Parsers and Generated Fields

Tag Fields Created by Parser fortinet-fortigate
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortigate
Vendor FieldCPS FieldDescription
`dns.resolved_ip[]`ArrayVendor.ipaddr
`email.from.address[]`ArrayVendor.collectedemail, Vendor.from
`email.to.address[]`ArrayVendor.dstcollectedemail, Vendor.recipient
`event.category[]`ArrayVendor.type, Vendor.subtype, Vendor.action, Vendor.logdesc
`event.type[]`ArrayVendor.type, Vendor.action, Vendor.subtype
`tls.client.x509.issuer.common_name[]`ArrayVendor.ccertissuer
`tls.server.x509.issuer.common_name[]`ArrayVendor.scertissuer
`tls.server.x509.subject.common_name[]`ArrayVendor.scertcname
`vulnerability.category[]`ArrayVendor.dtype
`network.bytes`CalculatedVendor.sentbyte, Vendor.rcvdbyte
`network.packets`CalculatedVendor.sentpkt, Vendor.rcvdpkt
`destination.address`ConditionalVendor.daddr, Vendor.dst_host, Vendor.dstname
`destination.port`ConditionalVendor.dstport, Vendor.dst_port, Vendor.remport
`event.dataset`ConditionalVendor.type, Vendor.subtype
`event.outcome`ConditionalVendor.type, Vendor.action, Vendor.status, Vendor.result, Vendor.logdesc, Vendor.reason, Vendor.subtype
`rule.description`ConditionalVendor.logdesc, Vendor.comment, Vendor.msg
`rule.ruleset`ConditionalVendor.policytype, Vendor.applist, Vendor.profile
`source.port`ConditionalVendor.srcport, Vendor.locport, Vendor.src_port
`client.ip`CopiedVendor.srcip, Vendor.remip, Vendor.locip
`client.port`CopiedVendor.srcport, Vendor.locport, Vendor.src_port
`destination.bytes`CopiedVendor.rcvdbyte
`destination.geo.city_name`CopiedVendor.dstcity
`destination.geo.country_name`CopiedVendor.dstcountry
`destination.geo.region_name`CopiedVendor.dstregion
`destination.ip`CopiedVendor.dstip
`destination.nat.ip`CopiedVendor.tranip
`destination.nat.port`CopiedVendor.tranport
`destination.packets`CopiedVendor.rcvdpkt
`destination.user.name`CopiedVendor.dstuser
`dns.id`CopiedVendor.xid
`dns.question.class`CopiedVendor.qclass
`dns.question.name`CopiedVendor.qname
`dns.question.type`CopiedVendor.qtype
`email.cc.address[0]`CopiedVendor.cc
`email.sender.address`CopiedVendor.sender
`email.subject`CopiedVendor.subject
`error.code`CopiedVendor.error_num
`error.message`CopiedVendor.error
`event.action`CopiedVendor.action, Vendor.eventtype
`event.duration`CopiedVendor.sess_duration
`event.id`CopiedVendor.event_id, Vendor.eventid
`event.reason`CopiedVendor.reason
`event.reference`CopiedVendor.ref
`file.extension`CopiedVendor.filetype, Vendor.infectedfiletype, Vendor.matchedfiletype
`file.name`CopiedVendor.filename, Vendor.infectedfilename, Vendor.matchedfilename
`file.path`CopiedVendor.file
`file.size`CopiedVendor.filesize, Vendor.infectedfilesize
`host.name`CopiedVendor.srcname
`host.risk.calculated_level`CopiedVendor.crlevel
`host.risk.calculated_score`CopiedVendor.crscore
`http.request.method`CopiedVendor.httpmethod, Vendor.method
`http.response.status_code`CopiedVendor.status
`log.level`CopiedVendor.level
`message`CopiedVendor.msg
`network.application`CopiedVendor.app
`network.iana_number`CopiedVendor.proto
`observer.egress.interface.name`CopiedVendor.dstintf, Vendor.dst_int
`observer.egress.zone`CopiedVendor.dstintfrole
`observer.ingress.interface.name`CopiedVendor.srcintf, Vendor.src_int
`observer.ingress.zone`CopiedVendor.srcintfrole
`observer.name`CopiedVendor.devname
