Parsers and Generated Fields

Tag Fields Created by Parser checkpoint-ngfw
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser checkpoint-ngfw
Source FieldCPS Field
Vendor.received_bytesdestination.bytes
Vendor.server_outbound_bytesdestination.bytes
Vendor.dstdestination.ip
Vendor.mac_destination_addressdestination.mac
Vendor.xlatedstdestination.nat.ip
Vendor.xlatedportdestination.nat.port
Vendor.xlatedport_svcdestination.nat.port
Vendor.server_outbound_packetsdestination.packets
Vendor.servicedestination.port
Vendor.svcdestination.port
Vendor.todestination.user.email
Vendor.usercheck_incident_uiddestination.user.id
Vendor.dst_user_namedestination.user.name
Vendor.domain_namedns.question.name
Vendor.dns_typedns.question.type
Vendor.dns_message_typedns.type
Vendor.delivery_timeemail.delivery_timestamp
Vendor.email_queue_idemail.local_id
Vendor.email_message_idemail.message_id
Vendor.email_subjectemail.subject
Vendor.action;event.action
Vendor.last_detectionevent.end
Vendor.lastupdatetimeevent.end
Vendor.loguidevent.id
Vendor.additional_infoevent.reason
Vendor.descriptionevent.reason
Vendor.informationevent.reason
Vendor.session_descriptionevent.reason
Vendor.app_riskevent.risk_score
Vendor.sequencenumevent.sequence
Vendor.severityevent.severity
Vendor.first_detectionevent.start
Vendor.start_timeevent.start
Vendor.packet_captureevent.url
Vendor.file_idfile.inode
Vendor.dlp_file_namefile.name
Vendor.file_namefile.name
Vendor.file_sizefile.size
Vendor.file_typefile.type
Vendor.user_groupgroup.name
Venodr.endpoint_iphost.ip[0]
Vendor.os_namehost.os.name
Vendor.os_versionhost.os.version
Vendor.methodhttp.request.method
Vendor.referrerhttp.request.referrer
Vendor.applicationnetwork.application
Vendor.service_idnetwork.application
source.bytesnetwork.bytes
Vendor.bytesnetwork.bytes
Vendor.conn_directionnetwork.direction
Vendor.ifdirnetwork.direction
Vendor.protonetwork.iana_number
Vendor.layer_namenetwork.name
Vendor.packetsnetwork.packets
Vendor.client_outbound_interface;observer.egress.interface.name
Vendor.ifname;observer.egress.interface.name
Vendor.server_outbound_interfaceobserver.egress.interface.name
Vendor.outzoneobserver.egress.zone
Vendor.client_inbound_interface;observer.ingress.interface.name
Vendor.ifname;observer.ingress.interface.name
Vendor.client_inbound_interfaceobserver.ingress.interface.name
Vendor.inzoneobserver.ingress.zone
Vendor.security_outzoneobserver.ingress.zone
Vendor.origin_ipobserver.ip[0]
Vendor.endpoint_ipobserver.ip[1]
Vendor.originobserver.name
Vendor.productobserver.product
Vendor.typeobserver.type
Vendor.update_versionobserver.version
Vendor.process_nameprocess.name
Vendor.parent_process_nameprocess.parent.name
Vendor.categoriesrule.category
Vendor.matched_categoryrule.category
Vendor.malware_actionrule.description
Vendor.app_rule_idrule.id
Vendor.malware_rule_idrule.id
Vendor.app_rule_namerule.name
Vendor.dlp_rule_namerule.name
Vendor.malware_rule_namerule.name
Vendor.objectnamerule.name
Vendor.rule_namerule.name
Vendor.policyrule.ruleset
Vendor.smartdefence_profilerule.ruleset
Vendor.dlp_rule_uidrule.uuid
Vendor.rule_uidrule.uuid
Vendor.client_outbound_bytessource.bytes
Vendor.sent_bytessource.bytes
Vendor.client_ipsource.ip
Vendor.srcsource.ip
Vendor.mac_source_addresssource.mac
Vendor.xlatesrcsource.nat.ip
Vendor.xlatesportsource.nat.port
Vendor.xlatesport_svcsource.nat.port
Vendor.client_outbound_packetssource.packets
Vendor.s_portsource.port
Vendor.sport_svcsource.port
Vendor.fromsource.user.email
Vendor.src_user_groupsource.user.group.name
Vendor.uidsource.user.id
Vendor.administratorsource.user.name
Vendor.src_user_namesource.user.name
Vendor.session_uidtransaction.id
Vendor.resourceurl.original
Vendor.urlurl.original
Vendor.useruser.name
Vendor.web_client_typeuser_agent.name
Vendor.user_agentuser_agent.original
Vendor.industry_referencevulnerability.id