Your IP : 216.73.216.17


Current Path : /proc/thread-self/root/etc/filebeat/
Upload File :
Current File : //proc/thread-self/root/etc/filebeat/fields.yml

# WARNING! Do not edit this file directly, it was generated by the ECS project,
# based on ECS version 1.4.0.
# Please visit https://github.com/elastic/ecs to suggest changes to ECS fields.

- key: ecs
  title: ECS
  description: ECS Fields.
  fields:
  - name: '@timestamp'
    level: core
    required: true
    type: date
    description: 'Date/time when the event originated.

      This is the date/time extracted from the event, typically representing when
      the event was generated by the source.

      If the event source has no original timestamp, this value is typically populated
      by the first time the event was received by the pipeline.

      Required field for all events.'
    example: '2016-05-23T08:05:34.853Z'
  - name: labels
    level: core
    type: object
    object_type: keyword
    description: 'Custom key/value pairs.

      Can be used to add meta information to events. Should not contain nested objects.
      All values are stored as keyword.

      Example: `docker` and `k8s` labels.'
    example:
      application: foo-bar
      env: production
  - name: message
    level: core
    type: text
    description: 'For log events the message field contains the log message, optimized
      for viewing in a log viewer.

      For structured logs without an original message field, other fields can be concatenated
      to form a human-readable summary of the event.

      If multiple messages exist, they can be combined into one message.'
    example: Hello World
  - name: tags
    level: core
    type: keyword
    ignore_above: 1024
    description: List of keywords used to tag each event.
    example: '["production", "env2"]'
  - name: agent
    title: Agent
    group: 2
    description: 'The agent fields contain the data about the software entity, if
      any, that collects, detects, or observes events on a host, or takes measurements
      on a host.

      Examples include Beats. Agents may also run on observers. ECS agent.* fields
      shall be populated with details of the agent running on the host or observer
      where the event happened or the measurement was taken.'
    footnote: 'Examples: In the case of Beats for logs, the agent.name is filebeat.
      For APM, it is the agent running in the app/service. The agent information does
      not change if data is sent through queuing systems like Kafka, Redis, or processing
      systems such as Logstash or APM Server.'
    type: group
    fields:
    - name: ephemeral_id
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Ephemeral identifier of this agent (if one exists).

        This id normally changes across restarts, but `agent.id` does not.'
      example: 8a4f500f
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Unique identifier of this agent (if one exists).

        Example: For Beats this would be beat.id.'
      example: 8a4f500d
    - name: name
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Custom name of the agent.

        This is a name that can be given to an agent. This can be helpful if for example
        two Filebeat instances are running on the same host but a human readable separation
        is needed on which Filebeat instance data is coming from.

        If no name is given, the name is often left empty.'
      example: foo
    - name: type
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Type of the agent.

        The agent type stays always the same and should be given by the agent used.
        In case of Filebeat the agent would always be Filebeat also if two Filebeat
        instances are run on the same machine.'
      example: filebeat
    - name: version
      level: core
      type: keyword
      ignore_above: 1024
      description: Version of the agent.
      example: 6.0.0-rc2
  - name: as
    title: Autonomous System
    group: 2
    description: An autonomous system (AS) is a collection of connected Internet Protocol
      (IP) routing prefixes under the control of one or more network operators on
      behalf of a single administrative entity or domain that presents a common, clearly
      defined routing policy to the internet.
    type: group
    fields:
    - name: number
      level: extended
      type: long
      description: Unique number allocated to the autonomous system. The autonomous
        system number (ASN) uniquely identifies each network on the Internet.
      example: 15169
    - name: organization.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Organization name.
      example: Google LLC
  - name: client
    title: Client
    group: 2
    description: 'A client is defined as the initiator of a network connection for
      events regarding sessions, connections, or bidirectional flow records.

      For TCP events, the client is the initiator of the TCP connection that sends
      the SYN packet(s). For other protocols, the client is generally the initiator
      or requestor in the network transaction. Some systems use the term "originator"
      to refer the client in TCP connections. The client fields describe details about
      the system acting as the client in the network event. Client fields are usually
      populated in conjunction with server fields. Client fields are generally not
      populated for packet-level events.

      Client / server representations can add semantic context to an exchange, which
      is helpful to visualize the data in certain situations. If your context falls
      in that category, you should still ensure that source and destination are filled
      appropriately.'
    type: group
    fields:
    - name: address
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Some event client addresses are defined ambiguously. The event
        will sometimes list an IP, a domain or a unix socket.  You should always store
        the raw address in the `.address` field.

        Then it should be duplicated to `.ip` or `.domain`, depending on which one
        it is.'
    - name: as.number
      level: extended
      type: long
      description: Unique number allocated to the autonomous system. The autonomous
        system number (ASN) uniquely identifies each network on the Internet.
      example: 15169
    - name: as.organization.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Organization name.
      example: Google LLC
    - name: bytes
      level: core
      type: long
      format: bytes
      description: Bytes sent from the client to the server.
      example: 184
    - name: domain
      level: core
      type: keyword
      ignore_above: 1024
      description: Client domain.
    - name: geo.city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: geo.continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: geo.country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: geo.country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: geo.location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: geo.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: geo.region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: geo.region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
    - name: ip
      level: core
      type: ip
      description: 'IP address of the client.

        Can be one or multiple IPv4 or IPv6 addresses.'
    - name: mac
      level: core
      type: keyword
      ignore_above: 1024
      description: MAC address of the client.
    - name: nat.ip
      level: extended
      type: ip
      description: 'Translated IP of source based NAT sessions (e.g. internal client
        to internet).

        Typically connections traversing load balancers, firewalls, or routers.'
    - name: nat.port
      level: extended
      type: long
      format: string
      description: 'Translated port of source based NAT sessions (e.g. internal client
        to internet).

        Typically connections traversing load balancers, firewalls, or routers.'
    - name: packets
      level: core
      type: long
      description: Packets sent from the client to the server.
      example: 12
    - name: port
      level: core
      type: long
      format: string
      description: Port of the client.
    - name: registered_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The highest registered client domain, stripped of the subdomain.

        For example, the registered domain for "foo.google.com" is "google.com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last two labels will not work well for TLDs such as "co.uk".'
      example: google.com
    - name: top_level_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The effective top level domain (eTLD), also known as the domain
        suffix, is the last part of the domain name. For example, the top level domain
        for google.com is "com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last label will not work well for effective TLDs such as "co.uk".'
      example: co.uk
    - name: user.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the user is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.email
      level: extended
      type: keyword
      ignore_above: 1024
      description: User email address.
    - name: user.full_name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: User's full name, if available.
      example: Albert Einstein
    - name: user.group.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.group.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: user.group.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
    - name: user.hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique user hash to correlate information for a user in anonymized
        form.

        Useful if `user.id` or `user.name` contain confidential information and cannot
        be used.'
    - name: user.id
      level: core
      type: keyword
      ignore_above: 1024
      description: One or multiple unique identifiers of the user.
    - name: user.name
      level: core
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Short name or login of the user.
      example: albert
  - name: cloud
    title: Cloud
    group: 2
    description: Fields related to the cloud or infrastructure the events are coming
      from.
    footnote: 'Examples: If Metricbeat is running on an EC2 host and fetches data
      from its host, the cloud info contains the data about this machine. If Metricbeat
      runs on a remote machine outside the cloud and fetches data from a service running
      in the cloud, the field contains cloud data from the machine the service is
      running on.'
    type: group
    fields:
    - name: account.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The cloud account or organization id used to identify different
        entities in a multi-tenant environment.

        Examples: AWS account id, Google Cloud ORG Id, or other unique identifier.'
      example: 666777888999
    - name: availability_zone
      level: extended
      type: keyword
      ignore_above: 1024
      description: Availability zone in which this host is running.
      example: us-east-1c
    - name: instance.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Instance ID of the host machine.
      example: i-1234567890abcdef0
    - name: instance.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Instance name of the host machine.
    - name: machine.type
      level: extended
      type: keyword
      ignore_above: 1024
      description: Machine type of the host machine.
      example: t2.medium
    - name: provider
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the cloud provider. Example values are aws, azure, gcp,
        or digitalocean.
      example: aws
    - name: region
      level: extended
      type: keyword
      ignore_above: 1024
      description: Region in which this host is running.
      example: us-east-1
  - name: container
    title: Container
    group: 2
    description: 'Container fields are used for meta information about the specific
      container that is the source of information.

      These fields help correlate data based containers from any runtime.'
    type: group
    fields:
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: Unique container id.
    - name: image.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the image the container was built on.
    - name: image.tag
      level: extended
      type: keyword
      ignore_above: 1024
      description: Container image tag.
    - name: labels
      level: extended
      type: object
      object_type: keyword
      description: Image labels.
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Container name.
    - name: runtime
      level: extended
      type: keyword
      ignore_above: 1024
      description: Runtime managing this container.
      example: docker
  - name: destination
    title: Destination
    group: 2
    description: 'Destination fields describe details about the destination of a packet/event.

      Destination fields are usually populated in conjunction with source fields.'
    type: group
    fields:
    - name: address
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Some event destination addresses are defined ambiguously. The
        event will sometimes list an IP, a domain or a unix socket.  You should always
        store the raw address in the `.address` field.

        Then it should be duplicated to `.ip` or `.domain`, depending on which one
        it is.'
    - name: as.number
      level: extended
      type: long
      description: Unique number allocated to the autonomous system. The autonomous
        system number (ASN) uniquely identifies each network on the Internet.
      example: 15169
    - name: as.organization.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Organization name.
      example: Google LLC
    - name: bytes
      level: core
      type: long
      format: bytes
      description: Bytes sent from the destination to the source.
      example: 184
    - name: domain
      level: core
      type: keyword
      ignore_above: 1024
      description: Destination domain.
    - name: geo.city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: geo.continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: geo.country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: geo.country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: geo.location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: geo.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: geo.region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: geo.region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
    - name: ip
      level: core
      type: ip
      description: 'IP address of the destination.

        Can be one or multiple IPv4 or IPv6 addresses.'
    - name: mac
      level: core
      type: keyword
      ignore_above: 1024
      description: MAC address of the destination.
    - name: nat.ip
      level: extended
      type: ip
      description: 'Translated ip of destination based NAT sessions (e.g. internet
        to private DMZ)

        Typically used with load balancers, firewalls, or routers.'
    - name: nat.port
      level: extended
      type: long
      format: string
      description: 'Port the source session is translated to by NAT Device.

        Typically used with load balancers, firewalls, or routers.'
    - name: packets
      level: core
      type: long
      description: Packets sent from the destination to the source.
      example: 12
    - name: port
      level: core
      type: long
      format: string
      description: Port of the destination.
    - name: registered_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The highest registered destination domain, stripped of the subdomain.

        For example, the registered domain for "foo.google.com" is "google.com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last two labels will not work well for TLDs such as "co.uk".'
      example: google.com
    - name: top_level_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The effective top level domain (eTLD), also known as the domain
        suffix, is the last part of the domain name. For example, the top level domain
        for google.com is "com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last label will not work well for effective TLDs such as "co.uk".'
      example: co.uk
    - name: user.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the user is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.email
      level: extended
      type: keyword
      ignore_above: 1024
      description: User email address.
    - name: user.full_name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: User's full name, if available.
      example: Albert Einstein
    - name: user.group.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.group.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: user.group.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
    - name: user.hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique user hash to correlate information for a user in anonymized
        form.

        Useful if `user.id` or `user.name` contain confidential information and cannot
        be used.'
    - name: user.id
      level: core
      type: keyword
      ignore_above: 1024
      description: One or multiple unique identifiers of the user.
    - name: user.name
      level: core
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Short name or login of the user.
      example: albert
  - name: dns
    title: DNS
    group: 2
    description: 'Fields describing DNS queries and answers.

      DNS events should either represent a single DNS query prior to getting answers
      (`dns.type:query`) or they should represent a full exchange and contain the
      query details as well as all of the answers that were provided for this query
      (`dns.type:answer`).'
    type: group
    fields:
    - name: answers
      level: extended
      type: object
      object_type: keyword
      description: 'An array containing an object for each answer section returned
        by the server.

        The main keys that should be present in these objects are defined by ECS.
        Records that have more information may contain more keys than what ECS defines.

        Not all DNS data sources give all details about DNS answers. At minimum, answer
        objects must contain the `data` key. If more information is available, map
        as much of it to ECS as possible, and add any additional fields to the answer
        objects as custom fields.'
    - name: answers.class
      level: extended
      type: keyword
      ignore_above: 1024
      description: The class of DNS data contained in this resource record.
      example: IN
    - name: answers.data
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The data describing the resource.

        The meaning of this data depends on the type and class of the resource record.'
      example: 10.10.10.10
    - name: answers.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The domain name to which this resource record pertains.

        If a chain of CNAME is being resolved, each answer''s `name` should be the
        one that corresponds with the answer''s `data`. It should not simply be the
        original `question.name` repeated.'
      example: www.google.com
    - name: answers.ttl
      level: extended
      type: long
      description: The time interval in seconds that this resource record may be cached
        before it should be discarded. Zero values mean that the data should not be
        cached.
      example: 180
    - name: answers.type
      level: extended
      type: keyword
      ignore_above: 1024
      description: The type of data contained in this resource record.
      example: CNAME
    - name: header_flags
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Array of 2 letter DNS header flags.

        Expected values are: AA, TC, RD, RA, AD, CD, DO.'
      example:
      - RD
      - RA
    - name: id
      level: extended
      type: keyword
      ignore_above: 1024
      description: The DNS packet identifier assigned by the program that generated
        the query. The identifier is copied to the response.
      example: 62111
    - name: op_code
      level: extended
      type: keyword
      ignore_above: 1024
      description: The DNS operation code that specifies the kind of query in the
        message. This value is set by the originator of a query and copied into the
        response.
      example: QUERY
    - name: question.class
      level: extended
      type: keyword
      ignore_above: 1024
      description: The class of records being queried.
      example: IN
    - name: question.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The name being queried.

        If the name field contains non-printable characters (below 32 or above 126),
        those characters should be represented as escaped base 10 integers (\DDD).
        Back slashes and quotes should be escaped. Tabs, carriage returns, and line
        feeds should be converted to \t, \r, and \n respectively.'
      example: www.google.com
    - name: question.registered_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The highest registered domain, stripped of the subdomain.

        For example, the registered domain for "foo.google.com" is "google.com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last two labels will not work well for TLDs such as "co.uk".'
      example: google.com
    - name: question.subdomain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The subdomain is all of the labels under the registered_domain.

        If the domain has multiple levels of subdomain, such as "sub2.sub1.example.com",
        the subdomain field should contain "sub2.sub1", with no trailing period.'
      example: www
    - name: question.top_level_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The effective top level domain (eTLD), also known as the domain
        suffix, is the last part of the domain name. For example, the top level domain
        for google.com is "com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last label will not work well for effective TLDs such as "co.uk".'
      example: co.uk
    - name: question.type
      level: extended
      type: keyword
      ignore_above: 1024
      description: The type of record being queried.
      example: AAAA
    - name: resolved_ip
      level: extended
      type: ip
      description: 'Array containing all IPs seen in `answers.data`.

        The `answers` array can be difficult to use, because of the variety of data
        formats it can contain. Extracting all IP addresses seen in there to `dns.resolved_ip`
        makes it possible to index them as IP addresses, and makes them easier to
        visualize and query for.'
      example:
      - 10.10.10.10
      - 10.10.10.11
    - name: response_code
      level: extended
      type: keyword
      ignore_above: 1024
      description: The DNS response code.
      example: NOERROR
    - name: type
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The type of DNS event captured, query or answer.

        If your source of DNS events only gives you DNS queries, you should only create
        dns events of type `dns.type:query`.

        If your source of DNS events gives you answers as well, you should create
        one event per query (optionally as soon as the query is seen). And a second
        event containing all query details as well as an array of answers.'
      example: answer
  - name: ecs
    title: ECS
    group: 2
    description: Meta-information specific to ECS.
    type: group
    fields:
    - name: version
      level: core
      required: true
      type: keyword
      ignore_above: 1024
      description: 'ECS version this event conforms to. `ecs.version` is a required
        field and must exist in all events.

        When querying across multiple indices -- which may conform to slightly different
        ECS versions -- this field lets integrations adjust to the schema version
        of the events.'
      example: 1.0.0
  - name: error
    title: Error
    group: 2
    description: 'These fields can represent errors of any kind.

      Use them for errors that happen while fetching events or in cases where the
      event itself contains an error.'
    type: group
    fields:
    - name: code
      level: core
      type: keyword
      ignore_above: 1024
      description: Error code describing the error.
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the error.
    - name: message
      level: core
      type: text
      description: Error message.
    - name: stack_trace
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: The stack trace of this error in plain text.
    - name: type
      level: extended
      type: keyword
      ignore_above: 1024
      description: The type of the error, for example the class name of the exception.
      example: java.lang.NullPointerException
  - name: event
    title: Event
    group: 2
    description: 'The event fields are used for context information about the log
      or metric event itself.

      A log is defined as an event containing details of something that happened.
      Log events must include the time at which the thing happened. Examples of log
      events include a process starting on a host, a network packet being sent from
      a source to a destination, or a network connection between a client and a server
      being initiated or closed. A metric is defined as an event containing one or
      more numerical or categorical measurements and the time at which the measurement
      was taken. Examples of metric events include memory pressure measured on a host,
      or vulnerabilities measured on a scanned host.'
    type: group
    fields:
    - name: action
      level: core
      type: keyword
      ignore_above: 1024
      description: 'The action captured by the event.

        This describes the information in the event. It is more specific than `event.category`.
        Examples are `group-add`, `process-started`, `file-created`. The value is
        normally defined by the implementer.'
      example: user-password-change
    - name: category
      level: core
      type: keyword
      ignore_above: 1024
      description: 'This is one of four ECS Categorization Fields, and indicates the
        second level in the ECS category hierarchy.

        `event.category` represents the "big buckets" of ECS categories. For example,
        filtering on `event.category:process` yields all events relating to process
        activity. This field is closely related to `event.type`, which is used as
        a subcategory.

        This field is an array. This will allow proper categorization of some events
        that fall in multiple categories.'
      example: authentication
    - name: code
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Identification code for this event, if one exists.

        Some event sources use event codes to identify messages unambiguously, regardless
        of message language or wording adjustments over time. An example of this is
        the Windows Event ID.'
      example: 4648
    - name: created
      level: core
      type: date
      description: 'event.created contains the date/time when the event was first
        read by an agent, or by your pipeline.

        This field is distinct from @timestamp in that @timestamp typically contain
        the time extracted from the original event.

        In most situations, these two timestamps will be slightly different. The difference
        can be used to calculate the delay between your source generating an event,
        and the time when your agent first processed it. This can be used to monitor
        your agent''s or pipeline''s ability to keep up with your event source.

        In case the two timestamps are identical, @timestamp should be used.'
      example: 2016-05-23 08:05:34.857000
    - name: dataset
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Name of the dataset.

        If an event source publishes more than one type of log or events (e.g. access
        log, error log), the dataset is used to specify which one the event comes
        from.

        It''s recommended but not required to start the dataset name with the module
        name, followed by a dot, then the dataset name.'
      example: apache.access
    - name: duration
      level: core
      type: long
      format: duration
      input_format: nanoseconds
      output_format: asMilliseconds
      output_precision: 1
      description: 'Duration of the event in nanoseconds.

        If event.start and event.end are known this value should be the difference
        between the end and start time.'
    - name: end
      level: extended
      type: date
      description: event.end contains the date when the event ended or when the activity
        was last observed.
    - name: hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: Hash (perhaps logstash fingerprint) of raw field to be able to
        demonstrate log integrity.
      example: 123456789012345678901234567890ABCD
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: Unique ID to describe the event.
      example: 8a4f500d
    - name: ingested
      level: core
      type: date
      description: 'Timestamp when an event arrived in the central data store.

        This is different from `@timestamp`, which is when the event originally occurred.  It''s
        also different from `event.created`, which is meant to capture the first time
        an agent saw the event.

        In normal conditions, assuming no tampering, the timestamps should chronologically
        look like this: `@timestamp` < `event.created` < `event.ingested`.'
      example: 2016-05-23 08:05:35.101000
      default_field: false
    - name: kind
      level: core
      type: keyword
      ignore_above: 1024
      description: 'This is one of four ECS Categorization Fields, and indicates the
        highest level in the ECS category hierarchy.

        `event.kind` gives high-level information about what type of information the
        event contains, without being specific to the contents of the event. For example,
        values of this field distinguish alert events from metric events.

        The value of this field can be used to inform how these kinds of events should
        be handled. They may warrant different retention, different access control,
        it may also help understand whether the data coming in at a regular interval
        or not.'
      example: alert
    - name: module
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Name of the module this data is coming from.

        If your monitoring agent supports the concept of modules or plugins to process
        events of a given source (e.g. Apache logs), `event.module` should contain
        the name of this module.'
      example: apache
    - name: original
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Raw text message of entire event. Used to demonstrate log integrity.

        This field is not indexed and doc_values are disabled. It cannot be searched,
        but it can be retrieved from `_source`.'
      example: Sep 19 08:26:10 host CEF:0&#124;Security&#124; threatmanager&#124;1.0&#124;100&#124;
        worm successfully stopped&#124;10&#124;src=10.0.0.1 dst=2.1.2.2spt=1232
    - name: outcome
      level: core
      type: keyword
      ignore_above: 1024
      description: 'This is one of four ECS Categorization Fields, and indicates the
        lowest level in the ECS category hierarchy.

        `event.outcome` simply denotes whether the event represent a success or a
        failure. Note that not all events will have an associated outcome. For example,
        this field is generally not populated for metric events or events with `event.type:info`.'
      example: success
    - name: provider
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Source of the event.

        Event transports such as Syslog or the Windows Event Log typically mention
        the source of an event. It can be the name of the software that generated
        the event (e.g. Sysmon, httpd), or of a subsystem of the operating system
        (kernel, Microsoft-Windows-Security-Auditing).'
      example: kernel
    - name: risk_score
      level: core
      type: float
      description: Risk score or priority of the event (e.g. security solutions).
        Use your system's original value here.
    - name: risk_score_norm
      level: extended
      type: float
      description: 'Normalized risk score or priority of the event, on a scale of
        0 to 100.

        This is mainly useful if you use more than one system that assigns risk scores,
        and you want to see a normalized value across all systems.'
    - name: sequence
      level: extended
      type: long
      format: string
      description: 'Sequence number of the event.

        The sequence number is a value published by some event sources, to make the
        exact ordering of events unambiguous, regarless of the timestamp precision.'
    - name: severity
      level: core
      type: long
      format: string
      description: 'The numeric severity of the event according to your event source.

        What the different severity values mean can be different between sources and
        use cases. It''s up to the implementer to make sure severities are consistent
        across events from the same source.

        The Syslog severity belongs in `log.syslog.severity.code`. `event.severity`
        is meant to represent the severity according to the event source (e.g. firewall,
        IDS). If the event source does not publish its own severity, you may optionally
        copy the `log.syslog.severity.code` to `event.severity`.'
      example: 7
    - name: start
      level: extended
      type: date
      description: event.start contains the date when the event started or when the
        activity was first observed.
    - name: timezone
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'This field should be populated when the event''s timestamp does
        not include timezone information already (e.g. default Syslog timestamps).
        It''s optional otherwise.

        Acceptable timezone formats are: a canonical ID (e.g. "Europe/Amsterdam"),
        abbreviated (e.g. "EST") or an HH:mm differential (e.g. "-05:00").'
    - name: type
      level: core
      type: keyword
      ignore_above: 1024
      description: 'This is one of four ECS Categorization Fields, and indicates the
        third level in the ECS category hierarchy.

        `event.type` represents a categorization "sub-bucket" that, when used along
        with the `event.category` field values, enables filtering events down to a
        level appropriate for single visualization.

        This field is an array. This will allow proper categorization of some events
        that fall in multiple event types.'
  - name: file
    title: File
    group: 2
    description: 'A file is defined as a set of information that has been created
      on, or has existed on a filesystem.

      File objects can be associated with host events, network events, and/or file
      events (e.g., those produced by File Integrity Monitoring [FIM] products or
      services). File fields provide details about the affected file associated with
      the event or metric.'
    type: group
    fields:
    - name: accessed
      level: extended
      type: date
      description: 'Last time the file was accessed.

        Note that not all filesystems keep track of access time.'
    - name: attributes
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Array of file attributes.

        Attributes names will vary by platform. Here''s a non-exhaustive list of values
        that are expected in this field: archive, compressed, directory, encrypted,
        execute, hidden, read, readonly, system, write.'
      example: '["readonly", "system"]'
      default_field: false
    - name: created
      level: extended
      type: date
      description: 'File creation time.

        Note that not all filesystems store the creation time.'
    - name: ctime
      level: extended
      type: date
      description: 'Last time the file attributes or metadata changed.

        Note that changes to the file content will update `mtime`. This implies `ctime`
        will be adjusted at the same time, since `mtime` is an attribute of the file.'
    - name: device
      level: extended
      type: keyword
      ignore_above: 1024
      description: Device that is the source of the file.
      example: sda
    - name: directory
      level: extended
      type: keyword
      ignore_above: 1024
      description: Directory where the file is located. It should include the drive
        letter, when appropriate.
      example: /home/alice
    - name: drive_letter
      level: extended
      type: keyword
      ignore_above: 1
      description: 'Drive letter where the file is located. This field is only relevant
        on Windows.

        The value should be uppercase, and not include the colon.'
      example: C
      default_field: false
    - name: extension
      level: extended
      type: keyword
      ignore_above: 1024
      description: File extension.
      example: png
    - name: gid
      level: extended
      type: keyword
      ignore_above: 1024
      description: Primary group ID (GID) of the file.
      example: '1001'
    - name: group
      level: extended
      type: keyword
      ignore_above: 1024
      description: Primary group name of the file.
      example: alice
    - name: hash.md5
      level: extended
      type: keyword
      ignore_above: 1024
      description: MD5 hash.
    - name: hash.sha1
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA1 hash.
    - name: hash.sha256
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA256 hash.
    - name: hash.sha512
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA512 hash.
    - name: inode
      level: extended
      type: keyword
      ignore_above: 1024
      description: Inode representing the file in the filesystem.
      example: '256383'
    - name: mode
      level: extended
      type: keyword
      ignore_above: 1024
      description: Mode of the file in octal representation.
      example: '0640'
    - name: mtime
      level: extended
      type: date
      description: Last time the file content was modified.
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the file including the extension, without the directory.
      example: example.png
    - name: owner
      level: extended
      type: keyword
      ignore_above: 1024
      description: File owner's username.
      example: alice
    - name: path
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Full path to the file, including the file name. It should include
        the drive letter, when appropriate.
      example: /home/alice/example.png
    - name: size
      level: extended
      type: long
      description: 'File size in bytes.

        Only relevant when `file.type` is "file".'
      example: 16384
    - name: target_path
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Target path for symlinks.
    - name: type
      level: extended
      type: keyword
      ignore_above: 1024
      description: File type (file, dir, or symlink).
      example: file
    - name: uid
      level: extended
      type: keyword
      ignore_above: 1024
      description: The user ID (UID) or security identifier (SID) of the file owner.
      example: '1001'
  - name: geo
    title: Geo
    group: 2
    description: 'Geo fields can carry data about a specific location related to an
      event.

      This geolocation information can be derived from techniques such as Geo IP,
      or be user-supplied.'
    type: group
    fields:
    - name: city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
  - name: group
    title: Group
    group: 2
    description: The group fields are meant to represent groups that are relevant
      to the event.
    type: group
    fields:
    - name: domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
  - name: hash
    title: Hash
    group: 2
    description: 'The hash fields represent different hash algorithms and their values.

      Field names for common hashes (e.g. MD5, SHA1) are predefined. Add fields for
      other hashes by lowercasing the hash algorithm name and using underscore separators
      as appropriate (snake case, e.g. sha3_512).'
    type: group
    fields:
    - name: md5
      level: extended
      type: keyword
      ignore_above: 1024
      description: MD5 hash.
    - name: sha1
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA1 hash.
    - name: sha256
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA256 hash.
    - name: sha512
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA512 hash.
  - name: host
    title: Host
    group: 2
    description: 'A host is defined as a general computing instance.

      ECS host.* fields should be populated with details about the host on which the
      event happened, or from which the measurement was taken. Host types include
      hardware, virtual machines, Docker containers, and Kubernetes nodes.'
    type: group
    fields:
    - name: architecture
      level: core
      type: keyword
      ignore_above: 1024
      description: Operating system architecture.
      example: x86_64
    - name: domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the domain of which the host is a member.

        For example, on Windows this could be the host''s Active Directory domain
        or NetBIOS domain name. For Linux this could be the domain of the host''s
        LDAP provider.'
      example: CONTOSO
      default_field: false
    - name: geo.city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: geo.continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: geo.country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: geo.country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: geo.location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: geo.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: geo.region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: geo.region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
    - name: hostname
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Hostname of the host.

        It normally contains what the `hostname` command returns on the host machine.'
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Unique host id.

        As hostname is not always unique, use values that are meaningful in your environment.

        Example: The current usage of `beat.name`.'
    - name: ip
      level: core
      type: ip
      description: Host ip address.
    - name: mac
      level: core
      type: keyword
      ignore_above: 1024
      description: Host mac address.
    - name: name
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Name of the host.

        It can contain what `hostname` returns on Unix systems, the fully qualified
        domain name, or a name specified by the user. The sender decides which value
        to use.'
    - name: os.family
      level: extended
      type: keyword
      ignore_above: 1024
      description: OS family (such as redhat, debian, freebsd, windows).
      example: debian
    - name: os.full
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, including the version or code name.
      example: Mac OS Mojave
    - name: os.kernel
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system kernel version as a raw string.
      example: 4.4.0-112-generic
    - name: os.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, without the version.
      example: Mac OS X
    - name: os.platform
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system platform (such centos, ubuntu, windows).
      example: darwin
    - name: os.version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system version as a raw string.
      example: 10.14.1
    - name: type
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Type of host.

        For Cloud providers this can be the machine type like `t2.medium`. If vm,
        this could be the container, for example, or other information meaningful
        in your environment.'
    - name: uptime
      level: extended
      type: long
      description: Seconds the host has been up.
      example: 1325
    - name: user.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the user is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.email
      level: extended
      type: keyword
      ignore_above: 1024
      description: User email address.
    - name: user.full_name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: User's full name, if available.
      example: Albert Einstein
    - name: user.group.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.group.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: user.group.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
    - name: user.hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique user hash to correlate information for a user in anonymized
        form.

        Useful if `user.id` or `user.name` contain confidential information and cannot
        be used.'
    - name: user.id
      level: core
      type: keyword
      ignore_above: 1024
      description: One or multiple unique identifiers of the user.
    - name: user.name
      level: core
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Short name or login of the user.
      example: albert
  - name: http
    title: HTTP
    group: 2
    description: Fields related to HTTP activity. Use the `url` field set to store
      the url of the request.
    type: group
    fields:
    - name: request.body.bytes
      level: extended
      type: long
      format: bytes
      description: Size in bytes of the request body.
      example: 887
    - name: request.body.content
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: The full HTTP request body.
      example: Hello world
    - name: request.bytes
      level: extended
      type: long
      format: bytes
      description: Total size in bytes of the request (body and headers).
      example: 1437
    - name: request.method
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'HTTP request method.

        The field value must be normalized to lowercase for querying. See the documentation
        section "Implementing ECS".'
      example: get, post, put
    - name: request.referrer
      level: extended
      type: keyword
      ignore_above: 1024
      description: Referrer for this HTTP request.
      example: https://blog.example.com/
    - name: response.body.bytes
      level: extended
      type: long
      format: bytes
      description: Size in bytes of the response body.
      example: 887
    - name: response.body.content
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: The full HTTP response body.
      example: Hello world
    - name: response.bytes
      level: extended
      type: long
      format: bytes
      description: Total size in bytes of the response (body and headers).
      example: 1437
    - name: response.status_code
      level: extended
      type: long
      format: string
      description: HTTP response status code.
      example: 404
    - name: version
      level: extended
      type: keyword
      ignore_above: 1024
      description: HTTP version.
      example: 1.1
  - name: log
    title: Log
    group: 2
    description: 'Details about the event''s logging mechanism or logging transport.

      The log.* fields are typically populated with details about the logging mechanism
      used to create and/or transport the event. For example, syslog details belong
      under `log.syslog.*`.

      The details specific to your event source are typically not logged under `log.*`,
      but rather in `event.*` or in other ECS fields.'
    type: group
    fields:
    - name: level
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Original log level of the log event.

        If the source of the event provides a log level or textual severity, this
        is the one that goes in `log.level`. If your source doesn''t specify one,
        you may put your event transport''s severity here (e.g. Syslog severity).

        Some examples are `warn`, `err`, `i`, `informational`.'
      example: error
    - name: logger
      level: core
      type: keyword
      ignore_above: 1024
      description: The name of the logger inside an application. This is usually the
        name of the class which initialized the logger, or can be a custom name.
      example: org.elasticsearch.bootstrap.Bootstrap
    - name: origin.file.line
      level: extended
      type: integer
      description: The line number of the file containing the source code which originated
        the log event.
      example: 42
    - name: origin.file.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: The name of the file containing the source code which originated
        the log event. Note that this is not the name of the log file.
      example: Bootstrap.java
    - name: origin.function
      level: extended
      type: keyword
      ignore_above: 1024
      description: The name of the function or method which originated the log event.
      example: init
    - name: original
      level: core
      type: keyword
      ignore_above: 1024
      description: 'This is the original log message and contains the full log message
        before splitting it up in multiple parts.

        In contrast to the `message` field which can contain an extracted part of
        the log message, this field contains the original, full log message. It can
        have already some modifications applied like encoding or new lines removed
        to clean up the log message.

        This field is not indexed and doc_values are disabled so it can''t be queried
        but the value can be retrieved from `_source`.'
      example: Sep 19 08:26:10 localhost My log
    - name: syslog
      level: extended
      type: object
      object_type: keyword
      description: The Syslog metadata of the event, if the event was transmitted
        via Syslog. Please see RFCs 5424 or 3164.
    - name: syslog.facility.code
      level: extended
      type: long
      format: string
      description: 'The Syslog numeric facility of the log event, if available.

        According to RFCs 5424 and 3164, this value should be an integer between 0
        and 23.'
      example: 23
    - name: syslog.facility.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: The Syslog text-based facility of the log event, if available.
      example: local7
    - name: syslog.priority
      level: extended
      type: long
      format: string
      description: 'Syslog numeric priority of the event, if available.

        According to RFCs 5424 and 3164, the priority is 8 * facility + severity.
        This number is therefore expected to contain a value between 0 and 191.'
      example: 135
    - name: syslog.severity.code
      level: extended
      type: long
      description: 'The Syslog numeric severity of the log event, if available.

        If the event source publishing via Syslog provides a different numeric severity
        value (e.g. firewall, IDS), your source''s numeric severity should go to `event.severity`.
        If the event source does not specify a distinct severity, you can optionally
        copy the Syslog severity to `event.severity`.'
      example: 3
    - name: syslog.severity.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The Syslog numeric severity of the log event, if available.

        If the event source publishing via Syslog provides a different severity value
        (e.g. firewall, IDS), your source''s text severity should go to `log.level`.
        If the event source does not specify a distinct severity, you can optionally
        copy the Syslog severity to `log.level`.'
      example: Error
  - name: network
    title: Network
    group: 2
    description: 'The network is defined as the communication path over which a host
      or network event happens.

      The network.* fields should be populated with details about the network activity
      associated with an event.'
    type: group
    fields:
    - name: application
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'A name given to an application level protocol. This can be arbitrarily
        assigned for things like microservices, but also apply to things like skype,
        icq, facebook, twitter. This would be used in situations where the vendor
        or service can be decoded such as from the source/dest IP owners, ports, or
        wire format.

        The field value must be normalized to lowercase for querying. See the documentation
        section "Implementing ECS".'
      example: aim
    - name: bytes
      level: core
      type: long
      format: bytes
      description: 'Total bytes transferred in both directions.

        If `source.bytes` and `destination.bytes` are known, `network.bytes` is their
        sum.'
      example: 368
    - name: community_id
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'A hash of source and destination IPs and ports, as well as the
        protocol used in a communication. This is a tool-agnostic standard to identify
        flows.

        Learn more at https://github.com/corelight/community-id-spec.'
      example: 1:hO+sN4H+MG5MY/8hIrXPqc4ZQz0=
    - name: direction
      level: core
      type: keyword
      ignore_above: 1024
      description: "Direction of the network traffic.\nRecommended values are:\n \
        \ * inbound\n  * outbound\n  * internal\n  * external\n  * unknown\n\nWhen\
        \ mapping events from a host-based monitoring context, populate this field\
        \ from the host's point of view.\nWhen mapping events from a network or perimeter-based\
        \ monitoring context, populate this field from the point of view of your network\
        \ perimeter."
      example: inbound
    - name: forwarded_ip
      level: core
      type: ip
      description: Host IP address when the source IP address is the proxy.
      example: 192.1.1.2
    - name: iana_number
      level: extended
      type: keyword
      ignore_above: 1024
      description: IANA Protocol Number (https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml).
        Standardized list of protocols. This aligns well with NetFlow and sFlow related
        logs which use the IANA Protocol Number.
      example: 6
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name given by operators to sections of their network.
      example: Guest Wifi
    - name: packets
      level: core
      type: long
      description: 'Total packets transferred in both directions.

