Parsers and Generated Fields

Tag Fields Created by Parser fortimail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortimail
Source FieldLogScale Repository Field
Vendor.log.dstdestination.ip
Vendor.log.directionemail.direction
Vendor.log.subjectemail.subject
Vendor.log.msg.subjectemail.subject[0]
Vendor.log.actionevent.action
Vendor.log.prilog.level
Vendor.log.mailermailer
Vendor.log.msgmessage
Vendor.log.clientsource.ip
Vendor.log.srcsource.ip
Vendor.log.ui.ipsource.ip
Vendor.log.clientsource.user.name
Vendor.log.msg.usersource.user.name
Vendor.log.msg.useruser.name
Vendor.log.useruser.name