0100-fortigate_decoders.xml 151 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426
  1. <decoder name="fortinet-fortigate-firewall">
  2. <prematch type="pcre2">^date=\d{4}-\d{2}-\d{2}\s+time=\d{2}:\d{2}:\d{2}\s+devname="[^"]*"\s+devid="[^"]*"\s+eventtime=\d+\s+tz="[^"]*"\s+logid="\d+"</prematch>
  3. </decoder>
  4. <decoder name="fortinet-fortigate-fields-v7">
  5. <parent>fortinet-fortigate-firewall</parent>
  6. <regex>devname="(\.*)"|devname=(\.*)\s|devname=(\.*)$</regex>
  7. <order>devname</order>
  8. </decoder>
  9. <decoder name="fortinet-fortigate-fields-v7">
  10. <parent>fortinet-fortigate-firewall</parent>
  11. <regex>\s+accessctrl="(\.*)"|\s+accessctrl=(\.*)\s|\s+accessctrl=(\.*)$</regex>
  12. <order>accessctrl</order>
  13. </decoder>
  14. <decoder name="fortinet-fortigate-fields-v7">
  15. <parent>fortinet-fortigate-firewall</parent>
  16. <regex>\s+accessproxy="(\.*)"|\s+accessproxy=(\.*)\s|\s+accessproxy=(\.*)$</regex>
  17. <order>accessproxy</order>
  18. </decoder>
  19. <decoder name="fortinet-fortigate-fields-v7">
  20. <parent>fortinet-fortigate-firewall</parent>
  21. <regex>\s+acct_stat="(\.*)"|\s+acct_stat=(\.*)\s|\s+acct_stat=(\.*)$</regex>
  22. <order>acct_stat</order>
  23. </decoder>
  24. <decoder name="fortinet-fortigate-fields-v7">
  25. <parent>fortinet-fortigate-firewall</parent>
  26. <regex>\s+acktime="(\.*)"|\s+acktime=(\.*)\s|\s+acktime=(\.*)$</regex>
  27. <order>acktime</order>
  28. </decoder>
  29. <decoder name="fortinet-fortigate-fields-v7">
  30. <parent>fortinet-fortigate-firewall</parent>
  31. <regex>\s+act="(\.*)"|\s+act=(\.*)\s|\s+act=(\.*)$</regex>
  32. <order>act</order>
  33. </decoder>
  34. <decoder name="fortinet-fortigate-fields-v7">
  35. <parent>fortinet-fortigate-firewall</parent>
  36. <regex>\s+action="(\.*)"|\s+action=(\.*)\s|\s+action=(\.*)$</regex>
  37. <order>action</order>
  38. </decoder>
  39. <decoder name="fortinet-fortigate-fields-v7">
  40. <parent>fortinet-fortigate-firewall</parent>
  41. <regex>\s+activity="(\.*)"|\s+activity=(\.*)\s|\s+activity=(\.*)$</regex>
  42. <order>activity</order>
  43. </decoder>
  44. <decoder name="fortinet-fortigate-fields-v7">
  45. <parent>fortinet-fortigate-firewall</parent>
  46. <regex>\s+activitycategory="(\.*)"|\s+activitycategory=(\.*)\s|\s+activitycategory=(\.*)$</regex>
  47. <order>activitycategory</order>
  48. </decoder>
  49. <decoder name="fortinet-fortigate-fields-v7">
  50. <parent>fortinet-fortigate-firewall</parent>
  51. <regex>\s+addr="(\.*)"|\s+addr=(\.*)\s|\s+addr=(\.*)$</regex>
  52. <order>addr</order>
  53. </decoder>
  54. <decoder name="fortinet-fortigate-fields-v7">
  55. <parent>fortinet-fortigate-firewall</parent>
  56. <regex>\s+addr_type="(\.*)"|\s+addr_type=(\.*)\s|\s+addr_type=(\.*)$</regex>
  57. <order>addr_type</order>
  58. </decoder>
  59. <decoder name="fortinet-fortigate-fields-v7">
  60. <parent>fortinet-fortigate-firewall</parent>
  61. <regex>\s+addrgrp="(\.*)"|\s+addrgrp=(\.*)\s|\s+addrgrp=(\.*)$</regex>
  62. <order>addrgrp</order>
  63. </decoder>
  64. <decoder name="fortinet-fortigate-fields-v7">
  65. <parent>fortinet-fortigate-firewall</parent>
  66. <regex>\s+adgroup="(\.*)"|\s+adgroup=(\.*)\s|\s+adgroup=(\.*)$</regex>
  67. <order>adgroup</order>
  68. </decoder>
  69. <decoder name="fortinet-fortigate-fields-v7">
  70. <parent>fortinet-fortigate-firewall</parent>
  71. <regex>\s+admin="(\.*)"|\s+admin=(\.*)\s|\s+admin=(\.*)$</regex>
  72. <order>admin</order>
  73. </decoder>
  74. <decoder name="fortinet-fortigate-fields-v7">
  75. <parent>fortinet-fortigate-firewall</parent>
  76. <regex>\s+advpnsc="(\.*)"|\s+advpnsc=(\.*)\s|\s+advpnsc=(\.*)$</regex>
  77. <order>advpnsc</order>
  78. </decoder>
  79. <decoder name="fortinet-fortigate-fields-v7">
  80. <parent>fortinet-fortigate-firewall</parent>
  81. <regex>\s+age="(\.*)"|\s+age=(\.*)\s|\s+age=(\.*)$</regex>
  82. <order>age</order>
  83. </decoder>
  84. <decoder name="fortinet-fortigate-fields-v7">
  85. <parent>fortinet-fortigate-firewall</parent>
  86. <regex>\s+agent="(\.*)"|\s+agent=(\.*)\s|\s+agent=(\.*)$</regex>
  87. <order>agent</order>
  88. </decoder>
  89. <decoder name="fortinet-fortigate-fields-v7">
  90. <parent>fortinet-fortigate-firewall</parent>
  91. <regex>\s+alarmid="(\.*)"|\s+alarmid=(\.*)\s|\s+alarmid=(\.*)$</regex>
  92. <order>alarmid</order>
  93. </decoder>
  94. <decoder name="fortinet-fortigate-fields-v7">
  95. <parent>fortinet-fortigate-firewall</parent>
  96. <regex>\s+alert="(\.*)"|\s+alert=(\.*)\s|\s+alert=(\.*)$</regex>
  97. <order>alert</order>
  98. </decoder>
  99. <decoder name="fortinet-fortigate-fields-v7">
  100. <parent>fortinet-fortigate-firewall</parent>
  101. <regex>\s+analyticscksum="(\.*)"|\s+analyticscksum=(\.*)\s|\s+analyticscksum=(\.*)$</regex>
  102. <order>analyticscksum</order>
  103. </decoder>
  104. <decoder name="fortinet-fortigate-fields-v7">
  105. <parent>fortinet-fortigate-firewall</parent>
  106. <regex>\s+analyticssubmit="(\.*)"|\s+analyticssubmit=(\.*)\s|\s+analyticssubmit=(\.*)$</regex>
  107. <order>analyticssubmit</order>
  108. </decoder>
  109. <decoder name="fortinet-fortigate-fields-v7">
  110. <parent>fortinet-fortigate-firewall</parent>
  111. <regex>\s+anomaly="(\.*)"|\s+anomaly=(\.*)\s|\s+anomaly=(\.*)$</regex>
  112. <order>anomaly</order>
  113. </decoder>
  114. <decoder name="fortinet-fortigate-fields-v7">
  115. <parent>fortinet-fortigate-firewall</parent>
  116. <regex>\s+antiphishdc="(\.*)"|\s+antiphishdc=(\.*)\s|\s+antiphishdc=(\.*)$</regex>
  117. <order>antiphishdc</order>
  118. </decoder>
  119. <decoder name="fortinet-fortigate-fields-v7">
  120. <parent>fortinet-fortigate-firewall</parent>
  121. <regex>\s+antiphishrule="(\.*)"|\s+antiphishrule=(\.*)\s|\s+antiphishrule=(\.*)$</regex>
  122. <order>antiphishrule</order>
  123. </decoder>
  124. <decoder name="fortinet-fortigate-fields-v7">
  125. <parent>fortinet-fortigate-firewall</parent>
  126. <regex>\s+ap="(\.*)"|\s+ap=(\.*)\s|\s+ap=(\.*)$</regex>
  127. <order>ap</order>
  128. </decoder>
  129. <decoder name="fortinet-fortigate-fields-v7">
  130. <parent>fortinet-fortigate-firewall</parent>
  131. <regex>\s+apn="(\.*)"|\s+apn=(\.*)\s|\s+apn=(\.*)$</regex>
  132. <order>apn</order>
  133. </decoder>
  134. <decoder name="fortinet-fortigate-fields-v7">
  135. <parent>fortinet-fortigate-firewall</parent>
  136. <regex>\s+app="(\.*)"|\s+app=(\.*)\s|\s+app=(\.*)$</regex>
  137. <order>app</order>
  138. </decoder>
  139. <decoder name="fortinet-fortigate-fields-v7">
  140. <parent>fortinet-fortigate-firewall</parent>
  141. <regex>\s+appact="(\.*)"|\s+appact=(\.*)\s|\s+appact=(\.*)$</regex>
  142. <order>appact</order>
  143. </decoder>
  144. <decoder name="fortinet-fortigate-fields-v7">
  145. <parent>fortinet-fortigate-firewall</parent>
  146. <regex>\s+appcat="(\.*)"|\s+appcat=(\.*)\s|\s+appcat=(\.*)$</regex>
  147. <order>appcat</order>
  148. </decoder>
  149. <decoder name="fortinet-fortigate-fields-v7">
  150. <parent>fortinet-fortigate-firewall</parent>
  151. <regex>\s+apperror="(\.*)"|\s+apperror=(\.*)\s|\s+apperror=(\.*)$</regex>
  152. <order>apperror</order>
  153. </decoder>
  154. <decoder name="fortinet-fortigate-fields-v7">
  155. <parent>fortinet-fortigate-firewall</parent>
  156. <regex>\s+appid="(\.*)"|\s+appid=(\.*)\s|\s+appid=(\.*)$</regex>
  157. <order>appid</order>
  158. </decoder>
  159. <decoder name="fortinet-fortigate-fields-v7">
  160. <parent>fortinet-fortigate-firewall</parent>
  161. <regex>\s+applist="(\.*)"|\s+applist=(\.*)\s|\s+applist=(\.*)$</regex>
  162. <order>applist</order>
  163. </decoder>
  164. <decoder name="fortinet-fortigate-fields-v7">
  165. <parent>fortinet-fortigate-firewall</parent>
  166. <regex>\s+apprisk="(\.*)"|\s+apprisk=(\.*)\s|\s+apprisk=(\.*)$</regex>
  167. <order>apprisk</order>
  168. </decoder>
  169. <decoder name="fortinet-fortigate-fields-v7">
  170. <parent>fortinet-fortigate-firewall</parent>
  171. <regex>\s+apscan="(\.*)"|\s+apscan=(\.*)\s|\s+apscan=(\.*)$</regex>
  172. <order>apscan</order>
  173. </decoder>
  174. <decoder name="fortinet-fortigate-fields-v7">
  175. <parent>fortinet-fortigate-firewall</parent>
  176. <regex>\s+apsn="(\.*)"|\s+apsn=(\.*)\s|\s+apsn=(\.*)$</regex>
  177. <order>apsn</order>
  178. </decoder>
  179. <decoder name="fortinet-fortigate-fields-v7">
  180. <parent>fortinet-fortigate-firewall</parent>
  181. <regex>\s+apstatus="(\.*)"|\s+apstatus=(\.*)\s|\s+apstatus=(\.*)$</regex>
  182. <order>apstatus</order>
  183. </decoder>
  184. <decoder name="fortinet-fortigate-fields-v7">
  185. <parent>fortinet-fortigate-firewall</parent>
  186. <regex>\s+aptype="(\.*)"|\s+aptype=(\.*)\s|\s+aptype=(\.*)$</regex>
  187. <order>aptype</order>
  188. </decoder>
  189. <decoder name="fortinet-fortigate-fields-v7">
  190. <parent>fortinet-fortigate-firewall</parent>
  191. <regex>\s+assigned="(\.*)"|\s+assigned=(\.*)\s|\s+assigned=(\.*)$</regex>
  192. <order>assigned</order>
  193. </decoder>
  194. <decoder name="fortinet-fortigate-fields-v7">
  195. <parent>fortinet-fortigate-firewall</parent>
  196. <regex>\s+assignip="(\.*)"|\s+assignip=(\.*)\s|\s+assignip=(\.*)$</regex>
  197. <order>assignip</order>
  198. </decoder>
  199. <decoder name="fortinet-fortigate-fields-v7">
  200. <parent>fortinet-fortigate-firewall</parent>
  201. <regex>\s+attachment="(\.*)"|\s+attachment=(\.*)\s|\s+attachment=(\.*)$</regex>
  202. <order>attachment</order>
  203. </decoder>
  204. <decoder name="fortinet-fortigate-fields-v7">
  205. <parent>fortinet-fortigate-firewall</parent>
  206. <regex>\s+attack="(\.*)"|\s+attack=(\.*)\s|\s+attack=(\.*)$</regex>
  207. <order>attack</order>
  208. </decoder>
  209. <decoder name="fortinet-fortigate-fields-v7">
  210. <parent>fortinet-fortigate-firewall</parent>
  211. <regex>\s+attackcontext="(\.*)"|\s+attackcontext=(\.*)\s|\s+attackcontext=(\.*)$</regex>
  212. <order>attackcontext</order>
  213. </decoder>
  214. <decoder name="fortinet-fortigate-fields-v7">
  215. <parent>fortinet-fortigate-firewall</parent>
  216. <regex>\s+attackcontextid="(\.*)"|\s+attackcontextid=(\.*)\s|\s+attackcontextid=(\.*)$</regex>
  217. <order>attackcontextid</order>
  218. </decoder>
  219. <decoder name="fortinet-fortigate-fields-v7">
  220. <parent>fortinet-fortigate-firewall</parent>
  221. <regex>\s+attackid="(\.*)"|\s+attackid=(\.*)\s|\s+attackid=(\.*)$</regex>
  222. <order>attackid</order>
  223. </decoder>
  224. <decoder name="fortinet-fortigate-fields-v7">
  225. <parent>fortinet-fortigate-firewall</parent>
  226. <regex>\s+auditid="(\.*)"|\s+auditid=(\.*)\s|\s+auditid=(\.*)$</regex>
  227. <order>auditid</order>
  228. </decoder>
  229. <decoder name="fortinet-fortigate-fields-v7">
  230. <parent>fortinet-fortigate-firewall</parent>
  231. <regex>\s+auditreporttype="(\.*)"|\s+auditreporttype=(\.*)\s|\s+auditreporttype=(\.*)$</regex>
  232. <order>auditreporttype</order>
  233. </decoder>
  234. <decoder name="fortinet-fortigate-fields-v7">
  235. <parent>fortinet-fortigate-firewall</parent>
  236. <regex>\s+auditscore="(\.*)"|\s+auditscore=(\.*)\s|\s+auditscore=(\.*)$</regex>
  237. <order>auditscore</order>
  238. </decoder>
  239. <decoder name="fortinet-fortigate-fields-v7">
  240. <parent>fortinet-fortigate-firewall</parent>
  241. <regex>\s+audittime="(\.*)"|\s+audittime=(\.*)\s|\s+audittime=(\.*)$</regex>
  242. <order>audittime</order>
  243. </decoder>
  244. <decoder name="fortinet-fortigate-fields-v7">
  245. <parent>fortinet-fortigate-firewall</parent>
  246. <regex>\s+authalgo="(\.*)"|\s+authalgo=(\.*)\s|\s+authalgo=(\.*)$</regex>
  247. <order>authalgo</order>
  248. </decoder>
  249. <decoder name="fortinet-fortigate-fields-v7">
  250. <parent>fortinet-fortigate-firewall</parent>
  251. <regex>\s+authgrp="(\.*)"|\s+authgrp=(\.*)\s|\s+authgrp=(\.*)$</regex>
  252. <order>authgrp</order>
  253. </decoder>
  254. <decoder name="fortinet-fortigate-fields-v7">
  255. <parent>fortinet-fortigate-firewall</parent>
  256. <regex>\s+authid="(\.*)"|\s+authid=(\.*)\s|\s+authid=(\.*)$</regex>
  257. <order>authid</order>
  258. </decoder>
  259. <decoder name="fortinet-fortigate-fields-v7">
  260. <parent>fortinet-fortigate-firewall</parent>
  261. <regex>\s+authproto="(\.*)"|\s+authproto=(\.*)\s|\s+authproto=(\.*)$</regex>
  262. <order>authproto</order>
  263. </decoder>
  264. <decoder name="fortinet-fortigate-fields-v7">
  265. <parent>fortinet-fortigate-firewall</parent>
  266. <regex>\s+authserver="(\.*)"|\s+authserver=(\.*)\s|\s+authserver=(\.*)$</regex>
  267. <order>authserver</order>
  268. </decoder>
  269. <decoder name="fortinet-fortigate-fields-v7">
  270. <parent>fortinet-fortigate-firewall</parent>
  271. <regex>\s+bandwidth="(\.*)"|\s+bandwidth=(\.*)\s|\s+bandwidth=(\.*)$</regex>
  272. <order>bandwidth</order>
  273. </decoder>
  274. <decoder name="fortinet-fortigate-fields-v7">
  275. <parent>fortinet-fortigate-firewall</parent>
  276. <regex>\s+banned_rule="(\.*)"|\s+banned_rule=(\.*)\s|\s+banned_rule=(\.*)$</regex>
  277. <order>banned_rule</order>
  278. </decoder>
  279. <decoder name="fortinet-fortigate-fields-v7">
  280. <parent>fortinet-fortigate-firewall</parent>
  281. <regex>\s+banned_src="(\.*)"|\s+banned_src=(\.*)\s|\s+banned_src=(\.*)$</regex>
  282. <order>banned_src</order>
  283. </decoder>
  284. <decoder name="fortinet-fortigate-fields-v7">
  285. <parent>fortinet-fortigate-firewall</parent>
  286. <regex>\s+banword="(\.*)"|\s+banword=(\.*)\s|\s+banword=(\.*)$</regex>
  287. <order>banword</order>
  288. </decoder>
  289. <decoder name="fortinet-fortigate-fields-v7">
  290. <parent>fortinet-fortigate-firewall</parent>
  291. <regex>\s+bibandwidth="(\.*)"|\s+bibandwidth=(\.*)\s|\s+bibandwidth=(\.*)$</regex>
  292. <order>bibandwidth</order>
  293. </decoder>
  294. <decoder name="fortinet-fortigate-fields-v7">
  295. <parent>fortinet-fortigate-firewall</parent>
  296. <regex>\s+bibandwidthavailable="(\.*)"|\s+bibandwidthavailable=(\.*)\s|\s+bibandwidthavailable=(\.*)$</regex>
  297. <order>bibandwidthavailable</order>
  298. </decoder>
  299. <decoder name="fortinet-fortigate-fields-v7">
  300. <parent>fortinet-fortigate-firewall</parent>
  301. <regex>\s+bibandwidthused="(\.*)"|\s+bibandwidthused=(\.*)\s|\s+bibandwidthused=(\.*)$</regex>
  302. <order>bibandwidthused</order>
  303. </decoder>
  304. <decoder name="fortinet-fortigate-fields-v7">
  305. <parent>fortinet-fortigate-firewall</parent>
  306. <regex>\s+botnetdomain="(\.*)"|\s+botnetdomain=(\.*)\s|\s+botnetdomain=(\.*)$</regex>
  307. <order>botnetdomain</order>
  308. </decoder>
  309. <decoder name="fortinet-fortigate-fields-v7">
  310. <parent>fortinet-fortigate-firewall</parent>
  311. <regex>\s+botnetip="(\.*)"|\s+botnetip=(\.*)\s|\s+botnetip=(\.*)$</regex>
  312. <order>botnetip</order>
  313. </decoder>
  314. <decoder name="fortinet-fortigate-fields-v7">
  315. <parent>fortinet-fortigate-firewall</parent>
  316. <regex>\s+bssid="(\.*)"|\s+bssid=(\.*)\s|\s+bssid=(\.*)$</regex>
  317. <order>bssid</order>
  318. </decoder>
  319. <decoder name="fortinet-fortigate-fields-v7">
  320. <parent>fortinet-fortigate-firewall</parent>
  321. <regex>\s+call_id="(\.*)"|\s+call_id=(\.*)\s|\s+call_id=(\.*)$</regex>
  322. <order>call_id</order>
  323. </decoder>
  324. <decoder name="fortinet-fortigate-fields-v7">
  325. <parent>fortinet-fortigate-firewall</parent>
  326. <regex>\s+carrier_ep="(\.*)"|\s+carrier_ep=(\.*)\s|\s+carrier_ep=(\.*)$</regex>
  327. <order>carrier_ep</order>
  328. </decoder>
  329. <decoder name="fortinet-fortigate-fields-v7">
  330. <parent>fortinet-fortigate-firewall</parent>
  331. <regex>\s+casb="(\.*)"|\s+casb=(\.*)\s|\s+casb=(\.*)$</regex>
  332. <order>casb</order>
  333. </decoder>
  334. <decoder name="fortinet-fortigate-fields-v7">
  335. <parent>fortinet-fortigate-firewall</parent>
  336. <regex>\s+cat="(\.*)"|\s+cat=(\.*)\s|\s+cat=(\.*)$</regex>
  337. <order>cat</order>
  338. </decoder>
  339. <decoder name="fortinet-fortigate-fields-v7">
  340. <parent>fortinet-fortigate-firewall</parent>
  341. <regex>\s+catdesc="(\.*)"|\s+catdesc=(\.*)\s|\s+catdesc=(\.*)$</regex>
  342. <order>catdesc</order>
  343. </decoder>
  344. <decoder name="fortinet-fortigate-fields-v7">
  345. <parent>fortinet-fortigate-firewall</parent>
  346. <regex>\s+category="(\.*)"|\s+category=(\.*)\s|\s+category=(\.*)$</regex>
  347. <order>category</order>
  348. </decoder>
  349. <decoder name="fortinet-fortigate-fields-v7">
  350. <parent>fortinet-fortigate-firewall</parent>
  351. <regex>\s+cc="(\.*)"|\s+cc=(\.*)\s|\s+cc=(\.*)$</regex>
  352. <order>cc</order>
  353. </decoder>
  354. <decoder name="fortinet-fortigate-fields-v7">
  355. <parent>fortinet-fortigate-firewall</parent>
  356. <regex>\s+ccertissuer="(\.*)"|\s+ccertissuer=(\.*)\s|\s+ccertissuer=(\.*)$</regex>
  357. <order>ccertissuer</order>
  358. </decoder>
  359. <decoder name="fortinet-fortigate-fields-v7">
  360. <parent>fortinet-fortigate-firewall</parent>
  361. <regex>\s+cdrcontent="(\.*)"|\s+cdrcontent=(\.*)\s|\s+cdrcontent=(\.*)$</regex>
  362. <order>cdrcontent</order>
  363. </decoder>
  364. <decoder name="fortinet-fortigate-fields-v7">
  365. <parent>fortinet-fortigate-firewall</parent>
  366. <regex>\s+centralnatid="(\.*)"|\s+centralnatid=(\.*)\s|\s+centralnatid=(\.*)$</regex>
  367. <order>centralnatid</order>
  368. </decoder>
  369. <decoder name="fortinet-fortigate-fields-v7">
  370. <parent>fortinet-fortigate-firewall</parent>
  371. <regex>\s+cert="(\.*)"|\s+cert=(\.*)\s|\s+cert=(\.*)$</regex>
  372. <order>cert</order>
  373. </decoder>
  374. <decoder name="fortinet-fortigate-fields-v7">
  375. <parent>fortinet-fortigate-firewall</parent>
  376. <regex>\s+certdesc="(\.*)"|\s+certdesc=(\.*)\s|\s+certdesc=(\.*)$</regex>
  377. <order>certdesc</order>
  378. </decoder>
  379. <decoder name="fortinet-fortigate-fields-v7">
  380. <parent>fortinet-fortigate-firewall</parent>
  381. <regex>\s+certhash="(\.*)"|\s+certhash=(\.*)\s|\s+certhash=(\.*)$</regex>
  382. <order>certhash</order>
  383. </decoder>
  384. <decoder name="fortinet-fortigate-fields-v7">
  385. <parent>fortinet-fortigate-firewall</parent>
  386. <regex>\s+cfgattr="(\.*)"|\s+cfgattr=(\.*)\s|\s+cfgattr=(\.*)$</regex>
  387. <order>cfgattr</order>
  388. </decoder>
  389. <decoder name="fortinet-fortigate-fields-v7">
  390. <parent>fortinet-fortigate-firewall</parent>
  391. <regex>\s+cfgobj="(\.*)"|\s+cfgobj=(\.*)\s|\s+cfgobj=(\.*)$</regex>
  392. <order>cfgobj</order>
  393. </decoder>
  394. <decoder name="fortinet-fortigate-fields-v7">
  395. <parent>fortinet-fortigate-firewall</parent>
  396. <regex>\s+cfgpath="(\.*)"|\s+cfgpath=(\.*)\s|\s+cfgpath=(\.*)$</regex>
  397. <order>cfgpath</order>
  398. </decoder>
  399. <decoder name="fortinet-fortigate-fields-v7">
  400. <parent>fortinet-fortigate-firewall</parent>
  401. <regex>\s+cfgtid="(\.*)"|\s+cfgtid=(\.*)\s|\s+cfgtid=(\.*)$</regex>
  402. <order>cfgtid</order>
  403. </decoder>
  404. <decoder name="fortinet-fortigate-fields-v7">
  405. <parent>fortinet-fortigate-firewall</parent>
  406. <regex>\s+cfgtxpower="(\.*)"|\s+cfgtxpower=(\.*)\s|\s+cfgtxpower=(\.*)$</regex>
  407. <order>cfgtxpower</order>
  408. </decoder>
  409. <decoder name="fortinet-fortigate-fields-v7">
  410. <parent>fortinet-fortigate-firewall</parent>
  411. <regex>\s+cfseid="(\.*)"|\s+cfseid=(\.*)\s|\s+cfseid=(\.*)$</regex>
  412. <order>cfseid</order>
  413. </decoder>
  414. <decoder name="fortinet-fortigate-fields-v7">
  415. <parent>fortinet-fortigate-firewall</parent>
  416. <regex>\s+cfseidaddr="(\.*)"|\s+cfseidaddr=(\.*)\s|\s+cfseidaddr=(\.*)$</regex>
  417. <order>cfseidaddr</order>
  418. </decoder>
  419. <decoder name="fortinet-fortigate-fields-v7">
  420. <parent>fortinet-fortigate-firewall</parent>
  421. <regex>\s+cggsn="(\.*)"|\s+cggsn=(\.*)\s|\s+cggsn=(\.*)$</regex>
  422. <order>cggsn</order>
  423. </decoder>
  424. <decoder name="fortinet-fortigate-fields-v7">
  425. <parent>fortinet-fortigate-firewall</parent>
  426. <regex>\s+cgsn="(\.*)"|\s+cgsn=(\.*)\s|\s+cgsn=(\.*)$</regex>
  427. <order>cgsn</order>
  428. </decoder>
  429. <decoder name="fortinet-fortigate-fields-v7">
  430. <parent>fortinet-fortigate-firewall</parent>
  431. <regex>\s+channel="(\.*)"|\s+channel=(\.*)\s|\s+channel=(\.*)$</regex>
  432. <order>channel</order>
  433. </decoder>
  434. <decoder name="fortinet-fortigate-fields-v7">
  435. <parent>fortinet-fortigate-firewall</parent>
  436. <regex>\s+channeltype="(\.*)"|\s+channeltype=(\.*)\s|\s+channeltype=(\.*)$</regex>
  437. <order>channeltype</order>
  438. </decoder>
  439. <decoder name="fortinet-fortigate-fields-v7">
  440. <parent>fortinet-fortigate-firewall</parent>
  441. <regex>\s+chassisid="(\.*)"|\s+chassisid=(\.*)\s|\s+chassisid=(\.*)$</regex>
  442. <order>chassisid</order>
  443. </decoder>
  444. <decoder name="fortinet-fortigate-fields-v7">
  445. <parent>fortinet-fortigate-firewall</parent>
  446. <regex>\s+checksum="(\.*)"|\s+checksum=(\.*)\s|\s+checksum=(\.*)$</regex>
  447. <order>checksum</order>
  448. </decoder>
  449. <decoder name="fortinet-fortigate-fields-v7">
  450. <parent>fortinet-fortigate-firewall</parent>
  451. <regex>\s+chgheaders="(\.*)"|\s+chgheaders=(\.*)\s|\s+chgheaders=(\.*)$</regex>
  452. <order>chgheaders</order>
  453. </decoder>
  454. <decoder name="fortinet-fortigate-fields-v7">
  455. <parent>fortinet-fortigate-firewall</parent>
  456. <regex>\s+cipher="(\.*)"|\s+cipher=(\.*)\s|\s+cipher=(\.*)$</regex>
  457. <order>cipher</order>
  458. </decoder>
  459. <decoder name="fortinet-fortigate-fields-v7">
  460. <parent>fortinet-fortigate-firewall</parent>
  461. <regex>\s+clashtunnelidx="(\.*)"|\s+clashtunnelidx=(\.*)\s|\s+clashtunnelidx=(\.*)$</regex>
  462. <order>clashtunnelidx</order>
  463. </decoder>
  464. <decoder name="fortinet-fortigate-fields-v7">
  465. <parent>fortinet-fortigate-firewall</parent>
  466. <regex>\s+cldobjid="(\.*)"|\s+cldobjid=(\.*)\s|\s+cldobjid=(\.*)$</regex>
  467. <order>cldobjid</order>
  468. </decoder>
  469. <decoder name="fortinet-fortigate-fields-v7">
  470. <parent>fortinet-fortigate-firewall</parent>
