0100-fortigate_decoders.xml 151 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434
  1. <!--
  2. - Fortigate Decoders
  3. - Author: Alexander Tibor Assenheimer - github: alextibor
  4. - This program is a free software; you can redistribute it and/or modify it under the terms of GPLv2.
  5. - Rules create based on the Fortigate Log Reference from version 7.0.14, 7.2.7, 7.2.8 and 7.4.3
  6. -->
  7. <decoder name="fortinet-fortigate-firewall">
  8. <prematch type="pcre2">^date=\d{4}-\d{2}-\d{2}\s+time=\d{2}:\d{2}:\d{2}\s+devname="[^"]*"\s+devid="[^"]*"\s+eventtime=\d+\s+tz="[^"]*"\s+logid="\d+"</prematch>
  9. </decoder>
  10. <decoder name="fortinet-fortigate-fields-v7">
  11. <parent>fortinet-fortigate-firewall</parent>
  12. <regex>devname="(\.*)"|devname=(\.*)\s|devname=(\.*)$</regex>
  13. <order>devname</order>
  14. </decoder>
  15. <decoder name="fortinet-fortigate-fields-v7">
  16. <parent>fortinet-fortigate-firewall</parent>
  17. <regex>\s+accessctrl="(\.*)"|\s+accessctrl=(\.*)\s|\s+accessctrl=(\.*)$</regex>
  18. <order>accessctrl</order>
  19. </decoder>
  20. <decoder name="fortinet-fortigate-fields-v7">
  21. <parent>fortinet-fortigate-firewall</parent>
  22. <regex>\s+accessproxy="(\.*)"|\s+accessproxy=(\.*)\s|\s+accessproxy=(\.*)$</regex>
  23. <order>accessproxy</order>
  24. </decoder>
  25. <decoder name="fortinet-fortigate-fields-v7">
  26. <parent>fortinet-fortigate-firewall</parent>
  27. <regex>\s+acct_stat="(\.*)"|\s+acct_stat=(\.*)\s|\s+acct_stat=(\.*)$</regex>
  28. <order>acct_stat</order>
  29. </decoder>
  30. <decoder name="fortinet-fortigate-fields-v7">
  31. <parent>fortinet-fortigate-firewall</parent>
  32. <regex>\s+acktime="(\.*)"|\s+acktime=(\.*)\s|\s+acktime=(\.*)$</regex>
  33. <order>acktime</order>
  34. </decoder>
  35. <decoder name="fortinet-fortigate-fields-v7">
  36. <parent>fortinet-fortigate-firewall</parent>
  37. <regex>\s+act="(\.*)"|\s+act=(\.*)\s|\s+act=(\.*)$</regex>
  38. <order>act</order>
  39. </decoder>
  40. <decoder name="fortinet-fortigate-fields-v7">
  41. <parent>fortinet-fortigate-firewall</parent>
  42. <regex>\s+action="(\.*)"|\s+action=(\.*)\s|\s+action=(\.*)$</regex>
  43. <order>action</order>
  44. </decoder>
  45. <decoder name="fortinet-fortigate-fields-v7">
  46. <parent>fortinet-fortigate-firewall</parent>
  47. <regex>\s+activity="(\.*)"|\s+activity=(\.*)\s|\s+activity=(\.*)$</regex>
  48. <order>activity</order>
  49. </decoder>
  50. <decoder name="fortinet-fortigate-fields-v7">
  51. <parent>fortinet-fortigate-firewall</parent>
  52. <regex>\s+activitycategory="(\.*)"|\s+activitycategory=(\.*)\s|\s+activitycategory=(\.*)$</regex>
  53. <order>activitycategory</order>
  54. </decoder>
  55. <decoder name="fortinet-fortigate-fields-v7">
  56. <parent>fortinet-fortigate-firewall</parent>
  57. <regex>\s+addr="(\.*)"|\s+addr=(\.*)\s|\s+addr=(\.*)$</regex>
  58. <order>addr</order>
  59. </decoder>
  60. <decoder name="fortinet-fortigate-fields-v7">
  61. <parent>fortinet-fortigate-firewall</parent>
  62. <regex>\s+addr_type="(\.*)"|\s+addr_type=(\.*)\s|\s+addr_type=(\.*)$</regex>
  63. <order>addr_type</order>
  64. </decoder>
  65. <decoder name="fortinet-fortigate-fields-v7">
  66. <parent>fortinet-fortigate-firewall</parent>
  67. <regex>\s+addrgrp="(\.*)"|\s+addrgrp=(\.*)\s|\s+addrgrp=(\.*)$</regex>
  68. <order>addrgrp</order>
  69. </decoder>
  70. <decoder name="fortinet-fortigate-fields-v7">
  71. <parent>fortinet-fortigate-firewall</parent>
  72. <regex>\s+adgroup="(\.*)"|\s+adgroup=(\.*)\s|\s+adgroup=(\.*)$</regex>
  73. <order>adgroup</order>
  74. </decoder>
  75. <decoder name="fortinet-fortigate-fields-v7">
  76. <parent>fortinet-fortigate-firewall</parent>
  77. <regex>\s+admin="(\.*)"|\s+admin=(\.*)\s|\s+admin=(\.*)$</regex>
  78. <order>admin</order>
  79. </decoder>
  80. <decoder name="fortinet-fortigate-fields-v7">
  81. <parent>fortinet-fortigate-firewall</parent>
  82. <regex>\s+advpnsc="(\.*)"|\s+advpnsc=(\.*)\s|\s+advpnsc=(\.*)$</regex>
  83. <order>advpnsc</order>
  84. </decoder>
  85. <decoder name="fortinet-fortigate-fields-v7">
  86. <parent>fortinet-fortigate-firewall</parent>
  87. <regex>\s+age="(\.*)"|\s+age=(\.*)\s|\s+age=(\.*)$</regex>
  88. <order>age</order>
  89. </decoder>
  90. <decoder name="fortinet-fortigate-fields-v7">
  91. <parent>fortinet-fortigate-firewall</parent>
  92. <regex>\s+agent="(\.*)"|\s+agent=(\.*)\s|\s+agent=(\.*)$</regex>
  93. <order>agent</order>
  94. </decoder>
  95. <decoder name="fortinet-fortigate-fields-v7">
  96. <parent>fortinet-fortigate-firewall</parent>
  97. <regex>\s+alarmid="(\.*)"|\s+alarmid=(\.*)\s|\s+alarmid=(\.*)$</regex>
  98. <order>alarmid</order>
  99. </decoder>
  100. <decoder name="fortinet-fortigate-fields-v7">
  101. <parent>fortinet-fortigate-firewall</parent>
  102. <regex>\s+alert="(\.*)"|\s+alert=(\.*)\s|\s+alert=(\.*)$</regex>
  103. <order>alert</order>
  104. </decoder>
  105. <decoder name="fortinet-fortigate-fields-v7">
  106. <parent>fortinet-fortigate-firewall</parent>
  107. <regex>\s+analyticscksum="(\.*)"|\s+analyticscksum=(\.*)\s|\s+analyticscksum=(\.*)$</regex>
  108. <order>analyticscksum</order>
  109. </decoder>
  110. <decoder name="fortinet-fortigate-fields-v7">
  111. <parent>fortinet-fortigate-firewall</parent>
  112. <regex>\s+analyticssubmit="(\.*)"|\s+analyticssubmit=(\.*)\s|\s+analyticssubmit=(\.*)$</regex>
  113. <order>analyticssubmit</order>
  114. </decoder>
  115. <decoder name="fortinet-fortigate-fields-v7">
  116. <parent>fortinet-fortigate-firewall</parent>
  117. <regex>\s+anomaly="(\.*)"|\s+anomaly=(\.*)\s|\s+anomaly=(\.*)$</regex>
  118. <order>anomaly</order>
  119. </decoder>
  120. <decoder name="fortinet-fortigate-fields-v7">
  121. <parent>fortinet-fortigate-firewall</parent>
  122. <regex>\s+antiphishdc="(\.*)"|\s+antiphishdc=(\.*)\s|\s+antiphishdc=(\.*)$</regex>
  123. <order>antiphishdc</order>
  124. </decoder>
  125. <decoder name="fortinet-fortigate-fields-v7">
  126. <parent>fortinet-fortigate-firewall</parent>
  127. <regex>\s+antiphishrule="(\.*)"|\s+antiphishrule=(\.*)\s|\s+antiphishrule=(\.*)$</regex>
  128. <order>antiphishrule</order>
  129. </decoder>
  130. <decoder name="fortinet-fortigate-fields-v7">
  131. <parent>fortinet-fortigate-firewall</parent>
  132. <regex>\s+ap="(\.*)"|\s+ap=(\.*)\s|\s+ap=(\.*)$</regex>
  133. <order>ap</order>
  134. </decoder>
  135. <decoder name="fortinet-fortigate-fields-v7">
  136. <parent>fortinet-fortigate-firewall</parent>
  137. <regex>\s+apn="(\.*)"|\s+apn=(\.*)\s|\s+apn=(\.*)$</regex>
  138. <order>apn</order>
  139. </decoder>
  140. <decoder name="fortinet-fortigate-fields-v7">
  141. <parent>fortinet-fortigate-firewall</parent>
  142. <regex>\s+app="(\.*)"|\s+app=(\.*)\s|\s+app=(\.*)$</regex>
  143. <order>app</order>
  144. </decoder>
  145. <decoder name="fortinet-fortigate-fields-v7">
  146. <parent>fortinet-fortigate-firewall</parent>
  147. <regex>\s+appact="(\.*)"|\s+appact=(\.*)\s|\s+appact=(\.*)$</regex>
  148. <order>appact</order>
  149. </decoder>
  150. <decoder name="fortinet-fortigate-fields-v7">
  151. <parent>fortinet-fortigate-firewall</parent>
  152. <regex>\s+appcat="(\.*)"|\s+appcat=(\.*)\s|\s+appcat=(\.*)$</regex>
  153. <order>appcat</order>
  154. </decoder>
  155. <decoder name="fortinet-fortigate-fields-v7">
  156. <parent>fortinet-fortigate-firewall</parent>
  157. <regex>\s+apperror="(\.*)"|\s+apperror=(\.*)\s|\s+apperror=(\.*)$</regex>
  158. <order>apperror</order>
  159. </decoder>
  160. <decoder name="fortinet-fortigate-fields-v7">
  161. <parent>fortinet-fortigate-firewall</parent>
  162. <regex>\s+appid="(\.*)"|\s+appid=(\.*)\s|\s+appid=(\.*)$</regex>
  163. <order>appid</order>
  164. </decoder>
  165. <decoder name="fortinet-fortigate-fields-v7">
  166. <parent>fortinet-fortigate-firewall</parent>
  167. <regex>\s+applist="(\.*)"|\s+applist=(\.*)\s|\s+applist=(\.*)$</regex>
  168. <order>applist</order>
  169. </decoder>
  170. <decoder name="fortinet-fortigate-fields-v7">
  171. <parent>fortinet-fortigate-firewall</parent>
  172. <regex>\s+apprisk="(\.*)"|\s+apprisk=(\.*)\s|\s+apprisk=(\.*)$</regex>
  173. <order>apprisk</order>
  174. </decoder>
  175. <decoder name="fortinet-fortigate-fields-v7">
  176. <parent>fortinet-fortigate-firewall</parent>
  177. <regex>\s+apscan="(\.*)"|\s+apscan=(\.*)\s|\s+apscan=(\.*)$</regex>
  178. <order>apscan</order>
  179. </decoder>
  180. <decoder name="fortinet-fortigate-fields-v7">
  181. <parent>fortinet-fortigate-firewall</parent>
  182. <regex>\s+apsn="(\.*)"|\s+apsn=(\.*)\s|\s+apsn=(\.*)$</regex>
  183. <order>apsn</order>
  184. </decoder>
  185. <decoder name="fortinet-fortigate-fields-v7">
  186. <parent>fortinet-fortigate-firewall</parent>
  187. <regex>\s+apstatus="(\.*)"|\s+apstatus=(\.*)\s|\s+apstatus=(\.*)$</regex>
  188. <order>apstatus</order>
  189. </decoder>
  190. <decoder name="fortinet-fortigate-fields-v7">
  191. <parent>fortinet-fortigate-firewall</parent>
  192. <regex>\s+aptype="(\.*)"|\s+aptype=(\.*)\s|\s+aptype=(\.*)$</regex>
  193. <order>aptype</order>
  194. </decoder>
  195. <decoder name="fortinet-fortigate-fields-v7">
  196. <parent>fortinet-fortigate-firewall</parent>
  197. <regex>\s+assigned="(\.*)"|\s+assigned=(\.*)\s|\s+assigned=(\.*)$</regex>
  198. <order>assigned</order>
  199. </decoder>
  200. <decoder name="fortinet-fortigate-fields-v7">
  201. <parent>fortinet-fortigate-firewall</parent>
  202. <regex>\s+assignip="(\.*)"|\s+assignip=(\.*)\s|\s+assignip=(\.*)$</regex>
  203. <order>assignip</order>
  204. </decoder>
  205. <decoder name="fortinet-fortigate-fields-v7">
  206. <parent>fortinet-fortigate-firewall</parent>
  207. <regex>\s+attachment="(\.*)"|\s+attachment=(\.*)\s|\s+attachment=(\.*)$</regex>
  208. <order>attachment</order>
  209. </decoder>
  210. <decoder name="fortinet-fortigate-fields-v7">
  211. <parent>fortinet-fortigate-firewall</parent>
  212. <regex>\s+attack="(\.*)"|\s+attack=(\.*)\s|\s+attack=(\.*)$</regex>
  213. <order>attack</order>
  214. </decoder>
  215. <decoder name="fortinet-fortigate-fields-v7">
  216. <parent>fortinet-fortigate-firewall</parent>
  217. <regex>\s+attackcontext="(\.*)"|\s+attackcontext=(\.*)\s|\s+attackcontext=(\.*)$</regex>
  218. <order>attackcontext</order>
  219. </decoder>
  220. <decoder name="fortinet-fortigate-fields-v7">
  221. <parent>fortinet-fortigate-firewall</parent>
  222. <regex>\s+attackcontextid="(\.*)"|\s+attackcontextid=(\.*)\s|\s+attackcontextid=(\.*)$</regex>
  223. <order>attackcontextid</order>
  224. </decoder>
  225. <decoder name="fortinet-fortigate-fields-v7">
  226. <parent>fortinet-fortigate-firewall</parent>
  227. <regex>\s+attackid="(\.*)"|\s+attackid=(\.*)\s|\s+attackid=(\.*)$</regex>
  228. <order>attackid</order>
  229. </decoder>
  230. <decoder name="fortinet-fortigate-fields-v7">
  231. <parent>fortinet-fortigate-firewall</parent>
  232. <regex>\s+auditid="(\.*)"|\s+auditid=(\.*)\s|\s+auditid=(\.*)$</regex>
  233. <order>auditid</order>
  234. </decoder>
  235. <decoder name="fortinet-fortigate-fields-v7">
  236. <parent>fortinet-fortigate-firewall</parent>
  237. <regex>\s+auditreporttype="(\.*)"|\s+auditreporttype=(\.*)\s|\s+auditreporttype=(\.*)$</regex>
  238. <order>auditreporttype</order>
  239. </decoder>
  240. <decoder name="fortinet-fortigate-fields-v7">
  241. <parent>fortinet-fortigate-firewall</parent>
  242. <regex>\s+auditscore="(\.*)"|\s+auditscore=(\.*)\s|\s+auditscore=(\.*)$</regex>
  243. <order>auditscore</order>
  244. </decoder>
  245. <decoder name="fortinet-fortigate-fields-v7">
  246. <parent>fortinet-fortigate-firewall</parent>
  247. <regex>\s+audittime="(\.*)"|\s+audittime=(\.*)\s|\s+audittime=(\.*)$</regex>
  248. <order>audittime</order>
  249. </decoder>
  250. <decoder name="fortinet-fortigate-fields-v7">
  251. <parent>fortinet-fortigate-firewall</parent>
  252. <regex>\s+authalgo="(\.*)"|\s+authalgo=(\.*)\s|\s+authalgo=(\.*)$</regex>
  253. <order>authalgo</order>
  254. </decoder>
  255. <decoder name="fortinet-fortigate-fields-v7">
  256. <parent>fortinet-fortigate-firewall</parent>
  257. <regex>\s+authgrp="(\.*)"|\s+authgrp=(\.*)\s|\s+authgrp=(\.*)$</regex>
  258. <order>authgrp</order>
  259. </decoder>
  260. <decoder name="fortinet-fortigate-fields-v7">
  261. <parent>fortinet-fortigate-firewall</parent>
  262. <regex>\s+authid="(\.*)"|\s+authid=(\.*)\s|\s+authid=(\.*)$</regex>
  263. <order>authid</order>
  264. </decoder>
  265. <decoder name="fortinet-fortigate-fields-v7">
  266. <parent>fortinet-fortigate-firewall</parent>
  267. <regex>\s+authproto="(\.*)"|\s+authproto=(\.*)\s|\s+authproto=(\.*)$</regex>
  268. <order>authproto</order>
  269. </decoder>
  270. <decoder name="fortinet-fortigate-fields-v7">
  271. <parent>fortinet-fortigate-firewall</parent>
  272. <regex>\s+authserver="(\.*)"|\s+authserver=(\.*)\s|\s+authserver=(\.*)$</regex>
  273. <order>authserver</order>
  274. </decoder>
  275. <decoder name="fortinet-fortigate-fields-v7">
  276. <parent>fortinet-fortigate-firewall</parent>
  277. <regex>\s+bandwidth="(\.*)"|\s+bandwidth=(\.*)\s|\s+bandwidth=(\.*)$</regex>
  278. <order>bandwidth</order>
  279. </decoder>
  280. <decoder name="fortinet-fortigate-fields-v7">
  281. <parent>fortinet-fortigate-firewall</parent>
  282. <regex>\s+banned_rule="(\.*)"|\s+banned_rule=(\.*)\s|\s+banned_rule=(\.*)$</regex>
  283. <order>banned_rule</order>
  284. </decoder>
  285. <decoder name="fortinet-fortigate-fields-v7">
  286. <parent>fortinet-fortigate-firewall</parent>
  287. <regex>\s+banned_src="(\.*)"|\s+banned_src=(\.*)\s|\s+banned_src=(\.*)$</regex>
  288. <order>banned_src</order>
  289. </decoder>
  290. <decoder name="fortinet-fortigate-fields-v7">
  291. <parent>fortinet-fortigate-firewall</parent>
  292. <regex>\s+banword="(\.*)"|\s+banword=(\.*)\s|\s+banword=(\.*)$</regex>
  293. <order>banword</order>
  294. </decoder>
  295. <decoder name="fortinet-fortigate-fields-v7">
  296. <parent>fortinet-fortigate-firewall</parent>
  297. <regex>\s+bibandwidth="(\.*)"|\s+bibandwidth=(\.*)\s|\s+bibandwidth=(\.*)$</regex>
  298. <order>bibandwidth</order>
  299. </decoder>
  300. <decoder name="fortinet-fortigate-fields-v7">
  301. <parent>fortinet-fortigate-firewall</parent>
  302. <regex>\s+bibandwidthavailable="(\.*)"|\s+bibandwidthavailable=(\.*)\s|\s+bibandwidthavailable=(\.*)$</regex>
  303. <order>bibandwidthavailable</order>
  304. </decoder>
  305. <decoder name="fortinet-fortigate-fields-v7">
  306. <parent>fortinet-fortigate-firewall</parent>
  307. <regex>\s+bibandwidthused="(\.*)"|\s+bibandwidthused=(\.*)\s|\s+bibandwidthused=(\.*)$</regex>
  308. <order>bibandwidthused</order>
  309. </decoder>
  310. <decoder name="fortinet-fortigate-fields-v7">
  311. <parent>fortinet-fortigate-firewall</parent>
  312. <regex>\s+botnetdomain="(\.*)"|\s+botnetdomain=(\.*)\s|\s+botnetdomain=(\.*)$</regex>
  313. <order>botnetdomain</order>
  314. </decoder>
  315. <decoder name="fortinet-fortigate-fields-v7">
  316. <parent>fortinet-fortigate-firewall</parent>
  317. <regex>\s+botnetip="(\.*)"|\s+botnetip=(\.*)\s|\s+botnetip=(\.*)$</regex>
  318. <order>botnetip</order>
  319. </decoder>
  320. <decoder name="fortinet-fortigate-fields-v7">
  321. <parent>fortinet-fortigate-firewall</parent>
  322. <regex>\s+bssid="(\.*)"|\s+bssid=(\.*)\s|\s+bssid=(\.*)$</regex>
  323. <order>bssid</order>
  324. </decoder>
  325. <decoder name="fortinet-fortigate-fields-v7">
  326. <parent>fortinet-fortigate-firewall</parent>
  327. <regex>\s+call_id="(\.*)"|\s+call_id=(\.*)\s|\s+call_id=(\.*)$</regex>
  328. <order>call_id</order>
  329. </decoder>
  330. <decoder name="fortinet-fortigate-fields-v7">
  331. <parent>fortinet-fortigate-firewall</parent>
  332. <regex>\s+carrier_ep="(\.*)"|\s+carrier_ep=(\.*)\s|\s+carrier_ep=(\.*)$</regex>
  333. <order>carrier_ep</order>
  334. </decoder>
  335. <decoder name="fortinet-fortigate-fields-v7">
  336. <parent>fortinet-fortigate-firewall</parent>
  337. <regex>\s+casb="(\.*)"|\s+casb=(\.*)\s|\s+casb=(\.*)$</regex>
  338. <order>casb</order>
  339. </decoder>
  340. <decoder name="fortinet-fortigate-fields-v7">
  341. <parent>fortinet-fortigate-firewall</parent>
  342. <regex>\s+cat="(\.*)"|\s+cat=(\.*)\s|\s+cat=(\.*)$</regex>
  343. <order>cat</order>
  344. </decoder>
  345. <decoder name="fortinet-fortigate-fields-v7">
  346. <parent>fortinet-fortigate-firewall</parent>
  347. <regex>\s+catdesc="(\.*)"|\s+catdesc=(\.*)\s|\s+catdesc=(\.*)$</regex>
  348. <order>catdesc</order>
  349. </decoder>
  350. <decoder name="fortinet-fortigate-fields-v7">
  351. <parent>fortinet-fortigate-firewall</parent>
  352. <regex>\s+category="(\.*)"|\s+category=(\.*)\s|\s+category=(\.*)$</regex>
  353. <order>category</order>
  354. </decoder>
  355. <decoder name="fortinet-fortigate-fields-v7">
  356. <parent>fortinet-fortigate-firewall</parent>
  357. <regex>\s+cc="(\.*)"|\s+cc=(\.*)\s|\s+cc=(\.*)$</regex>
  358. <order>cc</order>
  359. </decoder>
  360. <decoder name="fortinet-fortigate-fields-v7">
  361. <parent>fortinet-fortigate-firewall</parent>
  362. <regex>\s+ccertissuer="(\.*)"|\s+ccertissuer=(\.*)\s|\s+ccertissuer=(\.*)$</regex>
  363. <order>ccertissuer</order>
  364. </decoder>
  365. <decoder name="fortinet-fortigate-fields-v7">
  366. <parent>fortinet-fortigate-firewall</parent>
  367. <regex>\s+cdrcontent="(\.*)"|\s+cdrcontent=(\.*)\s|\s+cdrcontent=(\.*)$</regex>
  368. <order>cdrcontent</order>
  369. </decoder>
  370. <decoder name="fortinet-fortigate-fields-v7">
  371. <parent>fortinet-fortigate-firewall</parent>
  372. <regex>\s+centralnatid="(\.*)"|\s+centralnatid=(\.*)\s|\s+centralnatid=(\.*)$</regex>
  373. <order>centralnatid</order>
  374. </decoder>
  375. <decoder name="fortinet-fortigate-fields-v7">
  376. <parent>fortinet-fortigate-firewall</parent>
  377. <regex>\s+cert="(\.*)"|\s+cert=(\.*)\s|\s+cert=(\.*)$</regex>
  378. <order>cert</order>
  379. </decoder>
  380. <decoder name="fortinet-fortigate-fields-v7">
  381. <parent>fortinet-fortigate-firewall</parent>
  382. <regex>\s+certdesc="(\.*)"|\s+certdesc=(\.*)\s|\s+certdesc=(\.*)$</regex>
  383. <order>certdesc</order>
  384. </decoder>
  385. <decoder name="fortinet-fortigate-fields-v7">
  386. <parent>fortinet-fortigate-firewall</parent>
  387. <regex>\s+certhash="(\.*)"|\s+certhash=(\.*)\s|\s+certhash=(\.*)$</regex>
  388. <order>certhash</order>
  389. </decoder>
  390. <decoder name="fortinet-fortigate-fields-v7">
  391. <parent>fortinet-fortigate-firewall</parent>
  392. <regex>\s+cfgattr="(\.*)"|\s+cfgattr=(\.*)\s|\s+cfgattr=(\.*)$</regex>
  393. <order>cfgattr</order>
  394. </decoder>
  395. <decoder name="fortinet-fortigate-fields-v7">
  396. <parent>fortinet-fortigate-firewall</parent>
  397. <regex>\s+cfgobj="(\.*)"|\s+cfgobj=(\.*)\s|\s+cfgobj=(\.*)$</regex>
  398. <order>cfgobj</order>
  399. </decoder>
