Parsers and Generated Fields

Tag Fields Created by Parser fortinet-fortigate
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortigate
Vendor FieldCPS FieldDescription
Vendor.eventtime@timestampPrimary timestamp field
source.ipclient.ip 
source.portclient.port 
Vendor.daddrdestination.address  
Vendor.dst_hostdestination.address  
Vendor.rcvdbytedestination.bytes  
Vendor.dstcitydestination.geo.city_name  
Vendor.dstcountrydestination.geo.country_name  
Vendor.dstregiondestination.geo.region_name  
Vendor.dstipdestination.ipDestination IP address
Vendor.dstipdestination.ip  
Vendor.tranipdestination.nat.ip  
Vendor.tranportdestination.nat.port  
Vendor.rcvdpktdestination.packets  
Vendor.dstportdestination.portDestination port
Vendor.dst_portdestination.port  
Vendor.dstportdestination.port  
Vendor.remportdestination.port  
Vendor.dstuserdestination.user.name  
Vendor.xiddns.id  
Vendor.qclassdns.question.class  
Vendor.qnamedns.question.name  
Vendor.qtypedns.question.type  
Vendor.subjectemail.subject  
Vendor.error_numerror.codeError code
Vendor.error_numerror.code  
Vendor.errorerror.messageError message
Vendor.errorerror.message  
Vendor.actionevent.actionFor traffic and event types
Vendor.eventtypeevent.actionFor UTM type events
Vendor.actionevent.action  
Vendor.eventtypeevent.action  
Vendor.sess_durationevent.durationSession duration
Vendor.sess_durationevent.duration  
Vendor.event_idevent.id  
Vendor.eventidevent.id  
Vendor.reasonevent.reasonEvent reason
Vendor.refevent.referenceEvent reference
Vendor.refevent.reference  
Vendor.severityevent.severityMaps severity levels to numeric values (critical=90, high=70, medium=50, low=30, info=10)
Vendor.filetypefile.extension  
Vendor.infectedfiletypefile.extension  
Vendor.matchedfiletypefile.extension  
Vendor.filenamefile.name  
Vendor.infectedfilenamefile.name  
Vendor.matchedfilenamefile.name  
Vendor.filefile.path  
Vendor.filesizefile.size  
Vendor.infectedfilesizefile.size  
Vendor.srcnamehost.name  
Vendor.crlevelhost.risk.calculated_level  
Vendor.crscorehost.risk.calculated_score  
Vendor.httpmethodhttp.request.methodHTTP method for UTM events
Vendor.methodhttp.request.methodFor REST API events
Vendor.statushttp.response.status_codeFor REST API events
Vendor.status;http.response.status_code 
Vendor.levellog.level  
source.bytesnetwork.bytes 
Vendor.protonetwork.iana_number  
source.packetsnetwork.packets 
Vendor.dst_intobserver.egress.interface.name  
Vendor.dstintfobserver.egress.interface.name  
Vendor.dstintfroleobserver.egress.zoneDestination interface role
Vendor.dstintfroleobserver.egress.zone  
Vendor.src_intobserver.ingress.interface.name  
Vendor.srcintfobserver.ingress.interface.name  
Vendor.srcintfroleobserver.ingress.zoneSource interface role
Vendor.srcintfroleobserver.ingress.zone  
Vendor.devnameobserver.nameDevice name
Vendor.devnameobserver.name  
Vendor.device_idobserver.serial_numberAlternative device ID
Vendor.devidobserver.serial_numberDevice ID
Vendor.devidobserver.serial_number  
Vendor.appprocess.name  
Vendor.catdescrule.category  
Vendor.msg;rule.description 
Vendor.commentrule.description  
Vendor.logdescrule.description  
Vendor.policyidrule.id 
Vendor.policyidrule.id  
Vendor.policynamerule.name 
Vendor.applistrule.ruleset  
Vendor.policytyperule.ruleset  
Vendor.profilerule.ruleset  
Vendor.poluuidrule.uuid  
destination.ipserver.ip 
destination.portserver.port 
Vendor.sentbytesource.bytes  
Vendor.srccountrysource.geo.country_nameSource country (if not "Reserved")
Vendor.srccountry;source.geo.country_name 
Vendor.remipsource.ipAlternative source IP field
Vendor.srcipsource.ipSource IP address
Vendor.locipsource.ip  
Vendor.remipsource.ip  
Vendor.srcipsource.ip  
Vendor.transipsource.nat.ip  
Vendor.transportsource.nat.port  
Vendor.sentpktsource.packets  
Vendor.srcportsource.portSource port
Vendor.locportsource.port  
Vendor.src_portsource.port  
Vendor.srcportsource.port  
Vendor.groupsource.user.group.name  
Vendor.unauthusersource.user.name  
Vendor.usersource.user.name  
Vendor.ccertissuertls.client.issuer  
tls.client.issuertls.client.x509.issuer.common_name[0] 
Vendor.scertissuertls.server.issuer  
tls.server.issuertls.server.x509.issuer.common_name[0] 
Vendor.scertcnametls.server.x509.subject.common_name[0]  
Vendor.hostnameurl.domainURL domain name
Vendor.urlurl.originalOriginal URL
Vendor.urlurl.original  
top_ldurl.top_level_domain  
source.user.nameuser.name 
Vendor.agentuser_agent.original  
Vendor.dtypevulnerability.category[0]