Parsers and Generated Fields

Tag Fields Created by Parser fortinet-fortigate
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortigate
Source FieldLogScale Repository Field
Vendor.agentagent.original
Vendor.rcvdbytedestination.bytes
Vendor.dstipdestination.ip
Vendor.remipdestination.ip
Vendor.tranipdestination.nat.ip
Vendor.tranportdestination.nat.port
Vendor.rcvdpktdestination.packets
Vendor.dstdestination.port
Vendor.dstportdestination.port
Vendor.remportdestination.port
Vendor.dstuserdestination.user.name
Vendor.xiddns.id
Vendor.qclassdns.question.class
Vendor.qnamedns.question.name
Vendor.qtypedns.question.type
Vendor.subjectemail.subject
Vendor.errorerror.code
Vendor.actionevent.action
Vendor.eventtypeevent.action
Vendor.sessevent.duration
Vendor.eventevent.id
Vendor.eventidevent.id
Vendor.errorevent.message
Vendor.refevent.reference
Vendor.extensionfile.extension
Vendor.infectedfiletypefile.extension
Vendor.matchedfiletypefile.extension
Vendor.filenamefile.name
Vendor.infectedfilenamefile.name
Vendor.matchedfilenamefile.name
Vendor.filefile.path
Vendor.filesizefile.size
Vendor.infectedfilesizefile.size
Vendor.filetypefile.type
Vendor.srcnamehost.name
Vendor.crlevellevel
Vendor.levellog.level
Vendor.dstcityname
Vendor.dstcountryname
Vendor.dstregionname
Vendor.scertcnamename[0]
tls.client.issuername[0]
tls.server.issuername[0]
Vendor.appnetwork.application
source.bytesnetwork.bytes
source.packetsnetwork.packets
Vendor.devidnumber
Vendor.protonumber
Vendor.dstobserver.egress.interface.name
Vendor.dstintfobserver.egress.interface.name
Vendor.dstintfroleobserver.egress.zone
Vendor.srcobserver.ingress.interface.name
Vendor.srcintfobserver.ingress.interface.name
Vendor.srcintfroleobserver.ingress.zone
Vendor.devnameobserver.name
event.moduleobserver.product
Vendor.appprocess.name
Vendor.appcatrule.category
Vendor.catdescrule.category
Vendor.commentrule.description
Vendor.logdescrule.description
Vendor.msgrule.description
Vendor.policyidrule.id
Vendor.policynamerule.name
Vendor.applistrule.ruleset
Vendor.policytyperule.ruleset
Vendor.profilerule.ruleset
Vendor.poluuidrule.uuid
Vendor.crscorescore
Vendor.sentbytesource.bytes
source.ipsource.geo
Vendor.locipsource.ip
Vendor.srcipsource.ip
Vendor.transipsource.nat.ip
Vendor.transportsource.nat.port
Vendor.sentpktsource.packets
Vendor.locportsource.port
Vendor.srcsource.port
Vendor.srcportsource.port
Vendor.groupsource.user.group.name
Vendor.unauthusersource.user.name
Vendor.usersource.user.name
Vendor.ccertissuertls.client.issuer
Vendor.scertissuertls.server.issuer
Vendor.urlurl.path
source.user.nameuser.name
Vendor.dtypevulnerability.category