  400. <decoder name="fortinet-fortigate-fields-v7">
  401. <parent>fortinet-fortigate-firewall</parent>
  402. <regex>\s+cfgpath="(\.*)"|\s+cfgpath=(\.*)\s|\s+cfgpath=(\.*)$</regex>
  403. <order>cfgpath</order>
  404. </decoder>
  405. <decoder name="fortinet-fortigate-fields-v7">
  406. <parent>fortinet-fortigate-firewall</parent>
  407. <regex>\s+cfgtid="(\.*)"|\s+cfgtid=(\.*)\s|\s+cfgtid=(\.*)$</regex>
  408. <order>cfgtid</order>
  409. </decoder>
  410. <decoder name="fortinet-fortigate-fields-v7">
  411. <parent>fortinet-fortigate-firewall</parent>
  412. <regex>\s+cfgtxpower="(\.*)"|\s+cfgtxpower=(\.*)\s|\s+cfgtxpower=(\.*)$</regex>
  413. <order>cfgtxpower</order>
  414. </decoder>
  415. <decoder name="fortinet-fortigate-fields-v7">
  416. <parent>fortinet-fortigate-firewall</parent>
  417. <regex>\s+cfseid="(\.*)"|\s+cfseid=(\.*)\s|\s+cfseid=(\.*)$</regex>
  418. <order>cfseid</order>
  419. </decoder>
  420. <decoder name="fortinet-fortigate-fields-v7">
  421. <parent>fortinet-fortigate-firewall</parent>
  422. <regex>\s+cfseidaddr="(\.*)"|\s+cfseidaddr=(\.*)\s|\s+cfseidaddr=(\.*)$</regex>
  423. <order>cfseidaddr</order>
  424. </decoder>
  425. <decoder name="fortinet-fortigate-fields-v7">
  426. <parent>fortinet-fortigate-firewall</parent>
  427. <regex>\s+cggsn="(\.*)"|\s+cggsn=(\.*)\s|\s+cggsn=(\.*)$</regex>
  428. <order>cggsn</order>
  429. </decoder>
  430. <decoder name="fortinet-fortigate-fields-v7">
  431. <parent>fortinet-fortigate-firewall</parent>
  432. <regex>\s+cgsn="(\.*)"|\s+cgsn=(\.*)\s|\s+cgsn=(\.*)$</regex>
  433. <order>cgsn</order>
  434. </decoder>
  435. <decoder name="fortinet-fortigate-fields-v7">
  436. <parent>fortinet-fortigate-firewall</parent>
  437. <regex>\s+channel="(\.*)"|\s+channel=(\.*)\s|\s+channel=(\.*)$</regex>
  438. <order>channel</order>
  439. </decoder>
  440. <decoder name="fortinet-fortigate-fields-v7">
  441. <parent>fortinet-fortigate-firewall</parent>
  442. <regex>\s+channeltype="(\.*)"|\s+channeltype=(\.*)\s|\s+channeltype=(\.*)$</regex>
  443. <order>channeltype</order>
  444. </decoder>
  445. <decoder name="fortinet-fortigate-fields-v7">
  446. <parent>fortinet-fortigate-firewall</parent>
  447. <regex>\s+chassisid="(\.*)"|\s+chassisid=(\.*)\s|\s+chassisid=(\.*)$</regex>
  448. <order>chassisid</order>
  449. </decoder>
  450. <decoder name="fortinet-fortigate-fields-v7">
  451. <parent>fortinet-fortigate-firewall</parent>
  452. <regex>\s+checksum="(\.*)"|\s+checksum=(\.*)\s|\s+checksum=(\.*)$</regex>
  453. <order>checksum</order>
  454. </decoder>
  455. <decoder name="fortinet-fortigate-fields-v7">
  456. <parent>fortinet-fortigate-firewall</parent>
  457. <regex>\s+chgheaders="(\.*)"|\s+chgheaders=(\.*)\s|\s+chgheaders=(\.*)$</regex>
  458. <order>chgheaders</order>
  459. </decoder>
  460. <decoder name="fortinet-fortigate-fields-v7">
  461. <parent>fortinet-fortigate-firewall</parent>
  462. <regex>\s+cipher="(\.*)"|\s+cipher=(\.*)\s|\s+cipher=(\.*)$</regex>
  463. <order>cipher</order>
  464. </decoder>
  465. <decoder name="fortinet-fortigate-fields-v7">
  466. <parent>fortinet-fortigate-firewall</parent>
  467. <regex>\s+clashtunnelidx="(\.*)"|\s+clashtunnelidx=(\.*)\s|\s+clashtunnelidx=(\.*)$</regex>
  468. <order>clashtunnelidx</order>
  469. </decoder>
  470. <decoder name="fortinet-fortigate-fields-v7">
  471. <parent>fortinet-fortigate-firewall</parent>
  472. <regex>\s+cldobjid="(\.*)"|\s+cldobjid=(\.*)\s|\s+cldobjid=(\.*)$</regex>
  473. <order>cldobjid</order>
  474. </decoder>
  475. <decoder name="fortinet-fortigate-fields-v7">
  476. <parent>fortinet-fortigate-firewall</parent>
  477. <regex>\s+client_addr="(\.*)"|\s+client_addr=(\.*)\s|\s+client_addr=(\.*)$</regex>
  478. <order>client_addr</order>
  479. </decoder>
  480. <decoder name="fortinet-fortigate-fields-v7">
  481. <parent>fortinet-fortigate-firewall</parent>
  482. <regex>\s+clientcert="(\.*)"|\s+clientcert=(\.*)\s|\s+clientcert=(\.*)$</regex>
  483. <order>clientcert</order>
  484. </decoder>
  485. <decoder name="fortinet-fortigate-fields-v7">
  486. <parent>fortinet-fortigate-firewall</parent>
  487. <regex>\s+clientdeviceems="(\.*)"|\s+clientdeviceems=(\.*)\s|\s+clientdeviceems=(\.*)$</regex>
  488. <order>clientdeviceems</order>
  489. </decoder>
  490. <decoder name="fortinet-fortigate-fields-v7">
  491. <parent>fortinet-fortigate-firewall</parent>
  492. <regex>\s+clientdeviceid="(\.*)"|\s+clientdeviceid=(\.*)\s|\s+clientdeviceid=(\.*)$</regex>
  493. <order>clientdeviceid</order>
  494. </decoder>
  495. <decoder name="fortinet-fortigate-fields-v7">
  496. <parent>fortinet-fortigate-firewall</parent>
  497. <regex>\s+clientdevicemanageable="(\.*)"|\s+clientdevicemanageable=(\.*)\s|\s+clientdevicemanageable=(\.*)$</regex>
  498. <order>clientdevicemanageable</order>
  499. </decoder>
  500. <decoder name="fortinet-fortigate-fields-v7">
  501. <parent>fortinet-fortigate-firewall</parent>
  502. <regex>\s+clientdeviceowner="(\.*)"|\s+clientdeviceowner=(\.*)\s|\s+clientdeviceowner=(\.*)$</regex>
  503. <order>clientdeviceowner</order>
  504. </decoder>
  505. <decoder name="fortinet-fortigate-fields-v7">
  506. <parent>fortinet-fortigate-firewall</parent>
  507. <regex>\s+clientdevicetags="(\.*)"|\s+clientdevicetags=(\.*)\s|\s+clientdevicetags=(\.*)$</regex>
  508. <order>clientdevicetags</order>
  509. </decoder>
  510. <decoder name="fortinet-fortigate-fields-v7">
  511. <parent>fortinet-fortigate-firewall</parent>
  512. <regex>\s+cloudaction="(\.*)"|\s+cloudaction=(\.*)\s|\s+cloudaction=(\.*)$</regex>
  513. <order>cloudaction</order>
  514. </decoder>
  515. <decoder name="fortinet-fortigate-fields-v7">
  516. <parent>fortinet-fortigate-firewall</parent>
  517. <regex>\s+clouddevice="(\.*)"|\s+clouddevice=(\.*)\s|\s+clouddevice=(\.*)$</regex>
  518. <order>clouddevice</order>
  519. </decoder>
  520. <decoder name="fortinet-fortigate-fields-v7">
  521. <parent>fortinet-fortigate-firewall</parent>
  522. <regex>\s+clouduser="(\.*)"|\s+clouduser=(\.*)\s|\s+clouduser=(\.*)$</regex>
  523. <order>clouduser</order>
  524. </decoder>
  525. <decoder name="fortinet-fortigate-fields-v7">
  526. <parent>fortinet-fortigate-firewall</parent>
  527. <regex>\s+cmdbpathname="(\.*)"|\s+cmdbpathname=(\.*)\s|\s+cmdbpathname=(\.*)$</regex>
  528. <order>cmdbpathname</order>
  529. </decoder>
  530. <decoder name="fortinet-fortigate-fields-v7">
  531. <parent>fortinet-fortigate-firewall</parent>
  532. <regex>\s+cmdbtablename="(\.*)"|\s+cmdbtablename=(\.*)\s|\s+cmdbtablename=(\.*)$</regex>
  533. <order>cmdbtablename</order>
  534. </decoder>
  535. <decoder name="fortinet-fortigate-fields-v7">
  536. <parent>fortinet-fortigate-firewall</parent>
  537. <regex>\s+cn="(\.*)"|\s+cn=(\.*)\s|\s+cn=(\.*)$</regex>
  538. <order>cn</order>
  539. </decoder>
  540. <decoder name="fortinet-fortigate-fields-v7">
  541. <parent>fortinet-fortigate-firewall</parent>
  542. <regex>\s+column="(\.*)"|\s+column=(\.*)\s|\s+column=(\.*)$</regex>
  543. <order>column</order>
  544. </decoder>
  545. <decoder name="fortinet-fortigate-fields-v7">
  546. <parent>fortinet-fortigate-firewall</parent>
  547. <regex>\s+command="(\.*)"|\s+command=(\.*)\s|\s+command=(\.*)$</regex>
  548. <order>command</order>
  549. </decoder>
  550. <decoder name="fortinet-fortigate-fields-v7">
  551. <parent>fortinet-fortigate-firewall</parent>
  552. <regex>\s+comment="(\.*)"|\s+comment=(\.*)\s|\s+comment=(\.*)$</regex>
  553. <order>comment</order>
  554. </decoder>
  555. <decoder name="fortinet-fortigate-fields-v7">
  556. <parent>fortinet-fortigate-firewall</parent>
  557. <regex>\s+community="(\.*)"|\s+community=(\.*)\s|\s+community=(\.*)$</regex>
  558. <order>community</order>
  559. </decoder>
  560. <decoder name="fortinet-fortigate-fields-v7">
  561. <parent>fortinet-fortigate-firewall</parent>
  562. <regex>\s+components="(\.*)"|\s+components=(\.*)\s|\s+components=(\.*)$</regex>
  563. <order>components</order>
  564. </decoder>
  565. <decoder name="fortinet-fortigate-fields-v7">
  566. <parent>fortinet-fortigate-firewall</parent>
  567. <regex>\s+configcountry="(\.*)"|\s+configcountry=(\.*)\s|\s+configcountry=(\.*)$</regex>
  568. <order>configcountry</order>
  569. </decoder>
  570. <decoder name="fortinet-fortigate-fields-v7">
  571. <parent>fortinet-fortigate-firewall</parent>
  572. <regex>\s+conflictcount="(\.*)"|\s+conflictcount=(\.*)\s|\s+conflictcount=(\.*)$</regex>
  573. <order>conflictcount</order>
  574. </decoder>
  575. <decoder name="fortinet-fortigate-fields-v7">
  576. <parent>fortinet-fortigate-firewall</parent>
  577. <regex>\s+connection_type="(\.*)"|\s+connection_type=(\.*)\s|\s+connection_type=(\.*)$</regex>
  578. <order>connection_type</order>
  579. </decoder>
  580. <decoder name="fortinet-fortigate-fields-v7">
  581. <parent>fortinet-fortigate-firewall</parent>
  582. <regex>\s+conserve="(\.*)"|\s+conserve=(\.*)\s|\s+conserve=(\.*)$</regex>
  583. <order>conserve</order>
  584. </decoder>
  585. <decoder name="fortinet-fortigate-fields-v7">
  586. <parent>fortinet-fortigate-firewall</parent>
  587. <regex>\s+constraint="(\.*)"|\s+constraint=(\.*)\s|\s+constraint=(\.*)$</regex>
  588. <order>constraint</order>
  589. </decoder>
  590. <decoder name="fortinet-fortigate-fields-v7">
  591. <parent>fortinet-fortigate-firewall</parent>
  592. <regex>\s+contentdisarmed="(\.*)"|\s+contentdisarmed=(\.*)\s|\s+contentdisarmed=(\.*)$</regex>
  593. <order>contentdisarmed</order>
  594. </decoder>
  595. <decoder name="fortinet-fortigate-fields-v7">
  596. <parent>fortinet-fortigate-firewall</parent>
  597. <regex>\s+contentencoding="(\.*)"|\s+contentencoding=(\.*)\s|\s+contentencoding=(\.*)$</regex>
  598. <order>contentencoding</order>
  599. </decoder>
  600. <decoder name="fortinet-fortigate-fields-v7">
  601. <parent>fortinet-fortigate-firewall</parent>
  602. <regex>\s+contenttype="(\.*)"|\s+contenttype=(\.*)\s|\s+contenttype=(\.*)$</regex>
  603. <order>contenttype</order>
  604. </decoder>
  605. <decoder name="fortinet-fortigate-fields-v7">
  606. <parent>fortinet-fortigate-firewall</parent>
  607. <regex>\s+cookies="(\.*)"|\s+cookies=(\.*)\s|\s+cookies=(\.*)$</regex>
  608. <order>cookies</order>
  609. </decoder>
  610. <decoder name="fortinet-fortigate-fields-v7">
  611. <parent>fortinet-fortigate-firewall</parent>
  612. <regex>\s+core="(\.*)"|\s+core=(\.*)\s|\s+core=(\.*)$</regex>
  613. <order>core</order>
  614. </decoder>
  615. <decoder name="fortinet-fortigate-fields-v7">
  616. <parent>fortinet-fortigate-firewall</parent>
  617. <regex>\s+count="(\.*)"|\s+count=(\.*)\s|\s+count=(\.*)$</regex>
  618. <order>count</order>
  619. </decoder>
  620. <decoder name="fortinet-fortigate-fields-v7">
  621. <parent>fortinet-fortigate-firewall</parent>
  622. <regex>\s+countapp="(\.*)"|\s+countapp=(\.*)\s|\s+countapp=(\.*)$</regex>
  623. <order>countapp</order>
  624. </decoder>
  625. <decoder name="fortinet-fortigate-fields-v7">
  626. <parent>fortinet-fortigate-firewall</parent>
  627. <regex>\s+countav="(\.*)"|\s+countav=(\.*)\s|\s+countav=(\.*)$</regex>
  628. <order>countav</order>
  629. </decoder>
  630. <decoder name="fortinet-fortigate-fields-v7">
  631. <parent>fortinet-fortigate-firewall</parent>
  632. <regex>\s+countcasb="(\.*)"|\s+countcasb=(\.*)\s|\s+countcasb=(\.*)$</regex>
  633. <order>countcasb</order>
  634. </decoder>
  635. <decoder name="fortinet-fortigate-fields-v7">
  636. <parent>fortinet-fortigate-firewall</parent>
  637. <regex>\s+countcifs="(\.*)"|\s+countcifs=(\.*)\s|\s+countcifs=(\.*)$</regex>
  638. <order>countcifs</order>
  639. </decoder>
  640. <decoder name="fortinet-fortigate-fields-v7">
  641. <parent>fortinet-fortigate-firewall</parent>
  642. <regex>\s+countdlp="(\.*)"|\s+countdlp=(\.*)\s|\s+countdlp=(\.*)$</regex>
  643. <order>countdlp</order>
  644. </decoder>
  645. <decoder name="fortinet-fortigate-fields-v7">
  646. <parent>fortinet-fortigate-firewall</parent>
  647. <regex>\s+countdns="(\.*)"|\s+countdns=(\.*)\s|\s+countdns=(\.*)$</regex>
  648. <order>countdns</order>
  649. </decoder>
  650. <decoder name="fortinet-fortigate-fields-v7">
  651. <parent>fortinet-fortigate-firewall</parent>
  652. <regex>\s+countemail="(\.*)"|\s+countemail=(\.*)\s|\s+countemail=(\.*)$</regex>
  653. <order>countemail</order>
  654. </decoder>
  655. <decoder name="fortinet-fortigate-fields-v7">
  656. <parent>fortinet-fortigate-firewall</parent>
  657. <regex>\s+countff="(\.*)"|\s+countff=(\.*)\s|\s+countff=(\.*)$</regex>
  658. <order>countff</order>
  659. </decoder>
  660. <decoder name="fortinet-fortigate-fields-v7">
  661. <parent>fortinet-fortigate-firewall</parent>
  662. <regex>\s+counticap="(\.*)"|\s+counticap=(\.*)\s|\s+counticap=(\.*)$</regex>
  663. <order>counticap</order>
  664. </decoder>
  665. <decoder name="fortinet-fortigate-fields-v7">
  666. <parent>fortinet-fortigate-firewall</parent>
  667. <regex>\s+countips="(\.*)"|\s+countips=(\.*)\s|\s+countips=(\.*)$</regex>
  668. <order>countips</order>
  669. </decoder>
  670. <decoder name="fortinet-fortigate-fields-v7">
  671. <parent>fortinet-fortigate-firewall</parent>
  672. <regex>\s+countsctpf="(\.*)"|\s+countsctpf=(\.*)\s|\s+countsctpf=(\.*)$</regex>
  673. <order>countsctpf</order>
  674. </decoder>
  675. <decoder name="fortinet-fortigate-fields-v7">
  676. <parent>fortinet-fortigate-firewall</parent>
  677. <regex>\s+countssh="(\.*)"|\s+countssh=(\.*)\s|\s+countssh=(\.*)$</regex>
  678. <order>countssh</order>
  679. </decoder>
  680. <decoder name="fortinet-fortigate-fields-v7">
  681. <parent>fortinet-fortigate-firewall</parent>
  682. <regex>\s+countssl="(\.*)"|\s+countssl=(\.*)\s|\s+countssl=(\.*)$</regex>
  683. <order>countssl</order>
  684. </decoder>
  685. <decoder name="fortinet-fortigate-fields-v7">
  686. <parent>fortinet-fortigate-firewall</parent>
  687. <regex>\s+countvpatch="(\.*)"|\s+countvpatch=(\.*)\s|\s+countvpatch=(\.*)$</regex>
  688. <order>countvpatch</order>
  689. </decoder>
  690. <decoder name="fortinet-fortigate-fields-v7">
  691. <parent>fortinet-fortigate-firewall</parent>
  692. <regex>\s+countwaf="(\.*)"|\s+countwaf=(\.*)\s|\s+countwaf=(\.*)$</regex>
  693. <order>countwaf</order>
  694. </decoder>
  695. <decoder name="fortinet-fortigate-fields-v7">
  696. <parent>fortinet-fortigate-firewall</parent>
  697. <regex>\s+countweb="(\.*)"|\s+countweb=(\.*)\s|\s+countweb=(\.*)$</regex>
  698. <order>countweb</order>
  699. </decoder>
  700. <decoder name="fortinet-fortigate-fields-v7">
  701. <parent>fortinet-fortigate-firewall</parent>
  702. <regex>\s+countztna="(\.*)"|\s+countztna=(\.*)\s|\s+countztna=(\.*)$</regex>
  703. <order>countztna</order>
  704. </decoder>
  705. <decoder name="fortinet-fortigate-fields-v7">
  706. <parent>fortinet-fortigate-firewall</parent>
  707. <regex>\s+cpaddr="(\.*)"|\s+cpaddr=(\.*)\s|\s+cpaddr=(\.*)$</regex>
  708. <order>cpaddr</order>
  709. </decoder>
  710. <decoder name="fortinet-fortigate-fields-v7">
  711. <parent>fortinet-fortigate-firewall</parent>
  712. <regex>\s+cpdladdr="(\.*)"|\s+cpdladdr=(\.*)\s|\s+cpdladdr=(\.*)$</regex>
  713. <order>cpdladdr</order>
  714. </decoder>
  715. <decoder name="fortinet-fortigate-fields-v7">
  716. <parent>fortinet-fortigate-firewall</parent>
  717. <regex>\s+cpdlisraddr="(\.*)"|\s+cpdlisraddr=(\.*)\s|\s+cpdlisraddr=(\.*)$</regex>
  718. <order>cpdlisraddr</order>
  719. </decoder>
  720. <decoder name="fortinet-fortigate-fields-v7">
  721. <parent>fortinet-fortigate-firewall</parent>
  722. <regex>\s+cpdlisrteid="(\.*)"|\s+cpdlisrteid=(\.*)\s|\s+cpdlisrteid=(\.*)$</regex>
  723. <order>cpdlisrteid</order>
  724. </decoder>
  725. <decoder name="fortinet-fortigate-fields-v7">
  726. <parent>fortinet-fortigate-firewall</parent>
  727. <regex>\s+cpdlteid="(\.*)"|\s+cpdlteid=(\.*)\s|\s+cpdlteid=(\.*)$</regex>
  728. <order>cpdlteid</order>
  729. </decoder>
  730. <decoder name="fortinet-fortigate-fields-v7">
  731. <parent>fortinet-fortigate-firewall</parent>
  732. <regex>\s+cpteid="(\.*)"|\s+cpteid=(\.*)\s|\s+cpteid=(\.*)$</regex>
  733. <order>cpteid</order>
  734. </decoder>
  735. <decoder name="fortinet-fortigate-fields-v7">
  736. <parent>fortinet-fortigate-firewall</parent>
  737. <regex>\s+cpu="(\.*)"|\s+cpu=(\.*)\s|\s+cpu=(\.*)$</regex>
  738. <order>cpu</order>
  739. </decoder>
  740. <decoder name="fortinet-fortigate-fields-v7">
  741. <parent>fortinet-fortigate-firewall</parent>
  742. <regex>\s+cpuladdr="(\.*)"|\s+cpuladdr=(\.*)\s|\s+cpuladdr=(\.*)$</regex>
  743. <order>cpuladdr</order>
  744. </decoder>
  745. <decoder name="fortinet-fortigate-fields-v7">
  746. <parent>fortinet-fortigate-firewall</parent>
  747. <regex>\s+cpulteid="(\.*)"|\s+cpulteid=(\.*)\s|\s+cpulteid=(\.*)$</regex>
  748. <order>cpulteid</order>
  749. </decoder>
  750. <decoder name="fortinet-fortigate-fields-v7">
  751. <parent>fortinet-fortigate-firewall</parent>
  752. <regex>\s+craction="(\.*)"|\s+craction=(\.*)\s|\s+craction=(\.*)$</regex>
  753. <order>craction</order>
  754. </decoder>
  755. <decoder name="fortinet-fortigate-fields-v7">
  756. <parent>fortinet-fortigate-firewall</parent>
  757. <regex>\s+created="(\.*)"|\s+created=(\.*)\s|\s+created=(\.*)$</regex>
  758. <order>created</order>
  759. </decoder>
  760. <decoder name="fortinet-fortigate-fields-v7">
  761. <parent>fortinet-fortigate-firewall</parent>
  762. <regex>\s+criticalcount="(\.*)"|\s+criticalcount=(\.*)\s|\s+criticalcount=(\.*)$</regex>
  763. <order>criticalcount</order>
  764. </decoder>
  765. <decoder name="fortinet-fortigate-fields-v7">
  766. <parent>fortinet-fortigate-firewall</parent>
  767. <regex>\s+crl="(\.*)"|\s+crl=(\.*)\s|\s+crl=(\.*)$</regex>
  768. <order>crl</order>
  769. </decoder>
  770. <decoder name="fortinet-fortigate-fields-v7">
  771. <parent>fortinet-fortigate-firewall</parent>
  772. <regex>\s+crlevel="(\.*)"|\s+crlevel=(\.*)\s|\s+crlevel=(\.*)$</regex>
  773. <order>crlevel</order>
  774. </decoder>
  775. <decoder name="fortinet-fortigate-fields-v7">
  776. <parent>fortinet-fortigate-firewall</parent>
  777. <regex>\s+crscore="(\.*)"|\s+crscore=(\.*)\s|\s+crscore=(\.*)$</regex>
  778. <order>crscore</order>
  779. </decoder>
  780. <decoder name="fortinet-fortigate-fields-v7">
  781. <parent>fortinet-fortigate-firewall</parent>
  782. <regex>\s+csgsn="(\.*)"|\s+csgsn=(\.*)\s|\s+csgsn=(\.*)$</regex>
  783. <order>csgsn</order>
  784. </decoder>
  785. <decoder name="fortinet-fortigate-fields-v7">
  786. <parent>fortinet-fortigate-firewall</parent>
  787. <regex>\s+cveid="(\.*)"|\s+cveid=(\.*)\s|\s+cveid=(\.*)$</regex>
  788. <order>cveid</order>
  789. </decoder>
  790. <decoder name="fortinet-fortigate-fields-v7">
  791. <parent>fortinet-fortigate-firewall</parent>
  792. <regex>\s+daddr="(\.*)"|\s+daddr=(\.*)\s|\s+daddr=(\.*)$</regex>
  793. <order>daddr</order>
  794. </decoder>