  471. <regex>\s+client_addr="(\.*)"|\s+client_addr=(\.*)\s|\s+client_addr=(\.*)$</regex>
  472. <order>client_addr</order>
  473. </decoder>
  474. <decoder name="fortinet-fortigate-fields-v7">
  475. <parent>fortinet-fortigate-firewall</parent>
  476. <regex>\s+clientcert="(\.*)"|\s+clientcert=(\.*)\s|\s+clientcert=(\.*)$</regex>
  477. <order>clientcert</order>
  478. </decoder>
  479. <decoder name="fortinet-fortigate-fields-v7">
  480. <parent>fortinet-fortigate-firewall</parent>
  481. <regex>\s+clientdeviceems="(\.*)"|\s+clientdeviceems=(\.*)\s|\s+clientdeviceems=(\.*)$</regex>
  482. <order>clientdeviceems</order>
  483. </decoder>
  484. <decoder name="fortinet-fortigate-fields-v7">
  485. <parent>fortinet-fortigate-firewall</parent>
  486. <regex>\s+clientdeviceid="(\.*)"|\s+clientdeviceid=(\.*)\s|\s+clientdeviceid=(\.*)$</regex>
  487. <order>clientdeviceid</order>
  488. </decoder>
  489. <decoder name="fortinet-fortigate-fields-v7">
  490. <parent>fortinet-fortigate-firewall</parent>
  491. <regex>\s+clientdevicemanageable="(\.*)"|\s+clientdevicemanageable=(\.*)\s|\s+clientdevicemanageable=(\.*)$</regex>
  492. <order>clientdevicemanageable</order>
  493. </decoder>
  494. <decoder name="fortinet-fortigate-fields-v7">
  495. <parent>fortinet-fortigate-firewall</parent>
  496. <regex>\s+clientdeviceowner="(\.*)"|\s+clientdeviceowner=(\.*)\s|\s+clientdeviceowner=(\.*)$</regex>
  497. <order>clientdeviceowner</order>
  498. </decoder>
  499. <decoder name="fortinet-fortigate-fields-v7">
  500. <parent>fortinet-fortigate-firewall</parent>
  501. <regex>\s+clientdevicetags="(\.*)"|\s+clientdevicetags=(\.*)\s|\s+clientdevicetags=(\.*)$</regex>
  502. <order>clientdevicetags</order>
  503. </decoder>
  504. <decoder name="fortinet-fortigate-fields-v7">
  505. <parent>fortinet-fortigate-firewall</parent>
  506. <regex>\s+cloudaction="(\.*)"|\s+cloudaction=(\.*)\s|\s+cloudaction=(\.*)$</regex>
  507. <order>cloudaction</order>
  508. </decoder>
  509. <decoder name="fortinet-fortigate-fields-v7">
  510. <parent>fortinet-fortigate-firewall</parent>
  511. <regex>\s+clouddevice="(\.*)"|\s+clouddevice=(\.*)\s|\s+clouddevice=(\.*)$</regex>
  512. <order>clouddevice</order>
  513. </decoder>
  514. <decoder name="fortinet-fortigate-fields-v7">
  515. <parent>fortinet-fortigate-firewall</parent>
  516. <regex>\s+clouduser="(\.*)"|\s+clouduser=(\.*)\s|\s+clouduser=(\.*)$</regex>
  517. <order>clouduser</order>
  518. </decoder>
  519. <decoder name="fortinet-fortigate-fields-v7">
  520. <parent>fortinet-fortigate-firewall</parent>
  521. <regex>\s+cmdbpathname="(\.*)"|\s+cmdbpathname=(\.*)\s|\s+cmdbpathname=(\.*)$</regex>
  522. <order>cmdbpathname</order>
  523. </decoder>
  524. <decoder name="fortinet-fortigate-fields-v7">
  525. <parent>fortinet-fortigate-firewall</parent>
  526. <regex>\s+cmdbtablename="(\.*)"|\s+cmdbtablename=(\.*)\s|\s+cmdbtablename=(\.*)$</regex>
  527. <order>cmdbtablename</order>
  528. </decoder>
  529. <decoder name="fortinet-fortigate-fields-v7">
  530. <parent>fortinet-fortigate-firewall</parent>
  531. <regex>\s+cn="(\.*)"|\s+cn=(\.*)\s|\s+cn=(\.*)$</regex>
  532. <order>cn</order>
  533. </decoder>
  534. <decoder name="fortinet-fortigate-fields-v7">
  535. <parent>fortinet-fortigate-firewall</parent>
  536. <regex>\s+column="(\.*)"|\s+column=(\.*)\s|\s+column=(\.*)$</regex>
  537. <order>column</order>
  538. </decoder>
  539. <decoder name="fortinet-fortigate-fields-v7">
  540. <parent>fortinet-fortigate-firewall</parent>
  541. <regex>\s+command="(\.*)"|\s+command=(\.*)\s|\s+command=(\.*)$</regex>
  542. <order>command</order>
  543. </decoder>
  544. <decoder name="fortinet-fortigate-fields-v7">
  545. <parent>fortinet-fortigate-firewall</parent>
  546. <regex>\s+comment="(\.*)"|\s+comment=(\.*)\s|\s+comment=(\.*)$</regex>
  547. <order>comment</order>
  548. </decoder>
  549. <decoder name="fortinet-fortigate-fields-v7">
  550. <parent>fortinet-fortigate-firewall</parent>
  551. <regex>\s+community="(\.*)"|\s+community=(\.*)\s|\s+community=(\.*)$</regex>
  552. <order>community</order>
  553. </decoder>
  554. <decoder name="fortinet-fortigate-fields-v7">
  555. <parent>fortinet-fortigate-firewall</parent>
  556. <regex>\s+components="(\.*)"|\s+components=(\.*)\s|\s+components=(\.*)$</regex>
  557. <order>components</order>
  558. </decoder>
  559. <decoder name="fortinet-fortigate-fields-v7">
  560. <parent>fortinet-fortigate-firewall</parent>
  561. <regex>\s+configcountry="(\.*)"|\s+configcountry=(\.*)\s|\s+configcountry=(\.*)$</regex>
  562. <order>configcountry</order>
  563. </decoder>
  564. <decoder name="fortinet-fortigate-fields-v7">
  565. <parent>fortinet-fortigate-firewall</parent>
  566. <regex>\s+conflictcount="(\.*)"|\s+conflictcount=(\.*)\s|\s+conflictcount=(\.*)$</regex>
  567. <order>conflictcount</order>
  568. </decoder>
  569. <decoder name="fortinet-fortigate-fields-v7">
  570. <parent>fortinet-fortigate-firewall</parent>
  571. <regex>\s+connection_type="(\.*)"|\s+connection_type=(\.*)\s|\s+connection_type=(\.*)$</regex>
  572. <order>connection_type</order>
  573. </decoder>
  574. <decoder name="fortinet-fortigate-fields-v7">
  575. <parent>fortinet-fortigate-firewall</parent>
  576. <regex>\s+conserve="(\.*)"|\s+conserve=(\.*)\s|\s+conserve=(\.*)$</regex>
  577. <order>conserve</order>
  578. </decoder>
  579. <decoder name="fortinet-fortigate-fields-v7">
  580. <parent>fortinet-fortigate-firewall</parent>
  581. <regex>\s+constraint="(\.*)"|\s+constraint=(\.*)\s|\s+constraint=(\.*)$</regex>
  582. <order>constraint</order>
  583. </decoder>
  584. <decoder name="fortinet-fortigate-fields-v7">
  585. <parent>fortinet-fortigate-firewall</parent>
  586. <regex>\s+contentdisarmed="(\.*)"|\s+contentdisarmed=(\.*)\s|\s+contentdisarmed=(\.*)$</regex>
  587. <order>contentdisarmed</order>
  588. </decoder>
  589. <decoder name="fortinet-fortigate-fields-v7">
  590. <parent>fortinet-fortigate-firewall</parent>
  591. <regex>\s+contentencoding="(\.*)"|\s+contentencoding=(\.*)\s|\s+contentencoding=(\.*)$</regex>
  592. <order>contentencoding</order>
  593. </decoder>
  594. <decoder name="fortinet-fortigate-fields-v7">
  595. <parent>fortinet-fortigate-firewall</parent>
  596. <regex>\s+contenttype="(\.*)"|\s+contenttype=(\.*)\s|\s+contenttype=(\.*)$</regex>
  597. <order>contenttype</order>
  598. </decoder>
  599. <decoder name="fortinet-fortigate-fields-v7">
  600. <parent>fortinet-fortigate-firewall</parent>
  601. <regex>\s+cookies="(\.*)"|\s+cookies=(\.*)\s|\s+cookies=(\.*)$</regex>
  602. <order>cookies</order>
  603. </decoder>
  604. <decoder name="fortinet-fortigate-fields-v7">
  605. <parent>fortinet-fortigate-firewall</parent>
  606. <regex>\s+core="(\.*)"|\s+core=(\.*)\s|\s+core=(\.*)$</regex>
  607. <order>core</order>
  608. </decoder>
  609. <decoder name="fortinet-fortigate-fields-v7">
  610. <parent>fortinet-fortigate-firewall</parent>
  611. <regex>\s+count="(\.*)"|\s+count=(\.*)\s|\s+count=(\.*)$</regex>
  612. <order>count</order>
  613. </decoder>
  614. <decoder name="fortinet-fortigate-fields-v7">
  615. <parent>fortinet-fortigate-firewall</parent>
  616. <regex>\s+countapp="(\.*)"|\s+countapp=(\.*)\s|\s+countapp=(\.*)$</regex>
  617. <order>countapp</order>
  618. </decoder>
  619. <decoder name="fortinet-fortigate-fields-v7">
  620. <parent>fortinet-fortigate-firewall</parent>
  621. <regex>\s+countav="(\.*)"|\s+countav=(\.*)\s|\s+countav=(\.*)$</regex>
  622. <order>countav</order>
  623. </decoder>
  624. <decoder name="fortinet-fortigate-fields-v7">
  625. <parent>fortinet-fortigate-firewall</parent>
  626. <regex>\s+countcasb="(\.*)"|\s+countcasb=(\.*)\s|\s+countcasb=(\.*)$</regex>
  627. <order>countcasb</order>
  628. </decoder>
  629. <decoder name="fortinet-fortigate-fields-v7">
  630. <parent>fortinet-fortigate-firewall</parent>
  631. <regex>\s+countcifs="(\.*)"|\s+countcifs=(\.*)\s|\s+countcifs=(\.*)$</regex>
  632. <order>countcifs</order>
  633. </decoder>
  634. <decoder name="fortinet-fortigate-fields-v7">
  635. <parent>fortinet-fortigate-firewall</parent>
  636. <regex>\s+countdlp="(\.*)"|\s+countdlp=(\.*)\s|\s+countdlp=(\.*)$</regex>
  637. <order>countdlp</order>
  638. </decoder>
  639. <decoder name="fortinet-fortigate-fields-v7">
  640. <parent>fortinet-fortigate-firewall</parent>
  641. <regex>\s+countdns="(\.*)"|\s+countdns=(\.*)\s|\s+countdns=(\.*)$</regex>
  642. <order>countdns</order>
  643. </decoder>
  644. <decoder name="fortinet-fortigate-fields-v7">
  645. <parent>fortinet-fortigate-firewall</parent>
  646. <regex>\s+countemail="(\.*)"|\s+countemail=(\.*)\s|\s+countemail=(\.*)$</regex>
  647. <order>countemail</order>
  648. </decoder>
  649. <decoder name="fortinet-fortigate-fields-v7">
  650. <parent>fortinet-fortigate-firewall</parent>
  651. <regex>\s+countff="(\.*)"|\s+countff=(\.*)\s|\s+countff=(\.*)$</regex>
  652. <order>countff</order>
  653. </decoder>
  654. <decoder name="fortinet-fortigate-fields-v7">
  655. <parent>fortinet-fortigate-firewall</parent>
  656. <regex>\s+counticap="(\.*)"|\s+counticap=(\.*)\s|\s+counticap=(\.*)$</regex>
  657. <order>counticap</order>
  658. </decoder>
  659. <decoder name="fortinet-fortigate-fields-v7">
  660. <parent>fortinet-fortigate-firewall</parent>
  661. <regex>\s+countips="(\.*)"|\s+countips=(\.*)\s|\s+countips=(\.*)$</regex>
  662. <order>countips</order>
  663. </decoder>
  664. <decoder name="fortinet-fortigate-fields-v7">
  665. <parent>fortinet-fortigate-firewall</parent>
  666. <regex>\s+countsctpf="(\.*)"|\s+countsctpf=(\.*)\s|\s+countsctpf=(\.*)$</regex>
  667. <order>countsctpf</order>
  668. </decoder>
  669. <decoder name="fortinet-fortigate-fields-v7">
  670. <parent>fortinet-fortigate-firewall</parent>
  671. <regex>\s+countssh="(\.*)"|\s+countssh=(\.*)\s|\s+countssh=(\.*)$</regex>
  672. <order>countssh</order>
  673. </decoder>
  674. <decoder name="fortinet-fortigate-fields-v7">
  675. <parent>fortinet-fortigate-firewall</parent>
  676. <regex>\s+countssl="(\.*)"|\s+countssl=(\.*)\s|\s+countssl=(\.*)$</regex>
  677. <order>countssl</order>
  678. </decoder>
  679. <decoder name="fortinet-fortigate-fields-v7">
  680. <parent>fortinet-fortigate-firewall</parent>
  681. <regex>\s+countvpatch="(\.*)"|\s+countvpatch=(\.*)\s|\s+countvpatch=(\.*)$</regex>
  682. <order>countvpatch</order>
  683. </decoder>
  684. <decoder name="fortinet-fortigate-fields-v7">
  685. <parent>fortinet-fortigate-firewall</parent>
  686. <regex>\s+countwaf="(\.*)"|\s+countwaf=(\.*)\s|\s+countwaf=(\.*)$</regex>
  687. <order>countwaf</order>
  688. </decoder>
  689. <decoder name="fortinet-fortigate-fields-v7">
  690. <parent>fortinet-fortigate-firewall</parent>
  691. <regex>\s+countweb="(\.*)"|\s+countweb=(\.*)\s|\s+countweb=(\.*)$</regex>
  692. <order>countweb</order>
  693. </decoder>
  694. <decoder name="fortinet-fortigate-fields-v7">
  695. <parent>fortinet-fortigate-firewall</parent>
  696. <regex>\s+countztna="(\.*)"|\s+countztna=(\.*)\s|\s+countztna=(\.*)$</regex>
  697. <order>countztna</order>
  698. </decoder>
  699. <decoder name="fortinet-fortigate-fields-v7">
  700. <parent>fortinet-fortigate-firewall</parent>
  701. <regex>\s+cpaddr="(\.*)"|\s+cpaddr=(\.*)\s|\s+cpaddr=(\.*)$</regex>
  702. <order>cpaddr</order>
  703. </decoder>
  704. <decoder name="fortinet-fortigate-fields-v7">
  705. <parent>fortinet-fortigate-firewall</parent>
  706. <regex>\s+cpdladdr="(\.*)"|\s+cpdladdr=(\.*)\s|\s+cpdladdr=(\.*)$</regex>
  707. <order>cpdladdr</order>
  708. </decoder>
  709. <decoder name="fortinet-fortigate-fields-v7">
  710. <parent>fortinet-fortigate-firewall</parent>
  711. <regex>\s+cpdlisraddr="(\.*)"|\s+cpdlisraddr=(\.*)\s|\s+cpdlisraddr=(\.*)$</regex>
  712. <order>cpdlisraddr</order>
  713. </decoder>
  714. <decoder name="fortinet-fortigate-fields-v7">
  715. <parent>fortinet-fortigate-firewall</parent>
  716. <regex>\s+cpdlisrteid="(\.*)"|\s+cpdlisrteid=(\.*)\s|\s+cpdlisrteid=(\.*)$</regex>
  717. <order>cpdlisrteid</order>
  718. </decoder>
  719. <decoder name="fortinet-fortigate-fields-v7">
  720. <parent>fortinet-fortigate-firewall</parent>
  721. <regex>\s+cpdlteid="(\.*)"|\s+cpdlteid=(\.*)\s|\s+cpdlteid=(\.*)$</regex>
  722. <order>cpdlteid</order>
  723. </decoder>
  724. <decoder name="fortinet-fortigate-fields-v7">
  725. <parent>fortinet-fortigate-firewall</parent>
  726. <regex>\s+cpteid="(\.*)"|\s+cpteid=(\.*)\s|\s+cpteid=(\.*)$</regex>
  727. <order>cpteid</order>
  728. </decoder>
  729. <decoder name="fortinet-fortigate-fields-v7">
  730. <parent>fortinet-fortigate-firewall</parent>
  731. <regex>\s+cpu="(\.*)"|\s+cpu=(\.*)\s|\s+cpu=(\.*)$</regex>
  732. <order>cpu</order>
  733. </decoder>
  734. <decoder name="fortinet-fortigate-fields-v7">
  735. <parent>fortinet-fortigate-firewall</parent>
  736. <regex>\s+cpuladdr="(\.*)"|\s+cpuladdr=(\.*)\s|\s+cpuladdr=(\.*)$</regex>
  737. <order>cpuladdr</order>
  738. </decoder>
  739. <decoder name="fortinet-fortigate-fields-v7">
  740. <parent>fortinet-fortigate-firewall</parent>
  741. <regex>\s+cpulteid="(\.*)"|\s+cpulteid=(\.*)\s|\s+cpulteid=(\.*)$</regex>
  742. <order>cpulteid</order>
  743. </decoder>
  744. <decoder name="fortinet-fortigate-fields-v7">
  745. <parent>fortinet-fortigate-firewall</parent>
  746. <regex>\s+craction="(\.*)"|\s+craction=(\.*)\s|\s+craction=(\.*)$</regex>
  747. <order>craction</order>
  748. </decoder>
  749. <decoder name="fortinet-fortigate-fields-v7">
  750. <parent>fortinet-fortigate-firewall</parent>
  751. <regex>\s+created="(\.*)"|\s+created=(\.*)\s|\s+created=(\.*)$</regex>
  752. <order>created</order>
  753. </decoder>
  754. <decoder name="fortinet-fortigate-fields-v7">
  755. <parent>fortinet-fortigate-firewall</parent>
  756. <regex>\s+criticalcount="(\.*)"|\s+criticalcount=(\.*)\s|\s+criticalcount=(\.*)$</regex>
  757. <order>criticalcount</order>
  758. </decoder>
  759. <decoder name="fortinet-fortigate-fields-v7">
  760. <parent>fortinet-fortigate-firewall</parent>
  761. <regex>\s+crl="(\.*)"|\s+crl=(\.*)\s|\s+crl=(\.*)$</regex>
  762. <order>crl</order>
  763. </decoder>
  764. <decoder name="fortinet-fortigate-fields-v7">
  765. <parent>fortinet-fortigate-firewall</parent>
  766. <regex>\s+crlevel="(\.*)"|\s+crlevel=(\.*)\s|\s+crlevel=(\.*)$</regex>
  767. <order>crlevel</order>
  768. </decoder>
  769. <decoder name="fortinet-fortigate-fields-v7">
  770. <parent>fortinet-fortigate-firewall</parent>
  771. <regex>\s+crscore="(\.*)"|\s+crscore=(\.*)\s|\s+crscore=(\.*)$</regex>
  772. <order>crscore</order>
  773. </decoder>
  774. <decoder name="fortinet-fortigate-fields-v7">
  775. <parent>fortinet-fortigate-firewall</parent>
  776. <regex>\s+csgsn="(\.*)"|\s+csgsn=(\.*)\s|\s+csgsn=(\.*)$</regex>
  777. <order>csgsn</order>
  778. </decoder>
  779. <decoder name="fortinet-fortigate-fields-v7">
  780. <parent>fortinet-fortigate-firewall</parent>
  781. <regex>\s+cveid="(\.*)"|\s+cveid=(\.*)\s|\s+cveid=(\.*)$</regex>
  782. <order>cveid</order>
  783. </decoder>
  784. <decoder name="fortinet-fortigate-fields-v7">
  785. <parent>fortinet-fortigate-firewall</parent>
  786. <regex>\s+daddr="(\.*)"|\s+daddr=(\.*)\s|\s+daddr=(\.*)$</regex>
  787. <order>daddr</order>
  788. </decoder>
  789. <decoder name="fortinet-fortigate-fields-v7">
  790. <parent>fortinet-fortigate-firewall</parent>
  791. <regex>\s+daemon="(\.*)"|\s+daemon=(\.*)\s|\s+daemon=(\.*)$</regex>
  792. <order>daemon</order>
  793. </decoder>
  794. <decoder name="fortinet-fortigate-fields-v7">
  795. <parent>fortinet-fortigate-firewall</parent>
  796. <regex>\s+datarange="(\.*)"|\s+datarange=(\.*)\s|\s+datarange=(\.*)$</regex>
  797. <order>datarange</order>
  798. </decoder>
  799. <decoder name="fortinet-fortigate-fields-v7">
  800. <parent>fortinet-fortigate-firewall</parent>
  801. <regex>date="(\.*)"|date=(\.*)\s|date=(\.*)$</regex>
  802. <order>date</order>
  803. </decoder>
  804. <decoder name="fortinet-fortigate-fields-v7">
  805. <parent>fortinet-fortigate-firewall</parent>
  806. <regex>\s+ddnsserver="(\.*)"|\s+ddnsserver=(\.*)\s|\s+ddnsserver=(\.*)$</regex>
  807. <order>ddnsserver</order>
  808. </decoder>
  809. <decoder name="fortinet-fortigate-fields-v7">
  810. <parent>fortinet-fortigate-firewall</parent>
  811. <regex>\s+deny_cause="(\.*)"|\s+deny_cause=(\.*)\s|\s+deny_cause=(\.*)$</regex>
  812. <order>deny_cause</order>
  813. </decoder>
  814. <decoder name="fortinet-fortigate-fields-v7">
  815. <parent>fortinet-fortigate-firewall</parent>
  816. <regex>\s+desc="(\.*)"|\s+desc=(\.*)\s|\s+desc=(\.*)$</regex>
  817. <order>desc</order>
  818. </decoder>
  819. <decoder name="fortinet-fortigate-fields-v7">
  820. <parent>fortinet-fortigate-firewall</parent>
  821. <regex>\s+detectionmethod="(\.*)"|\s+detectionmethod=(\.*)\s|\s+detectionmethod=(\.*)$</regex>
  822. <order>detectionmethod</order>
  823. </decoder>
  824. <decoder name="fortinet-fortigate-fields-v7">
  825. <parent>fortinet-fortigate-firewall</parent>
  826. <regex>\s+devid="(\.*)"|\s+devid=(\.*)\s|\s+devid=(\.*)$</regex>
  827. <order>devid</order>
  828. </decoder>
  829. <decoder name="fortinet-fortigate-fields-v7">
  830. <parent>fortinet-fortigate-firewall</parent>
  831. <regex>\s+devintfname="(\.*)"|\s+devintfname=(\.*)\s|\s+devintfname=(\.*)$</regex>
  832. <order>devintfname</order>
  833. </decoder>
  834. <decoder name="fortinet-fortigate-fields-v7">
  835. <parent>fortinet-fortigate-firewall</parent>
  836. <regex>\s+devtype="(\.*)"|\s+devtype=(\.*)\s|\s+devtype=(\.*)$</regex>
  837. <order>devtype</order>
  838. </decoder>
  839. <decoder name="fortinet-fortigate-fields-v7">
  840. <parent>fortinet-fortigate-firewall</parent>
  841. <regex>\s+dhcp_msg="(\.*)"|\s+dhcp_msg=(\.*)\s|\s+dhcp_msg=(\.*)$</regex>
  842. <order>dhcp_msg</order>
  843. </decoder>
  844. <decoder name="fortinet-fortigate-fields-v7">
  845. <parent>fortinet-fortigate-firewall</parent>
  846. <regex>\s+dintf="(\.*)"|\s+dintf=(\.*)\s|\s+dintf=(\.*)$</regex>
  847. <order>dintf</order>
  848. </decoder>
  849. <decoder name="fortinet-fortigate-fields-v7">
  850. <parent>fortinet-fortigate-firewall</parent>
  851. <regex>\s+dir="(\.*)"|\s+dir=(\.*)\s|\s+dir=(\.*)$</regex>
  852. <order>dir</order>
  853. </decoder>
  854. <decoder name="fortinet-fortigate-fields-v7">
  855. <parent>fortinet-fortigate-firewall</parent>
  856. <regex>\s+direction="(\.*)"|\s+direction=(\.*)\s|\s+direction=(\.*)$</regex>
  857. <order>direction</order>
  858. </decoder>
  859. <decoder name="fortinet-fortigate-fields-v7">
  860. <parent>fortinet-fortigate-firewall</parent>
  861. <regex>\s+disk="(\.*)"|\s+disk=(\.*)\s|\s+disk=(\.*)$</regex>
  862. <order>disk</order>
  863. </decoder>
  864. <decoder name="fortinet-fortigate-fields-v7">
  865. <parent>fortinet-fortigate-firewall</parent>
  866. <regex>\s+disklograte="(\.*)"|\s+disklograte=(\.*)\s|\s+disklograte=(\.*)$</regex>
  867. <order>disklograte</order>
  868. </decoder>
  869. <decoder name="fortinet-fortigate-fields-v7">
  870. <parent>fortinet-fortigate-firewall</parent>
  871. <regex>\s+dlp="(\.*)"|\s+dlp=(\.*)\s|\s+dlp=(\.*)$</regex>
  872. <order>dlp</order>
  873. </decoder>
  874. <decoder name="fortinet-fortigate-fields-v7">
  875. <parent>fortinet-fortigate-firewall</parent>
  876. <regex>\s+dlpextra="(\.*)"|\s+dlpextra=(\.*)\s|\s+dlpextra=(\.*)$</regex>
  877. <order>dlpextra</order>
  878. </decoder>
  879. <decoder name="fortinet-fortigate-fields-v7">
  880. <parent>fortinet-fortigate-firewall</parent>
  881. <regex>\s+dns="(\.*)"|\s+dns=(\.*)\s|\s+dns=(\.*)$</regex>
  882. <order>dns</order>
  883. </decoder>
  884. <decoder name="fortinet-fortigate-fields-v7">
  885. <parent>fortinet-fortigate-firewall</parent>
  886. <regex>\s+docsource="(\.*)"|\s+docsource=(\.*)\s|\s+docsource=(\.*)$</regex>
  887. <order>docsource</order>
  888. </decoder>
  889. <decoder name="fortinet-fortigate-fields-v7">
  890. <parent>fortinet-fortigate-firewall</parent>
  891. <regex>\s+domainctrlauthstate="(\.*)"|\s+domainctrlauthstate=(\.*)\s|\s+domainctrlauthstate=(\.*)$</regex>
  892. <order>domainctrlauthstate</order>
  893. </decoder>
  894. <decoder name="fortinet-fortigate-fields-v7">
  895. <parent>fortinet-fortigate-firewall</parent>
  896. <regex>\s+domainctrlauthtype="(\.*)"|\s+domainctrlauthtype=(\.*)\s|\s+domainctrlauthtype=(\.*)$</regex>
  897. <order>domainctrlauthtype</order>
  898. </decoder>
  899. <decoder name="fortinet-fortigate-fields-v7">
  900. <parent>fortinet-fortigate-firewall</parent>
  901. <regex>\s+domainctrldomain="(\.*)"|\s+domainctrldomain=(\.*)\s|\s+domainctrldomain=(\.*)$</regex>
  902. <order>domainctrldomain</order>
  903. </decoder>
  904. <decoder name="fortinet-fortigate-fields-v7">
  905. <parent>fortinet-fortigate-firewall</parent>
  906. <regex>\s+domainctrlip="(\.*)"|\s+domainctrlip=(\.*)\s|\s+domainctrlip=(\.*)$</regex>
  907. <order>domainctrlip</order>
  908. </decoder>
  909. <decoder name="fortinet-fortigate-fields-v7">
  910. <parent>fortinet-fortigate-firewall</parent>
  911. <regex>\s+domainctrlname="(\.*)"|\s+domainctrlname=(\.*)\s|\s+domainctrlname=(\.*)$</regex>
  912. <order>domainctrlname</order>
  913. </decoder>
  914. <decoder name="fortinet-fortigate-fields-v7">
  915. <parent>fortinet-fortigate-firewall</parent>
  916. <regex>\s+domainctrlprotocoltype="(\.*)"|\s+domainctrlprotocoltype=(\.*)\s|\s+domainctrlprotocoltype=(\.*)$</regex>
  917. <order>domainctrlprotocoltype</order>
  918. </decoder>
  919. <decoder name="fortinet-fortigate-fields-v7">
  920. <parent>fortinet-fortigate-firewall</parent>
  921. <regex>\s+domainctrlusername="(\.*)"|\s+domainctrlusername=(\.*)\s|\s+domainctrlusername=(\.*)$</regex>
  922. <order>domainctrlusername</order>
  923. </decoder>
  924. <decoder name="fortinet-fortigate-fields-v7">
  925. <parent>fortinet-fortigate-firewall</parent>
  926. <regex>\s+domainfilteridx="(\.*)"|\s+domainfilteridx=(\.*)\s|\s+domainfilteridx=(\.*)$</regex>
  927. <order>domainfilteridx</order>
  928. </decoder>
  929. <decoder name="fortinet-fortigate-fields-v7">
  930. <parent>fortinet-fortigate-firewall</parent>
  931. <regex>\s+domainfilterlist="(\.*)"|\s+domainfilterlist=(\.*)\s|\s+domainfilterlist=(\.*)$</regex>
