Parsers and Generated Fields

Tag Fields Created by Parser juniper-srx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser juniper-srx
Vendor FieldCPS FieldDescription
source.bytesclient.bytes 
source.ipclient.ip 
source.nat.ipclient.nat.ip 
source.nat.portclient.nat.port 
source.packetsclient.packets 
source.portclient.port 
Vendor.bytes-from-serverdestination.bytesBytes sent from server to client
Vendor.inbound-bytesdestination.bytesAlternative bytes from server field
Vendor.destination-addressdestination.ipDestination IP address
Vendor.dst-addrdestination.ipAlternative destination IP address field
Vendor.nat-destination-addressdestination.nat.ipNAT destination IP address
Vendor.nat-remote-addressdestination.nat.ipAlternative NAT destination IP address field
Vendor.nat-destination-portdestination.nat.portNAT destination port
Vendor.inbound-packetsdestination.packetsAlternative packets from server field
Vendor.packets-from-serverdestination.packetsPackets sent from server to client
Vendor.destination-portdestination.portDestination port
Vendor.dst-portdestination.portAlternative destination port field
Vendor.actionevent.action 
Vendor.reasonevent.reasonReason for the event
Vendor.application-riskevent.risk_scoreRisk score associated with the application
Vendor.sample-sha256file.hash.sha256SHA256 hash of the file (lowercased)
Vendor.file-namefile.nameAlternative file name field
Vendor.filenamefile.nameFile name
Vendor.syslog.hostname;log.syslog.hostname 
Vendor.syslog.msgid;log.syslog.msgid 
Vendor.syslog.procid;log.syslog.procid 
source.bytesnetwork.bytes 
Vendor.protocol-idnetwork.iana_numberProtocol ID number
client.packetsnetwork.packets 
Vendor.protocolnetwork.protocolNetwork protocol
Vendor.packet-protocolnetwork.transportAlternative transport protocol field
Vendor.protocol-namenetwork.transportTransport protocol name
Vendor.destination-interface-nameobserver.egress.interface.nameDestination interface name
Vendor.destination-zone-nameobserver.egress.zoneDestination security zone
Vendor.interface-nameobserver.ingress.interface.nameInterface name
Vendor.packet-incoming-interfaceobserver.ingress.interface.nameIncoming packet interface
Vendor.source-interface-nameobserver.ingress.interface.nameSource interface name
Vendor.source-zone-nameobserver.ingress.zoneSource security zone
Vendor.pidprocess.pidProcess ID
Vendor.policy-namerule.namePolicy or rule name
Vendor.rule-namerule.nameAlternative rule name field
Vendor.rulebase-namerule.nameAlternative rule name field
destination.bytesserver.bytes 
destination.ipserver.ip 
destination.nat.ipserver.nat.ip 
destination.nat.portserver.nat.port 
destination.packetsserver.packets 
destination.portserver.port 
Vendor.client-modeservice.typeClient connection mode
Vendor.bytes-from-clientsource.bytesBytes sent from client to server
Vendor.outbound-bytessource.bytesAlternative bytes from client field
Vendor.local-addresssource.ipAlternative source IP address field for VPN connections
Vendor.source-addresssource.ipSource IP address
Vendor.src-addrsource.ipAlternative source IP address field
Vendor.src-ip-strsource.ipAnother alternative source IP address field
Vendor.nat-local-addresssource.nat.ipAlternative NAT source IP address field
Vendor.nat-source-addresssource.nat.ipNAT source IP address
Vendor.nat-source-portsource.nat.portNAT source port
Vendor.outbound-packetssource.packetsAlternative packets from client field
Vendor.packets-from-clientsource.packetsPackets sent from client to server
Vendor.packets-numsource.packetsAlternative packet count field
Vendor.source-portsource.portSource port
Vendor.src-portsource.portAlternative source port field
Vendor.usernamesource.user.nameUsername associated with the source
Vendor.http-hosturl.domainAlternative URL domain field
Vendor.urlurl.domainURL domain (lowercased)
Vendor.objurl.pathURL path
Vendor.usernameuser.nameUsername when source.user.name is available
source.user.name;user.name 
Vendor.class-nameuser.roles[]User role information