        If `source.packets` and `destination.packets` are known, `network.packets`
        is their sum.'
      example: 24
    - name: protocol
      level: core
      type: keyword
      ignore_above: 1024
      description: 'L7 Network protocol name. ex. http, lumberjack, transport protocol.

        The field value must be normalized to lowercase for querying. See the documentation
        section "Implementing ECS".'
      example: http
    - name: transport
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Same as network.iana_number, but instead using the Keyword name
        of the transport layer (udp, tcp, ipv6-icmp, etc.)

        The field value must be normalized to lowercase for querying. See the documentation
        section "Implementing ECS".'
      example: tcp
    - name: type
      level: core
      type: keyword
      ignore_above: 1024
      description: 'In the OSI Model this would be the Network Layer. ipv4, ipv6,
        ipsec, pim, etc

        The field value must be normalized to lowercase for querying. See the documentation
        section "Implementing ECS".'
      example: ipv4
  - name: observer
    title: Observer
    group: 2
    description: 'An observer is defined as a special network, security, or application
      device used to detect, observe, or create network, security, or application-related
      events and metrics.

      This could be a custom hardware appliance or a server that has been configured
      to run special network, security, or application software. Examples include
      firewalls, web proxies, intrusion detection/prevention systems, network monitoring
      sensors, web application firewalls, data loss prevention systems, and APM servers.
      The observer.* fields shall be populated with details of the system, if any,
      that detects, observes and/or creates a network, security, or application event
      or metric. Message queues and ETL components used in processing events or metrics
      are not considered observers in ECS.'
    type: group
    fields:
    - name: geo.city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: geo.continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: geo.country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: geo.country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: geo.location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: geo.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: geo.region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: geo.region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
    - name: hostname
      level: core
      type: keyword
      ignore_above: 1024
      description: Hostname of the observer.
    - name: ip
      level: core
      type: ip
      description: IP address of the observer.
    - name: mac
      level: core
      type: keyword
      ignore_above: 1024
      description: MAC address of the observer
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Custom name of the observer.

        This is a name that can be given to an observer. This can be helpful for example
        if multiple firewalls of the same model are used in an organization.

        If no custom name is needed, the field can be left empty.'
      example: 1_proxySG
    - name: os.family
      level: extended
      type: keyword
      ignore_above: 1024
      description: OS family (such as redhat, debian, freebsd, windows).
      example: debian
    - name: os.full
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, including the version or code name.
      example: Mac OS Mojave
    - name: os.kernel
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system kernel version as a raw string.
      example: 4.4.0-112-generic
    - name: os.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, without the version.
      example: Mac OS X
    - name: os.platform
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system platform (such centos, ubuntu, windows).
      example: darwin
    - name: os.version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system version as a raw string.
      example: 10.14.1
    - name: product
      level: extended
      type: keyword
      ignore_above: 1024
      description: The product name of the observer.
      example: s200
    - name: serial_number
      level: extended
      type: keyword
      ignore_above: 1024
      description: Observer serial number.
    - name: type
      level: core
      type: keyword
      ignore_above: 1024
      description: 'The type of the observer the data is coming from.

        There is no predefined list of observer types. Some examples are `forwarder`,
        `firewall`, `ids`, `ips`, `proxy`, `poller`, `sensor`, `APM server`.'
      example: firewall
    - name: vendor
      level: core
      type: keyword
      ignore_above: 1024
      description: Vendor name of the observer.
      example: Symantec
    - name: version
      level: core
      type: keyword
      ignore_above: 1024
      description: Observer version.
  - name: organization
    title: Organization
    group: 2
    description: 'The organization fields enrich data with information about the company
      or entity the data is associated with.

      These fields help you arrange or filter data stored in an index by one or multiple
      organizations.'
    type: group
    fields:
    - name: id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the organization.
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Organization name.
  - name: os
    title: Operating System
    group: 2
    description: The OS fields contain information about the operating system.
    type: group
    fields:
    - name: family
      level: extended
      type: keyword
      ignore_above: 1024
      description: OS family (such as redhat, debian, freebsd, windows).
      example: debian
    - name: full
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, including the version or code name.
      example: Mac OS Mojave
    - name: kernel
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system kernel version as a raw string.
      example: 4.4.0-112-generic
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, without the version.
      example: Mac OS X
    - name: platform
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system platform (such centos, ubuntu, windows).
      example: darwin
    - name: version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system version as a raw string.
      example: 10.14.1
  - name: package
    title: Package
    group: 2
    description: These fields contain information about an installed software package.
      It contains general information about a package, such as name, version or size.
      It also contains installation details, such as time or location.
    type: group
    fields:
    - name: architecture
      level: extended
      type: keyword
      ignore_above: 1024
      description: Package architecture.
      example: x86_64
    - name: build_version
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Additional information about the build version of the installed
        package.

        For example use the commit SHA of a non-released package.'
      example: 36f4f7e89dd61b0988b12ee000b98966867710cd
      default_field: false
    - name: checksum
      level: extended
      type: keyword
      ignore_above: 1024
      description: Checksum of the installed package for verification.
      example: 68b329da9893e34099c7d8ad5cb9c940
    - name: description
      level: extended
      type: keyword
      ignore_above: 1024
      description: Description of the package.
      example: Open source programming language to build simple/reliable/efficient
        software.
    - name: install_scope
      level: extended
      type: keyword
      ignore_above: 1024
      description: Indicating how the package was installed, e.g. user-local, global.
      example: global
    - name: installed
      level: extended
      type: date
      description: Time when package was installed.
    - name: license
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'License under which the package was released.

        Use a short name, e.g. the license identifier from SPDX License List where
        possible (https://spdx.org/licenses/).'
      example: Apache License 2.0
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Package name
      example: go
    - name: path
      level: extended
      type: keyword
      ignore_above: 1024
      description: Path where the package is installed.
      example: /usr/local/Cellar/go/1.12.9/
    - name: reference
      level: extended
      type: keyword
      ignore_above: 1024
      description: Home page or reference URL of the software in this package, if
        available.
      example: https://golang.org
      default_field: false
    - name: size
      level: extended
      type: long
      format: string
      description: Package size in bytes.
      example: 62231
    - name: type
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Type of package.

        This should contain the package file type, rather than the package manager
        name. Examples: rpm, dpkg, brew, npm, gem, nupkg, jar.'
      example: rpm
      default_field: false
    - name: version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Package version
      example: 1.12.9
  - name: process
    title: Process
    group: 2
    description: 'These fields contain information about a process.

      These fields can help you correlate metrics information with a process id/name
      from a log message.  The `process.pid` often stays in the metric itself and
      is copied to the global field for correlation.'
    type: group
    fields:
    - name: args
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Array of process arguments, starting with the absolute path to
        the executable.

        May be filtered to protect sensitive information.'
      example:
      - /usr/bin/ssh
      - -l
      - user
      - 10.0.0.16
    - name: args_count
      level: extended
      type: long
      description: 'Length of the process.args array.

        This field can be useful for querying or performing bucket analysis on how
        many arguments were provided to start a process. More arguments may be an
        indication of suspicious activity.'
      example: 4
      default_field: false
    - name: command_line
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: 'Full command line that started the process, including the absolute
        path to the executable, and all arguments.

        Some arguments may be filtered to protect sensitive information.'
      example: /usr/bin/ssh -l user 10.0.0.16
      default_field: false
    - name: executable
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Absolute path to the process executable.
      example: /usr/bin/ssh
    - name: exit_code
      level: extended
      type: long
      description: 'The exit code of the process, if this is a termination event.

        The field should be absent if there is no exit code for the event (e.g. process
        start).'
      example: 137
      default_field: false
    - name: hash.md5
      level: extended
      type: keyword
      ignore_above: 1024
      description: MD5 hash.
    - name: hash.sha1
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA1 hash.
    - name: hash.sha256
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA256 hash.
    - name: hash.sha512
      level: extended
      type: keyword
      ignore_above: 1024
      description: SHA512 hash.
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: 'Process name.

        Sometimes called program name or similar.'
      example: ssh
    - name: parent.args
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Array of process arguments.

        May be filtered to protect sensitive information.'
      example:
      - ssh
      - -l
      - user
      - 10.0.0.16
      default_field: false
    - name: parent.args_count
      level: extended
      type: long
      description: 'Length of the process.args array.

        This field can be useful for querying or performing bucket analysis on how
        many arguments were provided to start a process. More arguments may be an
        indication of suspicious activity.'
      example: 4
      default_field: false
    - name: parent.command_line
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: 'Full command line that started the process, including the absolute
        path to the executable, and all arguments.

        Some arguments may be filtered to protect sensitive information.'
      example: /usr/bin/ssh -l user 10.0.0.16
      default_field: false
    - name: parent.executable
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: Absolute path to the process executable.
      example: /usr/bin/ssh
      default_field: false
    - name: parent.exit_code
      level: extended
      type: long
      description: 'The exit code of the process, if this is a termination event.

        The field should be absent if there is no exit code for the event (e.g. process
        start).'
      example: 137
      default_field: false
    - name: parent.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: 'Process name.

        Sometimes called program name or similar.'
      example: ssh
      default_field: false
    - name: parent.pgid
      level: extended
      type: long
      format: string
      description: Identifier of the group of processes the process belongs to.
      default_field: false
    - name: parent.pid
      level: core
      type: long
      format: string
      description: Process id.
      example: 4242
      default_field: false
    - name: parent.ppid
      level: extended
      type: long
      format: string
      description: Parent process' pid.
      example: 4241
      default_field: false
    - name: parent.start
      level: extended
      type: date
      description: The time the process started.
      example: '2016-05-23T08:05:34.853Z'
      default_field: false
    - name: parent.thread.id
      level: extended
      type: long
      format: string
      description: Thread ID.
      example: 4242
      default_field: false
    - name: parent.thread.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Thread name.
      example: thread-0
      default_field: false
    - name: parent.title
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: 'Process title.

        The proctitle, some times the same as process name. Can also be different:
        for example a browser setting its title to the web page currently opened.'
      default_field: false
    - name: parent.uptime
      level: extended
      type: long
      description: Seconds the process has been up.
      example: 1325
      default_field: false
    - name: parent.working_directory
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: The working directory of the process.
      example: /home/alice
      default_field: false
    - name: pgid
      level: extended
      type: long
      format: string
      description: Identifier of the group of processes the process belongs to.
    - name: pid
      level: core
      type: long
      format: string
      description: Process id.
      example: 4242
    - name: ppid
      level: extended
      type: long
      format: string
      description: Parent process' pid.
      example: 4241
    - name: start
      level: extended
      type: date
      description: The time the process started.
      example: '2016-05-23T08:05:34.853Z'
    - name: thread.id
      level: extended
      type: long
      format: string
      description: Thread ID.
      example: 4242
    - name: thread.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Thread name.
      example: thread-0
    - name: title
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: 'Process title.

        The proctitle, some times the same as process name. Can also be different:
        for example a browser setting its title to the web page currently opened.'
    - name: uptime
      level: extended
      type: long
      description: Seconds the process has been up.
      example: 1325
    - name: working_directory
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: The working directory of the process.
      example: /home/alice
  - name: registry
    title: Registry
    group: 2
    description: Fields related to Windows Registry operations.
    type: group
    fields:
    - name: data.bytes
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Original bytes written with base64 encoding.

        For Windows registry operations, such as SetValueEx and RegQueryValueEx, this
        corresponds to the data pointed by `lp_data`. This is optional but provides
        better recoverability and should be populated for REG_BINARY encoded values.'
      example: ZQBuAC0AVQBTAAAAZQBuAAAAAAA=
      default_field: false
    - name: data.strings
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Content when writing string types.

        Populated as an array when writing string data to the registry. For single
        string registry types (REG_SZ, REG_EXPAND_SZ), this should be an array with
        one string. For sequences of string with REG_MULTI_SZ, this array will be
        variable length. For numeric data, such as REG_DWORD and REG_QWORD, this should
        be populated with the decimal representation (e.g `"1"`).'
      example: '["C:\rta\red_ttp\bin\myapp.exe"]'
      default_field: false
    - name: data.type
      level: core
      type: keyword
      ignore_above: 1024
      description: Standard registry type for encoding contents
      example: REG_SZ
      default_field: false
    - name: hive
      level: core
      type: keyword
      ignore_above: 1024
      description: Abbreviated name for the hive.
      example: HKLM
      default_field: false
    - name: key
      level: core
      type: keyword
      ignore_above: 1024
      description: Hive-relative path of keys.
      example: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe
      default_field: false
    - name: path
      level: core
      type: keyword
      ignore_above: 1024
      description: Full path, including hive, key and value
      example: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
        Options\winword.exe\Debugger
      default_field: false
    - name: value
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the value written.
      example: Debugger
      default_field: false
  - name: related
    title: Related
    group: 2
    description: 'This field set is meant to facilitate pivoting around a piece of
      data.

      Some pieces of information can be seen in many places in an ECS event. To facilitate
      searching for them, store an array of all seen values to their corresponding
      field in `related.`.

      A concrete example is IP addresses, which can be under host, observer, source,
      destination, client, server, and network.forwarded_ip. If you append all IPs
      to `related.ip`, you can then search for a given IP trivially, no matter where
      it appeared, by querying `related.ip:a.b.c.d`.'
    type: group
    fields:
    - name: ip
      level: extended
      type: ip
      description: All of the IPs seen on your event.
    - name: user
      level: extended
      type: keyword
      ignore_above: 1024
      description: All the user names seen on your event.
      default_field: false
  - name: rule
    title: Rule
    group: 2
    description: 'Rule fields are used to capture the specifics of any observer or
      agent rules that generate alerts or other notable events.

      Examples of data sources that would populate the rule fields include: network
      admission control platforms, network or host IDS/IPS, network firewalls, web
      application firewalls, url filters, endpoint detection and response (EDR) systems,
      etc.'
    type: group
    fields:
    - name: category
      level: extended
      type: keyword
      ignore_above: 1024
      description: A categorization value keyword used by the entity using the rule
        for detection of this event.
      example: Attempted Information Leak
      default_field: false
    - name: description
      level: extended
      type: keyword
      ignore_above: 1024
      description: The description of the rule generating the event.
      example: Block requests to public DNS over HTTPS / TLS protocols
      default_field: false
    - name: id
      level: extended
      type: keyword
      ignore_above: 1024
      description: A rule ID that is unique within the scope of an agent, observer,
        or other entity using the rule for detection of this event.
      example: 101
      default_field: false
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: The name of the rule or signature generating the event.
      example: BLOCK_DNS_over_TLS
      default_field: false
    - name: reference
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Reference URL to additional information about the rule used to
        generate this event.

        The URL can point to the vendor''s documentation about the rule. If that''s
        not available, it can also be a link to a more general page describing this
        type of alert.'
      example: https://en.wikipedia.org/wiki/DNS_over_TLS
      default_field: false
    - name: ruleset
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the ruleset, policy, group, or parent category in which
        the rule used to generate this event is a member.
      example: Standard_Protocol_Filters
      default_field: false
    - name: uuid
      level: extended
      type: keyword
      ignore_above: 1024
      description: A rule ID that is unique within the scope of a set or group of
        agents, observers, or other entities using the rule for detection of this
        event.
      example: 1100110011
      default_field: false
    - name: version
      level: extended
      type: keyword
      ignore_above: 1024
      description: The version / revision of the rule being used for analysis.
      example: 1.1
      default_field: false
  - name: server
    title: Server
    group: 2
    description: 'A Server is defined as the responder in a network connection for
      events regarding sessions, connections, or bidirectional flow records.

      For TCP events, the server is the receiver of the initial SYN packet(s) of the
      TCP connection. For other protocols, the server is generally the responder in
      the network transaction. Some systems actually use the term "responder" to refer
      the server in TCP connections. The server fields describe details about the
      system acting as the server in the network event. Server fields are usually
      populated in conjunction with client fields. Server fields are generally not
      populated for packet-level events.

      Client / server representations can add semantic context to an exchange, which
      is helpful to visualize the data in certain situations. If your context falls
      in that category, you should still ensure that source and destination are filled
      appropriately.'
    type: group
    fields:
    - name: address
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Some event server addresses are defined ambiguously. The event
        will sometimes list an IP, a domain or a unix socket.  You should always store
        the raw address in the `.address` field.

        Then it should be duplicated to `.ip` or `.domain`, depending on which one
        it is.'
    - name: as.number
      level: extended
      type: long
      description: Unique number allocated to the autonomous system. The autonomous
        system number (ASN) uniquely identifies each network on the Internet.
      example: 15169
    - name: as.organization.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Organization name.
      example: Google LLC
    - name: bytes
      level: core
      type: long
      format: bytes
      description: Bytes sent from the server to the client.
      example: 184
    - name: domain
      level: core
      type: keyword
      ignore_above: 1024
      description: Server domain.
    - name: geo.city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: geo.continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: geo.country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: geo.country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: geo.location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: geo.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: geo.region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: geo.region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
    - name: ip
      level: core
      type: ip
      description: 'IP address of the server.

        Can be one or multiple IPv4 or IPv6 addresses.'
    - name: mac
      level: core
      type: keyword
      ignore_above: 1024
      description: MAC address of the server.
    - name: nat.ip
      level: extended
      type: ip
      description: 'Translated ip of destination based NAT sessions (e.g. internet
        to private DMZ)

        Typically used with load balancers, firewalls, or routers.'
    - name: nat.port
      level: extended
      type: long
      format: string
      description: 'Translated port of destination based NAT sessions (e.g. internet
        to private DMZ)

        Typically used with load balancers, firewalls, or routers.'
    - name: packets
      level: core
      type: long
      description: Packets sent from the server to the client.
      example: 12
    - name: port
      level: core
      type: long
      format: string
      description: Port of the server.
    - name: registered_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The highest registered server domain, stripped of the subdomain.

        For example, the registered domain for "foo.google.com" is "google.com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last two labels will not work well for TLDs such as "co.uk".'
      example: google.com
    - name: top_level_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The effective top level domain (eTLD), also known as the domain
        suffix, is the last part of the domain name. For example, the top level domain
        for google.com is "com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last label will not work well for effective TLDs such as "co.uk".'
      example: co.uk
    - name: user.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the user is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.email
      level: extended
      type: keyword
      ignore_above: 1024
      description: User email address.
    - name: user.full_name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: User's full name, if available.
      example: Albert Einstein
    - name: user.group.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.group.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: user.group.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
    - name: user.hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique user hash to correlate information for a user in anonymized
        form.

        Useful if `user.id` or `user.name` contain confidential information and cannot
        be used.'
    - name: user.id
      level: core
      type: keyword
      ignore_above: 1024
      description: One or multiple unique identifiers of the user.
    - name: user.name
      level: core
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Short name or login of the user.
      example: albert
  - name: service
    title: Service
    group: 2
    description: 'The service fields describe the service for or from which the data
      was collected.

      These fields help you find and correlate logs for a specific service and version.'
    type: group
    fields:
    - name: ephemeral_id
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Ephemeral identifier of this service (if one exists).

        This id normally changes across restarts, but `service.id` does not.'
      example: 8a4f500f
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Unique identifier of the running service. If the service is comprised
        of many nodes, the `service.id` should be the same for all nodes.

        This id should uniquely identify the service. This makes it possible to correlate
        logs and metrics for one specific service, no matter which particular node
        emitted the event.

        Note that if you need to see the events from one specific host of the service,
        you should filter on that `host.name` or `host.id` instead.'
      example: d37e5ebfe0ae6c4972dbe9f0174a1637bb8247f6
    - name: name
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Name of the service data is collected from.

        The name of the service is normally user given. This allows for distributed
        services that run on multiple hosts to correlate the related instances based
        on the name.

        In the case of Elasticsearch the `service.name` could contain the cluster
        name. For Beats the `service.name` is by default a copy of the `service.type`
        field if no name is specified.'
      example: elasticsearch-metrics
    - name: node.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of a service node.

        This allows for two nodes of the same service running on the same host to
        be differentiated. Therefore, `service.node.name` should typically be unique
        across nodes of a given service.

        In the case of Elasticsearch, the `service.node.name` could contain the unique
        node name within the Elasticsearch cluster. In cases where the service doesn''t
        have the concept of a node name, the host name or container name can be used
        to distinguish running instances that make up this service. If those do not
        provide uniqueness (e.g. multiple instances of the service running on the
        same host) - the node name can be manually set.'
      example: instance-0000000016
    - name: state
      level: core
      type: keyword
      ignore_above: 1024
      description: Current state of the service.
    - name: type
      level: core
      type: keyword
      ignore_above: 1024
      description: 'The type of the service data is collected from.

        The type can be used to group and correlate logs and metrics from one service
        type.

        Example: If logs or metrics are collected from Elasticsearch, `service.type`
        would be `elasticsearch`.'
      example: elasticsearch
    - name: version
      level: core
      type: keyword
      ignore_above: 1024
      description: 'Version of the service the data was collected from.

        This allows to look at a data set only for a specific version of a service.'
      example: 3.2.4
  - name: source
    title: Source
    group: 2
    description: 'Source fields describe details about the source of a packet/event.

      Source fields are usually populated in conjunction with destination fields.'
    type: group
    fields:
    - name: address
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Some event source addresses are defined ambiguously. The event
        will sometimes list an IP, a domain or a unix socket.  You should always store
        the raw address in the `.address` field.

        Then it should be duplicated to `.ip` or `.domain`, depending on which one
        it is.'
    - name: as.number
      level: extended
      type: long
      description: Unique number allocated to the autonomous system. The autonomous
        system number (ASN) uniquely identifies each network on the Internet.
      example: 15169
    - name: as.organization.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Organization name.
      example: Google LLC
    - name: bytes
      level: core
      type: long
      format: bytes
      description: Bytes sent from the source to the destination.
      example: 184
    - name: domain
      level: core
      type: keyword
      ignore_above: 1024
      description: Source domain.
    - name: geo.city_name
      level: core
      type: keyword
      ignore_above: 1024
      description: City name.
      example: Montreal
    - name: geo.continent_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Name of the continent.
      example: North America
    - name: geo.country_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Country ISO code.
      example: CA
    - name: geo.country_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Country name.
      example: Canada
    - name: geo.location
      level: core
      type: geo_point
      description: Longitude and latitude.
      example: '{ "lon": -73.614830, "lat": 45.505918 }'
    - name: geo.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'User-defined description of a location, at the level of granularity
        they care about.

        Could be the name of their data centers, the floor number, if this describes
        a local physical entity, city names.

        Not typically used in automated geolocation.'
      example: boston-dc
    - name: geo.region_iso_code
      level: core
      type: keyword
      ignore_above: 1024
      description: Region ISO code.
      example: CA-QC
    - name: geo.region_name
      level: core
      type: keyword
      ignore_above: 1024
      description: Region name.
      example: Quebec
    - name: ip
      level: core
      type: ip
      description: 'IP address of the source.

        Can be one or multiple IPv4 or IPv6 addresses.'
    - name: mac
      level: core
      type: keyword
      ignore_above: 1024
      description: MAC address of the source.
    - name: nat.ip
      level: extended
      type: ip
      description: 'Translated ip of source based NAT sessions (e.g. internal client
        to internet)

        Typically connections traversing load balancers, firewalls, or routers.'
    - name: nat.port
      level: extended
      type: long
      format: string
      description: 'Translated port of source based NAT sessions. (e.g. internal client
        to internet)

        Typically used with load balancers, firewalls, or routers.'
    - name: packets
      level: core
      type: long
      description: Packets sent from the source to the destination.
      example: 12
    - name: port
      level: core
      type: long
      format: string
      description: Port of the source.
    - name: registered_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The highest registered source domain, stripped of the subdomain.

        For example, the registered domain for "foo.google.com" is "google.com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last two labels will not work well for TLDs such as "co.uk".'
      example: google.com
    - name: top_level_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The effective top level domain (eTLD), also known as the domain
        suffix, is the last part of the domain name. For example, the top level domain
        for google.com is "com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last label will not work well for effective TLDs such as "co.uk".'
      example: co.uk
    - name: user.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the user is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.email
      level: extended
      type: keyword
      ignore_above: 1024
      description: User email address.
    - name: user.full_name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: User's full name, if available.
      example: Albert Einstein
    - name: user.group.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: user.group.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: user.group.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
    - name: user.hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique user hash to correlate information for a user in anonymized
        form.

        Useful if `user.id` or `user.name` contain confidential information and cannot
        be used.'
    - name: user.id
      level: core
      type: keyword
      ignore_above: 1024
      description: One or multiple unique identifiers of the user.
    - name: user.name
      level: core
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Short name or login of the user.
      example: albert
  - name: threat
    title: Threat
    group: 2
    description: 'Fields to classify events and alerts according to a threat taxonomy
      such as the Mitre ATT&CK framework.

      These fields are for users to classify alerts from all of their sources (e.g.
      IDS, NGFW, etc.) within a common taxonomy. The threat.tactic.* are meant to
      capture the high level category of the threat (e.g. "impact"). The threat.technique.*
      fields are meant to capture which kind of approach is used by this detected
      threat, to accomplish the goal (e.g. "endpoint denial of service").'
    type: group
    fields:
    - name: framework
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the threat framework used to further categorize and classify
        the tactic and technique of the reported threat. Framework classification
        can be provided by detecting systems, evaluated at ingest time, or retrospectively
        tagged to events.
      example: MITRE ATT&CK
    - name: tactic.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: The id of tactic used by this threat. You can use the Mitre ATT&CK
        Matrix Tactic categorization, for example. (ex. https://attack.mitre.org/tactics/TA0040/
        )
      example: TA0040
    - name: tactic.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the type of tactic used by this threat. You can use the
        Mitre ATT&CK Matrix Tactic categorization, for example. (ex. https://attack.mitre.org/tactics/TA0040/
        )
      example: impact
    - name: tactic.reference
      level: extended
      type: keyword
      ignore_above: 1024
      description: The reference url of tactic used by this threat. You can use the
        Mitre ATT&CK Matrix Tactic categorization, for example. (ex. https://attack.mitre.org/tactics/TA0040/
        )
      example: https://attack.mitre.org/tactics/TA0040/
    - name: technique.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: The id of technique used by this tactic. You can use the Mitre
        ATT&CK Matrix Tactic categorization, for example. (ex. https://attack.mitre.org/techniques/T1499/
        )
      example: T1499
    - name: technique.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: The name of technique used by this tactic. You can use the Mitre
        ATT&CK Matrix Tactic categorization, for example. (ex. https://attack.mitre.org/techniques/T1499/
        )
      example: endpoint denial of service
    - name: technique.reference
      level: extended
      type: keyword
      ignore_above: 1024
      description: The reference url of technique used by this tactic. You can use
        the Mitre ATT&CK Matrix Tactic categorization, for example. (ex. https://attack.mitre.org/techniques/T1499/
        )
      example: https://attack.mitre.org/techniques/T1499/
  - name: tls
    title: TLS
    group: 2
    description: Fields related to a TLS connection. These fields focus on the TLS
      protocol itself and intentionally avoids in-depth analysis of the related x.509
      certificate files.
    type: group
    fields:
    - name: cipher
      level: extended
      type: keyword
      ignore_above: 1024
      description: String indicating the cipher used during the current connection.
      example: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
      default_field: false
    - name: client.certificate
      level: extended
      type: keyword
      ignore_above: 1024
      description: PEM-encoded stand-alone certificate offered by the client. This
        is usually mutually-exclusive of `client.certificate_chain` since this value
        also exists in that list.
      example: MII...
      default_field: false
    - name: client.certificate_chain
      level: extended
      type: keyword
      ignore_above: 1024
      description: Array of PEM-encoded certificates that make up the certificate
        chain offered by the client. This is usually mutually-exclusive of `client.certificate`
        since that value should be the first certificate in the chain.
      example:
      - MII...
      - MII...
      default_field: false
    - name: client.hash.md5
      level: extended
      type: keyword
      ignore_above: 1024
      description: Certificate fingerprint using the MD5 digest of DER-encoded version
        of certificate offered by the client. For consistency with other hash values,
        this value should be formatted as an uppercase hash.
      example: 0F76C7F2C55BFD7D8E8B8F4BFBF0C9EC
      default_field: false
    - name: client.hash.sha1
      level: extended
      type: keyword
      ignore_above: 1024
      description: Certificate fingerprint using the SHA1 digest of DER-encoded version
        of certificate offered by the client. For consistency with other hash values,
        this value should be formatted as an uppercase hash.
      example: 9E393D93138888D288266C2D915214D1D1CCEB2A
      default_field: false
    - name: client.hash.sha256
      level: extended
      type: keyword
      ignore_above: 1024
      description: Certificate fingerprint using the SHA256 digest of DER-encoded
        version of certificate offered by the client. For consistency with other hash
        values, this value should be formatted as an uppercase hash.
      example: 0687F666A054EF17A08E2F2162EAB4CBC0D265E1D7875BE74BF3C712CA92DAF0
      default_field: false
    - name: client.issuer
      level: extended
      type: keyword
      ignore_above: 1024
      description: Distinguished name of subject of the issuer of the x.509 certificate
        presented by the client.
      example: CN=MyDomain Root CA, OU=Infrastructure Team, DC=mydomain, DC=com
      default_field: false
    - name: client.ja3
      level: extended
      type: keyword
      ignore_above: 1024
      description: A hash that identifies clients based on how they perform an SSL/TLS
        handshake.
      example: d4e5b18d6b55c71272893221c96ba240
      default_field: false
    - name: client.not_after
      level: extended
      type: date
      description: Date/Time indicating when client certificate is no longer considered
        valid.
      example: '2021-01-01T00:00:00.000Z'
      default_field: false
    - name: client.not_before
      level: extended
      type: date
      description: Date/Time indicating when client certificate is first considered
        valid.
      example: '1970-01-01T00:00:00.000Z'
      default_field: false
    - name: client.server_name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Also called an SNI, this tells the server which hostname to which
        the client is attempting to connect. When this value is available, it should
        get copied to `destination.domain`.
      example: www.elastic.co
      default_field: false
    - name: client.subject
      level: extended
      type: keyword
      ignore_above: 1024
      description: Distinguished name of subject of the x.509 certificate presented
        by the client.
      example: CN=myclient, OU=Documentation Team, DC=mydomain, DC=com
      default_field: false
    - name: client.supported_ciphers
      level: extended
      type: keyword
      ignore_above: 1024
      description: Array of ciphers offered by the client during the client hello.
      example:
      - TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
      - TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
      - '...'
      default_field: false
    - name: curve
      level: extended
      type: keyword
      ignore_above: 1024
      description: String indicating the curve used for the given cipher, when applicable.
      example: secp256r1
      default_field: false
    - name: established
      level: extended
      type: boolean
      description: Boolean flag indicating if the TLS negotiation was successful and
        transitioned to an encrypted tunnel.
      default_field: false
    - name: next_protocol
      level: extended
      type: keyword
      ignore_above: 1024
      description: String indicating the protocol being tunneled. Per the values in
        the IANA registry (https://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xhtml#alpn-protocol-ids),
        this string should be lower case.
      example: http/1.1
      default_field: false
    - name: resumed
      level: extended
      type: boolean
      description: Boolean flag indicating if this TLS connection was resumed from
        an existing TLS negotiation.
      default_field: false
    - name: server.certificate
      level: extended
      type: keyword
      ignore_above: 1024
      description: PEM-encoded stand-alone certificate offered by the server. This
        is usually mutually-exclusive of `server.certificate_chain` since this value
        also exists in that list.
      example: MII...
      default_field: false
    - name: server.certificate_chain
      level: extended
      type: keyword
      ignore_above: 1024
      description: Array of PEM-encoded certificates that make up the certificate
        chain offered by the server. This is usually mutually-exclusive of `server.certificate`
        since that value should be the first certificate in the chain.
      example:
      - MII...
      - MII...
      default_field: false
    - name: server.hash.md5
      level: extended
      type: keyword
      ignore_above: 1024
      description: Certificate fingerprint using the MD5 digest of DER-encoded version
        of certificate offered by the server. For consistency with other hash values,
        this value should be formatted as an uppercase hash.
      example: 0F76C7F2C55BFD7D8E8B8F4BFBF0C9EC
      default_field: false
    - name: server.hash.sha1
      level: extended
      type: keyword
      ignore_above: 1024
      description: Certificate fingerprint using the SHA1 digest of DER-encoded version
        of certificate offered by the server. For consistency with other hash values,
        this value should be formatted as an uppercase hash.
      example: 9E393D93138888D288266C2D915214D1D1CCEB2A
      default_field: false
    - name: server.hash.sha256
      level: extended
      type: keyword
      ignore_above: 1024
      description: Certificate fingerprint using the SHA256 digest of DER-encoded
        version of certificate offered by the server. For consistency with other hash
        values, this value should be formatted as an uppercase hash.
      example: 0687F666A054EF17A08E2F2162EAB4CBC0D265E1D7875BE74BF3C712CA92DAF0
      default_field: false
    - name: server.issuer
      level: extended
      type: keyword
      ignore_above: 1024
      description: Subject of the issuer of the x.509 certificate presented by the
        server.
      example: CN=MyDomain Root CA, OU=Infrastructure Team, DC=mydomain, DC=com
      default_field: false
    - name: server.ja3s
      level: extended
      type: keyword
      ignore_above: 1024
      description: A hash that identifies servers based on how they perform an SSL/TLS
        handshake.
      example: 394441ab65754e2207b1e1b457b3641d
      default_field: false
    - name: server.not_after
      level: extended
      type: date
      description: Timestamp indicating when server certificate is no longer considered
        valid.
      example: '2021-01-01T00:00:00.000Z'
      default_field: false
    - name: server.not_before
      level: extended
      type: date
      description: Timestamp indicating when server certificate is first considered
        valid.
      example: '1970-01-01T00:00:00.000Z'
      default_field: false
    - name: server.subject
      level: extended
      type: keyword
      ignore_above: 1024
      description: Subject of the x.509 certificate presented by the server.
      example: CN=www.mydomain.com, OU=Infrastructure Team, DC=mydomain, DC=com
      default_field: false
    - name: version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Numeric part of the version parsed from the original string.
      example: '1.2'
      default_field: false
    - name: version_protocol
      level: extended
      type: keyword
      ignore_above: 1024
      description: Normalized lowercase protocol name parsed from original string.
      example: tls
      default_field: false
  - name: tracing
    title: Tracing
    group: 2
    description: Distributed tracing makes it possible to analyze performance throughout
      a microservice architecture all in one view. This is accomplished by tracing
      all of the requests - from the initial web request in the front-end service
      - to queries made through multiple back-end services.
    type: group
    fields:
    - name: trace.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique identifier of the trace.

        A trace groups multiple events like transactions that belong together. For
        example, a user request handled by multiple inter-connected services.'
      example: 4bf92f3577b34da6a3ce929d0e0e4736
    - name: transaction.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique identifier of the transaction.

        A transaction is the highest level of work measured within a service, such
        as a request to a server.'
      example: 00f067aa0ba902b7
  - name: url
    title: URL
    group: 2
    description: URL fields provide support for complete or partial URLs, and supports
      the breaking down into scheme, domain, path, and so on.
    type: group
    fields:
    - name: domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Domain of the url, such as "www.elastic.co".

        In some cases a URL may refer to an IP and/or port directly, without a domain
        name. In this case, the IP address would go to the `domain` field.'
      example: www.elastic.co
    - name: extension
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The field contains the file extension from the original request
        url.

        The file extension is only set if it exists, as not every url has a file extension.

        The leading period must not be included. For example, the value must be "png",
        not ".png".'
      example: png
    - name: fragment
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Portion of the url after the `#`, such as "top".

        The `#` is not part of the fragment.'
    - name: full
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: If full URLs are important to your use case, they should be stored
        in `url.full`, whether this field is reconstructed or present in the event
        source.
      example: https://www.elastic.co:443/search?q=elasticsearch#top
    - name: original
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: 'Unmodified original url as seen in the event source.

        Note that in network monitoring, the observed URL may be a full URL, whereas
        in access logs, the URL is often just represented as a path.

        This field is meant to represent the URL as it was observed, complete or not.'
      example: https://www.elastic.co:443/search?q=elasticsearch#top or /search?q=elasticsearch
    - name: password
      level: extended
      type: keyword
      ignore_above: 1024
      description: Password of the request.
    - name: path
      level: extended
      type: keyword
      ignore_above: 1024
      description: Path of the request, such as "/search".
    - name: port
      level: extended
      type: long
      format: string
      description: Port of the request, such as 443.
      example: 443
    - name: query
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The query field describes the query string of the request, such
        as "q=elasticsearch".

        The `?` is excluded from the query string. If a URL contains no `?`, there
        is no query field. If there is a `?` but no query, the query field exists
        with an empty string. The `exists` query can be used to differentiate between
        the two cases.'
    - name: registered_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The highest registered url domain, stripped of the subdomain.

        For example, the registered domain for "foo.google.com" is "google.com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last two labels will not work well for TLDs such as "co.uk".'
      example: google.com
    - name: scheme
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Scheme of the request, such as "https".