  932. <order>domainfilterlist</order>
  933. </decoder>
  934. <decoder name="fortinet-fortigate-fields-v7">
  935. <parent>fortinet-fortigate-firewall</parent>
  936. <regex>\s+downbandwidthmeasured="(\.*)"|\s+downbandwidthmeasured=(\.*)\s|\s+downbandwidthmeasured=(\.*)$</regex>
  937. <order>downbandwidthmeasured</order>
  938. </decoder>
  939. <decoder name="fortinet-fortigate-fields-v7">
  940. <parent>fortinet-fortigate-firewall</parent>
  941. <regex>\s+ds="(\.*)"|\s+ds=(\.*)\s|\s+ds=(\.*)$</regex>
  942. <order>ds</order>
  943. </decoder>
  944. <decoder name="fortinet-fortigate-fields-v7">
  945. <parent>fortinet-fortigate-firewall</parent>
  946. <regex>\s+dst_host="(\.*)"|\s+dst_host=(\.*)\s|\s+dst_host=(\.*)$</regex>
  947. <order>dst_host</order>
  948. </decoder>
  949. <decoder name="fortinet-fortigate-fields-v7">
  950. <parent>fortinet-fortigate-firewall</parent>
  951. <regex>\s+dst_int="(\.*)"|\s+dst_int=(\.*)\s|\s+dst_int=(\.*)$</regex>
  952. <order>dst_int</order>
  953. </decoder>
  954. <decoder name="fortinet-fortigate-fields-v7">
  955. <parent>fortinet-fortigate-firewall</parent>
  956. <regex>\s+dst_port="(\.*)"|\s+dst_port=(\.*)\s|\s+dst_port=(\.*)$</regex>
  957. <order>dst_port</order>
  958. </decoder>
  959. <decoder name="fortinet-fortigate-fields-v7">
  960. <parent>fortinet-fortigate-firewall</parent>
  961. <regex>\s+dstauthserver="(\.*)"|\s+dstauthserver=(\.*)\s|\s+dstauthserver=(\.*)$</regex>
  962. <order>dstauthserver</order>
  963. </decoder>
  964. <decoder name="fortinet-fortigate-fields-v7">
  965. <parent>fortinet-fortigate-firewall</parent>
  966. <regex>\s+dstcity="(\.*)"|\s+dstcity=(\.*)\s|\s+dstcity=(\.*)$</regex>
  967. <order>dstcity</order>
  968. </decoder>
  969. <decoder name="fortinet-fortigate-fields-v7">
  970. <parent>fortinet-fortigate-firewall</parent>
  971. <regex>\s+dstcountry="(\.*)"|\s+dstcountry=(\.*)\s|\s+dstcountry=(\.*)$</regex>
  972. <order>dstcountry</order>
  973. </decoder>
  974. <decoder name="fortinet-fortigate-fields-v7">
  975. <parent>fortinet-fortigate-firewall</parent>
  976. <regex>\s+dstdevtype="(\.*)"|\s+dstdevtype=(\.*)\s|\s+dstdevtype=(\.*)$</regex>
  977. <order>dstdevtype</order>
  978. </decoder>
  979. <decoder name="fortinet-fortigate-fields-v7">
  980. <parent>fortinet-fortigate-firewall</parent>
  981. <regex>\s+dstfamily="(\.*)"|\s+dstfamily=(\.*)\s|\s+dstfamily=(\.*)$</regex>
  982. <order>dstfamily</order>
  983. </decoder>
  984. <decoder name="fortinet-fortigate-fields-v7">
  985. <parent>fortinet-fortigate-firewall</parent>
  986. <regex>\s+dsthwvendor="(\.*)"|\s+dsthwvendor=(\.*)\s|\s+dsthwvendor=(\.*)$</regex>
  987. <order>dsthwvendor</order>
  988. </decoder>
  989. <decoder name="fortinet-fortigate-fields-v7">
  990. <parent>fortinet-fortigate-firewall</parent>
  991. <regex>\s+dsthwversion="(\.*)"|\s+dsthwversion=(\.*)\s|\s+dsthwversion=(\.*)$</regex>
  992. <order>dsthwversion</order>
  993. </decoder>
  994. <decoder name="fortinet-fortigate-fields-v7">
  995. <parent>fortinet-fortigate-firewall</parent>
  996. <regex>\s+dstinetsvc="(\.*)"|\s+dstinetsvc=(\.*)\s|\s+dstinetsvc=(\.*)$</regex>
  997. <order>dstinetsvc</order>
  998. </decoder>
  999. <decoder name="fortinet-fortigate-fields-v7">
  1000. <parent>fortinet-fortigate-firewall</parent>
  1001. <regex>\s+dstintf="(\.*)"|\s+dstintf=(\.*)\s|\s+dstintf=(\.*)$</regex>
  1002. <order>dstintf</order>
  1003. </decoder>
  1004. <decoder name="fortinet-fortigate-fields-v7">
  1005. <parent>fortinet-fortigate-firewall</parent>
  1006. <regex>\s+dstintfrole="(\.*)"|\s+dstintfrole=(\.*)\s|\s+dstintfrole=(\.*)$</regex>
  1007. <order>dstintfrole</order>
  1008. </decoder>
  1009. <decoder name="fortinet-fortigate-fields-v7">
  1010. <parent>fortinet-fortigate-firewall</parent>
  1011. <regex>\s+dstip="(\.*)"|\s+dstip=(\.*)\s|\s+dstip=(\.*)$</regex>
  1012. <order>dstip</order>
  1013. </decoder>
  1014. <decoder name="fortinet-fortigate-fields-v7">
  1015. <parent>fortinet-fortigate-firewall</parent>
  1016. <regex>\s+dstmac="(\.*)"|\s+dstmac=(\.*)\s|\s+dstmac=(\.*)$</regex>
  1017. <order>dstmac</order>
  1018. </decoder>
  1019. <decoder name="fortinet-fortigate-fields-v7">
  1020. <parent>fortinet-fortigate-firewall</parent>
  1021. <regex>\s+dstname="(\.*)"|\s+dstname=(\.*)\s|\s+dstname=(\.*)$</regex>
  1022. <order>dstname</order>
  1023. </decoder>
  1024. <decoder name="fortinet-fortigate-fields-v7">
  1025. <parent>fortinet-fortigate-firewall</parent>
  1026. <regex>\s+dstosname="(\.*)"|\s+dstosname=(\.*)\s|\s+dstosname=(\.*)$</regex>
  1027. <order>dstosname</order>
  1028. </decoder>
  1029. <decoder name="fortinet-fortigate-fields-v7">
  1030. <parent>fortinet-fortigate-firewall</parent>
  1031. <regex>\s+dstport="(\.*)"|\s+dstport=(\.*)\s|\s+dstport=(\.*)$</regex>
  1032. <order>dstport</order>
  1033. </decoder>
  1034. <decoder name="fortinet-fortigate-fields-v7">
  1035. <parent>fortinet-fortigate-firewall</parent>
  1036. <regex>\s+dstregion="(\.*)"|\s+dstregion=(\.*)\s|\s+dstregion=(\.*)$</regex>
  1037. <order>dstregion</order>
  1038. </decoder>
  1039. <decoder name="fortinet-fortigate-fields-v7">
  1040. <parent>fortinet-fortigate-firewall</parent>
  1041. <regex>\s+dstreputation="(\.*)"|\s+dstreputation=(\.*)\s|\s+dstreputation=(\.*)$</regex>
  1042. <order>dstreputation</order>
  1043. </decoder>
  1044. <decoder name="fortinet-fortigate-fields-v7">
  1045. <parent>fortinet-fortigate-firewall</parent>
  1046. <regex>\s+dstserver="(\.*)"|\s+dstserver=(\.*)\s|\s+dstserver=(\.*)$</regex>
  1047. <order>dstserver</order>
  1048. </decoder>
  1049. <decoder name="fortinet-fortigate-fields-v7">
  1050. <parent>fortinet-fortigate-firewall</parent>
  1051. <regex>\s+dstssid="(\.*)"|\s+dstssid=(\.*)\s|\s+dstssid=(\.*)$</regex>
  1052. <order>dstssid</order>
  1053. </decoder>
  1054. <decoder name="fortinet-fortigate-fields-v7">
  1055. <parent>fortinet-fortigate-firewall</parent>
  1056. <regex>\s+dstswversion="(\.*)"|\s+dstswversion=(\.*)\s|\s+dstswversion=(\.*)$</regex>
  1057. <order>dstswversion</order>
  1058. </decoder>
  1059. <decoder name="fortinet-fortigate-fields-v7">
  1060. <parent>fortinet-fortigate-firewall</parent>
  1061. <regex>\s+dstthreatfeed="(\.*)"|\s+dstthreatfeed=(\.*)\s|\s+dstthreatfeed=(\.*)$</regex>
  1062. <order>dstthreatfeed</order>
  1063. </decoder>
  1064. <decoder name="fortinet-fortigate-fields-v7">
  1065. <parent>fortinet-fortigate-firewall</parent>
  1066. <regex>\s+dstunauthuser="(\.*)"|\s+dstunauthuser=(\.*)\s|\s+dstunauthuser=(\.*)$</regex>
  1067. <order>dstunauthuser</order>
  1068. </decoder>
  1069. <decoder name="fortinet-fortigate-fields-v7">
  1070. <parent>fortinet-fortigate-firewall</parent>
  1071. <regex>\s+dstunauthusersource="(\.*)"|\s+dstunauthusersource=(\.*)\s|\s+dstunauthusersource=(\.*)$</regex>
  1072. <order>dstunauthusersource</order>
  1073. </decoder>
  1074. <decoder name="fortinet-fortigate-fields-v7">
  1075. <parent>fortinet-fortigate-firewall</parent>
  1076. <regex>\s+dstuser="(\.*)"|\s+dstuser=(\.*)\s|\s+dstuser=(\.*)$</regex>
  1077. <order>dstuser</order>
  1078. </decoder>
  1079. <decoder name="fortinet-fortigate-fields-v7">
  1080. <parent>fortinet-fortigate-firewall</parent>
  1081. <regex>\s+dstuuid="(\.*)"|\s+dstuuid=(\.*)\s|\s+dstuuid=(\.*)$</regex>
  1082. <order>dstuuid</order>
  1083. </decoder>
  1084. <decoder name="fortinet-fortigate-fields-v7">
  1085. <parent>fortinet-fortigate-firewall</parent>
  1086. <regex>\s+dtlexp="(\.*)"|\s+dtlexp=(\.*)\s|\s+dtlexp=(\.*)$</regex>
  1087. <order>dtlexp</order>
  1088. </decoder>
  1089. <decoder name="fortinet-fortigate-fields-v7">
  1090. <parent>fortinet-fortigate-firewall</parent>
  1091. <regex>\s+dtype="(\.*)"|\s+dtype=(\.*)\s|\s+dtype=(\.*)$</regex>
  1092. <order>dtype</order>
  1093. </decoder>
  1094. <decoder name="fortinet-fortigate-fields-v7">
  1095. <parent>fortinet-fortigate-firewall</parent>
  1096. <regex>\s+duid="(\.*)"|\s+duid=(\.*)\s|\s+duid=(\.*)$</regex>
  1097. <order>duid</order>
  1098. </decoder>
  1099. <decoder name="fortinet-fortigate-fields-v7">
  1100. <parent>fortinet-fortigate-firewall</parent>
  1101. <regex>\s+duration="(\.*)"|\s+duration=(\.*)\s|\s+duration=(\.*)$</regex>
  1102. <order>duration</order>
  1103. </decoder>
  1104. <decoder name="fortinet-fortigate-fields-v7">
  1105. <parent>fortinet-fortigate-firewall</parent>
  1106. <regex>\s+durationdelta="(\.*)"|\s+durationdelta=(\.*)\s|\s+durationdelta=(\.*)$</regex>
  1107. <order>durationdelta</order>
  1108. </decoder>
  1109. <decoder name="fortinet-fortigate-fields-v7">
  1110. <parent>fortinet-fortigate-firewall</parent>
  1111. <regex>\s+eapolcnt="(\.*)"|\s+eapolcnt=(\.*)\s|\s+eapolcnt=(\.*)$</regex>
  1112. <order>eapolcnt</order>
  1113. </decoder>
  1114. <decoder name="fortinet-fortigate-fields-v7">
  1115. <parent>fortinet-fortigate-firewall</parent>
  1116. <regex>\s+eapoltype="(\.*)"|\s+eapoltype=(\.*)\s|\s+eapoltype=(\.*)$</regex>
  1117. <order>eapoltype</order>
  1118. </decoder>
  1119. <decoder name="fortinet-fortigate-fields-v7">
  1120. <parent>fortinet-fortigate-firewall</parent>
  1121. <regex>\s+emailfilter="(\.*)"|\s+emailfilter=(\.*)\s|\s+emailfilter=(\.*)$</regex>
  1122. <order>emailfilter</order>
  1123. </decoder>
  1124. <decoder name="fortinet-fortigate-fields-v7">
  1125. <parent>fortinet-fortigate-firewall</parent>
  1126. <regex>\s+emsconnection="(\.*)"|\s+emsconnection=(\.*)\s|\s+emsconnection=(\.*)$</regex>
  1127. <order>emsconnection</order>
  1128. </decoder>
  1129. <decoder name="fortinet-fortigate-fields-v7">
  1130. <parent>fortinet-fortigate-firewall</parent>
  1131. <regex>\s+encrypt="(\.*)"|\s+encrypt=(\.*)\s|\s+encrypt=(\.*)$</regex>
  1132. <order>encrypt</order>
  1133. </decoder>
  1134. <decoder name="fortinet-fortigate-fields-v7">
  1135. <parent>fortinet-fortigate-firewall</parent>
  1136. <regex>\s+encryption="(\.*)"|\s+encryption=(\.*)\s|\s+encryption=(\.*)$</regex>
  1137. <order>encryption</order>
  1138. </decoder>
  1139. <decoder name="fortinet-fortigate-fields-v7">
  1140. <parent>fortinet-fortigate-firewall</parent>
  1141. <regex>\s+end="(\.*)"|\s+end=(\.*)\s|\s+end=(\.*)$</regex>
  1142. <order>end</order>
  1143. </decoder>
  1144. <decoder name="fortinet-fortigate-fields-v7">
  1145. <parent>fortinet-fortigate-firewall</parent>
  1146. <regex>\s+endusraddress="(\.*)"|\s+endusraddress=(\.*)\s|\s+endusraddress=(\.*)$</regex>
  1147. <order>endusraddress</order>
  1148. </decoder>
  1149. <decoder name="fortinet-fortigate-fields-v7">
  1150. <parent>fortinet-fortigate-firewall</parent>
  1151. <regex>\s+epoch="(\.*)"|\s+epoch=(\.*)\s|\s+epoch=(\.*)$</regex>
  1152. <order>epoch</order>
  1153. </decoder>
  1154. <decoder name="fortinet-fortigate-fields-v7">
  1155. <parent>fortinet-fortigate-firewall</parent>
  1156. <regex>\s+error="(\.*)"|\s+error=(\.*)\s|\s+error=(\.*)$</regex>
  1157. <order>error</order>
  1158. </decoder>
  1159. <decoder name="fortinet-fortigate-fields-v7">
  1160. <parent>fortinet-fortigate-firewall</parent>
  1161. <regex>\s+error_num="(\.*)"|\s+error_num=(\.*)\s|\s+error_num=(\.*)$</regex>
  1162. <order>error_num</order>
  1163. </decoder>
  1164. <decoder name="fortinet-fortigate-fields-v7">
  1165. <parent>fortinet-fortigate-firewall</parent>
  1166. <regex>\s+errorcount="(\.*)"|\s+errorcount=(\.*)\s|\s+errorcount=(\.*)$</regex>
  1167. <order>errorcount</order>
  1168. </decoder>
  1169. <decoder name="fortinet-fortigate-fields-v7">
  1170. <parent>fortinet-fortigate-firewall</parent>
  1171. <regex>\s+espauth="(\.*)"|\s+espauth=(\.*)\s|\s+espauth=(\.*)$</regex>
  1172. <order>espauth</order>
  1173. </decoder>
  1174. <decoder name="fortinet-fortigate-fields-v7">
  1175. <parent>fortinet-fortigate-firewall</parent>
  1176. <regex>\s+esptransform="(\.*)"|\s+esptransform=(\.*)\s|\s+esptransform=(\.*)$</regex>
  1177. <order>esptransform</order>
  1178. </decoder>
  1179. <decoder name="fortinet-fortigate-fields-v7">
  1180. <parent>fortinet-fortigate-firewall</parent>
  1181. <regex>\s+event="(\.*)"|\s+event=(\.*)\s|\s+event=(\.*)$</regex>
  1182. <order>event</order>
  1183. </decoder>
  1184. <decoder name="fortinet-fortigate-fields-v7">
  1185. <parent>fortinet-fortigate-firewall</parent>
  1186. <regex>\s+event_id="(\.*)"|\s+event_id=(\.*)\s|\s+event_id=(\.*)$</regex>
  1187. <order>event_id</order>
  1188. </decoder>
  1189. <decoder name="fortinet-fortigate-fields-v7">
  1190. <parent>fortinet-fortigate-firewall</parent>
  1191. <regex>\s+eventid="(\.*)"|\s+eventid=(\.*)\s|\s+eventid=(\.*)$</regex>
  1192. <order>eventid</order>
  1193. </decoder>
  1194. <decoder name="fortinet-fortigate-fields-v7">
  1195. <parent>fortinet-fortigate-firewall</parent>
  1196. <regex>\s+eventsubtype="(\.*)"|\s+eventsubtype=(\.*)\s|\s+eventsubtype=(\.*)$</regex>
  1197. <order>eventsubtype</order>
  1198. </decoder>
  1199. <decoder name="fortinet-fortigate-fields-v7">
  1200. <parent>fortinet-fortigate-firewall</parent>
  1201. <regex>\s+eventtime="(\.*)"|\s+eventtime=(\.*)\s|\s+eventtime=(\.*)$</regex>
  1202. <order>eventtime</order>
  1203. </decoder>
  1204. <decoder name="fortinet-fortigate-fields-v7">
  1205. <parent>fortinet-fortigate-firewall</parent>
  1206. <regex>\s+eventtype="(\.*)"|\s+eventtype=(\.*)\s|\s+eventtype=(\.*)$</regex>
  1207. <order>eventtype</order>
  1208. </decoder>
  1209. <decoder name="fortinet-fortigate-fields-v7">
  1210. <parent>fortinet-fortigate-firewall</parent>
  1211. <regex>\s+exch="(\.*)"|\s+exch=(\.*)\s|\s+exch=(\.*)$</regex>
  1212. <order>exch</order>
  1213. </decoder>
  1214. <decoder name="fortinet-fortigate-fields-v7">
  1215. <parent>fortinet-fortigate-firewall</parent>
  1216. <regex>\s+exchange="(\.*)"|\s+exchange=(\.*)\s|\s+exchange=(\.*)$</regex>
  1217. <order>exchange</order>
  1218. </decoder>
  1219. <decoder name="fortinet-fortigate-fields-v7">
  1220. <parent>fortinet-fortigate-firewall</parent>
  1221. <regex>\s+expectedsignature="(\.*)"|\s+expectedsignature=(\.*)\s|\s+expectedsignature=(\.*)$</regex>
  1222. <order>expectedsignature</order>
  1223. </decoder>
  1224. <decoder name="fortinet-fortigate-fields-v7">
  1225. <parent>fortinet-fortigate-firewall</parent>
  1226. <regex>\s+expiry="(\.*)"|\s+expiry=(\.*)\s|\s+expiry=(\.*)$</regex>
  1227. <order>expiry</order>
  1228. </decoder>
  1229. <decoder name="fortinet-fortigate-fields-v7">
  1230. <parent>fortinet-fortigate-firewall</parent>
  1231. <regex>\s+extension="(\.*)"|\s+extension=(\.*)\s|\s+extension=(\.*)$</regex>
  1232. <order>extension</order>
  1233. </decoder>
  1234. <decoder name="fortinet-fortigate-fields-v7">
  1235. <parent>fortinet-fortigate-firewall</parent>
  1236. <regex>\s+faiaction="(\.*)"|\s+faiaction=(\.*)\s|\s+faiaction=(\.*)$</regex>
  1237. <order>faiaction</order>
  1238. </decoder>
  1239. <decoder name="fortinet-fortigate-fields-v7">
  1240. <parent>fortinet-fortigate-firewall</parent>
  1241. <regex>\s+faiconfidence="(\.*)"|\s+faiconfidence=(\.*)\s|\s+faiconfidence=(\.*)$</regex>
  1242. <order>faiconfidence</order>
  1243. </decoder>
  1244. <decoder name="fortinet-fortigate-fields-v7">
  1245. <parent>fortinet-fortigate-firewall</parent>
  1246. <regex>\s+faifileid="(\.*)"|\s+faifileid=(\.*)\s|\s+faifileid=(\.*)$</regex>
  1247. <order>faifileid</order>
  1248. </decoder>
  1249. <decoder name="fortinet-fortigate-fields-v7">
  1250. <parent>fortinet-fortigate-firewall</parent>
  1251. <regex>\s+faifiletype="(\.*)"|\s+faifiletype=(\.*)\s|\s+faifiletype=(\.*)$</regex>
  1252. <order>faifiletype</order>
  1253. </decoder>
  1254. <decoder name="fortinet-fortigate-fields-v7">
  1255. <parent>fortinet-fortigate-firewall</parent>
  1256. <regex>\s+failuredev="(\.*)"|\s+failuredev=(\.*)\s|\s+failuredev=(\.*)$</regex>
  1257. <order>failuredev</order>
  1258. </decoder>
  1259. <decoder name="fortinet-fortigate-fields-v7">
  1260. <parent>fortinet-fortigate-firewall</parent>
  1261. <regex>\s+faiseverity="(\.*)"|\s+faiseverity=(\.*)\s|\s+faiseverity=(\.*)$</regex>
  1262. <order>faiseverity</order>
  1263. </decoder>
  1264. <decoder name="fortinet-fortigate-fields-v7">
  1265. <parent>fortinet-fortigate-firewall</parent>
  1266. <regex>\s+fams_pause="(\.*)"|\s+fams_pause=(\.*)\s|\s+fams_pause=(\.*)$</regex>
  1267. <order>fams_pause</order>
  1268. </decoder>
  1269. <decoder name="fortinet-fortigate-fields-v7">
  1270. <parent>fortinet-fortigate-firewall</parent>
  1271. <regex>\s+fazlograte="(\.*)"|\s+fazlograte=(\.*)\s|\s+fazlograte=(\.*)$</regex>
  1272. <order>fazlograte</order>
  1273. </decoder>
  1274. <decoder name="fortinet-fortigate-fields-v7">
  1275. <parent>fortinet-fortigate-firewall</parent>
  1276. <regex>\s+fctemsname="(\.*)"|\s+fctemsname=(\.*)\s|\s+fctemsname=(\.*)$</regex>
  1277. <order>fctemsname</order>
  1278. </decoder>
  1279. <decoder name="fortinet-fortigate-fields-v7">
  1280. <parent>fortinet-fortigate-firewall</parent>
  1281. <regex>\s+fctemssn="(\.*)"|\s+fctemssn=(\.*)\s|\s+fctemssn=(\.*)$</regex>
  1282. <order>fctemssn</order>
  1283. </decoder>
  1284. <decoder name="fortinet-fortigate-fields-v7">
  1285. <parent>fortinet-fortigate-firewall</parent>
  1286. <regex>\s+fctuid="(\.*)"|\s+fctuid=(\.*)\s|\s+fctuid=(\.*)$</regex>
  1287. <order>fctuid</order>
  1288. </decoder>
  1289. <decoder name="fortinet-fortigate-fields-v7">
  1290. <parent>fortinet-fortigate-firewall</parent>
  1291. <regex>\s+field="(\.*)"|\s+field=(\.*)\s|\s+field=(\.*)$</regex>
  1292. <order>field</order>
  1293. </decoder>
  1294. <decoder name="fortinet-fortigate-fields-v7">
  1295. <parent>fortinet-fortigate-firewall</parent>
  1296. <regex>\s+file="(\.*)"|\s+file=(\.*)\s|\s+file=(\.*)$</regex>
  1297. <order>file</order>
  1298. </decoder>
  1299. <decoder name="fortinet-fortigate-fields-v7">
  1300. <parent>fortinet-fortigate-firewall</parent>
  1301. <regex>\s+filefilter="(\.*)"|\s+filefilter=(\.*)\s|\s+filefilter=(\.*)$</regex>
  1302. <order>filefilter</order>
  1303. </decoder>
  1304. <decoder name="fortinet-fortigate-fields-v7">
  1305. <parent>fortinet-fortigate-firewall</parent>
  1306. <regex>\s+filehash="(\.*)"|\s+filehash=(\.*)\s|\s+filehash=(\.*)$</regex>
  1307. <order>filehash</order>
  1308. </decoder>
  1309. <decoder name="fortinet-fortigate-fields-v7">
  1310. <parent>fortinet-fortigate-firewall</parent>
  1311. <regex>\s+filehashsrc="(\.*)"|\s+filehashsrc=(\.*)\s|\s+filehashsrc=(\.*)$</regex>
  1312. <order>filehashsrc</order>
  1313. </decoder>
  1314. <decoder name="fortinet-fortigate-fields-v7">
  1315. <parent>fortinet-fortigate-firewall</parent>
  1316. <regex>\s+filename="(\.*)"|\s+filename=(\.*)\s|\s+filename=(\.*)$</regex>
  1317. <order>filename</order>
  1318. </decoder>
  1319. <decoder name="fortinet-fortigate-fields-v7">
  1320. <parent>fortinet-fortigate-firewall</parent>
  1321. <regex>\s+filesize="(\.*)"|\s+filesize=(\.*)\s|\s+filesize=(\.*)$</regex>
  1322. <order>filesize</order>
  1323. </decoder>
  1324. <decoder name="fortinet-fortigate-fields-v7">
  1325. <parent>fortinet-fortigate-firewall</parent>
  1326. <regex>\s+filetype="(\.*)"|\s+filetype=(\.*)\s|\s+filetype=(\.*)$</regex>
  1327. <order>filetype</order>
  1328. </decoder>
  1329. <decoder name="fortinet-fortigate-fields-v7">
  1330. <parent>fortinet-fortigate-firewall</parent>
  1331. <regex>\s+filtercat="(\.*)"|\s+filtercat=(\.*)\s|\s+filtercat=(\.*)$</regex>
  1332. <order>filtercat</order>
  1333. </decoder>
  1334. <decoder name="fortinet-fortigate-fields-v7">
  1335. <parent>fortinet-fortigate-firewall</parent>
  1336. <regex>\s+filteridx="(\.*)"|\s+filteridx=(\.*)\s|\s+filteridx=(\.*)$</regex>
  1337. <order>filteridx</order>
  1338. </decoder>
  1339. <decoder name="fortinet-fortigate-fields-v7">
  1340. <parent>fortinet-fortigate-firewall</parent>
  1341. <regex>\s+filtername="(\.*)"|\s+filtername=(\.*)\s|\s+filtername=(\.*)$</regex>
  1342. <order>filtername</order>
  1343. </decoder>
  1344. <decoder name="fortinet-fortigate-fields-v7">
  1345. <parent>fortinet-fortigate-firewall</parent>
  1346. <regex>\s+filtertype="(\.*)"|\s+filtertype=(\.*)\s|\s+filtertype=(\.*)$</regex>
  1347. <order>filtertype</order>
  1348. </decoder>
  1349. <decoder name="fortinet-fortigate-fields-v7">
  1350. <parent>fortinet-fortigate-firewall</parent>
  1351. <regex>\s+fndraction="(\.*)"|\s+fndraction=(\.*)\s|\s+fndraction=(\.*)$</regex>
  1352. <order>fndraction</order>
  1353. </decoder>
  1354. <decoder name="fortinet-fortigate-fields-v7">
  1355. <parent>fortinet-fortigate-firewall</parent>
  1356. <regex>\s+fndrconfidence="(\.*)"|\s+fndrconfidence=(\.*)\s|\s+fndrconfidence=(\.*)$</regex>
  1357. <order>fndrconfidence</order>
  1358. </decoder>
  1359. <decoder name="fortinet-fortigate-fields-v7">
  1360. <parent>fortinet-fortigate-firewall</parent>
  1361. <regex>\s+fndrfileid="(\.*)"|\s+fndrfileid=(\.*)\s|\s+fndrfileid=(\.*)$</regex>
  1362. <order>fndrfileid</order>
  1363. </decoder>
  1364. <decoder name="fortinet-fortigate-fields-v7">
  1365. <parent>fortinet-fortigate-firewall</parent>
  1366. <regex>\s+fndrfiletype="(\.*)"|\s+fndrfiletype=(\.*)\s|\s+fndrfiletype=(\.*)$</regex>
  1367. <order>fndrfiletype</order>
  1368. </decoder>
  1369. <decoder name="fortinet-fortigate-fields-v7">
  1370. <parent>fortinet-fortigate-firewall</parent>
  1371. <regex>\s+fndrseverity="(\.*)"|\s+fndrseverity=(\.*)\s|\s+fndrseverity=(\.*)$</regex>
  1372. <order>fndrseverity</order>
  1373. </decoder>
  1374. <decoder name="fortinet-fortigate-fields-v7">
  1375. <parent>fortinet-fortigate-firewall</parent>
  1376. <regex>\s+fndrverdict="(\.*)"|\s+fndrverdict=(\.*)\s|\s+fndrverdict=(\.*)$</regex>
  1377. <order>fndrverdict</order>
  1378. </decoder>
  1379. <decoder name="fortinet-fortigate-fields-v7">
  1380. <parent>fortinet-fortigate-firewall</parent>
  1381. <regex>\s+forti="(\.*)"|\s+forti=(\.*)\s|\s+forti=(\.*)$</regex>
  1382. <order>forti</order>
  1383. </decoder>
  1384. <decoder name="fortinet-fortigate-fields-v7">
  1385. <parent>fortinet-fortigate-firewall</parent>
  1386. <regex>\s+fortiguardresp="(\.*)"|\s+fortiguardresp=(\.*)\s|\s+fortiguardresp=(\.*)$</regex>
