Parsers and Generated Fields

Tag Fields Created by Parser fortimail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortimail
Source FieldCPS Field
Vendor.log.dst_ipdestination.ip
Vendor.log.directionemail.direction
Vendor.log.subjectemail.subject
Vendor.log.msg.subjectemail.subject[0]
Vendor.log.maileremail.x_mailer
Vendor.log.actionevent.action
Vendor.log.action;event.action
Vendor.log.prilog.level
Vendor.log.msgmessage
Vendor.log.client_ipsource.ip
Vendor.log.srcsource.ip
Vendor.log.ui.ipsource.ip
Vendor.log.client_namesource.user.name
Vendor.log.msg.usersource.user.name
Vendor.log.msg.useruser.name
Vendor.log.useruser.name
Tag Fields Created by Parser fortinet-fortimail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortimail
Source FieldCPS Field
Vendor.log.dst_ipdestination.ip
Vendor.log.directionemail.direction
Vendor.log.msg.subjectemail.subject
Vendor.log.subjectemail.subject
Vendor.log.maileremail.x_mailer
Vendor.log.actionevent.action
Vendor.log.prilog.level
Vendor.log.msgmessage
Vendor.log.srcsource.ip
Vendor.log.client_ipsource.ip
Vendor.log.ui.ipsource.ip
Vendor.log.client_namesource.user.name
Vendor.log.msg.usersource.user.name
Vendor.log.msg.useruser.name
Vendor.log.useruser.name