Parsers and Generated Fields

Tag Fields Created by Parser fortinet-fortigate
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortigate
Source FieldCPS Field
source.ipclient.ip
source.portclient.port
Vendor.daddrdestination.address
Vendor.dst_hostdestination.address
Vendor.rcvdbytedestination.bytes
Vendor.dstcitydestination.geo.city_name
Vendor.dstcountrydestination.geo.country_name
Vendor.dstregiondestination.geo.region_name
Vendor.dstipdestination.ip
Vendor.remipdestination.ip
Vendor.tranipdestination.nat.ip
Vendor.tranportdestination.nat.port
Vendor.rcvdpktdestination.packets
Vendor.dst_portdestination.port
Vendor.dstportdestination.port
Vendor.remportdestination.port
Vendor.dstuserdestination.user.name
Vendor.xiddns.id
Vendor.qclassdns.question.class
Vendor.qnamedns.question.name
Vendor.qtypedns.question.type
Vendor.subjectemail.subject
Vendor.error_numerror.code
Vendor.errorerror.message
Vendor.actionevent.action
Vendor.eventtypeevent.action
Vendor.sess_durationevent.duration
Vendor.event_idevent.id
Vendor.eventidevent.id
Vendor.refevent.reference
Vendor.filetypefile.extension
Vendor.infectedfiletypefile.extension
Vendor.matchedfiletypefile.extension
Vendor.filenamefile.name
Vendor.infectedfilenamefile.name
Vendor.matchedfilenamefile.name
Vendor.filefile.path
Vendor.filesizefile.size
Vendor.infectedfilesizefile.size
Vendor.srcnamehost.name
Vendor.crlevelhost.risk.calculated_level
Vendor.crscorehost.risk.calculated_score
Vendor.levellog.level
source.bytesnetwork.bytes
Vendor.protonetwork.iana_number
source.packetsnetwork.packets
Vendor.dst_intobserver.egress.interface.name
Vendor.dstintfobserver.egress.interface.name
Vendor.dstintfroleobserver.egress.zone
Vendor.src_intobserver.ingress.interface.name
Vendor.srcintfobserver.ingress.interface.name
Vendor.srcintfroleobserver.ingress.zone
Vendor.devnameobserver.name
Vendor.devidobserver.serial_number
Vendor.appprocess.name
Vendor.catdescrule.category
Vendor.msg;rule.description
Vendor.commentrule.description
Vendor.logdescrule.description
Vendor.policyidrule.id
Vendor.policyidrule.id
Vendor.policynamerule.name
Vendor.applistrule.ruleset
Vendor.policytyperule.ruleset
Vendor.profilerule.ruleset
Vendor.poluuidrule.uuid
destination.ipserver.ip
destination.portserver.port
Vendor.sentbytesource.bytes
Vendor.locipsource.ip
Vendor.srcipsource.ip
Vendor.transipsource.nat.ip
Vendor.transportsource.nat.port
Vendor.sentpktsource.packets
Vendor.locportsource.port
Vendor.src_portsource.port
Vendor.srcportsource.port
Vendor.groupsource.user.group.name
Vendor.unauthusersource.user.name
Vendor.usersource.user.name
Vendor.ccertissuertls.client.issuer
tls.client.issuertls.client.x509.issuer.common_name[0]
Vendor.scertissuertls.server.issuer
tls.server.issuertls.server.x509.issuer.common_name[0]
Vendor.scertcnametls.server.x509.subject.common_name[0]
Vendor.urlurl.path
source.user.nameuser.name
Vendor.agentuser_agent.original
Vendor.dtypevulnerability.category[0]