        Note: The `:` is not part of the scheme.'
      example: https
    - name: top_level_domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The effective top level domain (eTLD), also known as the domain
        suffix, is the last part of the domain name. For example, the top level domain
        for google.com is "com".

        This value can be determined precisely with a list like the public suffix
        list (http://publicsuffix.org). Trying to approximate this by simply taking
        the last label will not work well for effective TLDs such as "co.uk".'
      example: co.uk
    - name: username
      level: extended
      type: keyword
      ignore_above: 1024
      description: Username of the request.
  - name: user
    title: User
    group: 2
    description: 'The user fields describe information about the user that is relevant
      to the event.

      Fields can have one entry or multiple entries. If a user has more than one id,
      provide an array that includes all of them.'
    type: group
    fields:
    - name: domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the user is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: email
      level: extended
      type: keyword
      ignore_above: 1024
      description: User email address.
    - name: full_name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: User's full name, if available.
      example: Albert Einstein
    - name: group.domain
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Name of the directory the group is a member of.

        For example, an LDAP or Active Directory domain name.'
    - name: group.id
      level: extended
      type: keyword
      ignore_above: 1024
      description: Unique identifier for the group on the system/platform.
    - name: group.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the group.
    - name: hash
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'Unique user hash to correlate information for a user in anonymized
        form.

        Useful if `user.id` or `user.name` contain confidential information and cannot
        be used.'
    - name: id
      level: core
      type: keyword
      ignore_above: 1024
      description: One or multiple unique identifiers of the user.
    - name: name
      level: core
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Short name or login of the user.
      example: albert
  - name: user_agent
    title: User agent
    group: 2
    description: 'The user_agent fields normally come from a browser request.

      They often show up in web service logs coming from the parsed user agent string.'
    type: group
    fields:
    - name: device.name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the device.
      example: iPhone
    - name: name
      level: extended
      type: keyword
      ignore_above: 1024
      description: Name of the user agent.
      example: Safari
    - name: original
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: Unparsed user_agent string.
      example: Mozilla/5.0 (iPhone; CPU iPhone OS 12_1 like Mac OS X) AppleWebKit/605.1.15
        (KHTML, like Gecko) Version/12.0 Mobile/15E148 Safari/604.1
    - name: os.family
      level: extended
      type: keyword
      ignore_above: 1024
      description: OS family (such as redhat, debian, freebsd, windows).
      example: debian
    - name: os.full
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, including the version or code name.
      example: Mac OS Mojave
    - name: os.kernel
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system kernel version as a raw string.
      example: 4.4.0-112-generic
    - name: os.name
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
        default_field: false
      description: Operating system name, without the version.
      example: Mac OS X
    - name: os.platform
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system platform (such centos, ubuntu, windows).
      example: darwin
    - name: os.version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Operating system version as a raw string.
      example: 10.14.1
    - name: version
      level: extended
      type: keyword
      ignore_above: 1024
      description: Version of the user agent.
      example: 12.0
  - name: vulnerability
    title: Vulnerability
    group: 2
    description: The vulnerability fields describe information about a vulnerability
      that is relevant to an event.
    type: group
    fields:
    - name: category
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The type of system or architecture that the vulnerability affects.
        These may be platform-specific (for example, Debian or SUSE) or general (for
        example, Database or Firewall). For example (https://qualysguard.qualys.com/qwebhelp/fo_portal/knowledgebase/vulnerability_categories.htm[Qualys
        vulnerability categories])

        This field must be an array.'
      example: '["Firewall"]'
      default_field: false
    - name: classification
      level: extended
      type: keyword
      ignore_above: 1024
      description: The classification of the vulnerability scoring system. For example
        (https://www.first.org/cvss/)
      example: CVSS
      default_field: false
    - name: description
      level: extended
      type: keyword
      ignore_above: 1024
      multi_fields:
      - name: text
        type: text
        norms: false
      description: The description of the vulnerability that provides additional context
        of the vulnerability. For example (https://cve.mitre.org/about/faqs.html#cve_entry_descriptions_created[Common
        Vulnerabilities and Exposure CVE description])
      example: In macOS before 2.12.6, there is a vulnerability in the RPC...
      default_field: false
    - name: enumeration
      level: extended
      type: keyword
      ignore_above: 1024
      description: The type of identifier used for this vulnerability. For example
        (https://cve.mitre.org/about/)
      example: CVE
      default_field: false
    - name: id
      level: extended
      type: keyword
      ignore_above: 1024
      description: The identification (ID) is the number portion of a vulnerability
        entry. It includes a unique identification number for the vulnerability. For
        example (https://cve.mitre.org/about/faqs.html#what_is_cve_id)[Common Vulnerabilities
        and Exposure CVE ID]
      example: CVE-2019-00001
      default_field: false
    - name: reference
      level: extended
      type: keyword
      ignore_above: 1024
      description: A resource that provides additional information, context, and mitigations
        for the identified vulnerability.
      example: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111
      default_field: false
    - name: report_id
      level: extended
      type: keyword
      ignore_above: 1024
      description: The report or scan identification number.
      example: 20191018.0001
      default_field: false
    - name: scanner.vendor
      level: extended
      type: keyword
      ignore_above: 1024
      description: The name of the vulnerability scanner vendor.
      example: Tenable
      default_field: false
    - name: score.base
      level: extended
      type: float
      description: 'Scores can range from 0.0 to 10.0, with 10.0 being the most severe.

        Base scores cover an assessment for exploitability metrics (attack vector,
        complexity, privileges, and user interaction), impact metrics (confidentiality,
        integrity, and availability), and scope. For example (https://www.first.org/cvss/specification-document)'
      example: 5.5
      default_field: false
    - name: score.environmental
      level: extended
      type: float
      description: 'Scores can range from 0.0 to 10.0, with 10.0 being the most severe.

        Environmental scores cover an assessment for any modified Base metrics, confidentiality,
        integrity, and availability requirements. For example (https://www.first.org/cvss/specification-document)'
      example: 5.5
      default_field: false
    - name: score.temporal
      level: extended
      type: float
      description: 'Scores can range from 0.0 to 10.0, with 10.0 being the most severe.

        Temporal scores cover an assessment for code maturity, remediation level,
        and confidence. For example (https://www.first.org/cvss/specification-document)'
      default_field: false
    - name: score.version
      level: extended
      type: keyword
      ignore_above: 1024
      description: 'The National Vulnerability Database (NVD) provides qualitative
        severity rankings of "Low", "Medium", and "High" for CVSS v2.0 base score
        ranges in addition to the severity ratings for CVSS v3.0 as they are defined
        in the CVSS v3.0 specification.

        CVSS is owned and managed by FIRST.Org, Inc. (FIRST), a US-based non-profit
        organization, whose mission is to help computer security incident response
        teams across the world. For example (https://nvd.nist.gov/vuln-metrics/cvss)'
      example: 2.0
      default_field: false
    - name: severity
      level: extended
      type: keyword
      ignore_above: 1024
      description: The severity of the vulnerability can help with metrics and internal
        prioritization regarding remediation. For example (https://nvd.nist.gov/vuln-metrics/cvss)
      example: Critical
      default_field: false
- key: beat
  anchor: beat-common
  title: Beat
  description: >
    Contains common beat fields available in all event types.
  fields:
    - name: agent.hostname
      type: keyword
      description: Hostname of the agent.

    - name: beat.timezone
      type: alias
      path: event.timezone
      migration: true

    - name: fields
      type: object
      object_type: keyword
      description: >
        Contains user configurable fields.

    - name: beat.name
      type: alias
      path: host.name
      migration: true

    - name: beat.hostname
      type: alias
      path: agent.hostname
      migration: true

    - name: timeseries.instance
      type: keyword
      description: Time series instance id
- key: cloud
  title: Cloud provider metadata
  description: >
    Metadata from cloud providers added by the add_cloud_metadata processor.
  fields:

    - name: cloud.project.id
      example: project-x
      description: >
        Name of the project in Google Cloud.
    
    - name: cloud.image.id
      example: ami-abcd1234
      description: >
        Image ID for the cloud instance.

    # Alias for old fields
    - name: meta.cloud.provider
      type: alias
      path: cloud.provider
      migration: true

    - name: meta.cloud.instance_id
      type: alias
      path: cloud.instance.id
      migration: true

    - name: meta.cloud.instance_name
      type: alias
      path: cloud.instance.name
      migration: true

    - name: meta.cloud.machine_type
      type: alias
      path: cloud.machine.type
      migration: true

    - name: meta.cloud.availability_zone
      type: alias
      path: cloud.availability_zone
      migration: true

    - name: meta.cloud.project_id
      type: alias
      path: cloud.project.id
      migration: true

    - name: meta.cloud.region
      type: alias
      path: cloud.region
      migration: true

    
- key: docker
  title: Docker
  description: >
    Docker stats collected from Docker.
  short_config: false
  anchor: docker-processor
  fields:
    - name: docker
      type: group
      fields:
        - name: container.id
          type: alias
          path: container.id
          migration: true

        - name: container.image
          type: alias
          path: container.image.name
          migration: true

        - name: container.name
          type: alias
          path: container.name
          migration: true

        - name: container.labels  # TODO: How to map these?
          type: object
          object_type: keyword
          description: >
            Image labels.
- key: host
  title: Host
  description: >
    Info collected for the host machine.
  anchor: host-processor
  fields:

    # ECS fields are in fields.ecs.yml.
    # These are the non-ECS fields.
    - name: host
      type: group
      fields:

        - name: containerized
          type: boolean
          description: >
            If the host is a container.

        - name: os.build
          type: keyword
          example: "18D109"
          description: >
            OS build information.

        - name: os.codename
          type: keyword
          example: "stretch"
          description: >
            OS codename, if any.
- key: kubernetes
  title: Kubernetes
  description: >
    Kubernetes metadata added by the kubernetes processor
  short_config: false
  anchor: kubernetes-processor
  fields:
    - name: kubernetes
      type: group
      fields:
        - name: pod.name
          type: keyword
          description: >
            Kubernetes pod name

        - name: pod.uid
          type: keyword
          description: >
            Kubernetes Pod UID

        - name: namespace
          type: keyword
          description: >
            Kubernetes namespace

        - name: node.name
          type: keyword
          description: >
            Kubernetes node name

        - name: labels.*
          type: object
          object_type: keyword
          object_type_mapping_type: "*"
          description: >
            Kubernetes labels map

        - name: annotations.*
          type: object
          object_type: keyword
          object_type_mapping_type: "*"
          description: >
            Kubernetes annotations map

        - name: replicaset.name
          type: keyword
          description: >
            Kubernetes replicaset name

        - name: deployment.name
          type: keyword
          description: >
            Kubernetes deployment name

        - name: statefulset.name
          type: keyword
          description: >
            Kubernetes statefulset name

        - name: container.name
          type: keyword
          description: >
            Kubernetes container name

        - name: container.image
          type: keyword
          description: >
            Kubernetes container image
- key: process
  title: Process
  description: >
    Process metadata fields
  fields:
    - name: process
      type: group
      fields:
        - name: exe
          type: alias
          path: process.executable
          migration: true
- key: jolokia-autodiscover
  title: Jolokia Discovery autodiscover provider
  description: >
    Metadata from Jolokia Discovery added by the jolokia provider.
  fields:
    - name: jolokia.agent.version
      type: keyword
      description: >
        Version number of jolokia agent.
    - name: jolokia.agent.id
      type: keyword
      description: >
        Each agent has a unique id which can be either provided during startup of the agent in form of a configuration parameter or being autodetected. If autodected, the id has several parts: The IP, the process id, hashcode of the agent and its type.
    - name: jolokia.server.product
      type: keyword
      description: >
        The container product if detected.
    - name: jolokia.server.version
      type: keyword
      description: >
        The container's version (if detected).
    - name: jolokia.server.vendor
      type: keyword
      description: >
        The vendor of the container the agent is running in.
    - name: jolokia.url
      type: keyword
      description: >
        The URL how this agent can be contacted.
    - name: jolokia.secured
      type: boolean
      description: >
        Whether the agent was configured for authentication or not.
- key: log
  title: Log file content
  description: >
    Contains log file lines.
  fields:

    - name: log.file.path
      type: keyword
      required: false
      description: >
        The file from which the line was read. This field contains the absolute path to the file.
        For example: `/var/log/system.log`.

    - name: log.source.address
      type: keyword
      required: false
      description: >
        Source address from which the log event was read / sent from.

    - name: log.offset
      type: long
      required: false
      description: >
        The file offset the reported line starts at.

    - name: stream
      type: keyword
      required: false
      description: >
        Log stream when reading container logs, can be 'stdout' or 'stderr'

    - name: input.type
      required: true
      description: >
        The input type from which the event was generated. This field is set to the value specified
        for the `type` option in the input section of the Filebeat config file.

    - name: syslog.facility
      type: long
      required: false
      description: >
        The facility extracted from the priority.

    - name: syslog.priority
      type: long
      required: false
      description: >
        The priority of the syslog event.

    - name: syslog.severity_label
      type: keyword
      required: false
      description: >
        The human readable severity.

    - name: syslog.facility_label
      type: keyword
      required: false
      description: >
        The human readable facility.

    - name: process.program
      type: keyword
      required: false
      description: >
        The name of the program.

    - name: log.flags
      description: >
        This field contains the flags of the event.

    - name: http.response.content_length
      type: alias
      path: http.response.body.bytes
      migration: true

    - name: user_agent
      type: group
      fields:
      - name: os
        type: group
        fields:
        - name: full_name
          type: keyword

    - name: fileset.name
      type: keyword
      description: >
        The Filebeat fileset that generated this event.

    - name: fileset.module
      type: alias
      path: event.module
      migration: true

    - name: read_timestamp
      type: alias
      path: event.created
      migration: true

    - name: docker.attrs
      type: object
      object_type: keyword
      description: >
        docker.attrs contains labels and environment variables written by docker's JSON File logging driver.
        These fields are only available when they are configured in the logging driver options.

    - name: icmp.code
      type: keyword
      description: >
        ICMP code.

    - name: icmp.type
      type: keyword
      description: >
        ICMP type.

    - name: igmp.type
      type: keyword
      description: >
        IGMP type.


    - name: azure
      type: group
      fields:
        - name: eventhub
          type: keyword
          description: >
            Name of the eventhub.
        - name: offset
          type: long
          description: >
            The offset.
        - name: enqueued_time
          type: date
          description: >
            The enqueued time.
        - name: partition_id
          type: long
          description: >
            The partition id.
        - name: consumer_group
          type: keyword
          description: >
            The consumer group.
        - name: sequence_number
          type: long
          description: >
            The sequence number.


    - name: kafka
      type: group
      fields:
        - name: topic
          type: keyword
          description: >
            Kafka topic

        - name: partition
          type: long
          description: >
            Kafka partition number

        - name: offset
          type: long
          description: >
            Kafka offset of this message

        - name: key
          type: keyword
          description: >
            Kafka key, corresponding to the Kafka value stored in the message

        - name: block_timestamp
          type: date
          description: >
            Kafka outer (compressed) block timestamp

        - name: headers
          type: array
          description: >
            An array of Kafka header strings for this message, in the form
            "<key>: <value>".
- key: apache
  title: "Apache"
  description: >
    Apache Module
  short_config: true
  fields:
    - name: apache2
      type: group
      description: >
        Aliases for backward compatibility with old apache2 fields
      fields:
        - name: access
          type: group
          fields:
            - name: remote_ip
              type: alias
              path: source.address
              migration: true
            - name: ssl.protocol
              type: alias
              path: apache.access.ssl.protocol
              migration: true
            - name: ssl.cipher
              type: alias
              path: apache.access.ssl.cipher
              migration: true
            - name: body_sent.bytes
              type: alias
              path: http.response.body.bytes
              migration: true
            - name: user_name
              type: alias
              path: user.name
              migration: true
            - name: method
              type: alias
              path: http.request.method
              migration: true
            - name: url
              type: alias
              path: url.original
              migration: true
            - name: http_version
              type: alias
              path: http.version
              migration: true
            - name: response_code
              type: alias
              path: http.response.status_code
              migration: true
            - name: referrer
              type: alias
              path: http.request.referrer
              migration: true
            - name: agent
              type: alias
              path: user_agent.original
              migration: true

            - name: user_agent
              type: group
              fields:
                - name: device
                  type: alias
                  path: user_agent.device.name
                  migration: true
                - name: name
                  type: alias
                  path: user_agent.name
                  migration: true
                - name: os
                  type: alias
                  path: user_agent.os.full_name
                  migration: true
                - name: os_name
                  type: alias
                  path: user_agent.os.name
                  migration: true
                - name: original
                  type: alias
                  path: user_agent.original
                  migration: true
            - name: geoip
              type: group
              fields:
                - name: continent_name
                  type: alias
                  path: source.geo.continent_name
                  migration: true
                - name: country_iso_code
                  type: alias
                  path: source.geo.country_iso_code
                  migration: true
                - name: location
                  type: alias
                  path: source.geo.location
                  migration: true
                - name: region_name
                  type: alias
                  path: source.geo.region_name
                  migration: true
                - name: city_name
                  type: alias
                  path: source.geo.city_name
                  migration: true
                - name: region_iso_code
                  type: alias
                  path: source.geo.region_iso_code
                  migration: true
        - name: error
          type: group
          fields:
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
            - name: pid
              type: alias
              path: process.pid
              migration: true
            - name: tid
              type: alias
              path: process.thread.id
              migration: true
            - name: module
              type: alias
              path: apache.error.module
              migration: true


    - name: apache
      type: group
      description: >
        Apache fields.
      fields:
        - name: access
          type: group
          description: >
            Contains fields for the Apache HTTP Server access logs.
          fields:
            - name: ssl.protocol
              type: keyword
              description: >
                SSL protocol version.
        
            - name: ssl.cipher
              type: keyword
              description: >
                SSL cipher name.
        - name: error
          type: group
          description: >
            Fields from the Apache error logs.
          fields:
            - name: module
              type: keyword
              description: >
                The module producing the logged message.
- key: auditd
  title: "Auditd"
  description: >
    Module for parsing auditd logs.
  short_config: true
  fields:

    - name: user
      type: group
      fields:

        - name: terminal
          type: keyword
          description: >
            Terminal or tty device on which the user is performing the observed activity.

        - name: audit
          type: group
          fields:
            - name: id
              type: keyword
              description: >
                One or multiple unique identifiers of the user.
            - name: name
              type: keyword
              example: albert
              description: >
                Short name or login of the user.

            - name: group.id
              type: keyword
              description: >
                Unique identifier for the group on the system/platform.
            - name: group.name
              type: keyword
              description: >
                    Name of the group.

        - name: effective
          type: group
          fields:
            - name: id
              type: keyword
              description: >
                One or multiple unique identifiers of the user.
            - name: name
              type: keyword
              example: albert
              description: >
                Short name or login of the user.
            - name: group.id
              type: keyword
              description: >
                Unique identifier for the group on the system/platform.
            - name: group.name
              type: keyword
              description: >
                    Name of the group.

        - name: filesystem
          type: group
          fields:
            - name: id
              type: keyword
              description: >
                One or multiple unique identifiers of the user.
            - name: name
              type: keyword
              example: albert
              description: >
                Short name or login of the user.
            - name: group.id
              type: keyword
              description: >
                Unique identifier for the group on the system/platform.
            - name: group.name
              type: keyword
              description: >
                    Name of the group.

        - name: owner
          type: group
          fields:
            - name: id
              type: keyword
              description: >
                One or multiple unique identifiers of the user.
            - name: name
              type: keyword
              example: albert
              description: >
                Short name or login of the user.
            - name: group.id
              type: keyword
              description: >
                Unique identifier for the group on the system/platform.
            - name: group.name
              type: keyword
              description: >
                    Name of the group.

        - name: saved
          type: group
          fields:
            - name: id
              type: keyword
              description: >
                One or multiple unique identifiers of the user.
            - name: name
              type: keyword
              example: albert
              description: >
                Short name or login of the user.
            - name: group.id
              type: keyword
              description: >
                Unique identifier for the group on the system/platform.
            - name: group.name
              type: keyword
              description: >
                    Name of the group.

    - name: auditd
      type: group
      description: >
        Fields from the auditd logs.
      fields:
        - name: log
          type: group
          description: >
            Fields from the Linux audit log. Not all fields are documented here because
            they are dynamic and vary by audit event type.
          fields:
            - name: old_auid
              description: >
                For login events this is the old audit ID used for the user prior to
                this login.
            - name: new_auid
              description: >
                For login events this is the new audit ID. The audit ID can be used to
                trace future events to the user even if their identity changes (like
                becoming root).
            - name: old_ses
              description: >
                For login events this is the old session ID used for the user prior to
                this login.
            - name: new_ses
              description: >
                For login events this is the new session ID. It can be used to tie a
                user to future events by session ID.
            - name: sequence
              type: long
              description: >
                The audit event sequence number.
            - name: items
              description: >
                The number of items in an event.
            - name: item
              description: >
                The item field indicates which item out of the total number of items.
                This number is zero-based; a value of 0 means it is the first item.
            - name: tty
              type: keyword
              definition: >
                TTY udevice the user is running programs on.
            - name: a0
              description: >
                The first argument to the system call.
            - name: addr
              type: ip
              definition: >
                Remote address that the user is connecting from.
            - name: rport
              type: long
              definition: >
                Remote port number.
            - name: laddr
              type: ip
              definition: >
                Local network address.
            - name: lport
              type: long
              definition: >
                Local port number.
        
            - name: acct
              type: alias
              path: user.name
              migration: true
            - name: pid
              type: alias
              path: process.pid
              migration: true
            - name: ppid
              type: alias
              path: process.ppid
              migration: true
            - name: res
              type: alias
              path: event.outcome
              migration: true
            - name: record_type
              type: alias
              path: event.action
              migration: true
            - name: geoip
              type: group
              fields:
                - name: continent_name
                  type: alias
                  path: source.geo.continent_name
                  migration: true
                - name: country_iso_code
                  type: alias
                  path: source.geo.country_iso_code
                  migration: true
                - name: location
                  type: alias
                  path: source.geo.location
                  migration: true
                - name: region_name
                  type: alias
                  path: source.geo.region_name
                  migration: true
                - name: city_name
                  type: alias
                  path: source.geo.city_name
                  migration: true
                - name: region_iso_code
                  type: alias
                  path: source.geo.region_iso_code
                  migration: true
        
            # Fields below were not defined in 6.x but were still being populated.
            - name: arch
              type: alias
              path: host.architecture
              migration: true
            - name: gid
              type: alias
              path: user.group.id
              migration: true
            - name: uid
              type: alias
              path: user.id
              migration: true
            - name: agid
              type: alias
              path: user.audit.group.id
              migration: true
            - name: auid
              type: alias
              path: user.audit.id
              migration: true
            - name: fsgid
              type: alias
              path: user.filesystem.group.id
              migration: true
            - name: fsuid
              type: alias
              path: user.filesystem.id
              migration: true
            - name: egid
              type: alias
              path: user.effective.group.id
              migration: true
            - name: euid
              type: alias
              path: user.effective.id
              migration: true
            - name: sgid
              type: alias
              path: user.saved.group.id
              migration: true
            - name: suid
              type: alias
              path: user.saved.id
              migration: true
            - name: ogid
              type: alias
              path: user.owner.group.id
              migration: true
            - name: ouid
              type: alias
              path: user.owner.id
              migration: true
            - name: comm
              type: alias
              path: process.name
              migration: true
            - name: exe
              type: alias
              path: process.executable
              migration: true
            - name: terminal
              type: alias
              path: user.terminal
              migration: true
            - name: msg
              type: alias
              path: message
              migration: true
            - name: src
              type: alias
              path: source.address
              migration: true
            - name: dst
              type: alias
              path: destination.address
              migration: true
- key: elasticsearch
  title: "elasticsearch"
  description: >
    elasticsearch Module
  fields:
    - name: elasticsearch
      type: group
      description: >
      fields:
        - name: component
          description: "Elasticsearch component from where the log event originated"
          example: "o.e.c.m.MetaDataCreateIndexService"
          type: keyword
        - name: cluster.uuid
          description: "UUID of the cluster"
          example: "GmvrbHlNTiSVYiPf8kxg9g"
          type: keyword
        - name: cluster.name
          description: "Name of the cluster"
          example: "docker-cluster"
          type: keyword
        - name: node.id
          description: "ID of the node"
          example: "DSiWcTyeThWtUXLB9J0BMw"
          type: keyword
        - name: node.name
          description: "Name of the node"
          example: "vWNJsZ3"
          type: keyword
        - name: index.name
          description: "Index name"
          example: "filebeat-test-input"
          type: keyword
        - name: index.id
          description: "Index id"
          example: "aOGgDwbURfCV57AScqbCgw"
          type: keyword
        - name: shard.id
          description: "Id of the shard"
          example: "0"
          type: keyword
        - name: audit
          type: group
          description: >
          fields:
            - name: layer
              description: "The layer from which this event originated: rest, transport or ip_filter"
              example: "rest"
              type: keyword
            - name: event_type
              description: "The type of event that occurred: anonymous_access_denied, authentication_failed, access_denied, access_granted, connection_granted, connection_denied, tampered_request, run_as_granted, run_as_denied"
              example: "access_granted"
              type: keyword
            - name: origin.type
              description: "Where the request originated: rest (request originated from a REST API request), transport (request was received on the transport channel), local_node (the local node issued the request)"
              example: "local_node"
              type: keyword
            - name: realm
              description: "The authentication realm the authentication was validated against"
              example": "default_file"
              type: keyword
            - name: user.realm
              description: "The user's authentication realm, if authenticated"
              example": "active_directory"
              type: keyword
            - name: user.roles
              description: "Roles to which the principal belongs"
              example: [ "kibana_user", "beats_admin" ]
              type: keyword
            - name: action
              description: "The name of the action that was executed"
              example: "cluster:monitor/main"
              type: keyword
            - name: url.params
              description: "REST URI parameters"
              example: "{username=jacknich2}"
            - name: indices
              description: "Indices accessed by action"
              example: [ "foo-2019.01.04", "foo-2019.01.03", "foo-2019.01.06" ]
              type: keyword
            - name: request.id
              description: "Unique ID of request"
              example: "WzL_kb6VSvOhAq0twPvHOQ"
              type: keyword
            - name: request.name
              description: "The type of request that was executed"
              example: "ClearScrollRequest"
              type: keyword
            - name: request_body
              type: alias
              path: http.request.body.content
              migration: true
            - name: origin_address
              type: alias
              path: source.ip
              migration: true
            - name: uri
              type: alias
              path: url.original
              migration: true
            - name: principal
              type: alias
              path: user.name
              migration: true
            - name: message
              type: text
        - name: deprecation
          type: group
          description: >
          fields:
        - name: gc
          type: group
          description: >
            GC fileset fields.
          fields:
            - name: phase
              type: group
              description: >
                Fields specific to GC phase.
              fields:
                - name: name
                  type: keyword
                  description: >
                    Name of the GC collection phase.
                - name: duration_sec
                  type: float
                  description: >
                    Collection phase duration according to the Java virtual machine.
                - name: scrub_symbol_table_time_sec
                  type: float
                  description: >
                     Pause time in seconds cleaning up symbol tables.
                - name: scrub_string_table_time_sec
                  type: float
                  description: >
                    Pause time in seconds cleaning up string tables.
                - name: weak_refs_processing_time_sec
                  type: float
                  description: >
                    Time spent processing weak references in seconds.
                - name: parallel_rescan_time_sec
                  type: float
                  description: >
                    Time spent in seconds marking live objects while application is stopped.
                - name: class_unload_time_sec
                  type: float
                  description: >
                    Time spent unloading unused classes in seconds.
                - name: cpu_time
                  type: group
                  description: >
                    Process CPU time spent performing collections.
                  fields:
                    - name: user_sec
                      type: float
                      description: >
                        CPU time spent outside the kernel.
                    - name: sys_sec
                      type: float
                      description: >
                        CPU time spent inside the kernel. 
                    - name: real_sec
                      type: float
                      description: >
                        Total elapsed CPU time spent to complete the collection from start to finish.
            - name: jvm_runtime_sec
              type: float
              description: >
                The time from JVM start up in seconds, as a floating point number.
            - name: threads_total_stop_time_sec
              type: float
              description: >
                Garbage collection threads total stop time seconds.
            - name: stopping_threads_time_sec
              type: float
              description: >
                Time took to stop threads seconds.
            - name: tags
              type: keyword
              description: >
                GC logging tags.
            - name: heap
              type: group
              description: >
                Heap allocation and total size.
              fields:
                - name: size_kb
                  type: integer
                  description: >
                    Total heap size in kilobytes.
                - name: used_kb
                  type: integer
                  description: >
                    Used heap in kilobytes.
            - name: old_gen
              type: group
              description: >
                Old generation occupancy and total size.
              fields:
                - name: size_kb
                  type: integer
                  description: >
                    Total size of old generation in kilobytes.
                - name: used_kb
                  type: integer
                  description: >
                    Old generation occupancy in kilobytes.
            - name: young_gen
              type: group
              description: >
                Young generation occupancy and total size.
              fields:
                - name: size_kb
                  type: integer
                  description: >
                    Total size of young generation in kilobytes.
                - name: used_kb
                  type: integer
                  description: >
                    Young generation occupancy in kilobytes.
        - name: server
          description: "Server log file"
          type: group
          fields:
          - name: stacktrace
            description": Stack trace in case of errors
            index: false
          - name: gc
            description: "GC log"
            type: group
            fields:
            - name: young
              description: "Young GC"
              example: ""
              type: group
              fields:
              - name: one
                description: ""
                example: ""
                type: long
              - name: two
                description: ""
                example: ""
                type: long
            - name: overhead_seq
              description: "Sequence number"
              example: 3449992
              type: long
            - name: collection_duration.ms
              description: "Time spent in GC, in milliseconds"
              example: 1600
              type: float
            - name: observation_duration.ms
              description: "Total time over which collection was observed, in milliseconds"
              example: 1800
              type: float
        - name: slowlog
          description: "Slowlog events from Elasticsearch"
          example: "[2018-06-29T10:06:14,933][INFO ][index.search.slowlog.query] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[4.5ms], took_millis[4], total_hits[19435], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"query\":{\"match_all\":{\"boost\":1.0}}}],"
          type: group
          fields:
          - name: logger
            description: "Logger name"
            example: "index.search.slowlog.fetch"
            type: keyword
          - name: took
            description: "Time it took to execute the query"
            example: "300ms"
            type: keyword
          - name: types
            description: "Types"
            example: ""
            type: keyword
          - name: stats
            description: "Stats groups"
            example: "group1"
            type: keyword
          - name: search_type
            description: "Search type"
            example: "QUERY_THEN_FETCH"
            type: keyword
          - name: source_query
            description: "Slow query"
            example: "{\"query\":{\"match_all\":{\"boost\":1.0}}}"
            type: keyword
          - name: extra_source
            description: "Extra source information"
            example: ""
            type: keyword
          - name: total_hits
            description: "Total hits"
            example: 42
            type: keyword
          - name: total_shards
            description: "Total queried shards"
            example: 22
            type: keyword
          - name: routing
            description: "Routing"
            example: "s01HZ2QBk9jw4gtgaFtn"
            type: keyword
          - name: id
            description: Id
            example: ""
            type: keyword
          - name: type
            description: "Type"
            example: "doc"
            type: keyword
          - name: source
            description: Source of document that was indexed
            type: keyword
- key: haproxy
  title: "haproxy"
  description: >
    haproxy Module
  fields:
    - name: haproxy
      type: group
      description: >
      fields:

        - name: frontend_name
          description: Name of the frontend (or listener) which received and processed the connection.

        - name: backend_name
          description: Name of the backend (or listener) which was selected to manage the connection to the server.

        - name: server_name
          description: Name of the last server to which the connection was sent.

        - name: total_waiting_time_ms
          description: Total time in milliseconds spent waiting in the various queues
          type: long

        - name: connection_wait_time_ms
          description: Total time in milliseconds spent waiting for the connection to establish to the final server
          type: long

        - name: bytes_read
          description: Total number of bytes transmitted to the client when the log is emitted.
          type: long

        - name: time_queue
          description: Total time in milliseconds spent waiting in the various queues.
          type: long

        - name: time_backend_connect
          description: Total time in milliseconds spent waiting for the connection to establish to the final server, including retries.
          type: long

        - name: server_queue
          description: Total number of requests which were processed before this one in the server queue.
          type: long

        - name: backend_queue
          description: Total number of requests which were processed before this one in the backend's global queue.
          type: long

        - name: bind_name
          description: Name of the listening address which received the connection.

        - name: error_message
          description: Error message logged by HAProxy in case of error.
          type: text

        - name: source
          type: keyword
          description: The HAProxy source of the log

        - name: termination_state
          description: Condition the session was in when the session ended.

        - name: mode
          type: keyword
          description: mode that the frontend is operating (TCP or HTTP)

        - name: connections
          description: Contains various counts of connections active in the process.
          type: group
          fields:
            - name: active
              description: Total number of concurrent connections on the process when the session was logged.
              type: long

            - name: frontend
              description: Total number of concurrent connections on the frontend when the session was logged.
              type: long

            - name: backend
              description: Total number of concurrent connections handled by the backend when the session was logged.
              type: long

            - name: server
              description: Total number of concurrent connections still active on the server when the session was logged.
              type: long

            - name: retries
              description: Number of connection retries experienced by this session when trying to connect to the server.
              type: long

        - name: client
          description: Information about the client doing the request
          type: group
          fields:
          - name: ip
            type: alias
            path: source.address
            migration: true
          - name: port
            type: alias
            path: source.port
            migration: true

        - name: process_name
          type: alias
          path: process.name
          migration: true

        - name: pid
          type: alias
          path: process.pid
          migration: true

        - name: destination
          description: Destination information
          type: group
          fields:
          - name: port
            type: alias
            path: destination.port
            migration: true
          - name: ip
            type: alias
            path: destination.ip
            migration: true

        - name: geoip
          type: group
          description: >
            Contains GeoIP information gathered based on the client.ip field.
            Only present if the GeoIP Elasticsearch plugin is available and
            used.
          fields:
            - name: continent_name
              type: alias
              path: source.geo.continent_name
              migration: true
            - name: country_iso_code
              type: alias
              path: source.geo.country_iso_code
              migration: true
            - name: location
              type: alias
              path: source.geo.location
              migration: true
            - name: region_name
              type: alias
              path: source.geo.region_name
              migration: true
            - name: city_name
              type: alias
              path: source.geo.city_name
              migration: true
            - name: region_iso_code
              type: alias
              path: source.geo.region_iso_code
              migration: true
        - name: http
          description: Please add description
          type: group
          fields:
        
          - name: response
            description: Fields related to the HTTP response
            type: group
            fields:
            - name: captured_cookie
              description: >
                Optional "name=value" entry indicating that the client had this cookie in the response.
        
            - name: captured_headers
              description: >
                List of headers captured in the response due to the presence of the "capture response header" statement in the frontend.
              type: keyword
        
            - name: status_code
              type: alias
              path: http.response.status_code
              migration: true
        
          - name: request
            description: Fields related to the HTTP request
            type: group
            fields:
            - name: captured_cookie
              description: >
                Optional "name=value" entry indicating that the server has returned a cookie with its request.
        
            - name: captured_headers
              description: >
                List of headers captured in the request due to the presence of the "capture request header" statement in the frontend.
              type: keyword
        
            - name: raw_request_line
              description: Complete HTTP request line, including the method, request and HTTP version string.
              type: keyword
        
            - name: time_wait_without_data_ms
              description: Total time in milliseconds spent waiting for the server to send a full HTTP response, not counting data.
              type: long
        
            - name: time_wait_ms
              description: Total time in milliseconds spent waiting for a full HTTP request from the client (not counting body) after the first byte was received.
              type: long
        
        - name: tcp
          description: TCP log format
          type: group
          fields:
          - name: connection_waiting_time_ms
            type: long
            description: Total time in milliseconds elapsed between the accept and the last close
- key: icinga
  title: "Icinga"
  description: >
    Icinga Module
  fields:
    - name: icinga
      type: group
      description: >
      fields:
        - name: debug
          type: group
          description: >
            Contains fields for the Icinga debug logs.
          fields:
            - name: facility
              type: keyword
              description: >
                Specifies what component of Icinga logged the message.
        
            - name: severity
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
        - name: main
          type: group
          description: >
            Contains fields for the Icinga main logs.
          fields:
            - name: facility
              type: keyword
              description: >
                Specifies what component of Icinga logged the message.
        
            - name: severity
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
        - name: startup
          type: group
          description: >
            Contains fields for the Icinga startup logs.
          fields:
            - name: facility
              type: keyword
              description: >
                Specifies what component of Icinga logged the message.
        
            - name: severity
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
- key: iis
  title: "IIS"
  description: >
    Module for parsing IIS log files.
  fields:
    - name: iis
      type: group
      description: >
        Fields from IIS log files.
      fields:

        - name: access
          type: group
          description: >
            Contains fields for IIS access logs.
          fields:
            - name: sub_status
              type: long
              description: >
                The HTTP substatus code.
            - name: win32_status
              type: long
              description: >
                The Windows status code.
            - name: site_name
              type: keyword
              description: >
                The site name and instance number.
            - name: server_name
              type: keyword
              description: >
                The name of the server on which the log file entry was generated.
            - name: cookie
              type: keyword
              description: >
                The content of the cookie sent or received, if any.
        