  795. <decoder name="fortinet-fortigate-fields-v7">
  796. <parent>fortinet-fortigate-firewall</parent>
  797. <regex>\s+daemon="(\.*)"|\s+daemon=(\.*)\s|\s+daemon=(\.*)$</regex>
  798. <order>daemon</order>
  799. </decoder>
  800. <decoder name="fortinet-fortigate-fields-v7">
  801. <parent>fortinet-fortigate-firewall</parent>
  802. <regex>\s+datarange="(\.*)"|\s+datarange=(\.*)\s|\s+datarange=(\.*)$</regex>
  803. <order>datarange</order>
  804. </decoder>
  805. <decoder name="fortinet-fortigate-fields-v7">
  806. <parent>fortinet-fortigate-firewall</parent>
  807. <regex>date="(\.*)"|date=(\.*)\s|date=(\.*)$</regex>
  808. <order>date</order>
  809. </decoder>
  810. <decoder name="fortinet-fortigate-fields-v7">
  811. <parent>fortinet-fortigate-firewall</parent>
  812. <regex>\s+ddnsserver="(\.*)"|\s+ddnsserver=(\.*)\s|\s+ddnsserver=(\.*)$</regex>
  813. <order>ddnsserver</order>
  814. </decoder>
  815. <decoder name="fortinet-fortigate-fields-v7">
  816. <parent>fortinet-fortigate-firewall</parent>
  817. <regex>\s+deny_cause="(\.*)"|\s+deny_cause=(\.*)\s|\s+deny_cause=(\.*)$</regex>
  818. <order>deny_cause</order>
  819. </decoder>
  820. <decoder name="fortinet-fortigate-fields-v7">
  821. <parent>fortinet-fortigate-firewall</parent>
  822. <regex>\s+desc="(\.*)"|\s+desc=(\.*)\s|\s+desc=(\.*)$</regex>
  823. <order>desc</order>
  824. </decoder>
  825. <decoder name="fortinet-fortigate-fields-v7">
  826. <parent>fortinet-fortigate-firewall</parent>
  827. <regex>\s+detectionmethod="(\.*)"|\s+detectionmethod=(\.*)\s|\s+detectionmethod=(\.*)$</regex>
  828. <order>detectionmethod</order>
  829. </decoder>
  830. <decoder name="fortinet-fortigate-fields-v7">
  831. <parent>fortinet-fortigate-firewall</parent>
  832. <regex>\s+devid="(\.*)"|\s+devid=(\.*)\s|\s+devid=(\.*)$</regex>
  833. <order>devid</order>
  834. </decoder>
  835. <decoder name="fortinet-fortigate-fields-v7">
  836. <parent>fortinet-fortigate-firewall</parent>
  837. <regex>\s+devintfname="(\.*)"|\s+devintfname=(\.*)\s|\s+devintfname=(\.*)$</regex>
  838. <order>devintfname</order>
  839. </decoder>
  840. <decoder name="fortinet-fortigate-fields-v7">
  841. <parent>fortinet-fortigate-firewall</parent>
  842. <regex>\s+devtype="(\.*)"|\s+devtype=(\.*)\s|\s+devtype=(\.*)$</regex>
  843. <order>devtype</order>
  844. </decoder>
  845. <decoder name="fortinet-fortigate-fields-v7">
  846. <parent>fortinet-fortigate-firewall</parent>
  847. <regex>\s+dhcp_msg="(\.*)"|\s+dhcp_msg=(\.*)\s|\s+dhcp_msg=(\.*)$</regex>
  848. <order>dhcp_msg</order>
  849. </decoder>
  850. <decoder name="fortinet-fortigate-fields-v7">
  851. <parent>fortinet-fortigate-firewall</parent>
  852. <regex>\s+dintf="(\.*)"|\s+dintf=(\.*)\s|\s+dintf=(\.*)$</regex>
  853. <order>dintf</order>
  854. </decoder>
  855. <decoder name="fortinet-fortigate-fields-v7">
  856. <parent>fortinet-fortigate-firewall</parent>
  857. <regex>\s+dir="(\.*)"|\s+dir=(\.*)\s|\s+dir=(\.*)$</regex>
  858. <order>dir</order>
  859. </decoder>
  860. <decoder name="fortinet-fortigate-fields-v7">
  861. <parent>fortinet-fortigate-firewall</parent>
  862. <regex>\s+direction="(\.*)"|\s+direction=(\.*)\s|\s+direction=(\.*)$</regex>
  863. <order>direction</order>
  864. </decoder>
  865. <decoder name="fortinet-fortigate-fields-v7">
  866. <parent>fortinet-fortigate-firewall</parent>
  867. <regex>\s+disk="(\.*)"|\s+disk=(\.*)\s|\s+disk=(\.*)$</regex>
  868. <order>disk</order>
  869. </decoder>
  870. <decoder name="fortinet-fortigate-fields-v7">
  871. <parent>fortinet-fortigate-firewall</parent>
  872. <regex>\s+disklograte="(\.*)"|\s+disklograte=(\.*)\s|\s+disklograte=(\.*)$</regex>
  873. <order>disklograte</order>
  874. </decoder>
  875. <decoder name="fortinet-fortigate-fields-v7">
  876. <parent>fortinet-fortigate-firewall</parent>
  877. <regex>\s+dlp="(\.*)"|\s+dlp=(\.*)\s|\s+dlp=(\.*)$</regex>
  878. <order>dlp</order>
  879. </decoder>
  880. <decoder name="fortinet-fortigate-fields-v7">
  881. <parent>fortinet-fortigate-firewall</parent>
  882. <regex>\s+dlpextra="(\.*)"|\s+dlpextra=(\.*)\s|\s+dlpextra=(\.*)$</regex>
  883. <order>dlpextra</order>
  884. </decoder>
  885. <decoder name="fortinet-fortigate-fields-v7">
  886. <parent>fortinet-fortigate-firewall</parent>
  887. <regex>\s+dns="(\.*)"|\s+dns=(\.*)\s|\s+dns=(\.*)$</regex>
  888. <order>dns</order>
  889. </decoder>
  890. <decoder name="fortinet-fortigate-fields-v7">
  891. <parent>fortinet-fortigate-firewall</parent>
  892. <regex>\s+docsource="(\.*)"|\s+docsource=(\.*)\s|\s+docsource=(\.*)$</regex>
  893. <order>docsource</order>
  894. </decoder>
  895. <decoder name="fortinet-fortigate-fields-v7">
  896. <parent>fortinet-fortigate-firewall</parent>
  897. <regex>\s+domainctrlauthstate="(\.*)"|\s+domainctrlauthstate=(\.*)\s|\s+domainctrlauthstate=(\.*)$</regex>
  898. <order>domainctrlauthstate</order>
  899. </decoder>
  900. <decoder name="fortinet-fortigate-fields-v7">
  901. <parent>fortinet-fortigate-firewall</parent>
  902. <regex>\s+domainctrlauthtype="(\.*)"|\s+domainctrlauthtype=(\.*)\s|\s+domainctrlauthtype=(\.*)$</regex>
  903. <order>domainctrlauthtype</order>
  904. </decoder>
  905. <decoder name="fortinet-fortigate-fields-v7">
  906. <parent>fortinet-fortigate-firewall</parent>
  907. <regex>\s+domainctrldomain="(\.*)"|\s+domainctrldomain=(\.*)\s|\s+domainctrldomain=(\.*)$</regex>
  908. <order>domainctrldomain</order>
  909. </decoder>
  910. <decoder name="fortinet-fortigate-fields-v7">
  911. <parent>fortinet-fortigate-firewall</parent>
  912. <regex>\s+domainctrlip="(\.*)"|\s+domainctrlip=(\.*)\s|\s+domainctrlip=(\.*)$</regex>
  913. <order>domainctrlip</order>
  914. </decoder>
  915. <decoder name="fortinet-fortigate-fields-v7">
  916. <parent>fortinet-fortigate-firewall</parent>
  917. <regex>\s+domainctrlname="(\.*)"|\s+domainctrlname=(\.*)\s|\s+domainctrlname=(\.*)$</regex>
  918. <order>domainctrlname</order>
  919. </decoder>
  920. <decoder name="fortinet-fortigate-fields-v7">
  921. <parent>fortinet-fortigate-firewall</parent>
  922. <regex>\s+domainctrlprotocoltype="(\.*)"|\s+domainctrlprotocoltype=(\.*)\s|\s+domainctrlprotocoltype=(\.*)$</regex>
  923. <order>domainctrlprotocoltype</order>
  924. </decoder>
  925. <decoder name="fortinet-fortigate-fields-v7">
  926. <parent>fortinet-fortigate-firewall</parent>
  927. <regex>\s+domainctrlusername="(\.*)"|\s+domainctrlusername=(\.*)\s|\s+domainctrlusername=(\.*)$</regex>
  928. <order>domainctrlusername</order>
  929. </decoder>
  930. <decoder name="fortinet-fortigate-fields-v7">
  931. <parent>fortinet-fortigate-firewall</parent>
  932. <regex>\s+domainfilteridx="(\.*)"|\s+domainfilteridx=(\.*)\s|\s+domainfilteridx=(\.*)$</regex>
  933. <order>domainfilteridx</order>
  934. </decoder>
  935. <decoder name="fortinet-fortigate-fields-v7">
  936. <parent>fortinet-fortigate-firewall</parent>
  937. <regex>\s+domainfilterlist="(\.*)"|\s+domainfilterlist=(\.*)\s|\s+domainfilterlist=(\.*)$</regex>
  938. <order>domainfilterlist</order>
  939. </decoder>
  940. <decoder name="fortinet-fortigate-fields-v7">
  941. <parent>fortinet-fortigate-firewall</parent>
  942. <regex>\s+downbandwidthmeasured="(\.*)"|\s+downbandwidthmeasured=(\.*)\s|\s+downbandwidthmeasured=(\.*)$</regex>
  943. <order>downbandwidthmeasured</order>
  944. </decoder>
  945. <decoder name="fortinet-fortigate-fields-v7">
  946. <parent>fortinet-fortigate-firewall</parent>
  947. <regex>\s+ds="(\.*)"|\s+ds=(\.*)\s|\s+ds=(\.*)$</regex>
  948. <order>ds</order>
  949. </decoder>
  950. <decoder name="fortinet-fortigate-fields-v7">
  951. <parent>fortinet-fortigate-firewall</parent>
  952. <regex>\s+dst_host="(\.*)"|\s+dst_host=(\.*)\s|\s+dst_host=(\.*)$</regex>
  953. <order>dst_host</order>
  954. </decoder>
  955. <decoder name="fortinet-fortigate-fields-v7">
  956. <parent>fortinet-fortigate-firewall</parent>
  957. <regex>\s+dst_int="(\.*)"|\s+dst_int=(\.*)\s|\s+dst_int=(\.*)$</regex>
  958. <order>dst_int</order>
  959. </decoder>
  960. <decoder name="fortinet-fortigate-fields-v7">
  961. <parent>fortinet-fortigate-firewall</parent>
  962. <regex>\s+dst_port="(\.*)"|\s+dst_port=(\.*)\s|\s+dst_port=(\.*)$</regex>
  963. <order>dst_port</order>
  964. </decoder>
  965. <decoder name="fortinet-fortigate-fields-v7">
  966. <parent>fortinet-fortigate-firewall</parent>
  967. <regex>\s+dstauthserver="(\.*)"|\s+dstauthserver=(\.*)\s|\s+dstauthserver=(\.*)$</regex>
  968. <order>dstauthserver</order>
  969. </decoder>
  970. <decoder name="fortinet-fortigate-fields-v7">
  971. <parent>fortinet-fortigate-firewall</parent>
  972. <regex>\s+dstcity="(\.*)"|\s+dstcity=(\.*)\s|\s+dstcity=(\.*)$</regex>
  973. <order>dstcity</order>
  974. </decoder>
  975. <decoder name="fortinet-fortigate-fields-v7">
  976. <parent>fortinet-fortigate-firewall</parent>
  977. <regex>\s+dstcountry="(\.*)"|\s+dstcountry=(\.*)\s|\s+dstcountry=(\.*)$</regex>
  978. <order>dstcountry</order>
  979. </decoder>
  980. <decoder name="fortinet-fortigate-fields-v7">
  981. <parent>fortinet-fortigate-firewall</parent>
  982. <regex>\s+dstdevtype="(\.*)"|\s+dstdevtype=(\.*)\s|\s+dstdevtype=(\.*)$</regex>
  983. <order>dstdevtype</order>
  984. </decoder>
  985. <decoder name="fortinet-fortigate-fields-v7">
  986. <parent>fortinet-fortigate-firewall</parent>
  987. <regex>\s+dstfamily="(\.*)"|\s+dstfamily=(\.*)\s|\s+dstfamily=(\.*)$</regex>
  988. <order>dstfamily</order>
  989. </decoder>
  990. <decoder name="fortinet-fortigate-fields-v7">
  991. <parent>fortinet-fortigate-firewall</parent>
  992. <regex>\s+dsthwvendor="(\.*)"|\s+dsthwvendor=(\.*)\s|\s+dsthwvendor=(\.*)$</regex>
  993. <order>dsthwvendor</order>
  994. </decoder>
  995. <decoder name="fortinet-fortigate-fields-v7">
  996. <parent>fortinet-fortigate-firewall</parent>
  997. <regex>\s+dsthwversion="(\.*)"|\s+dsthwversion=(\.*)\s|\s+dsthwversion=(\.*)$</regex>
  998. <order>dsthwversion</order>
  999. </decoder>
  1000. <decoder name="fortinet-fortigate-fields-v7">
  1001. <parent>fortinet-fortigate-firewall</parent>
  1002. <regex>\s+dstinetsvc="(\.*)"|\s+dstinetsvc=(\.*)\s|\s+dstinetsvc=(\.*)$</regex>
  1003. <order>dstinetsvc</order>
  1004. </decoder>
  1005. <decoder name="fortinet-fortigate-fields-v7">
  1006. <parent>fortinet-fortigate-firewall</parent>
  1007. <regex>\s+dstintf="(\.*)"|\s+dstintf=(\.*)\s|\s+dstintf=(\.*)$</regex>
  1008. <order>dstintf</order>
  1009. </decoder>
  1010. <decoder name="fortinet-fortigate-fields-v7">
  1011. <parent>fortinet-fortigate-firewall</parent>
  1012. <regex>\s+dstintfrole="(\.*)"|\s+dstintfrole=(\.*)\s|\s+dstintfrole=(\.*)$</regex>
  1013. <order>dstintfrole</order>
  1014. </decoder>
  1015. <decoder name="fortinet-fortigate-fields-v7">
  1016. <parent>fortinet-fortigate-firewall</parent>
  1017. <regex>\s+dstip="(\.*)"|\s+dstip=(\.*)\s|\s+dstip=(\.*)$</regex>
  1018. <order>dstip</order>
  1019. </decoder>
  1020. <decoder name="fortinet-fortigate-fields-v7">
  1021. <parent>fortinet-fortigate-firewall</parent>
  1022. <regex>\s+dstmac="(\.*)"|\s+dstmac=(\.*)\s|\s+dstmac=(\.*)$</regex>
  1023. <order>dstmac</order>
  1024. </decoder>
  1025. <decoder name="fortinet-fortigate-fields-v7">
  1026. <parent>fortinet-fortigate-firewall</parent>
  1027. <regex>\s+dstname="(\.*)"|\s+dstname=(\.*)\s|\s+dstname=(\.*)$</regex>
  1028. <order>dstname</order>
  1029. </decoder>
  1030. <decoder name="fortinet-fortigate-fields-v7">
  1031. <parent>fortinet-fortigate-firewall</parent>
  1032. <regex>\s+dstosname="(\.*)"|\s+dstosname=(\.*)\s|\s+dstosname=(\.*)$</regex>
  1033. <order>dstosname</order>
  1034. </decoder>
  1035. <decoder name="fortinet-fortigate-fields-v7">
  1036. <parent>fortinet-fortigate-firewall</parent>
  1037. <regex>\s+dstport="(\.*)"|\s+dstport=(\.*)\s|\s+dstport=(\.*)$</regex>
  1038. <order>dstport</order>
  1039. </decoder>
  1040. <decoder name="fortinet-fortigate-fields-v7">
  1041. <parent>fortinet-fortigate-firewall</parent>
  1042. <regex>\s+dstregion="(\.*)"|\s+dstregion=(\.*)\s|\s+dstregion=(\.*)$</regex>
  1043. <order>dstregion</order>
  1044. </decoder>
  1045. <decoder name="fortinet-fortigate-fields-v7">
  1046. <parent>fortinet-fortigate-firewall</parent>
  1047. <regex>\s+dstreputation="(\.*)"|\s+dstreputation=(\.*)\s|\s+dstreputation=(\.*)$</regex>
  1048. <order>dstreputation</order>
  1049. </decoder>
  1050. <decoder name="fortinet-fortigate-fields-v7">
  1051. <parent>fortinet-fortigate-firewall</parent>
  1052. <regex>\s+dstserver="(\.*)"|\s+dstserver=(\.*)\s|\s+dstserver=(\.*)$</regex>
  1053. <order>dstserver</order>
  1054. </decoder>
  1055. <decoder name="fortinet-fortigate-fields-v7">
  1056. <parent>fortinet-fortigate-firewall</parent>
  1057. <regex>\s+dstssid="(\.*)"|\s+dstssid=(\.*)\s|\s+dstssid=(\.*)$</regex>
  1058. <order>dstssid</order>
  1059. </decoder>
  1060. <decoder name="fortinet-fortigate-fields-v7">
  1061. <parent>fortinet-fortigate-firewall</parent>
  1062. <regex>\s+dstswversion="(\.*)"|\s+dstswversion=(\.*)\s|\s+dstswversion=(\.*)$</regex>
  1063. <order>dstswversion</order>
  1064. </decoder>
  1065. <decoder name="fortinet-fortigate-fields-v7">
  1066. <parent>fortinet-fortigate-firewall</parent>
  1067. <regex>\s+dstthreatfeed="(\.*)"|\s+dstthreatfeed=(\.*)\s|\s+dstthreatfeed=(\.*)$</regex>
  1068. <order>dstthreatfeed</order>
  1069. </decoder>
  1070. <decoder name="fortinet-fortigate-fields-v7">
  1071. <parent>fortinet-fortigate-firewall</parent>
  1072. <regex>\s+dstunauthuser="(\.*)"|\s+dstunauthuser=(\.*)\s|\s+dstunauthuser=(\.*)$</regex>
  1073. <order>dstunauthuser</order>
  1074. </decoder>
  1075. <decoder name="fortinet-fortigate-fields-v7">
  1076. <parent>fortinet-fortigate-firewall</parent>
  1077. <regex>\s+dstunauthusersource="(\.*)"|\s+dstunauthusersource=(\.*)\s|\s+dstunauthusersource=(\.*)$</regex>
  1078. <order>dstunauthusersource</order>
  1079. </decoder>
  1080. <decoder name="fortinet-fortigate-fields-v7">
  1081. <parent>fortinet-fortigate-firewall</parent>
  1082. <regex>\s+dstuser="(\.*)"|\s+dstuser=(\.*)\s|\s+dstuser=(\.*)$</regex>
  1083. <order>dstuser</order>
  1084. </decoder>
  1085. <decoder name="fortinet-fortigate-fields-v7">
  1086. <parent>fortinet-fortigate-firewall</parent>
  1087. <regex>\s+dstuuid="(\.*)"|\s+dstuuid=(\.*)\s|\s+dstuuid=(\.*)$</regex>
  1088. <order>dstuuid</order>
  1089. </decoder>
  1090. <decoder name="fortinet-fortigate-fields-v7">
  1091. <parent>fortinet-fortigate-firewall</parent>
  1092. <regex>\s+dtlexp="(\.*)"|\s+dtlexp=(\.*)\s|\s+dtlexp=(\.*)$</regex>
  1093. <order>dtlexp</order>
  1094. </decoder>
  1095. <decoder name="fortinet-fortigate-fields-v7">
  1096. <parent>fortinet-fortigate-firewall</parent>
  1097. <regex>\s+dtype="(\.*)"|\s+dtype=(\.*)\s|\s+dtype=(\.*)$</regex>
  1098. <order>dtype</order>
  1099. </decoder>
  1100. <decoder name="fortinet-fortigate-fields-v7">
  1101. <parent>fortinet-fortigate-firewall</parent>
  1102. <regex>\s+duid="(\.*)"|\s+duid=(\.*)\s|\s+duid=(\.*)$</regex>
  1103. <order>duid</order>
  1104. </decoder>
  1105. <decoder name="fortinet-fortigate-fields-v7">
  1106. <parent>fortinet-fortigate-firewall</parent>
  1107. <regex>\s+duration="(\.*)"|\s+duration=(\.*)\s|\s+duration=(\.*)$</regex>
  1108. <order>duration</order>
  1109. </decoder>
  1110. <decoder name="fortinet-fortigate-fields-v7">
  1111. <parent>fortinet-fortigate-firewall</parent>
  1112. <regex>\s+durationdelta="(\.*)"|\s+durationdelta=(\.*)\s|\s+durationdelta=(\.*)$</regex>
  1113. <order>durationdelta</order>
  1114. </decoder>
  1115. <decoder name="fortinet-fortigate-fields-v7">
  1116. <parent>fortinet-fortigate-firewall</parent>
  1117. <regex>\s+eapolcnt="(\.*)"|\s+eapolcnt=(\.*)\s|\s+eapolcnt=(\.*)$</regex>
  1118. <order>eapolcnt</order>
  1119. </decoder>
  1120. <decoder name="fortinet-fortigate-fields-v7">
  1121. <parent>fortinet-fortigate-firewall</parent>
  1122. <regex>\s+eapoltype="(\.*)"|\s+eapoltype=(\.*)\s|\s+eapoltype=(\.*)$</regex>
  1123. <order>eapoltype</order>
  1124. </decoder>
  1125. <decoder name="fortinet-fortigate-fields-v7">
  1126. <parent>fortinet-fortigate-firewall</parent>
  1127. <regex>\s+emailfilter="(\.*)"|\s+emailfilter=(\.*)\s|\s+emailfilter=(\.*)$</regex>
  1128. <order>emailfilter</order>
  1129. </decoder>
  1130. <decoder name="fortinet-fortigate-fields-v7">
  1131. <parent>fortinet-fortigate-firewall</parent>
  1132. <regex>\s+emsconnection="(\.*)"|\s+emsconnection=(\.*)\s|\s+emsconnection=(\.*)$</regex>
  1133. <order>emsconnection</order>
  1134. </decoder>
  1135. <decoder name="fortinet-fortigate-fields-v7">
  1136. <parent>fortinet-fortigate-firewall</parent>
  1137. <regex>\s+encrypt="(\.*)"|\s+encrypt=(\.*)\s|\s+encrypt=(\.*)$</regex>
  1138. <order>encrypt</order>
  1139. </decoder>
  1140. <decoder name="fortinet-fortigate-fields-v7">
  1141. <parent>fortinet-fortigate-firewall</parent>
  1142. <regex>\s+encryption="(\.*)"|\s+encryption=(\.*)\s|\s+encryption=(\.*)$</regex>
  1143. <order>encryption</order>
  1144. </decoder>
  1145. <decoder name="fortinet-fortigate-fields-v7">
  1146. <parent>fortinet-fortigate-firewall</parent>
  1147. <regex>\s+end="(\.*)"|\s+end=(\.*)\s|\s+end=(\.*)$</regex>
  1148. <order>end</order>
  1149. </decoder>
  1150. <decoder name="fortinet-fortigate-fields-v7">
  1151. <parent>fortinet-fortigate-firewall</parent>
  1152. <regex>\s+endusraddress="(\.*)"|\s+endusraddress=(\.*)\s|\s+endusraddress=(\.*)$</regex>
  1153. <order>endusraddress</order>
  1154. </decoder>
  1155. <decoder name="fortinet-fortigate-fields-v7">
  1156. <parent>fortinet-fortigate-firewall</parent>
  1157. <regex>\s+epoch="(\.*)"|\s+epoch=(\.*)\s|\s+epoch=(\.*)$</regex>
  1158. <order>epoch</order>
  1159. </decoder>
  1160. <decoder name="fortinet-fortigate-fields-v7">
  1161. <parent>fortinet-fortigate-firewall</parent>
  1162. <regex>\s+error="(\.*)"|\s+error=(\.*)\s|\s+error=(\.*)$</regex>
  1163. <order>error</order>
  1164. </decoder>
  1165. <decoder name="fortinet-fortigate-fields-v7">
  1166. <parent>fortinet-fortigate-firewall</parent>
  1167. <regex>\s+error_num="(\.*)"|\s+error_num=(\.*)\s|\s+error_num=(\.*)$</regex>
  1168. <order>error_num</order>
  1169. </decoder>
  1170. <decoder name="fortinet-fortigate-fields-v7">
  1171. <parent>fortinet-fortigate-firewall</parent>
  1172. <regex>\s+errorcount="(\.*)"|\s+errorcount=(\.*)\s|\s+errorcount=(\.*)$</regex>
  1173. <order>errorcount</order>
  1174. </decoder>
  1175. <decoder name="fortinet-fortigate-fields-v7">
  1176. <parent>fortinet-fortigate-firewall</parent>
  1177. <regex>\s+espauth="(\.*)"|\s+espauth=(\.*)\s|\s+espauth=(\.*)$</regex>
  1178. <order>espauth</order>
  1179. </decoder>
  1180. <decoder name="fortinet-fortigate-fields-v7">
  1181. <parent>fortinet-fortigate-firewall</parent>
  1182. <regex>\s+esptransform="(\.*)"|\s+esptransform=(\.*)\s|\s+esptransform=(\.*)$</regex>
