Parsers and Generated Fields

Tag Fields Created by Parser checkpoint-ngfw
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser checkpoint-ngfw
Source FieldCPS FieldDescriptionMapping
Vendor.time, ts, Vendor.rt@timestampEvent timestampParsed from timestamp fields using various formats
source.ipclient.ipClient IP addressCopied from source.ip for application control logs
source.portclient.portClient portCopied from source.port for application control logs
Vendor.dst, Vendor.tls_server_host_namedestination.addressDestination addressCopied from destination fields
Vendor.server_outbound_bytes, Vendor.received_bytesdestination.bytesDestination byte countCopied from byte count fields
Vendor.destination_dns_hostname, Vendor.dst_machine_name, Vendor.http_host, Vendor.dst_domain_namedestination.domainDestination domainCopied from hostname fields (lowercase)
destination.addressdestination.ipDestination IP addressCopied from destination address with CIDR validation
Vendor.mac_destination_addressdestination.macDestination MACCopied from Vendor.mac_destination_address
Vendor.xlatedstdestination.nat.ipDestination NAT IPCopied from Vendor.xlatedst
Vendor.xlatedport, Vendor.xlatedport_svcdestination.nat.portDestination NAT portCopied from NAT port fields
Vendor.server_outbound_packetsdestination.packetsDestination packet countCopied from Vendor.server_outbound_packets
Vendor.service, Vendor.svc, Vendor.dptdestination.portDestination portCopied from service port fields
Vendor.todestination.user.emailDestination emailCopied from Vendor.to
Vendor.usercheck_incident_uiddestination.user.idDestination user IDCopied from Vendor.usercheck_incident_uid
Vendor.dst_user_namedestination.user.nameDestination usernameCopied from Vendor.dst_user_name with regex extraction
Vendor.domain_namedns.question.nameDNS query nameCopied from Vendor.domain_name
Vendor.dns_typedns.question.typeDNS query typeCopied from Vendor.dns_type
Vendor.dns_message_typedns.typeDNS message typeCopied from Vendor.dns_message_type
Noneecs.versionECS schema versionStatic value: 9.2.0
Vendor.bccemail.bcc.address[]Email BCC addressesArray from Vendor.bcc (lowercase)
Vendor.ccemail.cc.address[]Email CC addressesArray from Vendor.cc (lowercase)
Vendor.delivery_timeemail.delivery_timestampEmail delivery timestampCopied from Vendor.delivery_time
source.user.email, Vendor.mime_fromemail.from.address[]Email sender addressesArray from email addresses (lowercase)
Vendor.email_queue_idemail.local_idEmail local IDCopied from Vendor.email_queue_id
Vendor.email_message_idemail.message_idEmail message IDCopied from Vendor.email_message_id
Vendor.email_subjectemail.subjectEmail subject lineCopied from Vendor.email_subject
destination.user.email, Vendor.mime_toemail.to.address[]Email recipient addressesArray from email addresses (lowercase)
Vendor.action, Vendor.actevent.actionAction takenMapped from Vendor.action or act with numeric conversion
Various vendor fieldsevent.category[]Event categoriesArray populated based on event type and action
Vendor.productevent.datasetEvent datasetGenerated from product name
Vendor.last_detection, Vendor.lastupdatetime, Vendor.last_hit_timeevent.endEvent end timeCopied from end time fields
Vendor.loguidevent.idUnique log identifierCopied from Vendor.loguid
Noneevent.kindEvent kindStatic value: event
Noneevent.moduleEvent moduleStatic value: ngfw
Vendor.audit_status, Vendor.operation_results, Vendor.descriptionevent.outcomeEvent outcomeDetermined from audit status and results
Vendor.action_reason, Vendor.additional_info, Vendor.description, Vendor.informationevent.reasonEvent reasonCopied from description or additional info
Vendor.app_risk, Vendor.cp_app_riskevent.risk_scoreApplication risk scoreCopied from risk fields
Vendor.sequencenumevent.sequenceEvent sequence numberCopied from Vendor.sequencenum
Vendor.severityevent.severityEvent severity levelMapped from Vendor.severity values
Vendor.start_time, Vendor.first_detection, Vendor.creation_timeevent.startEvent start timeCopied from start time fields
Various vendor fieldsevent.type[]Event typesArray populated based on event action
Vendor.packet_captureevent.urlURL to packet captureCopied from Vendor.packet_capture
Vendor.file_md5file.hash.md5File MD5 hashCopied from Vendor.file_md5 (lowercase)
Vendor.file_sha1file.hash.sha1File SHA1 hashCopied from Vendor.file_sha1 (lowercase)
Vendor.file_sha256file.hash.sha256File SHA256 hashCopied from Vendor.file_sha256 (lowercase)
Vendor.file_idfile.inodeFile inode numberCopied from Vendor.file_id
Vendor.file_name, Vendor.dlp_file_namefile.nameFile nameCopied from file name fields
Vendor.file_sizefile.sizeFile sizeCopied from Vendor.file_size
Vendor.file_typefile.typeFile typeCopied from Vendor.file_type
Vendor.user_groupgroup.nameGroup nameCopied from Vendor.user_group
Vendor.endpoint_iphost.ip[]Host IP addressesArray from Vendor.endpoint_ip
Vendor.os_namehost.os.nameHost OS nameCopied from Vendor.os_name
Vendor.os_versionhost.os.versionHost OS versionCopied from Vendor.os_version
Vendor.method, Vendor.requestMethodhttp.request.methodHTTP request methodCopied from method fields
Vendor.referrerhttp.request.referrerHTTP referrerCopied from Vendor.referrer