            - name: body_received.bytes
              type: alias
              path: http.request.body.bytes
              migration: true
            - name: body_sent.bytes
              type: alias
              path: http.response.body.bytes
              migration: true
            - name: server_ip
              type: alias
              path: destination.address
              migration: true
            - name: method
              type: alias
              path: http.request.method
              migration: true
            - name: url
              type: alias
              path: url.path
              migration: true
            - name: query_string
              type: alias
              path: url.query
              migration: true
            - name: port
              type: alias
              path: destination.port
              migration: true
            - name: user_name
              type: alias
              path: user.name
              migration: true
            - name: remote_ip
              type: alias
              path: source.address
              migration: true
            - name: referrer
              type: alias
              path: http.request.referrer
              migration: true
            - name: response_code
              type: alias
              path: http.response.status_code
              migration: true
            - name: http_version
              type: alias
              path: http.version
              migration: true
            - name: hostname
              type: alias
              path: host.hostname
              migration: true
            - name: user_agent
              type: group
              fields:
                - name: device
                  type: alias
                  path: user_agent.device.name
                  migration: true
                - name: name
                  type: alias
                  path: user_agent.name
                  migration: true
                - name: os
                  type: alias
                  path: user_agent.os.full_name
                  migration: true
                - name: os_name
                  type: alias
                  path: user_agent.os.name
                  migration: true
                - name: original
                  type: alias
                  path: user_agent.original
                  migration: true
            - name: geoip
              type: group
              fields:
                - name: continent_name
                  type: alias
                  path: source.geo.continent_name
                  migration: true
                - name: country_iso_code
                  type: alias
                  path: source.geo.country_iso_code
                  migration: true
                - name: location
                  type: alias
                  path: source.geo.location
                  migration: true
                - name: region_name
                  type: alias
                  path: source.geo.region_name
                  migration: true
                - name: city_name
                  type: alias
                  path: source.geo.city_name
                  migration: true
                - name: region_iso_code
                  type: alias
                  path: source.geo.region_iso_code
                  migration: true
        - name: error
          type: group
          description: >
            Contains fields for IIS error logs.
          fields:
            - name: reason_phrase
              type: keyword
              description: >
                The HTTP reason phrase.
            - name: queue_name
              type: keyword
              description: >
                The IIS application pool name.
        
            - name: remote_ip
              type: alias
              path: source.address
              migration: true
            - name: remote_port
              type: alias
              path: source.port
              migration: true
            - name: server_ip
              type: alias
              path: destination.address
              migration: true
            - name: server_port
              type: alias
              path: destination.port
              migration: true
            - name: http_version
              type: alias
              path: http.version
              migration: true
            - name: method
              type: alias
              path: http.request.method
              migration: true
            - name: url
              type: alias
              path: url.original
              migration: true
            - name: response_code
              type: alias
              path: http.response.status_code
              migration: true
            - name: geoip
              type: group
              fields:
                - name: continent_name
                  type: alias
                  path: source.geo.continent_name
                  migration: true
                - name: country_iso_code
                  type: alias
                  path: source.geo.country_iso_code
                  migration: true
                - name: location
                  type: alias
                  path: source.geo.location
                  migration: true
                - name: region_name
                  type: alias
                  path: source.geo.region_name
                  migration: true
                - name: city_name
                  type: alias
                  path: source.geo.city_name
                  migration: true
                - name: region_iso_code
                  type: alias
                  path: source.geo.region_iso_code
                  migration: true
- key: kafka
  title: "Kafka"
  description: >
    Kafka module
  fields:
    - name: kafka
      type: group
      description: >
      fields:
        - name: log
          type: group
          description: >
            Kafka log lines.
          fields:
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
        
            - name: component
              type: keyword
              description: >
                Component the log is coming from.
            - name: class
              type: keyword
              description: >
                Java class the log is coming from.
            - name: trace
              type: group
              description: >
                  Trace in the log line.
              fields:
                - name: class
                  type: keyword
                  description: >
                    Java class the trace is coming from.
                - name: message
                  type: text
                  description: >
                      Message part of the trace.
- key: kibana
  title: "kibana"
  description: >
    kibana Module
  fields:
    - name: kibana
      type: group
      description: >
      fields:
        - name: log
          type: group
          description: >
            Kafka log lines.
          fields:
            - name: tags
              type: keyword
              description: >
                Kibana logging tags.
            - name: state
              type: keyword
              description: >
                Current state of Kibana.
            - name: meta
              type: object
              object_type: keyword
        
            - name: kibana.log.meta.req.headers.referer
              type: alias
              path: http.request.referrer
              migration: true
            - name: kibana.log.meta.req.referer
              type: alias
              path: http.request.referrer
              migration: true
            - name: kibana.log.meta.req.headers.user-agent
              type: alias
              path: user_agent.original
              migration: true
            - name: kibana.log.meta.req.remoteAddress
              type: alias
              path: source.address
              migration: true
            - name: kibana.log.meta.req.url
              type: alias
              path: url.original
              migration: true
            - name: kibana.log.meta.statusCode
              type: alias
              path: http.response.status_code
              migration: true
            - name: kibana.log.meta.method
              type: alias
              path: http.request.method
              migration: true
- key: logstash
  title: "logstash"
  description: >
    logstash Module
  fields:
    - name: logstash
      type: group
      description: >
      fields:
        - name: log
          title: "Logstash"
          type: group
          description: >
            Fields from the Logstash logs.
          fields:
            - name: module
              type: keyword
              description: >
                The module or class where the event originate.
            - name: thread
              type: keyword
              description: >
                Information about the running thread where the log originate.
              multi_fields:
                - name: text
                  type: text
            - name: log_event
              type: object
              description: >
                key and value debugging information.
            - name: pipeline_id
              type: keyword
              example: main
              description: >
                The ID of the pipeline.
        
            - name: message
              type: alias
              path: message
              migration: true
            - name: level
              type: alias
              path: log.level
              migration: true
        - name: slowlog
          type: group
          description: >
            slowlog
          fields:
            - name: module
              type: keyword
              description: >
                The module or class where the event originate.
            - name: thread
              type: keyword
              description: >
                Information about the running thread where the log originate.
              multi_fields:
                - name: text
                  type: text
            - name: event
              type: keyword
              description: >
                Raw dump of the original event
              multi_fields:
                - name: text
                  type: text
            - name: plugin_name
              type: keyword
              description: >
                Name of the plugin
            - name: plugin_type
              type: keyword
              description: >
                Type of the plugin: Inputs, Filters, Outputs or Codecs.
            - name: took_in_millis
              type: long
              description: >
                Execution time for the plugin in milliseconds.
            - name: plugin_params
              type: keyword
              description: >
                String value of the plugin configuration
              multi_fields:
                - name: text
                  type: text
            - name: plugin_params_object
              type: object
              description: >
                key -> value of the configuration used by the plugin.
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: took_in_nanos
              type: alias
              path: event.duration
              migration: true
- key: mongodb
  title: "mongodb"
  description: >
    Module for parsing MongoDB log files.
  fields:
    - name: mongodb
      type: group
      description: >
          Fields from MongoDB logs.
      fields:
        - name: log
          type: group
          description: >
              Contains fields from MongoDB logs.
          fields:
          - name: component
            description: >
                Functional categorization of message
            example: COMMAND
            type: keyword
          - name: context
            description: >
                Context of message
            example: initandlisten
            type: keyword
        
          - name: severity
            type: alias
            path: log.level
            migration: true
          - name: message
            type: alias
            path: message
            migration: true
- key: mysql
  title: "MySQL"
  description: >
    Module for parsing the MySQL log files.
  short_config: true
  fields:
    - name: mysql
      type: group
      description: >
        Fields from the MySQL log files.
      fields:
        - name: thread_id
          type: long
          description: >
            The connection or thread ID for the query.
        - name: error
          type: group
          description: >
            Contains fields from the MySQL error logs.
          fields:
            - name: thread_id
              type: alias
              path: mysql.thread_id
              migration: true
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
        - name: slowlog
          type: group
          description: >
            Contains fields from the MySQL slow logs.
          fields:
            - name: lock_time.sec
              type: float
              description: >
                The amount of time the query waited for the lock to be available. The
                value is in seconds, as a floating point number.
            - name: rows_sent
              type: long
              description: >
                The number of rows returned by the query.
            - name: rows_examined
              type: long
              description: >
                The number of rows scanned by the query.
            - name: rows_affected
              type: long
              description: >
                The number of rows modified by the query.
            - name: bytes_sent
              type: long
              format: bytes
              description: >
                The number of bytes sent to client.
            - name: bytes_received
              type: long
              format: bytes
              description: >
                The number of bytes received from client.
            - name: query
              description: >
                The slow query.
            - name: id
              type: alias
              path: mysql.thread_id
              migration: true
            - name: schema
              type: keyword
              description: >
                The schema where the slow query was executed.
            - name: current_user
              type: keyword
              description: >
                Current authenticated user, used to determine access privileges. Can differ from the value for user.
            - name: last_errno
              type: keyword
              description: >
                Last SQL error seen.
            - name: killed
              type: keyword
              description: >
                Code of the reason if the query was killed.
        
            - name: query_cache_hit
              type: boolean
              description: >
                Whether the query cache was hit.
            - name: tmp_table
              type: boolean
              description: >
                Whether a temporary table was used to resolve the query.
            - name: tmp_table_on_disk
              type: boolean
              description: >
                Whether the query needed temporary tables on disk.
            - name: tmp_tables
              type: long
              description: >
                Number of temporary tables created for this query
            - name: tmp_disk_tables
              type: long
              description: >
                Number of temporary tables created on disk for this query.
            - name: tmp_table_sizes
              type: long
              format: bytes
              description:
                Size of temporary tables created for this query.
            - name: filesort
              type: boolean
              description: >
                Whether filesort optimization was used.
            - name: filesort_on_disk
              type: boolean
              description: >
                Whether filesort optimization was used and it needed temporary tables on disk.
            - name: priority_queue
              type: boolean
              description: >
                Whether a priority queue was used for filesort.
            - name: full_scan
              type: boolean
              description: >
                Whether a full table scan was needed for the slow query.
            - name: full_join
              type: boolean
              description: >
                Whether a full join was needed for the slow query (no indexes were used for joins).
            - name: merge_passes
              type: long
              description: >
                Number of merge passes executed for the query.
            - name: sort_merge_passes
              type: long
              description: >
                Number of merge passes that the sort algorithm has had to do.
            - name: sort_range_count
              type: long
              description: >
                Number of sorts that were done using ranges. 
            - name: sort_rows
              type: long
              description: >
                Number of sorted rows.
            - name: sort_scan_count
              type: long
              description: >
                Number of sorts that were done by scanning the table.
            - name: log_slow_rate_type
              type: keyword
              description: >
                Type of slow log rate limit, it can be `session` if the rate limit
                is applied per session, or `query` if it applies per query.
            - name: log_slow_rate_limit
              type: keyword
              description: >
                Slow log rate limit, a value of 100 means that one in a hundred queries
                or sessions are being logged.
            - name: read_first
              type: long
              description: >
                The number of times the first entry in an index was read.
            - name: read_last
              type: long
              description: >
                The number of times the last key in an index was read.
            - name: read_key
              type: long
              description: >
                The number of requests to read a row based on a key.
            - name: read_next
              type: long
              description: >
                The number of requests to read the next row in key order.
            - name: read_prev
              type: long
              description: >
                The number of requests to read the previous row in key order.
            - name: read_rnd
              type: long
              description: >
                The number of requests to read a row based on a fixed position. 
            - name: read_rnd_next
              type: long
              description: >
                The number of requests to read the next row in the data file.
        
            # https://www.percona.com/doc/percona-server/5.7/diagnostics/slow_extended.html
            - name: innodb
              type: group
              description: >
                Contains fields relative to InnoDB engine
              fields:
                - name: trx_id
                  type: keyword
                  description: >
                    Transaction ID
                - name: io_r_ops
                  type: long
                  description: >
                    Number of page read operations.
                - name: io_r_bytes
                  type: long
                  format: bytes
                  description: >
                    Bytes read during page read operations.
                - name: io_r_wait.sec
                  type: long
                  description: >
                    How long it took to read all needed data from storage.
                - name: rec_lock_wait.sec
                  type: long
                  description: >
                    How long the query waited for locks.
                - name: queue_wait.sec
                  type: long
                  description: >
                    How long the query waited to enter the InnoDB queue and to be executed once
                    in the queue.
                - name: pages_distinct
                  type: long
                  description: >
                    Approximated count of pages accessed to execute the query.
        
            - name: user
              type: alias
              path: user.name
              migration: true
            - name: host
              type: alias
              path: source.domain
              migration: true
            - name: ip
              type: alias
              path: source.ip
              migration: true
        
- key: nats
  title: "nats"
  description: >
    Module for parsing NATS log files.
  release: beta
  fields:
    - name: nats
      type: group
      description: >
        Fields from NATS logs.
      fields:
        - name: log
          type: group
          description: >
            Nats log files
          release: beta
          fields:
            - name: client
              type: group
              description: >
                Fields from NATS logs client.
              fields:
                - name: id
                  type: integer
                  description: >
                    The id of the client
            - name: msg
              type: group
              description: >
                Fields from NATS logs message.
              fields:
                - name: bytes
                  type: long
                  format: bytes
                  description: >
                    Size of the payload in bytes
                - name: type
                  type: keyword
                  description: >
                    The protocol message type
                - name: subject
                  type: keyword
                  description: >
                    Subject name this message was received on
                - name: sid
                  type: integer
                  description: >
                    The unique alphanumeric subscription ID of the subject
                - name: reply_to
                  type: keyword
                  description: >
                    The inbox subject on which the publisher is listening for responses
                - name: max_messages
                  type: integer
                  description: >
                    An optional number of messages to wait for before automatically unsubscribing
                - name: error.message
                  type: text
                  description: >
                    Details about the error occurred
                - name: queue_group
                  type: text
                  description: >
                    The queue group which subscriber will join
- key: nginx
  title: "Nginx"
  description: >
    Module for parsing the Nginx log files.
  short_config: true
  fields:
    - name: nginx
      type: group
      description: >
        Fields from the Nginx log files.
      fields:
        - name: access
          type: group
          description: >
            Contains fields for the Nginx access logs.
          fields:
            - name: remote_ip_list
              type: array
              description: >
                An array of remote IP addresses. It is a list because it is common to include, besides the client
                IP address, IP addresses from headers like `X-Forwarded-For`.
                Real source IP is restored to `source.ip`.
        
            - name: body_sent.bytes
              type: alias
              path: http.response.body.bytes
              migration: true
            - name: user_name
              type: alias
              path: user.name
              migration: true
            - name: method
              type: alias
              path: http.request.method
              migration: true
            - name: url
              type: alias
              path: url.original
              migration: true
            - name: http_version
              type: alias
              path: http.version
              migration: true
            - name: response_code
              type: alias
              path: http.response.status_code
              migration: true
            - name: referrer
              type: alias
              path: http.request.referrer
              migration: true
            - name: agent
              type: alias
              path: user_agent.original
              migration: true
        
            - name: user_agent
              type: group
              fields:
                - name: device
                  type: alias
                  path: user_agent.device.name
                  migration: true
                - name: name
                  type: alias
                  path: user_agent.name
                  migration: true
                - name: os
                  type: alias
                  path: user_agent.os.full_name
                  migration: true
                - name: os_name
                  type: alias
                  path: user_agent.os.name
                  migration: true
                - name: original
                  type: alias
                  path: user_agent.original
                  migration: true
        
            - name: geoip
              type: group
              fields:
                - name: continent_name
                  type: alias
                  path: source.geo.continent_name
                  migration: true
                - name: country_iso_code
                  type: alias
                  path: source.geo.country_iso_code
                  migration: true
                - name: location
                  type: alias
                  path: source.geo.location
                  migration: true
                - name: region_name
                  type: alias
                  path: source.geo.region_name
                  migration: true
                - name: city_name
                  type: alias
                  path: source.geo.city_name
                  migration: true
                - name: region_iso_code
                  type: alias
                  path: source.geo.region_iso_code
                  migration: true
        - name: error
          type: group
          description: >
            Contains fields for the Nginx error logs.
          fields:
            - name: connection_id
              type: long
              description: >
                Connection identifier.
        
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: pid
              type: alias
              path: process.pid
              migration: true
            - name: tid
              type: alias
              path: process.thread.id
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
- key: osquery
  title: "Osquery"
  description: >
    Fields exported by the `osquery` module
  fields:
    - name: osquery
      type: group
      description: >
      fields:
        - name: result
          type: group
          description: >
            Common fields exported by the result metricset.
          fields:
            - name: name
              type: keyword
              description: >
                The name of the query that generated this event.
            - name: action
              type: keyword
              description: >
                For incremental data, marks whether the entry was added
                or removed. It can be one of "added", "removed", or "snapshot".
            - name: host_identifier
              type: keyword
              description: >
                The identifier for the host on which the osquery agent is running.
                Normally the hostname.
            - name: unix_time
              type: long
              description: >
                Unix timestamp of the event, in seconds since the epoch. Used for computing the `@timestamp` column.
            - name: calendar_time
              type: keyword
              description: >
                String representation of the collection time, as formatted by osquery.
- key: postgresql
  title: "PostgreSQL"
  description: >
    Module for parsing the PostgreSQL log files.
  short_config: true
  fields:
    - name: postgresql
      type: group
      description: >
          Fields from PostgreSQL logs.
      fields:
        - name: log
          type: group
          description: >
            Fields from the PostgreSQL log files.
          fields:
            - name: timestamp
              deprecated: 7.3.0
              description: >
                The timestamp from the log line.
            - name: core_id
              type: long
              description: >
                Core id
            - name: database
              example: "mydb"
              description: >
                Name of database
            - name: query
              example: "SELECT * FROM users;"
              description: >
                Query statement.
            - name: query_step
              example: "parse"
              description: >
                Statement step when using extended query protocol (one of statement, parse, bind or execute)
            - name: query_name
              example: "pdo_stmt_00000001"
              description: >
                Name given to a query when using extended query protocol. If it is "<unnamed>", or not present,
                this field is ignored.
        
            - name: error.code
              type: long
              description: Error code returned by Postgres (if any)
        
            - name: timezone
              type: alias
              path: event.timezone
              migration: true
            - name: thread_id
              type: alias
              path: process.pid
              migration: true
            - name: user
              type: alias
              path: user.name
              migration: true
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
- key: redis
  title: "Redis"
  description: >
    Redis Module
  fields:
    - name: redis
      type: group
      description: >
      fields:
        - name: log
          type: group
          description: >
            Redis log files
          fields:
            - name: role
              type: keyword
              description: >
                The role of the Redis instance. Can be one of `master`, `slave`, `child` (for RDF/AOF writing child),
                or `sentinel`.
        
            - name: pid
              type: alias
              path: process.pid
              migration: true
            - name: level
              type: alias
              path: log.level
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
        - name: slowlog
          type: group
          description: >
            Slow logs are retrieved from Redis via a network connection.
          fields:
            - name: cmd
              type: keyword
              description: >
                The command executed.
            - name: duration.us
              type: long
              description: >
                How long it took to execute the command in microseconds.
            - name: id
              type: long
              description: >
                The ID of the query.
            - name: key
              type: keyword
              description: >
                The key on which the command was executed.
            - name: args
              type: keyword
              description: >
                The arguments with which the command was called.
- key: santa
  title: "Google Santa"
  description: >
    Santa Module
  fields:
    - name: santa
      type: group
      description: >
      fields:

        - name: action
          type: keyword
          example: EXEC
          description: Action

        - name: decision
          type: keyword
          example: ALLOW
          description: Decision that santad took.

        - name: reason
          type: keyword
          example: CERT
          description: Reason for the decsision.

        - name: mode
          type: keyword
          example: M
          description: Operating mode of Santa.

        - name: disk
          type: group
          description: Fields for DISKAPPEAR actions.
          fields:
            - name: volume
              description: The volume name.

            - name: bus
              description: The disk bus protocol.

            - name: serial
              description: The disk serial number.

            - name: bsdname
              example: disk1s3
              description: The disk BSD name.

            - name: model
              example: APPLE SSD SM0512L
              description: The disk model.

            - name: fs
              example: apfs
              description: The disk volume kind (filesystem type).

            - name: mount
              description: The disk volume path.

    - name: certificate.common_name
      type: keyword
      description: Common name from code signing certificate.

    - name: certificate.sha256
      type: keyword
      description: SHA256 hash of code signing certificate.
- key: system
  title: "System"
  description: >
    Module for parsing system log files.
  short_config: true
  fields:
    - name: system
      type: group
      description: >
        Fields from the system log files.
      fields:
        - name: auth
          type: group
          description: >
            Fields from the Linux authorization logs.
          fields:
            - name: timestamp
              type: alias
              path: '@timestamp'
              migration: true
            - name: hostname
              type: alias
              path: host.hostname
              migration: true
            - name: program
              type: alias
              path: process.name
              migration: true
            - name: pid
              type: alias
              path: process.pid
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
            - name: user
              type: alias
              path: user.name
              migration: true
        
            - name: ssh
              type: group
              fields:
              - name: method
                description: >
                  The SSH authentication method. Can be one of "password" or "publickey".
              - name: signature
                description: >
                  The signature of the client public key.
              - name: dropped_ip
                type: ip
                description: >
                  The client IP from SSH connections that are open and immediately dropped.
        
              - name: event
                example: Accepted
                description: >
                  The SSH event as found in the logs (Accepted, Invalid, Failed, etc.)
        
              - name: ip
                type: alias
                path: source.ip
                migration: true
              - name: port
                type: alias
                path: source.port
                migration: true
        
              - name: geoip
                type: group
                fields:
                  - name: continent_name
                    type: alias
                    path: source.geo.continent_name
                    migration: true
                  - name: country_iso_code
                    type: alias
                    path: source.geo.country_iso_code
                    migration: true
                  - name: location
                    type: alias
                    path: source.geo.location
                    migration: true
                  - name: region_name
                    type: alias
                    path: source.geo.region_name
                    migration: true
                  - name: city_name
                    type: alias
                    path: source.geo.city_name
                    migration: true
                  - name: region_iso_code
                    type: alias
                    path: source.geo.region_iso_code
                    migration: true
        
            - name: sudo
              type: group
              description: >
                Fields specific to events created by the `sudo` command.
              fields:
              - name: error
                example: user NOT in sudoers
                description: >
                  The error message in case the sudo command failed.
              - name: tty
                description: >
                  The TTY where the sudo command is executed.
              - name: pwd
                description: >
                  The current directory where the sudo command is executed.
              - name: user
                example: root
                description: >
                  The target user to which the sudo command is switching.
              - name: command
                description: >
                  The command executed via sudo.
        
            - name: useradd
              type: group
              description: >
                Fields specific to events created by the `useradd` command.
              fields:
              - name: home
                description:
                  The home folder for the new user.
              - name: shell
                description:
                  The default shell for the new user.
        
              - name: name
                type: alias
                path: user.name
                migration: true
              - name: uid
                type: alias
                path: user.id
                migration: true
              - name: gid
                type: alias
                path: group.id
                migration: true
        
            - name: groupadd
              type: group
              description: >
                Fields specific to events created by the `groupadd` command.
              fields:
              - name: name
                type: alias
                path: group.name
                migration: true
              - name: gid
                type: alias
                path: group.id
                migration: true
        - name: syslog
          type: group
          description: >
            Contains fields from the syslog system logs.
          fields:
            - name: timestamp
              type: alias
              path: '@timestamp'
              migration: true
            - name: hostname
              type: alias
              path: host.hostname
              migration: true
            - name: program
              type: alias
              path: process.name
              migration: true
            - name: pid
              type: alias
              path: process.pid
              migration: true
            - name: message
              type: alias
              path: message
              migration: true
- key: traefik
  title: "Traefik"
  description: >
    Module for parsing the Traefik log files.
  fields:
    - name: traefik
      type: group
      description: >
        Fields from the Traefik log files.
      fields:
        - name: access
          type: group
          description: >
            Contains fields for the Traefik access logs.
          fields:
            - name: user_identifier
              type: keyword
              description: >
                Is the RFC 1413 identity of the client
            - name: request_count
              type: long
              description: >
                The number of requests
            - name: frontend_name
              type: keyword
              description: >
                The name of the frontend used
            - name: backend_url
              type: keyword
              description:
                The url of the backend where request is forwarded
        
            - name: body_sent.bytes
              type: alias
              path: http.response.body.bytes
              migration: true
            - name: remote_ip
              type: alias
              path: source.address
              migration: true
            - name: user_name
              type: alias
              path: user.name
              migration: true
            - name: method
              type: alias
              path: http.request.method
              migration: true
            - name: url
              type: alias
              path: url.original
              migration: true
            - name: http_version
              type: alias
              path: http.version
              migration: true
            - name: response_code
              type: alias
              path: http.response.status_code
              migration: true
            - name: referrer
              type: alias
              path: http.request.referrer
              migration: true
            - name: agent
              type: alias
              path: user_agent.original
              migration: true
        
            - name: user_agent
              type: group
              fields:
                - name: device
                  type: alias
                  path: user_agent.device.name
                - name: name
                  type: alias
                  path: user_agent.name
                - name: os
                  type: alias
                  path: user_agent.os.full_name
                - name: os_name
                  type: alias
                  path: user_agent.os.name
                - name: original
                  type: alias
                  path: user_agent.original
        
            - name: geoip
              type: group
              fields:
                - name: continent_name
                  type: alias
                  path: source.geo.continent_name
                - name: country_iso_code
                  type: alias
                  path: source.geo.country_iso_code
                - name: location
                  type: alias
                  path: source.geo.location
                - name: region_name
                  type: alias
                  path: source.geo.region_name
                - name: city_name
                  type: alias
                  path: source.geo.city_name
                - name: region_iso_code
                  type: alias
                  path: source.geo.region_iso_code
        
- key: activemq
  title: "activemq"
  release: beta
  description: >
    Module for parsing ActiveMQ log files.
  fields:
    - name: activemq
      type: group
      description: >
      fields:
        - name: caller
          type: keyword
          description: >
            Name of the caller issuing the logging request (class or resource).
        - name: thread
          type: keyword
          description: >
            Thread that generated the logging event.
        - name: user
          type: keyword
          description: >
            User that generated the logging event.
        - name: audit
          type: group
          description: >
            Fields from ActiveMQ audit logs.
          fields:
        - name: log
          type: group
          description: >
            Fields from ActiveMQ application logs.
          fields:
            - name: stack_trace
              type: keyword
- key: aws
  title: AWS
  release: beta
  description: >
    Module for handling logs from AWS.
  fields:
    - name: aws
      type: group
      description: >
        Fields from AWS logs.
      fields:
        - name: cloudtrail
          type: group
          release: beta
          default_field: false
          description: >
            Fields for AWS CloudTrail logs.
          fields:
            - name: event_version
              type: keyword
              description: >
                The CloudTrail version of the log event format.
            - name: user_identity
              type: group
              description: >-
                The userIdentity element contains details about the type of
                IAM identity that made the request, and which credentials were
                used. If temporary credentials were used, the element shows how the
                credentials were obtained.
              fields:
                - name: type
                  type: keyword
                  description: >
                    The type of the identity
                - name: arn
                  type: keyword
                  description: >-
                    The Amazon Resource Name (ARN) of the principal that made the call.
                - name: access_key_id
                  type: keyword
                  description: >-
                    The access key ID that was used to sign the request.
                - name: session_context
                  type: group
                  description: >-
                    If the request was made with temporary security
                    credentials, an element that provides information about the session
                    that was created for those credentials
                  fields:
                    - name: mfa_authenticated
                      type: keyword
                      description: >-
                        The value is true if the root user or IAM user whose
                        credentials were used for the request also was authenticated with an
                        MFA device; otherwise, false.
                    - name: creation_date
                      type: date
                      description: >-
                        The date and time when the temporary security credentials were issued.
                - name: invoked_by
                  type: keyword
                  description: >-
                    The name of the AWS service that made the request, such as
                    Amazon EC2 Auto Scaling or AWS Elastic Beanstalk.
            - name: error_code
              type: keyword
              description: >-
                The AWS service error if the request returns an error.
            - name: error_message
              type: keyword
              description: >-
                If the request returns an error, the description of the error.
            - name: request_parameters
              type: keyword
              description: >-
                The parameters, if any, that were sent with the request.
            - name: response_elements
              type: keyword
              description: >-
                The response element for actions that make changes (create,
                update, or delete actions).
            - name: additional_eventdata
              type: keyword
              description: >-
                Additional data about the event that was not part of the
                request or response.
            - name: request_id
              type: keyword
              description: >-
                The value that identifies the request. The service being
                called generates this value.
            - name: event_type
              type: keyword
              description: >-
                Identifies the type of event that generated the event record.
            - name: api_version
              type: keyword
              description: >-
                Identifies the API version associated with the AwsApiCall
                eventType value.
            - name: management_event
              type: keyword
              description: >-
                A Boolean value that identifies whether the event is a
                management event.
            - name: read_only
              type: keyword
              description: >-
                Identifies whether this operation is a read-only operation.
            - name: resources
              type: group
              description: >-
                A list of resources accessed in the event.
              fields:
                - name: arn
                  type: keyword
                  description: >-
                    Resource ARNs
                - name: account_id
                  type: keyword
                  description: >-
                    Account ID of the resource owner
                - name: type
                  type: keyword
                  description: >-
                    Resource type identifier in the format: AWS::aws-service-name::data-type-name
            - name: recipient_account_id
              type: keyword
              description: >-
                Represents the account ID that received this event.
            - name: service_event_details
              type: keyword
              description: >-
                Identifies the service event, including what triggered the
                event and the result.
            - name: shared_event_id
              type: keyword
              description: >-
                GUID generated by CloudTrail to uniquely identify CloudTrail
                events from the same AWS action that is sent to different AWS
                accounts.
            - name: vpc_endpoint_id
              type: keyword
              description: >-
                Identifies the VPC endpoint in which requests were made from a
                VPC to another AWS service, such as Amazon S3.
        - name: elb
          type: group
          release: ga
          description: >
            Fields for AWS ELB logs.
          fields:
            - name: name
              type: keyword
              description: >
                The name of the load balancer.
            - name: type
              type: keyword
              description: >
                The type of the load balancer for v2 Load Balancers.
            - name: target_group.arn
              type: keyword
              description: >
                The ARN of the target group handling the request.
            - name: listener
              type: keyword
              description: >
                The ELB listener that received the connection.
            - name: protocol
              type: keyword
              description: >
                The protocol of the load balancer (http or tcp).
            - name: request_processing_time.sec
              type: float
              description: >
                The total time in seconds since the connection or request is received until it is sent to a registered backend.
            - name: backend_processing_time.sec
              type: float
              description: >
                The total time in seconds since the connection is sent to the backend till the backend starts responding.
            - name: response_processing_time.sec
              type: float
              description: >
                The total time in seconds since the response is received from the backend till it is sent to the client.
            - name: connection_time.ms
              type: long
              description: >
                The total time of the connection in milliseconds, since it is opened till it is closed.
            - name: tls_handshake_time.ms
              type: long
              description: >
                The total time for the TLS handshake to complete in milliseconds once the connection has been established.
            - name: backend.ip
              type: keyword
              description: >
                The IP address of the backend processing this connection.
            - name: backend.port
              type: keyword
              description: >
                The port in the backend processing this connection.
            - name: backend.http.response.status_code
              type: keyword
              description: >
                The status code from the backend (status code sent to the client from ELB is stored in `http.response.status_code`
            - name: ssl_cipher
              type: keyword
              description: >
                The SSL cipher used in TLS/SSL connections.
            - name: ssl_protocol
              type: keyword
              description: >
                The SSL protocol used in TLS/SSL connections.
            - name: chosen_cert.arn
              type: keyword
              description: >
                The ARN of the chosen certificate presented to the client in TLS/SSL connections.
            - name: chosen_cert.serial
              type: keyword
              description: >
                The serial number of the chosen certificate presented to the client in TLS/SSL connections.
            - name: incoming_tls_alert
              type: keyword
              description: >
                The integer value of TLS alerts received by the load balancer from the client, if present.
            - name: tls_named_group
              type: keyword
              description: >
                The TLS named group.
            - name: trace_id
              type: keyword
              description: >
                The contents of the `X-Amzn-Trace-Id` header.
            - name: matched_rule_priority
              type: keyword
              description: >
                The priority value of the rule that matched the request, if a rule matched.
            - name: action_executed
              type: keyword
              description: >
                The action executed when processing the request (forward, fixed-response, authenticate...). It can contain several values.
            - name: redirect_url
              type: keyword
              description: >
                The URL used if a redirection action was executed.
            - name: error.reason
              type: keyword
              description:
                The error reason if the executed action failed.
        - name: s3access
          type: group
          release: ga
          description: >
            Fields for AWS S3 server access logs.
          fields:
            - name: bucket_owner
              type: keyword
              description: >
                The canonical user ID of the owner of the source bucket.
            - name: bucket
              type: keyword
              description: >
                The name of the bucket that the request was processed against.
            - name: remote_ip
              type: ip
              description: >
                The apparent internet address of the requester.
            - name: requester
              type: keyword
              description: >
                The canonical user ID of the requester, or a - for unauthenticated requests.
            - name: request_id
              type: keyword
              description: >
                A string generated by Amazon S3 to uniquely identify each request.
            - name: operation
              type: keyword
              description: >
                The operation listed here is declared as SOAP.operation, REST.HTTP_method.resource_type, WEBSITE.HTTP_method.resource_type, or BATCH.DELETE.OBJECT.
            - name: key
              type: keyword
              description: >
                The "key" part of the request, URL encoded, or "-" if the operation does not take a key parameter.
            - name: request_uri
              type: keyword
              description: >
                The Request-URI part of the HTTP request message.
            - name: http_status
              type: long
              description: >
                The numeric HTTP status code of the response.
            - name: error_code
              type: keyword
              description: >
                The Amazon S3 Error Code, or "-" if no error occurred.
            - name: bytes_sent
              type: long
              description: >
                The number of response bytes sent, excluding HTTP protocol overhead, or "-" if zero.
            - name: object_size
              type: long
              description: >
                The total size of the object in question.
            - name: total_time
              type: long
              description: >
                The number of milliseconds the request was in flight from the server's perspective.
            - name: turn_around_time
              type: long
              description: >
                The number of milliseconds that Amazon S3 spent processing your request.
            - name: referrer
              type: keyword
              description: >
                The value of the HTTP Referrer header, if present.
            - name: user_agent
              type: keyword
              description: >
                The value of the HTTP User-Agent header.
            - name: version_id
              type: keyword
              description: >
                The version ID in the request, or "-" if the operation does not take a versionId parameter.
            - name: host_id
              type: keyword
              description: >
                The x-amz-id-2 or Amazon S3 extended request ID.
            - name: signature_version
              type: keyword
              description: >
                The signature version, SigV2 or SigV4, that was used to authenticate the request or a - for unauthenticated requests.
            - name: cipher_suite
              type: keyword
              description: >
                The Secure Sockets Layer (SSL) cipher that was negotiated for HTTPS request or a - for HTTP.
            - name: authentication_type
              type: keyword
              description: >
                The type of request authentication used, AuthHeader for authentication headers, QueryString for query string (pre-signed URL) or a - for unauthenticated requests.
            - name: host_header
              type: keyword
              description: >
                The endpoint used to connect to Amazon S3.
            - name: tls_version
              type: keyword
              description: >
                The Transport Layer Security (TLS) version negotiated by the client.
        - name: vpcflow
          type: group
          release: beta
          description: >
            Fields for AWS VPC flow logs.
          fields:
            - name: version
              type: keyword
              description: >
                The VPC Flow Logs version. If you use the default format, the version is 2. If you specify a custom format, the version is 3.
            - name: account_id
              type: keyword
              description: >
                The AWS account ID for the flow log.
            - name: interface_id
              type: keyword
              description: >
                The ID of the network interface for which the traffic is recorded.
            - name: action
              type: keyword
              description: >
                The action that is associated with the traffic, ACCEPT or REJECT.
            - name: log_status
              type: keyword
              description: >
                The logging status of the flow log, OK, NODATA or SKIPDATA.
            - name: instance_id
              type: keyword
              description: >
                The ID of the instance that's associated with network interface for which the traffic is recorded, if the instance is owned by you.
            - name: pkt_srcaddr
              type: ip
              description: >
                The packet-level (original) source IP address of the traffic.
            - name: pkt_dstaddr
              type: ip
              description: >
                The packet-level (original) destination IP address for the traffic.
            - name: vpc_id
              type: keyword
              description: >
                The ID of the VPC that contains the network interface for which the traffic is recorded.
            - name: subnet_id
              type: keyword
              description: >
                The ID of the subnet that contains the network interface for which the traffic is recorded.
            - name: tcp_flags
              type: keyword
              description: >
                The bitmask value for the following TCP flags: 2=SYN,18=SYN-ACK,1=FIN,4=RST
            - name: type
              type: keyword
              description: >
                The type of traffic: IPv4, IPv6, or EFA.
- key: azure
  title: "Azure"
  release: beta
  description: >
    Azure Module
  fields:
    - name: azure
      type: group
      description: >
      fields:
        - name: subscription_id
          type: keyword
          description: >
            Azure subscription ID
        - name: correlation_id
          type: keyword
          description: >
            Correlation ID
        - name: tenant_id
          type: keyword
          description: >
            tenant ID
        - name: resource
          type: group
          description: >
            Resource
          fields:
            - name: id
              type: keyword
              description: >
                Resource ID
            - name: group
              type: keyword
              description: >
                Resource group
            - name: provider
              type: keyword
              description: >
                Resource type/namespace
            - name: namespace
              type: keyword
              description: >
                Resource type/namespace
            - name: name
              type: keyword
              description: >
                Name
            - name: authorization_rule
              type: keyword
              description: >
                Authorization rule
        - name: activitylogs
          type: group
          release: beta
          description: >
            Fields for Azure activity logs.
          fields:
            - name: identity
              type: group
              description: >
                Identity
              fields:
                - name: claims_initiated_by_user
                  type: group
                  description: >
                    Claims initiated by user
                  fields:
                    - name: name
                      type: keyword
                      description: >
                        Name
                    - name: givenname
                      type: keyword
                      description: >
                        Givenname
                    - name: surname
                      type: keyword
                      description: >
                        Surname
                    - name: fullname
                      type: keyword
                      description: >
                        Fullname
                    - name: schema
                      type: keyword
                      description: >
                        Schema
                - name: claims.*
                  type: object
                  object_type: keyword
                  object_type_mapping_type: "*"
                  description: >
                    Claims
                - name: authorization
                  type: group
                  description: >
                    Authorization
                  fields:
                    - name: scope
                      type: keyword
                      description: >
                        Scope
                    - name: action
                      type: keyword
                      description: >
                        Action
                    - name: evidence
                      type: group
                      description: >
                        Evidence
                      fields:
                        - name: role_assignment_scope
                          type: keyword
                          description: >
                            Role assignment scope
                        - name: role_definition_id
                          type: keyword
                          description: >
                            Role definition ID
                        - name: role
                          type: keyword
                          description: >
                            Role
                        - name: role_assignment_id
                          type: keyword
                          description: >
                            Role assignment ID
                        - name: principal_id
                          type: keyword
                          description: >
                            Principal ID
                        - name: principal_type
                          type: keyword
                          description: >
                            Principal type
            - name: operation_name
              type: keyword
              description: >
                Operation name
            - name: result_signature
              type: keyword
              description: >
                Result signature
            - name: category
              type: keyword
              description: >
                Category
            - name: properties
              type: group
              description: >
                Properties
              fields:
                - name: service_request_id
                  type: keyword
                  description: >
                    Service Request Id
                - name: status_code
                  type: keyword
                  description: >
                    Status code
        