  1183. <order>esptransform</order>
  1184. </decoder>
  1185. <decoder name="fortinet-fortigate-fields-v7">
  1186. <parent>fortinet-fortigate-firewall</parent>
  1187. <regex>\s+event="(\.*)"|\s+event=(\.*)\s|\s+event=(\.*)$</regex>
  1188. <order>event</order>
  1189. </decoder>
  1190. <decoder name="fortinet-fortigate-fields-v7">
  1191. <parent>fortinet-fortigate-firewall</parent>
  1192. <regex>\s+event_id="(\.*)"|\s+event_id=(\.*)\s|\s+event_id=(\.*)$</regex>
  1193. <order>event_id</order>
  1194. </decoder>
  1195. <decoder name="fortinet-fortigate-fields-v7">
  1196. <parent>fortinet-fortigate-firewall</parent>
  1197. <regex>\s+eventid="(\.*)"|\s+eventid=(\.*)\s|\s+eventid=(\.*)$</regex>
  1198. <order>eventid</order>
  1199. </decoder>
  1200. <decoder name="fortinet-fortigate-fields-v7">
  1201. <parent>fortinet-fortigate-firewall</parent>
  1202. <regex>\s+eventsubtype="(\.*)"|\s+eventsubtype=(\.*)\s|\s+eventsubtype=(\.*)$</regex>
  1203. <order>eventsubtype</order>
  1204. </decoder>
  1205. <decoder name="fortinet-fortigate-fields-v7">
  1206. <parent>fortinet-fortigate-firewall</parent>
  1207. <regex>\s+eventtime="(\.*)"|\s+eventtime=(\.*)\s|\s+eventtime=(\.*)$</regex>
  1208. <order>eventtime</order>
  1209. </decoder>
  1210. <decoder name="fortinet-fortigate-fields-v7">
  1211. <parent>fortinet-fortigate-firewall</parent>
  1212. <regex>\s+eventtype="(\.*)"|\s+eventtype=(\.*)\s|\s+eventtype=(\.*)$</regex>
  1213. <order>eventtype</order>
  1214. </decoder>
  1215. <decoder name="fortinet-fortigate-fields-v7">
  1216. <parent>fortinet-fortigate-firewall</parent>
  1217. <regex>\s+exch="(\.*)"|\s+exch=(\.*)\s|\s+exch=(\.*)$</regex>
  1218. <order>exch</order>
  1219. </decoder>
  1220. <decoder name="fortinet-fortigate-fields-v7">
  1221. <parent>fortinet-fortigate-firewall</parent>
  1222. <regex>\s+exchange="(\.*)"|\s+exchange=(\.*)\s|\s+exchange=(\.*)$</regex>
  1223. <order>exchange</order>
  1224. </decoder>
  1225. <decoder name="fortinet-fortigate-fields-v7">
  1226. <parent>fortinet-fortigate-firewall</parent>
  1227. <regex>\s+expectedsignature="(\.*)"|\s+expectedsignature=(\.*)\s|\s+expectedsignature=(\.*)$</regex>
  1228. <order>expectedsignature</order>
  1229. </decoder>
  1230. <decoder name="fortinet-fortigate-fields-v7">
  1231. <parent>fortinet-fortigate-firewall</parent>
  1232. <regex>\s+expiry="(\.*)"|\s+expiry=(\.*)\s|\s+expiry=(\.*)$</regex>
  1233. <order>expiry</order>
  1234. </decoder>
  1235. <decoder name="fortinet-fortigate-fields-v7">
  1236. <parent>fortinet-fortigate-firewall</parent>
  1237. <regex>\s+extension="(\.*)"|\s+extension=(\.*)\s|\s+extension=(\.*)$</regex>
  1238. <order>extension</order>
  1239. </decoder>
  1240. <decoder name="fortinet-fortigate-fields-v7">
  1241. <parent>fortinet-fortigate-firewall</parent>
  1242. <regex>\s+faiaction="(\.*)"|\s+faiaction=(\.*)\s|\s+faiaction=(\.*)$</regex>
  1243. <order>faiaction</order>
  1244. </decoder>
  1245. <decoder name="fortinet-fortigate-fields-v7">
  1246. <parent>fortinet-fortigate-firewall</parent>
  1247. <regex>\s+faiconfidence="(\.*)"|\s+faiconfidence=(\.*)\s|\s+faiconfidence=(\.*)$</regex>
  1248. <order>faiconfidence</order>
  1249. </decoder>
  1250. <decoder name="fortinet-fortigate-fields-v7">
  1251. <parent>fortinet-fortigate-firewall</parent>
  1252. <regex>\s+faifileid="(\.*)"|\s+faifileid=(\.*)\s|\s+faifileid=(\.*)$</regex>
  1253. <order>faifileid</order>
  1254. </decoder>
  1255. <decoder name="fortinet-fortigate-fields-v7">
  1256. <parent>fortinet-fortigate-firewall</parent>
  1257. <regex>\s+faifiletype="(\.*)"|\s+faifiletype=(\.*)\s|\s+faifiletype=(\.*)$</regex>
  1258. <order>faifiletype</order>
  1259. </decoder>
  1260. <decoder name="fortinet-fortigate-fields-v7">
  1261. <parent>fortinet-fortigate-firewall</parent>
  1262. <regex>\s+failuredev="(\.*)"|\s+failuredev=(\.*)\s|\s+failuredev=(\.*)$</regex>
  1263. <order>failuredev</order>
  1264. </decoder>
  1265. <decoder name="fortinet-fortigate-fields-v7">
  1266. <parent>fortinet-fortigate-firewall</parent>
  1267. <regex>\s+faiseverity="(\.*)"|\s+faiseverity=(\.*)\s|\s+faiseverity=(\.*)$</regex>
  1268. <order>faiseverity</order>
  1269. </decoder>
  1270. <decoder name="fortinet-fortigate-fields-v7">
  1271. <parent>fortinet-fortigate-firewall</parent>
  1272. <regex>\s+fams_pause="(\.*)"|\s+fams_pause=(\.*)\s|\s+fams_pause=(\.*)$</regex>
  1273. <order>fams_pause</order>
  1274. </decoder>
  1275. <decoder name="fortinet-fortigate-fields-v7">
  1276. <parent>fortinet-fortigate-firewall</parent>
  1277. <regex>\s+fazlograte="(\.*)"|\s+fazlograte=(\.*)\s|\s+fazlograte=(\.*)$</regex>
  1278. <order>fazlograte</order>
  1279. </decoder>
  1280. <decoder name="fortinet-fortigate-fields-v7">
  1281. <parent>fortinet-fortigate-firewall</parent>
  1282. <regex>\s+fctemsname="(\.*)"|\s+fctemsname=(\.*)\s|\s+fctemsname=(\.*)$</regex>
  1283. <order>fctemsname</order>
  1284. </decoder>
  1285. <decoder name="fortinet-fortigate-fields-v7">
  1286. <parent>fortinet-fortigate-firewall</parent>
  1287. <regex>\s+fctemssn="(\.*)"|\s+fctemssn=(\.*)\s|\s+fctemssn=(\.*)$</regex>
  1288. <order>fctemssn</order>
  1289. </decoder>
  1290. <decoder name="fortinet-fortigate-fields-v7">
  1291. <parent>fortinet-fortigate-firewall</parent>
  1292. <regex>\s+fctuid="(\.*)"|\s+fctuid=(\.*)\s|\s+fctuid=(\.*)$</regex>
  1293. <order>fctuid</order>
  1294. </decoder>
  1295. <decoder name="fortinet-fortigate-fields-v7">
  1296. <parent>fortinet-fortigate-firewall</parent>
  1297. <regex>\s+field="(\.*)"|\s+field=(\.*)\s|\s+field=(\.*)$</regex>
  1298. <order>field</order>
  1299. </decoder>
  1300. <decoder name="fortinet-fortigate-fields-v7">
  1301. <parent>fortinet-fortigate-firewall</parent>
  1302. <regex>\s+file="(\.*)"|\s+file=(\.*)\s|\s+file=(\.*)$</regex>
  1303. <order>file</order>
  1304. </decoder>
  1305. <decoder name="fortinet-fortigate-fields-v7">
  1306. <parent>fortinet-fortigate-firewall</parent>
  1307. <regex>\s+filefilter="(\.*)"|\s+filefilter=(\.*)\s|\s+filefilter=(\.*)$</regex>
  1308. <order>filefilter</order>
  1309. </decoder>
  1310. <decoder name="fortinet-fortigate-fields-v7">
  1311. <parent>fortinet-fortigate-firewall</parent>
  1312. <regex>\s+filehash="(\.*)"|\s+filehash=(\.*)\s|\s+filehash=(\.*)$</regex>
  1313. <order>filehash</order>
  1314. </decoder>
  1315. <decoder name="fortinet-fortigate-fields-v7">
  1316. <parent>fortinet-fortigate-firewall</parent>
  1317. <regex>\s+filehashsrc="(\.*)"|\s+filehashsrc=(\.*)\s|\s+filehashsrc=(\.*)$</regex>
  1318. <order>filehashsrc</order>
  1319. </decoder>
  1320. <decoder name="fortinet-fortigate-fields-v7">
  1321. <parent>fortinet-fortigate-firewall</parent>
  1322. <regex>\s+filename="(\.*)"|\s+filename=(\.*)\s|\s+filename=(\.*)$</regex>
  1323. <order>filename</order>
  1324. </decoder>
  1325. <decoder name="fortinet-fortigate-fields-v7">
  1326. <parent>fortinet-fortigate-firewall</parent>
  1327. <regex>\s+filesize="(\.*)"|\s+filesize=(\.*)\s|\s+filesize=(\.*)$</regex>
  1328. <order>filesize</order>
  1329. </decoder>
  1330. <decoder name="fortinet-fortigate-fields-v7">
  1331. <parent>fortinet-fortigate-firewall</parent>
  1332. <regex>\s+filetype="(\.*)"|\s+filetype=(\.*)\s|\s+filetype=(\.*)$</regex>
  1333. <order>filetype</order>
  1334. </decoder>
  1335. <decoder name="fortinet-fortigate-fields-v7">
  1336. <parent>fortinet-fortigate-firewall</parent>
  1337. <regex>\s+filtercat="(\.*)"|\s+filtercat=(\.*)\s|\s+filtercat=(\.*)$</regex>
  1338. <order>filtercat</order>
  1339. </decoder>
  1340. <decoder name="fortinet-fortigate-fields-v7">
  1341. <parent>fortinet-fortigate-firewall</parent>
  1342. <regex>\s+filteridx="(\.*)"|\s+filteridx=(\.*)\s|\s+filteridx=(\.*)$</regex>
  1343. <order>filteridx</order>
  1344. </decoder>
  1345. <decoder name="fortinet-fortigate-fields-v7">
  1346. <parent>fortinet-fortigate-firewall</parent>
  1347. <regex>\s+filtername="(\.*)"|\s+filtername=(\.*)\s|\s+filtername=(\.*)$</regex>
  1348. <order>filtername</order>
  1349. </decoder>
  1350. <decoder name="fortinet-fortigate-fields-v7">
  1351. <parent>fortinet-fortigate-firewall</parent>
  1352. <regex>\s+filtertype="(\.*)"|\s+filtertype=(\.*)\s|\s+filtertype=(\.*)$</regex>
  1353. <order>filtertype</order>
  1354. </decoder>
  1355. <decoder name="fortinet-fortigate-fields-v7">
  1356. <parent>fortinet-fortigate-firewall</parent>
  1357. <regex>\s+fndraction="(\.*)"|\s+fndraction=(\.*)\s|\s+fndraction=(\.*)$</regex>
  1358. <order>fndraction</order>
  1359. </decoder>
  1360. <decoder name="fortinet-fortigate-fields-v7">
  1361. <parent>fortinet-fortigate-firewall</parent>
  1362. <regex>\s+fndrconfidence="(\.*)"|\s+fndrconfidence=(\.*)\s|\s+fndrconfidence=(\.*)$</regex>
  1363. <order>fndrconfidence</order>
  1364. </decoder>
  1365. <decoder name="fortinet-fortigate-fields-v7">
  1366. <parent>fortinet-fortigate-firewall</parent>
  1367. <regex>\s+fndrfileid="(\.*)"|\s+fndrfileid=(\.*)\s|\s+fndrfileid=(\.*)$</regex>
  1368. <order>fndrfileid</order>
  1369. </decoder>
  1370. <decoder name="fortinet-fortigate-fields-v7">
  1371. <parent>fortinet-fortigate-firewall</parent>
  1372. <regex>\s+fndrfiletype="(\.*)"|\s+fndrfiletype=(\.*)\s|\s+fndrfiletype=(\.*)$</regex>
  1373. <order>fndrfiletype</order>
  1374. </decoder>
  1375. <decoder name="fortinet-fortigate-fields-v7">
  1376. <parent>fortinet-fortigate-firewall</parent>
  1377. <regex>\s+fndrseverity="(\.*)"|\s+fndrseverity=(\.*)\s|\s+fndrseverity=(\.*)$</regex>
  1378. <order>fndrseverity</order>
  1379. </decoder>
  1380. <decoder name="fortinet-fortigate-fields-v7">
  1381. <parent>fortinet-fortigate-firewall</parent>
  1382. <regex>\s+fndrverdict="(\.*)"|\s+fndrverdict=(\.*)\s|\s+fndrverdict=(\.*)$</regex>
  1383. <order>fndrverdict</order>
  1384. </decoder>
  1385. <decoder name="fortinet-fortigate-fields-v7">
  1386. <parent>fortinet-fortigate-firewall</parent>
  1387. <regex>\s+forti="(\.*)"|\s+forti=(\.*)\s|\s+forti=(\.*)$</regex>
  1388. <order>forti</order>
  1389. </decoder>
  1390. <decoder name="fortinet-fortigate-fields-v7">
  1391. <parent>fortinet-fortigate-firewall</parent>
  1392. <regex>\s+fortiguardresp="(\.*)"|\s+fortiguardresp=(\.*)\s|\s+fortiguardresp=(\.*)$</regex>
  1393. <order>fortiguardresp</order>
  1394. </decoder>
  1395. <decoder name="fortinet-fortigate-fields-v7">
  1396. <parent>fortinet-fortigate-firewall</parent>
  1397. <regex>\s+forwardedfor="(\.*)"|\s+forwardedfor=(\.*)\s|\s+forwardedfor=(\.*)$</regex>
  1398. <order>forwardedfor</order>
  1399. </decoder>
  1400. <decoder name="fortinet-fortigate-fields-v7">
  1401. <parent>fortinet-fortigate-firewall</parent>
  1402. <regex>\s+fqdn="(\.*)"|\s+fqdn=(\.*)\s|\s+fqdn=(\.*)$</regex>
  1403. <order>fqdn</order>
  1404. </decoder>
  1405. <decoder name="fortinet-fortigate-fields-v7">
  1406. <parent>fortinet-fortigate-firewall</parent>
  1407. <regex>\s+frametype="(\.*)"|\s+frametype=(\.*)\s|\s+frametype=(\.*)$</regex>
  1408. <order>frametype</order>
  1409. </decoder>
  1410. <decoder name="fortinet-fortigate-fields-v7">
  1411. <parent>fortinet-fortigate-firewall</parent>
  1412. <regex>\s+freediskstorage="(\.*)"|\s+freediskstorage=(\.*)\s|\s+freediskstorage=(\.*)$</regex>
  1413. <order>freediskstorage</order>
  1414. </decoder>
  1415. <decoder name="fortinet-fortigate-fields-v7">
  1416. <parent>fortinet-fortigate-firewall</parent>
  1417. <regex>\s+from="(\.*)"|\s+from=(\.*)\s|\s+from=(\.*)$</regex>
  1418. <order>from</order>
  1419. </decoder>
  1420. <decoder name="fortinet-fortigate-fields-v7">
  1421. <parent>fortinet-fortigate-firewall</parent>
  1422. <regex>\s+from_vcluster="(\.*)"|\s+from_vcluster=(\.*)\s|\s+from_vcluster=(\.*)$</regex>
  1423. <order>from_vcluster</order>
  1424. </decoder>
  1425. <decoder name="fortinet-fortigate-fields-v7">
  1426. <parent>fortinet-fortigate-firewall</parent>
  1427. <regex>\s+fsaaction="(\.*)"|\s+fsaaction=(\.*)\s|\s+fsaaction=(\.*)$</regex>
  1428. <order>fsaaction</order>
  1429. </decoder>
  1430. <decoder name="fortinet-fortigate-fields-v7">
  1431. <parent>fortinet-fortigate-firewall</parent>
  1432. <regex>\s+fsafileid="(\.*)"|\s+fsafileid=(\.*)\s|\s+fsafileid=(\.*)$</regex>
  1433. <order>fsafileid</order>
  1434. </decoder>
  1435. <decoder name="fortinet-fortigate-fields-v7">
  1436. <parent>fortinet-fortigate-firewall</parent>
  1437. <regex>\s+fsafiletype="(\.*)"|\s+fsafiletype=(\.*)\s|\s+fsafiletype=(\.*)$</regex>
  1438. <order>fsafiletype</order>
  1439. </decoder>
  1440. <decoder name="fortinet-fortigate-fields-v7">
  1441. <parent>fortinet-fortigate-firewall</parent>
  1442. <regex>\s+fsaseverity="(\.*)"|\s+fsaseverity=(\.*)\s|\s+fsaseverity=(\.*)$</regex>
  1443. <order>fsaseverity</order>
  1444. </decoder>
  1445. <decoder name="fortinet-fortigate-fields-v7">
  1446. <parent>fortinet-fortigate-firewall</parent>
  1447. <regex>\s+fsaverdict="(\.*)"|\s+fsaverdict=(\.*)\s|\s+fsaverdict=(\.*)$</regex>
  1448. <order>fsaverdict</order>
  1449. </decoder>
  1450. <decoder name="fortinet-fortigate-fields-v7">
  1451. <parent>fortinet-fortigate-firewall</parent>
  1452. <regex>\s+ftlkintf="(\.*)"|\s+ftlkintf=(\.*)\s|\s+ftlkintf=(\.*)$</regex>
  1453. <order>ftlkintf</order>
  1454. </decoder>
  1455. <decoder name="fortinet-fortigate-fields-v7">
  1456. <parent>fortinet-fortigate-firewall</parent>
  1457. <regex>\s+fwdsrv="(\.*)"|\s+fwdsrv=(\.*)\s|\s+fwdsrv=(\.*)$</regex>
  1458. <order>fwdsrv</order>
  1459. </decoder>
  1460. <decoder name="fortinet-fortigate-fields-v7">
  1461. <parent>fortinet-fortigate-firewall</parent>
  1462. <regex>\s+fwserver_name="(\.*)"|\s+fwserver_name=(\.*)\s|\s+fwserver_name=(\.*)$</regex>
  1463. <order>fwserver_name</order>
  1464. </decoder>
  1465. <decoder name="fortinet-fortigate-fields-v7">
  1466. <parent>fortinet-fortigate-firewall</parent>
  1467. <regex>\s+gateway="(\.*)"|\s+gateway=(\.*)\s|\s+gateway=(\.*)$</regex>
  1468. <order>gateway</order>
  1469. </decoder>
  1470. <decoder name="fortinet-fortigate-fields-v7">
  1471. <parent>fortinet-fortigate-firewall</parent>
  1472. <regex>\s+gatewayid="(\.*)"|\s+gatewayid=(\.*)\s|\s+gatewayid=(\.*)$</regex>
  1473. <order>gatewayid</order>
  1474. </decoder>
  1475. <decoder name="fortinet-fortigate-fields-v7">
  1476. <parent>fortinet-fortigate-firewall</parent>
  1477. <regex>\s+green="(\.*)"|\s+green=(\.*)\s|\s+green=(\.*)$</regex>
  1478. <order>green</order>
  1479. </decoder>
  1480. <decoder name="fortinet-fortigate-fields-v7">
  1481. <parent>fortinet-fortigate-firewall</parent>
  1482. <regex>\s+group="(\.*)"|\s+group=(\.*)\s|\s+group=(\.*)$</regex>
  1483. <order>group</order>
  1484. </decoder>
  1485. <decoder name="fortinet-fortigate-fields-v7">
  1486. <parent>fortinet-fortigate-firewall</parent>
  1487. <regex>\s+groupid="(\.*)"|\s+groupid=(\.*)\s|\s+groupid=(\.*)$</regex>
  1488. <order>groupid</order>
  1489. </decoder>
  1490. <decoder name="fortinet-fortigate-fields-v7">
  1491. <parent>fortinet-fortigate-firewall</parent>
  1492. <regex>\s+gtp="(\.*)"|\s+gtp=(\.*)\s|\s+gtp=(\.*)$</regex>
  1493. <order>gtp</order>
  1494. </decoder>
  1495. <decoder name="fortinet-fortigate-fields-v7">
  1496. <parent>fortinet-fortigate-firewall</parent>
  1497. <regex>\s+ha="(\.*)"|\s+ha=(\.*)\s|\s+ha=(\.*)$</regex>
  1498. <order>ha</order>
  1499. </decoder>
  1500. <decoder name="fortinet-fortigate-fields-v7">
  1501. <parent>fortinet-fortigate-firewall</parent>
  1502. <regex>\s+ha_group="(\.*)"|\s+ha_group=(\.*)\s|\s+ha_group=(\.*)$</regex>
  1503. <order>ha_group</order>
  1504. </decoder>
  1505. <decoder name="fortinet-fortigate-fields-v7">
  1506. <parent>fortinet-fortigate-firewall</parent>
  1507. <regex>\s+ha_role="(\.*)"|\s+ha_role=(\.*)\s|\s+ha_role=(\.*)$</regex>
  1508. <order>ha_role</order>
  1509. </decoder>
  1510. <decoder name="fortinet-fortigate-fields-v7">
  1511. <parent>fortinet-fortigate-firewall</parent>
  1512. <regex>\s+handshake="(\.*)"|\s+handshake=(\.*)\s|\s+handshake=(\.*)$</regex>
  1513. <order>handshake</order>
  1514. </decoder>
  1515. <decoder name="fortinet-fortigate-fields-v7">
  1516. <parent>fortinet-fortigate-firewall</parent>
  1517. <regex>\s+headerteid="(\.*)"|\s+headerteid=(\.*)\s|\s+headerteid=(\.*)$</regex>
  1518. <order>headerteid</order>
  1519. </decoder>
  1520. <decoder name="fortinet-fortigate-fields-v7">
  1521. <parent>fortinet-fortigate-firewall</parent>
  1522. <regex>\s+healthcheck="(\.*)"|\s+healthcheck=(\.*)\s|\s+healthcheck=(\.*)$</regex>
  1523. <order>healthcheck</order>
  1524. </decoder>
  1525. <decoder name="fortinet-fortigate-fields-v7">
  1526. <parent>fortinet-fortigate-firewall</parent>
  1527. <regex>\s+highcount="(\.*)"|\s+highcount=(\.*)\s|\s+highcount=(\.*)$</regex>
  1528. <order>highcount</order>
  1529. </decoder>
  1530. <decoder name="fortinet-fortigate-fields-v7">
  1531. <parent>fortinet-fortigate-firewall</parent>
  1532. <regex>\s+host="(\.*)"|\s+host=(\.*)\s|\s+host=(\.*)$</regex>
  1533. <order>host</order>
  1534. </decoder>
  1535. <decoder name="fortinet-fortigate-fields-v7">
  1536. <parent>fortinet-fortigate-firewall</parent>
  1537. <regex>\s+hostkeystatus="(\.*)"|\s+hostkeystatus=(\.*)\s|\s+hostkeystatus=(\.*)$</regex>
  1538. <order>hostkeystatus</order>
  1539. </decoder>
  1540. <decoder name="fortinet-fortigate-fields-v7">
  1541. <parent>fortinet-fortigate-firewall</parent>
  1542. <regex>\s+hostname="(\.*)"|\s+hostname=(\.*)\s|\s+hostname=(\.*)$</regex>
  1543. <order>hostname</order>
  1544. </decoder>
  1545. <decoder name="fortinet-fortigate-fields-v7">
  1546. <parent>fortinet-fortigate-firewall</parent>
  1547. <regex>\s+hseid="(\.*)"|\s+hseid=(\.*)\s|\s+hseid=(\.*)$</regex>
  1548. <order>hseid</order>
  1549. </decoder>
  1550. <decoder name="fortinet-fortigate-fields-v7">
  1551. <parent>fortinet-fortigate-firewall</parent>
  1552. <regex>\s+httpcode="(\.*)"|\s+httpcode=(\.*)\s|\s+httpcode=(\.*)$</regex>
  1553. <order>httpcode</order>
  1554. </decoder>
  1555. <decoder name="fortinet-fortigate-fields-v7">
  1556. <parent>fortinet-fortigate-firewall</parent>
  1557. <regex>\s+httpmethod="(\.*)"|\s+httpmethod=(\.*)\s|\s+httpmethod=(\.*)$</regex>
  1558. <order>httpmethod</order>
  1559. </decoder>
  1560. <decoder name="fortinet-fortigate-fields-v7">
  1561. <parent>fortinet-fortigate-firewall</parent>
  1562. <regex>\s+iaid="(\.*)"|\s+iaid=(\.*)\s|\s+iaid=(\.*)$</regex>
  1563. <order>iaid</order>
  1564. </decoder>
  1565. <decoder name="fortinet-fortigate-fields-v7">
  1566. <parent>fortinet-fortigate-firewall</parent>
  1567. <regex>\s+icap="(\.*)"|\s+icap=(\.*)\s|\s+icap=(\.*)$</regex>
  1568. <order>icap</order>
  1569. </decoder>
  1570. <decoder name="fortinet-fortigate-fields-v7">
  1571. <parent>fortinet-fortigate-firewall</parent>