Vendor.applicationnetwork.applicationNetwork applicationCopied from Vendor.application (lowercase)
source.bytes, destination.bytes, Vendor.bytesnetwork.bytesNetwork bytesCalculated from source and destination bytes
source.ip, destination.ip, source.port, destination.port, network.iana_number, Vendor.icmp_code, Vendor.icmp_typenetwork.community_idNetwork community IDGenerated using communityId function
Vendor.ifdir, Vendor.deviceDirectionnetwork.directionNetwork directionMapped from direction fields
Vendor.protonetwork.iana_numberIANA protocol numberCopied from Vendor.proto
Vendor.layer_namenetwork.nameNetwork layer nameCopied from Vendor.layer_name
Vendor.packetsnetwork.packetsNetwork packetsCopied from Vendor.packets
Vendor.protocol, Vendor.service_idnetwork.protocolNetwork protocolDetected from protocol and service fields
network.iana_numbernetwork.transportNetwork transport protocolMapped from network.iana_number
Vendor.server_outbound_interface, Vendor.client_outbound_interface, Vendor.ifnameobserver.egress.interface.nameEgress interface nameCopied from interface fields
Vendor.outzoneobserver.egress.zoneEgress zoneCopied from Vendor.outzone
Vendor.client_inbound_interface, Vendor.ifnameobserver.ingress.interface.nameIngress interface nameCopied from interface fields
Vendor.inzone, Vendor.security_outzoneobserver.ingress.zoneIngress zoneCopied from zone fields
Vendor.origin_ip, Vendor.endpoint_ip, Vendor.originobserver.ip[]Observer IP addressesArray from IP fields
Vendor.mac_addressobserver.mac[]Observer MAC addressesArray from Vendor.mac_address (uppercase)
Vendor.originsicname.CN, Vendor.originsicname.cnobserver.nameObserver nameExtracted from parsed originsicname CN field
Vendor.productobserver.productObserver productCopied from Vendor.product
Noneobserver.typeObserver typeStatic value: firewall
Noneobserver.vendorObserver vendorStatic value: checkpoint
Vendor.update_versionobserver.versionObserver versionCopied from Vendor.update_version
Vendor.process_md5process.hash.md5Process MD5 hashCopied from Vendor.process_md5 (lowercase)
Vendor.process_nameprocess.nameProcess nameCopied from Vendor.process_name
Vendor.parent_process_md5process.parent.hash.md5Parent process MD5 hashCopied from Vendor.parent_process_md5 (lowercase)
Vendor.parent_process_nameprocess.parent.nameParent process nameCopied from Vendor.parent_process_name
Vendor.matched_category, Vendor.categoriesrule.categoryRule categoryCopied from category fields
Vendor.malware_actionrule.descriptionRule descriptionCopied from Vendor.malware_action
Vendor.malware_rule_id, Vendor.app_rule_idrule.idRule IDCopied from rule ID fields
Vendor.objectname, Vendor.rule_name, Vendor.malware_rule_name, Vendor.app_rule_name, Vendor.dlp_rule_namerule.nameRule nameCopied from rule name fields
Vendor.smartdefence_profile, Vendor.policy, Vendor.__policy_id_tag.policy_namerule.rulesetRule rulesetCopied from ruleset fields including parsed policy name
Vendor.rule_uid, Vendor.dlp_rule_uid, Vendor.nat_rule_uidrule.uuidRule UUIDCopied from rule UID fields including NAT rule UID
destination.ipserver.ipServer IP addressCopied from destination.ip for application control logs
destination.portserver.portServer portCopied from destination.port for application control logs
Vendor.srcsource.addressSource addressCopied from Vendor.src
Vendor.client_outbound_bytes, Vendor.sent_bytessource.bytesSource byte countCopied from byte count fields
Vendor.src_machine_namesource.domainSource domainCopied from machine name (lowercase)
Vendor.src, Vendor.client_ipsource.ipSource IP addressCopied from source IP fields with CIDR validation
Vendor.mac_source_addresssource.macSource MAC addressCopied from Vendor.mac_source_address
Vendor.xlatesrc, Vendor.proxy_src_ipsource.nat.ipSource NAT IPCopied from NAT source fields
Vendor.xlatesport, Vendor.xlatesport_svcsource.nat.portSource NAT portCopied from NAT port fields
Vendor.client_outbound_packetssource.packetsSource packet countCopied from Vendor.client_outbound_packets
Vendor.s_port, Vendor.spt, Vendor.sport_svcsource.portSource portCopied from port fields
Vendor.fromsource.user.emailSource email addressExtracted from Vendor.from if contains @
Vendor.src_user_groupsource.user.group.nameSource user groupCopied from Vendor.src_user_group
Vendor.uidsource.user.idSource user IDCopied from Vendor.uid
Vendor.administrator, Vendor.src_user_namesource.user.nameSource usernameCopied from user name fields with regex extraction
Vendor.client_to_gateway_cipherstls.cipherTLS cipherCopied from Vendor.client_to_gateway_ciphers
Vendor.client_to_gateway_tls_ver_tls.versionTLS versionCopied from Vendor.client_to_gateway_tls_ver_
Vendor.session_uidtransaction.idTransaction IDCopied from Vendor.session_uid
Vendor.http_hosturl.domainURL domainCopied from Vendor.http_host (lowercase)
Vendor.url, Vendor.resourceurl.originalOriginal URLCopied from URL fields
Vendor.useruser.nameUsernameCopied from Vendor.user with regex extraction
Vendor.web_client_typeuser_agent.nameUser agent nameCopied from Vendor.web_client_type
Vendor.user_agentuser_agent.originalOriginal user agentCopied from Vendor.user_agent
Vendor.industry_referencevulnerability.idVulnerability IDCopied from Vendor.industry_reference