        - name: auditlogs
          type: group
          description: >
            Fields for Azure audit logs.
          fields:
            - name: operation_name
              type: keyword
              description: >
                The operation name
            - name: operation_version
              type: keyword
              description: >
                The operation version
            - name: identity
              type: keyword
              description: >
                Identity
            - name: tenant_id
              type: keyword
              description: >
                Tenant ID
            - name: result_signature
              type: keyword
              description: >
                Result signature
            - name: properties
              type: group
              description: >
                The audit log properties
              fields:
                - name: result
                  type: keyword
                  description: >
                    Log result
                - name: activity_display_name
                  type: keyword
                  description: >
                    Activity display name
                - name: result_reason
                  type: keyword
                  description: >
                    Reason for the log result
                - name: correlation_id
                  type: keyword
                  description: >
                    Correlation ID
                - name: logged_by_service
                  type: keyword
                  description: >
                    Logged by service
                - name: operation_type
                  type: keyword
                  description: >
                    Operation type
                - name: id
                  type: keyword
                  description: >
                    ID
                - name: activity_datetime
                  type: date
                  description: >
                    Activity timestamp
                - name: category
                  type: keyword
                  description: >
                    category
                - name: target_resources.*
                  type: group
                  object_type_mapping_type: "*"
                  description: >
                    Target resources
                  fields:
                    - name: display_name
                      type: keyword
                      description: >
                        Display name
                    - name: id
                      type: keyword
                      description: >
                        ID
                    - name: type
                      type: keyword
                      description: >
                        Type
                    - name: ip_address
                      type: keyword
                      description: >
                         ip Address
                    - name: user_principal_name
                      type: keyword
                      description: >
                        User principal name
                    - name: modified_properties.*
                      type: group
                      object_type: keyword
                      object_type_mapping_type: "*"
                      description: >
                        Modified properties
                      fields:
                        - name: new_value
                          type: keyword
                          description: >
                            New value
                        - name: display_name
                          type: keyword
                          description: >
                            Display value
                        - name: old_value
                          type: keyword
                          description: >
                            Old value
                - name: initiated_by
                  type: group
                  description: >
                    Information regarding the initiator
                  fields:
                    - name: app
                      type: group
                      description: >
                        App
                      fields:
                        - name: servicePrincipalName
                          type: keyword
                          description: >
                            Service principal name
                        - name: displayName
                          type: keyword
                          description: >
                            Display name
                        - name: appId
                          type: keyword
                          description: >
                            App ID
                        - name: servicePrincipalId
                          type: keyword
                          description: >
                            Service principal ID
                    - name: user
                      type: group
                      description: >
                        User
                      fields:
                        - name: userPrincipalName
                          type: keyword
                          description: >
                            User principal name
                        - name: displayName
                          type: keyword
                          description: >
                            Display name
                        - name: id
                          type: keyword
                          description: >
                            ID
                        - name: ipAddress
                          type: keyword
                          description: >
                            ip Address
        
        
        
        
        - name: signinlogs
          type: group
          description: >
            Fields for Azure sign-in logs.
          fields:
            - name: operation_name
              type: keyword
              description: >
                The operation name
            - name: operation_version
              type: keyword
              description: >
                The operation version
            - name: tenant_id
              type: keyword
              description: >
                Tenant ID
            - name: result_signature
              type: keyword
              description: >
                Result signature
            - name: result_description
              type: keyword
              description: >
                Result description
            - name: identity
              type: keyword
              description: >
                Identity
            - name: properties
              type: group
              description: >
                The signin log properties
              fields:
                - name: id
                  type: keyword
                  description: >
                    ID
                - name: created_at
                  type: date
                  description: >
                    Created date time
                - name: user_display_name
                  type: keyword
                  description: >
                    User display name
                - name: correlation_id
                  type: keyword
                  description: >
                    Correlation ID
                - name: user_principal_name
                  type: keyword
                  description: >
                    User principal name
                - name: user_id
                  type: keyword
                  description: >
                    User ID
                - name: app_id
                  type: keyword
                  description: >
                    App ID
                - name: app_display_name
                  type: keyword
                  description: >
                    App display name
                - name: ip_address
                  type: keyword
                  description: >
                    Ip address
                - name: client_app_used
                  type: keyword
                  description: >
                    Client app used
                - name: conditional_access_status
                  type: keyword
                  description: >
                    Conditional access status
                - name: original_request_id
                  type: keyword
                  description: >
                    Original request ID
                - name: is_interactive
                  type: keyword
                  description: >
                    Is interactive
                - name: token_issuer_name
                  type: keyword
                  description: >
                    Token issuer name
                - name: token_issuer_type
                  type: keyword
                  description: >
                    Token issuer type
                - name: processing_time_ms
                  type: float
                  description: >
                    Processing time in milliseconds
                - name: risk_detail
                  type: keyword
                  description: >
                    Risk detail
                - name: risk_level_aggregated
                  type: keyword
                  description: >
                    Risk level aggregated
                - name: risk_level_during_signin
                  type: keyword
                  description: >
                    Risk level during signIn
                - name: risk_state
                  type: keyword
                  description: >
                    Risk state
                - name: resource_display_name
                  type: keyword
                  description: >
                    Resource display name
                - name: status
                  type: group
                  description: >
                    Status
                  fields:
                    - name: error_code
                      type: keyword
                      description: >
                        Error code
                - name: device_detail
                  type: group
                  description: >
                    Status
                  fields:
                    - name: device_id
                      type: keyword
                      description: >
                        Device ID
                    - name: operating_system
                      type: keyword
                      description: >
                        Operating system
                    - name: browser
                      type: keyword
                      description: >
                        Browser
                    - name: display_name
                      type: keyword
                      description: >
                        Display name
                    - name: trust_type
                      type: keyword
                      description: >
                        Trust type
                - name: service_principal_id
                  type: keyword
                  description: >
                    Status
        
- key: cef-module
  title: CEF
  description: >
    Module for receiving CEF logs over Syslog. The module does not add fields
    beyond what the decode_cef processor provides.
  fields:
- key: cisco
  title: Cisco
  description: >
    Module for handling Cisco network device logs.
  fields:
    - name: cisco
      type: group
      description: >
        Fields from Cisco logs.
      fields:
        - name: asa
          type: group
          description: >
            Fields for Cisco ASA Firewall.
          fields:
          - name: message_id
            type: keyword
            description: >
              The Cisco ASA message identifier.
        
          - name: suffix
            type: keyword
            example: session
            description: >
              Optional suffix after %ASA identifier.
        
          - name: source_interface
            type: keyword
            description: >
              Source interface for the flow or event.
        
          - name: destination_interface
            type: keyword
            description: >
              Destination interface for the flow or event.
        
          - name: rule_name
            type: keyword
            description: >
              Name of the Access Control List rule that matched this event.
        
          - name: source_username
            type: keyword
            description: >
              Name of the user that is the source for this event.
        
          - name: destination_username
            type: keyword
            description: >
              Name of the user that is the destination for this event.
        
          - name: mapped_source_ip
            type: ip
            description: >
              The translated source IP address.
        
          - name: mapped_source_port
            type: long
            description: >
              The translated source port.
        
          - name: mapped_destination_ip
            type: ip
            description: >
              The translated destination IP address.
        
          - name: mapped_destination_port
            type: long
            description: >
              The translated destination port.
        
          - name: threat_level
            type: keyword
            description: >
              Threat level for malware / botnet traffic. One of very-low, low,
              moderate, high or very-high.
        
          - name: threat_category
            type: keyword
            description: >
              Category for the malware / botnet traffic. For example: virus, botnet,
              trojan, etc.
        
          - name: connection_id
            type: keyword
            description: >
              Unique identifier for a flow.
        
          - name: icmp_type
            type: short
            description: >
              ICMP type.
        
          - name: icmp_code
            type: short
            description: >
              ICMP code.
        - name: ftd
          type: group
          description: >
            Fields for Cisco Firepower Threat Defense Firewall.
          fields:
          - name: message_id
            type: keyword
            description: >
              The Cisco FTD message identifier.
        
          - name: suffix
            type: keyword
            example: session
            description: >
              Optional suffix after %FTD identifier.
        
          - name: source_interface
            type: keyword
            description: >
              Source interface for the flow or event.
        
          - name: destination_interface
            type: keyword
            description: >
              Destination interface for the flow or event.
        
          - name: rule_name
            type: keyword
            description: >
              Name of the Access Control List rule that matched this event.
        
          - name: source_username
            type: keyword
            description: >
              Name of the user that is the source for this event.
        
          - name: destination_username
            type: keyword
            description: >
              Name of the user that is the destination for this event.
        
          - name: mapped_source_ip
            type: ip
            description: >
              The translated source IP address. Use ECS source.nat.ip.
        
          - name: mapped_source_port
            type: long
            description: >
              The translated source port. Use ECS source.nat.port.
        
          - name: mapped_destination_ip
            type: ip
            description: >
              The translated destination IP address. Use ECS destination.nat.ip.
        
          - name: mapped_destination_port
            type: long
            description: >
              The translated destination port. Use ECS destination.nat.port.
        
          - name: threat_level
            type: keyword
            description: >
              Threat level for malware / botnet traffic. One of very-low, low,
              moderate, high or very-high.
        
          - name: threat_category
            type: keyword
            description: >
              Category for the malware / botnet traffic. For example: virus, botnet,
              trojan, etc.
        
          - name: connection_id
            type: keyword
            description: >
              Unique identifier for a flow.
        
          - name: icmp_type
            type: short
            description: >
              ICMP type.
        
          - name: icmp_code
            type: short
            description: >
              ICMP code.
        
          - name: security
            type: object
            description:
              Raw fields for Security Events.
        - name: ios
          type: group
          description: >
            Fields for Cisco IOS logs.
          fields:
          - name: access_list
            type: keyword
            description: >
              Name of the IP access list.
        
          - name: facility
            type: keyword
            example: SEC
            description: >
              The facility to which the message refers (for example, SNMP, SYS, and so
              forth). A facility can be a hardware device, a protocol, or a module of
              the system software. It denotes the source or the cause of the system
              message.
- key: coredns
  title: Coredns
  description: >
    Module for handling logs produced by coredns
  fields:
  - name: coredns
    type: group
    description: >
      coredns fields after normalization
    fields:
    - name: id
      type: keyword
      description: >
        id of the DNS transaction

    - name: query.size
      type: integer
      format: bytes
      description: >
        size of the DNS query

    - name: query.class
      type: keyword
      description: >
        DNS query class

    - name: query.name
      type: keyword
      description: >
        DNS query name

    - name: query.type
      type: keyword
      description: >
        DNS query type

    - name: response.code
      type: keyword
      description: >
        DNS response code

    - name: response.flags
      type: keyword
      description: >
        DNS response flags

    - name: response.size
      type: integer
      format: bytes
      description: >
        size of the DNS response
    
    - name: dnssec_ok
      type: boolean
      description: >
        dnssec flag
        
- key: envoyproxy
  title: Envoyproxy
  description: >
    Module for handling logs produced by envoy
  fields:
  - name: envoyproxy
    type: group
    description: >
      Fields from envoy proxy logs after normalization
    fields:
    - name: log_type
      type: keyword
      description: >
        Envoy log type, normally ACCESS

    - name: response_flags
      type: keyword
      description: >
        Response flags

    - name: upstream_service_time
      type: long
      format: duration
      input_format: nanoseconds
      description: >
        Upstream service time in nanoseconds

    - name: request_id
      type: keyword
      description: >
        ID of the request

    - name: authority
      type: keyword
      description: >
        Envoy proxy authority field

    - name: proxy_type
      type: keyword
      description: >
        Envoy proxy type, tcp or http



        
- key: googlecloud
  title: Google Cloud
  description: >
    Module for handling logs from Google Cloud.
  fields:
    - name: googlecloud
      type: group
      description: >
        Fields from Google Cloud logs.
      fields:
        - name: destination.instance
          type: group
          description: >
            If the destination of the connection was a VM located on the same VPC,
            this field is populated with VM instance details. In a Shared VPC
            configuration, project_id corresponds to the project that owns the
            instance, usually the service project.
          fields:
            - name: project_id
              type: keyword
              description: >
                ID of the project containing the VM.

            - name: region
              type: keyword
              description: >
                Region of the VM.

            - name: zone
              type: keyword
              description: >
                Zone of the VM.

        - name: destination.vpc
          type: group
          description: >
            If the destination of the connection was a VM located on the same VPC,
            this field is populated with VPC network details. In a Shared VPC
            configuration, project_id corresponds to that of the host project.
          fields:
            - name: project_id
              type: keyword
              description: >
                ID of the project containing the VM.

            - name: vpc_name
              type: keyword
              description: >
                VPC on which the VM is operating.

            - name: subnetwork_name
              type: keyword
              description: >
                Subnetwork on which the VM is operating.

        - name: source.instance
          type: group
          description: >
            If the source of the connection was a VM located on the same VPC, this
            field is populated with VM instance details. In a Shared VPC
            configuration, project_id corresponds to the project that owns the
            instance, usually the service project.
          fields:
            - name: project_id
              type: keyword
              description: >
                ID of the project containing the VM.

            - name: region
              type: keyword
              description: >
                Region of the VM.

            - name: zone
              type: keyword
              description: >
                Zone of the VM.

        - name: source.vpc
          type: group
          description: >
            If the source of the connection was a VM located on the same VPC, this
            field is populated with VPC network details. In a Shared VPC
            configuration, project_id corresponds to that of the host project.
          fields:
            - name: project_id
              type: keyword
              description: >
                ID of the project containing the VM.

            - name: vpc_name
              type: keyword
              description: >
                VPC on which the VM is operating.

            - name: subnetwork_name
              type: keyword
              description: >
                Subnetwork on which the VM is operating.
        - name: audit
          type: group
          description: >
            Fields for Google Cloud audit logs.
          fields:
          - name: type
            type: keyword
            description: >
              Type property.
          - name: authentication_info
            type: group
            description: >
              Authentication information. 
            fields:
            - name: principal_email
              type: keyword
              description: >
                The email address of the authenticated user making the request. 
            - name: authority_selector
              type: keyword
              description: >
                The authority selector specified by the requestor, if any. It is not guaranteed 
                that the principal was allowed to use this authority. 
          - name: authorization_info
            type: array
            description: >
              Authorization information for the operation.
            fields:
            - name: permission
              type: keyword
              description: >
                The required IAM permission. 
            - name: granted
              type: boolean
              description: >
                Whether or not authorization for resource and permission was granted. 
            - name: resource_attributes
              type: group
              description: >
                The attributes of the resource.
              fields:
              - name: service
                type: keyword
                description: >
                  The name of the service.
              - name: name
                type: keyword
                description: >
                  The name of the resource.
              - name: type
                type: keyword
                description: >
                  The type of the resource.
          - name: method_name
            type: keyword
            description: >
              The name of the service method or operation. For API calls, this 
              should be the name of the API method. 
              For example, 'google.datastore.v1.Datastore.RunQuery'.
          - name: num_response_items
            type: long
            description: >
              The number of items returned from a List or Query API method, if applicable.
          - name: request
            type: group
            description: >
              The operation request.
            fields:
            - name: proto_name
              type: keyword
              description: >
                Type property of the request.
            - name: filter
              type: keyword
              description: >
                Filter of the request.
            - name: name
              type: keyword
              description: >
                Name of the request. 
            - name: resource_name
              type: keyword
              description: >
                Name of the request resource. 
          - name: request_metadata
            type: group
            description: >
              Metadata about the request.
            fields:
            - name: caller_ip
              type: ip
              description: >
                The IP address of the caller. 
            - name: caller_supplied_user_agent
              type: keyword
              description: >
                The user agent of the caller. This information is not authenticated and 
                should be treated accordingly.
          - name: resource_name
            type: keyword
            description: >
              The resource or collection that is the target of the operation. 
              The name is a scheme-less URI, not including the API service name. 
              For example, 'shelves/SHELF_ID/books'.
          - name: resource_location
            type: group
            description: >
              The location of the resource.
            fields:
            - name: current_locations
              type: keyword
              description: >
                Current locations of the resource.
          - name: service_name
            type: keyword
            description: >
              The name of the API service performing the operation. 
              For example, datastore.googleapis.com.
          - name: status
            type: group
            description: >
              The status of the overall operation. 
            fields:
            - name: code
              type: integer
              description: >
                The status code, which should be an enum value of google.rpc.Code. 
            - name: message
              type: keyword
              description: >
                A developer-facing error message, which should be in English. Any user-facing 
                error message should be localized and sent in the google.rpc.Status.details 
                field, or localized by the client. 
        - name: firewall
          type: group
          description: >
            Fields for Google Cloud Firewall logs.
          fields:
          - name: rule_details
            type: group
            description: >
              Description of the firewall rule that matched this connection.
            fields:
              - name: priority
                type: long
                description: The priority for the firewall rule.
              - name: action
                type: keyword
                description: Action that the rule performs on match.
              - name: direction
                type: keyword
                description: Direction of traffic that matches this rule.
              - name: reference
                type: keyword
                description: Reference to the firewall rule.
              - name: source_range
                type: keyword
                description: List of source ranges that the firewall rule applies to.
              - name: destination_range
                type: keyword
                description: List of destination ranges that the firewall applies to.
              - name: source_tag
                type: keyword
                description: >
                  List of all the source tags that the firewall rule applies to.
              - name: target_tag
                type: keyword
                description: >
                  List of all the target tags that the firewall rule applies to.
              - name: ip_port_info
                type: array
                description: >
                  List of ip protocols and applicable port ranges for rules.
              - name: source_service_account
                type: keyword
                description: >
                  List of all the source service accounts that the firewall rule applies to.
              - name: target_service_account
                type: keyword
                description: >
                  List of all the target service accounts that the firewall rule applies to.
        - name: vpcflow
          type: group
          description: >
            Fields for Google Cloud VPC flow logs.
          fields:
          - name: reporter
            type: keyword
            description: >
              The side which reported the flow. Can be either 'SRC' or 'DEST'.
        
          - name: rtt.ms
            type: long
            description: >
              Latency as measured (for TCP flows only) during the time interval. This is
              the time elapsed between sending a SEQ and receiving a corresponding ACK
              and it contains the network RTT as well as the application related delay.
- key: ibmmq
  title: "ibmmq"
  description: >
    ibmmq Module
  release: ga
  fields:
    - name: ibmmq
      type: group
      description: >
      fields:
        - name: errorlog
          description: IBM MQ error logs
          type: group
          fields:
          - name: installation
            description: >
              This is the installation name which can be given at installation time.
        
              Each installation of IBM MQ on UNIX, Linux, and Windows, has a unique identifier known as an installation name. The installation name is used to associate things such as queue managers and configuration files with an installation.
        
            type: keyword
          - name: qmgr
            description: >
              Name of the queue manager. Queue managers provide queuing services to applications, and manages the queues that belong to them.
            type: keyword
          - name: arithinsert
            description: Changing content based on error.id
            type: keyword
          - name: commentinsert
            description: Changing content based on error.id
            type: keyword
          - name: errordescription
            description: Please add description
            example: Please add example
            type: text
          - name: explanation
            description: Explaines the error in more detail
            type: keyword
          - name: action
            description: Defines what to do when the error occurs
            type: keyword
          - name: code
            description: Error code.
            type: keyword
- key: iptables
  title: iptables
  description: >
    Module for handling the iptables logs.
  fields:
    - name: iptables
      type: group
      description: >
        Fields from the iptables logs.
      fields:
        - name: ether_type
          type: long
          description: >
            Value of the ethernet type field identifying the network layer protocol.
        
        - name: flow_label
          type: integer
          description: >
            IPv6 flow label.
        
        - name: fragment_flags
          type: keyword
          description: >
            IP fragment flags. A combination of CE, DF and MF.
        
        - name: fragment_offset
          type: long
          description: >
            Offset of the current IP fragment.
        
        - name: icmp
          type: group
          description: >
            ICMP fields.
          fields:
        
          - name: code
            type: long
            description: >
              ICMP code.
        
          - name: id
            type: long
            description: >
              ICMP ID.
        
          - name: parameter
            type: long
            description: >
              ICMP parameter.
        
          - name: redirect
            type: ip
            description: >
              ICMP redirect address.
        
          - name: seq
            type: long
            description: >
              ICMP sequence number.
        
          - name: type
            type: long
            description: >
              ICMP type.
        
        - name: id
          type: long
          description: >
            Packet identifier.
        
        - name: incomplete_bytes
          type: long
          description: >
            Number of incomplete bytes.
        
        - name: input_device
          type: keyword
          description: >
            Device that received the packet.
        
        - name: precedence_bits
          type: short
          description: >
            IP precedence bits.
        
        - name: tos
          type: long
          description: >
              IP Type of Service field.
        
        - name: length
          type: long
          description: >
            Packet length.
        
        - name: output_device
          type: keyword
          description: >
            Device that output the packet.
        
        - name: tcp
          type: group
          description: >
            TCP fields.
          fields:
        
          - name: flags
            type: keyword
            description: >
              TCP flags.
        
          - name: reserved_bits
            type: short
            description: >
              TCP reserved bits.
        
          - name: seq
            type: long
            description: >
              TCP sequence number.
        
          - name: ack
            type: long
            description: >
              TCP Acknowledgment number.
        
          - name: window
            type: long
            description: >
              Advertised TCP window size.
        
        - name: ttl
          type: integer
          description: >
            Time To Live field.
        
        - name: udp
          type: group
          description: >
            UDP fields.
          fields:
        
          - name: length
            type: long
            description: >
              Length of the UDP header and payload.
        
        - name: ubiquiti
          type: group
          description: >
            Fields for Ubiquiti network devices.
          fields:
        
            - name: input_zone
              type: keyword
              description: >
                Input zone.
        
            - name: output_zone
              type: keyword
              description: >
                Output zone.
        
            - name: rule_number
              type: keyword
              description:
                The rule number within the rule set.
        
            - name: rule_set
              type: keyword
              description:
                The rule set name.
- key: misp
  title: MISP
  description: >
    Module for handling threat information from MISP.
  fields:
    - name: misp
      type: group
      description: >
        Fields from MISP threat information.
      fields:
        - name: attack_pattern
          title: Attack Pattern
          short: Fields that let you store attack patterns
          description: >
            Fields provide support for specifying information about attack patterns.
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the threat indicator.
        
          - name: name
            level: core
            type: keyword
            description: >
              Name of the attack pattern.
        
          - name: description
            level: extended
            type: text
            description: >
              Description of the attack pattern.
        
          - name: kill_chain_phases
            level: extended
            type: keyword
            description: >
              The kill chain phase(s) to which this attack pattern corresponds.
        
        - name: campaign
          title: Campaign
          short: Fields that let you store campaign information
          description: >
            Fields provide support for specifying information about campaigns.
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the campaign.
        
          - name: name
            level: core
            type: keyword
            description: >
              Name of the campaign.
        
          - name: description
            level: extended
            type: text
            description: >
              Description of the campaign.
        
          - name: aliases
            level: extended
            type: text
            description: >
              Alternative names used to identify this campaign.
        
          - name: first_seen
            level: core
            type: date
            description: >
              The time that this Campaign was first seen, in RFC3339 format.
        
          - name: last_seen
            level: core
            type: date
            description: >
              The time that this Campaign was last seen, in RFC3339 format.
        
          - name: objective
            level: core
            type: keyword
            description: >
              This field defines the Campaign's primary goal, objective, desired outcome, or intended effect.
        
        - name: course_of_action
          title: Course of Action
          short: Fields that let you store information about course of action.
          description: >
            A Course of Action is an action taken either to prevent an attack or to respond to an attack that is in progress.
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Course of Action.
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Course of Action.
        
          - name: description
            level: extended
            type: text
            description: >
              Description of the Course of Action.
        
        - name: identity
          title: Identity
          short: Fields that let you store information about identity.
          description: >
            Identity can represent actual individuals, organizations, or groups, as well as classes of individuals, organizations, or groups.
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Identity.
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Identity.
        
          - name: description
            level: extended
            type: text
            description: >
              Description of the Identity.
        
          - name: identity_class
            level: core
            type: keyword
            description: >
              The type of entity that this Identity describes, e.g., an individual or organization. Open Vocab - identity-class-ov 
        
          - name: labels
            level: extended
            type: keyword
            description: >
              The list of roles that this Identity performs.  
            example: >
              CEO
        
          - name: sectors
            level: extended
            type: keyword
            description: >
              The list of sectors that this Identity belongs to. Open Vocab - industry-sector-ov 
        
          - name: contact_information
            level: extended
            type: text
            description: >
              The contact information (e-mail, phone number, etc.) for this Identity.
        
        - name: intrusion_set
          title: Intrusion Set
          short: Fields that let you store information about Intrusion Set.
          description: >
            An Intrusion Set is a grouped set of adversary behavior and resources with common properties that is believed to be orchestrated by a single organization.
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Intrusion Set.
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Intrusion Set.
        
          - name: description
            level: extended
            type: text
            description: >
              Description of the Intrusion Set.
        
          - name: aliases
            level: extended
            type: text
            description: >
              Alternative names used to identify the Intrusion Set.
        
          - name: first_seen
            level: extended
            type: date
            description: >
              The time that this Intrusion Set was first seen, in RFC3339 format.
        
          - name: last_seen
            level: extended
            type: date
            description: >
              The time that this Intrusion Set was last seen, in RFC3339 format.
        
          - name: goals
            level: extended
            type: text
            description: >
              The high level goals of this Intrusion Set, namely, what are they trying to do.
        
          - name: resource_level
            level: extended
            type: text
            description: >
              This defines the organizational level at which this Intrusion Set typically works. Open Vocab - attack-resource-level-ov
        
          - name: primary_motivation
            level: extended
            type: text
            description: >
              The primary reason, motivation, or purpose behind this Intrusion Set. Open Vocab - attack-motivation-ov
        
          - name: secondary_motivations
            level: extended
            type: text
            description: >
              The secondary reasons, motivations, or purposes behind this Intrusion Set. Open Vocab - attack-motivation-ov
        
        - name: malware
          title: Malware
          short: Fields that let you store information about Malware.
          description: >
            Malware is a type of TTP that is also known as malicious code and malicious software, refers to a program that is inserted into a system, usually covertly, with the intent of compromising the confidentiality, integrity, or availability of the victim's data, applications, or operating system (OS) or of otherwise annoying or disrupting the victim.
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Malware.
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Malware.
        
          - name: description
            level: extended
            type: text
            description: >
              Description of the Malware.
        
          - name: labels
            level: core
            type: keyword
            description: >
              The type of malware being described. 
              Open Vocab - malware-label-ov. 
              adware,backdoor,bot,ddos,dropper,exploit-kit,keylogger,ransomware, remote-access-trojan,resource-exploitation,rogue-security-software,rootkit, screen-capture,spyware,trojan,virus,worm
        
          - name: kill_chain_phases
            format: string
            level: extended
            type: keyword
            description: >
              The list of kill chain phases for which this Malware instance can be used.
        
        - name: note
          title: Note
          short: Fields that let you store information about Malware.
          description: >
            A Note is a comment or note containing informative text to help explain the context of one or more STIX Objects (SDOs or SROs) or to provide additional analysis that is not contained in the original object.
        
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Note.
        
          - name: summary
            level: extended
            type: keyword
            description: >
              A brief description used as a summary of the Note.
        
          - name: description
            level: extended
            type: text
            description: >
              The content of the Note.
        
          - name: authors
            level: extended
            type: keyword
            description: >
              The name of the author(s) of this Note.
        
          - name: object_refs
            level: extended
            type: keyword
            description: >
              The STIX Objects (SDOs and SROs) that the note is being applied to.
        
        - name: threat_indicator
          title: Threat Indicator
          short: Fields that let you store Threat Indicators
          description: >
            Fields provide support for specifying information about threat indicators, and related matching patterns.
          type: group
          fields:
        
          - name: labels
            level: core
            type: keyword
            description: >
              list of type open-vocab that specifies the type of indicator.  
            example: >
              Domain Watchlist
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the threat indicator.
        
          - name: version
            level: core
            type: keyword
            description: >
              Version of the threat indicator.
        
          - name: type
            level: core
            type: keyword
            description: >
              Type of the threat indicator.
        
          - name: description
            level: core
            type: text
            description: >
              Description of the threat indicator.
        
          - name: feed
            level: core
            type: text
            description: >
              Name of the threat feed.
        
          - name: valid_from
            level: core
            type: date
            description: >
              The time from which this Indicator should be considered valuable 
              intelligence, in RFC3339 format.
        
          - name: valid_until
            level: core
            type: date
            description: >
              The time at which this Indicator should no longer be considered valuable intelligence. If the valid_until property is omitted, then there is no constraint on the latest time for which the indicator should be used, in RFC3339 format.
        
          - name: severity
            format: string
            level: core
            type: keyword
            description: >
              Threat severity to which this indicator corresponds.
            example: high
        
          - name: confidence
            level: core
            type: keyword
            description: >
              Confidence level to which this indicator corresponds.
            example: high
        
          - name: kill_chain_phases
            format: string
            level: extended
            type: keyword
            description: >
              The kill chain phase(s) to which this indicator corresponds.
        
          - name: mitre_tactic
            format: string
            level: extended
            type: keyword
            description: >
              MITRE tactics to which this indicator corresponds.
            example: Initial Access
        
          - name: mitre_technique
            format: string
            level: extended
            type: keyword
            description: >
              MITRE techniques to which this indicator corresponds.
            example: Drive-by Compromise
        
          - name: attack_pattern
            level: core
            type: keyword
            description: >
              The attack_pattern for this indicator is a STIX Pattern as specified in STIX Version 2.0 Part 5 - STIX Patterning. 
            example: >
              [destination:ip = '91.219.29.188/32']
        
          - name: attack_pattern_kql
            level: core
            type: keyword
            description: >
              The attack_pattern for this indicator is KQL query that matches the attack_pattern specified in the STIX Pattern format. 
            example: >
              destination.ip: "91.219.29.188/32"
        
          - name: negate
            level: core
            type: boolean
            description: >
              When set to true, it specifies the absence of the attack_pattern.
          
          - name: intrusion_set
            level: extended
            type: keyword
            description: >
              Name of the intrusion set if known.
        
          - name: campaign
            level: extended
            type: keyword
            description: >
              Name of the attack campaign if known.
        
          - name: threat_actor
            level: extended
            type: keyword
            description: >
              Name of the threat actor if known.
        
        - name: observed_data
          title: Observed Data
          short: Fields that let you store information about Observed Data.
          description: >
            Observed data conveys information that was observed on systems and networks, such as log data or network traffic, using the Cyber Observable specification.
        
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Observed Data.
        
          - name: first_observed
            level: core
            type: date
            description: >
              The beginning of the time window that the data was observed, in RFC3339 format.
        
          - name: last_observed
            level: core
            type: date
            description: >
              The end of the time window that the data was observed, in RFC3339 format.
        
          - name: number_observed
            level: core
            type: integer
            description: >
              The number of times the data represented in the objects property was observed. This MUST be an integer between 1 and 999,999,999 inclusive.
        
          - name: objects
            level: core
            type: keyword
            description: >
              A dictionary of Cyber Observable Objects that describes the single fact that was observed.
        
        - name: report
          title: Report
          short: Fields that let you store information about Report.
          description: >
            Reports are collections of threat intelligence focused on one or more topics, such as a description of a threat actor, malware, or attack technique, including context and related details.
        
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Report.
        
          - name: labels
            level: core
            type: keyword
            description: >
              This field is an Open Vocabulary that specifies the primary subject of this report. 
              Open Vocab - report-label-ov.
              threat-report,attack-pattern,campaign,identity,indicator,malware,observed-data,threat-actor,tool,vulnerability
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Report.
        
          - name: description
            level: extended
            type: text
            description: >
              A description that provides more details and context about Report.
        
          - name: published
            level: extended
            type: date
            description: >
              The date that this report object was officially published by the creator of this report, in RFC3339 format.
        
          - name: object_refs
            level: core
            type: text
            description: >
              Specifies the STIX Objects that are referred to by this Report.
        
        - name: threat_actor
          title: Threat Actor
          short: Fields that let you store information about Threat Actor.
          description: >
            Threat Actors are actual individuals, groups, or organizations believed to be operating with malicious intent.
        
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Threat Actor.
        
          - name: labels
            level: core
            type: keyword
            description: >
              This field specifies the type of threat actor. 
              Open Vocab - threat-actor-label-ov.
              activist,competitor,crime-syndicate,criminal,hacker,insider-accidental,insider-disgruntled,nation-state,sensationalist,spy,terrorist
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify this Threat Actor or Threat Actor group.
        
          - name: description
            level: extended
            type: text
            description: >
              A description that provides more details and context about the Threat Actor.
        
          - name: aliases
            level: extended
            type: text
            description: >
              A list of other names that this Threat Actor is believed to use.
        
          - name: roles
            level: extended
            type: text
            description: >
              This is a list of roles the Threat Actor plays. 
              Open Vocab - threat-actor-role-ov.
              agent,director,independent,sponsor,infrastructure-operator,infrastructure-architect,malware-author
        
          - name: goals
            level: extended
            type: text
            description: >
              The high level goals of this Threat Actor, namely, what are they trying to do.
        
          - name: sophistication
            level: extended
            type: text
            description: >
              The skill, specific knowledge, special training, or expertise a Threat Actor 
              must have to perform the attack. 
              Open Vocab - threat-actor-sophistication-ov.
              none,minimal,intermediate,advanced,strategic,expert,innovator
        
          - name: resource_level
            level: extended
            type: text
            description: >
              This defines the organizational level at which this Threat Actor typically works. 
              Open Vocab - attack-resource-level-ov.
              individual,club,contest,team,organization,government
        
          - name: primary_motivation
            level: extended
            type: text
            description: >
              The primary reason, motivation, or purpose behind this Threat Actor. 
              Open Vocab - attack-motivation-ov.
              accidental,coercion,dominance,ideology,notoriety,organizational-gain,personal-gain,personal-satisfaction,revenge,unpredictable
        
          - name: secondary_motivations
            level: extended
            type: text
            description: >
              The secondary reasons, motivations, or purposes behind this Threat Actor. 
              Open Vocab - attack-motivation-ov.
              accidental,coercion,dominance,ideology,notoriety,organizational-gain,personal-gain,personal-satisfaction,revenge,unpredictable
        
          - name: personal_motivations
            level: extended
            type: text
            description: >
              The personal reasons, motivations, or purposes of the Threat Actor regardless of 
              organizational goals.
              Open Vocab - attack-motivation-ov.
              accidental,coercion,dominance,ideology,notoriety,organizational-gain,personal-gain,personal-satisfaction,revenge,unpredictable
        
        - name: tool
          title: Tool
          short: Fields that let you store information about Tool.
          description: >
            Tools are legitimate software that can be used by threat actors to perform attacks.
        
