Parsers and Generated Fields

Tag Fields Created by Parser fortinet-fortigate
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortigate
Source FieldCPS Field
Vendor.rcvdbytedestination.bytes
Vendor.dstcitydestination.geo.city_name
Vendor.dstcountry;destination.geo.country_name
Vendor.dstregiondestination.geo.region_name
Vendor.dstipdestination.ip
Vendor.remip;destination.ip
Vendor.tranipdestination.nat.ip
Vendor.tranportdestination.nat.port
Vendor.rcvdpktdestination.packets
Vendor.dst_portdestination.port
Vendor.dstportdestination.port
Vendor.dstport;destination.port
Vendor.remport;destination.port
Vendor.dstuserdestination.user.name
Vendor.xiddns.id
Vendor.qclassdns.question.class
Vendor.qnamedns.question.name
Vendor.qtypedns.question.type
Vendor.subjectemail.subject
Vendor.error_numerror.code
Vendor.action;event.action
Vendor.eventtype;event.action
Vendor.sess_durationevent.duration
Vendor.event_id;event.id
Vendor.eventid;event.id
Vendor.errorevent.message
Vendor.refevent.reference
Vendor.extensionfile.extension
Vendor.infectedfiletype;file.extension
Vendor.matchedfiletype;file.extension
Vendor.filenamefile.name
Vendor.infectedfilename;file.name
Vendor.matchedfilename;file.name
Vendor.filefile.path
Vendor.filesizefile.size
Vendor.infectedfilesize;file.size
Vendor.filetypefile.type
Vendor.srcnamehost.name
Vendor.levellog.level
Vendor.appnetwork.application
source.bytesnetwork.bytes
Vendor.protonetwork.iana_number
source.packetsnetwork.packets
Vendor.dst_int;observer.egress.interface.name
Vendor.dstintf;observer.egress.interface.name
Vendor.dstintfroleobserver.egress.zone
Vendor.src_int;observer.ingress.interface.name
Vendor.srcintf;observer.ingress.interface.name
Vendor.srcintfroleobserver.ingress.zone
Vendor.devnameobserver.name
event.moduleobserver.product
Vendor.devidobserver.serial_number
Vendor.appprocess.name
Vendor.crlevelrisk.calculated_level
Vendor.crscorerisk.calculated_score
Vendor.appcatrule.category
Vendor.catdesc;rule.category
Vendor.comment;rule.description
Vendor.logdesc;rule.description
Vendor.msg;rule.description
Vendor.policyidrule.id
Vendor.policyid;rule.id
Vendor.policynamerule.name
Vendor.applistrule.ruleset
Vendor.policytype;rule.ruleset
Vendor.profile;rule.ruleset
Vendor.poluuidrule.uuid
Vendor.sentbytesource.bytes
source.ipsource.geo
Vendor.locip;source.ip
Vendor.srcipsource.ip
Vendor.transipsource.nat.ip
Vendor.transportsource.nat.port
Vendor.sentpktsource.packets
Vendor.locportsource.port
Vendor.locport;source.port
Vendor.src_port;source.port
Vendor.srcportsource.port
Vendor.srcport;source.port
Vendor.groupsource.user.group.name
Vendor.unauthuser;source.user.name
Vendor.user;source.user.name
Vendor.ccertissuertls.client.issuer
tls.client.issuertls.client.x509.issuer.common_name[0]
Vendor.scertissuertls.server.issuer
tls.server.issuertls.server.x509.issuer.common_name[0]
Vendor.scertcnametls.server.x509.subject.common_name[0]
Vendor.urlurl.path
source.user.nameuser.name
Vendor.agentuser_agent.original
Vendor.dtypevulnerability.category