  1572. <regex>\s+icbaction="(\.*)"|\s+icbaction=(\.*)\s|\s+icbaction=(\.*)$</regex>
  1573. <order>icbaction</order>
  1574. </decoder>
  1575. <decoder name="fortinet-fortigate-fields-v7">
  1576. <parent>fortinet-fortigate-firewall</parent>
  1577. <regex>\s+icbconfidence="(\.*)"|\s+icbconfidence=(\.*)\s|\s+icbconfidence=(\.*)$</regex>
  1578. <order>icbconfidence</order>
  1579. </decoder>
  1580. <decoder name="fortinet-fortigate-fields-v7">
  1581. <parent>fortinet-fortigate-firewall</parent>
  1582. <regex>\s+icbfileid="(\.*)"|\s+icbfileid=(\.*)\s|\s+icbfileid=(\.*)$</regex>
  1583. <order>icbfileid</order>
  1584. </decoder>
  1585. <decoder name="fortinet-fortigate-fields-v7">
  1586. <parent>fortinet-fortigate-firewall</parent>
  1587. <regex>\s+icbfiletype="(\.*)"|\s+icbfiletype=(\.*)\s|\s+icbfiletype=(\.*)$</regex>
  1588. <order>icbfiletype</order>
  1589. </decoder>
  1590. <decoder name="fortinet-fortigate-fields-v7">
  1591. <parent>fortinet-fortigate-firewall</parent>
  1592. <regex>\s+icbseverity="(\.*)"|\s+icbseverity=(\.*)\s|\s+icbseverity=(\.*)$</regex>
  1593. <order>icbseverity</order>
  1594. </decoder>
  1595. <decoder name="fortinet-fortigate-fields-v7">
  1596. <parent>fortinet-fortigate-firewall</parent>
  1597. <regex>\s+icbverdict="(\.*)"|\s+icbverdict=(\.*)\s|\s+icbverdict=(\.*)$</regex>
  1598. <order>icbverdict</order>
  1599. </decoder>
  1600. <decoder name="fortinet-fortigate-fields-v7">
  1601. <parent>fortinet-fortigate-firewall</parent>
  1602. <regex>\s+icmpcode="(\.*)"|\s+icmpcode=(\.*)\s|\s+icmpcode=(\.*)$</regex>
  1603. <order>icmpcode</order>
  1604. </decoder>
  1605. <decoder name="fortinet-fortigate-fields-v7">
  1606. <parent>fortinet-fortigate-firewall</parent>
  1607. <regex>\s+icmpid="(\.*)"|\s+icmpid=(\.*)\s|\s+icmpid=(\.*)$</regex>
  1608. <order>icmpid</order>
  1609. </decoder>
  1610. <decoder name="fortinet-fortigate-fields-v7">
  1611. <parent>fortinet-fortigate-firewall</parent>
  1612. <regex>\s+icmptype="(\.*)"|\s+icmptype=(\.*)\s|\s+icmptype=(\.*)$</regex>
  1613. <order>icmptype</order>
  1614. </decoder>
  1615. <decoder name="fortinet-fortigate-fields-v7">
  1616. <parent>fortinet-fortigate-firewall</parent>
  1617. <regex>\s+identifier="(\.*)"|\s+identifier=(\.*)\s|\s+identifier=(\.*)$</regex>
  1618. <order>identifier</order>
  1619. </decoder>
  1620. <decoder name="fortinet-fortigate-fields-v7">
  1621. <parent>fortinet-fortigate-firewall</parent>
  1622. <regex>\s+ietype="(\.*)"|\s+ietype=(\.*)\s|\s+ietype=(\.*)$</regex>
  1623. <order>ietype</order>
  1624. </decoder>
  1625. <decoder name="fortinet-fortigate-fields-v7">
  1626. <parent>fortinet-fortigate-firewall</parent>
  1627. <regex>\s+imei="(\.*)"|\s+imei=(\.*)\s|\s+imei=(\.*)$</regex>
  1628. <order>imei</order>
  1629. </decoder>
  1630. <decoder name="fortinet-fortigate-fields-v7">
  1631. <parent>fortinet-fortigate-firewall</parent>
  1632. <regex>\s+imsi="(\.*)"|\s+imsi=(\.*)\s|\s+imsi=(\.*)$</regex>
  1633. <order>imsi</order>
  1634. </decoder>
  1635. <decoder name="fortinet-fortigate-fields-v7">
  1636. <parent>fortinet-fortigate-firewall</parent>
  1637. <regex>\s+in_spi="(\.*)"|\s+in_spi=(\.*)\s|\s+in_spi=(\.*)$</regex>
  1638. <order>in_spi</order>
  1639. </decoder>
  1640. <decoder name="fortinet-fortigate-fields-v7">
  1641. <parent>fortinet-fortigate-firewall</parent>
  1642. <regex>\s+inbandwidth="(\.*)"|\s+inbandwidth=(\.*)\s|\s+inbandwidth=(\.*)$</regex>
  1643. <order>inbandwidth</order>
  1644. </decoder>
  1645. <decoder name="fortinet-fortigate-fields-v7">
  1646. <parent>fortinet-fortigate-firewall</parent>
  1647. <regex>\s+inbandwidthavailable="(\.*)"|\s+inbandwidthavailable=(\.*)\s|\s+inbandwidthavailable=(\.*)$</regex>
  1648. <order>inbandwidthavailable</order>
  1649. </decoder>
  1650. <decoder name="fortinet-fortigate-fields-v7">
  1651. <parent>fortinet-fortigate-firewall</parent>
  1652. <regex>\s+inbandwidthused="(\.*)"|\s+inbandwidthused=(\.*)\s|\s+inbandwidthused=(\.*)$</regex>
  1653. <order>inbandwidthused</order>
  1654. </decoder>
  1655. <decoder name="fortinet-fortigate-fields-v7">
  1656. <parent>fortinet-fortigate-firewall</parent>
  1657. <regex>\s+incidentserialno="(\.*)"|\s+incidentserialno=(\.*)\s|\s+incidentserialno=(\.*)$</regex>
  1658. <order>incidentserialno</order>
  1659. </decoder>
  1660. <decoder name="fortinet-fortigate-fields-v7">
  1661. <parent>fortinet-fortigate-firewall</parent>
  1662. <regex>\s+infectedfilelevel="(\.*)"|\s+infectedfilelevel=(\.*)\s|\s+infectedfilelevel=(\.*)$</regex>
  1663. <order>infectedfilelevel</order>
  1664. </decoder>
  1665. <decoder name="fortinet-fortigate-fields-v7">
  1666. <parent>fortinet-fortigate-firewall</parent>
  1667. <regex>\s+infectedfilename="(\.*)"|\s+infectedfilename=(\.*)\s|\s+infectedfilename=(\.*)$</regex>
  1668. <order>infectedfilename</order>
  1669. </decoder>
  1670. <decoder name="fortinet-fortigate-fields-v7">
  1671. <parent>fortinet-fortigate-firewall</parent>
  1672. <regex>\s+infectedfilesize="(\.*)"|\s+infectedfilesize=(\.*)\s|\s+infectedfilesize=(\.*)$</regex>
  1673. <order>infectedfilesize</order>
  1674. </decoder>
  1675. <decoder name="fortinet-fortigate-fields-v7">
  1676. <parent>fortinet-fortigate-firewall</parent>
  1677. <regex>\s+infectedfiletype="(\.*)"|\s+infectedfiletype=(\.*)\s|\s+infectedfiletype=(\.*)$</regex>
  1678. <order>infectedfiletype</order>
  1679. </decoder>
  1680. <decoder name="fortinet-fortigate-fields-v7">
  1681. <parent>fortinet-fortigate-firewall</parent>
  1682. <regex>\s+infection="(\.*)"|\s+infection=(\.*)\s|\s+infection=(\.*)$</regex>
  1683. <order>infection</order>
  1684. </decoder>
  1685. <decoder name="fortinet-fortigate-fields-v7">
  1686. <parent>fortinet-fortigate-firewall</parent>
  1687. <regex>\s+informationsource="(\.*)"|\s+informationsource=(\.*)\s|\s+informationsource=(\.*)$</regex>
  1688. <order>informationsource</order>
  1689. </decoder>
  1690. <decoder name="fortinet-fortigate-fields-v7">
  1691. <parent>fortinet-fortigate-firewall</parent>
  1692. <regex>\s+init="(\.*)"|\s+init=(\.*)\s|\s+init=(\.*)$</regex>
  1693. <order>init</order>
  1694. </decoder>
  1695. <decoder name="fortinet-fortigate-fields-v7">
  1696. <parent>fortinet-fortigate-firewall</parent>
  1697. <regex>\s+initiator="(\.*)"|\s+initiator=(\.*)\s|\s+initiator=(\.*)$</regex>
  1698. <order>initiator</order>
  1699. </decoder>
  1700. <decoder name="fortinet-fortigate-fields-v7">
  1701. <parent>fortinet-fortigate-firewall</parent>
  1702. <regex>\s+interface="(\.*)"|\s+interface=(\.*)\s|\s+interface=(\.*)$</regex>
  1703. <order>interface</order>
  1704. </decoder>
  1705. <decoder name="fortinet-fortigate-fields-v7">
  1706. <parent>fortinet-fortigate-firewall</parent>
  1707. <regex>\s+intf="(\.*)"|\s+intf=(\.*)\s|\s+intf=(\.*)$</regex>
  1708. <order>intf</order>
  1709. </decoder>
  1710. <decoder name="fortinet-fortigate-fields-v7">
  1711. <parent>fortinet-fortigate-firewall</parent>
  1712. <regex>\s+invalidmac="(\.*)"|\s+invalidmac=(\.*)\s|\s+invalidmac=(\.*)$</regex>
  1713. <order>invalidmac</order>
  1714. </decoder>
  1715. <decoder name="fortinet-fortigate-fields-v7">
  1716. <parent>fortinet-fortigate-firewall</parent>
  1717. <regex>\s+ip="(\.*)"|\s+ip=(\.*)\s|\s+ip=(\.*)$</regex>
  1718. <order>ip</order>
  1719. </decoder>
  1720. <decoder name="fortinet-fortigate-fields-v7">
  1721. <parent>fortinet-fortigate-firewall</parent>
  1722. <regex>\s+ipaddr="(\.*)"|\s+ipaddr=(\.*)\s|\s+ipaddr=(\.*)$</regex>
  1723. <order>ipaddr</order>
  1724. </decoder>
  1725. <decoder name="fortinet-fortigate-fields-v7">
  1726. <parent>fortinet-fortigate-firewall</parent>
  1727. <regex>\s+ips="(\.*)"|\s+ips=(\.*)\s|\s+ips=(\.*)$</regex>
  1728. <order>ips</order>
  1729. </decoder>
  1730. <decoder name="fortinet-fortigate-fields-v7">
  1731. <parent>fortinet-fortigate-firewall</parent>
  1732. <regex>\s+iptype="(\.*)"|\s+iptype=(\.*)\s|\s+iptype=(\.*)$</regex>
  1733. <order>iptype</order>
  1734. </decoder>
  1735. <decoder name="fortinet-fortigate-fields-v7">
  1736. <parent>fortinet-fortigate-firewall</parent>
  1737. <regex>\s+issuer="(\.*)"|\s+issuer=(\.*)\s|\s+issuer=(\.*)$</regex>
  1738. <order>issuer</order>
  1739. </decoder>
  1740. <decoder name="fortinet-fortigate-fields-v7">
  1741. <parent>fortinet-fortigate-firewall</parent>
  1742. <regex>\s+jitter="(\.*)"|\s+jitter=(\.*)\s|\s+jitter=(\.*)$</regex>
  1743. <order>jitter</order>
  1744. </decoder>
  1745. <decoder name="fortinet-fortigate-fields-v7">
  1746. <parent>fortinet-fortigate-firewall</parent>
  1747. <regex>\s+keyalgo="(\.*)"|\s+keyalgo=(\.*)\s|\s+keyalgo=(\.*)$</regex>
  1748. <order>keyalgo</order>
  1749. </decoder>
  1750. <decoder name="fortinet-fortigate-fields-v7">
  1751. <parent>fortinet-fortigate-firewall</parent>
  1752. <regex>\s+keysize="(\.*)"|\s+keysize=(\.*)\s|\s+keysize=(\.*)$</regex>
  1753. <order>keysize</order>
  1754. </decoder>
  1755. <decoder name="fortinet-fortigate-fields-v7">
  1756. <parent>fortinet-fortigate-firewall</parent>
  1757. <regex>\s+keyword="(\.*)"|\s+keyword=(\.*)\s|\s+keyword=(\.*)$</regex>
  1758. <order>keyword</order>
  1759. </decoder>
  1760. <decoder name="fortinet-fortigate-fields-v7">
  1761. <parent>fortinet-fortigate-firewall</parent>
  1762. <regex>\s+kind="(\.*)"|\s+kind=(\.*)\s|\s+kind=(\.*)$</regex>
  1763. <order>kind</order>
  1764. </decoder>
  1765. <decoder name="fortinet-fortigate-fields-v7">
  1766. <parent>fortinet-fortigate-firewall</parent>
  1767. <regex>\s+kxcurve="(\.*)"|\s+kxcurve=(\.*)\s|\s+kxcurve=(\.*)$</regex>
  1768. <order>kxcurve</order>
  1769. </decoder>
  1770. <decoder name="fortinet-fortigate-fields-v7">
  1771. <parent>fortinet-fortigate-firewall</parent>
  1772. <regex>\s+kxproto="(\.*)"|\s+kxproto=(\.*)\s|\s+kxproto=(\.*)$</regex>
  1773. <order>kxproto</order>
  1774. </decoder>
  1775. <decoder name="fortinet-fortigate-fields-v7">
  1776. <parent>fortinet-fortigate-firewall</parent>
  1777. <regex>\s+lanin="(\.*)"|\s+lanin=(\.*)\s|\s+lanin=(\.*)$</regex>
  1778. <order>lanin</order>
  1779. </decoder>
  1780. <decoder name="fortinet-fortigate-fields-v7">
  1781. <parent>fortinet-fortigate-firewall</parent>
  1782. <regex>\s+lanout="(\.*)"|\s+lanout=(\.*)\s|\s+lanout=(\.*)$</regex>
  1783. <order>lanout</order>
  1784. </decoder>
  1785. <decoder name="fortinet-fortigate-fields-v7">
  1786. <parent>fortinet-fortigate-firewall</parent>
  1787. <regex>\s+latency="(\.*)"|\s+latency=(\.*)\s|\s+latency=(\.*)$</regex>
  1788. <order>latency</order>
  1789. </decoder>
  1790. <decoder name="fortinet-fortigate-fields-v7">
  1791. <parent>fortinet-fortigate-firewall</parent>
  1792. <regex>\s+lease="(\.*)"|\s+lease=(\.*)\s|\s+lease=(\.*)$</regex>
  1793. <order>lease</order>
  1794. </decoder>
  1795. <decoder name="fortinet-fortigate-fields-v7">
  1796. <parent>fortinet-fortigate-firewall</parent>
  1797. <regex>\s+level="(\.*)"|\s+level=(\.*)\s|\s+level=(\.*)$</regex>
  1798. <order>level</order>
  1799. </decoder>
  1800. <decoder name="fortinet-fortigate-fields-v7">
  1801. <parent>fortinet-fortigate-firewall</parent>
  1802. <regex>\s+license_limit="(\.*)"|\s+license_limit=(\.*)\s|\s+license_limit=(\.*)$</regex>
  1803. <order>license_limit</order>
  1804. </decoder>
  1805. <decoder name="fortinet-fortigate-fields-v7">
  1806. <parent>fortinet-fortigate-firewall</parent>
  1807. <regex>\s+limit="(\.*)"|\s+limit=(\.*)\s|\s+limit=(\.*)$</regex>
  1808. <order>limit</order>
  1809. </decoder>
  1810. <decoder name="fortinet-fortigate-fields-v7">
  1811. <parent>fortinet-fortigate-firewall</parent>
  1812. <regex>\s+line="(\.*)"|\s+line=(\.*)\s|\s+line=(\.*)$</regex>
  1813. <order>line</order>
  1814. </decoder>
  1815. <decoder name="fortinet-fortigate-fields-v7">
  1816. <parent>fortinet-fortigate-firewall</parent>
  1817. <regex>\s+linked="(\.*)"|\s+linked=(\.*)\s|\s+linked=(\.*)$</regex>
  1818. <order>linked</order>
  1819. </decoder>
  1820. <decoder name="fortinet-fortigate-fields-v7">
  1821. <parent>fortinet-fortigate-firewall</parent>
  1822. <regex>\s+live="(\.*)"|\s+live=(\.*)\s|\s+live=(\.*)$</regex>
  1823. <order>live</order>
  1824. </decoder>
  1825. <decoder name="fortinet-fortigate-fields-v7">
  1826. <parent>fortinet-fortigate-firewall</parent>
  1827. <regex>\s+local="(\.*)"|\s+local=(\.*)\s|\s+local=(\.*)$</regex>
  1828. <order>local</order>
  1829. </decoder>
  1830. <decoder name="fortinet-fortigate-fields-v7">
  1831. <parent>fortinet-fortigate-firewall</parent>
  1832. <regex>\s+localdevcount="(\.*)"|\s+localdevcount=(\.*)\s|\s+localdevcount=(\.*)$</regex>
  1833. <order>localdevcount</order>
  1834. </decoder>
  1835. <decoder name="fortinet-fortigate-fields-v7">
  1836. <parent>fortinet-fortigate-firewall</parent>
  1837. <regex>\s+locip="(\.*)"|\s+locip=(\.*)\s|\s+locip=(\.*)$</regex>
  1838. <order>locip</order>
  1839. </decoder>
  1840. <decoder name="fortinet-fortigate-fields-v7">
  1841. <parent>fortinet-fortigate-firewall</parent>
  1842. <regex>\s+locport="(\.*)"|\s+locport=(\.*)\s|\s+locport=(\.*)$</regex>
  1843. <order>locport</order>
  1844. </decoder>
  1845. <decoder name="fortinet-fortigate-fields-v7">
  1846. <parent>fortinet-fortigate-firewall</parent>
  1847. <regex>\s+log="(\.*)"|\s+log=(\.*)\s|\s+log=(\.*)$</regex>
  1848. <order>log</order>
  1849. </decoder>
  1850. <decoder name="fortinet-fortigate-fields-v7">
  1851. <parent>fortinet-fortigate-firewall</parent>
  1852. <regex>\s+logdesc="(\.*)"|\s+logdesc=(\.*)\s|\s+logdesc=(\.*)$</regex>
  1853. <order>logdesc</order>
  1854. </decoder>
  1855. <decoder name="fortinet-fortigate-fields-v7">
  1856. <parent>fortinet-fortigate-firewall</parent>
  1857. <regex>\s+logid="(\.*)"|\s+logid=(\.*)\s|\s+logid=(\.*)$</regex>
  1858. <order>logid</order>
  1859. </decoder>
  1860. <decoder name="fortinet-fortigate-fields-v7">
  1861. <parent>fortinet-fortigate-firewall</parent>
  1862. <regex>\s+login="(\.*)"|\s+login=(\.*)\s|\s+login=(\.*)$</regex>
  1863. <order>login</order>
  1864. </decoder>
  1865. <decoder name="fortinet-fortigate-fields-v7">
  1866. <parent>fortinet-fortigate-firewall</parent>
  1867. <regex>\s+logsrc="(\.*)"|\s+logsrc=(\.*)\s|\s+logsrc=(\.*)$</regex>
  1868. <order>logsrc</order>
  1869. </decoder>
  1870. <decoder name="fortinet-fortigate-fields-v7">
  1871. <parent>fortinet-fortigate-firewall</parent>
  1872. <regex>\s+lowcount="(\.*)"|\s+lowcount=(\.*)\s|\s+lowcount=(\.*)$</regex>
  1873. <order>lowcount</order>
  1874. </decoder>
  1875. <decoder name="fortinet-fortigate-fields-v7">
  1876. <parent>fortinet-fortigate-firewall</parent>
  1877. <regex>\s+mac="(\.*)"|\s+mac=(\.*)\s|\s+mac=(\.*)$</regex>
  1878. <order>mac</order>
  1879. </decoder>
  1880. <decoder name="fortinet-fortigate-fields-v7">
  1881. <parent>fortinet-fortigate-firewall</parent>
  1882. <regex>\s+malform_data="(\.*)"|\s+malform_data=(\.*)\s|\s+malform_data=(\.*)$</regex>
  1883. <order>malform_data</order>
  1884. </decoder>
  1885. <decoder name="fortinet-fortigate-fields-v7">
  1886. <parent>fortinet-fortigate-firewall</parent>
  1887. <regex>\s+malform_desc="(\.*)"|\s+malform_desc=(\.*)\s|\s+malform_desc=(\.*)$</regex>
  1888. <order>malform_desc</order>
  1889. </decoder>
  1890. <decoder name="fortinet-fortigate-fields-v7">
  1891. <parent>fortinet-fortigate-firewall</parent>
  1892. <regex>\s+manuf="(\.*)"|\s+manuf=(\.*)\s|\s+manuf=(\.*)$</regex>
  1893. <order>manuf</order>
  1894. </decoder>
  1895. <decoder name="fortinet-fortigate-fields-v7">
  1896. <parent>fortinet-fortigate-firewall</parent>
  1897. <regex>\s+masterdstmac="(\.*)"|\s+masterdstmac=(\.*)\s|\s+masterdstmac=(\.*)$</regex>
  1898. <order>masterdstmac</order>
  1899. </decoder>
  1900. <decoder name="fortinet-fortigate-fields-v7">
  1901. <parent>fortinet-fortigate-firewall</parent>
  1902. <regex>\s+mastersrcmac="(\.*)"|\s+mastersrcmac=(\.*)\s|\s+mastersrcmac=(\.*)$</regex>
  1903. <order>mastersrcmac</order>
  1904. </decoder>
  1905. <decoder name="fortinet-fortigate-fields-v7">
  1906. <parent>fortinet-fortigate-firewall</parent>
  1907. <regex>\s+matchfilename="(\.*)"|\s+matchfilename=(\.*)\s|\s+matchfilename=(\.*)$</regex>
  1908. <order>matchfilename</order>
  1909. </decoder>
  1910. <decoder name="fortinet-fortigate-fields-v7">
  1911. <parent>fortinet-fortigate-firewall</parent>
  1912. <regex>\s+matchfiletype="(\.*)"|\s+matchfiletype=(\.*)\s|\s+matchfiletype=(\.*)$</regex>
  1913. <order>matchfiletype</order>
  1914. </decoder>
  1915. <decoder name="fortinet-fortigate-fields-v7">
  1916. <parent>fortinet-fortigate-firewall</parent>
  1917. <regex>\s+max="(\.*)"|\s+max=(\.*)\s|\s+max=(\.*)$</regex>
  1918. <order>max</order>
  1919. </decoder>
  1920. <decoder name="fortinet-fortigate-fields-v7">
  1921. <parent>fortinet-fortigate-firewall</parent>
  1922. <regex>\s+mediumcount="(\.*)"|\s+mediumcount=(\.*)\s|\s+mediumcount=(\.*)$</regex>
  1923. <order>mediumcount</order>
  1924. </decoder>
  1925. <decoder name="fortinet-fortigate-fields-v7">
  1926. <parent>fortinet-fortigate-firewall</parent>
  1927. <regex>\s+mem="(\.*)"|\s+mem=(\.*)\s|\s+mem=(\.*)$</regex>
  1928. <order>mem</order>
  1929. </decoder>
  1930. <decoder name="fortinet-fortigate-fields-v7">
  1931. <parent>fortinet-fortigate-firewall</parent>
  1932. <regex>\s+member="(\.*)"|\s+member=(\.*)\s|\s+member=(\.*)$</regex>
  1933. <order>member</order>
  1934. </decoder>
  1935. <decoder name="fortinet-fortigate-fields-v7">
  1936. <parent>fortinet-fortigate-firewall</parent>
  1937. <regex>\s+meshmode="(\.*)"|\s+meshmode=(\.*)\s|\s+meshmode=(\.*)$</regex>
  1938. <order>meshmode</order>
  1939. </decoder>
  1940. <decoder name="fortinet-fortigate-fields-v7">
  1941. <parent>fortinet-fortigate-firewall</parent>
  1942. <regex>\s+message_type="(\.*)"|\s+message_type=(\.*)\s|\s+message_type=(\.*)$</regex>
  1943. <order>message_type</order>
  1944. </decoder>
  1945. <decoder name="fortinet-fortigate-fields-v7">
  1946. <parent>fortinet-fortigate-firewall</parent>
  1947. <regex>\s+method="(\.*)"|\s+method=(\.*)\s|\s+method=(\.*)$</regex>
  1948. <order>method</order>
  1949. </decoder>
  1950. <decoder name="fortinet-fortigate-fields-v7">
  1951. <parent>fortinet-fortigate-firewall</parent>
  1952. <regex>\s+mgmtcnt="(\.*)"|\s+mgmtcnt=(\.*)\s|\s+mgmtcnt=(\.*)$</regex>
  1953. <order>mgmtcnt</order>
  1954. </decoder>
  1955. <decoder name="fortinet-fortigate-fields-v7">
  1956. <parent>fortinet-fortigate-firewall</parent>
  1957. <regex>\s+mitm="(\.*)"|\s+mitm=(\.*)\s|\s+mitm=(\.*)$</regex>
  1958. <order>mitm</order>
  1959. </decoder>
  1960. <decoder name="fortinet-fortigate-fields-v7">
  1961. <parent>fortinet-fortigate-firewall</parent>
  1962. <regex>\s+mode="(\.*)"|\s+mode=(\.*)\s|\s+mode=(\.*)$</regex>
  1963. <order>mode</order>
