Parsers and Generated Fields

Tag Fields Created by Parser fortinet-fortimail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortimail
Vendor FieldCPS FieldDescription
`event.category[]`ArrayVendor.log.type, Vendor.log.subtype
`event.type[]`ArrayVendor.log.type, Vendor.log.msg
`log.syslog.facility.code`Calculatedlog.syslog.priority, log.syslog.severity.code
`destination.domain`CopiedVendor.log.domain
`destination.ip`CopiedVendor.log.dst_ip
`email.direction`CopiedVendor.log.direction
`email.message_id`CopiedVendor.log.message_id
`email.subject`CopiedVendor.log.subject
`email.x_mailer`CopiedVendor.log.mailer
`event.action`CopiedVendor.log.action
`event.id`CopiedVendor.log.log_id
`event.reason`CopiedVendor.log.classifier
`event.sequence`CopiedVendor.log.log_part
`log.level`CopiedVendor.log.pri
`rule.id`CopiedVendor.log.polid
`server.domain`CopiedVendor.log.domain
`source.address`CopiedVendor.log.client_name
`source.geo.country_iso_code`CopiedVendor.log.client_cc
`source.ip`CopiedVendor.log.client_ip, Vendor.log.src, Vendor.log.ui
`threat.indicator.name`CopiedVendor.log.virus
`url.original`CopiedVendor.log.url
`user.name`CopiedVendor.log.user
`event.outcome`DeterminedVendor.log.status, Vendor.log.msg
`email.from.address[]`ExtractedVendor.log.from
`log.syslog.priority`Extracted@rawstring
`network.protocol`ExtractedVendor.log.ui
`event.dataset`Formattedevent.module, Vendor.log.type
`event.severity`Mappedlog.level
`log.syslog.severity.code`Mappedlog.level
`@timestamp`ParsedVendor.log.date, Vendor.log.time
`email.to.address`ParsedVendor.log.to
`url.domain`Parsedurl.original
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
Vendor.log.dst_ipdestination.ip 
Vendor.log.directionemail.direction 
Vendor.log.message_idemail.message_id 
Vendor.log.subjectemail.subject 
Vendor.log.maileremail.x_mailer 
Vendor.log.log_idevent.id 
Vendor.log.classifierevent.reason 
Vendor.log.log_partevent.sequence 
Vendor.log.prilog.level 
Vendor.log.polidrule.id 
Vendor.log.client_ccsource.geo.country_iso_code 
Vendor.log.virusthreat.indicator.name 
url.hosturl.domain  
Vendor.log.urlurl.original