Parsers and Generated Fields

Tag Fields Created by Parser fortimail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortimail
Vendor FieldCPS FieldDescription
Vendor.log.dst_ipdestination.ip 
Vendor.log.directionemail.direction 
Vendor.log.subjectemail.subject 
Vendor.log.msg.subjectemail.subject[0] 
Vendor.log.maileremail.x_mailer 
Vendor.log.actionevent.action 
Vendor.log.action;event.action 
Vendor.log.prilog.level 
Vendor.log.msgmessage 
Vendor.log.client_ipsource.ip 
Vendor.log.srcsource.ip 
Vendor.log.ui.ipsource.ip 
Vendor.log.client_namesource.user.name 
Vendor.log.msg.usersource.user.name 
Vendor.log.msg.useruser.name 
Vendor.log.useruser.name 
Tag Fields Created by Parser fortinet-fortimail
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser fortinet-fortimail
Vendor FieldCPS FieldDescription
Vendor.log.dst_ipdestination.ip  
Vendor.log.directionemail.direction  
Vendor.log.msg.subjectemail.subject  
Vendor.log.subjectemail.subject  
Vendor.log.maileremail.x_mailer  
Vendor.log.actionevent.action  
Vendor.log.prilog.level  
Vendor.log.msgmessage  
Vendor.log.srcsource.ip 
Vendor.log.client_ipsource.ip  
Vendor.log.ui.ipsource.ip  
Vendor.log.client_namesource.user.name  
Vendor.log.msg.usersource.user.name  
Vendor.log.msg.useruser.name  
Vendor.log.useruser.name