  1964. </decoder>
  1965. <decoder name="fortinet-fortigate-fields-v7">
  1966. <parent>fortinet-fortigate-firewall</parent>
  1967. <regex>\s+model="(\.*)"|\s+model=(\.*)\s|\s+model=(\.*)$</regex>
  1968. <order>model</order>
  1969. </decoder>
  1970. <decoder name="fortinet-fortigate-fields-v7">
  1971. <parent>fortinet-fortigate-firewall</parent>
  1972. <regex>\s+module="(\.*)"|\s+module=(\.*)\s|\s+module=(\.*)$</regex>
  1973. <order>module</order>
  1974. </decoder>
  1975. <decoder name="fortinet-fortigate-fields-v7">
  1976. <parent>fortinet-fortigate-firewall</parent>
  1977. <regex>\s+monitor="(\.*)"|\s+monitor=(\.*)\s|\s+monitor=(\.*)$</regex>
  1978. <order>monitor</order>
  1979. </decoder>
  1980. <decoder name="fortinet-fortigate-fields-v7">
  1981. <parent>fortinet-fortigate-firewall</parent>
  1982. <regex>\s+moscodec="(\.*)"|\s+moscodec=(\.*)\s|\s+moscodec=(\.*)$</regex>
  1983. <order>moscodec</order>
  1984. </decoder>
  1985. <decoder name="fortinet-fortigate-fields-v7">
  1986. <parent>fortinet-fortigate-firewall</parent>
  1987. <regex>\s+mosvalue="(\.*)"|\s+mosvalue=(\.*)\s|\s+mosvalue=(\.*)$</regex>
  1988. <order>mosvalue</order>
  1989. </decoder>
  1990. <decoder name="fortinet-fortigate-fields-v7">
  1991. <parent>fortinet-fortigate-firewall</parent>
  1992. <regex>\s+mpsk="(\.*)"|\s+mpsk=(\.*)\s|\s+mpsk=(\.*)$</regex>
  1993. <order>mpsk</order>
  1994. </decoder>
  1995. <decoder name="fortinet-fortigate-fields-v7">
  1996. <parent>fortinet-fortigate-firewall</parent>
  1997. <regex>\s+msg="(\.*)"|\s+msg=(\.*)\s|\s+msg=(\.*)$</regex>
  1998. <order>msg</order>
  1999. </decoder>
  2000. <decoder name="fortinet-fortigate-fields-v7">
  2001. <parent>fortinet-fortigate-firewall</parent>
  2002. <regex>\s+msgtypename="(\.*)"|\s+msgtypename=(\.*)\s|\s+msgtypename=(\.*)$</regex>
  2003. <order>msgtypename</order>
  2004. </decoder>
  2005. <decoder name="fortinet-fortigate-fields-v7">
  2006. <parent>fortinet-fortigate-firewall</parent>
  2007. <regex>\s+msisdn="(\.*)"|\s+msisdn=(\.*)\s|\s+msisdn=(\.*)$</regex>
  2008. <order>msisdn</order>
  2009. </decoder>
  2010. <decoder name="fortinet-fortigate-fields-v7">
  2011. <parent>fortinet-fortigate-firewall</parent>
  2012. <regex>\s+mtu="(\.*)"|\s+mtu=(\.*)\s|\s+mtu=(\.*)$</regex>
  2013. <order>mtu</order>
  2014. </decoder>
  2015. <decoder name="fortinet-fortigate-fields-v7">
  2016. <parent>fortinet-fortigate-firewall</parent>
  2017. <regex>\s+nai="(\.*)"|\s+nai=(\.*)\s|\s+nai=(\.*)$</regex>
  2018. <order>nai</order>
  2019. </decoder>
  2020. <decoder name="fortinet-fortigate-fields-v7">
  2021. <parent>fortinet-fortigate-firewall</parent>
  2022. <regex>\s+name="(\.*)"|\s+name=(\.*)\s|\s+name=(\.*)$</regex>
  2023. <order>name</order>
  2024. </decoder>
  2025. <decoder name="fortinet-fortigate-fields-v7">
  2026. <parent>fortinet-fortigate-firewall</parent>
  2027. <regex>\s+nat="(\.*)"|\s+nat=(\.*)\s|\s+nat=(\.*)$</regex>
  2028. <order>nat</order>
  2029. </decoder>
  2030. <decoder name="fortinet-fortigate-fields-v7">
  2031. <parent>fortinet-fortigate-firewall</parent>
  2032. <regex>\s+neighbor="(\.*)"|\s+neighbor=(\.*)\s|\s+neighbor=(\.*)$</regex>
  2033. <order>neighbor</order>
  2034. </decoder>
  2035. <decoder name="fortinet-fortigate-fields-v7">
  2036. <parent>fortinet-fortigate-firewall</parent>
  2037. <regex>\s+netid="(\.*)"|\s+netid=(\.*)\s|\s+netid=(\.*)$</regex>
  2038. <order>netid</order>
  2039. </decoder>
  2040. <decoder name="fortinet-fortigate-fields-v7">
  2041. <parent>fortinet-fortigate-firewall</parent>
  2042. <regex>\s+networktransfertime="(\.*)"|\s+networktransfertime=(\.*)\s|\s+networktransfertime=(\.*)$</regex>
  2043. <order>networktransfertime</order>
  2044. </decoder>
  2045. <decoder name="fortinet-fortigate-fields-v7">
  2046. <parent>fortinet-fortigate-firewall</parent>
  2047. <regex>\s+new_status="(\.*)"|\s+new_status=(\.*)\s|\s+new_status=(\.*)$</regex>
  2048. <order>new_status</order>
  2049. </decoder>
  2050. <decoder name="fortinet-fortigate-fields-v7">
  2051. <parent>fortinet-fortigate-firewall</parent>
  2052. <regex>\s+new_value="(\.*)"|\s+new_value=(\.*)\s|\s+new_value=(\.*)$</regex>
  2053. <order>new_value</order>
  2054. </decoder>
  2055. <decoder name="fortinet-fortigate-fields-v7">
  2056. <parent>fortinet-fortigate-firewall</parent>
  2057. <regex>\s+newchannel="(\.*)"|\s+newchannel=(\.*)\s|\s+newchannel=(\.*)$</regex>
  2058. <order>newchannel</order>
  2059. </decoder>
  2060. <decoder name="fortinet-fortigate-fields-v7">
  2061. <parent>fortinet-fortigate-firewall</parent>
  2062. <regex>\s+newchassisid="(\.*)"|\s+newchassisid=(\.*)\s|\s+newchassisid=(\.*)$</regex>
  2063. <order>newchassisid</order>
  2064. </decoder>
  2065. <decoder name="fortinet-fortigate-fields-v7">
  2066. <parent>fortinet-fortigate-firewall</parent>
  2067. <regex>\s+newslot="(\.*)"|\s+newslot=(\.*)\s|\s+newslot=(\.*)$</regex>
  2068. <order>newslot</order>
  2069. </decoder>
  2070. <decoder name="fortinet-fortigate-fields-v7">
  2071. <parent>fortinet-fortigate-firewall</parent>
  2072. <regex>\s+newvalue="(\.*)"|\s+newvalue=(\.*)\s|\s+newvalue=(\.*)$</regex>
  2073. <order>newvalue</order>
  2074. </decoder>
  2075. <decoder name="fortinet-fortigate-fields-v7">
  2076. <parent>fortinet-fortigate-firewall</parent>
  2077. <regex>\s+nextstat="(\.*)"|\s+nextstat=(\.*)\s|\s+nextstat=(\.*)$</regex>
  2078. <order>nextstat</order>
  2079. </decoder>
  2080. <decoder name="fortinet-fortigate-fields-v7">
  2081. <parent>fortinet-fortigate-firewall</parent>
  2082. <regex>\s+noise="(\.*)"|\s+noise=(\.*)\s|\s+noise=(\.*)$</regex>
  2083. <order>noise</order>
  2084. </decoder>
  2085. <decoder name="fortinet-fortigate-fields-v7">
  2086. <parent>fortinet-fortigate-firewall</parent>
  2087. <regex>\s+notafter="(\.*)"|\s+notafter=(\.*)\s|\s+notafter=(\.*)$</regex>
  2088. <order>notafter</order>
  2089. </decoder>
  2090. <decoder name="fortinet-fortigate-fields-v7">
  2091. <parent>fortinet-fortigate-firewall</parent>
  2092. <regex>\s+notbefore="(\.*)"|\s+notbefore=(\.*)\s|\s+notbefore=(\.*)$</regex>
  2093. <order>notbefore</order>
  2094. </decoder>
  2095. <decoder name="fortinet-fortigate-fields-v7">
  2096. <parent>fortinet-fortigate-firewall</parent>
  2097. <regex>\s+nsapi="(\.*)"|\s+nsapi=(\.*)\s|\s+nsapi=(\.*)$</regex>
  2098. <order>nsapi</order>
  2099. </decoder>
  2100. <decoder name="fortinet-fortigate-fields-v7">
  2101. <parent>fortinet-fortigate-firewall</parent>
  2102. <regex>\s+numpassmember="(\.*)"|\s+numpassmember=(\.*)\s|\s+numpassmember=(\.*)$</regex>
  2103. <order>numpassmember</order>
  2104. </decoder>
  2105. <decoder name="fortinet-fortigate-fields-v7">
  2106. <parent>fortinet-fortigate-firewall</parent>
  2107. <regex>\s+old_status="(\.*)"|\s+old_status=(\.*)\s|\s+old_status=(\.*)$</regex>
  2108. <order>old_status</order>
  2109. </decoder>
  2110. <decoder name="fortinet-fortigate-fields-v7">
  2111. <parent>fortinet-fortigate-firewall</parent>
  2112. <regex>\s+old_value="(\.*)"|\s+old_value=(\.*)\s|\s+old_value=(\.*)$</regex>
  2113. <order>old_value</order>
  2114. </decoder>
  2115. <decoder name="fortinet-fortigate-fields-v7">
  2116. <parent>fortinet-fortigate-firewall</parent>
  2117. <regex>\s+oldchannel="(\.*)"|\s+oldchannel=(\.*)\s|\s+oldchannel=(\.*)$</regex>
  2118. <order>oldchannel</order>
  2119. </decoder>
  2120. <decoder name="fortinet-fortigate-fields-v7">
  2121. <parent>fortinet-fortigate-firewall</parent>
  2122. <regex>\s+oldchassisid="(\.*)"|\s+oldchassisid=(\.*)\s|\s+oldchassisid=(\.*)$</regex>
  2123. <order>oldchassisid</order>
  2124. </decoder>
  2125. <decoder name="fortinet-fortigate-fields-v7">
  2126. <parent>fortinet-fortigate-firewall</parent>
  2127. <regex>\s+oldslot="(\.*)"|\s+oldslot=(\.*)\s|\s+oldslot=(\.*)$</regex>
  2128. <order>oldslot</order>
  2129. </decoder>
  2130. <decoder name="fortinet-fortigate-fields-v7">
  2131. <parent>fortinet-fortigate-firewall</parent>
  2132. <regex>\s+oldsn="(\.*)"|\s+oldsn=(\.*)\s|\s+oldsn=(\.*)$</regex>
  2133. <order>oldsn</order>
  2134. </decoder>
  2135. <decoder name="fortinet-fortigate-fields-v7">
  2136. <parent>fortinet-fortigate-firewall</parent>
  2137. <regex>\s+oldvalue="(\.*)"|\s+oldvalue=(\.*)\s|\s+oldvalue=(\.*)$</regex>
  2138. <order>oldvalue</order>
  2139. </decoder>
  2140. <decoder name="fortinet-fortigate-fields-v7">
  2141. <parent>fortinet-fortigate-firewall</parent>
  2142. <regex>\s+oldwprof="(\.*)"|\s+oldwprof=(\.*)\s|\s+oldwprof=(\.*)$</regex>
  2143. <order>oldwprof</order>
  2144. </decoder>
  2145. <decoder name="fortinet-fortigate-fields-v7">
  2146. <parent>fortinet-fortigate-firewall</parent>
  2147. <regex>\s+onwire="(\.*)"|\s+onwire=(\.*)\s|\s+onwire=(\.*)$</regex>
  2148. <order>onwire</order>
  2149. </decoder>
  2150. <decoder name="fortinet-fortigate-fields-v7">
  2151. <parent>fortinet-fortigate-firewall</parent>
  2152. <regex>\s+opercountry="(\.*)"|\s+opercountry=(\.*)\s|\s+opercountry=(\.*)$</regex>
  2153. <order>opercountry</order>
  2154. </decoder>
  2155. <decoder name="fortinet-fortigate-fields-v7">
  2156. <parent>fortinet-fortigate-firewall</parent>
  2157. <regex>\s+operdrmamode="(\.*)"|\s+operdrmamode=(\.*)\s|\s+operdrmamode=(\.*)$</regex>
  2158. <order>operdrmamode</order>
  2159. </decoder>
  2160. <decoder name="fortinet-fortigate-fields-v7">
  2161. <parent>fortinet-fortigate-firewall</parent>
  2162. <regex>\s+opertxpower="(\.*)"|\s+opertxpower=(\.*)\s|\s+opertxpower=(\.*)$</regex>
  2163. <order>opertxpower</order>
  2164. </decoder>
  2165. <decoder name="fortinet-fortigate-fields-v7">
  2166. <parent>fortinet-fortigate-firewall</parent>
  2167. <regex>\s+osname="(\.*)"|\s+osname=(\.*)\s|\s+osname=(\.*)$</regex>
  2168. <order>osname</order>
  2169. </decoder>
  2170. <decoder name="fortinet-fortigate-fields-v7">
  2171. <parent>fortinet-fortigate-firewall</parent>
  2172. <regex>\s+out_spi="(\.*)"|\s+out_spi=(\.*)\s|\s+out_spi=(\.*)$</regex>
  2173. <order>out_spi</order>
  2174. </decoder>
  2175. <decoder name="fortinet-fortigate-fields-v7">
  2176. <parent>fortinet-fortigate-firewall</parent>
  2177. <regex>\s+outbandwidth="(\.*)"|\s+outbandwidth=(\.*)\s|\s+outbandwidth=(\.*)$</regex>
  2178. <order>outbandwidth</order>
  2179. </decoder>
  2180. <decoder name="fortinet-fortigate-fields-v7">
  2181. <parent>fortinet-fortigate-firewall</parent>
  2182. <regex>\s+outbandwidthavailable="(\.*)"|\s+outbandwidthavailable=(\.*)\s|\s+outbandwidthavailable=(\.*)$</regex>
  2183. <order>outbandwidthavailable</order>
  2184. </decoder>
  2185. <decoder name="fortinet-fortigate-fields-v7">
  2186. <parent>fortinet-fortigate-firewall</parent>
  2187. <regex>\s+outbandwidthused="(\.*)"|\s+outbandwidthused=(\.*)\s|\s+outbandwidthused=(\.*)$</regex>
  2188. <order>outbandwidthused</order>
  2189. </decoder>
  2190. <decoder name="fortinet-fortigate-fields-v7">
  2191. <parent>fortinet-fortigate-firewall</parent>
  2192. <regex>\s+outintf="(\.*)"|\s+outintf=(\.*)\s|\s+outintf=(\.*)$</regex>
  2193. <order>outintf</order>
  2194. </decoder>
  2195. <decoder name="fortinet-fortigate-fields-v7">
  2196. <parent>fortinet-fortigate-firewall</parent>
  2197. <regex>\s+packetloss="(\.*)"|\s+packetloss=(\.*)\s|\s+packetloss=(\.*)$</regex>
  2198. <order>packetloss</order>
  2199. </decoder>
  2200. <decoder name="fortinet-fortigate-fields-v7">
  2201. <parent>fortinet-fortigate-firewall</parent>
  2202. <regex>\s+parameters="(\.*)"|\s+parameters=(\.*)\s|\s+parameters=(\.*)$</regex>
  2203. <order>parameters</order>
  2204. </decoder>
  2205. <decoder name="fortinet-fortigate-fields-v7">
  2206. <parent>fortinet-fortigate-firewall</parent>
  2207. <regex>\s+passedcount="(\.*)"|\s+passedcount=(\.*)\s|\s+passedcount=(\.*)$</regex>
  2208. <order>passedcount</order>
  2209. </decoder>
  2210. <decoder name="fortinet-fortigate-fields-v7">
  2211. <parent>fortinet-fortigate-firewall</parent>
  2212. <regex>\s+passwd="(\.*)"|\s+passwd=(\.*)\s|\s+passwd=(\.*)$</regex>
  2213. <order>passwd</order>
  2214. </decoder>
  2215. <decoder name="fortinet-fortigate-fields-v7">
  2216. <parent>fortinet-fortigate-firewall</parent>
  2217. <regex>\s+path="(\.*)"|\s+path=(\.*)\s|\s+path=(\.*)$</regex>
  2218. <order>path</order>
  2219. </decoder>
  2220. <decoder name="fortinet-fortigate-fields-v7">
  2221. <parent>fortinet-fortigate-firewall</parent>
  2222. <regex>\s+pathname="(\.*)"|\s+pathname=(\.*)\s|\s+pathname=(\.*)$</regex>
  2223. <order>pathname</order>
  2224. </decoder>
  2225. <decoder name="fortinet-fortigate-fields-v7">
  2226. <parent>fortinet-fortigate-firewall</parent>
  2227. <regex>\s+pdstport="(\.*)"|\s+pdstport=(\.*)\s|\s+pdstport=(\.*)$</regex>
  2228. <order>pdstport</order>
  2229. </decoder>
  2230. <decoder name="fortinet-fortigate-fields-v7">
  2231. <parent>fortinet-fortigate-firewall</parent>
  2232. <regex>\s+peer="(\.*)"|\s+peer=(\.*)\s|\s+peer=(\.*)$</regex>
  2233. <order>peer</order>
  2234. </decoder>
  2235. <decoder name="fortinet-fortigate-fields-v7">
  2236. <parent>fortinet-fortigate-firewall</parent>
  2237. <regex>\s+peer_notif="(\.*)"|\s+peer_notif=(\.*)\s|\s+peer_notif=(\.*)$</regex>
  2238. <order>peer_notif</order>
  2239. </decoder>
  2240. <decoder name="fortinet-fortigate-fields-v7">
  2241. <parent>fortinet-fortigate-firewall</parent>
  2242. <regex>\s+phase="(\.*)"|\s+phase=(\.*)\s|\s+phase=(\.*)$</regex>
  2243. <order>phase</order>
  2244. </decoder>
  2245. <decoder name="fortinet-fortigate-fields-v7">
  2246. <parent>fortinet-fortigate-firewall</parent>
  2247. <regex>\s+phone="(\.*)"|\s+phone=(\.*)\s|\s+phone=(\.*)$</regex>
  2248. <order>phone</order>
  2249. </decoder>
  2250. <decoder name="fortinet-fortigate-fields-v7">
  2251. <parent>fortinet-fortigate-firewall</parent>
  2252. <regex>\s+pid="(\.*)"|\s+pid=(\.*)\s|\s+pid=(\.*)$</regex>
  2253. <order>pid</order>
  2254. </decoder>
  2255. <decoder name="fortinet-fortigate-fields-v7">
  2256. <parent>fortinet-fortigate-firewall</parent>
  2257. <regex>\s+policy_id="(\.*)"|\s+policy_id=(\.*)\s|\s+policy_id=(\.*)$</regex>
  2258. <order>policy_id</order>
  2259. </decoder>
  2260. <decoder name="fortinet-fortigate-fields-v7">
  2261. <parent>fortinet-fortigate-firewall</parent>
  2262. <regex>\s+policyid="(\.*)"|\s+policyid=(\.*)\s|\s+policyid=(\.*)$</regex>
  2263. <order>policyid</order>
  2264. </decoder>
  2265. <decoder name="fortinet-fortigate-fields-v7">
  2266. <parent>fortinet-fortigate-firewall</parent>
  2267. <regex>\s+policymode="(\.*)"|\s+policymode=(\.*)\s|\s+policymode=(\.*)$</regex>
  2268. <order>policymode</order>
  2269. </decoder>
  2270. <decoder name="fortinet-fortigate-fields-v7">
  2271. <parent>fortinet-fortigate-firewall</parent>
  2272. <regex>\s+policyname="(\.*)"|\s+policyname=(\.*)\s|\s+policyname=(\.*)$</regex>
  2273. <order>policyname</order>
  2274. </decoder>
  2275. <decoder name="fortinet-fortigate-fields-v7">
  2276. <parent>fortinet-fortigate-firewall</parent>
  2277. <regex>\s+policytype="(\.*)"|\s+policytype=(\.*)\s|\s+policytype=(\.*)$</regex>
  2278. <order>policytype</order>
  2279. </decoder>
  2280. <decoder name="fortinet-fortigate-fields-v7">
  2281. <parent>fortinet-fortigate-firewall</parent>
  2282. <regex>\s+poluuid="(\.*)"|\s+poluuid=(\.*)\s|\s+poluuid=(\.*)$</regex>
  2283. <order>poluuid</order>
  2284. </decoder>
  2285. <decoder name="fortinet-fortigate-fields-v7">
  2286. <parent>fortinet-fortigate-firewall</parent>
  2287. <regex>\s+poolname="(\.*)"|\s+poolname=(\.*)\s|\s+poolname=(\.*)$</regex>
  2288. <order>poolname</order>
  2289. </decoder>
  2290. <decoder name="fortinet-fortigate-fields-v7">
  2291. <parent>fortinet-fortigate-firewall</parent>
  2292. <regex>\s+port="(\.*)"|\s+port=(\.*)\s|\s+port=(\.*)$</regex>
  2293. <order>port</order>
  2294. </decoder>
  2295. <decoder name="fortinet-fortigate-fields-v7">
  2296. <parent>fortinet-fortigate-firewall</parent>
  2297. <regex>\s+portbegin="(\.*)"|\s+portbegin=(\.*)\s|\s+portbegin=(\.*)$</regex>
  2298. <order>portbegin</order>
  2299. </decoder>
  2300. <decoder name="fortinet-fortigate-fields-v7">
  2301. <parent>fortinet-fortigate-firewall</parent>
  2302. <regex>\s+portend="(\.*)"|\s+portend=(\.*)\s|\s+portend=(\.*)$</regex>
  2303. <order>portend</order>
  2304. </decoder>
  2305. <decoder name="fortinet-fortigate-fields-v7">
  2306. <parent>fortinet-fortigate-firewall</parent>
  2307. <regex>\s+probeproto="(\.*)"|\s+probeproto=(\.*)\s|\s+probeproto=(\.*)$</regex>
  2308. <order>probeproto</order>
  2309. </decoder>
  2310. <decoder name="fortinet-fortigate-fields-v7">
  2311. <parent>fortinet-fortigate-firewall</parent>
  2312. <regex>\s+process="(\.*)"|\s+process=(\.*)\s|\s+process=(\.*)$</regex>
  2313. <order>process</order>
  2314. </decoder>
  2315. <decoder name="fortinet-fortigate-fields-v7">
  2316. <parent>fortinet-fortigate-firewall</parent>
  2317. <regex>\s+processtime="(\.*)"|\s+processtime=(\.*)\s|\s+processtime=(\.*)$</regex>
  2318. <order>processtime</order>
  2319. </decoder>
  2320. <decoder name="fortinet-fortigate-fields-v7">
  2321. <parent>fortinet-fortigate-firewall</parent>
  2322. <regex>\s+product="(\.*)"|\s+product=(\.*)\s|\s+product=(\.*)$</regex>
  2323. <order>product</order>
  2324. </decoder>
  2325. <decoder name="fortinet-fortigate-fields-v7">
  2326. <parent>fortinet-fortigate-firewall</parent>
  2327. <regex>\s+profile="(\.*)"|\s+profile=(\.*)\s|\s+profile=(\.*)$</regex>
  2328. <order>profile</order>
  2329. </decoder>
  2330. <decoder name="fortinet-fortigate-fields-v7">
  2331. <parent>fortinet-fortigate-firewall</parent>
  2332. <regex>\s+profiletype="(\.*)"|\s+profiletype=(\.*)\s|\s+profiletype=(\.*)$</regex>
  2333. <order>profiletype</order>
  2334. </decoder>
  2335. <decoder name="fortinet-fortigate-fields-v7">
  2336. <parent>fortinet-fortigate-firewall</parent>
  2337. <regex>\s+proto="(\.*)"|\s+proto=(\.*)\s|\s+proto=(\.*)$</regex>
  2338. <order>proto</order>
  2339. </decoder>
  2340. <decoder name="fortinet-fortigate-fields-v7">
  2341. <parent>fortinet-fortigate-firewall</parent>
  2342. <regex>\s+protocol="(\.*)"|\s+protocol=(\.*)\s|\s+protocol=(\.*)$</regex>
  2343. <order>protocol</order>
  2344. </decoder>
  2345. <decoder name="fortinet-fortigate-fields-v7">
  2346. <parent>fortinet-fortigate-firewall</parent>
  2347. <regex>\s+proxyapptype="(\.*)"|\s+proxyapptype=(\.*)\s|\s+proxyapptype=(\.*)$</regex>
  2348. <order>proxyapptype</order>
  2349. </decoder>
  2350. <decoder name="fortinet-fortigate-fields-v7">
  2351. <parent>fortinet-fortigate-firewall</parent>
  2352. <regex>\s+psrcport="(\.*)"|\s+psrcport=(\.*)\s|\s+psrcport=(\.*)$</regex>
  2353. <order>psrcport</order>
  2354. </decoder>
  2355. <decoder name="fortinet-fortigate-fields-v7">
  2356. <parent>fortinet-fortigate-firewall</parent>
