Parsers and Generated Fields

Tag Fields Created by Parser netgate-pfsense
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser netgate-pfsense
Source FieldCPS Field
Vendor.dst_ipdestination.ip
Vendor.dst_portdestination.port
Vendor.actionevent.action
Vendor.reasonevent.reason
Vendor.rule_numberrule.id
Vendor.src_ipsource.ip
Vendor.src_portsource.port
Tag Fields Created by Parser pfsense-syslog
  • #Cps.version

  • #Vendor

  • #ecs.version

  • #event.dataset

  • #event.kind

  • #event.module

  • #event.outcome

  • #observer.type

Fields Identified by Parser pfsense-syslog
Source FieldCPS Field
Vendor.dst_ipdestination.ip
Vendor.dst_portdestination.port
Vendor.actionevent.action
Vendor.reasonevent.reason
Vendor.logtypelog.syslog.appname
Vendor.syslog.prioritylog.syslog.priority
Vendor.pidlog.syslog.procid
Vendor.rule_numberrule.id
Vendor.src_ipsource.ip
Vendor.src_portsource.port