  1387. <order>fortiguardresp</order>
  1388. </decoder>
  1389. <decoder name="fortinet-fortigate-fields-v7">
  1390. <parent>fortinet-fortigate-firewall</parent>
  1391. <regex>\s+forwardedfor="(\.*)"|\s+forwardedfor=(\.*)\s|\s+forwardedfor=(\.*)$</regex>
  1392. <order>forwardedfor</order>
  1393. </decoder>
  1394. <decoder name="fortinet-fortigate-fields-v7">
  1395. <parent>fortinet-fortigate-firewall</parent>
  1396. <regex>\s+fqdn="(\.*)"|\s+fqdn=(\.*)\s|\s+fqdn=(\.*)$</regex>
  1397. <order>fqdn</order>
  1398. </decoder>
  1399. <decoder name="fortinet-fortigate-fields-v7">
  1400. <parent>fortinet-fortigate-firewall</parent>
  1401. <regex>\s+frametype="(\.*)"|\s+frametype=(\.*)\s|\s+frametype=(\.*)$</regex>
  1402. <order>frametype</order>
  1403. </decoder>
  1404. <decoder name="fortinet-fortigate-fields-v7">
  1405. <parent>fortinet-fortigate-firewall</parent>
  1406. <regex>\s+freediskstorage="(\.*)"|\s+freediskstorage=(\.*)\s|\s+freediskstorage=(\.*)$</regex>
  1407. <order>freediskstorage</order>
  1408. </decoder>
  1409. <decoder name="fortinet-fortigate-fields-v7">
  1410. <parent>fortinet-fortigate-firewall</parent>
  1411. <regex>\s+from="(\.*)"|\s+from=(\.*)\s|\s+from=(\.*)$</regex>
  1412. <order>from</order>
  1413. </decoder>
  1414. <decoder name="fortinet-fortigate-fields-v7">
  1415. <parent>fortinet-fortigate-firewall</parent>
  1416. <regex>\s+from_vcluster="(\.*)"|\s+from_vcluster=(\.*)\s|\s+from_vcluster=(\.*)$</regex>
  1417. <order>from_vcluster</order>
  1418. </decoder>
  1419. <decoder name="fortinet-fortigate-fields-v7">
  1420. <parent>fortinet-fortigate-firewall</parent>
  1421. <regex>\s+fsaaction="(\.*)"|\s+fsaaction=(\.*)\s|\s+fsaaction=(\.*)$</regex>
  1422. <order>fsaaction</order>
  1423. </decoder>
  1424. <decoder name="fortinet-fortigate-fields-v7">
  1425. <parent>fortinet-fortigate-firewall</parent>
  1426. <regex>\s+fsafileid="(\.*)"|\s+fsafileid=(\.*)\s|\s+fsafileid=(\.*)$</regex>
  1427. <order>fsafileid</order>
  1428. </decoder>
  1429. <decoder name="fortinet-fortigate-fields-v7">
  1430. <parent>fortinet-fortigate-firewall</parent>
  1431. <regex>\s+fsafiletype="(\.*)"|\s+fsafiletype=(\.*)\s|\s+fsafiletype=(\.*)$</regex>
  1432. <order>fsafiletype</order>
  1433. </decoder>
  1434. <decoder name="fortinet-fortigate-fields-v7">
  1435. <parent>fortinet-fortigate-firewall</parent>
  1436. <regex>\s+fsaseverity="(\.*)"|\s+fsaseverity=(\.*)\s|\s+fsaseverity=(\.*)$</regex>
  1437. <order>fsaseverity</order>
  1438. </decoder>
  1439. <decoder name="fortinet-fortigate-fields-v7">
  1440. <parent>fortinet-fortigate-firewall</parent>
  1441. <regex>\s+fsaverdict="(\.*)"|\s+fsaverdict=(\.*)\s|\s+fsaverdict=(\.*)$</regex>
  1442. <order>fsaverdict</order>
  1443. </decoder>
  1444. <decoder name="fortinet-fortigate-fields-v7">
  1445. <parent>fortinet-fortigate-firewall</parent>
  1446. <regex>\s+ftlkintf="(\.*)"|\s+ftlkintf=(\.*)\s|\s+ftlkintf=(\.*)$</regex>
  1447. <order>ftlkintf</order>
  1448. </decoder>
  1449. <decoder name="fortinet-fortigate-fields-v7">
  1450. <parent>fortinet-fortigate-firewall</parent>
  1451. <regex>\s+fwdsrv="(\.*)"|\s+fwdsrv=(\.*)\s|\s+fwdsrv=(\.*)$</regex>
  1452. <order>fwdsrv</order>
  1453. </decoder>
  1454. <decoder name="fortinet-fortigate-fields-v7">
  1455. <parent>fortinet-fortigate-firewall</parent>
  1456. <regex>\s+fwserver_name="(\.*)"|\s+fwserver_name=(\.*)\s|\s+fwserver_name=(\.*)$</regex>
  1457. <order>fwserver_name</order>
  1458. </decoder>
  1459. <decoder name="fortinet-fortigate-fields-v7">
  1460. <parent>fortinet-fortigate-firewall</parent>
  1461. <regex>\s+gateway="(\.*)"|\s+gateway=(\.*)\s|\s+gateway=(\.*)$</regex>
  1462. <order>gateway</order>
  1463. </decoder>
  1464. <decoder name="fortinet-fortigate-fields-v7">
  1465. <parent>fortinet-fortigate-firewall</parent>
  1466. <regex>\s+gatewayid="(\.*)"|\s+gatewayid=(\.*)\s|\s+gatewayid=(\.*)$</regex>
  1467. <order>gatewayid</order>
  1468. </decoder>
  1469. <decoder name="fortinet-fortigate-fields-v7">
  1470. <parent>fortinet-fortigate-firewall</parent>
  1471. <regex>\s+green="(\.*)"|\s+green=(\.*)\s|\s+green=(\.*)$</regex>
  1472. <order>green</order>
  1473. </decoder>
  1474. <decoder name="fortinet-fortigate-fields-v7">
  1475. <parent>fortinet-fortigate-firewall</parent>
  1476. <regex>\s+group="(\.*)"|\s+group=(\.*)\s|\s+group=(\.*)$</regex>
  1477. <order>group</order>
  1478. </decoder>
  1479. <decoder name="fortinet-fortigate-fields-v7">
  1480. <parent>fortinet-fortigate-firewall</parent>
  1481. <regex>\s+groupid="(\.*)"|\s+groupid=(\.*)\s|\s+groupid=(\.*)$</regex>
  1482. <order>groupid</order>
  1483. </decoder>
  1484. <decoder name="fortinet-fortigate-fields-v7">
  1485. <parent>fortinet-fortigate-firewall</parent>
  1486. <regex>\s+gtp="(\.*)"|\s+gtp=(\.*)\s|\s+gtp=(\.*)$</regex>
  1487. <order>gtp</order>
  1488. </decoder>
  1489. <decoder name="fortinet-fortigate-fields-v7">
  1490. <parent>fortinet-fortigate-firewall</parent>
  1491. <regex>\s+ha="(\.*)"|\s+ha=(\.*)\s|\s+ha=(\.*)$</regex>
  1492. <order>ha</order>
  1493. </decoder>
  1494. <decoder name="fortinet-fortigate-fields-v7">
  1495. <parent>fortinet-fortigate-firewall</parent>
  1496. <regex>\s+ha_group="(\.*)"|\s+ha_group=(\.*)\s|\s+ha_group=(\.*)$</regex>
  1497. <order>ha_group</order>
  1498. </decoder>
  1499. <decoder name="fortinet-fortigate-fields-v7">
  1500. <parent>fortinet-fortigate-firewall</parent>
  1501. <regex>\s+ha_role="(\.*)"|\s+ha_role=(\.*)\s|\s+ha_role=(\.*)$</regex>
  1502. <order>ha_role</order>
  1503. </decoder>
  1504. <decoder name="fortinet-fortigate-fields-v7">
  1505. <parent>fortinet-fortigate-firewall</parent>
  1506. <regex>\s+handshake="(\.*)"|\s+handshake=(\.*)\s|\s+handshake=(\.*)$</regex>
  1507. <order>handshake</order>
  1508. </decoder>
  1509. <decoder name="fortinet-fortigate-fields-v7">
  1510. <parent>fortinet-fortigate-firewall</parent>
  1511. <regex>\s+headerteid="(\.*)"|\s+headerteid=(\.*)\s|\s+headerteid=(\.*)$</regex>
  1512. <order>headerteid</order>
  1513. </decoder>
  1514. <decoder name="fortinet-fortigate-fields-v7">
  1515. <parent>fortinet-fortigate-firewall</parent>
  1516. <regex>\s+healthcheck="(\.*)"|\s+healthcheck=(\.*)\s|\s+healthcheck=(\.*)$</regex>
  1517. <order>healthcheck</order>
  1518. </decoder>
  1519. <decoder name="fortinet-fortigate-fields-v7">
  1520. <parent>fortinet-fortigate-firewall</parent>
  1521. <regex>\s+highcount="(\.*)"|\s+highcount=(\.*)\s|\s+highcount=(\.*)$</regex>
  1522. <order>highcount</order>
  1523. </decoder>
  1524. <decoder name="fortinet-fortigate-fields-v7">
  1525. <parent>fortinet-fortigate-firewall</parent>
  1526. <regex>\s+host="(\.*)"|\s+host=(\.*)\s|\s+host=(\.*)$</regex>
  1527. <order>host</order>
  1528. </decoder>
  1529. <decoder name="fortinet-fortigate-fields-v7">
  1530. <parent>fortinet-fortigate-firewall</parent>
  1531. <regex>\s+hostkeystatus="(\.*)"|\s+hostkeystatus=(\.*)\s|\s+hostkeystatus=(\.*)$</regex>
  1532. <order>hostkeystatus</order>
  1533. </decoder>
  1534. <decoder name="fortinet-fortigate-fields-v7">
  1535. <parent>fortinet-fortigate-firewall</parent>
  1536. <regex>\s+hostname="(\.*)"|\s+hostname=(\.*)\s|\s+hostname=(\.*)$</regex>
  1537. <order>hostname</order>
  1538. </decoder>
  1539. <decoder name="fortinet-fortigate-fields-v7">
  1540. <parent>fortinet-fortigate-firewall</parent>
  1541. <regex>\s+hseid="(\.*)"|\s+hseid=(\.*)\s|\s+hseid=(\.*)$</regex>
  1542. <order>hseid</order>
  1543. </decoder>
  1544. <decoder name="fortinet-fortigate-fields-v7">
  1545. <parent>fortinet-fortigate-firewall</parent>
  1546. <regex>\s+httpcode="(\.*)"|\s+httpcode=(\.*)\s|\s+httpcode=(\.*)$</regex>
  1547. <order>httpcode</order>
  1548. </decoder>
  1549. <decoder name="fortinet-fortigate-fields-v7">
  1550. <parent>fortinet-fortigate-firewall</parent>
  1551. <regex>\s+httpmethod="(\.*)"|\s+httpmethod=(\.*)\s|\s+httpmethod=(\.*)$</regex>
  1552. <order>httpmethod</order>
  1553. </decoder>
  1554. <decoder name="fortinet-fortigate-fields-v7">
  1555. <parent>fortinet-fortigate-firewall</parent>
  1556. <regex>\s+iaid="(\.*)"|\s+iaid=(\.*)\s|\s+iaid=(\.*)$</regex>
  1557. <order>iaid</order>
  1558. </decoder>
  1559. <decoder name="fortinet-fortigate-fields-v7">
  1560. <parent>fortinet-fortigate-firewall</parent>
  1561. <regex>\s+icap="(\.*)"|\s+icap=(\.*)\s|\s+icap=(\.*)$</regex>
  1562. <order>icap</order>
  1563. </decoder>
  1564. <decoder name="fortinet-fortigate-fields-v7">
  1565. <parent>fortinet-fortigate-firewall</parent>
  1566. <regex>\s+icbaction="(\.*)"|\s+icbaction=(\.*)\s|\s+icbaction=(\.*)$</regex>
  1567. <order>icbaction</order>
  1568. </decoder>
  1569. <decoder name="fortinet-fortigate-fields-v7">
  1570. <parent>fortinet-fortigate-firewall</parent>
  1571. <regex>\s+icbconfidence="(\.*)"|\s+icbconfidence=(\.*)\s|\s+icbconfidence=(\.*)$</regex>
  1572. <order>icbconfidence</order>
  1573. </decoder>
  1574. <decoder name="fortinet-fortigate-fields-v7">
  1575. <parent>fortinet-fortigate-firewall</parent>
  1576. <regex>\s+icbfileid="(\.*)"|\s+icbfileid=(\.*)\s|\s+icbfileid=(\.*)$</regex>
  1577. <order>icbfileid</order>
  1578. </decoder>
  1579. <decoder name="fortinet-fortigate-fields-v7">
  1580. <parent>fortinet-fortigate-firewall</parent>
  1581. <regex>\s+icbfiletype="(\.*)"|\s+icbfiletype=(\.*)\s|\s+icbfiletype=(\.*)$</regex>
  1582. <order>icbfiletype</order>
  1583. </decoder>
  1584. <decoder name="fortinet-fortigate-fields-v7">
  1585. <parent>fortinet-fortigate-firewall</parent>
  1586. <regex>\s+icbseverity="(\.*)"|\s+icbseverity=(\.*)\s|\s+icbseverity=(\.*)$</regex>
  1587. <order>icbseverity</order>
  1588. </decoder>
  1589. <decoder name="fortinet-fortigate-fields-v7">
  1590. <parent>fortinet-fortigate-firewall</parent>
  1591. <regex>\s+icbverdict="(\.*)"|\s+icbverdict=(\.*)\s|\s+icbverdict=(\.*)$</regex>
  1592. <order>icbverdict</order>
  1593. </decoder>
  1594. <decoder name="fortinet-fortigate-fields-v7">
  1595. <parent>fortinet-fortigate-firewall</parent>
  1596. <regex>\s+icmpcode="(\.*)"|\s+icmpcode=(\.*)\s|\s+icmpcode=(\.*)$</regex>
  1597. <order>icmpcode</order>
  1598. </decoder>
  1599. <decoder name="fortinet-fortigate-fields-v7">
  1600. <parent>fortinet-fortigate-firewall</parent>
  1601. <regex>\s+icmpid="(\.*)"|\s+icmpid=(\.*)\s|\s+icmpid=(\.*)$</regex>
  1602. <order>icmpid</order>
  1603. </decoder>
  1604. <decoder name="fortinet-fortigate-fields-v7">
  1605. <parent>fortinet-fortigate-firewall</parent>
  1606. <regex>\s+icmptype="(\.*)"|\s+icmptype=(\.*)\s|\s+icmptype=(\.*)$</regex>
  1607. <order>icmptype</order>
  1608. </decoder>
  1609. <decoder name="fortinet-fortigate-fields-v7">
  1610. <parent>fortinet-fortigate-firewall</parent>
  1611. <regex>\s+identifier="(\.*)"|\s+identifier=(\.*)\s|\s+identifier=(\.*)$</regex>
  1612. <order>identifier</order>
  1613. </decoder>
  1614. <decoder name="fortinet-fortigate-fields-v7">
  1615. <parent>fortinet-fortigate-firewall</parent>
  1616. <regex>\s+ietype="(\.*)"|\s+ietype=(\.*)\s|\s+ietype=(\.*)$</regex>
  1617. <order>ietype</order>
  1618. </decoder>
  1619. <decoder name="fortinet-fortigate-fields-v7">
  1620. <parent>fortinet-fortigate-firewall</parent>
  1621. <regex>\s+imei="(\.*)"|\s+imei=(\.*)\s|\s+imei=(\.*)$</regex>
  1622. <order>imei</order>
  1623. </decoder>
  1624. <decoder name="fortinet-fortigate-fields-v7">
  1625. <parent>fortinet-fortigate-firewall</parent>
  1626. <regex>\s+imsi="(\.*)"|\s+imsi=(\.*)\s|\s+imsi=(\.*)$</regex>
  1627. <order>imsi</order>
  1628. </decoder>
  1629. <decoder name="fortinet-fortigate-fields-v7">
  1630. <parent>fortinet-fortigate-firewall</parent>
  1631. <regex>\s+in_spi="(\.*)"|\s+in_spi=(\.*)\s|\s+in_spi=(\.*)$</regex>
  1632. <order>in_spi</order>
  1633. </decoder>
  1634. <decoder name="fortinet-fortigate-fields-v7">
  1635. <parent>fortinet-fortigate-firewall</parent>
  1636. <regex>\s+inbandwidth="(\.*)"|\s+inbandwidth=(\.*)\s|\s+inbandwidth=(\.*)$</regex>
  1637. <order>inbandwidth</order>
  1638. </decoder>
  1639. <decoder name="fortinet-fortigate-fields-v7">
  1640. <parent>fortinet-fortigate-firewall</parent>
  1641. <regex>\s+inbandwidthavailable="(\.*)"|\s+inbandwidthavailable=(\.*)\s|\s+inbandwidthavailable=(\.*)$</regex>
  1642. <order>inbandwidthavailable</order>
  1643. </decoder>
  1644. <decoder name="fortinet-fortigate-fields-v7">
  1645. <parent>fortinet-fortigate-firewall</parent>
  1646. <regex>\s+inbandwidthused="(\.*)"|\s+inbandwidthused=(\.*)\s|\s+inbandwidthused=(\.*)$</regex>
  1647. <order>inbandwidthused</order>
  1648. </decoder>
  1649. <decoder name="fortinet-fortigate-fields-v7">
  1650. <parent>fortinet-fortigate-firewall</parent>
  1651. <regex>\s+incidentserialno="(\.*)"|\s+incidentserialno=(\.*)\s|\s+incidentserialno=(\.*)$</regex>
  1652. <order>incidentserialno</order>
  1653. </decoder>
  1654. <decoder name="fortinet-fortigate-fields-v7">
  1655. <parent>fortinet-fortigate-firewall</parent>
  1656. <regex>\s+infectedfilelevel="(\.*)"|\s+infectedfilelevel=(\.*)\s|\s+infectedfilelevel=(\.*)$</regex>
  1657. <order>infectedfilelevel</order>
  1658. </decoder>
  1659. <decoder name="fortinet-fortigate-fields-v7">
  1660. <parent>fortinet-fortigate-firewall</parent>
  1661. <regex>\s+infectedfilename="(\.*)"|\s+infectedfilename=(\.*)\s|\s+infectedfilename=(\.*)$</regex>
  1662. <order>infectedfilename</order>
  1663. </decoder>
  1664. <decoder name="fortinet-fortigate-fields-v7">
  1665. <parent>fortinet-fortigate-firewall</parent>
  1666. <regex>\s+infectedfilesize="(\.*)"|\s+infectedfilesize=(\.*)\s|\s+infectedfilesize=(\.*)$</regex>
  1667. <order>infectedfilesize</order>
  1668. </decoder>
  1669. <decoder name="fortinet-fortigate-fields-v7">
  1670. <parent>fortinet-fortigate-firewall</parent>
  1671. <regex>\s+infectedfiletype="(\.*)"|\s+infectedfiletype=(\.*)\s|\s+infectedfiletype=(\.*)$</regex>
  1672. <order>infectedfiletype</order>
  1673. </decoder>
  1674. <decoder name="fortinet-fortigate-fields-v7">
  1675. <parent>fortinet-fortigate-firewall</parent>
  1676. <regex>\s+infection="(\.*)"|\s+infection=(\.*)\s|\s+infection=(\.*)$</regex>
  1677. <order>infection</order>
  1678. </decoder>
  1679. <decoder name="fortinet-fortigate-fields-v7">
  1680. <parent>fortinet-fortigate-firewall</parent>
  1681. <regex>\s+informationsource="(\.*)"|\s+informationsource=(\.*)\s|\s+informationsource=(\.*)$</regex>
  1682. <order>informationsource</order>
  1683. </decoder>
  1684. <decoder name="fortinet-fortigate-fields-v7">
  1685. <parent>fortinet-fortigate-firewall</parent>
  1686. <regex>\s+init="(\.*)"|\s+init=(\.*)\s|\s+init=(\.*)$</regex>
  1687. <order>init</order>
  1688. </decoder>
  1689. <decoder name="fortinet-fortigate-fields-v7">
  1690. <parent>fortinet-fortigate-firewall</parent>
  1691. <regex>\s+initiator="(\.*)"|\s+initiator=(\.*)\s|\s+initiator=(\.*)$</regex>
  1692. <order>initiator</order>
  1693. </decoder>
  1694. <decoder name="fortinet-fortigate-fields-v7">
  1695. <parent>fortinet-fortigate-firewall</parent>
  1696. <regex>\s+interface="(\.*)"|\s+interface=(\.*)\s|\s+interface=(\.*)$</regex>
  1697. <order>interface</order>
  1698. </decoder>
  1699. <decoder name="fortinet-fortigate-fields-v7">
  1700. <parent>fortinet-fortigate-firewall</parent>
  1701. <regex>\s+intf="(\.*)"|\s+intf=(\.*)\s|\s+intf=(\.*)$</regex>
  1702. <order>intf</order>
  1703. </decoder>
  1704. <decoder name="fortinet-fortigate-fields-v7">
  1705. <parent>fortinet-fortigate-firewall</parent>
  1706. <regex>\s+invalidmac="(\.*)"|\s+invalidmac=(\.*)\s|\s+invalidmac=(\.*)$</regex>
  1707. <order>invalidmac</order>
  1708. </decoder>
  1709. <decoder name="fortinet-fortigate-fields-v7">
  1710. <parent>fortinet-fortigate-firewall</parent>
  1711. <regex>\s+ip="(\.*)"|\s+ip=(\.*)\s|\s+ip=(\.*)$</regex>
  1712. <order>ip</order>
  1713. </decoder>
  1714. <decoder name="fortinet-fortigate-fields-v7">
  1715. <parent>fortinet-fortigate-firewall</parent>
  1716. <regex>\s+ipaddr="(\.*)"|\s+ipaddr=(\.*)\s|\s+ipaddr=(\.*)$</regex>
  1717. <order>ipaddr</order>
  1718. </decoder>
  1719. <decoder name="fortinet-fortigate-fields-v7">
  1720. <parent>fortinet-fortigate-firewall</parent>
  1721. <regex>\s+ips="(\.*)"|\s+ips=(\.*)\s|\s+ips=(\.*)$</regex>
  1722. <order>ips</order>
  1723. </decoder>
  1724. <decoder name="fortinet-fortigate-fields-v7">
  1725. <parent>fortinet-fortigate-firewall</parent>
  1726. <regex>\s+iptype="(\.*)"|\s+iptype=(\.*)\s|\s+iptype=(\.*)$</regex>
  1727. <order>iptype</order>
  1728. </decoder>
  1729. <decoder name="fortinet-fortigate-fields-v7">
  1730. <parent>fortinet-fortigate-firewall</parent>
  1731. <regex>\s+issuer="(\.*)"|\s+issuer=(\.*)\s|\s+issuer=(\.*)$</regex>
  1732. <order>issuer</order>
  1733. </decoder>
  1734. <decoder name="fortinet-fortigate-fields-v7">
  1735. <parent>fortinet-fortigate-firewall</parent>
  1736. <regex>\s+jitter="(\.*)"|\s+jitter=(\.*)\s|\s+jitter=(\.*)$</regex>
  1737. <order>jitter</order>
  1738. </decoder>
  1739. <decoder name="fortinet-fortigate-fields-v7">
  1740. <parent>fortinet-fortigate-firewall</parent>
  1741. <regex>\s+keyalgo="(\.*)"|\s+keyalgo=(\.*)\s|\s+keyalgo=(\.*)$</regex>
  1742. <order>keyalgo</order>
  1743. </decoder>
  1744. <decoder name="fortinet-fortigate-fields-v7">
  1745. <parent>fortinet-fortigate-firewall</parent>
  1746. <regex>\s+keysize="(\.*)"|\s+keysize=(\.*)\s|\s+keysize=(\.*)$</regex>
  1747. <order>keysize</order>
  1748. </decoder>
  1749. <decoder name="fortinet-fortigate-fields-v7">
  1750. <parent>fortinet-fortigate-firewall</parent>
  1751. <regex>\s+keyword="(\.*)"|\s+keyword=(\.*)\s|\s+keyword=(\.*)$</regex>
  1752. <order>keyword</order>
  1753. </decoder>
  1754. <decoder name="fortinet-fortigate-fields-v7">
  1755. <parent>fortinet-fortigate-firewall</parent>
  1756. <regex>\s+kind="(\.*)"|\s+kind=(\.*)\s|\s+kind=(\.*)$</regex>
  1757. <order>kind</order>
  1758. </decoder>
  1759. <decoder name="fortinet-fortigate-fields-v7">
  1760. <parent>fortinet-fortigate-firewall</parent>
  1761. <regex>\s+kxcurve="(\.*)"|\s+kxcurve=(\.*)\s|\s+kxcurve=(\.*)$</regex>
  1762. <order>kxcurve</order>
  1763. </decoder>
  1764. <decoder name="fortinet-fortigate-fields-v7">
  1765. <parent>fortinet-fortigate-firewall</parent>
  1766. <regex>\s+kxproto="(\.*)"|\s+kxproto=(\.*)\s|\s+kxproto=(\.*)$</regex>
  1767. <order>kxproto</order>
  1768. </decoder>
  1769. <decoder name="fortinet-fortigate-fields-v7">
  1770. <parent>fortinet-fortigate-firewall</parent>
  1771. <regex>\s+lanin="(\.*)"|\s+lanin=(\.*)\s|\s+lanin=(\.*)$</regex>
  1772. <order>lanin</order>
  1773. </decoder>
  1774. <decoder name="fortinet-fortigate-fields-v7">
  1775. <parent>fortinet-fortigate-firewall</parent>
  1776. <regex>\s+lanout="(\.*)"|\s+lanout=(\.*)\s|\s+lanout=(\.*)$</regex>
  1777. <order>lanout</order>
  1778. </decoder>
  1779. <decoder name="fortinet-fortigate-fields-v7">
  1780. <parent>fortinet-fortigate-firewall</parent>
  1781. <regex>\s+latency="(\.*)"|\s+latency=(\.*)\s|\s+latency=(\.*)$</regex>
  1782. <order>latency</order>
  1783. </decoder>
  1784. <decoder name="fortinet-fortigate-fields-v7">
  1785. <parent>fortinet-fortigate-firewall</parent>
  1786. <regex>\s+lease="(\.*)"|\s+lease=(\.*)\s|\s+lease=(\.*)$</regex>
  1787. <order>lease</order>
  1788. </decoder>
  1789. <decoder name="fortinet-fortigate-fields-v7">
  1790. <parent>fortinet-fortigate-firewall</parent>
  1791. <regex>\s+level="(\.*)"|\s+level=(\.*)\s|\s+level=(\.*)$</regex>
  1792. <order>level</order>
  1793. </decoder>
  1794. <decoder name="fortinet-fortigate-fields-v7">
  1795. <parent>fortinet-fortigate-firewall</parent>
  1796. <regex>\s+license_limit="(\.*)"|\s+license_limit=(\.*)\s|\s+license_limit=(\.*)$</regex>
  1797. <order>license_limit</order>
  1798. </decoder>
  1799. <decoder name="fortinet-fortigate-fields-v7">
  1800. <parent>fortinet-fortigate-firewall</parent>
  1801. <regex>\s+limit="(\.*)"|\s+limit=(\.*)\s|\s+limit=(\.*)$</regex>
  1802. <order>limit</order>
  1803. </decoder>
  1804. <decoder name="fortinet-fortigate-fields-v7">
  1805. <parent>fortinet-fortigate-firewall</parent>
  1806. <regex>\s+line="(\.*)"|\s+line=(\.*)\s|\s+line=(\.*)$</regex>
  1807. <order>line</order>
  1808. </decoder>
  1809. <decoder name="fortinet-fortigate-fields-v7">
  1810. <parent>fortinet-fortigate-firewall</parent>
  1811. <regex>\s+linked="(\.*)"|\s+linked=(\.*)\s|\s+linked=(\.*)$</regex>
  1812. <order>linked</order>
  1813. </decoder>
  1814. <decoder name="fortinet-fortigate-fields-v7">
  1815. <parent>fortinet-fortigate-firewall</parent>
  1816. <regex>\s+live="(\.*)"|\s+live=(\.*)\s|\s+live=(\.*)$</regex>
  1817. <order>live</order>
  1818. </decoder>
  1819. <decoder name="fortinet-fortigate-fields-v7">
  1820. <parent>fortinet-fortigate-firewall</parent>
  1821. <regex>\s+local="(\.*)"|\s+local=(\.*)\s|\s+local=(\.*)$</regex>
  1822. <order>local</order>
  1823. </decoder>
  1824. <decoder name="fortinet-fortigate-fields-v7">
  1825. <parent>fortinet-fortigate-firewall</parent>
  1826. <regex>\s+localdevcount="(\.*)"|\s+localdevcount=(\.*)\s|\s+localdevcount=(\.*)$</regex>
  1827. <order>localdevcount</order>
  1828. </decoder>
  1829. <decoder name="fortinet-fortigate-fields-v7">
  1830. <parent>fortinet-fortigate-firewall</parent>
  1831. <regex>\s+locip="(\.*)"|\s+locip=(\.*)\s|\s+locip=(\.*)$</regex>
  1832. <order>locip</order>
  1833. </decoder>
  1834. <decoder name="fortinet-fortigate-fields-v7">
  1835. <parent>fortinet-fortigate-firewall</parent>
  1836. <regex>\s+locport="(\.*)"|\s+locport=(\.*)\s|\s+locport=(\.*)$</regex>
  1837. <order>locport</order>
  1838. </decoder>
  1839. <decoder name="fortinet-fortigate-fields-v7">
  1840. <parent>fortinet-fortigate-firewall</parent>
  1841. <regex>\s+log="(\.*)"|\s+log=(\.*)\s|\s+log=(\.*)$</regex>
  1842. <order>log</order>
  1843. </decoder>
  1844. <decoder name="fortinet-fortigate-fields-v7">
  1845. <parent>fortinet-fortigate-firewall</parent>
  1846. <regex>\s+logdesc="(\.*)"|\s+logdesc=(\.*)\s|\s+logdesc=(\.*)$</regex>
  1847. <order>logdesc</order>
  1848. </decoder>