  2357. <regex>\s+qclass="(\.*)"|\s+qclass=(\.*)\s|\s+qclass=(\.*)$</regex>
  2358. <order>qclass</order>
  2359. </decoder>
  2360. <decoder name="fortinet-fortigate-fields-v7">
  2361. <parent>fortinet-fortigate-firewall</parent>
  2362. <regex>\s+qname="(\.*)"|\s+qname=(\.*)\s|\s+qname=(\.*)$</regex>
  2363. <order>qname</order>
  2364. </decoder>
  2365. <decoder name="fortinet-fortigate-fields-v7">
  2366. <parent>fortinet-fortigate-firewall</parent>
  2367. <regex>\s+qtype="(\.*)"|\s+qtype=(\.*)\s|\s+qtype=(\.*)$</regex>
  2368. <order>qtype</order>
  2369. </decoder>
  2370. <decoder name="fortinet-fortigate-fields-v7">
  2371. <parent>fortinet-fortigate-firewall</parent>
  2372. <regex>\s+qtypeval="(\.*)"|\s+qtypeval=(\.*)\s|\s+qtypeval=(\.*)$</regex>
  2373. <order>qtypeval</order>
  2374. </decoder>
  2375. <decoder name="fortinet-fortigate-fields-v7">
  2376. <parent>fortinet-fortigate-firewall</parent>
  2377. <regex>\s+quarskip="(\.*)"|\s+quarskip=(\.*)\s|\s+quarskip=(\.*)$</regex>
  2378. <order>quarskip</order>
  2379. </decoder>
  2380. <decoder name="fortinet-fortigate-fields-v7">
  2381. <parent>fortinet-fortigate-firewall</parent>
  2382. <regex>\s+quotaexceeded="(\.*)"|\s+quotaexceeded=(\.*)\s|\s+quotaexceeded=(\.*)$</regex>
  2383. <order>quotaexceeded</order>
  2384. </decoder>
  2385. <decoder name="fortinet-fortigate-fields-v7">
  2386. <parent>fortinet-fortigate-firewall</parent>
  2387. <regex>\s+quotamax="(\.*)"|\s+quotamax=(\.*)\s|\s+quotamax=(\.*)$</regex>
  2388. <order>quotamax</order>
  2389. </decoder>
  2390. <decoder name="fortinet-fortigate-fields-v7">
  2391. <parent>fortinet-fortigate-firewall</parent>
  2392. <regex>\s+quotatype="(\.*)"|\s+quotatype=(\.*)\s|\s+quotatype=(\.*)$</regex>
  2393. <order>quotatype</order>
  2394. </decoder>
  2395. <decoder name="fortinet-fortigate-fields-v7">
  2396. <parent>fortinet-fortigate-firewall</parent>
  2397. <regex>\s+quotaused="(\.*)"|\s+quotaused=(\.*)\s|\s+quotaused=(\.*)$</regex>
  2398. <order>quotaused</order>
  2399. </decoder>
  2400. <decoder name="fortinet-fortigate-fields-v7">
  2401. <parent>fortinet-fortigate-firewall</parent>
  2402. <regex>\s+radioband="(\.*)"|\s+radioband=(\.*)\s|\s+radioband=(\.*)$</regex>
  2403. <order>radioband</order>
  2404. </decoder>
  2405. <decoder name="fortinet-fortigate-fields-v7">
  2406. <parent>fortinet-fortigate-firewall</parent>
  2407. <regex>\s+radioid="(\.*)"|\s+radioid=(\.*)\s|\s+radioid=(\.*)$</regex>
  2408. <order>radioid</order>
  2409. </decoder>
  2410. <decoder name="fortinet-fortigate-fields-v7">
  2411. <parent>fortinet-fortigate-firewall</parent>
  2412. <regex>\s+radioidclosest="(\.*)"|\s+radioidclosest=(\.*)\s|\s+radioidclosest=(\.*)$</regex>
  2413. <order>radioidclosest</order>
  2414. </decoder>
  2415. <decoder name="fortinet-fortigate-fields-v7">
  2416. <parent>fortinet-fortigate-firewall</parent>
  2417. <regex>\s+radioiddetected="(\.*)"|\s+radioiddetected=(\.*)\s|\s+radioiddetected=(\.*)$</regex>
  2418. <order>radioiddetected</order>
  2419. </decoder>
  2420. <decoder name="fortinet-fortigate-fields-v7">
  2421. <parent>fortinet-fortigate-firewall</parent>
  2422. <regex>\s+rai="(\.*)"|\s+rai=(\.*)\s|\s+rai=(\.*)$</regex>
  2423. <order>rai</order>
  2424. </decoder>
  2425. <decoder name="fortinet-fortigate-fields-v7">
  2426. <parent>fortinet-fortigate-firewall</parent>
  2427. <regex>\s+rat="(\.*)"|\s+rat=(\.*)\s|\s+rat=(\.*)$</regex>
  2428. <order>rat</order>
  2429. </decoder>
  2430. <decoder name="fortinet-fortigate-fields-v7">
  2431. <parent>fortinet-fortigate-firewall</parent>
  2432. <regex>\s+rate="(\.*)"|\s+rate=(\.*)\s|\s+rate=(\.*)$</regex>
  2433. <order>rate</order>
  2434. </decoder>
  2435. <decoder name="fortinet-fortigate-fields-v7">
  2436. <parent>fortinet-fortigate-firewall</parent>
  2437. <regex>\s+ratemethod="(\.*)"|\s+ratemethod=(\.*)\s|\s+ratemethod=(\.*)$</regex>
  2438. <order>ratemethod</order>
  2439. </decoder>
  2440. <decoder name="fortinet-fortigate-fields-v7">
  2441. <parent>fortinet-fortigate-firewall</parent>
  2442. <regex>\s+rawdata="(\.*)"|\s+rawdata=(\.*)\s|\s+rawdata=(\.*)$</regex>
  2443. <order>rawdata</order>
  2444. </decoder>
  2445. <decoder name="fortinet-fortigate-fields-v7">
  2446. <parent>fortinet-fortigate-firewall</parent>
  2447. <regex>\s+rawdataid="(\.*)"|\s+rawdataid=(\.*)\s|\s+rawdataid=(\.*)$</regex>
  2448. <order>rawdataid</order>
  2449. </decoder>
  2450. <decoder name="fortinet-fortigate-fields-v7">
  2451. <parent>fortinet-fortigate-firewall</parent>
  2452. <regex>\s+rcode="(\.*)"|\s+rcode=(\.*)\s|\s+rcode=(\.*)$</regex>
  2453. <order>rcode</order>
  2454. </decoder>
  2455. <decoder name="fortinet-fortigate-fields-v7">
  2456. <parent>fortinet-fortigate-firewall</parent>
  2457. <regex>\s+rcvdbyte="(\.*)"|\s+rcvdbyte=(\.*)\s|\s+rcvdbyte=(\.*)$</regex>
  2458. <order>rcvdbyte</order>
  2459. </decoder>
  2460. <decoder name="fortinet-fortigate-fields-v7">
  2461. <parent>fortinet-fortigate-firewall</parent>
  2462. <regex>\s+rcvddelta="(\.*)"|\s+rcvddelta=(\.*)\s|\s+rcvddelta=(\.*)$</regex>
  2463. <order>rcvddelta</order>
  2464. </decoder>
  2465. <decoder name="fortinet-fortigate-fields-v7">
  2466. <parent>fortinet-fortigate-firewall</parent>
  2467. <regex>\s+rcvdpkt="(\.*)"|\s+rcvdpkt=(\.*)\s|\s+rcvdpkt=(\.*)$</regex>
  2468. <order>rcvdpkt</order>
  2469. </decoder>
  2470. <decoder name="fortinet-fortigate-fields-v7">
  2471. <parent>fortinet-fortigate-firewall</parent>
  2472. <regex>\s+rcvdpktdelta="(\.*)"|\s+rcvdpktdelta=(\.*)\s|\s+rcvdpktdelta=(\.*)$</regex>
  2473. <order>rcvdpktdelta</order>
  2474. </decoder>
  2475. <decoder name="fortinet-fortigate-fields-v7">
  2476. <parent>fortinet-fortigate-firewall</parent>
  2477. <regex>\s+realserverid="(\.*)"|\s+realserverid=(\.*)\s|\s+realserverid=(\.*)$</regex>
  2478. <order>realserverid</order>
  2479. </decoder>
  2480. <decoder name="fortinet-fortigate-fields-v7">
  2481. <parent>fortinet-fortigate-firewall</parent>
  2482. <regex>\s+reason="(\.*)"|\s+reason=(\.*)\s|\s+reason=(\.*)$</regex>
  2483. <order>reason</order>
  2484. </decoder>
  2485. <decoder name="fortinet-fortigate-fields-v7">
  2486. <parent>fortinet-fortigate-firewall</parent>
  2487. <regex>\s+received="(\.*)"|\s+received=(\.*)\s|\s+received=(\.*)$</regex>
  2488. <order>received</order>
  2489. </decoder>
  2490. <decoder name="fortinet-fortigate-fields-v7">
  2491. <parent>fortinet-fortigate-firewall</parent>
  2492. <regex>\s+receivedsignature="(\.*)"|\s+receivedsignature=(\.*)\s|\s+receivedsignature=(\.*)$</regex>
  2493. <order>receivedsignature</order>
  2494. </decoder>
  2495. <decoder name="fortinet-fortigate-fields-v7">
  2496. <parent>fortinet-fortigate-firewall</parent>
  2497. <regex>\s+recipient="(\.*)"|\s+recipient=(\.*)\s|\s+recipient=(\.*)$</regex>
  2498. <order>recipient</order>
  2499. </decoder>
  2500. <decoder name="fortinet-fortigate-fields-v7">
  2501. <parent>fortinet-fortigate-firewall</parent>
  2502. <regex>\s+red="(\.*)"|\s+red=(\.*)\s|\s+red=(\.*)$</regex>
  2503. <order>red</order>
  2504. </decoder>
  2505. <decoder name="fortinet-fortigate-fields-v7">
  2506. <parent>fortinet-fortigate-firewall</parent>
  2507. <regex>\s+ref="(\.*)"|\s+ref=(\.*)\s|\s+ref=(\.*)$</regex>
  2508. <order>ref</order>
  2509. </decoder>
  2510. <decoder name="fortinet-fortigate-fields-v7">
  2511. <parent>fortinet-fortigate-firewall</parent>
  2512. <regex>\s+referralurl="(\.*)"|\s+referralurl=(\.*)\s|\s+referralurl=(\.*)$</regex>
  2513. <order>referralurl</order>
  2514. </decoder>
  2515. <decoder name="fortinet-fortigate-fields-v7">
  2516. <parent>fortinet-fortigate-firewall</parent>
  2517. <regex>\s+remip="(\.*)"|\s+remip=(\.*)\s|\s+remip=(\.*)$</regex>
  2518. <order>remip</order>
  2519. </decoder>
  2520. <decoder name="fortinet-fortigate-fields-v7">
  2521. <parent>fortinet-fortigate-firewall</parent>
  2522. <regex>\s+remote="(\.*)"|\s+remote=(\.*)\s|\s+remote=(\.*)$</regex>
  2523. <order>remote</order>
  2524. </decoder>
  2525. <decoder name="fortinet-fortigate-fields-v7">
  2526. <parent>fortinet-fortigate-firewall</parent>
  2527. <regex>\s+remotetunnelid="(\.*)"|\s+remotetunnelid=(\.*)\s|\s+remotetunnelid=(\.*)$</regex>
  2528. <order>remotetunnelid</order>
  2529. </decoder>
  2530. <decoder name="fortinet-fortigate-fields-v7">
  2531. <parent>fortinet-fortigate-firewall</parent>
  2532. <regex>\s+remotewtptime="(\.*)"|\s+remotewtptime=(\.*)\s|\s+remotewtptime=(\.*)$</regex>
  2533. <order>remotewtptime</order>
  2534. </decoder>
  2535. <decoder name="fortinet-fortigate-fields-v7">
  2536. <parent>fortinet-fortigate-firewall</parent>
  2537. <regex>\s+remport="(\.*)"|\s+remport=(\.*)\s|\s+remport=(\.*)$</regex>
  2538. <order>remport</order>
  2539. </decoder>
  2540. <decoder name="fortinet-fortigate-fields-v7">
  2541. <parent>fortinet-fortigate-firewall</parent>
  2542. <regex>\s+replydstintf="(\.*)"|\s+replydstintf=(\.*)\s|\s+replydstintf=(\.*)$</regex>
  2543. <order>replydstintf</order>
  2544. </decoder>
  2545. <decoder name="fortinet-fortigate-fields-v7">
  2546. <parent>fortinet-fortigate-firewall</parent>
  2547. <regex>\s+replysrcintf="(\.*)"|\s+replysrcintf=(\.*)\s|\s+replysrcintf=(\.*)$</regex>
  2548. <order>replysrcintf</order>
  2549. </decoder>
  2550. <decoder name="fortinet-fortigate-fields-v7">
  2551. <parent>fortinet-fortigate-firewall</parent>
  2552. <regex>\s+reporttype="(\.*)"|\s+reporttype=(\.*)\s|\s+reporttype=(\.*)$</regex>
  2553. <order>reporttype</order>
  2554. </decoder>
  2555. <decoder name="fortinet-fortigate-fields-v7">
  2556. <parent>fortinet-fortigate-firewall</parent>
  2557. <regex>\s+reqtype="(\.*)"|\s+reqtype=(\.*)\s|\s+reqtype=(\.*)$</regex>
  2558. <order>reqtype</order>
  2559. </decoder>
  2560. <decoder name="fortinet-fortigate-fields-v7">
  2561. <parent>fortinet-fortigate-firewall</parent>
  2562. <regex>\s+request_name="(\.*)"|\s+request_name=(\.*)\s|\s+request_name=(\.*)$</regex>
  2563. <order>request_name</order>
  2564. </decoder>
  2565. <decoder name="fortinet-fortigate-fields-v7">
  2566. <parent>fortinet-fortigate-firewall</parent>
  2567. <regex>\s+result="(\.*)"|\s+result=(\.*)\s|\s+result=(\.*)$</regex>
  2568. <order>result</order>
  2569. </decoder>
  2570. <decoder name="fortinet-fortigate-fields-v7">
  2571. <parent>fortinet-fortigate-firewall</parent>
  2572. <regex>\s+role="(\.*)"|\s+role=(\.*)\s|\s+role=(\.*)$</regex>
  2573. <order>role</order>
  2574. </decoder>
  2575. <decoder name="fortinet-fortigate-fields-v7">
  2576. <parent>fortinet-fortigate-firewall</parent>
  2577. <regex>\s+rssi="(\.*)"|\s+rssi=(\.*)\s|\s+rssi=(\.*)$</regex>
  2578. <order>rssi</order>
  2579. </decoder>
  2580. <decoder name="fortinet-fortigate-fields-v7">
  2581. <parent>fortinet-fortigate-firewall</parent>
  2582. <regex>\s+rsso_key="(\.*)"|\s+rsso_key=(\.*)\s|\s+rsso_key=(\.*)$</regex>
  2583. <order>rsso_key</order>
  2584. </decoder>
  2585. <decoder name="fortinet-fortigate-fields-v7">
  2586. <parent>fortinet-fortigate-firewall</parent>
  2587. <regex>\s+ruleid="(\.*)"|\s+ruleid=(\.*)\s|\s+ruleid=(\.*)$</regex>
  2588. <order>ruleid</order>
  2589. </decoder>
  2590. <decoder name="fortinet-fortigate-fields-v7">
  2591. <parent>fortinet-fortigate-firewall</parent>
  2592. <regex>\s+rulename="(\.*)"|\s+rulename=(\.*)\s|\s+rulename=(\.*)$</regex>
  2593. <order>rulename</order>
  2594. </decoder>
  2595. <decoder name="fortinet-fortigate-fields-v7">
  2596. <parent>fortinet-fortigate-firewall</parent>
  2597. <regex>\s+saasapp="(\.*)"|\s+saasapp=(\.*)\s|\s+saasapp=(\.*)$</regex>
  2598. <order>saasapp</order>
  2599. </decoder>
  2600. <decoder name="fortinet-fortigate-fields-v7">
  2601. <parent>fortinet-fortigate-firewall</parent>
  2602. <regex>\s+saasname="(\.*)"|\s+saasname=(\.*)\s|\s+saasname=(\.*)$</regex>
  2603. <order>saasname</order>
  2604. </decoder>
  2605. <decoder name="fortinet-fortigate-fields-v7">
  2606. <parent>fortinet-fortigate-firewall</parent>
  2607. <regex>\s+saddr="(\.*)"|\s+saddr=(\.*)\s|\s+saddr=(\.*)$</regex>
  2608. <order>saddr</order>
  2609. </decoder>
  2610. <decoder name="fortinet-fortigate-fields-v7">
  2611. <parent>fortinet-fortigate-firewall</parent>
  2612. <regex>\s+san="(\.*)"|\s+san=(\.*)\s|\s+san=(\.*)$</regex>
  2613. <order>san</order>
  2614. </decoder>
  2615. <decoder name="fortinet-fortigate-fields-v7">
  2616. <parent>fortinet-fortigate-firewall</parent>
  2617. <regex>\s+scantime="(\.*)"|\s+scantime=(\.*)\s|\s+scantime=(\.*)$</regex>
  2618. <order>scantime</order>
  2619. </decoder>
  2620. <decoder name="fortinet-fortigate-fields-v7">
  2621. <parent>fortinet-fortigate-firewall</parent>
  2622. <regex>\s+scertcname="(\.*)"|\s+scertcname=(\.*)\s|\s+scertcname=(\.*)$</regex>
  2623. <order>scertcname</order>
  2624. </decoder>
  2625. <decoder name="fortinet-fortigate-fields-v7">
  2626. <parent>fortinet-fortigate-firewall</parent>
  2627. <regex>\s+scertissuer="(\.*)"|\s+scertissuer=(\.*)\s|\s+scertissuer=(\.*)$</regex>
  2628. <order>scertissuer</order>
  2629. </decoder>
  2630. <decoder name="fortinet-fortigate-fields-v7">
  2631. <parent>fortinet-fortigate-firewall</parent>
  2632. <regex>\s+scope="(\.*)"|\s+scope=(\.*)\s|\s+scope=(\.*)$</regex>
  2633. <order>scope</order>
  2634. </decoder>
  2635. <decoder name="fortinet-fortigate-fields-v7">
  2636. <parent>fortinet-fortigate-firewall</parent>
  2637. <regex>\s+security="(\.*)"|\s+security=(\.*)\s|\s+security=(\.*)$</regex>
  2638. <order>security</order>
  2639. </decoder>
  2640. <decoder name="fortinet-fortigate-fields-v7">
  2641. <parent>fortinet-fortigate-firewall</parent>
  2642. <regex>\s+selection="(\.*)"|\s+selection=(\.*)\s|\s+selection=(\.*)$</regex>
  2643. <order>selection</order>
  2644. </decoder>
  2645. <decoder name="fortinet-fortigate-fields-v7">
  2646. <parent>fortinet-fortigate-firewall</parent>
  2647. <regex>\s+sender="(\.*)"|\s+sender=(\.*)\s|\s+sender=(\.*)$</regex>
  2648. <order>sender</order>
  2649. </decoder>
  2650. <decoder name="fortinet-fortigate-fields-v7">
  2651. <parent>fortinet-fortigate-firewall</parent>
  2652. <regex>\s+sensitivity="(\.*)"|\s+sensitivity=(\.*)\s|\s+sensitivity=(\.*)$</regex>
  2653. <order>sensitivity</order>
  2654. </decoder>
  2655. <decoder name="fortinet-fortigate-fields-v7">
  2656. <parent>fortinet-fortigate-firewall</parent>
  2657. <regex>\s+sensor="(\.*)"|\s+sensor=(\.*)\s|\s+sensor=(\.*)$</regex>
  2658. <order>sensor</order>
  2659. </decoder>
  2660. <decoder name="fortinet-fortigate-fields-v7">
  2661. <parent>fortinet-fortigate-firewall</parent>
  2662. <regex>\s+sentbyte="(\.*)"|\s+sentbyte=(\.*)\s|\s+sentbyte=(\.*)$</regex>
  2663. <order>sentbyte</order>
  2664. </decoder>
  2665. <decoder name="fortinet-fortigate-fields-v7">
  2666. <parent>fortinet-fortigate-firewall</parent>
  2667. <regex>\s+sentdelta="(\.*)"|\s+sentdelta=(\.*)\s|\s+sentdelta=(\.*)$</regex>
  2668. <order>sentdelta</order>
  2669. </decoder>
  2670. <decoder name="fortinet-fortigate-fields-v7">
  2671. <parent>fortinet-fortigate-firewall</parent>
  2672. <regex>\s+sentpkt="(\.*)"|\s+sentpkt=(\.*)\s|\s+sentpkt=(\.*)$</regex>
  2673. <order>sentpkt</order>
  2674. </decoder>
  2675. <decoder name="fortinet-fortigate-fields-v7">
  2676. <parent>fortinet-fortigate-firewall</parent>
  2677. <regex>\s+sentpktdelta="(\.*)"|\s+sentpktdelta=(\.*)\s|\s+sentpktdelta=(\.*)$</regex>
  2678. <order>sentpktdelta</order>
  2679. </decoder>
  2680. <decoder name="fortinet-fortigate-fields-v7">
  2681. <parent>fortinet-fortigate-firewall</parent>
  2682. <regex>\s+seq="(\.*)"|\s+seq=(\.*)\s|\s+seq=(\.*)$</regex>
  2683. <order>seq</order>
  2684. </decoder>
  2685. <decoder name="fortinet-fortigate-fields-v7">
  2686. <parent>fortinet-fortigate-firewall</parent>
  2687. <regex>\s+seqnum="(\.*)"|\s+seqnum=(\.*)\s|\s+seqnum=(\.*)$</regex>
  2688. <order>seqnum</order>
  2689. </decoder>
  2690. <decoder name="fortinet-fortigate-fields-v7">
  2691. <parent>fortinet-fortigate-firewall</parent>
  2692. <regex>\s+serial="(\.*)"|\s+serial=(\.*)\s|\s+serial=(\.*)$</regex>
  2693. <order>serial</order>
  2694. </decoder>
  2695. <decoder name="fortinet-fortigate-fields-v7">
  2696. <parent>fortinet-fortigate-firewall</parent>
  2697. <regex>\s+serialno="(\.*)"|\s+serialno=(\.*)\s|\s+serialno=(\.*)$</regex>
  2698. <order>serialno</order>
  2699. </decoder>
  2700. <decoder name="fortinet-fortigate-fields-v7">
  2701. <parent>fortinet-fortigate-firewall</parent>
  2702. <regex>\s+server="(\.*)"|\s+server=(\.*)\s|\s+server=(\.*)$</regex>
  2703. <order>server</order>
  2704. </decoder>
  2705. <decoder name="fortinet-fortigate-fields-v7">
  2706. <parent>fortinet-fortigate-firewall</parent>
  2707. <regex>\s+serveraddr="(\.*)"|\s+serveraddr=(\.*)\s|\s+serveraddr=(\.*)$</regex>
  2708. <order>serveraddr</order>
  2709. </decoder>
  2710. <decoder name="fortinet-fortigate-fields-v7">
  2711. <parent>fortinet-fortigate-firewall</parent>
  2712. <regex>\s+servername="(\.*)"|\s+servername=(\.*)\s|\s+servername=(\.*)$</regex>
  2713. <order>servername</order>
  2714. </decoder>
  2715. <decoder name="fortinet-fortigate-fields-v7">
  2716. <parent>fortinet-fortigate-firewall</parent>
  2717. <regex>\s+serverresponsetime="(\.*)"|\s+serverresponsetime=(\.*)\s|\s+serverresponsetime=(\.*)$</regex>
  2718. <order>serverresponsetime</order>
  2719. </decoder>
  2720. <decoder name="fortinet-fortigate-fields-v7">
  2721. <parent>fortinet-fortigate-firewall</parent>
  2722. <regex>\s+service="(\.*)"|\s+service=(\.*)\s|\s+service=(\.*)$</regex>
  2723. <order>service</order>
  2724. </decoder>
  2725. <decoder name="fortinet-fortigate-fields-v7">
  2726. <parent>fortinet-fortigate-firewall</parent>
  2727. <regex>\s+serviceid="(\.*)"|\s+serviceid=(\.*)\s|\s+serviceid=(\.*)$</regex>
  2728. <order>serviceid</order>
  2729. </decoder>
  2730. <decoder name="fortinet-fortigate-fields-v7">
  2731. <parent>fortinet-fortigate-firewall</parent>
  2732. <regex>\s+session_id="(\.*)"|\s+session_id=(\.*)\s|\s+session_id=(\.*)$</regex>
  2733. <order>session_id</order>
  2734. </decoder>
  2735. <decoder name="fortinet-fortigate-fields-v7">
  2736. <parent>fortinet-fortigate-firewall</parent>
  2737. <regex>\s+sessionid="(\.*)"|\s+sessionid=(\.*)\s|\s+sessionid=(\.*)$</regex>
  2738. <order>sessionid</order>
  2739. </decoder>
  2740. <decoder name="fortinet-fortigate-fields-v7">
  2741. <parent>fortinet-fortigate-firewall</parent>
  2742. <regex>\s+setuprate="(\.*)"|\s+setuprate=(\.*)\s|\s+setuprate=(\.*)$</regex>
  2743. <order>setuprate</order>
  2744. </decoder>
  2745. <decoder name="fortinet-fortigate-fields-v7">
  2746. <parent>fortinet-fortigate-firewall</parent>
  2747. <regex>\s+severity="(\.*)"|\s+severity=(\.*)\s|\s+severity=(\.*)$</regex>
  2748. <order>severity</order>
