Parsers and Generated Fields

Tag Fields Created by Parser checkpoint-ngfw
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser checkpoint-ngfw
Source FieldCPS Field
Vendor.received_bytes;destination.bytes
Vendor.server_outbound_bytes;destination.bytes
Vendor.dstdestination.ip
Vendor.mac_destination_addressdestination.mac
Vendor.xlatedst;destination.nat.ip
Vendor.xlatedport;destination.nat.port
Vendor.xlatedport_svc;destination.nat.port
Vendor.server_outbound_packetsdestination.packets
Vendor.service;destination.port
Vendor.svc;destination.port
Vendor.service_namedestination.service.name
Vendor.todestination.user.email
Vendor.usercheck_incident_uiddestination.user.id
Vendor.dst_user_namedestination.user.name
Vendor.domain_namedns.question.name
Vendor.dns_typedns.question.type
Vendor.dns_message_typedns.type
Vendor.delivery_timeemail.delivery_timestamp
Vendor.email_queue_idemail.local_id
Vendor.email_message_idemail.message_id
Vendor.email_subjectemail.subject
Vendor.action;event.action
Vendor.last_detection;event.end
Vendor.lastupdatetime;event.end
Vendor.loguidevent.id
Vendor.additional_infoevent.reason
Vendor.descriptionevent.reason
Vendor.description;event.reason
Vendor.information;event.reason
Vendor.session_description;event.reason
Vendor.app_riskevent.risk_score
Vendor.sequencenumevent.sequence
Vendor.severityevent.severity
Vendor.first_detection;event.start
Vendor.start_time;event.start
Vendor.packet_captureevent.url
Vendor.file_idfile.inode
Vendor.dlp_file_name;file.name
Vendor.file_name;file.name
Vendor.file_sizefile.size
Vendor.file_typefile.type
Vendor.user_groupgroup.name
Venodr.endpoint_iphost.ip[0]
Vendor.os_namehost.os.name
Vendor.os_versionhost.os.version
Vendor.methodhttp.request.method
Vendor.referrerhttp.request.referrer
Vendor.applicationnetwork.app_name
Vendor.service_idnetwork.application
Vendor.bytesnetwork.bytes
source.bytesnetwork.bytes
Vendor.conn_direction;network.direction
Vendor.ifdirnetwork.direction
Vendor.protonetwork.iana_number
Vendor.layer_namenetwork.name
Vendor.packetsnetwork.packets
Vendor.client_outbound_interface;observer.egress.interface.name
Vendor.ifname;observer.egress.interface.name
Vendor.server_outbound_interfaceobserver.egress.interface.name
Vendor.outzoneobserver.egress.zone
Vendor.client_inbound_interfaceobserver.ingress.interface.name
Vendor.client_inbound_interface;observer.ingress.interface.name
Vendor.ifname;observer.ingress.interface.name
Vendor.inzone;observer.ingress.zone
Vendor.security_outzone;observer.ingress.zone
Vendor.origin_ipobserver.ip[0]
Vendor.endpoint_ipobserver.ip[1]
Vendor.originobserver.name
Vendor.productobserver.product
Vendor.typeobserver.type
Vendor.update_versionobserver.version
Vendor.process_nameprocess.name
Vendor.parent_process_nameprocess.parent.name
Vendor.categories;rule.category
Vendor.matched_category;rule.category
Vendor.malware_actionrule.description
Vendor.app_rule_id;rule.id
Vendor.malware_rule_id;rule.id
Vendor.app_rule_name;rule.name
Vendor.dlp_rule_name;rule.name
Vendor.malware_rule_name;rule.name
Vendor.objectname;rule.name
Vendor.rule_name;rule.name
Vendor.policy;rule.ruleset
Vendor.smartdefence_profile;rule.ruleset
Vendor.dlp_rule_uid;rule.uuid
Vendor.rule_uid;rule.uuid
Vendor.client_outbound_bytes;source.bytes
Vendor.sent_bytes;source.bytes
Vendor.client_ip;source.ip
Vendor.src;source.ip
Vendor.mac_source_addresssource.mac
Vendor.xlatesrc;source.nat.ip
Vendor.xlatesportsource.nat.port
Vendor.xlatesport_svcsource.nat.port
Vendor.client_outbound_packetssource.packets
Vendor.s_portsource.port
Vendor.sport_svcsource.port
Vendor.fromsource.user.email
Vendor.src_user_groupsource.user.group.name
Vendor.uidsource.user.id
Vendor.administrator;source.user.name
Vendor.src_user_name;source.user.name
Vendor.session_uidtransaction.id
Vendor.resource;url.original
Vendor.url;url.original
Vendor.useruser.name
Vendor.web_client_typeuser_agent.name
Vendor.user_agentuser_agent.original
Vendor.industry_referencevulnerability.id