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Tool.
        
          - name: labels
            level: core
            type: keyword
            description: >
              The kind(s) of tool(s) being described. 
              Open Vocab - tool-label-ov.
              denial-of-service,exploitation,information-gathering,network-capture,credential-exploitation,remote-access,vulnerability-scanning
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Tool.
        
          - name: description
            level: extended
            type: text
            description: >
              A description that provides more details and context about the Tool.
        
          - name: tool_version
            level: extended
            type: keyword
            description: >
              The version identifier associated with the Tool.
        
          - name: kill_chain_phases
            level: extended
            type: text
            description: >
              The list of kill chain phases for which this Tool instance can be used.
        
        - name: vulnerability
          title: Vulnerability
          short: Fields that let you store information about Vulnerability.
          description: >
            A Vulnerability is a mistake in software that can be directly used by a hacker to gain access to a system or network.
        
          type: group
          fields:
        
          - name: id
            level: core
            type: keyword
            description: >
              Identifier of the Vulnerability.
        
          - name: name
            level: core
            type: keyword
            description: >
              The name used to identify the Vulnerability.
        
          - name: description
            level: extended
            type: text
            description: >
              A description that provides more details and context about the Vulnerability.
        
        
          
        
        
        
        
        
        
- key: mssql
  title: "mssql"
  description: MS SQL Filebeat Module
  fields:
    - name: mssql
      type: group
      description: Fields from the MSSQL log files
      fields:
        - name: log
          description: Common log fields
          type: group
          fields:
            - name: origin
              description: Origin of the message, usually the server but it can also be a recovery process
              type: keyword
- key: netflow-module
  title: NetFlow
  description: >
    Module for receiving NetFlow and IPFIX flow records over UDP. The module
    does not add fields beyond what the netflow input provides.
  fields:
- key: panw
  title: panw
  description: >
    Module for Palo Alto Networks (PAN-OS)
  fields:
    - name: panw
      type: group
      description: >
        Fields from the panw module.
      fields:
         - name: panos
           type: group
           description: >
             Fields for the Palo Alto Networks PAN-OS logs.
           fields:
            - name: ruleset
              type: keyword
              description: >
                Name of the rule that matched this session.
            - name: source
              type: group
              description: >
                Fields to extend the top-level source object.
              fields:
                - name: zone
                  type: keyword
                  description: >
                    Source zone for this session.
                - name: interface
                  type: keyword
                  description: >
                    Source interface for this session.
                - name: nat
                  type: group
                  description: >
                    Post-NAT source address, if source NAT is performed.
                  fields:
                  - name: ip
                    type: ip
                    description: >
                      Post-NAT source IP.
                  - name: port
                    type: long
                    description: >
                      Post-NAT source port.
        
            - name: destination
              type: group
              description: >
                Fields to extend the top-level destination object.
              fields:
                - name: zone
                  type: keyword
                  description: >
                    Destination zone for this session.
                - name: interface
                  type: keyword
                  description: >
                    Destination interface for this session.
                - name: nat
                  type: group
                  description: >
                    Post-NAT destination address, if destination NAT is performed.
                  fields:
                    - name: ip
                      type: ip
                      description: >
                        Post-NAT destination IP.
                    - name: port
                      type: long
                      description: >
                        Post-NAT destination port.
        
            - name: network
              type: group
              description: >
                Fields to extend the top-level network object.
              fields:
                - name: pcap_id
                  type: keyword
                  description: >
                    Packet capture ID for a threat.
        
                - name: nat
                  type: group
                  fields:
                    - name: community_id
                      type: keyword
                      description: >
                        Community ID flow-hash for the NAT 5-tuple.
        
            - name: file
              type: group
              description: >
                Fields to extend the top-level file object.
              fields:
                - name: hash
                  description: >
                    Binary hash for a threat file sent to be analyzed
                    by the WildFire service.
                  type: keyword
        
            - name: url
              type: group
              description: >
                Fields to extend the top-level url object.
              fields:
                - name: category
                  type: keyword
                  description: >
                    For threat URLs, it's the URL category.
                    For WildFire, the verdict on the file and is
                    either 'malicious', 'grayware', or 'benign'.
        
            - name: flow_id
              type: keyword
              description: >
                Internal numeric identifier for each session.
        
            - name: sequence_number
              type: long
              description: >
                Log entry identifier that is incremented sequentially.
                Unique for each log type.
        
            - name: threat.resource
              type: keyword
              description: >
                URL or file name for a threat.
        
            - name: threat.id
              type: keyword
              description: >
                Palo Alto Networks identifier for the threat.
        
            - name: threat.name
              type: keyword
              description: >
                Palo Alto Networks name for the threat.
- key: rabbitmq
  title: "RabbitMQ"
  description: >
    RabbitMQ Module
  fields:
    - name: rabbitmq
      type: group
      description: >
      fields:
        - name: log
          type: group
          description: >
            RabbitMQ log files
          fields:
            - name: pid
              type: keyword
              description: The Erlang process id
              example: <0.222.0>
- key: suricata
  title: Suricata
  description: >
    Module for handling the EVE JSON logs produced by Suricata.
  fields:
    - name: suricata
      type: group
      description: >
        Fields from the Suricata EVE log file.
      fields:
        - name: eve
          type: group
          description: >
            Fields exported by the EVE JSON logs
          fields:
            - name: event_type
              type: keyword
        
            - name: app_proto_orig
              type: keyword
        
            - name: tcp
              type: group
              fields:
              - name: tcp_flags
                type: keyword
        
              - name: psh
                type: boolean
        
              - name: tcp_flags_tc
                type: keyword
        
              - name: ack
                type: boolean
        
              - name: syn
                type: boolean
        
              - name: state
                type: keyword
        
              - name: tcp_flags_ts
                type: keyword
        
              - name: rst
                type: boolean
        
              - name: fin
                type: boolean
        
            - name: fileinfo
              type: group
              fields:
              - name: sha1
                type: keyword
        
              - name: filename
                type: alias
                path: file.path
        
              - name: tx_id
                type: long
        
              - name: state
                type: keyword
        
              - name: stored
                type: boolean
        
              - name: gaps
                type: boolean
        
              - name: sha256
                type: keyword
        
              - name: md5
                type: keyword
        
              - name: size
                type: alias
                path: file.size
        
            - name: icmp_type
              type: long
        
            - name: dest_port
              type: alias
              path: destination.port
        
            - name: src_port
              type: alias
              path: source.port
        
            - name: proto
              type: alias
              path: network.transport
        
            - name: pcap_cnt
              type: long
        
            - name: src_ip
              type: alias
              path: source.ip
        
            - name: dns
              type: group
              fields:
              - name: type
                type: keyword
        
              - name: rrtype
                type: keyword
        
              - name: rrname
                type: keyword
        
              - name: rdata
                type: keyword
        
              - name: tx_id
                type: long
        
              - name: ttl
                type: long
        
              - name: rcode
                type: keyword
        
              - name: id
                type: long
        
            - name: flow_id
              type: keyword
        
            - name: email
              type: group
              fields:
              - name: status
                type: keyword
        
            - name: dest_ip
              type: alias
              path: destination.ip
        
            - name: icmp_code
              type: long
        
            - name: http
              type: group
              fields:
              - name: status
                type: alias
                path: http.response.status_code
        
              - name: redirect
                type: keyword
        
              - name: http_user_agent
                type: alias
                path: user_agent.original
        
              - name: protocol
                type: keyword
        
              - name: http_refer
                type: alias
                path: http.request.referrer
        
              - name: url
                type: alias
                path: url.original
        
              - name: hostname
                type: alias
                path: url.domain
        
              - name: length
                type: alias
                path: http.response.body.bytes
        
              - name: http_method
                type: alias
                path: http.request.method
        
              - name: http_content_type
                type: keyword
        
            - name: timestamp
              type: alias
              path: '@timestamp'
        
            - name: in_iface
              type: keyword
        
            - name: alert
              type: group
              fields:
              - name: category
                type: keyword
        
              - name: severity
                type: alias
                path: event.severity
        
              - name: rev
                type: long
        
              - name: gid
                type: long
        
              - name: signature
                type: keyword
        
              - name: action
                type: alias
                path: event.outcome
        
              - name: signature_id
                type: long
        
            - name: ssh
              type: group
              fields:
              - name: client
                type: group
                fields:
                - name: proto_version
                  type: keyword
        
                - name: software_version
                  type: keyword
        
              - name: server
                type: group
                fields:
                - name: proto_version
                  type: keyword
        
                - name: software_version
                  type: keyword
        
            - name: stats
              type: group
              fields:
              - name: capture
                type: group
                fields:
                - name: kernel_packets
                  type: long
        
                - name: kernel_drops
                  type: long
        
                - name: kernel_ifdrops
                  type: long
        
              - name: uptime
                type: long
        
              - name: detect
                type: group
                fields:
                - name: alert
                  type: long
        
              - name: http
                type: group
                fields:
                - name: memcap
                  type: long
        
                - name: memuse
                  type: long
        
              - name: file_store
                type: group
                fields:
                - name: open_files
                  type: long
        
              - name: defrag
                type: group
                fields:
                - name: max_frag_hits
                  type: long
        
                - name: ipv4
                  type: group
                  fields:
                  - name: timeouts
                    type: long
        
                  - name: fragments
                    type: long
        
                  - name: reassembled
                    type: long
        
                - name: ipv6
                  type: group
                  fields:
                  - name: timeouts
                    type: long
        
                  - name: fragments
                    type: long
        
                  - name: reassembled
                    type: long
        
              - name: flow
                type: group
                fields:
                - name: tcp_reuse
                  type: long
        
                - name: udp
                  type: long
        
                - name: memcap
                  type: long
        
                - name: emerg_mode_entered
                  type: long
        
                - name: emerg_mode_over
                  type: long
        
                - name: tcp
                  type: long
        
                - name: icmpv6
                  type: long
        
                - name: icmpv4
                  type: long
        
                - name: spare
                  type: long
        
                - name: memuse
                  type: long
        
              - name: tcp
                type: group
                fields:
                - name: pseudo_failed
                  type: long
        
                - name: ssn_memcap_drop
                  type: long
        
                - name: insert_data_overlap_fail
                  type: long
        
                - name: sessions
                  type: long
        
                - name: pseudo
                  type: long
        
                - name: synack
                  type: long
        
                - name: insert_data_normal_fail
                  type: long
        
                - name: syn
                  type: long
        
                - name: memuse
                  type: long
        
                - name: invalid_checksum
                  type: long
        
                - name: segment_memcap_drop
                  type: long
        
                - name: overlap
                  type: long
        
                - name: insert_list_fail
                  type: long
        
                - name: rst
                  type: long
        
                - name: stream_depth_reached
                  type: long
        
                - name: reassembly_memuse
                  type: long
        
                - name: reassembly_gap
                  type: long
        
                - name: overlap_diff_data
                  type: long
        
                - name: no_flow
                  type: long
        
              - name: decoder
                type: group
                fields:
                - name: avg_pkt_size
                  type: long
        
                - name: bytes
                  type: long
        
                - name: tcp
                  type: long
        
                - name: raw
                  type: long
        
                - name: ppp
                  type: long
        
                - name: vlan_qinq
                  type: long
        
                - name: 'null'
                  type: long
        
                - name: ltnull
                  type: group
                  fields:
                  - name: unsupported_type
                    type: long
        
                  - name: pkt_too_small
                    type: long
        
                - name: invalid
                  type: long
        
                - name: gre
                  type: long
        
                - name: ipv4
                  type: long
        
                - name: ipv6
                  type: long
        
                - name: pkts
                  type: long
        
                - name: ipv6_in_ipv6
                  type: long
        
                - name: ipraw
                  type: group
                  fields:
                  - name: invalid_ip_version
                    type: long
        
                - name: pppoe
                  type: long
        
                - name: udp
                  type: long
        
                - name: dce
                  type: group
                  fields:
                  - name: pkt_too_small
                    type: long
        
                - name: vlan
                  type: long
        
                - name: sctp
                  type: long
        
                - name: max_pkt_size
                  type: long
        
                - name: teredo
                  type: long
        
                - name: mpls
                  type: long
        
                - name: sll
                  type: long
        
                - name: icmpv6
                  type: long
        
                - name: icmpv4
                  type: long
        
                - name: erspan
                  type: long
        
                - name: ethernet
                  type: long
        
                - name: ipv4_in_ipv6
                  type: long
        
                - name: ieee8021ah
                  type: long
        
              - name: dns
                type: group
                fields:
                - name: memcap_global
                  type: long
        
                - name: memcap_state
                  type: long
        
                - name: memuse
                  type: long
        
              - name: flow_mgr
                type: group
                fields:
                - name: rows_busy
                  type: long
        
                - name: flows_timeout
                  type: long
        
                - name: flows_notimeout
                  type: long
        
                - name: rows_skipped
                  type: long
        
                - name: closed_pruned
                  type: long
        
                - name: new_pruned
                  type: long
        
                - name: flows_removed
                  type: long
        
                - name: bypassed_pruned
                  type: long
        
                - name: est_pruned
                  type: long
        
                - name: flows_timeout_inuse
                  type: long
        
                - name: flows_checked
                  type: long
        
                - name: rows_maxlen
                  type: long
        
                - name: rows_checked
                  type: long
        
                - name: rows_empty
                  type: long
        
              - name: app_layer
                type: group
                fields:
                - name: flow
                  type: group
                  fields:
                  - name: tls
                    type: long
        
                  - name: ftp
                    type: long
        
                  - name: http
                    type: long
        
                  - name: failed_udp
                    type: long
        
                  - name: dns_udp
                    type: long
        
                  - name: dns_tcp
                    type: long
        
                  - name: smtp
                    type: long
        
                  - name: failed_tcp
                    type: long
        
                  - name: msn
                    type: long
        
                  - name: ssh
                    type: long
        
                  - name: imap
                    type: long
        
                  - name: dcerpc_udp
                    type: long
        
                  - name: dcerpc_tcp
                    type: long
        
                  - name: smb
                    type: long
        
                - name: tx
                  type: group
                  fields:
                  - name: tls
                    type: long
        
                  - name: ftp
                    type: long
        
                  - name: http
                    type: long
        
                  - name: dns_udp
                    type: long
        
                  - name: dns_tcp
                    type: long
        
                  - name: smtp
                    type: long
        
                  - name: ssh
                    type: long
        
                  - name: dcerpc_udp
                    type: long
        
                  - name: dcerpc_tcp
                    type: long
        
                  - name: smb
                    type: long
        
            - name: tls
              type: group
              fields:
              - name: notbefore
                type: date
        
              - name: issuerdn
                type: keyword
        
              - name: sni
                type: keyword
        
              - name: version
                type: keyword
        
              - name: session_resumed
                type: boolean
        
              - name: fingerprint
                type: keyword
        
              - name: serial
                type: keyword
        
              - name: notafter
                type: date
        
              - name: subject
                type: keyword
        
            - name: app_proto_ts
              type: keyword
        
            - name: flow
              type: group
              fields:
              - name: bytes_toclient
                type: alias
                path: destination.bytes
        
              - name: start
                type: alias
                path: event.start
        
              - name: pkts_toclient
                type: alias
                path: destination.packets
        
              - name: age
                type: long
        
              - name: state
                type: keyword
        
              - name: bytes_toserver
                type: alias
                path: source.bytes
        
              - name: reason
                type: keyword
        
              - name: pkts_toserver
                type: alias
                path: source.packets
        
              - name: end
                type: date
        
              - name: alerted
                type: boolean
        
            - name: app_proto
              type: alias
              path: network.protocol
        
            - name: tx_id
              type: long
        
            - name: app_proto_tc
              type: keyword
        
            - name: smtp
              type: group
              fields:
              - name: rcpt_to
                type: keyword
        
              - name: mail_from
                type: keyword
        
              - name: helo
                type: keyword
        
            - name: app_proto_expected
              type: keyword
        
            - name: flags
              type: group
              fields:
- key: zeek
  title: Zeek
  description: >
    Module for handling logs produced by Zeek/Bro
  fields:
    - name: zeek
      type: group
      description: >
        Fields from Zeek/Bro logs after normalization
      fields:
        - name: session_id
          type: keyword
          description: >
            A unique identifier of the session
        - name: capture_loss
          type: group
          description: >
            Fields exported by the Zeek capture_loss log
          fields:
            - name: ts_delta
              type: integer
              description: |
                The time delay between this measurement and the last.
        
            - name: peer
              type: keyword
              description: |
                In the event that there are multiple Bro instances logging to the same host, this distinguishes each peer with its individual name.
        
            - name: gaps
              type: integer
              description: |
                Number of missed ACKs from the previous measurement interval.
        
            - name: acks
              type: integer
              description: |
                Total number of ACKs seen in the previous measurement interval.
        
            - name: percent_lost
              type: double
              description: |
                Percentage of ACKs seen where the data being ACKed wasn't seen.
        - name: connection
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek Connection log
          fields:
            - name: local_orig
              type: boolean
              description: >
                Indicates whether the session is originated locally.
        
            - name: local_resp
              type: boolean
              description: >
                Indicates whether the session is responded locally.
        
            - name: missed_bytes
              type: long
              description: >
                Missed bytes for the session.
        
            - name: state
              type: keyword
              description: >
                Code indicating the state of the session.
        
            - name: state_message
              type: keyword
              description: >
                The state of the session.
        
            - name: icmp
              type: group
              fields:
                - name: type
                  type: integer
                  description: >
                    ICMP message type.
        
                - name: code
                  type: integer
                  description: >
                    ICMP message code.
        
            - name: history
              type: keyword
              description: >
                Flags indicating the history of the session.
        
            - name: vlan
              type: integer
              description: >
                VLAN identifier.
        
            - name: inner_vlan
              type: integer
              description: >
                VLAN identifier.
        
        - name: dce_rpc
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek DCE_RPC log
          fields:
            - name: rtt
              type: integer
              description: |
                Round trip time from the request to the response. If either the request or response wasn't seen, this will be null.
        
            - name: named_pipe
              type: keyword
              description: |
                Remote pipe name.
        
            - name: endpoint
              type: keyword
              description: |
                Endpoint name looked up from the uuid.
        
            - name: operation
              type: keyword
              description: |
                Operation seen in the call.
        - name: dhcp
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek DHCP log
          fields:
            - name: domain
              type: keyword
              description: >
                Domain given by the server in option 15.
        
            - name: duration
              type: double
              description: |
                Duration of the DHCP session representing the time from the first
                message to the last, in seconds.
        
            - name: hostname
              type: keyword
              description: >
                Name given by client in Hostname option 12.
        
            - name: client_fqdn
              type: keyword
              description: >
                FQDN given by client in Client FQDN option 81.
        
            - name: lease_time
              type: integer
              description: >
                IP address lease interval in seconds.
        
            - name: address
              type: group
              description: >
                Addresses seen in this DHCP exchange.
              fields:
                - name: assigned
                  type: ip
                  description: >
                    IP address assigned by the server.
        
                - name: client
                  type: ip
                  description: |
                    IP address of the client. If a transaction is only a client sending
                    INFORM messages then there is no lease information exchanged so this
                    is helpful to know who sent the messages. Getting an address in this
                    field does require that the client sources at least one DHCP message
                    using a non-broadcast address.
        
                - name: mac
                  type: keyword
                  description: >
                    Client's hardware address.
        
                - name: requested
                  type: ip
                  description: >
                    IP address requested by the client.
        
                - name: server
                  type: ip
                  description: >
                    IP address of the DHCP server.
        
            - name: msg
              type: group
              fields:
                - name: types
                  type: keyword
                  description: >
                    List of DHCP message types seen in this exchange.
        
                - name: origin
                  type: ip
                  description: |
                    (present if policy/protocols/dhcp/msg-orig.bro is loaded)
                    The address that originated each message from the msg.types field.
        
                - name: client
                  type: keyword
                  description: |
                    Message typically accompanied with a DHCP_DECLINE so the client can
                    tell the server why it rejected an address.
        
                - name: server
                  type: keyword
                  description: |
                    Message typically accompanied with a DHCP_NAK to let the client know
                    why it rejected the request.
        
            - name: software
              type: group
              fields:
                - name: client
                  type: keyword
                  description: |
                    (present if policy/protocols/dhcp/software.bro is loaded)
                    Software reported by the client in the vendor_class option.
        
                - name: server
                  type: keyword
                  description: |
                    (present if policy/protocols/dhcp/software.bro is loaded)
                    Software reported by the client in the vendor_class option.
        
            - name: id
              type: group
              fields:
                - name: circuit
                  type: keyword
                  description: |
                    (present if policy/protocols/dhcp/sub-opts.bro is loaded)
                    Added by DHCP relay agents which terminate switched or permanent
                    circuits. It encodes an agent-local identifier of the circuit from
                    which a DHCP client-to-server packet was received. Typically it
                    should represent a router or switch interface number.
        
                - name: remote_agent
                  type: keyword
                  description: |
                    (present if policy/protocols/dhcp/sub-opts.bro is loaded)
                    A globally unique identifier added by relay agents to identify the
                    remote host end of the circuit.
        
                - name: subscriber
                  type: keyword
                  description: |
                    (present if policy/protocols/dhcp/sub-opts.bro is loaded)
                    The subscriber ID is a value independent of the physical network
                    configuration so that a customer's DHCP configuration can be given
                    to them correctly no matter where they are physically connected.
        - name: dnp3
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SSH log
          fields:
            - name: function
              type: group
              fields:
                - name: request
                  type: keyword
                  description: |
                    The name of the function message in the request.
        
                - name: reply
                  type: keyword
                  description: |
                    The name of the function message in the reply.
        
            - name: id
              type: integer
              description: |
                The response's internal indication number.
        
        - name: dns
          type: group
          description: >
            Fields exported by the Zeek DNS log
          fields:
            - name: trans_id
              type: keyword
              description: >
                DNS transaction identifier.
        
            - name: rtt
              type: double
              description: >
                Round trip time for the query and response.
        
            - name: query
              type: keyword
              description: >
                The domain name that is the subject of the DNS query.
        
            - name: qclass
              type: long
              description: >
                The QCLASS value specifying the class of the query.
        
            - name: qclass_name
              type: keyword
              description: >
                A descriptive name for the class of the query.
        
            - name: qtype
              type: long
              description: >
                A QTYPE value specifying the type of the query.
        
            - name: qtype_name
              type: keyword
              description: >
                A descriptive name for the type of the query.
        
            - name: rcode
              type: long
              description: >
                The response code value in DNS response messages.
        
            - name: rcode_name
              type: keyword
              description: >
                A descriptive name for the response code value.
        
            - name: AA
              type: boolean
              description: |
                The Authoritative Answer bit for response messages specifies that the responding
                name server is an authority for the domain name in the question section.
        
            - name: TC
              type: boolean
              description: >
                The Truncation bit specifies that the message was truncated.
        
            - name: RD
              type: boolean
              description: |
                The Recursion Desired bit in a request message indicates that the client
                wants recursive service for this query.
        
            - name: RA
              type: boolean
              description: |
                The Recursion Available bit in a response message indicates that the name
                server supports recursive queries.
        
            - name: answers
              type: keyword
              description: >
                The set of resource descriptions in the query answer.
        
            - name: TTLs
              type: double
              description: >
                The caching intervals of the associated RRs described by the answers field.
        
            - name: rejected
              type: boolean
              description: >
                Indicates whether the DNS query was rejected by the server.
        
            - name: total_answers
              type: integer
              description: >
                The total number of resource records in the reply.
        
            - name: total_replies
              type: integer
              description: >
                The total number of resource records in the reply message.
        
            - name: saw_query
              type: boolean
              description: >
                Whether the full DNS query has been seen.
        
            - name: saw_reply
              type: boolean
              description: >
                Whether the full DNS reply has been seen.
        - name: dpd
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek DPD log
          fields:
            - name: analyzer
              type: keyword
              description: >
                The analyzer that generated the violation.
        
            - name: failure_reason
              type: keyword
              description: >
                The textual reason for the analysis failure.
        
            - name: packet_segment
              type: keyword
              description: |
                (present if policy/frameworks/dpd/packet-segment-logging.bro is loaded)
                A chunk of the payload that most likely resulted in the protocol violation.
        - name: files
          type: group
          description: >
            Fields exported by the Zeek Files log.
          fields:
            - name: fuid
              type: keyword
              description: >
                A file unique identifier.
        
            - name: tx_host
              type: ip
              description: >
                The host that transferred the file.
        
            - name: rx_host
              type: ip
              description: >
                The host that received the file.
        
            - name: session_ids
              type: keyword
              description: >
                The sessions that have this file.
        
            - name: source
              type: keyword
              description: |
                An identification of the source of the file data. E.g. it may be a network protocol
                over which it was transferred, or a local file path which was read, or some other
                input source.
        
            - name: depth
              type: long
              description: |
                A value to represent the depth of this file in relation to its source. In SMTP, it
                is the depth of the MIME attachment on the message. In HTTP, it is the depth of the
                request within the TCP connection.
        
            - name: analyzers
              type: keyword
              description: >
                A set of analysis types done during the file analysis.
        
            - name: mime_type
              type: keyword
              description: >
                Mime type of the file.
        
            - name: filename
              type: keyword
              description: >
                Name of the file if available.
        
            - name: local_orig
              type: boolean
              description: |
                If the source of this file is a network connection, this field indicates if the data
                originated from the local network or not.
        
            - name: is_orig
              type: boolean
              description: |
                If the source of this file is a network connection, this field indicates if the file is
                being sent by the originator of the connection or the responder.
        
            - name: duration
              type: double
              description: >
                The duration the file was analyzed for. Not the duration of the session.
        
            - name: seen_bytes
              type: long
              description: >
                Number of bytes provided to the file analysis engine for the file.
        
            - name: total_bytes
              type: long
              description: >
                Total number of bytes that are supposed to comprise the full file.
        
            - name: missing_bytes
              type: long
              description: |
                The number of bytes in the file stream that were completely missed during the process
                of analysis.
        
            - name: overflow_bytes
              type: long
              description: |
                The number of bytes in the file stream that were not delivered to stream file analyzers.
                This could be overlapping bytes or bytes that couldn't be reassembled.
        
            - name: timedout
              type: boolean
              description: >
                Whether the file analysis timed out at least once for the file.
        
            - name: parent_fuid
              type: keyword
              description: |
                Identifier associated with a container file from which this one was extracted as part of
                the file analysis.
        
            - name: md5
              type: keyword
              description: >
                An MD5 digest of the file contents.
        
            - name: sha1
              type: keyword
              description: >
                A SHA1 digest of the file contents.
        
            - name: sha256
              type: keyword
              description: >
                A SHA256 digest of the file contents.
        
            - name: extracted
              type: keyword
              description: >
                Local filename of extracted file.
        
            - name: extracted_cutoff
              type: boolean
              description: >
                Indicate whether the file being extracted was cut off hence not extracted completely.
        
            - name: extracted_size
              type: long
              description: >
                The number of bytes extracted to disk.
        
            - name: entropy
              type: double
              description: >
                The information density of the contents of the file.
        - name: ftp
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek FTP log
          fields:
            - name: user
              type: keyword
              description: |
                User name for the current FTP session.
        
            - name: password
              type: keyword
              description: |
                Password for the current FTP session if captured.
        
            - name: command
              type: keyword
              description: |
                Command given by the client.
        
            - name: arg
              type: keyword
              description: |
                Argument for the command if one is given.
        
            - name: file
              type: group
              fields:
                - name: size
                  type: long
                  description: |
                    Size of the file if the command indicates a file transfer.
        
                - name: mime_type
                  type: keyword
                  description: |
                    Sniffed mime type of file.
        
                - name: fuid
                  type: keyword
                  description: |
                    (present if base/protocols/ftp/files.bro is loaded)
                    File unique ID.
        
            - name: reply
              type: group
              fields:
                - name: code
                  type: integer
                  description: |
                    Reply code from the server in response to the command.
        
                - name: msg
                  type: keyword
                  description: |
                    Reply message from the server in response to the command.
        
            - name: data_channel
              type: group
              description: |
                Expected FTP data channel.
              fields:
                - name: passive
                  type: boolean
                  description: |
                    Whether PASV mode is toggled for control channel.
        
                - name: originating_host
                  type: ip
                  description: |
                    The host that will be initiating the data connection.
        
                - name: response_host
                  type: ip
                  description: |
                    The host that will be accepting the data connection.
        
                - name: response_port
                  type: integer
                  description: |
                    The port at which the acceptor is listening for the data connection.
        
            - name: cwd
              type: keyword
              description: |
                Current working directory that this session is in. By making the default value '.', we can indicate that unless something more concrete is discovered that the existing but unknown directory is ok to use.
        
            - name: cmdarg
              type: group
              description: |
                Command that is currently waiting for a response.
              fields:
                - name: cmd
                  type: keyword
                  description: |
                    Command.
        
                - name: arg
                  type: keyword
                  description: |
                    Argument for the command if one was given.
        
                - name: seq
                  type: integer
                  description: |
                    Counter to track how many commands have been executed.
        
            - name: pending_commands
              type: integer
              description: |
                Queue for commands that have been sent but not yet responded to are tracked here.
        
            - name: passive
              type: boolean
              description: |
                Indicates if the session is in active or passive mode.
        
            - name: capture_password
              type: boolean
              description: |
                Determines if the password will be captured for this request.
        
            - name: last_auth_requested
              type: keyword
              description: |
                present if base/protocols/ftp/gridftp.bro is loaded.
                Last authentication/security mechanism that was used.
        - name: http
          type: group
          description: >
            Fields exported by the Zeek HTTP log
          fields:
            - name: trans_depth
              type: integer
              description: >
                Represents the pipelined depth into the connection of this request/response transaction.
        
            - name: status_msg
              type: keyword
              description: >
                Status message returned by the server.
        
            - name: info_code
              type: integer
              description: >
                Last seen 1xx informational reply code returned by the server.
        
            - name: info_msg
              type: keyword
              description: >
                Last seen 1xx informational reply message returned by the server.
        
            - name: tags
              type: keyword
              description: |
                A set of indicators of various attributes discovered and related to a particular
                request/response pair.
        
            - name: password
              type: keyword
              description: >
                Password if basic-auth is performed for the request.
        
            - name: captured_password
              type: boolean
              description: >
                Determines if the password will be captured for this request.
        
            - name: proxied
              type: keyword
              description: >
                All of the headers that may indicate if the HTTP request was proxied.
        
            - name: range_request
              type: boolean
              description: >
                Indicates if this request can assume 206 partial content in response.
        
            - name: client_header_names
              type: keyword
              description: |
                The vector of HTTP header names sent by the client. No header values
                are included here, just the header names.
        
            - name: server_header_names
              type: keyword
              description: |
                The vector of HTTP header names sent by the server. No header values
                are included here, just the header names.
        
            - name: orig_fuids
              type: keyword
              description: >
                An ordered vector of file unique IDs from the originator.
        
            - name: orig_mime_types
              type: keyword
              description: >
                An ordered vector of mime types from the originator.
        
            - name: orig_filenames
              type: keyword
              description: >
                An ordered vector of filenames from the originator.
        
            - name: resp_fuids
              type: keyword
              description: >
                An ordered vector of file unique IDs from the responder.
        
            - name: resp_mime_types
              type: keyword
              description: >
                An ordered vector of mime types from the responder.
        
            - name: resp_filenames
              type: keyword
              description: >
                An ordered vector of filenames from the responder.
        
            - name: orig_mime_depth
              type: integer
              description: >
                Current number of MIME entities in the HTTP request message body.
        
            - name: resp_mime_depth
              type: integer
              description: >
                Current number of MIME entities in the HTTP response message body.
        - name: intel
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek Intel log.
          fields:
        
            - name: seen
              type: group
              fields:
                - name: indicator
                  type: keyword
                  description: >
                    The intelligence indicator.
        
                - name: indicator_type
                  type: keyword
                  description: >
                    The type of data the indicator represents.
        
                - name: host
                  type: keyword
                  description: >
                    If the indicator type was Intel::ADDR, then this field will be present.
        
                - name: conn
                  type: keyword
                  description: >
                    If the data was discovered within a connection, the connection record should go here to give context to the data.
        
                - name: where
                  type: keyword
                  description: >
                    Where the data was discovered.
        
                - name: node
                  type: keyword
                  description: >
                    The name of the node where the match was discovered.
        
                - name: uid
                  type: keyword
                  description: >
                    If the data was discovered within a connection, the connection uid should go here to give context to the data. If the conn field is provided, this will be automatically filled out.
        
                - name: f
                  type: object
                  description: >
                    If the data was discovered within a file, the file record should go here to provide context to the data.
        
                - name: fuid
                  type: keyword
                  description: >
                    If the data was discovered within a file, the file uid should go here to provide context to the data. If the file record f is provided, this will be automatically filled out.
        
        
            - name: matched
              type: keyword
              description: >
                Event to represent a match in the intelligence data from data that was seen.
        
            - name: sources
              type: keyword
              description: >
                Sources which supplied data for this match.
        
            - name: fuid
              type: keyword
              description: >
                If a file was associated with this intelligence hit, this is the uid for the file.
        
            - name: file_mime_type
              type: keyword
              description: >
                A mime type if the intelligence hit is related to a file. If the $f field is provided this will be automatically filled out.
        
            - name: file_desc
              type: keyword
              description: >
                Frequently files can be described to give a bit more context. If the $f field is provided this field will be automatically filled out.
        - name: irc
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek IRC log
          fields:
            - name: nick
              type: keyword
              description: |
                Nickname given for the connection.
        
            - name: user
              type: keyword
              description: |
                Username given for the connection.
        
            - name: command
              type: keyword
              description: |
                Command given by the client.
        
            - name: value
              type: keyword
              description: |
                Value for the command given by the client.
        
            - name: addl
              type: keyword
              description: |
                Any additional data for the command.
        
            - name: dcc
              type: group
              fields:
                - name: file
                  type: group
                  fields:
                    - name: name
                      type: keyword
                      description: |
                        Present if base/protocols/irc/dcc-send.bro is loaded.
                        DCC filename requested.
        
                    - name: size
                      type: long
                      description: |
                        Present if base/protocols/irc/dcc-send.bro is loaded.
                        Size of the DCC transfer as indicated by the sender.
        
                - name: mime_type
                  type: keyword
                  description: |
                    present if base/protocols/irc/dcc-send.bro is loaded.
                    Sniffed mime type of the file.
        
            - name: fuid
              type: keyword
              description: |
                present if base/protocols/irc/files.bro is loaded.
                File unique ID.
        - name: kerberos
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek Kerberos log
          fields:
            - name: request_type
              type: keyword
              description: >
                Request type - Authentication Service (AS) or Ticket Granting Service (TGS).
        
            - name: client
              type: keyword
              description: >
                Client name.
        
            - name: service
              type: keyword
              description: >
                Service name.
        
            - name: success
              type: boolean
              description: >
                Request result.
        
            - name: error
              type: group
              fields:
                - name: code
                  type: integer
                  description: >
                    Error code.
        
                - name: msg
                  type: keyword
                  description: >
                    Error message.
        
            - name: valid
              type: group
              fields:
                - name: from
                  type: date
                  description: >
                    Ticket valid from.
        
                - name: until
                  type: date
                  description: >
                    Ticket valid until.
        
                - name: days
                  type: integer
                  description: >
                    Number of days the ticket is valid for.
        
            - name: cipher
              type: keyword
              description: >
                Ticket encryption type.
        
            - name: forwardable
              type: boolean
              description: >
                Forwardable ticket requested.
        
            - name: renewable
              type: boolean
              description: >
                Renewable ticket requested.
        
            - name: ticket
              type: group
              fields:
                - name: auth
                  type: keyword
                  description: >
                    Hash of ticket used to authorize request/transaction.
        
                - name: new
                  type: keyword
                  description: >
                    Hash of ticket returned by the KDC.
        
            - name: cert
              type: group
              fields:
                - name: client
                  type: group
                  fields:
                    - name: value
                      type: keyword
                      description: >
                        Client certificate.
        
                    - name: fuid
                      type: keyword
                      description: >
                        File unique ID of client cert.
        
                    - name: subject
                      type: keyword
                      description: >
                        Subject of client certificate.
        
                - name: server
                  type: group
                  fields:
                    - name: value
                      type: keyword
                      description: >
                        Server certificate.
        
                    - name: fuid
                      type: keyword
                      description: >
                        File unique ID of server certificate.
        
                    - name: subject
                      type: keyword
                      description: >
                        Subject of server certificate.
        - name: modbus
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek modbus log.
          fields:
            - name: function
              type: keyword
              description: |
                The name of the function message that was sent.
        
            - name: exception
              type: keyword
              description: |
                The exception if the response was a failure.
        
            - name: track_address
              type: integer
              description: |
                Present if policy/protocols/modbus/track-memmap.bro is loaded.
                Modbus track address.
        - name: mysql
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek MySQL log.
          fields:
            - name: cmd
              type: keyword
              description: |
                The command that was issued.
        
            - name: arg
              type: keyword
              description: |
                The argument issued to the command.
        
            - name: success
              type: boolean
              description: |
                Whether the command succeeded.
        