  1849. <decoder name="fortinet-fortigate-fields-v7">
  1850. <parent>fortinet-fortigate-firewall</parent>
  1851. <regex>\s+logid="(\.*)"|\s+logid=(\.*)\s|\s+logid=(\.*)$</regex>
  1852. <order>logid</order>
  1853. </decoder>
  1854. <decoder name="fortinet-fortigate-fields-v7">
  1855. <parent>fortinet-fortigate-firewall</parent>
  1856. <regex>\s+login="(\.*)"|\s+login=(\.*)\s|\s+login=(\.*)$</regex>
  1857. <order>login</order>
  1858. </decoder>
  1859. <decoder name="fortinet-fortigate-fields-v7">
  1860. <parent>fortinet-fortigate-firewall</parent>
  1861. <regex>\s+logsrc="(\.*)"|\s+logsrc=(\.*)\s|\s+logsrc=(\.*)$</regex>
  1862. <order>logsrc</order>
  1863. </decoder>
  1864. <decoder name="fortinet-fortigate-fields-v7">
  1865. <parent>fortinet-fortigate-firewall</parent>
  1866. <regex>\s+lowcount="(\.*)"|\s+lowcount=(\.*)\s|\s+lowcount=(\.*)$</regex>
  1867. <order>lowcount</order>
  1868. </decoder>
  1869. <decoder name="fortinet-fortigate-fields-v7">
  1870. <parent>fortinet-fortigate-firewall</parent>
  1871. <regex>\s+mac="(\.*)"|\s+mac=(\.*)\s|\s+mac=(\.*)$</regex>
  1872. <order>mac</order>
  1873. </decoder>
  1874. <decoder name="fortinet-fortigate-fields-v7">
  1875. <parent>fortinet-fortigate-firewall</parent>
  1876. <regex>\s+malform_data="(\.*)"|\s+malform_data=(\.*)\s|\s+malform_data=(\.*)$</regex>
  1877. <order>malform_data</order>
  1878. </decoder>
  1879. <decoder name="fortinet-fortigate-fields-v7">
  1880. <parent>fortinet-fortigate-firewall</parent>
  1881. <regex>\s+malform_desc="(\.*)"|\s+malform_desc=(\.*)\s|\s+malform_desc=(\.*)$</regex>
  1882. <order>malform_desc</order>
  1883. </decoder>
  1884. <decoder name="fortinet-fortigate-fields-v7">
  1885. <parent>fortinet-fortigate-firewall</parent>
  1886. <regex>\s+manuf="(\.*)"|\s+manuf=(\.*)\s|\s+manuf=(\.*)$</regex>
  1887. <order>manuf</order>
  1888. </decoder>
  1889. <decoder name="fortinet-fortigate-fields-v7">
  1890. <parent>fortinet-fortigate-firewall</parent>
  1891. <regex>\s+masterdstmac="(\.*)"|\s+masterdstmac=(\.*)\s|\s+masterdstmac=(\.*)$</regex>
  1892. <order>masterdstmac</order>
  1893. </decoder>
  1894. <decoder name="fortinet-fortigate-fields-v7">
  1895. <parent>fortinet-fortigate-firewall</parent>
  1896. <regex>\s+mastersrcmac="(\.*)"|\s+mastersrcmac=(\.*)\s|\s+mastersrcmac=(\.*)$</regex>
  1897. <order>mastersrcmac</order>
  1898. </decoder>
  1899. <decoder name="fortinet-fortigate-fields-v7">
  1900. <parent>fortinet-fortigate-firewall</parent>
  1901. <regex>\s+matchfilename="(\.*)"|\s+matchfilename=(\.*)\s|\s+matchfilename=(\.*)$</regex>
  1902. <order>matchfilename</order>
  1903. </decoder>
  1904. <decoder name="fortinet-fortigate-fields-v7">
  1905. <parent>fortinet-fortigate-firewall</parent>
  1906. <regex>\s+matchfiletype="(\.*)"|\s+matchfiletype=(\.*)\s|\s+matchfiletype=(\.*)$</regex>
  1907. <order>matchfiletype</order>
  1908. </decoder>
  1909. <decoder name="fortinet-fortigate-fields-v7">
  1910. <parent>fortinet-fortigate-firewall</parent>
  1911. <regex>\s+max="(\.*)"|\s+max=(\.*)\s|\s+max=(\.*)$</regex>
  1912. <order>max</order>
  1913. </decoder>
  1914. <decoder name="fortinet-fortigate-fields-v7">
  1915. <parent>fortinet-fortigate-firewall</parent>
  1916. <regex>\s+mediumcount="(\.*)"|\s+mediumcount=(\.*)\s|\s+mediumcount=(\.*)$</regex>
  1917. <order>mediumcount</order>
  1918. </decoder>
  1919. <decoder name="fortinet-fortigate-fields-v7">
  1920. <parent>fortinet-fortigate-firewall</parent>
  1921. <regex>\s+mem="(\.*)"|\s+mem=(\.*)\s|\s+mem=(\.*)$</regex>
  1922. <order>mem</order>
  1923. </decoder>
  1924. <decoder name="fortinet-fortigate-fields-v7">
  1925. <parent>fortinet-fortigate-firewall</parent>
  1926. <regex>\s+member="(\.*)"|\s+member=(\.*)\s|\s+member=(\.*)$</regex>
  1927. <order>member</order>
  1928. </decoder>
  1929. <decoder name="fortinet-fortigate-fields-v7">
  1930. <parent>fortinet-fortigate-firewall</parent>
  1931. <regex>\s+meshmode="(\.*)"|\s+meshmode=(\.*)\s|\s+meshmode=(\.*)$</regex>
  1932. <order>meshmode</order>
  1933. </decoder>
  1934. <decoder name="fortinet-fortigate-fields-v7">
  1935. <parent>fortinet-fortigate-firewall</parent>
  1936. <regex>\s+message_type="(\.*)"|\s+message_type=(\.*)\s|\s+message_type=(\.*)$</regex>
  1937. <order>message_type</order>
  1938. </decoder>
  1939. <decoder name="fortinet-fortigate-fields-v7">
  1940. <parent>fortinet-fortigate-firewall</parent>
  1941. <regex>\s+method="(\.*)"|\s+method=(\.*)\s|\s+method=(\.*)$</regex>
  1942. <order>method</order>
  1943. </decoder>
  1944. <decoder name="fortinet-fortigate-fields-v7">
  1945. <parent>fortinet-fortigate-firewall</parent>
  1946. <regex>\s+mgmtcnt="(\.*)"|\s+mgmtcnt=(\.*)\s|\s+mgmtcnt=(\.*)$</regex>
  1947. <order>mgmtcnt</order>
  1948. </decoder>
  1949. <decoder name="fortinet-fortigate-fields-v7">
  1950. <parent>fortinet-fortigate-firewall</parent>
  1951. <regex>\s+mitm="(\.*)"|\s+mitm=(\.*)\s|\s+mitm=(\.*)$</regex>
  1952. <order>mitm</order>
  1953. </decoder>
  1954. <decoder name="fortinet-fortigate-fields-v7">
  1955. <parent>fortinet-fortigate-firewall</parent>
  1956. <regex>\s+mode="(\.*)"|\s+mode=(\.*)\s|\s+mode=(\.*)$</regex>
  1957. <order>mode</order>
  1958. </decoder>
  1959. <decoder name="fortinet-fortigate-fields-v7">
  1960. <parent>fortinet-fortigate-firewall</parent>
  1961. <regex>\s+model="(\.*)"|\s+model=(\.*)\s|\s+model=(\.*)$</regex>
  1962. <order>model</order>
  1963. </decoder>
  1964. <decoder name="fortinet-fortigate-fields-v7">
  1965. <parent>fortinet-fortigate-firewall</parent>
  1966. <regex>\s+module="(\.*)"|\s+module=(\.*)\s|\s+module=(\.*)$</regex>
  1967. <order>module</order>
  1968. </decoder>
  1969. <decoder name="fortinet-fortigate-fields-v7">
  1970. <parent>fortinet-fortigate-firewall</parent>
  1971. <regex>\s+monitor="(\.*)"|\s+monitor=(\.*)\s|\s+monitor=(\.*)$</regex>
  1972. <order>monitor</order>
  1973. </decoder>
  1974. <decoder name="fortinet-fortigate-fields-v7">
  1975. <parent>fortinet-fortigate-firewall</parent>
  1976. <regex>\s+moscodec="(\.*)"|\s+moscodec=(\.*)\s|\s+moscodec=(\.*)$</regex>
  1977. <order>moscodec</order>
  1978. </decoder>
  1979. <decoder name="fortinet-fortigate-fields-v7">
  1980. <parent>fortinet-fortigate-firewall</parent>
  1981. <regex>\s+mosvalue="(\.*)"|\s+mosvalue=(\.*)\s|\s+mosvalue=(\.*)$</regex>
  1982. <order>mosvalue</order>
  1983. </decoder>
  1984. <decoder name="fortinet-fortigate-fields-v7">
  1985. <parent>fortinet-fortigate-firewall</parent>
  1986. <regex>\s+mpsk="(\.*)"|\s+mpsk=(\.*)\s|\s+mpsk=(\.*)$</regex>
  1987. <order>mpsk</order>
  1988. </decoder>
  1989. <decoder name="fortinet-fortigate-fields-v7">
  1990. <parent>fortinet-fortigate-firewall</parent>
  1991. <regex>\s+msg="(\.*)"|\s+msg=(\.*)\s|\s+msg=(\.*)$</regex>
  1992. <order>msg</order>
  1993. </decoder>
  1994. <decoder name="fortinet-fortigate-fields-v7">
  1995. <parent>fortinet-fortigate-firewall</parent>
  1996. <regex>\s+msgtypename="(\.*)"|\s+msgtypename=(\.*)\s|\s+msgtypename=(\.*)$</regex>
  1997. <order>msgtypename</order>
  1998. </decoder>
  1999. <decoder name="fortinet-fortigate-fields-v7">
  2000. <parent>fortinet-fortigate-firewall</parent>
  2001. <regex>\s+msisdn="(\.*)"|\s+msisdn=(\.*)\s|\s+msisdn=(\.*)$</regex>
  2002. <order>msisdn</order>
  2003. </decoder>
  2004. <decoder name="fortinet-fortigate-fields-v7">
  2005. <parent>fortinet-fortigate-firewall</parent>
  2006. <regex>\s+mtu="(\.*)"|\s+mtu=(\.*)\s|\s+mtu=(\.*)$</regex>
  2007. <order>mtu</order>
  2008. </decoder>
  2009. <decoder name="fortinet-fortigate-fields-v7">
  2010. <parent>fortinet-fortigate-firewall</parent>
  2011. <regex>\s+nai="(\.*)"|\s+nai=(\.*)\s|\s+nai=(\.*)$</regex>
  2012. <order>nai</order>
  2013. </decoder>
  2014. <decoder name="fortinet-fortigate-fields-v7">
  2015. <parent>fortinet-fortigate-firewall</parent>
  2016. <regex>\s+name="(\.*)"|\s+name=(\.*)\s|\s+name=(\.*)$</regex>
  2017. <order>name</order>
  2018. </decoder>
  2019. <decoder name="fortinet-fortigate-fields-v7">
  2020. <parent>fortinet-fortigate-firewall</parent>
  2021. <regex>\s+nat="(\.*)"|\s+nat=(\.*)\s|\s+nat=(\.*)$</regex>
  2022. <order>nat</order>
  2023. </decoder>
  2024. <decoder name="fortinet-fortigate-fields-v7">
  2025. <parent>fortinet-fortigate-firewall</parent>
  2026. <regex>\s+neighbor="(\.*)"|\s+neighbor=(\.*)\s|\s+neighbor=(\.*)$</regex>
  2027. <order>neighbor</order>
  2028. </decoder>
  2029. <decoder name="fortinet-fortigate-fields-v7">
  2030. <parent>fortinet-fortigate-firewall</parent>
  2031. <regex>\s+netid="(\.*)"|\s+netid=(\.*)\s|\s+netid=(\.*)$</regex>
  2032. <order>netid</order>
  2033. </decoder>
  2034. <decoder name="fortinet-fortigate-fields-v7">
  2035. <parent>fortinet-fortigate-firewall</parent>
  2036. <regex>\s+networktransfertime="(\.*)"|\s+networktransfertime=(\.*)\s|\s+networktransfertime=(\.*)$</regex>
  2037. <order>networktransfertime</order>
  2038. </decoder>
  2039. <decoder name="fortinet-fortigate-fields-v7">
  2040. <parent>fortinet-fortigate-firewall</parent>
  2041. <regex>\s+new_status="(\.*)"|\s+new_status=(\.*)\s|\s+new_status=(\.*)$</regex>
  2042. <order>new_status</order>
  2043. </decoder>
  2044. <decoder name="fortinet-fortigate-fields-v7">
  2045. <parent>fortinet-fortigate-firewall</parent>
  2046. <regex>\s+new_value="(\.*)"|\s+new_value=(\.*)\s|\s+new_value=(\.*)$</regex>
  2047. <order>new_value</order>
  2048. </decoder>
  2049. <decoder name="fortinet-fortigate-fields-v7">
  2050. <parent>fortinet-fortigate-firewall</parent>
  2051. <regex>\s+newchannel="(\.*)"|\s+newchannel=(\.*)\s|\s+newchannel=(\.*)$</regex>
  2052. <order>newchannel</order>
  2053. </decoder>
  2054. <decoder name="fortinet-fortigate-fields-v7">
  2055. <parent>fortinet-fortigate-firewall</parent>
  2056. <regex>\s+newchassisid="(\.*)"|\s+newchassisid=(\.*)\s|\s+newchassisid=(\.*)$</regex>
  2057. <order>newchassisid</order>
  2058. </decoder>
  2059. <decoder name="fortinet-fortigate-fields-v7">
  2060. <parent>fortinet-fortigate-firewall</parent>
  2061. <regex>\s+newslot="(\.*)"|\s+newslot=(\.*)\s|\s+newslot=(\.*)$</regex>
  2062. <order>newslot</order>
  2063. </decoder>
  2064. <decoder name="fortinet-fortigate-fields-v7">
  2065. <parent>fortinet-fortigate-firewall</parent>
  2066. <regex>\s+newvalue="(\.*)"|\s+newvalue=(\.*)\s|\s+newvalue=(\.*)$</regex>
  2067. <order>newvalue</order>
  2068. </decoder>
  2069. <decoder name="fortinet-fortigate-fields-v7">
  2070. <parent>fortinet-fortigate-firewall</parent>
  2071. <regex>\s+nextstat="(\.*)"|\s+nextstat=(\.*)\s|\s+nextstat=(\.*)$</regex>
  2072. <order>nextstat</order>
  2073. </decoder>
  2074. <decoder name="fortinet-fortigate-fields-v7">
  2075. <parent>fortinet-fortigate-firewall</parent>
  2076. <regex>\s+noise="(\.*)"|\s+noise=(\.*)\s|\s+noise=(\.*)$</regex>
  2077. <order>noise</order>
  2078. </decoder>
  2079. <decoder name="fortinet-fortigate-fields-v7">
  2080. <parent>fortinet-fortigate-firewall</parent>
  2081. <regex>\s+notafter="(\.*)"|\s+notafter=(\.*)\s|\s+notafter=(\.*)$</regex>
  2082. <order>notafter</order>
  2083. </decoder>
  2084. <decoder name="fortinet-fortigate-fields-v7">
  2085. <parent>fortinet-fortigate-firewall</parent>
  2086. <regex>\s+notbefore="(\.*)"|\s+notbefore=(\.*)\s|\s+notbefore=(\.*)$</regex>
  2087. <order>notbefore</order>
  2088. </decoder>
  2089. <decoder name="fortinet-fortigate-fields-v7">
  2090. <parent>fortinet-fortigate-firewall</parent>
  2091. <regex>\s+nsapi="(\.*)"|\s+nsapi=(\.*)\s|\s+nsapi=(\.*)$</regex>
  2092. <order>nsapi</order>
  2093. </decoder>
  2094. <decoder name="fortinet-fortigate-fields-v7">
  2095. <parent>fortinet-fortigate-firewall</parent>
  2096. <regex>\s+numpassmember="(\.*)"|\s+numpassmember=(\.*)\s|\s+numpassmember=(\.*)$</regex>
  2097. <order>numpassmember</order>
  2098. </decoder>
  2099. <decoder name="fortinet-fortigate-fields-v7">
  2100. <parent>fortinet-fortigate-firewall</parent>
  2101. <regex>\s+old_status="(\.*)"|\s+old_status=(\.*)\s|\s+old_status=(\.*)$</regex>
  2102. <order>old_status</order>
  2103. </decoder>
  2104. <decoder name="fortinet-fortigate-fields-v7">
  2105. <parent>fortinet-fortigate-firewall</parent>
  2106. <regex>\s+old_value="(\.*)"|\s+old_value=(\.*)\s|\s+old_value=(\.*)$</regex>
  2107. <order>old_value</order>
  2108. </decoder>
  2109. <decoder name="fortinet-fortigate-fields-v7">
  2110. <parent>fortinet-fortigate-firewall</parent>
  2111. <regex>\s+oldchannel="(\.*)"|\s+oldchannel=(\.*)\s|\s+oldchannel=(\.*)$</regex>
  2112. <order>oldchannel</order>
  2113. </decoder>
  2114. <decoder name="fortinet-fortigate-fields-v7">
  2115. <parent>fortinet-fortigate-firewall</parent>
  2116. <regex>\s+oldchassisid="(\.*)"|\s+oldchassisid=(\.*)\s|\s+oldchassisid=(\.*)$</regex>
  2117. <order>oldchassisid</order>
  2118. </decoder>
  2119. <decoder name="fortinet-fortigate-fields-v7">
  2120. <parent>fortinet-fortigate-firewall</parent>
  2121. <regex>\s+oldslot="(\.*)"|\s+oldslot=(\.*)\s|\s+oldslot=(\.*)$</regex>
  2122. <order>oldslot</order>
  2123. </decoder>
  2124. <decoder name="fortinet-fortigate-fields-v7">
  2125. <parent>fortinet-fortigate-firewall</parent>
  2126. <regex>\s+oldsn="(\.*)"|\s+oldsn=(\.*)\s|\s+oldsn=(\.*)$</regex>
  2127. <order>oldsn</order>
  2128. </decoder>
  2129. <decoder name="fortinet-fortigate-fields-v7">
  2130. <parent>fortinet-fortigate-firewall</parent>
  2131. <regex>\s+oldvalue="(\.*)"|\s+oldvalue=(\.*)\s|\s+oldvalue=(\.*)$</regex>
  2132. <order>oldvalue</order>
  2133. </decoder>
  2134. <decoder name="fortinet-fortigate-fields-v7">
  2135. <parent>fortinet-fortigate-firewall</parent>
  2136. <regex>\s+oldwprof="(\.*)"|\s+oldwprof=(\.*)\s|\s+oldwprof=(\.*)$</regex>
  2137. <order>oldwprof</order>
  2138. </decoder>
  2139. <decoder name="fortinet-fortigate-fields-v7">
  2140. <parent>fortinet-fortigate-firewall</parent>
  2141. <regex>\s+onwire="(\.*)"|\s+onwire=(\.*)\s|\s+onwire=(\.*)$</regex>
  2142. <order>onwire</order>
  2143. </decoder>
  2144. <decoder name="fortinet-fortigate-fields-v7">
  2145. <parent>fortinet-fortigate-firewall</parent>
  2146. <regex>\s+opercountry="(\.*)"|\s+opercountry=(\.*)\s|\s+opercountry=(\.*)$</regex>
  2147. <order>opercountry</order>
  2148. </decoder>
  2149. <decoder name="fortinet-fortigate-fields-v7">
  2150. <parent>fortinet-fortigate-firewall</parent>
  2151. <regex>\s+operdrmamode="(\.*)"|\s+operdrmamode=(\.*)\s|\s+operdrmamode=(\.*)$</regex>
  2152. <order>operdrmamode</order>
  2153. </decoder>
  2154. <decoder name="fortinet-fortigate-fields-v7">
  2155. <parent>fortinet-fortigate-firewall</parent>
  2156. <regex>\s+opertxpower="(\.*)"|\s+opertxpower=(\.*)\s|\s+opertxpower=(\.*)$</regex>
  2157. <order>opertxpower</order>
  2158. </decoder>
  2159. <decoder name="fortinet-fortigate-fields-v7">
  2160. <parent>fortinet-fortigate-firewall</parent>
  2161. <regex>\s+osname="(\.*)"|\s+osname=(\.*)\s|\s+osname=(\.*)$</regex>
  2162. <order>osname</order>
  2163. </decoder>
  2164. <decoder name="fortinet-fortigate-fields-v7">
  2165. <parent>fortinet-fortigate-firewall</parent>
  2166. <regex>\s+out_spi="(\.*)"|\s+out_spi=(\.*)\s|\s+out_spi=(\.*)$</regex>
  2167. <order>out_spi</order>
  2168. </decoder>
  2169. <decoder name="fortinet-fortigate-fields-v7">
  2170. <parent>fortinet-fortigate-firewall</parent>
  2171. <regex>\s+outbandwidth="(\.*)"|\s+outbandwidth=(\.*)\s|\s+outbandwidth=(\.*)$</regex>
  2172. <order>outbandwidth</order>
  2173. </decoder>
  2174. <decoder name="fortinet-fortigate-fields-v7">
  2175. <parent>fortinet-fortigate-firewall</parent>
  2176. <regex>\s+outbandwidthavailable="(\.*)"|\s+outbandwidthavailable=(\.*)\s|\s+outbandwidthavailable=(\.*)$</regex>
  2177. <order>outbandwidthavailable</order>
  2178. </decoder>
  2179. <decoder name="fortinet-fortigate-fields-v7">
  2180. <parent>fortinet-fortigate-firewall</parent>
  2181. <regex>\s+outbandwidthused="(\.*)"|\s+outbandwidthused=(\.*)\s|\s+outbandwidthused=(\.*)$</regex>
  2182. <order>outbandwidthused</order>
  2183. </decoder>
  2184. <decoder name="fortinet-fortigate-fields-v7">
  2185. <parent>fortinet-fortigate-firewall</parent>
  2186. <regex>\s+outintf="(\.*)"|\s+outintf=(\.*)\s|\s+outintf=(\.*)$</regex>
  2187. <order>outintf</order>
  2188. </decoder>
  2189. <decoder name="fortinet-fortigate-fields-v7">
  2190. <parent>fortinet-fortigate-firewall</parent>
  2191. <regex>\s+packetloss="(\.*)"|\s+packetloss=(\.*)\s|\s+packetloss=(\.*)$</regex>
  2192. <order>packetloss</order>
  2193. </decoder>
  2194. <decoder name="fortinet-fortigate-fields-v7">
  2195. <parent>fortinet-fortigate-firewall</parent>
  2196. <regex>\s+parameters="(\.*)"|\s+parameters=(\.*)\s|\s+parameters=(\.*)$</regex>
  2197. <order>parameters</order>
  2198. </decoder>
  2199. <decoder name="fortinet-fortigate-fields-v7">
  2200. <parent>fortinet-fortigate-firewall</parent>
  2201. <regex>\s+passedcount="(\.*)"|\s+passedcount=(\.*)\s|\s+passedcount=(\.*)$</regex>
  2202. <order>passedcount</order>
  2203. </decoder>
  2204. <decoder name="fortinet-fortigate-fields-v7">
  2205. <parent>fortinet-fortigate-firewall</parent>
  2206. <regex>\s+passwd="(\.*)"|\s+passwd=(\.*)\s|\s+passwd=(\.*)$</regex>
  2207. <order>passwd</order>
  2208. </decoder>
  2209. <decoder name="fortinet-fortigate-fields-v7">
  2210. <parent>fortinet-fortigate-firewall</parent>
  2211. <regex>\s+path="(\.*)"|\s+path=(\.*)\s|\s+path=(\.*)$</regex>
  2212. <order>path</order>
  2213. </decoder>
  2214. <decoder name="fortinet-fortigate-fields-v7">
  2215. <parent>fortinet-fortigate-firewall</parent>
  2216. <regex>\s+pathname="(\.*)"|\s+pathname=(\.*)\s|\s+pathname=(\.*)$</regex>
  2217. <order>pathname</order>
  2218. </decoder>
  2219. <decoder name="fortinet-fortigate-fields-v7">
  2220. <parent>fortinet-fortigate-firewall</parent>
  2221. <regex>\s+pdstport="(\.*)"|\s+pdstport=(\.*)\s|\s+pdstport=(\.*)$</regex>
  2222. <order>pdstport</order>
  2223. </decoder>
  2224. <decoder name="fortinet-fortigate-fields-v7">
  2225. <parent>fortinet-fortigate-firewall</parent>
  2226. <regex>\s+peer="(\.*)"|\s+peer=(\.*)\s|\s+peer=(\.*)$</regex>
  2227. <order>peer</order>
  2228. </decoder>
  2229. <decoder name="fortinet-fortigate-fields-v7">
  2230. <parent>fortinet-fortigate-firewall</parent>
  2231. <regex>\s+peer_notif="(\.*)"|\s+peer_notif=(\.*)\s|\s+peer_notif=(\.*)$</regex>
  2232. <order>peer_notif</order>
  2233. </decoder>
  2234. <decoder name="fortinet-fortigate-fields-v7">
  2235. <parent>fortinet-fortigate-firewall</parent>
  2236. <regex>\s+phase="(\.*)"|\s+phase=(\.*)\s|\s+phase=(\.*)$</regex>
  2237. <order>phase</order>
  2238. </decoder>
  2239. <decoder name="fortinet-fortigate-fields-v7">
  2240. <parent>fortinet-fortigate-firewall</parent>
  2241. <regex>\s+phone="(\.*)"|\s+phone=(\.*)\s|\s+phone=(\.*)$</regex>
  2242. <order>phone</order>
  2243. </decoder>
  2244. <decoder name="fortinet-fortigate-fields-v7">
  2245. <parent>fortinet-fortigate-firewall</parent>
  2246. <regex>\s+pid="(\.*)"|\s+pid=(\.*)\s|\s+pid=(\.*)$</regex>
  2247. <order>pid</order>
  2248. </decoder>
  2249. <decoder name="fortinet-fortigate-fields-v7">
  2250. <parent>fortinet-fortigate-firewall</parent>
  2251. <regex>\s+policy_id="(\.*)"|\s+policy_id=(\.*)\s|\s+policy_id=(\.*)$</regex>
  2252. <order>policy_id</order>
  2253. </decoder>
  2254. <decoder name="fortinet-fortigate-fields-v7">
  2255. <parent>fortinet-fortigate-firewall</parent>
  2256. <regex>\s+policyid="(\.*)"|\s+policyid=(\.*)\s|\s+policyid=(\.*)$</regex>
  2257. <order>policyid</order>
  2258. </decoder>
  2259. <decoder name="fortinet-fortigate-fields-v7">
  2260. <parent>fortinet-fortigate-firewall</parent>
  2261. <regex>\s+policymode="(\.*)"|\s+policymode=(\.*)\s|\s+policymode=(\.*)$</regex>
  2262. <order>policymode</order>
  2263. </decoder>
  2264. <decoder name="fortinet-fortigate-fields-v7">
  2265. <parent>fortinet-fortigate-firewall</parent>
  2266. <regex>\s+policyname="(\.*)"|\s+policyname=(\.*)\s|\s+policyname=(\.*)$</regex>
  2267. <order>policyname</order>
  2268. </decoder>
  2269. <decoder name="fortinet-fortigate-fields-v7">
  2270. <parent>fortinet-fortigate-firewall</parent>
  2271. <regex>\s+policytype="(\.*)"|\s+policytype=(\.*)\s|\s+policytype=(\.*)$</regex>
  2272. <order>policytype</order>
  2273. </decoder>
  2274. <decoder name="fortinet-fortigate-fields-v7">
  2275. <parent>fortinet-fortigate-firewall</parent>
  2276. <regex>\s+poluuid="(\.*)"|\s+poluuid=(\.*)\s|\s+poluuid=(\.*)$</regex>
  2277. <order>poluuid</order>
  2278. </decoder>
  2279. <decoder name="fortinet-fortigate-fields-v7">
  2280. <parent>fortinet-fortigate-firewall</parent>
  2281. <regex>\s+poolname="(\.*)"|\s+poolname=(\.*)\s|\s+poolname=(\.*)$</regex>
  2282. <order>poolname</order>
  2283. </decoder>
  2284. <decoder name="fortinet-fortigate-fields-v7">
  2285. <parent>fortinet-fortigate-firewall</parent>
  2286. <regex>\s+port="(\.*)"|\s+port=(\.*)\s|\s+port=(\.*)$</regex>
  2287. <order>port</order>
  2288. </decoder>
  2289. <decoder name="fortinet-fortigate-fields-v7">
  2290. <parent>fortinet-fortigate-firewall</parent>
  2291. <regex>\s+portbegin="(\.*)"|\s+portbegin=(\.*)\s|\s+portbegin=(\.*)$</regex>
  2292. <order>portbegin</order>
  2293. </decoder>
  2294. <decoder name="fortinet-fortigate-fields-v7">
  2295. <parent>fortinet-fortigate-firewall</parent>
  2296. <regex>\s+portend="(\.*)"|\s+portend=(\.*)\s|\s+portend=(\.*)$</regex>
  2297. <order>portend</order>
  2298. </decoder>
  2299. <decoder name="fortinet-fortigate-fields-v7">
  2300. <parent>fortinet-fortigate-firewall</parent>
  2301. <regex>\s+probeproto="(\.*)"|\s+probeproto=(\.*)\s|\s+probeproto=(\.*)$</regex>
  2302. <order>probeproto</order>
  2303. </decoder>
  2304. <decoder name="fortinet-fortigate-fields-v7">
  2305. <parent>fortinet-fortigate-firewall</parent>
  2306. <regex>\s+process="(\.*)"|\s+process=(\.*)\s|\s+process=(\.*)$</regex>
  2307. <order>process</order>
  2308. </decoder>
  2309. <decoder name="fortinet-fortigate-fields-v7">
  2310. <parent>fortinet-fortigate-firewall</parent>