`observer.serial_number`CopiedVendor.devid, Vendor.device_id
`process.name`CopiedVendor.app
`rule.category`CopiedVendor.catdesc
`rule.id`CopiedVendor.policyid
`rule.name`CopiedVendor.policyname, Vendor.attack
`rule.uuid`CopiedVendor.poluuid
`server.ip`CopiedVendor.dstip
`server.port`CopiedVendor.dstport, Vendor.dst_port, Vendor.remport
`source.bytes`CopiedVendor.sentbyte
`source.domain`CopiedVendor.srcdomain
`source.geo.country_name`CopiedVendor.srccountry
`source.ip`CopiedVendor.srcip, Vendor.remip, Vendor.locip
`source.mac`CopiedVendor.srcmac, Vendor.source_mac
`source.nat.ip`CopiedVendor.transip
`source.nat.port`CopiedVendor.transport
`source.packets`CopiedVendor.sentpkt
`source.user.group.name`CopiedVendor.group
`source.user.name`CopiedVendor.user, Vendor.unauthuser
`tls.client.issuer`CopiedVendor.ccertissuer
`tls.server.issuer`CopiedVendor.scertissuer
`url.domain`CopiedVendor.hostname
`url.original`CopiedVendor.url
`user.name`CopiedVendor.user, Vendor.unauthuser
`user_agent.original`CopiedVendor.agent
`log.syslog.priority`Extracted@rawstring
`network.protocol`ExtractedVendor.service
`event.severity`MappedVendor.severity
`network.direction`MappedVendor.dir, Vendor.direction
`network.transport`MappedVendor.proto
`@timestamp`ParsedVendor.eventtime
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.product`StaticNone
`observer.type`StaticNone
`observer.vendor`StaticNone
source.ipclient.ip 
source.portclient.port 
Vendor.dst_hostdestination.address 
Vendor.rcvdbytedestination.bytes 
Vendor.dstcitydestination.geo.city_name 
Vendor.dstregiondestination.geo.region_name 
Vendor.dstipdestination.ip 
Vendor.tranipdestination.nat.ip 
Vendor.tranportdestination.nat.port 
Vendor.rcvdpktdestination.packets 
Vendor.dst_portdestination.port 
Vendor.dstportdestination.port 
Vendor.dstuserdestination.user.name 
Vendor.xiddns.id 
Vendor.qclassdns.question.class 
Vendor.qnamedns.question.name 
Vendor.qtypedns.question.type 
Vendor.subjectemail.subject 
Vendor.error_numerror.code 
Vendor.errorerror.message 
Vendor.sess_durationevent.duration 
Vendor.reasonevent.reason 
Vendor.refevent.reference 
Vendor.filetypefile.extension 
Vendor.filenamefile.name 
Vendor.filefile.path 
Vendor.filesizefile.size 
Vendor.srcnamehost.name 
Vendor.crlevelhost.risk.calculated_level 
Vendor.crscorehost.risk.calculated_score 
Vendor.httpmethodhttp.request.method 
Vendor.methodhttp.request.method 
Vendor.levellog.level 
Vendor.msgmessage 
source.bytesnetwork.bytes 
Vendor.protonetwork.iana_number 
source.packetsnetwork.packets 
Vendor.dstintfroleobserver.egress.zone 
Vendor.srcintfroleobserver.ingress.zone 
Vendor.devnameobserver.name 
Vendor.device_idobserver.serial_number 
Vendor.devidobserver.serial_number 
Vendor.appprocess.name 
Vendor.catdescrule.category 
Vendor.policyidrule.id 
Vendor.policynamerule.name 
Vendor.applistrule.ruleset 
Vendor.poluuidrule.uuid 
destination.ipserver.ip 
destination.portserver.port 
Vendor.sentbytesource.bytes 
Vendor.remipsource.ip 
Vendor.srcipsource.ip 
Vendor.transipsource.nat.ip 
Vendor.transportsource.nat.port 
Vendor.sentpktsource.packets 
Vendor.locportsource.port 
Vendor.srcportsource.port 
Vendor.groupsource.user.group.name 
Vendor.ccertissuertls.client.issuer 
Vendor.scertissuertls.server.issuer 
Vendor.urlurl.original 
source.user.nameuser.name 
Vendor.agentuser_agent.original