            - name: rows
              type: integer
              description: |
                The number of affected rows, if any.
        
            - name: response
              type: keyword
              description: |
                Server message, if any.
        - name: notice
          type: group
          description: >
            Fields exported by the Zeek Notice log.
          fields:
            - name: connection_id
              type: keyword
              description: >
                Identifier of the related connection session.
        
            - name: icmp_id
              type: keyword
              description: >
                Identifier of the related ICMP session.
        
            - name: file.id
              type: keyword
              description: >
                An identifier associated with a single file that is related to this notice.
        
            - name: file.parent_id
              type: keyword
              description: >
                Identifier associated with a container file from which this one was extracted.
        
            - name: file.source
              type: keyword
              description: |
                An identification of the source of the file data. E.g. it may be a network protocol
                over which it was transferred, or a local file path which was read, or some other
                input source.
        
            - name: file.mime_type
              type: keyword
              description: >
                A mime type if the notice is related to a file.
        
            - name: file.is_orig
              type: boolean
              description: |
                If the source of this file is a network connection, this field indicates if the file is
                being sent by the originator of the connection or the responder.
        
            - name: file.seen_bytes
              type: long
              description: >
                Number of bytes provided to the file analysis engine for the file.
        
            - name: ffile.total_bytes
              type: long
              description: >
                Total number of bytes that are supposed to comprise the full file.
        
            - name: file.missing_bytes
              type: long
              description: |
                The number of bytes in the file stream that were completely missed during the process
                of analysis.
        
            - name: file.overflow_bytes
              type: long
              description: |
                The number of bytes in the file stream that were not delivered to stream file analyzers.
                This could be overlapping bytes or bytes that couldn't be reassembled.
        
            - name: fuid
              type: keyword
              description: >
                A file unique ID if this notice is related to a file.
        
            - name: note
              type: keyword
              description: >
                The type of the notice.
        
            - name: msg
              type: keyword
              description: >
                The human readable message for the notice.
        
            - name: sub
              type: keyword
              description: >
                The human readable sub-message.
        
            - name: n
              type: long
              description: >
                Associated count, or a status code.
        
            - name: peer_name
              type: keyword
              description: >
                Name of remote peer that raised this notice.
        
            - name: peer_descr
              type: text
              description: >
                Textual description for the peer that raised this notice.
        
            - name: actions
              type: keyword
              description: >
                The actions which have been applied to this notice.
        
            - name: email_body_sections
              type: text
              description: |
                By adding chunks of text into this element, other scripts can expand on notices
                that are being emailed.
        
            - name: email_delay_tokens
              type: keyword
              description: |
                Adding a string token to this set will cause the built-in emailing functionality
                to delay sending the email either the token has been removed or the email
                has been delayed for the specified time duration.
        
            - name: identifier
              type: keyword
              description: >
                This field is provided when a notice is generated for the purpose of deduplicating notices.
        
            - name: suppress_for
              type: double
              description: >
                This field indicates the length of time that this unique notice should be suppressed.
        
            - name: dropped
              type: boolean
              description: >
                Indicate if the source IP address was dropped and denied network access.
        
        - name: ntlm
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek NTLM log.
          fields:
            - name: domain
              type: keyword
              description: >
                Domain name given by the client.
        
            - name: hostname
              type: keyword
              description: >
                Hostname given by the client.
        
            - name: success
              type: boolean
              description: >
                Indicate whether or not the authentication was successful.
        
            - name: username
              type: keyword
              description: >
                Username given by the client.
        
            - name: server
              type: group
              fields:
                - name: name
                  type: group
                  fields:
                    - name: dns
                      type: keyword
                      description: >
                        DNS name given by the server in a CHALLENGE.
        
                    - name: netbios
                      type: keyword
                      description: >
                        NetBIOS name given by the server in a CHALLENGE.
        
                    - name: tree
                      type: keyword
                      description: >
                        Tree name given by the server in a CHALLENGE.
        - name: ocsp
          type: group
          default_field: false
          description: |
            Fields exported by the Zeek OCSP log
            Online Certificate Status Protocol (OCSP). Only created if policy script is loaded.
          fields:
            - name: file_id
              type: keyword
              description: |
                File id of the OCSP reply.
            - name: hash
              type: group
              fields:
                - name: algorithm
                  type: keyword
                  description: |
                    Hash algorithm used to generate issuerNameHash and issuerKeyHash.
        
                - name: issuer
                  type: group
                  fields:
                    - name: name
                      type: keyword
                      description: |
                        Hash of the issuer's distingueshed name.
        
                    - name: key
                      type: keyword
                      description: |
                        Hash of the issuer's public key.
        
            - name: serial_number
              type: keyword
              description: |
                Serial number of the affected certificate.
        
            - name: status
              type: keyword
              description: |
                Status of the affected certificate.
        
            - name: revoke
              type: group
              fields:
                - name: time
                  type: date
                  description: |
                    Time at which the certificate was revoked.
        
                - name: reason
                  type: keyword
                  description: |
                    Reason for which the certificate was revoked.
        
            - name: update
              type: group
              fields:
                - name: this
                  type: date
                  description: |
                    The time at which the status being shows is known to have been correct.
        
                - name: next
                  type: date
                  description: |
                    The latest time at which new information about the status of the certificate will be available.
        
        - name: pe
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek pe log.
          fields:
            - name: client
              type: keyword
              description: >
                The client's version string.
        
            - name: id
              type: keyword
              description: >
                File id of this portable executable file.
        
            - name: machine
              type: keyword
              description: >
                The target machine that the file was compiled for.
        
            - name: compile_time
              type: date
              description: >
                The time that the file was created at.
        
            - name: os
              type: keyword
              description: >
                The required operating system.
        
            - name: subsystem
              type: keyword
              description: >
                The subsystem that is required to run this file.
        
            - name: is_exe
              type: boolean
              description: >
                Is the file an executable, or just an object file?
        
            - name: is_64bit
              type: boolean
              description: >
                Is the file a 64-bit executable?
        
            - name: uses_aslr
              type: boolean
              description: >
                Does the file support Address Space Layout Randomization?
        
            - name: uses_dep
              type: boolean
              description: >
                Does the file support Data Execution Prevention?
        
            - name: uses_code_integrity
              type: boolean
              description: >
                Does the file enforce code integrity checks?
        
            - name: uses_seh
              type: boolean
              description: >
                Does the file use structured exception handing?
        
            - name: has_import_table
              type: boolean
              description: >
                Does the file have an import table?
        
            - name: has_export_table
              type: boolean
              description: >
                Does the file have an export table?
        
            - name: has_cert_table
              type: boolean
              description: >
                Does the file have an attribute certificate table?
        
            - name: has_debug_data
              type: boolean
              description: >
                Does the file have a debug table?
        
            - name: section_names
              type: keyword
              description: >
                The names of the sections, in order.
        
        - name: radius
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek Radius log.
          fields:
            - name: username
              type: keyword
              description: |
                The username, if present.
        
            - name: mac
              type: keyword
              description: |
                MAC address, if present.
        
            - name: framed_addr
              type: ip
              description: |
                The address given to the network access server, if present. This is only a hint from the RADIUS server and the network access server is not required to honor the address.
        
            - name: remote_ip
              type: ip
              description: |
                Remote IP address, if present. This is collected from the Tunnel-Client-Endpoint attribute.
        
            - name: connect_info
              type: keyword
              description: |
                Connect info, if present.
        
            - name: reply_msg
              type: keyword
              description: |
                Reply message from the server challenge. This is frequently shown to the user authenticating.
        
            - name: result
              type: keyword
              description: |
                Successful or failed authentication.
        
            - name: ttl
              type: integer
              description: |
                The duration between the first request and either the "Access-Accept" message or an error. If the field is empty, it means that either the request or response was not seen.
        
            - name: logged
              type: boolean
              description: |
                Whether this has already been logged and can be ignored.
        - name: rdp
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek RDP log.
          fields:
            - name: cookie
              type: keyword
              description: |
                Cookie value used by the client machine. This is typically a username.
        
            - name: result
              type: keyword
              description: |
                Status result for the connection. It's a mix between RDP negotation failure messages and GCC server create response messages.
        
            - name: security_protocol
              type: keyword
              description: |
                Security protocol chosen by the server.
        
            - name: keyboard_layout
              type: keyword
              description: |
                Keyboard layout (language) of the client machine.
        
            - name: client
              type: group
              fields:
                - name: build
                  type: keyword
                  description: |
                    RDP client version used by the client machine.
        
                - name: client_name
                  type: keyword
                  description: |
                    Name of the client machine.
        
                - name: product_id
                  type: keyword
                  description: |
                    Product ID of the client machine.
        
            - name: desktop
              type: group
              fields:
                - name: width
                  type: integer
                  description: |
                    Desktop width of the client machine.
        
                - name: height
                  type: integer
                  description: |
                    Desktop height of the client machine.
        
                - name: color_depth
                  type: keyword
                  description: |
                    The color depth requested by the client in the high_color_depth field.
        
            - name: cert
              type: group
              fields:
                - name: type
                  type: keyword
                  description: |
                    If the connection is being encrypted with native RDP encryption, this is the type of cert being used.
        
                - name: count
                  type: integer
                  description: |
                    The number of certs seen. X.509 can transfer an entire certificate chain.
        
                - name: permanent
                  type: boolean
                  description: |
                    Indicates if the provided certificate or certificate chain is permanent or temporary.
        
            - name: encryption
              type: group
              fields:
                - name: level
                  type: keyword
                  description: |
                    Encryption level of the connection.
        
                - name: method
                  type: keyword
                  description: |
                    Encryption method of the connection.
        
            - name: done
              type: boolean
              description: |
                Track status of logging RDP connections.
        
            - name: ssl
              type: boolean
              description: |
                (present if policy/protocols/rdp/indicate_ssl.bro is loaded)
                Flag the connection if it was seen over SSL.
        - name: rfb
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek RFB log.
          fields:
            - name: version
              type: group
              fields:
                - name: client
                  type: group
                  fields:
                    - name: major
                      type: keyword
                      description: |
                        Major version of the client.
        
                    - name: minor
                      type: keyword
                      description: |
                        Minor version of the client.
        
                - name: server
                  type: group
                  fields:
                    - name: major
                      type: keyword
                      description: |
                        Major version of the server.
        
                    - name: minor
                      type: keyword
                      description: |
                        Minor version of the server.
        
            - name: auth
              type: group
              fields:
                - name: success
                  type: boolean
                  description: |
                    Whether or not authentication was successful.
        
                - name: method
                  type: keyword
                  description: |
                    Identifier of authentication method used.
        
            - name: share_flag
              type: boolean
              description: |
                Whether the client has an exclusive or a shared session.
        
            - name: desktop_name
              type: keyword
              description: |
                Name of the screen that is being shared.
        
            - name: width
              type: integer
              description: |
                Width of the screen that is being shared.
        
            - name: height
              type: integer
              description: |
                Height of the screen that is being shared.
        - name: sip
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SIP log.
          fields:
            - name: transaction_depth
              type: integer
              description: >
                Represents the pipelined depth into the connection of this request/response transaction.
        
            - name: sequence
              type: group
              fields:
                - name: method
                  type: keyword
                  description: >
                    Verb used in the SIP request (INVITE, REGISTER etc.).
        
                - name: number
                  type: keyword
                  description: >
                    Contents of the CSeq: header from the client.
        
            - name: uri
              type: keyword
              description: >
                URI used in the request.
        
            - name: date
              type: keyword
              description: >
                Contents of the Date: header from the client.
        
            - name: request
              type: group
              fields:
                - name: from
                  type: keyword
                  description: >
                    Contents of the request From: header Note: The tag= value that's usually appended to the sender is stripped off and not logged.
        
                - name: to
                  type: keyword
                  description: >
                    Contents of the To: header.
        
                - name: path
                  type: keyword
                  description: >
                    The client message transmission path, as extracted from the headers.
        
                - name: body_length
                  type: long
                  description: >
                    Contents of the Content-Length: header from the client.
        
            - name: response
              type: group
              fields:
                - name: from
                  type: keyword
                  description: >
                    Contents of the response From: header Note: The tag= value that's usually appended to the sender is stripped off and not logged.
        
                - name: to
                  type: keyword
                  description: >
                    Contents of the response To: header.
        
                - name: path
                  type: keyword
                  description: >
                    The server message transmission path, as extracted from the headers.
        
                - name: body_length
                  type: long
                  description: >
                    Contents of the Content-Length: header from the server.
        
            - name: reply_to
              type: keyword
              description: >
                Contents of the Reply-To: header.
        
            - name: call_id
              type: keyword
              description: >
                Contents of the Call-ID: header from the client.
        
            - name: subject
              type: keyword
              description: >
                Contents of the Subject: header from the client.
        
            - name: user_agent
              type: keyword
              description: >
                Contents of the User-Agent: header from the client.
        
            - name: status
              type: group
              fields:
                - name: code
                  type: integer
                  description: >
                    Status code returned by the server.
        
                - name: msg
                  type: keyword
                  description: >
                    Status message returned by the server.
        
            - name: warning
              type: keyword
              description: >
                Contents of the Warning: header.
        
            - name: content_type
              type: keyword
              description: >
                Contents of the Content-Type: header from the server.
        - name: smb_cmd
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek smb_cmd log.
          fields:
            - name: command
              type: keyword
              description: |
                The command sent by the client.
        
            - name: sub_command
              type: keyword
              description: |
                The subcommand sent by the client, if present.
        
            - name: argument
              type: keyword
              description: |
                Command argument sent by the client, if any.
        
            - name: status
              type: keyword
              description: |
                Server reply to the client's command.
        
            - name: rtt
              type: double
              description: |
                Round trip time from the request to the response.
        
            - name: version
              type: keyword
              description: |
                Version of SMB for the command.
        
            - name: username
              type: keyword
              description: |
                Authenticated username, if available.
        
            - name: tree
              type: keyword
              description: |
                If this is related to a tree, this is the tree that was used for the current command.
        
            - name: tree_service
              type: keyword
              description: |
                The type of tree (disk share, printer share, named pipe, etc.).
        
            - name: file
              type: group
              description: |
                If the command referenced a file, store it here.
              fields:
                - name: name
                  type: keyword
                  description: |
                    Filename if one was seen.
        
                - name: action
                  type: keyword
                  description: |
                    Action this log record represents.
        
                - name: uid
                  type: keyword
                  description: |
                    UID of the referenced file.
        
                - name: host
                  type: group
                  fields:
                    - name: tx
                      type: ip
                      description: |
                        Address of the transmitting host.
        
                    - name: rx
                      type: ip
                      description: |
                        Address of the receiving host.
        
            - name: smb1_offered_dialects
              type: keyword
              description: |
                Present if base/protocols/smb/smb1-main.bro is loaded.
                Dialects offered by the client.
        
            - name: smb2_offered_dialects
              type:  integer
              description: |
                Present if base/protocols/smb/smb2-main.bro is loaded.
                Dialects offered by the client.
        - name: smb_files
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SMB Files log.
          fields:
            - name: action
              type: keyword
              description: >
                Action this log record represents.
        
            - name: fid
              type: integer
              description: >
                ID referencing this file.
        
            - name: name
              type: keyword
              description: >
                Filename if one was seen.
        
            - name: path
              type: keyword
              description: >
                Path pulled from the tree this file was transferred to or from.
        
            - name: previous_name
              type: keyword
              description: >
                If the rename action was seen, this will be the file's previous name.
        
            - name: size
              type: long
              description: >
                Byte size of the file.
        
            - name: times
              type: group
              description: >
                Timestamps of the file.
              fields:
                - name: accessed
                  type: date
                  description: >
                    The file's access time.
        
                - name: changed
                  type: date
                  description: >
                    The file's change time.
        
                - name: created
                  type: date
                  description: >
                    The file's create time.
        
                - name: modified
                  type: date
                  description: >
                    The file's modify time.
        
            - name: uuid
              type: keyword
              description: >
                UUID referencing this file if DCE/RPC.
        - name: smb_mapping
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SMB_Mapping log.
          fields:
            - name: path
              type: keyword
              description: >
                Name of the tree path.
        
            - name: service
              type: keyword
              description: >
                The type of resource of the tree (disk share, printer share, named pipe, etc.).
        
            - name: native_file_system
              type: keyword
              description: >
                File system of the tree.
        
            - name: share_type
              type: keyword
              description: |
                If this is SMB2, a share type will be included. For SMB1, the type of share
                will be deduced and included as well.
        - name: smtp
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SMTP log.
          fields:
            - name: transaction_depth
              type: integer
              description: >
                A count to represent the depth of this message transaction in a single connection where multiple messages were transferred.
        
            - name: helo
              type: keyword
              description: >
                Contents of the Helo header.
        
            - name: mail_from
              type: keyword
              description: >
                Email addresses found in the MAIL FROM header.
        
            - name: rcpt_to
              type: keyword
              description: >
                Email addresses found in the RCPT TO header.
        
            - name: date
              type: date
              description: >
                Contents of the Date header.
        
            - name: from
              type: keyword
              description: >
                Contents of the From header.
        
            - name: to
              type: keyword
              description: >
                Contents of the To header.
        
            - name: cc
              type: keyword
              description: >
                Contents of the CC header.
        
            - name: reply_to
              type: keyword
              description: >
                Contents of the ReplyTo header.
        
            - name: msg_id
              type: keyword
              description: >
                Contents of the MsgID header.
        
            - name: in_reply_to
              type: keyword
              description: >
                Contents of the In-Reply-To header.
        
            - name: subject
              type: keyword
              description: >
                Contents of the Subject header.
        
            - name: x_originating_ip
              type: keyword
              description: >
                Contents of the X-Originating-IP header.
        
            - name: first_received
              type: keyword
              description: |
                Contents of the first Received header.
        
            - name: second_received
              type: keyword
              description: |
                Contents of the second Received header.
        
            - name: last_reply
              type: keyword
              description: |
                The last message that the server sent to the client.
        
            - name: path
              type: ip
              description: |
                The message transmission path, as extracted from the headers.
        
            - name: user_agent
              type: keyword
              description: |
                Value of the User-Agent header from the client.
        
            - name: tls
              type: boolean
              description: |
                Indicates that the connection has switched to using TLS.
        
            - name: process_received_from
              type: boolean
              description: |
                Indicates if the "Received: from" headers should still be processed.
        
            - name: has_client_activity
              type: boolean
              description: |
                Indicates if client activity has been seen, but not yet logged.
        
            - name: fuids
              type: keyword
              description: |
                (present if base/protocols/smtp/files.bro is loaded)
                An ordered vector of file unique IDs seen attached to the message.
        
            - name: is_webmail
              type: boolean
              description: |
                Indicates if the message was sent through a webmail interface.
        - name: snmp
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SNMP log.
          fields:
            - name: duration
              type: double
              description: >
                The amount of time between the first packet beloning to the SNMP session and the latest one seen.
        
            - name: version
              type: keyword
              description: >
                The version of SNMP being used.
        
            - name: community
              type: keyword
              description: >
                The community string of the first SNMP packet associated with the session. This is used as part of SNMP's (v1 and v2c) administrative/security framework. See RFC 1157 or RFC 1901.
        
            - name: get
              type: group
              fields:
                - name: requests
                  type: integer
                  description: >
                    The number of variable bindings in GetRequest/GetNextRequest PDUs seen for the session.
        
                - name: bulk_requests
                  type: integer
                  description: >
                    The number of variable bindings in GetBulkRequest PDUs seen for the session.
        
                - name: responses
                  type: integer
                  description: >
                    The number of variable bindings in GetResponse/Response PDUs seen for the session.
        
            - name: set
              type: group
              fields:
                - name: requests
                  type: integer
                  description: >
                    The number of variable bindings in SetRequest PDUs seen for the session.
        
            - name: display_string
              type: keyword
              description: >
                A system description of the SNMP responder endpoint.
        
            - name: up_since
              type: date
              description: >
                The time at which the SNMP responder endpoint claims it's been up since.
        - name: socks
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SOCKS log.
          fields:
            - name: version
              type: integer
              description: |
                Protocol version of SOCKS.
        
            - name: user
              type: keyword
              description: |
                Username used to request a login to the proxy.
        
            - name: password
              type: keyword
              description: |
                Password used to request a login to the proxy.
        
            - name: status
              type: keyword
              description: |
                Server status for the attempt at using the proxy.
        
            - name: request
              type: group
              fields:
                - name: host
                  type: keyword
                  description: |
                    Client requested SOCKS address. Could be an address, a name or both.
        
                - name: port
                  type: integer
                  description: |
                    Client requested port.
        
            - name: bound
              type: group
              fields:
                - name: host
                  type: keyword
                  description: |
                    Server bound address. Could be an address, a name or both.
        
                - name: port
                  type: integer
                  description: |
                    Server bound port.
        
            - name: capture_password
              type: boolean
              description: |
                Determines if the password will be captured for this request.
        - name: ssh
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SSH log.
          fields:
            - name: client
              type: keyword
              description: >
                The client's version string.
        
            - name: direction
              type: keyword
              description: |
                Direction of the connection. If the client was a local host logging into
                an external host, this would be OUTBOUND. INBOUND would be set for the
                opposite situation.
        
            - name: host_key
              type: keyword
              description: >
                The server's key thumbprint.
        
            - name: server
              type: keyword
              description: >
                The server's version string.
        
            - name: version
              type: integer
              description: >
                SSH major version (1 or 2).
        
            - name: algorithm
              type: group
              description: >
                Cipher algorithms used in this session.
              fields:
                - name: cipher
                  type: keyword
                  description: >
                    The encryption algorithm in use.
        
                - name: compression
                  type: keyword
                  description: >
                    The compression algorithm in use.
        
                - name: host_key
                  type: keyword
                  description: >
                    The server host key's algorithm.
        
                - name: key_exchange
                  type: keyword
                  description: >
                    The key exchange algorithm in use.
        
                - name: mac
                  type: keyword
                  description: >
                    The signing (MAC) algorithm in use.
        
            - name: auth
              type: group
              fields:
                - name: attempts
                  type: integer
                  description: |
                    The number of authentication attemps we observed. There's always at
                    least one, since some servers might support no authentication at all.
                    It's important to note that not all of these are failures, since some
                    servers require two-factor auth (e.g. password AND pubkey).
        
                - name: success
                  type: boolean
                  description: >
                    Authentication result.
        - name: ssl
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SSL log.
          fields:
            - name: version
              type: keyword
              description: >
                SSL/TLS version that was logged.
        
            - name: cipher
              type: keyword
              description: >
                SSL/TLS cipher suite that was logged.
        
            - name: curve
              type: keyword
              description: >
                Elliptic curve that was logged when using ECDH/ECDHE.
        
            - name: resumed
              type: boolean
              description: |
                Flag to indicate if the session was resumed reusing the key material exchanged in an
                earlier connection.
        
            - name: next_protocol
              type: keyword
              description: >
                Next protocol the server chose using the application layer next protocol extension.
        
            - name: established
              type: boolean
              description: >
                Flag to indicate if this ssl session has been established successfully.
        
            - name: validation
              type: group
              fields:
                - name: status
                  type: keyword
                  description: >
                    Result of certificate validation for this connection.
        
                - name: code
                  type: keyword
                  description: >
                    Result of certificate validation for this connection, given as OpenSSL validation code.
        
            - name: last_alert
              type: keyword
              description: >
                Last alert that was seen during the connection.
        
            - name: server
              type: group
              fields:
                - name: name
                  type: keyword
                  description: |
                    Value of the Server Name Indicator SSL/TLS extension. It indicates the server name
                    that the client was requesting.
        
                - name: cert_chain
                  type: keyword
                  description: >
                    Chain of certificates offered by the server to validate its complete signing chain.
        
                - name: cert_chain_fuids
                  type: keyword
                  description: >
                    An ordered vector of certificate file identifiers for the certificates offered by the server.
        
                - name: issuer
                  type: group
                  description: >
                    Subject of the signer of the X.509 certificate offered by the server.
                  fields:
                    - name: common_name
                      type: keyword
                      description: >
                        Common name of the signer of the X.509 certificate offered by the server.
        
                    - name: country
                      type: keyword
                      description: >
                        Country code of the signer of the X.509 certificate offered by the server.
        
                    - name: locality
                      type: keyword
                      description: >
                        Locality of the signer of the X.509 certificate offered by the server.
        
                    - name: organization
                      type: keyword
                      description: >
                        Organization of the signer of the X.509 certificate offered by the server.
        
                    - name: organizational_unit
                      type: keyword
                      description: >
                        Organizational unit of the signer of the X.509 certificate offered by the server.
        
                    - name: state
                      type: keyword
                      description: >
                        State or province name of the signer of the X.509 certificate offered by the server.
        
                - name: subject
                  type: group
                  description: >
                    Subject of the X.509 certificate offered by the server.
                  fields:
                    - name: common_name
                      type: keyword
                      description: >
                        Common name of the X.509 certificate offered by the server.
        
                    - name: country
                      type: keyword
                      description: >
                        Country code of the X.509 certificate offered by the server.
        
                    - name: locality
                      type: keyword
                      description: >
                        Locality of the X.509 certificate offered by the server.
        
                    - name: organization
                      type: keyword
                      description: >
                        Organization of the X.509 certificate offered by the server.
        
                    - name: organizational_unit
                      type: keyword
                      description: >
                        Organizational unit of the X.509 certificate offered by the server.
        
                    - name: state
                      type: keyword
                      description: >
                        State or province name of the X.509 certificate offered by the server.
        
            - name: client
              type: group
              fields:
                - name: cert_chain
                  type: keyword
                  description: >
                    Chain of certificates offered by the client to validate its complete signing chain.
        
                - name: cert_chain_fuids
                  type: keyword
                  description: >
                    An ordered vector of certificate file identifiers for the certificates offered by the client.
        
                - name: issuer
                  type: group
                  description: >
                    Subject of the signer of the X.509 certificate offered by the client.
                  fields:
                    - name: common_name
                      type: keyword
                      description: >
                        Common name of the signer of the X.509 certificate offered by the client.
        
                    - name: country
                      type: keyword
                      description: >
                        Country code of the signer of the X.509 certificate offered by the client.
        
                    - name: locality
                      type: keyword
                      description: >
                        Locality of the signer of the X.509 certificate offered by the client.
        
                    - name: organization
                      type: keyword
                      description: >
                        Organization of the signer of the X.509 certificate offered by the client.
        
                    - name: organizational_unit
                      type: keyword
                      description: >
                        Organizational unit of the signer of the X.509 certificate offered by the client.
        
                    - name: state
                      type: keyword
                      description: >
                        State or province name of the signer of the X.509 certificate offered by the client.
        
                - name: subject
                  type: group
                  description: >
                    Subject of the X.509 certificate offered by the client.
                  fields:
                    - name: common_name
                      type: keyword
                      description: >
                        Common name of the X.509 certificate offered by the client.
        
                    - name: country
                      type: keyword
                      description: >
                        Country code of the X.509 certificate offered by the client.
        
                    - name: locality
                      type: keyword
                      description: >
                        Locality of the X.509 certificate offered by the client.
        
                    - name: organization
                      type: keyword
                      description: >
                        Organization of the X.509 certificate offered by the client.
        
                    - name: organizational_unit
                      type: keyword
                      description: >
                        Organizational unit of the X.509 certificate offered by the client.
        
                    - name: state
                      type: keyword
                      description: >
                        State or province name of the X.509 certificate offered by the client.
        - name: stats
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek stats log.
          fields:
            - name: peer
              type: keyword
              description: |
                Peer that generated this log. Mostly for clusters.
        
            - name: memory
              type: integer
              description: |
                Amount of memory currently in use in MB.
        
            - name: packets
              type: group
              fields:
                - name: processed
                  type: long
                  description: |
                    Number of packets processed since the last stats interval.
        
                - name: dropped
                  type: long
                  description: |
                    Number of packets dropped since the last stats interval if reading live traffic.
        
                - name: received
                  type: long
                  description: |
                    Number of packets seen on the link since the last stats interval if reading live traffic.
        
            - name: bytes
              type: group
              fields:
                - name: received
                  type: long
                  description: |
                    Number of bytes received since the last stats interval if reading live traffic.
        
            - name: connections
              type: group
              fields:
                - name: tcp
                  type: group
                  fields:
                    - name: active
                      type: integer
                      description: |
                        TCP connections currently in memory.
        
                    - name: count
                      type: integer
                      description: |
                        TCP connections seen since last stats interval.
        
                - name: udp
                  type: group
                  fields:
                    - name: active
                      type: integer
                      description: |
                        UDP connections currently in memory.
        
                    - name: count
                      type: integer
                      description: |
                        UDP connections seen since last stats interval.
        
                - name: icmp
                  type: group
                  fields:
                    - name: active
                      type: integer
                      description: |
                        ICMP connections currently in memory.
        
                    - name: count
                      type: integer
                      description: |
                        ICMP connections seen since last stats interval.
        
            - name: events
              type: group
              fields:
                - name: processed
                  type: integer
                  description: |
                    Number of events processed since the last stats interval.
        
                - name: queued
                  type: integer
                  description: |
                    Number of events that have been queued since the last stats interval.
        
            - name: timers
              type: group
              fields:
                - name: count
                  type: integer
                  description: |
                    Number of timers scheduled since last stats interval.
        
                - name: active
                  type: integer
                  description: |
                    Current number of scheduled timers.
        
            - name: files
              type: group
              fields:
                - name: count
                  type: integer
                  description: |
                    Number of files seen since last stats interval.
        
                - name: active
                  type: integer
                  description: |
                    Current number of files actively being seen.
        
            - name: dns_requests
              type: group
              fields:
                - name: count
                  type: integer
                  description: |
                    Number of DNS requests seen since last stats interval.
        
                - name: active
                  type: integer
                  description: |
                    Current number of DNS requests awaiting a reply.
        
            - name: reassembly_size
              type: group
              fields:
                - name: tcp
                  type: integer
                  description: |
                    Current size of TCP data in reassembly.
        
                - name: file
                  type: integer
                  description: |
                    Current size of File data in reassembly.
        
                - name: frag
                  type: integer
                  description: |
                    Current size of packet fragment data in reassembly.
        
                - name: unknown
                  type: integer
                  description: |
                    Current size of unknown data in reassembly (this is only PIA buffer right now).
        
            - name: timestamp_lag
              type: integer
              description: |
                Lag between the wall clock and packet timestamps if reading live traffic.
        - name: syslog
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek syslog log.
          fields:
            - name: facility
              type: keyword
              description: >
                Syslog facility for the message.
        
            - name: severity
              type: keyword
              description: >
                Syslog severity for the message.
        
            - name: message
              type: keyword
              description: >
                The plain text message.
        - name: tunnel
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek SSH log.
          fields:
            - name: type
              type: keyword
              description: >
                The type of tunnel.
        
            - name: action
              type: keyword
              description: >
                The type of activity that occurred.
        - name: weird
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek Weird log.
          fields:
            - name: name
              type: keyword
              description: |
                The name of the weird that occurred.
        
            - name: additional_info
              type: keyword
              description: |
                Additional information accompanying the weird if any.
        
            - name: notice
              type: boolean
              description: |
                Indicate if this weird was also turned into a notice.
        
            - name: peer
              type: keyword
              description: |
                The peer that originated this weird. This is helpful in cluster deployments if a particular cluster node is having trouble to help identify which node is having trouble.
        
            - name: identifier
              type: keyword
              description: |
                This field is to be provided when a weird is generated for the purpose of deduplicating weirds. The identifier string should be unique for a single instance of the weird. This field is used to define when a weird is conceptually a duplicate of a previous weird.
        - name: x509
          type: group
          default_field: false
          description: >
            Fields exported by the Zeek x509 log.
          fields:
            - name: id
              type: keyword
              description: >
                File id of this certificate.
        
            - name: certificate
              type: group
              description: >
                Basic information about the certificate.
              fields:
                - name: version
                  type: integer
                  description: >
                    Version number.
        
                - name: serial
                  type: keyword
                  description: >
                    Serial number.
        
                - name: subject
                  type: group
                  description: >
                    Subject.
                  fields:
                    - name: country
                      type: keyword
                      description: >
                        Country provided in the certificate subject.
        
                    - name: common_name
                      type: keyword
                      description: >
                        Common name provided in the certificate subject.
        
                    - name: locality
                      type: keyword
                      description: >
                        Locality provided in the certificate subject.
        
                    - name: organization
                      type: keyword
                      description: >
                        Organization provided in the certificate subject.
        
                    - name: organizational_unit
                      type: keyword
                      description: >
                        Organizational unit provided in the certificate subject.
        
                    - name: state
                      type: keyword
                      description: >
                        State or province provided in the certificate subject.
        
                - name: issuer
                  type: group
                  description: >
                    Issuer.
                  fields:
                    - name: country
                      type: keyword
                      description: >
                        Country provided in the certificate issuer field.
        
                    - name: common_name
                      type: keyword
                      description: >
                        Common name provided in the certificate issuer field.
        
                    - name: locality
                      type: keyword
                      description: >
                        Locality provided in the certificate issuer field.
        
                    - name: organization
                      type: keyword
                      description: >
                        Organization provided in the certificate issuer field.
        
                    - name: organizational_unit
                      type: keyword
                      description: >
                        Organizational unit provided in the certificate issuer field.
        
                    - name: state
                      type: keyword
                      description: >
                        State or province provided in the certificate issuer field.
        
                - name: common_name
                  type: keyword
                  description: >
                    Last (most specific) common name.
        
                - name: valid
                  type: group
                  description: >
                    Certificate validity timestamps
                  fields:
                    - name: from
                      type: date
                      description: >
                        Timestamp before when certificate is not valid.
        
                    - name: until
                      type: date
                      description: >
                        Timestamp after when certificate is not valid.
        
                - name: key
                  type: group
                  fields:
                    - name: algorithm
                      type: keyword
                      description: >
                        Name of the key algorithm.
        
                    - name: type
                      type: keyword
                      description: >
                        Key type, if key parseable by openssl (either rsa, dsa or ec).
        
                    - name: length
                      type: integer
                      description: >
                        Key length in bits.
        
                - name: signature_algorithm
                  type: keyword
                  description: >
                    Name of the signature algorithm.
        
                - name: exponent
                  type: keyword
                  description: >
                    Exponent, if RSA-certificate.
        
                - name: curve
                  type: keyword
                  description: >
                    Curve, if EC-certificate.
        
            - name: san
              type: group
              description: >
                Subject alternative name extension of the certificate.
              fields:
                - name: dns
                  type: keyword
                  description: >
                    List of DNS entries in SAN.
        
                - name: uri
                  type: keyword
                  description: >
                    List of URI entries in SAN.
        
                - name: email
                  type: keyword
                  description: >
                    List of email entries in SAN.
        
                - name: ip
                  type: ip
                  description: >
                    List of IP entries in SAN.
        
                - name: other_fields
                  type: boolean
                  description: >
                    True if the certificate contained other, not recognized or parsed name fields.
        
            - name: basic_constraints
              type: group
              description: >
                Basic constraints extension of the certificate.
              fields:
                - name: certificate_authority
                  type: boolean
                  description: >
                    CA flag set or not.
        
                - name: path_length
                  type: integer
                  description: >
                    Maximum path length.
        
            - name: log_cert
              type: boolean
              description: |
                Present if policy/protocols/ssl/log-hostcerts-only.bro is loaded
                Logging of certificate is suppressed if set to F.
- key: netflow
  title: "NetFlow"
  description: >
    Fields from NetFlow and IPFIX flows.
  fields:
    - name: netflow
      type: group
      description: >
        Fields from NetFlow and IPFIX.
      fields:
        - name: type
          type: keyword
          description: >
            The type of NetFlow record described by this event.

        - name: exporter
          type: group
          description: >
            Metadata related to the exporter device that generated this record.
          fields:
            - name: address
              type: keyword
              description: >
                Exporter's network address in IP:port format.

            - name: source_id
              type: long
              description: >
                Observation domain ID to which this record belongs.

            - name: timestamp
              type: date
              description: >
                Time and date of export.

            - name: uptime_millis
              type: long
              description: >
                How long the exporter process has been running, in milliseconds.

            - name: version
              type: integer
              description: >
                NetFlow version used.