  2311. <regex>\s+processtime="(\.*)"|\s+processtime=(\.*)\s|\s+processtime=(\.*)$</regex>
  2312. <order>processtime</order>
  2313. </decoder>
  2314. <decoder name="fortinet-fortigate-fields-v7">
  2315. <parent>fortinet-fortigate-firewall</parent>
  2316. <regex>\s+product="(\.*)"|\s+product=(\.*)\s|\s+product=(\.*)$</regex>
  2317. <order>product</order>
  2318. </decoder>
  2319. <decoder name="fortinet-fortigate-fields-v7">
  2320. <parent>fortinet-fortigate-firewall</parent>
  2321. <regex>\s+profile="(\.*)"|\s+profile=(\.*)\s|\s+profile=(\.*)$</regex>
  2322. <order>profile</order>
  2323. </decoder>
  2324. <decoder name="fortinet-fortigate-fields-v7">
  2325. <parent>fortinet-fortigate-firewall</parent>
  2326. <regex>\s+profiletype="(\.*)"|\s+profiletype=(\.*)\s|\s+profiletype=(\.*)$</regex>
  2327. <order>profiletype</order>
  2328. </decoder>
  2329. <decoder name="fortinet-fortigate-fields-v7">
  2330. <parent>fortinet-fortigate-firewall</parent>
  2331. <regex>\s+proto="(\.*)"|\s+proto=(\.*)\s|\s+proto=(\.*)$</regex>
  2332. <order>proto</order>
  2333. </decoder>
  2334. <decoder name="fortinet-fortigate-fields-v7">
  2335. <parent>fortinet-fortigate-firewall</parent>
  2336. <regex>\s+protocol="(\.*)"|\s+protocol=(\.*)\s|\s+protocol=(\.*)$</regex>
  2337. <order>protocol</order>
  2338. </decoder>
  2339. <decoder name="fortinet-fortigate-fields-v7">
  2340. <parent>fortinet-fortigate-firewall</parent>
  2341. <regex>\s+proxyapptype="(\.*)"|\s+proxyapptype=(\.*)\s|\s+proxyapptype=(\.*)$</regex>
  2342. <order>proxyapptype</order>
  2343. </decoder>
  2344. <decoder name="fortinet-fortigate-fields-v7">
  2345. <parent>fortinet-fortigate-firewall</parent>
  2346. <regex>\s+psrcport="(\.*)"|\s+psrcport=(\.*)\s|\s+psrcport=(\.*)$</regex>
  2347. <order>psrcport</order>
  2348. </decoder>
  2349. <decoder name="fortinet-fortigate-fields-v7">
  2350. <parent>fortinet-fortigate-firewall</parent>
  2351. <regex>\s+qclass="(\.*)"|\s+qclass=(\.*)\s|\s+qclass=(\.*)$</regex>
  2352. <order>qclass</order>
  2353. </decoder>
  2354. <decoder name="fortinet-fortigate-fields-v7">
  2355. <parent>fortinet-fortigate-firewall</parent>
  2356. <regex>\s+qname="(\.*)"|\s+qname=(\.*)\s|\s+qname=(\.*)$</regex>
  2357. <order>qname</order>
  2358. </decoder>
  2359. <decoder name="fortinet-fortigate-fields-v7">
  2360. <parent>fortinet-fortigate-firewall</parent>
  2361. <regex>\s+qtype="(\.*)"|\s+qtype=(\.*)\s|\s+qtype=(\.*)$</regex>
  2362. <order>qtype</order>
  2363. </decoder>
  2364. <decoder name="fortinet-fortigate-fields-v7">
  2365. <parent>fortinet-fortigate-firewall</parent>
  2366. <regex>\s+qtypeval="(\.*)"|\s+qtypeval=(\.*)\s|\s+qtypeval=(\.*)$</regex>
  2367. <order>qtypeval</order>
  2368. </decoder>
  2369. <decoder name="fortinet-fortigate-fields-v7">
  2370. <parent>fortinet-fortigate-firewall</parent>
  2371. <regex>\s+quarskip="(\.*)"|\s+quarskip=(\.*)\s|\s+quarskip=(\.*)$</regex>
  2372. <order>quarskip</order>
  2373. </decoder>
  2374. <decoder name="fortinet-fortigate-fields-v7">
  2375. <parent>fortinet-fortigate-firewall</parent>
  2376. <regex>\s+quotaexceeded="(\.*)"|\s+quotaexceeded=(\.*)\s|\s+quotaexceeded=(\.*)$</regex>
  2377. <order>quotaexceeded</order>
  2378. </decoder>
  2379. <decoder name="fortinet-fortigate-fields-v7">
  2380. <parent>fortinet-fortigate-firewall</parent>
  2381. <regex>\s+quotamax="(\.*)"|\s+quotamax=(\.*)\s|\s+quotamax=(\.*)$</regex>
  2382. <order>quotamax</order>
  2383. </decoder>
  2384. <decoder name="fortinet-fortigate-fields-v7">
  2385. <parent>fortinet-fortigate-firewall</parent>
  2386. <regex>\s+quotatype="(\.*)"|\s+quotatype=(\.*)\s|\s+quotatype=(\.*)$</regex>
  2387. <order>quotatype</order>
  2388. </decoder>
  2389. <decoder name="fortinet-fortigate-fields-v7">
  2390. <parent>fortinet-fortigate-firewall</parent>
  2391. <regex>\s+quotaused="(\.*)"|\s+quotaused=(\.*)\s|\s+quotaused=(\.*)$</regex>
  2392. <order>quotaused</order>
  2393. </decoder>
  2394. <decoder name="fortinet-fortigate-fields-v7">
  2395. <parent>fortinet-fortigate-firewall</parent>
  2396. <regex>\s+radioband="(\.*)"|\s+radioband=(\.*)\s|\s+radioband=(\.*)$</regex>
  2397. <order>radioband</order>
  2398. </decoder>
  2399. <decoder name="fortinet-fortigate-fields-v7">
  2400. <parent>fortinet-fortigate-firewall</parent>
  2401. <regex>\s+radioid="(\.*)"|\s+radioid=(\.*)\s|\s+radioid=(\.*)$</regex>
  2402. <order>radioid</order>
  2403. </decoder>
  2404. <decoder name="fortinet-fortigate-fields-v7">
  2405. <parent>fortinet-fortigate-firewall</parent>
  2406. <regex>\s+radioidclosest="(\.*)"|\s+radioidclosest=(\.*)\s|\s+radioidclosest=(\.*)$</regex>
  2407. <order>radioidclosest</order>
  2408. </decoder>
  2409. <decoder name="fortinet-fortigate-fields-v7">
  2410. <parent>fortinet-fortigate-firewall</parent>
  2411. <regex>\s+radioiddetected="(\.*)"|\s+radioiddetected=(\.*)\s|\s+radioiddetected=(\.*)$</regex>
  2412. <order>radioiddetected</order>
  2413. </decoder>
  2414. <decoder name="fortinet-fortigate-fields-v7">
  2415. <parent>fortinet-fortigate-firewall</parent>
  2416. <regex>\s+rai="(\.*)"|\s+rai=(\.*)\s|\s+rai=(\.*)$</regex>
  2417. <order>rai</order>
  2418. </decoder>
  2419. <decoder name="fortinet-fortigate-fields-v7">
  2420. <parent>fortinet-fortigate-firewall</parent>
  2421. <regex>\s+rat="(\.*)"|\s+rat=(\.*)\s|\s+rat=(\.*)$</regex>
  2422. <order>rat</order>
  2423. </decoder>
  2424. <decoder name="fortinet-fortigate-fields-v7">
  2425. <parent>fortinet-fortigate-firewall</parent>
  2426. <regex>\s+rate="(\.*)"|\s+rate=(\.*)\s|\s+rate=(\.*)$</regex>
  2427. <order>rate</order>
  2428. </decoder>
  2429. <decoder name="fortinet-fortigate-fields-v7">
  2430. <parent>fortinet-fortigate-firewall</parent>
  2431. <regex>\s+ratemethod="(\.*)"|\s+ratemethod=(\.*)\s|\s+ratemethod=(\.*)$</regex>
  2432. <order>ratemethod</order>
  2433. </decoder>
  2434. <decoder name="fortinet-fortigate-fields-v7">
  2435. <parent>fortinet-fortigate-firewall</parent>
  2436. <regex>\s+rawdata="(\.*)"|\s+rawdata=(\.*)\s|\s+rawdata=(\.*)$</regex>
  2437. <order>rawdata</order>
  2438. </decoder>
  2439. <decoder name="fortinet-fortigate-fields-v7">
  2440. <parent>fortinet-fortigate-firewall</parent>
  2441. <regex>\s+rawdataid="(\.*)"|\s+rawdataid=(\.*)\s|\s+rawdataid=(\.*)$</regex>
  2442. <order>rawdataid</order>
  2443. </decoder>
  2444. <decoder name="fortinet-fortigate-fields-v7">
  2445. <parent>fortinet-fortigate-firewall</parent>
  2446. <regex>\s+rcode="(\.*)"|\s+rcode=(\.*)\s|\s+rcode=(\.*)$</regex>
  2447. <order>rcode</order>
  2448. </decoder>
  2449. <decoder name="fortinet-fortigate-fields-v7">
  2450. <parent>fortinet-fortigate-firewall</parent>
  2451. <regex>\s+rcvdbyte="(\.*)"|\s+rcvdbyte=(\.*)\s|\s+rcvdbyte=(\.*)$</regex>
  2452. <order>rcvdbyte</order>
  2453. </decoder>
  2454. <decoder name="fortinet-fortigate-fields-v7">
  2455. <parent>fortinet-fortigate-firewall</parent>
  2456. <regex>\s+rcvddelta="(\.*)"|\s+rcvddelta=(\.*)\s|\s+rcvddelta=(\.*)$</regex>
  2457. <order>rcvddelta</order>
  2458. </decoder>
  2459. <decoder name="fortinet-fortigate-fields-v7">
  2460. <parent>fortinet-fortigate-firewall</parent>
  2461. <regex>\s+rcvdpkt="(\.*)"|\s+rcvdpkt=(\.*)\s|\s+rcvdpkt=(\.*)$</regex>
  2462. <order>rcvdpkt</order>
  2463. </decoder>
  2464. <decoder name="fortinet-fortigate-fields-v7">
  2465. <parent>fortinet-fortigate-firewall</parent>
  2466. <regex>\s+rcvdpktdelta="(\.*)"|\s+rcvdpktdelta=(\.*)\s|\s+rcvdpktdelta=(\.*)$</regex>
  2467. <order>rcvdpktdelta</order>
  2468. </decoder>
  2469. <decoder name="fortinet-fortigate-fields-v7">
  2470. <parent>fortinet-fortigate-firewall</parent>
  2471. <regex>\s+realserverid="(\.*)"|\s+realserverid=(\.*)\s|\s+realserverid=(\.*)$</regex>
  2472. <order>realserverid</order>
  2473. </decoder>
  2474. <decoder name="fortinet-fortigate-fields-v7">
  2475. <parent>fortinet-fortigate-firewall</parent>
  2476. <regex>\s+reason="(\.*)"|\s+reason=(\.*)\s|\s+reason=(\.*)$</regex>
  2477. <order>reason</order>
  2478. </decoder>
  2479. <decoder name="fortinet-fortigate-fields-v7">
  2480. <parent>fortinet-fortigate-firewall</parent>
  2481. <regex>\s+received="(\.*)"|\s+received=(\.*)\s|\s+received=(\.*)$</regex>
  2482. <order>received</order>
  2483. </decoder>
  2484. <decoder name="fortinet-fortigate-fields-v7">
  2485. <parent>fortinet-fortigate-firewall</parent>
  2486. <regex>\s+receivedsignature="(\.*)"|\s+receivedsignature=(\.*)\s|\s+receivedsignature=(\.*)$</regex>
  2487. <order>receivedsignature</order>
  2488. </decoder>
  2489. <decoder name="fortinet-fortigate-fields-v7">
  2490. <parent>fortinet-fortigate-firewall</parent>
  2491. <regex>\s+recipient="(\.*)"|\s+recipient=(\.*)\s|\s+recipient=(\.*)$</regex>
  2492. <order>recipient</order>
  2493. </decoder>
  2494. <decoder name="fortinet-fortigate-fields-v7">
  2495. <parent>fortinet-fortigate-firewall</parent>
  2496. <regex>\s+red="(\.*)"|\s+red=(\.*)\s|\s+red=(\.*)$</regex>
  2497. <order>red</order>
  2498. </decoder>
  2499. <decoder name="fortinet-fortigate-fields-v7">
  2500. <parent>fortinet-fortigate-firewall</parent>
  2501. <regex>\s+ref="(\.*)"|\s+ref=(\.*)\s|\s+ref=(\.*)$</regex>
  2502. <order>ref</order>
  2503. </decoder>
  2504. <decoder name="fortinet-fortigate-fields-v7">
  2505. <parent>fortinet-fortigate-firewall</parent>
  2506. <regex>\s+referralurl="(\.*)"|\s+referralurl=(\.*)\s|\s+referralurl=(\.*)$</regex>
  2507. <order>referralurl</order>
  2508. </decoder>
  2509. <decoder name="fortinet-fortigate-fields-v7">
  2510. <parent>fortinet-fortigate-firewall</parent>
  2511. <regex>\s+remip="(\.*)"|\s+remip=(\.*)\s|\s+remip=(\.*)$</regex>
  2512. <order>remip</order>
  2513. </decoder>
  2514. <decoder name="fortinet-fortigate-fields-v7">
  2515. <parent>fortinet-fortigate-firewall</parent>
  2516. <regex>\s+remote="(\.*)"|\s+remote=(\.*)\s|\s+remote=(\.*)$</regex>
  2517. <order>remote</order>
  2518. </decoder>
  2519. <decoder name="fortinet-fortigate-fields-v7">
  2520. <parent>fortinet-fortigate-firewall</parent>
  2521. <regex>\s+remotetunnelid="(\.*)"|\s+remotetunnelid=(\.*)\s|\s+remotetunnelid=(\.*)$</regex>
  2522. <order>remotetunnelid</order>
  2523. </decoder>
  2524. <decoder name="fortinet-fortigate-fields-v7">
  2525. <parent>fortinet-fortigate-firewall</parent>
  2526. <regex>\s+remotewtptime="(\.*)"|\s+remotewtptime=(\.*)\s|\s+remotewtptime=(\.*)$</regex>
  2527. <order>remotewtptime</order>
  2528. </decoder>
  2529. <decoder name="fortinet-fortigate-fields-v7">
  2530. <parent>fortinet-fortigate-firewall</parent>
  2531. <regex>\s+remport="(\.*)"|\s+remport=(\.*)\s|\s+remport=(\.*)$</regex>
  2532. <order>remport</order>
  2533. </decoder>
  2534. <decoder name="fortinet-fortigate-fields-v7">
  2535. <parent>fortinet-fortigate-firewall</parent>
  2536. <regex>\s+replydstintf="(\.*)"|\s+replydstintf=(\.*)\s|\s+replydstintf=(\.*)$</regex>
  2537. <order>replydstintf</order>
  2538. </decoder>
  2539. <decoder name="fortinet-fortigate-fields-v7">
  2540. <parent>fortinet-fortigate-firewall</parent>
  2541. <regex>\s+replysrcintf="(\.*)"|\s+replysrcintf=(\.*)\s|\s+replysrcintf=(\.*)$</regex>
  2542. <order>replysrcintf</order>
  2543. </decoder>
  2544. <decoder name="fortinet-fortigate-fields-v7">
  2545. <parent>fortinet-fortigate-firewall</parent>
  2546. <regex>\s+reporttype="(\.*)"|\s+reporttype=(\.*)\s|\s+reporttype=(\.*)$</regex>
  2547. <order>reporttype</order>
  2548. </decoder>
  2549. <decoder name="fortinet-fortigate-fields-v7">
  2550. <parent>fortinet-fortigate-firewall</parent>
  2551. <regex>\s+reqtype="(\.*)"|\s+reqtype=(\.*)\s|\s+reqtype=(\.*)$</regex>
  2552. <order>reqtype</order>
  2553. </decoder>
  2554. <decoder name="fortinet-fortigate-fields-v7">
  2555. <parent>fortinet-fortigate-firewall</parent>
  2556. <regex>\s+request_name="(\.*)"|\s+request_name=(\.*)\s|\s+request_name=(\.*)$</regex>
  2557. <order>request_name</order>
  2558. </decoder>
  2559. <decoder name="fortinet-fortigate-fields-v7">
  2560. <parent>fortinet-fortigate-firewall</parent>
  2561. <regex>\s+result="(\.*)"|\s+result=(\.*)\s|\s+result=(\.*)$</regex>
  2562. <order>result</order>
  2563. </decoder>
  2564. <decoder name="fortinet-fortigate-fields-v7">
  2565. <parent>fortinet-fortigate-firewall</parent>
  2566. <regex>\s+role="(\.*)"|\s+role=(\.*)\s|\s+role=(\.*)$</regex>
  2567. <order>role</order>
  2568. </decoder>
  2569. <decoder name="fortinet-fortigate-fields-v7">
  2570. <parent>fortinet-fortigate-firewall</parent>
  2571. <regex>\s+rssi="(\.*)"|\s+rssi=(\.*)\s|\s+rssi=(\.*)$</regex>
  2572. <order>rssi</order>
  2573. </decoder>
  2574. <decoder name="fortinet-fortigate-fields-v7">
  2575. <parent>fortinet-fortigate-firewall</parent>
  2576. <regex>\s+rsso_key="(\.*)"|\s+rsso_key=(\.*)\s|\s+rsso_key=(\.*)$</regex>
  2577. <order>rsso_key</order>
  2578. </decoder>
  2579. <decoder name="fortinet-fortigate-fields-v7">
  2580. <parent>fortinet-fortigate-firewall</parent>
  2581. <regex>\s+ruleid="(\.*)"|\s+ruleid=(\.*)\s|\s+ruleid=(\.*)$</regex>
  2582. <order>ruleid</order>
  2583. </decoder>
  2584. <decoder name="fortinet-fortigate-fields-v7">
  2585. <parent>fortinet-fortigate-firewall</parent>
  2586. <regex>\s+rulename="(\.*)"|\s+rulename=(\.*)\s|\s+rulename=(\.*)$</regex>
  2587. <order>rulename</order>
  2588. </decoder>
  2589. <decoder name="fortinet-fortigate-fields-v7">
  2590. <parent>fortinet-fortigate-firewall</parent>
  2591. <regex>\s+saasapp="(\.*)"|\s+saasapp=(\.*)\s|\s+saasapp=(\.*)$</regex>
  2592. <order>saasapp</order>
  2593. </decoder>
  2594. <decoder name="fortinet-fortigate-fields-v7">
  2595. <parent>fortinet-fortigate-firewall</parent>
  2596. <regex>\s+saasname="(\.*)"|\s+saasname=(\.*)\s|\s+saasname=(\.*)$</regex>
  2597. <order>saasname</order>
  2598. </decoder>
  2599. <decoder name="fortinet-fortigate-fields-v7">
  2600. <parent>fortinet-fortigate-firewall</parent>
  2601. <regex>\s+saddr="(\.*)"|\s+saddr=(\.*)\s|\s+saddr=(\.*)$</regex>
  2602. <order>saddr</order>
  2603. </decoder>
  2604. <decoder name="fortinet-fortigate-fields-v7">
  2605. <parent>fortinet-fortigate-firewall</parent>
  2606. <regex>\s+san="(\.*)"|\s+san=(\.*)\s|\s+san=(\.*)$</regex>
  2607. <order>san</order>
  2608. </decoder>
  2609. <decoder name="fortinet-fortigate-fields-v7">
  2610. <parent>fortinet-fortigate-firewall</parent>
  2611. <regex>\s+scantime="(\.*)"|\s+scantime=(\.*)\s|\s+scantime=(\.*)$</regex>
  2612. <order>scantime</order>
  2613. </decoder>
  2614. <decoder name="fortinet-fortigate-fields-v7">
  2615. <parent>fortinet-fortigate-firewall</parent>
  2616. <regex>\s+scertcname="(\.*)"|\s+scertcname=(\.*)\s|\s+scertcname=(\.*)$</regex>
  2617. <order>scertcname</order>
  2618. </decoder>
  2619. <decoder name="fortinet-fortigate-fields-v7">
  2620. <parent>fortinet-fortigate-firewall</parent>
  2621. <regex>\s+scertissuer="(\.*)"|\s+scertissuer=(\.*)\s|\s+scertissuer=(\.*)$</regex>
  2622. <order>scertissuer</order>
  2623. </decoder>
  2624. <decoder name="fortinet-fortigate-fields-v7">
  2625. <parent>fortinet-fortigate-firewall</parent>
  2626. <regex>\s+scope="(\.*)"|\s+scope=(\.*)\s|\s+scope=(\.*)$</regex>
  2627. <order>scope</order>
  2628. </decoder>
  2629. <decoder name="fortinet-fortigate-fields-v7">
  2630. <parent>fortinet-fortigate-firewall</parent>
  2631. <regex>\s+security="(\.*)"|\s+security=(\.*)\s|\s+security=(\.*)$</regex>
  2632. <order>security</order>
  2633. </decoder>
  2634. <decoder name="fortinet-fortigate-fields-v7">
  2635. <parent>fortinet-fortigate-firewall</parent>
  2636. <regex>\s+selection="(\.*)"|\s+selection=(\.*)\s|\s+selection=(\.*)$</regex>
  2637. <order>selection</order>
  2638. </decoder>
  2639. <decoder name="fortinet-fortigate-fields-v7">
  2640. <parent>fortinet-fortigate-firewall</parent>
  2641. <regex>\s+sender="(\.*)"|\s+sender=(\.*)\s|\s+sender=(\.*)$</regex>
  2642. <order>sender</order>
  2643. </decoder>
  2644. <decoder name="fortinet-fortigate-fields-v7">
  2645. <parent>fortinet-fortigate-firewall</parent>
  2646. <regex>\s+sensitivity="(\.*)"|\s+sensitivity=(\.*)\s|\s+sensitivity=(\.*)$</regex>
  2647. <order>sensitivity</order>
  2648. </decoder>
  2649. <decoder name="fortinet-fortigate-fields-v7">
  2650. <parent>fortinet-fortigate-firewall</parent>
  2651. <regex>\s+sensor="(\.*)"|\s+sensor=(\.*)\s|\s+sensor=(\.*)$</regex>
  2652. <order>sensor</order>
  2653. </decoder>
  2654. <decoder name="fortinet-fortigate-fields-v7">
  2655. <parent>fortinet-fortigate-firewall</parent>
  2656. <regex>\s+sentbyte="(\.*)"|\s+sentbyte=(\.*)\s|\s+sentbyte=(\.*)$</regex>
  2657. <order>sentbyte</order>
  2658. </decoder>
  2659. <decoder name="fortinet-fortigate-fields-v7">
  2660. <parent>fortinet-fortigate-firewall</parent>
  2661. <regex>\s+sentdelta="(\.*)"|\s+sentdelta=(\.*)\s|\s+sentdelta=(\.*)$</regex>
  2662. <order>sentdelta</order>
  2663. </decoder>
  2664. <decoder name="fortinet-fortigate-fields-v7">
  2665. <parent>fortinet-fortigate-firewall</parent>
  2666. <regex>\s+sentpkt="(\.*)"|\s+sentpkt=(\.*)\s|\s+sentpkt=(\.*)$</regex>
  2667. <order>sentpkt</order>
  2668. </decoder>
  2669. <decoder name="fortinet-fortigate-fields-v7">
  2670. <parent>fortinet-fortigate-firewall</parent>
  2671. <regex>\s+sentpktdelta="(\.*)"|\s+sentpktdelta=(\.*)\s|\s+sentpktdelta=(\.*)$</regex>
  2672. <order>sentpktdelta</order>
  2673. </decoder>
  2674. <decoder name="fortinet-fortigate-fields-v7">
  2675. <parent>fortinet-fortigate-firewall</parent>
  2676. <regex>\s+seq="(\.*)"|\s+seq=(\.*)\s|\s+seq=(\.*)$</regex>
  2677. <order>seq</order>
  2678. </decoder>
  2679. <decoder name="fortinet-fortigate-fields-v7">
  2680. <parent>fortinet-fortigate-firewall</parent>
  2681. <regex>\s+seqnum="(\.*)"|\s+seqnum=(\.*)\s|\s+seqnum=(\.*)$</regex>
  2682. <order>seqnum</order>
  2683. </decoder>
  2684. <decoder name="fortinet-fortigate-fields-v7">
  2685. <parent>fortinet-fortigate-firewall</parent>
  2686. <regex>\s+serial="(\.*)"|\s+serial=(\.*)\s|\s+serial=(\.*)$</regex>
  2687. <order>serial</order>
  2688. </decoder>
  2689. <decoder name="fortinet-fortigate-fields-v7">
  2690. <parent>fortinet-fortigate-firewall</parent>
  2691. <regex>\s+serialno="(\.*)"|\s+serialno=(\.*)\s|\s+serialno=(\.*)$</regex>
  2692. <order>serialno</order>
  2693. </decoder>
  2694. <decoder name="fortinet-fortigate-fields-v7">
  2695. <parent>fortinet-fortigate-firewall</parent>
  2696. <regex>\s+server="(\.*)"|\s+server=(\.*)\s|\s+server=(\.*)$</regex>
  2697. <order>server</order>
  2698. </decoder>
  2699. <decoder name="fortinet-fortigate-fields-v7">
  2700. <parent>fortinet-fortigate-firewall</parent>
  2701. <regex>\s+serveraddr="(\.*)"|\s+serveraddr=(\.*)\s|\s+serveraddr=(\.*)$</regex>
  2702. <order>serveraddr</order>
  2703. </decoder>
  2704. <decoder name="fortinet-fortigate-fields-v7">
  2705. <parent>fortinet-fortigate-firewall</parent>
  2706. <regex>\s+servername="(\.*)"|\s+servername=(\.*)\s|\s+servername=(\.*)$</regex>
  2707. <order>servername</order>
  2708. </decoder>
  2709. <decoder name="fortinet-fortigate-fields-v7">
  2710. <parent>fortinet-fortigate-firewall</parent>
  2711. <regex>\s+serverresponsetime="(\.*)"|\s+serverresponsetime=(\.*)\s|\s+serverresponsetime=(\.*)$</regex>
  2712. <order>serverresponsetime</order>
  2713. </decoder>
  2714. <decoder name="fortinet-fortigate-fields-v7">
  2715. <parent>fortinet-fortigate-firewall</parent>
  2716. <regex>\s+service="(\.*)"|\s+service=(\.*)\s|\s+service=(\.*)$</regex>
  2717. <order>service</order>
  2718. </decoder>
  2719. <decoder name="fortinet-fortigate-fields-v7">
  2720. <parent>fortinet-fortigate-firewall</parent>
  2721. <regex>\s+serviceid="(\.*)"|\s+serviceid=(\.*)\s|\s+serviceid=(\.*)$</regex>
  2722. <order>serviceid</order>
  2723. </decoder>
  2724. <decoder name="fortinet-fortigate-fields-v7">
  2725. <parent>fortinet-fortigate-firewall</parent>
  2726. <regex>\s+session_id="(\.*)"|\s+session_id=(\.*)\s|\s+session_id=(\.*)$</regex>
  2727. <order>session_id</order>
  2728. </decoder>
  2729. <decoder name="fortinet-fortigate-fields-v7">
  2730. <parent>fortinet-fortigate-firewall</parent>
  2731. <regex>\s+sessionid="(\.*)"|\s+sessionid=(\.*)\s|\s+sessionid=(\.*)$</regex>
  2732. <order>sessionid</order>
  2733. </decoder>
  2734. <decoder name="fortinet-fortigate-fields-v7">
  2735. <parent>fortinet-fortigate-firewall</parent>
  2736. <regex>\s+setuprate="(\.*)"|\s+setuprate=(\.*)\s|\s+setuprate=(\.*)$</regex>
  2737. <order>setuprate</order>
  2738. </decoder>
  2739. <decoder name="fortinet-fortigate-fields-v7">
  2740. <parent>fortinet-fortigate-firewall</parent>
  2741. <regex>\s+severity="(\.*)"|\s+severity=(\.*)\s|\s+severity=(\.*)$</regex>
  2742. <order>severity</order>
  2743. </decoder>
  2744. <decoder name="fortinet-fortigate-fields-v7">
  2745. <parent>fortinet-fortigate-firewall</parent>
  2746. <regex>\s+shaperdroprcvdbyte="(\.*)"|\s+shaperdroprcvdbyte=(\.*)\s|\s+shaperdroprcvdbyte=(\.*)$</regex>
  2747. <order>shaperdroprcvdbyte</order>
  2748. </decoder>
  2749. <decoder name="fortinet-fortigate-fields-v7">
  2750. <parent>fortinet-fortigate-firewall</parent>
  2751. <regex>\s+shaperdropsentbyte="(\.*)"|\s+shaperdropsentbyte=(\.*)\s|\s+shaperdropsentbyte=(\.*)$</regex>
  2752. <order>shaperdropsentbyte</order>
  2753. </decoder>
  2754. <decoder name="fortinet-fortigate-fields-v7">
  2755. <parent>fortinet-fortigate-firewall</parent>
  2756. <regex>\s+shaperperipdropbyte="(\.*)"|\s+shaperperipdropbyte=(\.*)\s|\s+shaperperipdropbyte=(\.*)$</regex>
  2757. <order>shaperperipdropbyte</order>
  2758. </decoder>
  2759. <decoder name="fortinet-fortigate-fields-v7">
  2760. <parent>fortinet-fortigate-firewall</parent>
  2761. <regex>\s+shaperperipname="(\.*)"|\s+shaperperipname=(\.*)\s|\s+shaperperipname=(\.*)$</regex>
  2762. <order>shaperperipname</order>
  2763. </decoder>
  2764. <decoder name="fortinet-fortigate-fields-v7">
  2765. <parent>fortinet-fortigate-firewall</parent>
  2766. <regex>\s+shaperrcvdname="(\.*)"|\s+shaperrcvdname=(\.*)\s|\s+shaperrcvdname=(\.*)$</regex>
  2767. <order>shaperrcvdname</order>
  2768. </decoder>
