Source Fieldsedit

Source fields describe details about the source of a packet/event.

Source fields are usually populated in conjunction with destination fields.

Source Field Detailsedit

FieldDescriptionLevel

source.address

Some event source addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the .address field.

Then it should be duplicated to .ip or .domain, depending on which one it is.

type: keyword

extended

source.bytes

Bytes sent from the source to the destination.

type: long

example: 184

core

source.domain

Source domain.

type: keyword

core

source.ip

IP address of the source.

Can be one or multiple IPv4 or IPv6 addresses.

type: ip

core

source.mac

MAC address of the source.

type: keyword

core

source.packets

Packets sent from the source to the destination.

type: long

example: 12

core

source.port

Port of the source.

type: long

core

Field Reuseedit

Field sets that can be nested under Sourceedit

Nested fieldsDescription

source.geo.*

Fields describing a location.

source.user.*

Fields to describe the user relevant to the event.