Skip to content

Commit d85f160

Browse files
committed
feat(filters): enhance Fortinet field mapping and cleanup
1 parent 090fed9 commit d85f160

1 file changed

Lines changed: 47 additions & 2 deletions

File tree

filters/fortinet/fortinet.yml

Lines changed: 47 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Fortinet firewall module filter, version 3.0.2
1+
# Fortinet firewall module filter, version 3.0.3
22
# Based in docs and samples provided
33
#
44
# Documentations
@@ -72,7 +72,26 @@ pipeline:
7272
from:
7373
- log.srcport
7474
to: origin.port
75-
75+
- rename:
76+
from:
77+
- log.mastersrcmac
78+
to: log.masterSourceMac
79+
- rename:
80+
from:
81+
- log.osname
82+
to: log.osName
83+
- rename:
84+
from:
85+
- log.unauthusersource
86+
to: log.unauthUserSource
87+
- rename:
88+
from:
89+
- log.srchwvendor
90+
to: log.sourceVendor
91+
- rename:
92+
from:
93+
- log.srcmac
94+
to: origin.mac
7695
- rename:
7796
from:
7897
- log.dest_ip
@@ -131,6 +150,19 @@ pipeline:
131150
- log.apprisk
132151
- log.scertcname
133152
- log.scertissuer
153+
- log.appact
154+
- log.applist
155+
- log.masterSourceMac
156+
- log.osName
157+
- log.service
158+
- log.trandisp
159+
- log.tz
160+
- log.srcswversion
161+
- log.unauthUserSource
162+
- origin.mac
163+
- log.unauthuser
164+
- log.srcname
165+
- log.sourceVendor
134166
- trim:
135167
function: suffix
136168
substring: '"'
@@ -161,6 +193,19 @@ pipeline:
161193
- log.apprisk
162194
- log.scertcname
163195
- log.scertissuer
196+
- log.appact
197+
- log.applist
198+
- log.masterSourceMac
199+
- log.osName
200+
- log.service
201+
- log.trandisp
202+
- log.tz
203+
- log.srcswversion
204+
- log.unauthUserSource
205+
- origin.mac
206+
- log.unauthuser
207+
- log.srcname
208+
- log.sourceVendor
164209

165210
# Adding geolocation to origin.ip
166211
- dynamic:

0 commit comments

Comments
 (0)