Parsers and Generated Fields

Tag Fields Created by Parser netgate-pfsense
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser netgate-pfsense
Vendor FieldCPS FieldDescription
netgateVendor 
Vendor.dst_ipdestination.ipDestination IP address
Vendor.dst_portdestination.portDestination port number
Vendor.actionevent.actionAction taken by the firewall (pass/block)
networkevent.category[0] 
pfsense.filterlogevent.dataset 
eventevent.kind 
pfsenseevent.module 
failureevent.outcome 
successevent.outcome 
unknownevent.outcome 
Vendor.reasonevent.reasonReason for the firewall action
connectionevent.type[0] 
allowedevent.type[1] 
deniedevent.type[1] 
Vendor.protocolnetwork.transportProtocol used for network transport
Vendor.rule_numberrule.idFirewall rule identifier
Vendor.src_ipsource.ipSource IP address
Vendor.src_portsource.portSource port number