Parsers and Generated Fields

Tag Fields Created by Parser netgate-pfsense
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser netgate-pfsense
Vendor FieldCPS FieldDescription
`event.category[]`ArrayNone
`event.type[]`ArrayVendor.action
`event.outcome`ConditionalVendor.action
`destination.ip`CopiedVendor.dst_ip
`destination.port`CopiedVendor.dst_port
`event.action`CopiedVendor.action
`event.reason`CopiedVendor.reason
`rule.id`CopiedVendor.rule_number
`source.ip`CopiedVendor.src_ip
`source.port`CopiedVendor.src_port
`log.syslog.appname`ExtractedNone
`log.syslog.hostname`ExtractedNone
`log.syslog.priority`ExtractedNone
`log.syslog.procid`ExtractedNone
`@timestamp`ParsedNone
`ecs.version`StaticNone
`event.dataset`StaticNone
`event.kind`StaticNone
`event.module`StaticNone
`network.transport`TransformedVendor.protocol
Vendor.dst_ipdestination.ip 
Vendor.dst_portdestination.port 
Vendor.actionevent.action 
Vendor.reasonevent.reason 
Vendor.rule_numberrule.id 
Vendor.src_ipsource.ip 
Vendor.src_portsource.port