        - name: octet_delta_count
          type: long

        - name: packet_delta_count
          type: long

        - name: delta_flow_count
          type: long

        - name: protocol_identifier
          type: short

        - name: ip_class_of_service
          type: short

        - name: tcp_control_bits
          type: integer

        - name: source_transport_port
          type: integer

        - name: source_ipv4_address
          type: ip

        - name: source_ipv4_prefix_length
          type: short

        - name: ingress_interface
          type: long

        - name: destination_transport_port
          type: integer

        - name: destination_ipv4_address
          type: ip

        - name: destination_ipv4_prefix_length
          type: short

        - name: egress_interface
          type: long

        - name: ip_next_hop_ipv4_address
          type: ip

        - name: bgp_source_as_number
          type: long

        - name: bgp_destination_as_number
          type: long

        - name: bgp_next_hop_ipv4_address
          type: ip

        - name: post_mcast_packet_delta_count
          type: long

        - name: post_mcast_octet_delta_count
          type: long

        - name: flow_end_sys_up_time
          type: long

        - name: flow_start_sys_up_time
          type: long

        - name: post_octet_delta_count
          type: long

        - name: post_packet_delta_count
          type: long

        - name: minimum_ip_total_length
          type: long

        - name: maximum_ip_total_length
          type: long

        - name: source_ipv6_address
          type: ip

        - name: destination_ipv6_address
          type: ip

        - name: source_ipv6_prefix_length
          type: short

        - name: destination_ipv6_prefix_length
          type: short

        - name: flow_label_ipv6
          type: long

        - name: icmp_type_code_ipv4
          type: integer

        - name: igmp_type
          type: short

        - name: sampling_interval
          type: long

        - name: sampling_algorithm
          type: short

        - name: flow_active_timeout
          type: integer

        - name: flow_idle_timeout
          type: integer

        - name: engine_type
          type: short

        - name: engine_id
          type: short

        - name: exported_octet_total_count
          type: long

        - name: exported_message_total_count
          type: long

        - name: exported_flow_record_total_count
          type: long

        - name: ipv4_router_sc
          type: ip

        - name: source_ipv4_prefix
          type: ip

        - name: destination_ipv4_prefix
          type: ip

        - name: mpls_top_label_type
          type: short

        - name: mpls_top_label_ipv4_address
          type: ip

        - name: sampler_id
          type: short

        - name: sampler_mode
          type: short

        - name: sampler_random_interval
          type: long

        - name: class_id
          type: long

        - name: minimum_ttl
          type: short

        - name: maximum_ttl
          type: short

        - name: fragment_identification
          type: long

        - name: post_ip_class_of_service
          type: short

        - name: source_mac_address
          type: keyword

        - name: post_destination_mac_address
          type: keyword

        - name: vlan_id
          type: integer

        - name: post_vlan_id
          type: integer

        - name: ip_version
          type: short

        - name: flow_direction
          type: short

        - name: ip_next_hop_ipv6_address
          type: ip

        - name: bgp_next_hop_ipv6_address
          type: ip

        - name: ipv6_extension_headers
          type: long

        - name: mpls_top_label_stack_section
          type: short

        - name: mpls_label_stack_section2
          type: short

        - name: mpls_label_stack_section3
          type: short

        - name: mpls_label_stack_section4
          type: short

        - name: mpls_label_stack_section5
          type: short

        - name: mpls_label_stack_section6
          type: short

        - name: mpls_label_stack_section7
          type: short

        - name: mpls_label_stack_section8
          type: short

        - name: mpls_label_stack_section9
          type: short

        - name: mpls_label_stack_section10
          type: short

        - name: destination_mac_address
          type: keyword

        - name: post_source_mac_address
          type: keyword

        - name: interface_name
          type: keyword

        - name: interface_description
          type: keyword

        - name: sampler_name
          type: keyword

        - name: octet_total_count
          type: long

        - name: packet_total_count
          type: long

        - name: flags_and_sampler_id
          type: long

        - name: fragment_offset
          type: integer

        - name: forwarding_status
          type: short

        - name: mpls_vpn_route_distinguisher
          type: short

        - name: mpls_top_label_prefix_length
          type: short

        - name: src_traffic_index
          type: long

        - name: dst_traffic_index
          type: long

        - name: application_description
          type: keyword

        - name: application_id
          type: short

        - name: application_name
          type: keyword

        - name: post_ip_diff_serv_code_point
          type: short

        - name: multicast_replication_factor
          type: long

        - name: class_name
          type: keyword

        - name: classification_engine_id
          type: short

        - name: layer2packet_section_offset
          type: integer

        - name: layer2packet_section_size
          type: integer

        - name: layer2packet_section_data
          type: short

        - name: bgp_next_adjacent_as_number
          type: long

        - name: bgp_prev_adjacent_as_number
          type: long

        - name: exporter_ipv4_address
          type: ip

        - name: exporter_ipv6_address
          type: ip

        - name: dropped_octet_delta_count
          type: long

        - name: dropped_packet_delta_count
          type: long

        - name: dropped_octet_total_count
          type: long

        - name: dropped_packet_total_count
          type: long

        - name: flow_end_reason
          type: short

        - name: common_properties_id
          type: long

        - name: observation_point_id
          type: long

        - name: icmp_type_code_ipv6
          type: integer

        - name: mpls_top_label_ipv6_address
          type: ip

        - name: line_card_id
          type: long

        - name: port_id
          type: long

        - name: metering_process_id
          type: long

        - name: exporting_process_id
          type: long

        - name: template_id
          type: integer

        - name: wlan_channel_id
          type: short

        - name: wlan_ssid
          type: keyword

        - name: flow_id
          type: long

        - name: observation_domain_id
          type: long

        - name: flow_start_seconds
          type: date

        - name: flow_end_seconds
          type: date

        - name: flow_start_milliseconds
          type: date

        - name: flow_end_milliseconds
          type: date

        - name: flow_start_microseconds
          type: date

        - name: flow_end_microseconds
          type: date

        - name: flow_start_nanoseconds
          type: date

        - name: flow_end_nanoseconds
          type: date

        - name: flow_start_delta_microseconds
          type: long

        - name: flow_end_delta_microseconds
          type: long

        - name: system_init_time_milliseconds
          type: date

        - name: flow_duration_milliseconds
          type: long

        - name: flow_duration_microseconds
          type: long

        - name: observed_flow_total_count
          type: long

        - name: ignored_packet_total_count
          type: long

        - name: ignored_octet_total_count
          type: long

        - name: not_sent_flow_total_count
          type: long

        - name: not_sent_packet_total_count
          type: long

        - name: not_sent_octet_total_count
          type: long

        - name: destination_ipv6_prefix
          type: ip

        - name: source_ipv6_prefix
          type: ip

        - name: post_octet_total_count
          type: long

        - name: post_packet_total_count
          type: long

        - name: flow_key_indicator
          type: long

        - name: post_mcast_packet_total_count
          type: long

        - name: post_mcast_octet_total_count
          type: long

        - name: icmp_type_ipv4
          type: short

        - name: icmp_code_ipv4
          type: short

        - name: icmp_type_ipv6
          type: short

        - name: icmp_code_ipv6
          type: short

        - name: udp_source_port
          type: integer

        - name: udp_destination_port
          type: integer

        - name: tcp_source_port
          type: integer

        - name: tcp_destination_port
          type: integer

        - name: tcp_sequence_number
          type: long

        - name: tcp_acknowledgement_number
          type: long

        - name: tcp_window_size
          type: integer

        - name: tcp_urgent_pointer
          type: integer

        - name: tcp_header_length
          type: short

        - name: ip_header_length
          type: short

        - name: total_length_ipv4
          type: integer

        - name: payload_length_ipv6
          type: integer

        - name: ip_ttl
          type: short

        - name: next_header_ipv6
          type: short

        - name: mpls_payload_length
          type: long

        - name: ip_diff_serv_code_point
          type: short

        - name: ip_precedence
          type: short

        - name: fragment_flags
          type: short

        - name: octet_delta_sum_of_squares
          type: long

        - name: octet_total_sum_of_squares
          type: long

        - name: mpls_top_label_ttl
          type: short

        - name: mpls_label_stack_length
          type: long

        - name: mpls_label_stack_depth
          type: long

        - name: mpls_top_label_exp
          type: short

        - name: ip_payload_length
          type: long

        - name: udp_message_length
          type: integer

        - name: is_multicast
          type: short

        - name: ipv4_ihl
          type: short

        - name: ipv4_options
          type: long

        - name: tcp_options
          type: long

        - name: padding_octets
          type: short

        - name: collector_ipv4_address
          type: ip

        - name: collector_ipv6_address
          type: ip

        - name: export_interface
          type: long

        - name: export_protocol_version
          type: short

        - name: export_transport_protocol
          type: short

        - name: collector_transport_port
          type: integer

        - name: exporter_transport_port
          type: integer

        - name: tcp_syn_total_count
          type: long

        - name: tcp_fin_total_count
          type: long

        - name: tcp_rst_total_count
          type: long

        - name: tcp_psh_total_count
          type: long

        - name: tcp_ack_total_count
          type: long

        - name: tcp_urg_total_count
          type: long

        - name: ip_total_length
          type: long

        - name: post_nat_source_ipv4_address
          type: ip

        - name: post_nat_destination_ipv4_address
          type: ip

        - name: post_napt_source_transport_port
          type: integer

        - name: post_napt_destination_transport_port
          type: integer

        - name: nat_originating_address_realm
          type: short

        - name: nat_event
          type: short

        - name: initiator_octets
          type: long

        - name: responder_octets
          type: long

        - name: firewall_event
          type: short

        - name: ingress_vrfid
          type: long

        - name: egress_vrfid
          type: long

        - name: vr_fname
          type: keyword

        - name: post_mpls_top_label_exp
          type: short

        - name: tcp_window_scale
          type: integer

        - name: biflow_direction
          type: short

        - name: ethernet_header_length
          type: short

        - name: ethernet_payload_length
          type: integer

        - name: ethernet_total_length
          type: integer

        - name: dot1q_vlan_id
          type: integer

        - name: dot1q_priority
          type: short

        - name: dot1q_customer_vlan_id
          type: integer

        - name: dot1q_customer_priority
          type: short

        - name: metro_evc_id
          type: keyword

        - name: metro_evc_type
          type: short

        - name: pseudo_wire_id
          type: long

        - name: pseudo_wire_type
          type: integer

        - name: pseudo_wire_control_word
          type: long

        - name: ingress_physical_interface
          type: long

        - name: egress_physical_interface
          type: long

        - name: post_dot1q_vlan_id
          type: integer

        - name: post_dot1q_customer_vlan_id
          type: integer

        - name: ethernet_type
          type: integer

        - name: post_ip_precedence
          type: short

        - name: collection_time_milliseconds
          type: date

        - name: export_sctp_stream_id
          type: integer

        - name: max_export_seconds
          type: date

        - name: max_flow_end_seconds
          type: date

        - name: message_md5_checksum
          type: short

        - name: message_scope
          type: short

        - name: min_export_seconds
          type: date

        - name: min_flow_start_seconds
          type: date

        - name: opaque_octets
          type: short

        - name: session_scope
          type: short

        - name: max_flow_end_microseconds
          type: date

        - name: max_flow_end_milliseconds
          type: date

        - name: max_flow_end_nanoseconds
          type: date

        - name: min_flow_start_microseconds
          type: date

        - name: min_flow_start_milliseconds
          type: date

        - name: min_flow_start_nanoseconds
          type: date

        - name: collector_certificate
          type: short

        - name: exporter_certificate
          type: short

        - name: data_records_reliability
          type: boolean

        - name: observation_point_type
          type: short

        - name: new_connection_delta_count
          type: long

        - name: connection_sum_duration_seconds
          type: long

        - name: connection_transaction_id
          type: long

        - name: post_nat_source_ipv6_address
          type: ip

        - name: post_nat_destination_ipv6_address
          type: ip

        - name: nat_pool_id
          type: long

        - name: nat_pool_name
          type: keyword

        - name: anonymization_flags
          type: integer

        - name: anonymization_technique
          type: integer

        - name: information_element_index
          type: integer

        - name: p2p_technology
          type: keyword

        - name: tunnel_technology
          type: keyword

        - name: encrypted_technology
          type: keyword

        - name: bgp_validity_state
          type: short

        - name: ip_sec_spi
          type: long

        - name: gre_key
          type: long

        - name: nat_type
          type: short

        - name: initiator_packets
          type: long

        - name: responder_packets
          type: long

        - name: observation_domain_name
          type: keyword

        - name: selection_sequence_id
          type: long

        - name: selector_id
          type: long

        - name: information_element_id
          type: integer

        - name: selector_algorithm
          type: integer

        - name: sampling_packet_interval
          type: long

        - name: sampling_packet_space
          type: long

        - name: sampling_time_interval
          type: long

        - name: sampling_time_space
          type: long

        - name: sampling_size
          type: long

        - name: sampling_population
          type: long

        - name: sampling_probability
          type: double

        - name: data_link_frame_size
          type: integer

        - name: ip_header_packet_section
          type: short

        - name: ip_payload_packet_section
          type: short

        - name: data_link_frame_section
          type: short

        - name: mpls_label_stack_section
          type: short

        - name: mpls_payload_packet_section
          type: short

        - name: selector_id_total_pkts_observed
          type: long

        - name: selector_id_total_pkts_selected
          type: long

        - name: absolute_error
          type: double

        - name: relative_error
          type: double

        - name: observation_time_seconds
          type: date

        - name: observation_time_milliseconds
          type: date

        - name: observation_time_microseconds
          type: date

        - name: observation_time_nanoseconds
          type: date

        - name: digest_hash_value
          type: long

        - name: hash_ip_payload_offset
          type: long

        - name: hash_ip_payload_size
          type: long

        - name: hash_output_range_min
          type: long

        - name: hash_output_range_max
          type: long

        - name: hash_selected_range_min
          type: long

        - name: hash_selected_range_max
          type: long

        - name: hash_digest_output
          type: boolean

        - name: hash_initialiser_value
          type: long

        - name: selector_name
          type: keyword

        - name: upper_ci_limit
          type: double

        - name: lower_ci_limit
          type: double

        - name: confidence_level
          type: double

        - name: information_element_data_type
          type: short

        - name: information_element_description
          type: keyword

        - name: information_element_name
          type: keyword

        - name: information_element_range_begin
          type: long

        - name: information_element_range_end
          type: long

        - name: information_element_semantics
          type: short

        - name: information_element_units
          type: integer

        - name: private_enterprise_number
          type: long

        - name: virtual_station_interface_id
          type: short

        - name: virtual_station_interface_name
          type: keyword

        - name: virtual_station_uuid
          type: short

        - name: virtual_station_name
          type: keyword

        - name: layer2_segment_id
          type: long

        - name: layer2_octet_delta_count
          type: long

        - name: layer2_octet_total_count
          type: long

        - name: ingress_unicast_packet_total_count
          type: long

        - name: ingress_multicast_packet_total_count
          type: long

        - name: ingress_broadcast_packet_total_count
          type: long

        - name: egress_unicast_packet_total_count
          type: long

        - name: egress_broadcast_packet_total_count
          type: long

        - name: monitoring_interval_start_milli_seconds
          type: date

        - name: monitoring_interval_end_milli_seconds
          type: date

        - name: port_range_start
          type: integer

        - name: port_range_end
          type: integer

        - name: port_range_step_size
          type: integer

        - name: port_range_num_ports
          type: integer

        - name: sta_mac_address
          type: keyword

        - name: sta_ipv4_address
          type: ip

        - name: wtp_mac_address
          type: keyword

        - name: ingress_interface_type
          type: long

        - name: egress_interface_type
          type: long

        - name: rtp_sequence_number
          type: integer

        - name: user_name
          type: keyword

        - name: application_category_name
          type: keyword

        - name: application_sub_category_name
          type: keyword

        - name: application_group_name
          type: keyword

        - name: original_flows_present
          type: long

        - name: original_flows_initiated
          type: long

        - name: original_flows_completed
          type: long

        - name: distinct_count_of_source_ip_address
          type: long

        - name: distinct_count_of_destination_ip_address
          type: long

        - name: distinct_count_of_source_ipv4_address
          type: long

        - name: distinct_count_of_destination_ipv4_address
          type: long

        - name: distinct_count_of_source_ipv6_address
          type: long

        - name: distinct_count_of_destination_ipv6_address
          type: long

        - name: value_distribution_method
          type: short

        - name: rfc3550_jitter_milliseconds
          type: long

        - name: rfc3550_jitter_microseconds
          type: long

        - name: rfc3550_jitter_nanoseconds
          type: long

        - name: dot1q_dei
          type: boolean

        - name: dot1q_customer_dei
          type: boolean

        - name: flow_selector_algorithm
          type: integer

        - name: flow_selected_octet_delta_count
          type: long

        - name: flow_selected_packet_delta_count
          type: long

        - name: flow_selected_flow_delta_count
          type: long

        - name: selector_id_total_flows_observed
          type: long

        - name: selector_id_total_flows_selected
          type: long

        - name: sampling_flow_interval
          type: long

        - name: sampling_flow_spacing
          type: long

        - name: flow_sampling_time_interval
          type: long

        - name: flow_sampling_time_spacing
          type: long

        - name: hash_flow_domain
          type: integer

        - name: transport_octet_delta_count
          type: long

        - name: transport_packet_delta_count
          type: long

        - name: original_exporter_ipv4_address
          type: ip

        - name: original_exporter_ipv6_address
          type: ip

        - name: original_observation_domain_id
          type: long

        - name: intermediate_process_id
          type: long

        - name: ignored_data_record_total_count
          type: long

        - name: data_link_frame_type
          type: integer

        - name: section_offset
          type: integer

        - name: section_exported_octets
          type: integer

        - name: dot1q_service_instance_tag
          type: short

        - name: dot1q_service_instance_id
          type: long

        - name: dot1q_service_instance_priority
          type: short

        - name: dot1q_customer_source_mac_address
          type: keyword

        - name: dot1q_customer_destination_mac_address
          type: keyword

        - name: post_layer2_octet_delta_count
          type: long

        - name: post_mcast_layer2_octet_delta_count
          type: long

        - name: post_layer2_octet_total_count
          type: long

        - name: post_mcast_layer2_octet_total_count
          type: long

        - name: minimum_layer2_total_length
          type: long

        - name: maximum_layer2_total_length
          type: long

        - name: dropped_layer2_octet_delta_count
          type: long

        - name: dropped_layer2_octet_total_count
          type: long

        - name: ignored_layer2_octet_total_count
          type: long

        - name: not_sent_layer2_octet_total_count
          type: long

        - name: layer2_octet_delta_sum_of_squares
          type: long

        - name: layer2_octet_total_sum_of_squares
          type: long

        - name: layer2_frame_delta_count
          type: long

        - name: layer2_frame_total_count
          type: long

        - name: pseudo_wire_destination_ipv4_address
          type: ip

        - name: ignored_layer2_frame_total_count
          type: long

        - name: mib_object_value_integer
          type: integer

        - name: mib_object_value_octet_string
          type: short

        - name: mib_object_value_oid
          type: short

        - name: mib_object_value_bits
          type: short

        - name: mib_object_value_ip_address
          type: ip

        - name: mib_object_value_counter
          type: long

        - name: mib_object_value_gauge
          type: long

        - name: mib_object_value_time_ticks
          type: long

        - name: mib_object_value_unsigned
          type: long

        - name: mib_object_identifier
          type: short

        - name: mib_sub_identifier
          type: long

        - name: mib_index_indicator
          type: long

        - name: mib_capture_time_semantics
          type: short

        - name: mib_context_engine_id
          type: short

        - name: mib_context_name
          type: keyword

        - name: mib_object_name
          type: keyword

        - name: mib_object_description
          type: keyword

        - name: mib_object_syntax
          type: keyword

        - name: mib_module_name
          type: keyword

        - name: mobile_imsi
          type: keyword

        - name: mobile_msisdn
          type: keyword

        - name: http_status_code
          type: integer

        - name: source_transport_ports_limit
          type: integer

        - name: http_request_method
          type: keyword

        - name: http_request_host
          type: keyword

        - name: http_request_target
          type: keyword

        - name: http_message_version
          type: keyword

        - name: nat_instance_id
          type: long

        - name: internal_address_realm
          type: short

        - name: external_address_realm
          type: short

        - name: nat_quota_exceeded_event
          type: long

        - name: nat_threshold_event
          type: long

        - name: http_user_agent
          type: keyword

        - name: http_content_type
          type: keyword

        - name: http_reason_phrase
          type: keyword

        - name: max_session_entries
          type: long

        - name: max_bib_entries
          type: long

        - name: max_entries_per_user
          type: long

        - name: max_subscribers
          type: long

        - name: max_fragments_pending_reassembly
          type: long

        - name: address_pool_high_threshold
          type: long

        - name: address_pool_low_threshold
          type: long

        - name: address_port_mapping_high_threshold
          type: long

        - name: address_port_mapping_low_threshold
          type: long

        - name: address_port_mapping_per_user_high_threshold
          type: long

        - name: global_address_mapping_high_threshold
          type: long

        - name: vpn_identifier
          type: short

- key: s3
  title: "s3"
  description: >
    S3 fields from s3 input.
  release: beta
  fields:
    - name: bucket_name
      type: keyword
      description: >
        Name of the S3 bucket that this log retrieved from.
    - name: object_key
      type: keyword
      description: >
        Name of the S3 object that this log retrieved from.
- key: cef
  title: Decode CEF processor fields
  description: >
    Common Event Format (CEF) data.
  fields:
    - name: cef
      type: group
      description: >
        By default the `decode_cef` processor writes all data from the CEF
        message to this `cef` object. It contains the CEF header fields and the
        extension data.
      fields:
        - name: version
          type: keyword
          description: >
            Version of the CEF specification used by the message.

        - name: device.vendor
          type: keyword
          description: >
            Vendor of the device that produced the message.

        - name: device.product
          type: keyword
          description: >
            Product of the device that produced the message.

        - name: device.version
          type: keyword
          description: >
            Version of the product that produced the message.

        - name: device.event_class_id
          type: keyword
          description: >
            Unique identifier of the event type.

        - name: severity
          type: keyword
          example: Very-High
          description: >
            Importance of the event. The valid string values are Unknown, Low,
            Medium, High, and Very-High. The valid integer values are 0-3=Low,
            4-6=Medium, 7- 8=High, and 9-10=Very-High.

        - name: name
          type: keyword
          description: >
            Short description of the event.

        - name: extensions
          type: group
          description: >
            Collection of key-value pairs carried in the CEF extension field.
          default_field: false
          fields:
            - name: agentAddress
              type: ip
              description: The IP address of the ArcSight connector that processed the event.

            - name: agentDnsDomain
              type: keyword
              description: The DNS domain name of the ArcSight connector that processed the event.

            - name: agentHostName
              type: keyword
              description: The hostname of the ArcSight connector that processed the event.

            - name: agentId
              type: keyword
              description: The agent ID of the ArcSight connector that processed the event.

            - name: agentMacAddress
              type: keyword
              description: The MAC address of the ArcSight connector that processed the event.

            - name: agentNtDomain
              type: keyword
              description:

            - name: agentReceiptTime
              type: date
              description: The time at which information about the event was received by the ArcSight connector.

            - name: agentTimeZone
              type: keyword
              description: The agent time zone of the ArcSight connector that processed the event.

            - name: agentTranslatedAddress
              type: ip
              description:

            - name: agentTranslatedZoneExternalID
              type: keyword
              description:

            - name: agentTranslatedZoneURI
              type: keyword
              description:

            - name: agentType
              type: keyword
              description: The agent type of the ArcSight connector that processed the event

            - name: agentVersion
              type: keyword
              description: The version of the ArcSight connector that processed the event.

            - name: agentZoneExternalID
              type: keyword
              description:

            - name: agentZoneURI
              type: keyword
              description:

            - name: applicationProtocol
              type: keyword
              description: Application level protocol, example values are HTTP, HTTPS, SSHv2, Telnet, POP, IMPA, IMAPS, and so on.

            - name: baseEventCount
              type: long
              description: A count associated with this event. How many times was this same event observed? Count can be omitted if it is 1.

            - name: bytesIn
              type: long
              description: Number of bytes transferred inbound, relative to the source to destination relationship, meaning that data was flowing from source to destination.

            - name: bytesOut
              type: long
              description: Number of bytes transferred outbound relative to the source to destination relationship. For example, the byte number of data flowing from the destination to the source.

            - name: customerExternalID
              type: keyword
              description:

            - name: customerURI
              type: keyword
              description:

            - name: destinationAddress
              type: ip
              description: Identifies the destination address that the event refers to in an IP network. The format is an IPv4 address.

            - name: destinationDnsDomain
              type: keyword
              description: The DNS domain part of the complete fully qualified domain name (FQDN).

            - name: destinationGeoLatitude
              type: double
              description: The latitudinal value from which the destination's IP address belongs.

            - name: destinationGeoLongitude
              type: double
              description: The longitudinal value from which the destination's IP address belongs.

            - name: destinationHostName
              type: keyword
              description: Identifies the destination that an event refers to in an IP network. The format should be a fully qualified domain name (FQDN) associated with the destination node, when a node is available.

            - name: destinationMacAddress
              type: keyword
              description: Six colon-seperated hexadecimal numbers.

            - name: destinationNtDomain
              type: keyword
              description: The Windows domain name of the destination address.

            - name: destinationPort
              type: long
              description: The valid port numbers are between 0 and 65535.

            - name: destinationProcessId
              type: long
              description: Provides the ID of the destination process associated with the event. For example, if an event contains process ID 105, "105" is the process ID.

            - name: destinationProcessName
              type: keyword
              description: The name of the event's destination process.

            - name: destinationServiceName
              type: keyword
              description: The service targeted by this event.

            - name: destinationTranslatedAddress
              type: ip
              description: Identifies the translated destination that the event refers to in an IP network.

            - name: destinationTranslatedPort
              type: long
              description: Port after it was translated; for example, a firewall. Valid port numbers are 0 to 65535.

            - name: destinationTranslatedZoneExternalID
              type: keyword
              description:

            - name: destinationTranslatedZoneURI
              type: keyword
              description: The URI for the Translated Zone that the destination asset has been assigned to in ArcSight.

            - name: destinationUserId
              type: keyword
              description: Identifies the destination user by ID. For example, in UNIX, the root user is generally associated with user ID 0.

            - name: destinationUserName
              type: keyword
              description: Identifies the destination user by name. This is the user associated with the event's destination. Email addresses are often mapped into the UserName fields. The recipient is a candidate to put into this field.

            - name: destinationUserPrivileges
              type: keyword
              description: The typical values are "Administrator", "User", and "Guest". This identifies the destination user's privileges. In UNIX, for example, activity executed on the root user would be identified with destinationUser Privileges of "Administrator".

            - name: destinationZoneExternalID
              type: keyword
              description:

            - name: destinationZoneURI
              type: keyword
              description: The URI for the Zone that the destination asset has been assigned to in ArcSight.

            - name: deviceAction
              type: keyword
              description: Action taken by the device.

            - name: deviceAddress
              type: ip
              description: Identifies the device address that an event refers to in an IP network.

            - name: deviceCustomFloatingPoint1Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomFloatingPoint3Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomFloatingPoint4Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomDate1
              type: date
              description: One of two timestamp fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomDate1Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomDate2
              type: date
              description: One of two timestamp fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomDate2Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomFloatingPoint1
              type: double
              description: One of four floating point fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomFloatingPoint2
              type: double
              description: One of four floating point fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomFloatingPoint2Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomFloatingPoint3
              type: double
              description: One of four floating point fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomFloatingPoint4
              type: double
              description: One of four floating point fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomIPv6Address1Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomIPv6Address4
              type: ip
              description: One of four IPv6 address fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomIPv6Address4Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomIPv6Address1
              type: ip
              description: One of four IPv6 address fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomIPv6Address3
              type: ip
              description: One of four IPv6 address fields available to map fields that do not apply to any other in this dictionary.

            - name: deviceCustomIPv6Address3Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomNumber1
              type: long
              description: One of three number fields available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomNumber1Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: DeviceCustomNumber2
              type: long
              description: One of three number fields available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomNumber2Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomNumber3
              type: long
              description: One of three number fields available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomNumber3Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomString1
              type: keyword
              description: One of six strings available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomString1Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomString2
              type: keyword
              description: One of six strings available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomString2Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomString3
              type: keyword
              description: One of six strings available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomString3Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomString4
              type: keyword
              description: One of six strings available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomString4Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomString5
              type: keyword
              description: One of six strings available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomString5Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceCustomString6
              type: keyword
              description: One of six strings available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible.

            - name: deviceCustomString6Label
              type: keyword
              description: All custom fields have a corresponding label field. Each of these fields is a string and describes the purpose of the custom field.

            - name: deviceDirection
              type: long
              description: Any information about what direction the observed communication has taken. The following values are supported - "0" for inbound or "1" for outbound.

            - name: deviceDnsDomain
              type: keyword
              description: The DNS domain part of the complete fully qualified domain name (FQDN).

            - name: deviceEventCategory
              type: keyword
              description: Represents the category assigned by the originating device. Devices often use their own categorization schema to classify event. Example "/Monitor/Disk/Read".

            - name: deviceExternalId
              type: keyword
              description: A name that uniquely identifies the device generating this event.

            - name: deviceFacility
              type: keyword
              description: The facility generating this event. For example, Syslog has an explicit facility associated with every event.

            - name: deviceHostName
              type: keyword
              description: The format should be a fully qualified domain name (FQDN) associated with the device node, when a node is available.

            - name: deviceInboundInterface
              type: keyword
              description: Interface on which the packet or data entered the device.

            - name: deviceMacAddress
              type: keyword
              description: Six colon-separated hexadecimal numbers.

            - name: deviceNtDomain
              type: keyword
              description: The Windows domain name of the device address.

            - name: deviceOutboundInterface
              type: keyword
              description: Interface on which the packet or data left the device.

            - name: devicePayloadId
              type: keyword
              description: Unique identifier for the payload associated with the event.

            - name: deviceProcessId
              type: long
              description: Provides the ID of the process on the device generating the event.

            - name: deviceProcessName
              type: keyword
              description: Process name associated with the event. An example might be the process generating the syslog entry in UNIX.

            - name: deviceReceiptTime
              type: date
              description: The time at which the event related to the activity was received. The format is MMM dd yyyy HH:mm:ss or milliseconds since epoch (Jan 1st 1970)

            - name: deviceTimeZone
              type: keyword
              description: The timezone for the device generating the event.

            - name: deviceTranslatedAddress
              type: ip
              description: Identifies the translated device address that the event refers to in an IP network.

            - name: deviceTranslatedZoneExternalID
              type: keyword
              description:

            - name: deviceTranslatedZoneURI
              type: keyword
              description: The URI for the Translated Zone that the device asset has been assigned to in ArcSight.

            - name: deviceZoneExternalID
              type: keyword
              description:

            - name: deviceZoneURI
              type: keyword
              description: Thee URI for the Zone that the device asset has been assigned to in ArcSight.

            - name: endTime
              type: date
              description: The time at which the activity related to the event ended. The format is MMM dd yyyy HH:mm:ss or milliseconds since epoch (Jan 1st1970). An example would be reporting the end of a session.

            - name: eventId
              type: long
              description: This is a unique ID that ArcSight assigns to each event.

            - name: eventOutcome
              type: keyword
              description: Displays the outcome, usually as 'success' or 'failure'.

            - name: externalId
              type: keyword
              description: The ID used by an originating device. They are usually increasing numbers, associated with events.

            - name: fileCreateTime
              type: date
              description: Time when the file was created.

            - name: fileHash
              type: keyword
              description: Hash of a file.

            - name: fileId
              type: keyword
              description: An ID associated with a file could be the inode.

            - name: fileModificationTime
              type: date
              description: Time when the file was last modified.

            - name: filename
              type: keyword
              description: Name of the file only (without its path).

            - name: filePath
              type: keyword
              description: Full path to the file, including file name itself.

            - name: filePermission
              type: keyword
              description: Permissions of the file.

            - name: fileSize
              type: long
              description: Size of the file.

            - name: fileType
              type: keyword
              description: Type of file (pipe, socket, etc.)

            - name: flexDate1
              type: date
              description: A timestamp field available to map a timestamp that does not apply to any other defined timestamp field in this dictionary. Use all flex fields sparingly and seek a more specific, dictionary supplied field when possible. These fields are typically reserved for customer use and should not be set by vendors unless necessary.

            - name: flexDate1Label
              type: keyword
              description: The label field is a string and describes the purpose of the flex field.

            - name: flexString1
              type: keyword
              description: One of four floating point fields available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible. These fields are typically reserved for customer use and should not be set by vendors unless necessary.

            - name: flexString2
              type: keyword
              description: One of four floating point fields available to map fields that do not apply to any other in this dictionary. Use sparingly and seek a more specific, dictionary supplied field when possible. These fields are typically reserved for customer use and should not be set by vendors unless necessary.

            - name: flexString1Label
              type: keyword
              description: The label field is a string and describes the purpose of the flex field.

            - name: flexString2Label
              type: keyword
              description: The label field is a string and describes the purpose of the flex field.

            - name: message
              type: keyword
              description: An arbitrary message giving more details about the event. Multi-line entries can be produced by using \n as the new line separator.

            - name: oldFileCreateTime
              type: date
              description: Time when old file was created.

            - name: oldFileHash
              type: keyword
              description: Hash of the old file.

            - name: oldFileId
              type: keyword
              description: An ID associated with the old file could be the inode.

            - name: oldFileModificationTime
              type: date
              description: Time when old file was last modified.

            - name: oldFileName
              type: keyword
              description: Name of the old file.

            - name: oldFilePath
              type: keyword
              description: Full path to the old file, including the file name itself.

            - name: oldFilePermission
              type: keyword
              description: Permissions of the old file.

            - name: oldFileSize
              type: long
              description: Size of the old file.

            - name: oldFileType
              type: keyword
              description: Type of the old file (pipe, socket, etc.)

            - name: rawEvent
              type: keyword
              description:

            - name: Reason
              type: keyword
              description: The reason an audit event was generated. For example "bad password" or "unknown user". This could also be an error or return code. Example "0x1234".

            - name: requestClientApplication
              type: keyword
              description: The User-Agent associated with the request.

            - name: requestContext
              type: keyword
              description: Description of the content from which the request originated (for example, HTTP Referrer)

            - name: requestCookies
              type: keyword
              description: Cookies associated with the request.

            - name: requestMethod
              type: keyword
              description: The HTTP method used to access a URL.

            - name: requestUrl
              type: keyword
              description: In the case of an HTTP request, this field contains the URL accessed. The URL should contain the protocol as well.

            - name: sourceAddress
              type: ip
              description: Identifies the source that an event refers to in an IP network.

            - name: sourceDnsDomain
              type: keyword
              description: The DNS domain part of the complete fully qualified domain name (FQDN).

            - name: sourceGeoLatitude
              type: double
              description:

            - name: sourceGeoLongitude
              type: double
              description:

            - name: sourceHostName
              type: keyword
              description: >
                Identifies the source that an event refers to in an IP network.
                The format should be a fully qualified domain name (FQDN) associated with the source node, when a
                mode is available. Examples: 'host' or 'host.domain.com'.

            - name: sourceMacAddress
              type: keyword
              example: "00:0d:60:af:1b:61"
              description: Six colon-separated hexadecimal numbers.

            - name: sourceNtDomain
              type: keyword
              description: The Windows domain name for the source address.

            - name: sourcePort
              type: long
              description: The valid port numbers are 0 to 65535.

            - name: sourceProcessId
              type: long
              description: The ID of the source process associated with the event.

            - name: sourceProcessName
              type: keyword
              description: The name of the event's source process.

            - name: sourceServiceName
              type: keyword
              description: The service that is responsible for generating this event.

            - name: sourceTranslatedAddress
              type: ip
              description: Identifies the translated source that the event refers to in an IP network.

            - name: sourceTranslatedPort
              type: long
              description: A port number after being translated by, for example, a firewall. Valid port numbers are 0 to 65535.

            - name: sourceTranslatedZoneExternalID
              type: keyword
              description:

            - name: sourceTranslatedZoneURI
              type: keyword
              description: The URI for the Translated Zone that the destination asset has been assigned to in ArcSight.

            - name: sourceUserId
              type: keyword
              description: Identifies the source user by ID. This is the user associated with the source of the event. For example, in UNIX, the root user is generally associated with user ID 0.

            - name: sourceUserName
              type: keyword
              description: Identifies the source user by name. Email addresses are also mapped into the UserName fields. The sender is a candidate to put into this field.

            - name: sourceUserPrivileges
              type: keyword
              description: The typical values are "Administrator", "User", and "Guest". It identifies the source user's privileges. In UNIX, for example, activity executed by the root user would be identified with "Administrator".

            - name: sourceZoneExternalID
              type: keyword
              description:

            - name: sourceZoneURI
              type: keyword
              description: The URI for the Zone that the source asset has been assigned to in ArcSight.

            - name: startTime
              type: date
              description: The time when the activity the event referred to started. The format is MMM dd yyyy HH:mm:ss or milliseconds since epoch (Jan 1st 1970)

            - name: transportProtocol
              type: keyword
              description: Identifies the Layer-4 protocol used. The possible values are protocols such as TCP or UDP.

            - name: type
              type: long
              description: 0 means base event, 1 means aggregated, 2 means correlation, and 3 means action. This field can be omitted for base events (type 0).

            # ArcSight fields.
            - name: categoryDeviceType
              type: keyword
              description: Device type. Examples - Proxy, IDS, Web Server

            - name: categoryObject
              type: keyword
              description: Object that the event is about. For example it can be an operating sytem, database, file, etc.

            - name: categoryBehavior
              type: keyword
              description: Action or a behavior associated with an event. It's what is being done to the object.

            - name: categoryTechnique
              type: keyword
              description: Technique being used (e.g. /DoS).

            - name: categoryDeviceGroup
              type: keyword
              description: General device group like Firewall.

            - name: categorySignificance
              type: keyword
              description: Characterization of the importance of the event.

            - name: categoryOutcome
              type: keyword
              description: Outcome of the event (e.g. sucess, failure, or attempt).

            - name: managerReceiptTime
              type: date
              description: When the Arcsight ESM received the event.

    - name: source.service.name
      type: keyword
      description:
        Service that is the source of the event.

    - name: destination.service.name
      type: keyword
      description:
        Service that is the target of the event.