  2769. <decoder name="fortinet-fortigate-fields-v7">
  2770. <parent>fortinet-fortigate-firewall</parent>
  2771. <regex>\s+shapersentname="(\.*)"|\s+shapersentname=(\.*)\s|\s+shapersentname=(\.*)$</regex>
  2772. <order>shapersentname</order>
  2773. </decoder>
  2774. <decoder name="fortinet-fortigate-fields-v7">
  2775. <parent>fortinet-fortigate-firewall</parent>
  2776. <regex>\s+shapingpolicyid="(\.*)"|\s+shapingpolicyid=(\.*)\s|\s+shapingpolicyid=(\.*)$</regex>
  2777. <order>shapingpolicyid</order>
  2778. </decoder>
  2779. <decoder name="fortinet-fortigate-fields-v7">
  2780. <parent>fortinet-fortigate-firewall</parent>
  2781. <regex>\s+shapingpolicyname="(\.*)"|\s+shapingpolicyname=(\.*)\s|\s+shapingpolicyname=(\.*)$</regex>
  2782. <order>shapingpolicyname</order>
  2783. </decoder>
  2784. <decoder name="fortinet-fortigate-fields-v7">
  2785. <parent>fortinet-fortigate-firewall</parent>
  2786. <regex>\s+sharename="(\.*)"|\s+sharename=(\.*)\s|\s+sharename=(\.*)$</regex>
  2787. <order>sharename</order>
  2788. </decoder>
  2789. <decoder name="fortinet-fortigate-fields-v7">
  2790. <parent>fortinet-fortigate-firewall</parent>
  2791. <regex>\s+signal="(\.*)"|\s+signal=(\.*)\s|\s+signal=(\.*)$</regex>
  2792. <order>signal</order>
  2793. </decoder>
  2794. <decoder name="fortinet-fortigate-fields-v7">
  2795. <parent>fortinet-fortigate-firewall</parent>
  2796. <regex>\s+size="(\.*)"|\s+size=(\.*)\s|\s+size=(\.*)$</regex>
  2797. <order>size</order>
  2798. </decoder>
  2799. <decoder name="fortinet-fortigate-fields-v7">
  2800. <parent>fortinet-fortigate-firewall</parent>
  2801. <regex>\s+ski="(\.*)"|\s+ski=(\.*)\s|\s+ski=(\.*)$</regex>
  2802. <order>ski</order>
  2803. </decoder>
  2804. <decoder name="fortinet-fortigate-fields-v7">
  2805. <parent>fortinet-fortigate-firewall</parent>
  2806. <regex>\s+slamap="(\.*)"|\s+slamap=(\.*)\s|\s+slamap=(\.*)$</regex>
  2807. <order>slamap</order>
  2808. </decoder>
  2809. <decoder name="fortinet-fortigate-fields-v7">
  2810. <parent>fortinet-fortigate-firewall</parent>
  2811. <regex>\s+slatargetid="(\.*)"|\s+slatargetid=(\.*)\s|\s+slatargetid=(\.*)$</regex>
  2812. <order>slatargetid</order>
  2813. </decoder>
  2814. <decoder name="fortinet-fortigate-fields-v7">
  2815. <parent>fortinet-fortigate-firewall</parent>
  2816. <regex>\s+slctdrmamode="(\.*)"|\s+slctdrmamode=(\.*)\s|\s+slctdrmamode=(\.*)$</regex>
  2817. <order>slctdrmamode</order>
  2818. </decoder>
  2819. <decoder name="fortinet-fortigate-fields-v7">
  2820. <parent>fortinet-fortigate-firewall</parent>
  2821. <regex>\s+slot="(\.*)"|\s+slot=(\.*)\s|\s+slot=(\.*)$</regex>
  2822. <order>slot</order>
  2823. </decoder>
  2824. <decoder name="fortinet-fortigate-fields-v7">
  2825. <parent>fortinet-fortigate-firewall</parent>
  2826. <regex>\s+sn="(\.*)"|\s+sn=(\.*)\s|\s+sn=(\.*)$</regex>
  2827. <order>sn</order>
  2828. </decoder>
  2829. <decoder name="fortinet-fortigate-fields-v7">
  2830. <parent>fortinet-fortigate-firewall</parent>
  2831. <regex>\s+snclosest="(\.*)"|\s+snclosest=(\.*)\s|\s+snclosest=(\.*)$</regex>
  2832. <order>snclosest</order>
  2833. </decoder>
  2834. <decoder name="fortinet-fortigate-fields-v7">
  2835. <parent>fortinet-fortigate-firewall</parent>
  2836. <regex>\s+sndetected="(\.*)"|\s+sndetected=(\.*)\s|\s+sndetected=(\.*)$</regex>
  2837. <order>sndetected</order>
  2838. </decoder>
  2839. <decoder name="fortinet-fortigate-fields-v7">
  2840. <parent>fortinet-fortigate-firewall</parent>
  2841. <regex>\s+snetwork="(\.*)"|\s+snetwork=(\.*)\s|\s+snetwork=(\.*)$</regex>
  2842. <order>snetwork</order>
  2843. </decoder>
  2844. <decoder name="fortinet-fortigate-fields-v7">
  2845. <parent>fortinet-fortigate-firewall</parent>
  2846. <regex>\s+sni="(\.*)"|\s+sni=(\.*)\s|\s+sni=(\.*)$</regex>
  2847. <order>sni</order>
  2848. </decoder>
  2849. <decoder name="fortinet-fortigate-fields-v7">
  2850. <parent>fortinet-fortigate-firewall</parent>
  2851. <regex>\s+snmeshparent="(\.*)"|\s+snmeshparent=(\.*)\s|\s+snmeshparent=(\.*)$</regex>
  2852. <order>snmeshparent</order>
  2853. </decoder>
  2854. <decoder name="fortinet-fortigate-fields-v7">
  2855. <parent>fortinet-fortigate-firewall</parent>
  2856. <regex>\s+snprev="(\.*)"|\s+snprev=(\.*)\s|\s+snprev=(\.*)$</regex>
  2857. <order>snprev</order>
  2858. </decoder>
  2859. <decoder name="fortinet-fortigate-fields-v7">
  2860. <parent>fortinet-fortigate-firewall</parent>
  2861. <regex>\s+snr="(\.*)"|\s+snr=(\.*)\s|\s+snr=(\.*)$</regex>
  2862. <order>snr</order>
  2863. </decoder>
  2864. <decoder name="fortinet-fortigate-fields-v7">
  2865. <parent>fortinet-fortigate-firewall</parent>
  2866. <regex>\s+source_mac="(\.*)"|\s+source_mac=(\.*)\s|\s+source_mac=(\.*)$</regex>
  2867. <order>source_mac</order>
  2868. </decoder>
  2869. <decoder name="fortinet-fortigate-fields-v7">
  2870. <parent>fortinet-fortigate-firewall</parent>
  2871. <regex>\s+speedtestserver="(\.*)"|\s+speedtestserver=(\.*)\s|\s+speedtestserver=(\.*)$</regex>
  2872. <order>speedtestserver</order>
  2873. </decoder>
  2874. <decoder name="fortinet-fortigate-fields-v7">
  2875. <parent>fortinet-fortigate-firewall</parent>
  2876. <regex>\s+spi="(\.*)"|\s+spi=(\.*)\s|\s+spi=(\.*)$</regex>
  2877. <order>spi</order>
  2878. </decoder>
  2879. <decoder name="fortinet-fortigate-fields-v7">
  2880. <parent>fortinet-fortigate-firewall</parent>
  2881. <regex>\s+src_int="(\.*)"|\s+src_int=(\.*)\s|\s+src_int=(\.*)$</regex>
  2882. <order>src_int</order>
  2883. </decoder>
  2884. <decoder name="fortinet-fortigate-fields-v7">
  2885. <parent>fortinet-fortigate-firewall</parent>
  2886. <regex>\s+src_port="(\.*)"|\s+src_port=(\.*)\s|\s+src_port=(\.*)$</regex>
  2887. <order>src_port</order>
  2888. </decoder>
  2889. <decoder name="fortinet-fortigate-fields-v7">
  2890. <parent>fortinet-fortigate-firewall</parent>
  2891. <regex>\s+srccity="(\.*)"|\s+srccity=(\.*)\s|\s+srccity=(\.*)$</regex>
  2892. <order>srccity</order>
  2893. </decoder>
  2894. <decoder name="fortinet-fortigate-fields-v7">
  2895. <parent>fortinet-fortigate-firewall</parent>
  2896. <regex>\s+srccountry="(\.*)"|\s+srccountry=(\.*)\s|\s+srccountry=(\.*)$</regex>
  2897. <order>srccountry</order>
  2898. </decoder>
  2899. <decoder name="fortinet-fortigate-fields-v7">
  2900. <parent>fortinet-fortigate-firewall</parent>
  2901. <regex>\s+srcdomain="(\.*)"|\s+srcdomain=(\.*)\s|\s+srcdomain=(\.*)$</regex>
  2902. <order>srcdomain</order>
  2903. </decoder>
  2904. <decoder name="fortinet-fortigate-fields-v7">
  2905. <parent>fortinet-fortigate-firewall</parent>
  2906. <regex>\s+srcfamily="(\.*)"|\s+srcfamily=(\.*)\s|\s+srcfamily=(\.*)$</regex>
  2907. <order>srcfamily</order>
  2908. </decoder>
  2909. <decoder name="fortinet-fortigate-fields-v7">
  2910. <parent>fortinet-fortigate-firewall</parent>
  2911. <regex>\s+srchwvendor="(\.*)"|\s+srchwvendor=(\.*)\s|\s+srchwvendor=(\.*)$</regex>
  2912. <order>srchwvendor</order>
  2913. </decoder>
  2914. <decoder name="fortinet-fortigate-fields-v7">
  2915. <parent>fortinet-fortigate-firewall</parent>
  2916. <regex>\s+srchwversion="(\.*)"|\s+srchwversion=(\.*)\s|\s+srchwversion=(\.*)$</regex>
  2917. <order>srchwversion</order>
  2918. </decoder>
  2919. <decoder name="fortinet-fortigate-fields-v7">
  2920. <parent>fortinet-fortigate-firewall</parent>
  2921. <regex>\s+srcinetsvc="(\.*)"|\s+srcinetsvc=(\.*)\s|\s+srcinetsvc=(\.*)$</regex>
  2922. <order>srcinetsvc</order>
  2923. </decoder>
  2924. <decoder name="fortinet-fortigate-fields-v7">
  2925. <parent>fortinet-fortigate-firewall</parent>
  2926. <regex>\s+srcintf="(\.*)"|\s+srcintf=(\.*)\s|\s+srcintf=(\.*)$</regex>
  2927. <order>srcintf</order>
  2928. </decoder>
  2929. <decoder name="fortinet-fortigate-fields-v7">
  2930. <parent>fortinet-fortigate-firewall</parent>
  2931. <regex>\s+srcintfrole="(\.*)"|\s+srcintfrole=(\.*)\s|\s+srcintfrole=(\.*)$</regex>
  2932. <order>srcintfrole</order>
  2933. </decoder>
  2934. <decoder name="fortinet-fortigate-fields-v7">
  2935. <parent>fortinet-fortigate-firewall</parent>
  2936. <regex>\s+srcip="(\.*)"|\s+srcip=(\.*)\s|\s+srcip=(\.*)$</regex>
  2937. <order>srcip</order>
  2938. </decoder>
  2939. <decoder name="fortinet-fortigate-fields-v7">
  2940. <parent>fortinet-fortigate-firewall</parent>
  2941. <regex>\s+srcmac="(\.*)"|\s+srcmac=(\.*)\s|\s+srcmac=(\.*)$</regex>
  2942. <order>srcmac</order>
  2943. </decoder>
  2944. <decoder name="fortinet-fortigate-fields-v7">
  2945. <parent>fortinet-fortigate-firewall</parent>
  2946. <regex>\s+srcmacvendor="(\.*)"|\s+srcmacvendor=(\.*)\s|\s+srcmacvendor=(\.*)$</regex>
  2947. <order>srcmacvendor</order>
  2948. </decoder>
  2949. <decoder name="fortinet-fortigate-fields-v7">
  2950. <parent>fortinet-fortigate-firewall</parent>
  2951. <regex>\s+srcname="(\.*)"|\s+srcname=(\.*)\s|\s+srcname=(\.*)$</regex>
  2952. <order>srcname</order>
  2953. </decoder>
  2954. <decoder name="fortinet-fortigate-fields-v7">
  2955. <parent>fortinet-fortigate-firewall</parent>
  2956. <regex>\s+srcport="(\.*)"|\s+srcport=(\.*)\s|\s+srcport=(\.*)$</regex>
  2957. <order>srcport</order>
  2958. </decoder>
  2959. <decoder name="fortinet-fortigate-fields-v7">
  2960. <parent>fortinet-fortigate-firewall</parent>
  2961. <regex>\s+srcregion="(\.*)"|\s+srcregion=(\.*)\s|\s+srcregion=(\.*)$</regex>
  2962. <order>srcregion</order>
  2963. </decoder>
  2964. <decoder name="fortinet-fortigate-fields-v7">
  2965. <parent>fortinet-fortigate-firewall</parent>
  2966. <regex>\s+srcremote="(\.*)"|\s+srcremote=(\.*)\s|\s+srcremote=(\.*)$</regex>
  2967. <order>srcremote</order>
  2968. </decoder>
  2969. <decoder name="fortinet-fortigate-fields-v7">
  2970. <parent>fortinet-fortigate-firewall</parent>
  2971. <regex>\s+srcreputation="(\.*)"|\s+srcreputation=(\.*)\s|\s+srcreputation=(\.*)$</regex>
  2972. <order>srcreputation</order>
  2973. </decoder>
  2974. <decoder name="fortinet-fortigate-fields-v7">
  2975. <parent>fortinet-fortigate-firewall</parent>
  2976. <regex>\s+srcserver="(\.*)"|\s+srcserver=(\.*)\s|\s+srcserver=(\.*)$</regex>
  2977. <order>srcserver</order>
  2978. </decoder>
  2979. <decoder name="fortinet-fortigate-fields-v7">
  2980. <parent>fortinet-fortigate-firewall</parent>
  2981. <regex>\s+srcssid="(\.*)"|\s+srcssid=(\.*)\s|\s+srcssid=(\.*)$</regex>
  2982. <order>srcssid</order>
  2983. </decoder>
  2984. <decoder name="fortinet-fortigate-fields-v7">
  2985. <parent>fortinet-fortigate-firewall</parent>
  2986. <regex>\s+srcswversion="(\.*)"|\s+srcswversion=(\.*)\s|\s+srcswversion=(\.*)$</regex>
  2987. <order>srcswversion</order>
  2988. </decoder>
  2989. <decoder name="fortinet-fortigate-fields-v7">
  2990. <parent>fortinet-fortigate-firewall</parent>
  2991. <regex>\s+srcthreatfeed="(\.*)"|\s+srcthreatfeed=(\.*)\s|\s+srcthreatfeed=(\.*)$</regex>
  2992. <order>srcthreatfeed</order>
  2993. </decoder>
  2994. <decoder name="fortinet-fortigate-fields-v7">
  2995. <parent>fortinet-fortigate-firewall</parent>
  2996. <regex>\s+srcuuid="(\.*)"|\s+srcuuid=(\.*)\s|\s+srcuuid=(\.*)$</regex>
  2997. <order>srcuuid</order>
  2998. </decoder>
  2999. <decoder name="fortinet-fortigate-fields-v7">
  3000. <parent>fortinet-fortigate-firewall</parent>
  3001. <regex>\s+sscname="(\.*)"|\s+sscname=(\.*)\s|\s+sscname=(\.*)$</regex>
  3002. <order>sscname</order>
  3003. </decoder>
  3004. <decoder name="fortinet-fortigate-fields-v7">
  3005. <parent>fortinet-fortigate-firewall</parent>
  3006. <regex>\s+ssh="(\.*)"|\s+ssh=(\.*)\s|\s+ssh=(\.*)$</regex>
  3007. <order>ssh</order>
  3008. </decoder>
  3009. <decoder name="fortinet-fortigate-fields-v7">
  3010. <parent>fortinet-fortigate-firewall</parent>
  3011. <regex>\s+ssid="(\.*)"|\s+ssid=(\.*)\s|\s+ssid=(\.*)$</regex>
  3012. <order>ssid</order>
  3013. </decoder>
  3014. <decoder name="fortinet-fortigate-fields-v7">
  3015. <parent>fortinet-fortigate-firewall</parent>
  3016. <regex>\s+ssl="(\.*)"|\s+ssl=(\.*)\s|\s+ssl=(\.*)$</regex>
  3017. <order>ssl</order>
  3018. </decoder>
  3019. <decoder name="fortinet-fortigate-fields-v7">
  3020. <parent>fortinet-fortigate-firewall</parent>
  3021. <regex>\s+sslaction="(\.*)"|\s+sslaction=(\.*)\s|\s+sslaction=(\.*)$</regex>
  3022. <order>sslaction</order>
  3023. </decoder>
  3024. <decoder name="fortinet-fortigate-fields-v7">
  3025. <parent>fortinet-fortigate-firewall</parent>
  3026. <regex>\s+ssllocal="(\.*)"|\s+ssllocal=(\.*)\s|\s+ssllocal=(\.*)$</regex>
  3027. <order>ssllocal</order>
  3028. </decoder>
  3029. <decoder name="fortinet-fortigate-fields-v7">
  3030. <parent>fortinet-fortigate-firewall</parent>
  3031. <regex>\s+sslremote="(\.*)"|\s+sslremote=(\.*)\s|\s+sslremote=(\.*)$</regex>
  3032. <order>sslremote</order>
  3033. </decoder>
  3034. <decoder name="fortinet-fortigate-fields-v7">
  3035. <parent>fortinet-fortigate-firewall</parent>
  3036. <regex>\s+stacount="(\.*)"|\s+stacount=(\.*)\s|\s+stacount=(\.*)$</regex>
  3037. <order>stacount</order>
  3038. </decoder>
  3039. <decoder name="fortinet-fortigate-fields-v7">
  3040. <parent>fortinet-fortigate-firewall</parent>
  3041. <regex>\s+stage="(\.*)"|\s+stage=(\.*)\s|\s+stage=(\.*)$</regex>
  3042. <order>stage</order>
  3043. </decoder>
  3044. <decoder name="fortinet-fortigate-fields-v7">
  3045. <parent>fortinet-fortigate-firewall</parent>
  3046. <regex>\s+stamac="(\.*)"|\s+stamac=(\.*)\s|\s+stamac=(\.*)$</regex>
  3047. <order>stamac</order>
  3048. </decoder>
  3049. <decoder name="fortinet-fortigate-fields-v7">
  3050. <parent>fortinet-fortigate-firewall</parent>
  3051. <regex>\s+state="(\.*)"|\s+state=(\.*)\s|\s+state=(\.*)$</regex>
  3052. <order>state</order>
  3053. </decoder>
  3054. <decoder name="fortinet-fortigate-fields-v7">
  3055. <parent>fortinet-fortigate-firewall</parent>
  3056. <regex>\s+status="(\.*)"|\s+status=(\.*)\s|\s+status=(\.*)$</regex>
  3057. <order>status</order>
  3058. </decoder>
  3059. <decoder name="fortinet-fortigate-fields-v7">
  3060. <parent>fortinet-fortigate-firewall</parent>
  3061. <regex>\s+stitch="(\.*)"|\s+stitch=(\.*)\s|\s+stitch=(\.*)$</regex>
  3062. <order>stitch</order>
  3063. </decoder>
  3064. <decoder name="fortinet-fortigate-fields-v7">
  3065. <parent>fortinet-fortigate-firewall</parent>
  3066. <regex>\s+stitchaction="(\.*)"|\s+stitchaction=(\.*)\s|\s+stitchaction=(\.*)$</regex>
  3067. <order>stitchaction</order>
  3068. </decoder>
  3069. <decoder name="fortinet-fortigate-fields-v7">
  3070. <parent>fortinet-fortigate-firewall</parent>
  3071. <regex>\s+subject="(\.*)"|\s+subject=(\.*)\s|\s+subject=(\.*)$</regex>
  3072. <order>subject</order>
  3073. </decoder>
  3074. <decoder name="fortinet-fortigate-fields-v7">
  3075. <parent>fortinet-fortigate-firewall</parent>
  3076. <regex>\s+submodule="(\.*)"|\s+submodule=(\.*)\s|\s+submodule=(\.*)$</regex>
  3077. <order>submodule</order>
  3078. </decoder>
  3079. <decoder name="fortinet-fortigate-fields-v7">
  3080. <parent>fortinet-fortigate-firewall</parent>
  3081. <regex>\s+subservice="(\.*)"|\s+subservice=(\.*)\s|\s+subservice=(\.*)$</regex>
  3082. <order>subservice</order>
  3083. </decoder>
  3084. <decoder name="fortinet-fortigate-fields-v7">
  3085. <parent>fortinet-fortigate-firewall</parent>
  3086. <regex>\s+subtype="(\.*)"|\s+subtype=(\.*)\s|\s+subtype=(\.*)$</regex>
  3087. <order>subtype</order>
  3088. </decoder>
  3089. <decoder name="fortinet-fortigate-fields-v7">
  3090. <parent>fortinet-fortigate-firewall</parent>
  3091. <regex>\s+successcount="(\.*)"|\s+successcount=(\.*)\s|\s+successcount=(\.*)$</regex>
  3092. <order>successcount</order>
  3093. </decoder>
  3094. <decoder name="fortinet-fortigate-fields-v7">
  3095. <parent>fortinet-fortigate-firewall</parent>
  3096. <regex>\s+switchaclid="(\.*)"|\s+switchaclid=(\.*)\s|\s+switchaclid=(\.*)$</regex>
  3097. <order>switchaclid</order>
  3098. </decoder>
  3099. <decoder name="fortinet-fortigate-fields-v7">
  3100. <parent>fortinet-fortigate-firewall</parent>
  3101. <regex>\s+switchautoip="(\.*)"|\s+switchautoip=(\.*)\s|\s+switchautoip=(\.*)$</regex>
  3102. <order>switchautoip</order>
  3103. </decoder>
  3104. <decoder name="fortinet-fortigate-fields-v7">
  3105. <parent>fortinet-fortigate-firewall</parent>
  3106. <regex>\s+switchid="(\.*)"|\s+switchid=(\.*)\s|\s+switchid=(\.*)$</regex>
  3107. <order>switchid</order>
  3108. </decoder>
  3109. <decoder name="fortinet-fortigate-fields-v7">
  3110. <parent>fortinet-fortigate-firewall</parent>
  3111. <regex>\s+switchinterface="(\.*)"|\s+switchinterface=(\.*)\s|\s+switchinterface=(\.*)$</regex>
  3112. <order>switchinterface</order>
  3113. </decoder>
  3114. <decoder name="fortinet-fortigate-fields-v7">
  3115. <parent>fortinet-fortigate-firewall</parent>
  3116. <regex>\s+switchl="(\.*)"|\s+switchl=(\.*)\s|\s+switchl=(\.*)$</regex>
  3117. <order>switchl</order>
  3118. </decoder>
  3119. <decoder name="fortinet-fortigate-fields-v7">
  3120. <parent>fortinet-fortigate-firewall</parent>
  3121. <regex>\s+switchmirrorsession="(\.*)"|\s+switchmirrorsession=(\.*)\s|\s+switchmirrorsession=(\.*)$</regex>
  3122. <order>switchmirrorsession</order>
  3123. </decoder>
  3124. <decoder name="fortinet-fortigate-fields-v7">
  3125. <parent>fortinet-fortigate-firewall</parent>
  3126. <regex>\s+switchphysicalport="(\.*)"|\s+switchphysicalport=(\.*)\s|\s+switchphysicalport=(\.*)$</regex>
  3127. <order>switchphysicalport</order>
  3128. </decoder>
  3129. <decoder name="fortinet-fortigate-fields-v7">
  3130. <parent>fortinet-fortigate-firewall</parent>
  3131. <regex>\s+switchproto="(\.*)"|\s+switchproto=(\.*)\s|\s+switchproto=(\.*)$</regex>
  3132. <order>switchproto</order>
  3133. </decoder>
  3134. <decoder name="fortinet-fortigate-fields-v7">
  3135. <parent>fortinet-fortigate-firewall</parent>
  3136. <regex>\s+switchsysteminterface="(\.*)"|\s+switchsysteminterface=(\.*)\s|\s+switchsysteminterface=(\.*)$</regex>
  3137. <order>switchsysteminterface</order>
  3138. </decoder>
  3139. <decoder name="fortinet-fortigate-fields-v7">
  3140. <parent>fortinet-fortigate-firewall</parent>
  3141. <regex>\s+switchtrunk="(\.*)"|\s+switchtrunk=(\.*)\s|\s+switchtrunk=(\.*)$</regex>
  3142. <order>switchtrunk</order>
  3143. </decoder>
  3144. <decoder name="fortinet-fortigate-fields-v7">
  3145. <parent>fortinet-fortigate-firewall</parent>
  3146. <regex>\s+switchtrunkinterface="(\.*)"|\s+switchtrunkinterface=(\.*)\s|\s+switchtrunkinterface=(\.*)$</regex>
  3147. <order>switchtrunkinterface</order>
  3148. </decoder>
  3149. <decoder name="fortinet-fortigate-fields-v7">
  3150. <parent>fortinet-fortigate-firewall</parent>
  3151. <regex>\s+sysuptime="(\.*)"|\s+sysuptime=(\.*)\s|\s+sysuptime=(\.*)$</regex>
  3152. <order>sysuptime</order>
  3153. </decoder>
  3154. <decoder name="fortinet-fortigate-fields-v7">
  3155. <parent>fortinet-fortigate-firewall</parent>
  3156. <regex>\s+tamac="(\.*)"|\s+tamac=(\.*)\s|\s+tamac=(\.*)$</regex>
  3157. <order>tamac</order>
  3158. </decoder>
  3159. <decoder name="fortinet-fortigate-fields-v7">
  3160. <parent>fortinet-fortigate-firewall</parent>
  3161. <regex>\s+threattype="(\.*)"|\s+threattype=(\.*)\s|\s+threattype=(\.*)$</regex>
  3162. <order>threattype</order>
  3163. </decoder>
  3164. <decoder name="fortinet-fortigate-fields-v7">
  3165. <parent>fortinet-fortigate-firewall</parent>
  3166. <regex>\s+ticket="(\.*)"|\s+ticket=(\.*)\s|\s+ticket=(\.*)$</regex>
  3167. <order>ticket</order>
  3168. </decoder>
  3169. <decoder name="fortinet-fortigate-fields-v7">
  3170. <parent>fortinet-fortigate-firewall</parent>
  3171. <regex>\s+time="(\.*)"|\s+time=(\.*)\s|\s+time=(\.*)$</regex>
  3172. <order>time</order>
  3173. </decoder>
  3174. <decoder name="fortinet-fortigate-fields-v7">
  3175. <parent>fortinet-fortigate-firewall</parent>
  3176. <regex>\s+timeoutdelete="(\.*)"|\s+timeoutdelete=(\.*)\s|\s+timeoutdelete=(\.*)$</regex>
  3177. <order>timeoutdelete</order>
  3178. </decoder>
  3179. <decoder name="fortinet-fortigate-fields-v7">
  3180. <parent>fortinet-fortigate-firewall</parent>
  3181. <regex>\s+timestamp="(\.*)"|\s+timestamp=(\.*)\s|\s+timestamp=(\.*)$</regex>
  3182. <order>timestamp</order>
  3183. </decoder>
  3184. <decoder name="fortinet-fortigate-fields-v7">
  3185. <parent>fortinet-fortigate-firewall</parent>
  3186. <regex>\s+tlsver="(\.*)"|\s+tlsver=(\.*)\s|\s+tlsver=(\.*)$</regex>
  3187. <order>tlsver</order>
  3188. </decoder>
  3189. <decoder name="fortinet-fortigate-fields-v7">
  3190. <parent>fortinet-fortigate-firewall</parent>
  3191. <regex>\s+to="(\.*)"|\s+to=(\.*)\s|\s+to=(\.*)$</regex>
  3192. <order>to</order>
  3193. </decoder>
  3194. <decoder name="fortinet-fortigate-fields-v7">
  3195. <parent>fortinet-fortigate-firewall</parent>
  3196. <regex>\s+to_vcluster="(\.*)"|\s+to_vcluster=(\.*)\s|\s+to_vcluster=(\.*)$</regex>
  3197. <order>to_vcluster</order>
  3198. </decoder>
  3199. <decoder name="fortinet-fortigate-fields-v7">
  3200. <parent>fortinet-fortigate-firewall</parent>
  3201. <regex>\s+total="(\.*)"|\s+total=(\.*)\s|\s+total=(\.*)$</regex>
  3202. <order>total</order>
  3203. </decoder>
  3204. <decoder name="fortinet-fortigate-fields-v7">
  3205. <parent>fortinet-fortigate-firewall</parent>
  3206. <regex>\s+totalsession="(\.*)"|\s+totalsession=(\.*)\s|\s+totalsession=(\.*)$</regex>
  3207. <order>totalsession</order>
  3208. </decoder>
  3209. <decoder name="fortinet-fortigate-fields-v7">
  3210. <parent>fortinet-fortigate-firewall</parent>
  3211. <regex>\s+traffic="(\.*)"|\s+traffic=(\.*)\s|\s+traffic=(\.*)$</regex>
  3212. <order>traffic</order>
  3213. </decoder>
  3214. <decoder name="fortinet-fortigate-fields-v7">
  3215. <parent>fortinet-fortigate-firewall</parent>
  3216. <regex>\s+trandisp="(\.*)"|\s+trandisp=(\.*)\s|\s+trandisp=(\.*)$</regex>
  3217. <order>trandisp</order>
  3218. </decoder>
  3219. <decoder name="fortinet-fortigate-fields-v7">
  3220. <parent>fortinet-fortigate-firewall</parent>
  3221. <regex>\s+tranip="(\.*)"|\s+tranip=(\.*)\s|\s+tranip=(\.*)$</regex>
  3222. <order>tranip</order>
  3223. </decoder>
  3224. <decoder name="fortinet-fortigate-fields-v7">
  3225. <parent>fortinet-fortigate-firewall</parent>
