Parsers and Generated Fields

Tag Fields Created by Parser juniper-srx
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser juniper-srx
Vendor FieldCPS FieldDescription
`event.category[]`Arraylog.syslog.appname, log.syslog.msgid
`event.type[]`Arraylog.syslog.msgid, Vendor.action
`user.roles[]`ArrayVendor.class-name
`network.bytes`Calculatedsource.bytes, destination.bytes
`network.packets`Calculatedclient.packets, server.packets
`event.dataset`Conditionallog.syslog.appname
`event.outcome`Conditionallog.syslog.priority, event context
`client.bytes`Copiedsource.bytes
`client.ip`Copiedsource.ip
`client.nat.ip`Copiedsource.nat.ip
`client.nat.port`Copiedsource.nat.port
`client.packets`Copiedsource.packets
`client.port`Copiedsource.port
`destination.address`CopiedVendor.destination-address, Vendor.dst-addr, Vendor.remote-address
`destination.bytes`CopiedVendor.bytes-from-server, Vendor.inbound-bytes
`destination.nat.ip`CopiedVendor.nat-destination-address, Vendor.nat-remote-address
`destination.nat.port`CopiedVendor.nat-destination-port
`destination.packets`CopiedVendor.packets-from-server, Vendor.inbound-packets
`destination.port`CopiedVendor.destination-port, Vendor.dst-port
`event.reason`CopiedVendor.reason
`event.risk_score`CopiedVendor.application-risk, Vendor.urlcategory-risk
`file.hash.sha256`CopiedVendor.sample-sha256
`file.name`CopiedVendor.filename, Vendor.file-name
`network.iana_number`CopiedVendor.protocol-id
`network.protocol`CopiedVendor.protocol
`observer.egress.interface.name`CopiedVendor.destination-interface-name
`observer.egress.zone`CopiedVendor.destination-zone-name
`observer.ingress.interface.name`CopiedVendor.source-interface-name, Vendor.packet-incoming-interface, Vendor.interface-name
`observer.ingress.zone`CopiedVendor.source-zone-name
`process.pid`CopiedVendor.pid
`rule.name`CopiedVendor.policy-name, Vendor.rule-name, Vendor.rulebase-name
`server.bytes`Copieddestination.bytes
`server.ip`Copieddestination.ip
`server.nat.ip`Copieddestination.nat.ip
`server.nat.port`Copieddestination.nat.port
`server.packets`Copieddestination.packets
`server.port`Copieddestination.port
`service.type`CopiedVendor.client-mode
`source.address`CopiedVendor.source-address, Vendor.src-addr, Vendor.src-ip-str, Vendor.local-address
`source.bytes`CopiedVendor.bytes-from-client, Vendor.outbound-bytes
`source.domain`CopiedVendor.hostname
`source.nat.ip`CopiedVendor.nat-source-address, Vendor.nat-local-address
`source.nat.port`CopiedVendor.nat-source-port
`source.packets`CopiedVendor.packets-from-client, Vendor.outbound-packets, Vendor.packets-num
`source.port`CopiedVendor.source-port, Vendor.src-port
`source.user.name`CopiedVendor.username
`url.domain`CopiedVendor.url, Vendor.http-host
`url.path`CopiedVendor.obj
`user.name`Copiedsource.user.name, Vendor.username
`log.level`Derivedlog.syslog.priority
`network.transport`Derivednetwork.iana_number, Vendor.protocol-name, Vendor.packet-protocol
`event.action`ExtractedVendor.action, log.syslog.msgid
`host.name`Extracted@rawstring
`log.syslog.appname`Extracted@rawstring
`log.syslog.hostname`Extracted@rawstring
`log.syslog.msgid`Extracted@rawstring
`log.syslog.priority`Extracted@rawstring
`log.syslog.procid`Extracted@rawstring
`log.syslog.structured_data`Extracted@rawstring
`log.syslog.version`Extracted@rawstring
`process.command_line`Extractedmessage
`event.severity`MappedVendor.threat-severity
`@timestamp`Parsed@timestamp
`ecs.version`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`observer.product`StaticNone
`observer.type`StaticNone
`destination.ip`Validateddestination.address
`source.ip`Validatedsource.address
source.bytesclient.bytes 
source.ipclient.ip 
source.nat.ipclient.nat.ip 
source.nat.portclient.nat.port 
source.packetsclient.packets 
source.portclient.port 
Vendor.actionevent.action 
Vendor.reasonevent.reason 
Vendor.filenamefile.name 
source.bytesnetwork.bytes 
client.packetsnetwork.packets 
Vendor.protocolnetwork.protocol 
Vendor.pidprocess.pid 
destination.bytesserver.bytes 
destination.ipserver.ip 
destination.nat.ipserver.nat.ip 
destination.nat.portserver.nat.port 
destination.packetsserver.packets 
destination.portserver.port 
Vendor.usernamesource.user.name 
Vendor.objurl.path 
Vendor.usernameuser.name