vendor.processprocess.name
Vendor.parentprocess.parent.name
Vendor.categoriesrule.category
Vendor.matchedrule.category
Vendor.malwarerule.description
Vendor.apprule.id
Vendor.malwarerule.id
Vendor.apprule.name
Vendor.dlprule.name
Vendor.malwarerule.name
Vendor.objectnamerule.name
Vendor.rulerule.name
Vendor.policyrule.ruleset
Vendor.smartdefencerule.ruleset
Vendor.dlprule.uuid
Vendor.rulerule.uuid
Vendor.appscore
Vendor.clientsource.bytes
Vendor.sentsource.bytes
source.ipsource.geo
Vendor.clientsource.ip
Vendor.srcsource.ip
Vendor.macsource.mac
Vendor.xlatesrcsource.nat.ip
Vendor.xlatesportsource.nat.port
Vendor.clientsource.packets
Vendor.ssource.port
Vendor.fromsource.user.email
Vendor.srcsource.user.group.name
Vendor.uidsource.user.id
Vendor.administratorsource.user.name
Vendor.srcsource.user.name
Vendor.deliverytimestamp
Vendor.resourceurl.original
Vendor.urlurl.original
Vendor.industryvulnerability.id