  3226. <regex>\s+tranport="(\.*)"|\s+tranport=(\.*)\s|\s+tranport=(\.*)$</regex>
  3227. <order>tranport</order>
  3228. </decoder>
  3229. <decoder name="fortinet-fortigate-fields-v7">
  3230. <parent>fortinet-fortigate-firewall</parent>
  3231. <regex>\s+transid="(\.*)"|\s+transid=(\.*)\s|\s+transid=(\.*)$</regex>
  3232. <order>transid</order>
  3233. </decoder>
  3234. <decoder name="fortinet-fortigate-fields-v7">
  3235. <parent>fortinet-fortigate-firewall</parent>
  3236. <regex>\s+transip="(\.*)"|\s+transip=(\.*)\s|\s+transip=(\.*)$</regex>
  3237. <order>transip</order>
  3238. </decoder>
  3239. <decoder name="fortinet-fortigate-fields-v7">
  3240. <parent>fortinet-fortigate-firewall</parent>
  3241. <regex>\s+translationid="(\.*)"|\s+translationid=(\.*)\s|\s+translationid=(\.*)$</regex>
  3242. <order>translationid</order>
  3243. </decoder>
  3244. <decoder name="fortinet-fortigate-fields-v7">
  3245. <parent>fortinet-fortigate-firewall</parent>
  3246. <regex>\s+transport="(\.*)"|\s+transport=(\.*)\s|\s+transport=(\.*)$</regex>
  3247. <order>transport</order>
  3248. </decoder>
  3249. <decoder name="fortinet-fortigate-fields-v7">
  3250. <parent>fortinet-fortigate-firewall</parent>
  3251. <regex>\s+trigger="(\.*)"|\s+trigger=(\.*)\s|\s+trigger=(\.*)$</regex>
  3252. <order>trigger</order>
  3253. </decoder>
  3254. <decoder name="fortinet-fortigate-fields-v7">
  3255. <parent>fortinet-fortigate-firewall</parent>
  3256. <regex>\s+trueclntip="(\.*)"|\s+trueclntip=(\.*)\s|\s+trueclntip=(\.*)$</regex>
  3257. <order>trueclntip</order>
  3258. </decoder>
  3259. <decoder name="fortinet-fortigate-fields-v7">
  3260. <parent>fortinet-fortigate-firewall</parent>
  3261. <regex>\s+tunnel="(\.*)"|\s+tunnel=(\.*)\s|\s+tunnel=(\.*)$</regex>
  3262. <order>tunnel</order>
  3263. </decoder>
  3264. <decoder name="fortinet-fortigate-fields-v7">
  3265. <parent>fortinet-fortigate-firewall</parent>
  3266. <regex>\s+tunnelid="(\.*)"|\s+tunnelid=(\.*)\s|\s+tunnelid=(\.*)$</regex>
  3267. <order>tunnelid</order>
  3268. </decoder>
  3269. <decoder name="fortinet-fortigate-fields-v7">
  3270. <parent>fortinet-fortigate-firewall</parent>
  3271. <regex>\s+tunnelip="(\.*)"|\s+tunnelip=(\.*)\s|\s+tunnelip=(\.*)$</regex>
  3272. <order>tunnelip</order>
  3273. </decoder>
  3274. <decoder name="fortinet-fortigate-fields-v7">
  3275. <parent>fortinet-fortigate-firewall</parent>
  3276. <regex>\s+tunneltype="(\.*)"|\s+tunneltype=(\.*)\s|\s+tunneltype=(\.*)$</regex>
  3277. <order>tunneltype</order>
  3278. </decoder>
  3279. <decoder name="fortinet-fortigate-fields-v7">
  3280. <parent>fortinet-fortigate-firewall</parent>
  3281. <regex>\s+type="(\.*)"|\s+type=(\.*)\s|\s+type=(\.*)$</regex>
  3282. <order>type</order>
  3283. </decoder>
  3284. <decoder name="fortinet-fortigate-fields-v7">
  3285. <parent>fortinet-fortigate-firewall</parent>
  3286. <regex>\s+tz="(\.*)"|\s+tz=(\.*)\s|\s+tz=(\.*)$</regex>
  3287. <order>tz</order>
  3288. </decoder>
  3289. <decoder name="fortinet-fortigate-fields-v7">
  3290. <parent>fortinet-fortigate-firewall</parent>
  3291. <regex>\s+ufseid="(\.*)"|\s+ufseid=(\.*)\s|\s+ufseid=(\.*)$</regex>
  3292. <order>ufseid</order>
  3293. </decoder>
  3294. <decoder name="fortinet-fortigate-fields-v7">
  3295. <parent>fortinet-fortigate-firewall</parent>
  3296. <regex>\s+ufseidaddr="(\.*)"|\s+ufseidaddr=(\.*)\s|\s+ufseidaddr=(\.*)$</regex>
  3297. <order>ufseidaddr</order>
  3298. </decoder>
  3299. <decoder name="fortinet-fortigate-fields-v7">
  3300. <parent>fortinet-fortigate-firewall</parent>
  3301. <regex>\s+uggsn="(\.*)"|\s+uggsn=(\.*)\s|\s+uggsn=(\.*)$</regex>
  3302. <order>uggsn</order>
  3303. </decoder>
  3304. <decoder name="fortinet-fortigate-fields-v7">
  3305. <parent>fortinet-fortigate-firewall</parent>
  3306. <regex>\s+ugsn="(\.*)"|\s+ugsn=(\.*)\s|\s+ugsn=(\.*)$</regex>
  3307. <order>ugsn</order>
  3308. </decoder>
  3309. <decoder name="fortinet-fortigate-fields-v7">
  3310. <parent>fortinet-fortigate-firewall</parent>
  3311. <regex>\s+ui="(\.*)"|\s+ui=(\.*)\s|\s+ui=(\.*)$</regex>
  3312. <order>ui</order>
  3313. </decoder>
  3314. <decoder name="fortinet-fortigate-fields-v7">
  3315. <parent>fortinet-fortigate-firewall</parent>
  3316. <regex>\s+uli="(\.*)"|\s+uli=(\.*)\s|\s+uli=(\.*)$</regex>
  3317. <order>uli</order>
  3318. </decoder>
  3319. <decoder name="fortinet-fortigate-fields-v7">
  3320. <parent>fortinet-fortigate-firewall</parent>
  3321. <regex>\s+ulimcc="(\.*)"|\s+ulimcc=(\.*)\s|\s+ulimcc=(\.*)$</regex>
  3322. <order>ulimcc</order>
  3323. </decoder>
  3324. <decoder name="fortinet-fortigate-fields-v7">
  3325. <parent>fortinet-fortigate-firewall</parent>
  3326. <regex>\s+ulimnc="(\.*)"|\s+ulimnc=(\.*)\s|\s+ulimnc=(\.*)$</regex>
  3327. <order>ulimnc</order>
  3328. </decoder>
  3329. <decoder name="fortinet-fortigate-fields-v7">
  3330. <parent>fortinet-fortigate-firewall</parent>
  3331. <regex>\s+unauthuser="(\.*)"|\s+unauthuser=(\.*)\s|\s+unauthuser=(\.*)$</regex>
  3332. <order>unauthuser</order>
  3333. </decoder>
  3334. <decoder name="fortinet-fortigate-fields-v7">
  3335. <parent>fortinet-fortigate-firewall</parent>
  3336. <regex>\s+unauthusersource="(\.*)"|\s+unauthusersource=(\.*)\s|\s+unauthusersource=(\.*)$</regex>
  3337. <order>unauthusersource</order>
  3338. </decoder>
  3339. <decoder name="fortinet-fortigate-fields-v7">
  3340. <parent>fortinet-fortigate-firewall</parent>
  3341. <regex>\s+unit="(\.*)"|\s+unit=(\.*)\s|\s+unit=(\.*)$</regex>
  3342. <order>unit</order>
  3343. </decoder>
  3344. <decoder name="fortinet-fortigate-fields-v7">
  3345. <parent>fortinet-fortigate-firewall</parent>
  3346. <regex>\s+upbandwidthmeasured="(\.*)"|\s+upbandwidthmeasured=(\.*)\s|\s+upbandwidthmeasured=(\.*)$</regex>
  3347. <order>upbandwidthmeasured</order>
  3348. </decoder>
  3349. <decoder name="fortinet-fortigate-fields-v7">
  3350. <parent>fortinet-fortigate-firewall</parent>
  3351. <regex>\s+upgradedevice="(\.*)"|\s+upgradedevice=(\.*)\s|\s+upgradedevice=(\.*)$</regex>
  3352. <order>upgradedevice</order>
  3353. </decoder>
  3354. <decoder name="fortinet-fortigate-fields-v7">
  3355. <parent>fortinet-fortigate-firewall</parent>
  3356. <regex>\s+upteid="(\.*)"|\s+upteid=(\.*)\s|\s+upteid=(\.*)$</regex>
  3357. <order>upteid</order>
  3358. </decoder>
  3359. <decoder name="fortinet-fortigate-fields-v7">
  3360. <parent>fortinet-fortigate-firewall</parent>
  3361. <regex>\s+url="(\.*)"|\s+url=(\.*)\s|\s+url=(\.*)$</regex>
  3362. <order>url</order>
  3363. </decoder>
  3364. <decoder name="fortinet-fortigate-fields-v7">
  3365. <parent>fortinet-fortigate-firewall</parent>
  3366. <regex>\s+urlfilteridx="(\.*)"|\s+urlfilteridx=(\.*)\s|\s+urlfilteridx=(\.*)$</regex>
  3367. <order>urlfilteridx</order>
  3368. </decoder>
  3369. <decoder name="fortinet-fortigate-fields-v7">
  3370. <parent>fortinet-fortigate-firewall</parent>
  3371. <regex>\s+urlfilterlist="(\.*)"|\s+urlfilterlist=(\.*)\s|\s+urlfilterlist=(\.*)$</regex>
  3372. <order>urlfilterlist</order>
  3373. </decoder>
  3374. <decoder name="fortinet-fortigate-fields-v7">
  3375. <parent>fortinet-fortigate-firewall</parent>
  3376. <regex>\s+urlsource="(\.*)"|\s+urlsource=(\.*)\s|\s+urlsource=(\.*)$</regex>
  3377. <order>urlsource</order>
  3378. </decoder>
  3379. <decoder name="fortinet-fortigate-fields-v7">
  3380. <parent>fortinet-fortigate-firewall</parent>
  3381. <regex>\s+urltype="(\.*)"|\s+urltype=(\.*)\s|\s+urltype=(\.*)$</regex>
  3382. <order>urltype</order>
  3383. </decoder>
  3384. <decoder name="fortinet-fortigate-fields-v7">
  3385. <parent>fortinet-fortigate-firewall</parent>
  3386. <regex>\s+used="(\.*)"|\s+used=(\.*)\s|\s+used=(\.*)$</regex>
  3387. <order>used</order>
  3388. </decoder>
  3389. <decoder name="fortinet-fortigate-fields-v7">
  3390. <parent>fortinet-fortigate-firewall</parent>
  3391. <regex>\s+used_for="(\.*)"|\s+used_for=(\.*)\s|\s+used_for=(\.*)$</regex>
  3392. <order>used_for</order>
  3393. </decoder>
  3394. <decoder name="fortinet-fortigate-fields-v7">
  3395. <parent>fortinet-fortigate-firewall</parent>
  3396. <regex>\s+user="(\.*)"|\s+user=(\.*)\s|\s+user=(\.*)$</regex>
  3397. <order>user</order>
  3398. </decoder>
  3399. <decoder name="fortinet-fortigate-fields-v7">
  3400. <parent>fortinet-fortigate-firewall</parent>
  3401. <regex>\s+user_data="(\.*)"|\s+user_data=(\.*)\s|\s+user_data=(\.*)$</regex>
  3402. <order>user_data</order>
  3403. </decoder>
  3404. <decoder name="fortinet-fortigate-fields-v7">
  3405. <parent>fortinet-fortigate-firewall</parent>
  3406. <regex>\s+useractivity="(\.*)"|\s+useractivity=(\.*)\s|\s+useractivity=(\.*)$</regex>
  3407. <order>useractivity</order>
  3408. </decoder>
  3409. <decoder name="fortinet-fortigate-fields-v7">
  3410. <parent>fortinet-fortigate-firewall</parent>
  3411. <regex>\s+useralt="(\.*)"|\s+useralt=(\.*)\s|\s+useralt=(\.*)$</regex>
  3412. <order>useralt</order>
  3413. </decoder>
  3414. <decoder name="fortinet-fortigate-fields-v7">
  3415. <parent>fortinet-fortigate-firewall</parent>
  3416. <regex>\s+usgsn="(\.*)"|\s+usgsn=(\.*)\s|\s+usgsn=(\.*)$</regex>
  3417. <order>usgsn</order>
  3418. </decoder>
  3419. <decoder name="fortinet-fortigate-fields-v7">
  3420. <parent>fortinet-fortigate-firewall</parent>
  3421. <regex>\s+utmaction="(\.*)"|\s+utmaction=(\.*)\s|\s+utmaction=(\.*)$</regex>
  3422. <order>utmaction</order>
  3423. </decoder>
  3424. <decoder name="fortinet-fortigate-fields-v7">
  3425. <parent>fortinet-fortigate-firewall</parent>
  3426. <regex>\s+vap="(\.*)"|\s+vap=(\.*)\s|\s+vap=(\.*)$</regex>
  3427. <order>vap</order>
  3428. </decoder>
  3429. <decoder name="fortinet-fortigate-fields-v7">
  3430. <parent>fortinet-fortigate-firewall</parent>
  3431. <regex>\s+vapmode="(\.*)"|\s+vapmode=(\.*)\s|\s+vapmode=(\.*)$</regex>
  3432. <order>vapmode</order>
  3433. </decoder>
  3434. <decoder name="fortinet-fortigate-fields-v7">
  3435. <parent>fortinet-fortigate-firewall</parent>
  3436. <regex>\s+vcluster="(\.*)"|\s+vcluster=(\.*)\s|\s+vcluster=(\.*)$</regex>
  3437. <order>vcluster</order>
  3438. </decoder>
  3439. <decoder name="fortinet-fortigate-fields-v7">
  3440. <parent>fortinet-fortigate-firewall</parent>
  3441. <regex>\s+vcluster_member="(\.*)"|\s+vcluster_member=(\.*)\s|\s+vcluster_member=(\.*)$</regex>
  3442. <order>vcluster_member</order>
  3443. </decoder>
  3444. <decoder name="fortinet-fortigate-fields-v7">
  3445. <parent>fortinet-fortigate-firewall</parent>
  3446. <regex>\s+vcluster_state="(\.*)"|\s+vcluster_state=(\.*)\s|\s+vcluster_state=(\.*)$</regex>
  3447. <order>vcluster_state</order>
  3448. </decoder>
  3449. <decoder name="fortinet-fortigate-fields-v7">
  3450. <parent>fortinet-fortigate-firewall</parent>
  3451. <regex>\s+vd="(\.*)"|\s+vd=(\.*)\s|\s+vd=(\.*)$</regex>
  3452. <order>vd</order>
  3453. </decoder>
  3454. <decoder name="fortinet-fortigate-fields-v7">
  3455. <parent>fortinet-fortigate-firewall</parent>
  3456. <regex>\s+vdname="(\.*)"|\s+vdname=(\.*)\s|\s+vdname=(\.*)$</regex>
  3457. <order>vdname</order>
  3458. </decoder>
  3459. <decoder name="fortinet-fortigate-fields-v7">
  3460. <parent>fortinet-fortigate-firewall</parent>
  3461. <regex>\s+vendor="(\.*)"|\s+vendor=(\.*)\s|\s+vendor=(\.*)$</regex>
  3462. <order>vendor</order>
  3463. </decoder>
  3464. <decoder name="fortinet-fortigate-fields-v7">
  3465. <parent>fortinet-fortigate-firewall</parent>
  3466. <regex>\s+vendorurl="(\.*)"|\s+vendorurl=(\.*)\s|\s+vendorurl=(\.*)$</regex>
  3467. <order>vendorurl</order>
  3468. </decoder>
  3469. <decoder name="fortinet-fortigate-fields-v7">
  3470. <parent>fortinet-fortigate-firewall</parent>
  3471. <regex>\s+version="(\.*)"|\s+version=(\.*)\s|\s+version=(\.*)$</regex>
  3472. <order>version</order>
  3473. </decoder>
  3474. <decoder name="fortinet-fortigate-fields-v7">
  3475. <parent>fortinet-fortigate-firewall</parent>
  3476. <regex>\s+versionmax="(\.*)"|\s+versionmax=(\.*)\s|\s+versionmax=(\.*)$</regex>
  3477. <order>versionmax</order>
  3478. </decoder>
  3479. <decoder name="fortinet-fortigate-fields-v7">
  3480. <parent>fortinet-fortigate-firewall</parent>
  3481. <regex>\s+versionmin="(\.*)"|\s+versionmin=(\.*)\s|\s+versionmin=(\.*)$</regex>
  3482. <order>versionmin</order>
  3483. </decoder>
  3484. <decoder name="fortinet-fortigate-fields-v7">
  3485. <parent>fortinet-fortigate-firewall</parent>
  3486. <regex>\s+videocategoryid="(\.*)"|\s+videocategoryid=(\.*)\s|\s+videocategoryid=(\.*)$</regex>
  3487. <order>videocategoryid</order>
  3488. </decoder>
  3489. <decoder name="fortinet-fortigate-fields-v7">
  3490. <parent>fortinet-fortigate-firewall</parent>
  3491. <regex>\s+videocategoryname="(\.*)"|\s+videocategoryname=(\.*)\s|\s+videocategoryname=(\.*)$</regex>
  3492. <order>videocategoryname</order>
  3493. </decoder>
  3494. <decoder name="fortinet-fortigate-fields-v7">
  3495. <parent>fortinet-fortigate-firewall</parent>
  3496. <regex>\s+videochannelid="(\.*)"|\s+videochannelid=(\.*)\s|\s+videochannelid=(\.*)$</regex>
  3497. <order>videochannelid</order>
  3498. </decoder>
  3499. <decoder name="fortinet-fortigate-fields-v7">
  3500. <parent>fortinet-fortigate-firewall</parent>
  3501. <regex>\s+videodesc="(\.*)"|\s+videodesc=(\.*)\s|\s+videodesc=(\.*)$</regex>
  3502. <order>videodesc</order>
  3503. </decoder>
  3504. <decoder name="fortinet-fortigate-fields-v7">
  3505. <parent>fortinet-fortigate-firewall</parent>
  3506. <regex>\s+videoid="(\.*)"|\s+videoid=(\.*)\s|\s+videoid=(\.*)$</regex>
  3507. <order>videoid</order>
  3508. </decoder>
  3509. <decoder name="fortinet-fortigate-fields-v7">
  3510. <parent>fortinet-fortigate-firewall</parent>
  3511. <regex>\s+videoinfosource="(\.*)"|\s+videoinfosource=(\.*)\s|\s+videoinfosource=(\.*)$</regex>
  3512. <order>videoinfosource</order>
  3513. </decoder>
  3514. <decoder name="fortinet-fortigate-fields-v7">
  3515. <parent>fortinet-fortigate-firewall</parent>
  3516. <regex>\s+videotitle="(\.*)"|\s+videotitle=(\.*)\s|\s+videotitle=(\.*)$</regex>
  3517. <order>videotitle</order>
  3518. </decoder>
  3519. <decoder name="fortinet-fortigate-fields-v7">
  3520. <parent>fortinet-fortigate-firewall</parent>
  3521. <regex>\s+violations="(\.*)"|\s+violations=(\.*)\s|\s+violations=(\.*)$</regex>
  3522. <order>violations</order>
  3523. </decoder>
  3524. <decoder name="fortinet-fortigate-fields-v7">
  3525. <parent>fortinet-fortigate-firewall</parent>
  3526. <regex>\s+vip="(\.*)"|\s+vip=(\.*)\s|\s+vip=(\.*)$</regex>
  3527. <order>vip</order>
  3528. </decoder>
  3529. <decoder name="fortinet-fortigate-fields-v7">
  3530. <parent>fortinet-fortigate-firewall</parent>
  3531. <regex>\s+virtual="(\.*)"|\s+virtual=(\.*)\s|\s+virtual=(\.*)$</regex>
  3532. <order>virtual</order>
  3533. </decoder>
  3534. <decoder name="fortinet-fortigate-fields-v7">
  3535. <parent>fortinet-fortigate-firewall</parent>
  3536. <regex>\s+virus="(\.*)"|\s+virus=(\.*)\s|\s+virus=(\.*)$</regex>
  3537. <order>virus</order>
  3538. </decoder>
  3539. <decoder name="fortinet-fortigate-fields-v7">
  3540. <parent>fortinet-fortigate-firewall</parent>
  3541. <regex>\s+viruscat="(\.*)"|\s+viruscat=(\.*)\s|\s+viruscat=(\.*)$</regex>
  3542. <order>viruscat</order>
  3543. </decoder>
  3544. <decoder name="fortinet-fortigate-fields-v7">
  3545. <parent>fortinet-fortigate-firewall</parent>
  3546. <regex>\s+virusid="(\.*)"|\s+virusid=(\.*)\s|\s+virusid=(\.*)$</regex>
  3547. <order>virusid</order>
  3548. </decoder>
  3549. <decoder name="fortinet-fortigate-fields-v7">
  3550. <parent>fortinet-fortigate-firewall</parent>
  3551. <regex>\s+vlan="(\.*)"|\s+vlan=(\.*)\s|\s+vlan=(\.*)$</regex>
  3552. <order>vlan</order>
  3553. </decoder>
  3554. <decoder name="fortinet-fortigate-fields-v7">
  3555. <parent>fortinet-fortigate-firewall</parent>
  3556. <regex>\s+voip="(\.*)"|\s+voip=(\.*)\s|\s+voip=(\.*)$</regex>
  3557. <order>voip</order>
  3558. </decoder>
  3559. <decoder name="fortinet-fortigate-fields-v7">
  3560. <parent>fortinet-fortigate-firewall</parent>
  3561. <regex>\s+voip_proto="(\.*)"|\s+voip_proto=(\.*)\s|\s+voip_proto=(\.*)$</regex>
  3562. <order>voip_proto</order>
  3563. </decoder>
  3564. <decoder name="fortinet-fortigate-fields-v7">
  3565. <parent>fortinet-fortigate-firewall</parent>
  3566. <regex>\s+vpn="(\.*)"|\s+vpn=(\.*)\s|\s+vpn=(\.*)$</regex>
  3567. <order>vpn</order>
  3568. </decoder>
  3569. <decoder name="fortinet-fortigate-fields-v7">
  3570. <parent>fortinet-fortigate-firewall</parent>
  3571. <regex>\s+vpntunnel="(\.*)"|\s+vpntunnel=(\.*)\s|\s+vpntunnel=(\.*)$</regex>
  3572. <order>vpntunnel</order>
  3573. </decoder>
  3574. <decoder name="fortinet-fortigate-fields-v7">
  3575. <parent>fortinet-fortigate-firewall</parent>
  3576. <regex>\s+vpntype="(\.*)"|\s+vpntype=(\.*)\s|\s+vpntype=(\.*)$</regex>
  3577. <order>vpntype</order>
  3578. </decoder>
  3579. <decoder name="fortinet-fortigate-fields-v7">
  3580. <parent>fortinet-fortigate-firewall</parent>
  3581. <regex>\s+vrf="(\.*)"|\s+vrf=(\.*)\s|\s+vrf=(\.*)$</regex>
  3582. <order>vrf</order>
  3583. </decoder>
  3584. <decoder name="fortinet-fortigate-fields-v7">
  3585. <parent>fortinet-fortigate-firewall</parent>
  3586. <regex>\s+vulncat="(\.*)"|\s+vulncat=(\.*)\s|\s+vulncat=(\.*)$</regex>
  3587. <order>vulncat</order>
  3588. </decoder>
  3589. <decoder name="fortinet-fortigate-fields-v7">
  3590. <parent>fortinet-fortigate-firewall</parent>
  3591. <regex>\s+vulncnt="(\.*)"|\s+vulncnt=(\.*)\s|\s+vulncnt=(\.*)$</regex>
  3592. <order>vulncnt</order>
  3593. </decoder>
  3594. <decoder name="fortinet-fortigate-fields-v7">
  3595. <parent>fortinet-fortigate-firewall</parent>
  3596. <regex>\s+vulnid="(\.*)"|\s+vulnid=(\.*)\s|\s+vulnid=(\.*)$</regex>
  3597. <order>vulnid</order>
  3598. </decoder>
  3599. <decoder name="fortinet-fortigate-fields-v7">
  3600. <parent>fortinet-fortigate-firewall</parent>
  3601. <regex>\s+vulnname="(\.*)"|\s+vulnname=(\.*)\s|\s+vulnname=(\.*)$</regex>
  3602. <order>vulnname</order>
  3603. </decoder>
  3604. <decoder name="fortinet-fortigate-fields-v7">
  3605. <parent>fortinet-fortigate-firewall</parent>
  3606. <regex>\s+vulnresult="(\.*)"|\s+vulnresult=(\.*)\s|\s+vulnresult=(\.*)$</regex>
  3607. <order>vulnresult</order>
  3608. </decoder>
  3609. <decoder name="fortinet-fortigate-fields-v7">
  3610. <parent>fortinet-fortigate-firewall</parent>
  3611. <regex>\s+vwlid="(\.*)"|\s+vwlid=(\.*)\s|\s+vwlid=(\.*)$</regex>
  3612. <order>vwlid</order>
  3613. </decoder>
  3614. <decoder name="fortinet-fortigate-fields-v7">
  3615. <parent>fortinet-fortigate-firewall</parent>
  3616. <regex>\s+vwlname="(\.*)"|\s+vwlname=(\.*)\s|\s+vwlname=(\.*)$</regex>
  3617. <order>vwlname</order>
  3618. </decoder>
  3619. <decoder name="fortinet-fortigate-fields-v7">
  3620. <parent>fortinet-fortigate-firewall</parent>
  3621. <regex>\s+vwlquality="(\.*)"|\s+vwlquality=(\.*)\s|\s+vwlquality=(\.*)$</regex>
  3622. <order>vwlquality</order>
  3623. </decoder>
  3624. <decoder name="fortinet-fortigate-fields-v7">
  3625. <parent>fortinet-fortigate-firewall</parent>
  3626. <regex>\s+vwlservice="(\.*)"|\s+vwlservice=(\.*)\s|\s+vwlservice=(\.*)$</regex>
  3627. <order>vwlservice</order>
  3628. </decoder>
  3629. <decoder name="fortinet-fortigate-fields-v7">
  3630. <parent>fortinet-fortigate-firewall</parent>
  3631. <regex>\s+vwpvlanid="(\.*)"|\s+vwpvlanid=(\.*)\s|\s+vwpvlanid=(\.*)$</regex>
  3632. <order>vwpvlanid</order>
  3633. </decoder>
  3634. <decoder name="fortinet-fortigate-fields-v7">
  3635. <parent>fortinet-fortigate-firewall</parent>
  3636. <regex>\s+waf="(\.*)"|\s+waf=(\.*)\s|\s+waf=(\.*)$</regex>
  3637. <order>waf</order>
  3638. </decoder>
  3639. <decoder name="fortinet-fortigate-fields-v7">
  3640. <parent>fortinet-fortigate-firewall</parent>
  3641. <regex>\s+wanin="(\.*)"|\s+wanin=(\.*)\s|\s+wanin=(\.*)$</regex>
  3642. <order>wanin</order>
  3643. </decoder>
  3644. <decoder name="fortinet-fortigate-fields-v7">
  3645. <parent>fortinet-fortigate-firewall</parent>
  3646. <regex>\s+waninfo="(\.*)"|\s+waninfo=(\.*)\s|\s+waninfo=(\.*)$</regex>
  3647. <order>waninfo</order>
  3648. </decoder>
  3649. <decoder name="fortinet-fortigate-fields-v7">
  3650. <parent>fortinet-fortigate-firewall</parent>
  3651. <regex>\s+wanoptapptype="(\.*)"|\s+wanoptapptype=(\.*)\s|\s+wanoptapptype=(\.*)$</regex>
  3652. <order>wanoptapptype</order>
  3653. </decoder>
  3654. <decoder name="fortinet-fortigate-fields-v7">
  3655. <parent>fortinet-fortigate-firewall</parent>
  3656. <regex>\s+wanout="(\.*)"|\s+wanout=(\.*)\s|\s+wanout=(\.*)$</regex>
  3657. <order>wanout</order>
  3658. </decoder>
  3659. <decoder name="fortinet-fortigate-fields-v7">
  3660. <parent>fortinet-fortigate-firewall</parent>
  3661. <regex>\s+weakwepiv="(\.*)"|\s+weakwepiv=(\.*)\s|\s+weakwepiv=(\.*)$</regex>
  3662. <order>weakwepiv</order>
  3663. </decoder>
  3664. <decoder name="fortinet-fortigate-fields-v7">
  3665. <parent>fortinet-fortigate-firewall</parent>
  3666. <regex>\s+webfilter="(\.*)"|\s+webfilter=(\.*)\s|\s+webfilter=(\.*)$</regex>
  3667. <order>webfilter</order>
  3668. </decoder>
  3669. <decoder name="fortinet-fortigate-fields-v7">
  3670. <parent>fortinet-fortigate-firewall</parent>
  3671. <regex>\s+webmailprovider="(\.*)"|\s+webmailprovider=(\.*)\s|\s+webmailprovider=(\.*)$</regex>
  3672. <order>webmailprovider</order>
  3673. </decoder>
  3674. <decoder name="fortinet-fortigate-fields-v7">
  3675. <parent>fortinet-fortigate-firewall</parent>
  3676. <regex>\s+wscode="(\.*)"|\s+wscode=(\.*)\s|\s+wscode=(\.*)$</regex>
  3677. <order>wscode</order>
  3678. </decoder>
  3679. <decoder name="fortinet-fortigate-fields-v7">
  3680. <parent>fortinet-fortigate-firewall</parent>
  3681. <regex>\s+xauthgroup="(\.*)"|\s+xauthgroup=(\.*)\s|\s+xauthgroup=(\.*)$</regex>
  3682. <order>xauthgroup</order>
  3683. </decoder>
  3684. <decoder name="fortinet-fortigate-fields-v7">
  3685. <parent>fortinet-fortigate-firewall</parent>
  3686. <regex>\s+xauthuser="(\.*)"|\s+xauthuser=(\.*)\s|\s+xauthuser=(\.*)$</regex>
  3687. <order>xauthuser</order>
  3688. </decoder>