Field Name | Example Values | Field Type | Notes |
---|---|---|---|
source_as_*
|
See: as_* fields |
||
source_category
|
keyword | Future: from entity mapping | |
source_geo_*
|
See: geo_* fields |
||
source_location_name
|
Chicago, US, Datacenter 01, Bismark - Finance | keyword | Field is derived either from an internal enterprise network definition or the Geo location fields if availble |
source_mac
|
a0:b4:44:01:a9:d1 | keyword | MAC address of host, colon-delimited and lower case |
source_priority
|
critical, high, medium, low | keyword | Future: from entity mapping |
source_priority_level
|
4-Jan | byte | Numeric value representing the priority of the source device, 1 = low, 2 = medium, 3 = high, 4 = critical |
source_reference
|
IPv4,IPv6, hostname,fqdn | keyword (normalized:loweronly) | Automatically mapped from the following fields: source_ip , source_hostname , source_vm_name , source_mac |