  2749. </decoder>
  2750. <decoder name="fortinet-fortigate-fields-v7">
  2751. <parent>fortinet-fortigate-firewall</parent>
  2752. <regex>\s+shaperdroprcvdbyte="(\.*)"|\s+shaperdroprcvdbyte=(\.*)\s|\s+shaperdroprcvdbyte=(\.*)$</regex>
  2753. <order>shaperdroprcvdbyte</order>
  2754. </decoder>
  2755. <decoder name="fortinet-fortigate-fields-v7">
  2756. <parent>fortinet-fortigate-firewall</parent>
  2757. <regex>\s+shaperdropsentbyte="(\.*)"|\s+shaperdropsentbyte=(\.*)\s|\s+shaperdropsentbyte=(\.*)$</regex>
  2758. <order>shaperdropsentbyte</order>
  2759. </decoder>
  2760. <decoder name="fortinet-fortigate-fields-v7">
  2761. <parent>fortinet-fortigate-firewall</parent>
  2762. <regex>\s+shaperperipdropbyte="(\.*)"|\s+shaperperipdropbyte=(\.*)\s|\s+shaperperipdropbyte=(\.*)$</regex>
  2763. <order>shaperperipdropbyte</order>
  2764. </decoder>
  2765. <decoder name="fortinet-fortigate-fields-v7">
  2766. <parent>fortinet-fortigate-firewall</parent>
  2767. <regex>\s+shaperperipname="(\.*)"|\s+shaperperipname=(\.*)\s|\s+shaperperipname=(\.*)$</regex>
  2768. <order>shaperperipname</order>
  2769. </decoder>
  2770. <decoder name="fortinet-fortigate-fields-v7">
  2771. <parent>fortinet-fortigate-firewall</parent>
  2772. <regex>\s+shaperrcvdname="(\.*)"|\s+shaperrcvdname=(\.*)\s|\s+shaperrcvdname=(\.*)$</regex>
  2773. <order>shaperrcvdname</order>
  2774. </decoder>
  2775. <decoder name="fortinet-fortigate-fields-v7">
  2776. <parent>fortinet-fortigate-firewall</parent>
  2777. <regex>\s+shapersentname="(\.*)"|\s+shapersentname=(\.*)\s|\s+shapersentname=(\.*)$</regex>
  2778. <order>shapersentname</order>
  2779. </decoder>
  2780. <decoder name="fortinet-fortigate-fields-v7">
  2781. <parent>fortinet-fortigate-firewall</parent>
  2782. <regex>\s+shapingpolicyid="(\.*)"|\s+shapingpolicyid=(\.*)\s|\s+shapingpolicyid=(\.*)$</regex>
  2783. <order>shapingpolicyid</order>
  2784. </decoder>
  2785. <decoder name="fortinet-fortigate-fields-v7">
  2786. <parent>fortinet-fortigate-firewall</parent>
  2787. <regex>\s+shapingpolicyname="(\.*)"|\s+shapingpolicyname=(\.*)\s|\s+shapingpolicyname=(\.*)$</regex>
  2788. <order>shapingpolicyname</order>
  2789. </decoder>
  2790. <decoder name="fortinet-fortigate-fields-v7">
  2791. <parent>fortinet-fortigate-firewall</parent>
  2792. <regex>\s+sharename="(\.*)"|\s+sharename=(\.*)\s|\s+sharename=(\.*)$</regex>
  2793. <order>sharename</order>
  2794. </decoder>
  2795. <decoder name="fortinet-fortigate-fields-v7">
  2796. <parent>fortinet-fortigate-firewall</parent>
  2797. <regex>\s+signal="(\.*)"|\s+signal=(\.*)\s|\s+signal=(\.*)$</regex>
  2798. <order>signal</order>
  2799. </decoder>
  2800. <decoder name="fortinet-fortigate-fields-v7">
  2801. <parent>fortinet-fortigate-firewall</parent>
  2802. <regex>\s+size="(\.*)"|\s+size=(\.*)\s|\s+size=(\.*)$</regex>
  2803. <order>size</order>
  2804. </decoder>
  2805. <decoder name="fortinet-fortigate-fields-v7">
  2806. <parent>fortinet-fortigate-firewall</parent>
  2807. <regex>\s+ski="(\.*)"|\s+ski=(\.*)\s|\s+ski=(\.*)$</regex>
  2808. <order>ski</order>
  2809. </decoder>
  2810. <decoder name="fortinet-fortigate-fields-v7">
  2811. <parent>fortinet-fortigate-firewall</parent>
  2812. <regex>\s+slamap="(\.*)"|\s+slamap=(\.*)\s|\s+slamap=(\.*)$</regex>
  2813. <order>slamap</order>
  2814. </decoder>
  2815. <decoder name="fortinet-fortigate-fields-v7">
  2816. <parent>fortinet-fortigate-firewall</parent>
  2817. <regex>\s+slatargetid="(\.*)"|\s+slatargetid=(\.*)\s|\s+slatargetid=(\.*)$</regex>
  2818. <order>slatargetid</order>
  2819. </decoder>
  2820. <decoder name="fortinet-fortigate-fields-v7">
  2821. <parent>fortinet-fortigate-firewall</parent>
  2822. <regex>\s+slctdrmamode="(\.*)"|\s+slctdrmamode=(\.*)\s|\s+slctdrmamode=(\.*)$</regex>
  2823. <order>slctdrmamode</order>
  2824. </decoder>
  2825. <decoder name="fortinet-fortigate-fields-v7">
  2826. <parent>fortinet-fortigate-firewall</parent>
  2827. <regex>\s+slot="(\.*)"|\s+slot=(\.*)\s|\s+slot=(\.*)$</regex>
  2828. <order>slot</order>
  2829. </decoder>
  2830. <decoder name="fortinet-fortigate-fields-v7">
  2831. <parent>fortinet-fortigate-firewall</parent>
  2832. <regex>\s+sn="(\.*)"|\s+sn=(\.*)\s|\s+sn=(\.*)$</regex>
  2833. <order>sn</order>
  2834. </decoder>
  2835. <decoder name="fortinet-fortigate-fields-v7">
  2836. <parent>fortinet-fortigate-firewall</parent>
  2837. <regex>\s+snclosest="(\.*)"|\s+snclosest=(\.*)\s|\s+snclosest=(\.*)$</regex>
  2838. <order>snclosest</order>
  2839. </decoder>
  2840. <decoder name="fortinet-fortigate-fields-v7">
  2841. <parent>fortinet-fortigate-firewall</parent>
  2842. <regex>\s+sndetected="(\.*)"|\s+sndetected=(\.*)\s|\s+sndetected=(\.*)$</regex>
  2843. <order>sndetected</order>
  2844. </decoder>
  2845. <decoder name="fortinet-fortigate-fields-v7">
  2846. <parent>fortinet-fortigate-firewall</parent>
  2847. <regex>\s+snetwork="(\.*)"|\s+snetwork=(\.*)\s|\s+snetwork=(\.*)$</regex>
  2848. <order>snetwork</order>
  2849. </decoder>
  2850. <decoder name="fortinet-fortigate-fields-v7">
  2851. <parent>fortinet-fortigate-firewall</parent>
  2852. <regex>\s+sni="(\.*)"|\s+sni=(\.*)\s|\s+sni=(\.*)$</regex>
  2853. <order>sni</order>
  2854. </decoder>
  2855. <decoder name="fortinet-fortigate-fields-v7">
  2856. <parent>fortinet-fortigate-firewall</parent>
  2857. <regex>\s+snmeshparent="(\.*)"|\s+snmeshparent=(\.*)\s|\s+snmeshparent=(\.*)$</regex>
  2858. <order>snmeshparent</order>
  2859. </decoder>
  2860. <decoder name="fortinet-fortigate-fields-v7">
  2861. <parent>fortinet-fortigate-firewall</parent>
  2862. <regex>\s+snprev="(\.*)"|\s+snprev=(\.*)\s|\s+snprev=(\.*)$</regex>
  2863. <order>snprev</order>
  2864. </decoder>
  2865. <decoder name="fortinet-fortigate-fields-v7">
  2866. <parent>fortinet-fortigate-firewall</parent>
  2867. <regex>\s+snr="(\.*)"|\s+snr=(\.*)\s|\s+snr=(\.*)$</regex>
  2868. <order>snr</order>
  2869. </decoder>
  2870. <decoder name="fortinet-fortigate-fields-v7">
  2871. <parent>fortinet-fortigate-firewall</parent>
  2872. <regex>\s+source_mac="(\.*)"|\s+source_mac=(\.*)\s|\s+source_mac=(\.*)$</regex>
  2873. <order>source_mac</order>
  2874. </decoder>
  2875. <decoder name="fortinet-fortigate-fields-v7">
  2876. <parent>fortinet-fortigate-firewall</parent>
  2877. <regex>\s+speedtestserver="(\.*)"|\s+speedtestserver=(\.*)\s|\s+speedtestserver=(\.*)$</regex>
  2878. <order>speedtestserver</order>
  2879. </decoder>
  2880. <decoder name="fortinet-fortigate-fields-v7">
  2881. <parent>fortinet-fortigate-firewall</parent>
  2882. <regex>\s+spi="(\.*)"|\s+spi=(\.*)\s|\s+spi=(\.*)$</regex>
  2883. <order>spi</order>
  2884. </decoder>
  2885. <decoder name="fortinet-fortigate-fields-v7">
  2886. <parent>fortinet-fortigate-firewall</parent>
  2887. <regex>\s+src_int="(\.*)"|\s+src_int=(\.*)\s|\s+src_int=(\.*)$</regex>
  2888. <order>src_int</order>
  2889. </decoder>
  2890. <decoder name="fortinet-fortigate-fields-v7">
  2891. <parent>fortinet-fortigate-firewall</parent>
  2892. <regex>\s+src_port="(\.*)"|\s+src_port=(\.*)\s|\s+src_port=(\.*)$</regex>
  2893. <order>src_port</order>
  2894. </decoder>
  2895. <decoder name="fortinet-fortigate-fields-v7">
  2896. <parent>fortinet-fortigate-firewall</parent>
  2897. <regex>\s+srccity="(\.*)"|\s+srccity=(\.*)\s|\s+srccity=(\.*)$</regex>
  2898. <order>srccity</order>
  2899. </decoder>
  2900. <decoder name="fortinet-fortigate-fields-v7">
  2901. <parent>fortinet-fortigate-firewall</parent>
  2902. <regex>\s+srccountry="(\.*)"|\s+srccountry=(\.*)\s|\s+srccountry=(\.*)$</regex>
  2903. <order>srccountry</order>
  2904. </decoder>
  2905. <decoder name="fortinet-fortigate-fields-v7">
  2906. <parent>fortinet-fortigate-firewall</parent>
  2907. <regex>\s+srcdomain="(\.*)"|\s+srcdomain=(\.*)\s|\s+srcdomain=(\.*)$</regex>
  2908. <order>srcdomain</order>
  2909. </decoder>
  2910. <decoder name="fortinet-fortigate-fields-v7">
  2911. <parent>fortinet-fortigate-firewall</parent>
  2912. <regex>\s+srcfamily="(\.*)"|\s+srcfamily=(\.*)\s|\s+srcfamily=(\.*)$</regex>
  2913. <order>srcfamily</order>
  2914. </decoder>
  2915. <decoder name="fortinet-fortigate-fields-v7">
  2916. <parent>fortinet-fortigate-firewall</parent>
  2917. <regex>\s+srchwvendor="(\.*)"|\s+srchwvendor=(\.*)\s|\s+srchwvendor=(\.*)$</regex>
  2918. <order>srchwvendor</order>
  2919. </decoder>
  2920. <decoder name="fortinet-fortigate-fields-v7">
  2921. <parent>fortinet-fortigate-firewall</parent>
  2922. <regex>\s+srchwversion="(\.*)"|\s+srchwversion=(\.*)\s|\s+srchwversion=(\.*)$</regex>
  2923. <order>srchwversion</order>
  2924. </decoder>
  2925. <decoder name="fortinet-fortigate-fields-v7">
  2926. <parent>fortinet-fortigate-firewall</parent>
  2927. <regex>\s+srcinetsvc="(\.*)"|\s+srcinetsvc=(\.*)\s|\s+srcinetsvc=(\.*)$</regex>
  2928. <order>srcinetsvc</order>
  2929. </decoder>
  2930. <decoder name="fortinet-fortigate-fields-v7">
  2931. <parent>fortinet-fortigate-firewall</parent>
  2932. <regex>\s+srcintf="(\.*)"|\s+srcintf=(\.*)\s|\s+srcintf=(\.*)$</regex>
  2933. <order>srcintf</order>
  2934. </decoder>
  2935. <decoder name="fortinet-fortigate-fields-v7">
  2936. <parent>fortinet-fortigate-firewall</parent>
  2937. <regex>\s+srcintfrole="(\.*)"|\s+srcintfrole=(\.*)\s|\s+srcintfrole=(\.*)$</regex>
  2938. <order>srcintfrole</order>
  2939. </decoder>
  2940. <decoder name="fortinet-fortigate-fields-v7">
  2941. <parent>fortinet-fortigate-firewall</parent>
  2942. <regex>\s+srcip="(\.*)"|\s+srcip=(\.*)\s|\s+srcip=(\.*)$</regex>
  2943. <order>srcip</order>
  2944. </decoder>
  2945. <decoder name="fortinet-fortigate-fields-v7">
  2946. <parent>fortinet-fortigate-firewall</parent>
  2947. <regex>\s+srcmac="(\.*)"|\s+srcmac=(\.*)\s|\s+srcmac=(\.*)$</regex>
  2948. <order>srcmac</order>
  2949. </decoder>
  2950. <decoder name="fortinet-fortigate-fields-v7">
  2951. <parent>fortinet-fortigate-firewall</parent>
  2952. <regex>\s+srcmacvendor="(\.*)"|\s+srcmacvendor=(\.*)\s|\s+srcmacvendor=(\.*)$</regex>
  2953. <order>srcmacvendor</order>
  2954. </decoder>
  2955. <decoder name="fortinet-fortigate-fields-v7">
  2956. <parent>fortinet-fortigate-firewall</parent>
  2957. <regex>\s+srcname="(\.*)"|\s+srcname=(\.*)\s|\s+srcname=(\.*)$</regex>
  2958. <order>srcname</order>
  2959. </decoder>
  2960. <decoder name="fortinet-fortigate-fields-v7">
  2961. <parent>fortinet-fortigate-firewall</parent>
  2962. <regex>\s+srcport="(\.*)"|\s+srcport=(\.*)\s|\s+srcport=(\.*)$</regex>
  2963. <order>srcport</order>
  2964. </decoder>
  2965. <decoder name="fortinet-fortigate-fields-v7">
  2966. <parent>fortinet-fortigate-firewall</parent>
  2967. <regex>\s+srcregion="(\.*)"|\s+srcregion=(\.*)\s|\s+srcregion=(\.*)$</regex>
  2968. <order>srcregion</order>
  2969. </decoder>
  2970. <decoder name="fortinet-fortigate-fields-v7">
  2971. <parent>fortinet-fortigate-firewall</parent>
  2972. <regex>\s+srcremote="(\.*)"|\s+srcremote=(\.*)\s|\s+srcremote=(\.*)$</regex>
  2973. <order>srcremote</order>
  2974. </decoder>
  2975. <decoder name="fortinet-fortigate-fields-v7">
  2976. <parent>fortinet-fortigate-firewall</parent>
  2977. <regex>\s+srcreputation="(\.*)"|\s+srcreputation=(\.*)\s|\s+srcreputation=(\.*)$</regex>
  2978. <order>srcreputation</order>
  2979. </decoder>
  2980. <decoder name="fortinet-fortigate-fields-v7">
  2981. <parent>fortinet-fortigate-firewall</parent>
  2982. <regex>\s+srcserver="(\.*)"|\s+srcserver=(\.*)\s|\s+srcserver=(\.*)$</regex>
  2983. <order>srcserver</order>
  2984. </decoder>
  2985. <decoder name="fortinet-fortigate-fields-v7">
  2986. <parent>fortinet-fortigate-firewall</parent>
  2987. <regex>\s+srcssid="(\.*)"|\s+srcssid=(\.*)\s|\s+srcssid=(\.*)$</regex>
  2988. <order>srcssid</order>
  2989. </decoder>
  2990. <decoder name="fortinet-fortigate-fields-v7">
  2991. <parent>fortinet-fortigate-firewall</parent>
  2992. <regex>\s+srcswversion="(\.*)"|\s+srcswversion=(\.*)\s|\s+srcswversion=(\.*)$</regex>
  2993. <order>srcswversion</order>
  2994. </decoder>
  2995. <decoder name="fortinet-fortigate-fields-v7">
  2996. <parent>fortinet-fortigate-firewall</parent>
  2997. <regex>\s+srcthreatfeed="(\.*)"|\s+srcthreatfeed=(\.*)\s|\s+srcthreatfeed=(\.*)$</regex>
  2998. <order>srcthreatfeed</order>
  2999. </decoder>
  3000. <decoder name="fortinet-fortigate-fields-v7">
  3001. <parent>fortinet-fortigate-firewall</parent>
  3002. <regex>\s+srcuuid="(\.*)"|\s+srcuuid=(\.*)\s|\s+srcuuid=(\.*)$</regex>
  3003. <order>srcuuid</order>
  3004. </decoder>
  3005. <decoder name="fortinet-fortigate-fields-v7">
  3006. <parent>fortinet-fortigate-firewall</parent>
  3007. <regex>\s+sscname="(\.*)"|\s+sscname=(\.*)\s|\s+sscname=(\.*)$</regex>
  3008. <order>sscname</order>
  3009. </decoder>
  3010. <decoder name="fortinet-fortigate-fields-v7">
  3011. <parent>fortinet-fortigate-firewall</parent>
  3012. <regex>\s+ssh="(\.*)"|\s+ssh=(\.*)\s|\s+ssh=(\.*)$</regex>
  3013. <order>ssh</order>
  3014. </decoder>
  3015. <decoder name="fortinet-fortigate-fields-v7">
  3016. <parent>fortinet-fortigate-firewall</parent>
  3017. <regex>\s+ssid="(\.*)"|\s+ssid=(\.*)\s|\s+ssid=(\.*)$</regex>
  3018. <order>ssid</order>
  3019. </decoder>
  3020. <decoder name="fortinet-fortigate-fields-v7">
  3021. <parent>fortinet-fortigate-firewall</parent>
  3022. <regex>\s+ssl="(\.*)"|\s+ssl=(\.*)\s|\s+ssl=(\.*)$</regex>
  3023. <order>ssl</order>
  3024. </decoder>
  3025. <decoder name="fortinet-fortigate-fields-v7">
  3026. <parent>fortinet-fortigate-firewall</parent>
  3027. <regex>\s+sslaction="(\.*)"|\s+sslaction=(\.*)\s|\s+sslaction=(\.*)$</regex>
  3028. <order>sslaction</order>
  3029. </decoder>
  3030. <decoder name="fortinet-fortigate-fields-v7">
  3031. <parent>fortinet-fortigate-firewall</parent>
  3032. <regex>\s+ssllocal="(\.*)"|\s+ssllocal=(\.*)\s|\s+ssllocal=(\.*)$</regex>
  3033. <order>ssllocal</order>
  3034. </decoder>
  3035. <decoder name="fortinet-fortigate-fields-v7">
  3036. <parent>fortinet-fortigate-firewall</parent>
  3037. <regex>\s+sslremote="(\.*)"|\s+sslremote=(\.*)\s|\s+sslremote=(\.*)$</regex>
  3038. <order>sslremote</order>
  3039. </decoder>
  3040. <decoder name="fortinet-fortigate-fields-v7">
  3041. <parent>fortinet-fortigate-firewall</parent>
  3042. <regex>\s+stacount="(\.*)"|\s+stacount=(\.*)\s|\s+stacount=(\.*)$</regex>
  3043. <order>stacount</order>
  3044. </decoder>
  3045. <decoder name="fortinet-fortigate-fields-v7">
  3046. <parent>fortinet-fortigate-firewall</parent>
  3047. <regex>\s+stage="(\.*)"|\s+stage=(\.*)\s|\s+stage=(\.*)$</regex>
  3048. <order>stage</order>
  3049. </decoder>
  3050. <decoder name="fortinet-fortigate-fields-v7">
  3051. <parent>fortinet-fortigate-firewall</parent>
  3052. <regex>\s+stamac="(\.*)"|\s+stamac=(\.*)\s|\s+stamac=(\.*)$</regex>
  3053. <order>stamac</order>
  3054. </decoder>
  3055. <decoder name="fortinet-fortigate-fields-v7">
  3056. <parent>fortinet-fortigate-firewall</parent>
  3057. <regex>\s+state="(\.*)"|\s+state=(\.*)\s|\s+state=(\.*)$</regex>
  3058. <order>state</order>
  3059. </decoder>
  3060. <decoder name="fortinet-fortigate-fields-v7">
  3061. <parent>fortinet-fortigate-firewall</parent>
  3062. <regex>\s+status="(\.*)"|\s+status=(\.*)\s|\s+status=(\.*)$</regex>
  3063. <order>status</order>
  3064. </decoder>
  3065. <decoder name="fortinet-fortigate-fields-v7">
  3066. <parent>fortinet-fortigate-firewall</parent>
  3067. <regex>\s+stitch="(\.*)"|\s+stitch=(\.*)\s|\s+stitch=(\.*)$</regex>
  3068. <order>stitch</order>
  3069. </decoder>
  3070. <decoder name="fortinet-fortigate-fields-v7">
  3071. <parent>fortinet-fortigate-firewall</parent>
  3072. <regex>\s+stitchaction="(\.*)"|\s+stitchaction=(\.*)\s|\s+stitchaction=(\.*)$</regex>
  3073. <order>stitchaction</order>
  3074. </decoder>
  3075. <decoder name="fortinet-fortigate-fields-v7">
  3076. <parent>fortinet-fortigate-firewall</parent>
  3077. <regex>\s+subject="(\.*)"|\s+subject=(\.*)\s|\s+subject=(\.*)$</regex>
  3078. <order>subject</order>
  3079. </decoder>
  3080. <decoder name="fortinet-fortigate-fields-v7">
  3081. <parent>fortinet-fortigate-firewall</parent>
  3082. <regex>\s+submodule="(\.*)"|\s+submodule=(\.*)\s|\s+submodule=(\.*)$</regex>
  3083. <order>submodule</order>
  3084. </decoder>
  3085. <decoder name="fortinet-fortigate-fields-v7">
  3086. <parent>fortinet-fortigate-firewall</parent>
  3087. <regex>\s+subservice="(\.*)"|\s+subservice=(\.*)\s|\s+subservice=(\.*)$</regex>
  3088. <order>subservice</order>
  3089. </decoder>
  3090. <decoder name="fortinet-fortigate-fields-v7">
  3091. <parent>fortinet-fortigate-firewall</parent>
  3092. <regex>\s+subtype="(\.*)"|\s+subtype=(\.*)\s|\s+subtype=(\.*)$</regex>
  3093. <order>subtype</order>
  3094. </decoder>
  3095. <decoder name="fortinet-fortigate-fields-v7">
  3096. <parent>fortinet-fortigate-firewall</parent>
  3097. <regex>\s+successcount="(\.*)"|\s+successcount=(\.*)\s|\s+successcount=(\.*)$</regex>
  3098. <order>successcount</order>
  3099. </decoder>
  3100. <decoder name="fortinet-fortigate-fields-v7">
  3101. <parent>fortinet-fortigate-firewall</parent>
  3102. <regex>\s+switchaclid="(\.*)"|\s+switchaclid=(\.*)\s|\s+switchaclid=(\.*)$</regex>
  3103. <order>switchaclid</order>
  3104. </decoder>
  3105. <decoder name="fortinet-fortigate-fields-v7">
  3106. <parent>fortinet-fortigate-firewall</parent>
  3107. <regex>\s+switchautoip="(\.*)"|\s+switchautoip=(\.*)\s|\s+switchautoip=(\.*)$</regex>
  3108. <order>switchautoip</order>
  3109. </decoder>
  3110. <decoder name="fortinet-fortigate-fields-v7">
  3111. <parent>fortinet-fortigate-firewall</parent>
  3112. <regex>\s+switchid="(\.*)"|\s+switchid=(\.*)\s|\s+switchid=(\.*)$</regex>
  3113. <order>switchid</order>
  3114. </decoder>
  3115. <decoder name="fortinet-fortigate-fields-v7">
  3116. <parent>fortinet-fortigate-firewall</parent>
  3117. <regex>\s+switchinterface="(\.*)"|\s+switchinterface=(\.*)\s|\s+switchinterface=(\.*)$</regex>
  3118. <order>switchinterface</order>
  3119. </decoder>
  3120. <decoder name="fortinet-fortigate-fields-v7">
  3121. <parent>fortinet-fortigate-firewall</parent>
  3122. <regex>\s+switchl="(\.*)"|\s+switchl=(\.*)\s|\s+switchl=(\.*)$</regex>
  3123. <order>switchl</order>
  3124. </decoder>
  3125. <decoder name="fortinet-fortigate-fields-v7">
  3126. <parent>fortinet-fortigate-firewall</parent>
  3127. <regex>\s+switchmirrorsession="(\.*)"|\s+switchmirrorsession=(\.*)\s|\s+switchmirrorsession=(\.*)$</regex>
  3128. <order>switchmirrorsession</order>
  3129. </decoder>
  3130. <decoder name="fortinet-fortigate-fields-v7">
  3131. <parent>fortinet-fortigate-firewall</parent>
  3132. <regex>\s+switchphysicalport="(\.*)"|\s+switchphysicalport=(\.*)\s|\s+switchphysicalport=(\.*)$</regex>
  3133. <order>switchphysicalport</order>
  3134. </decoder>
  3135. <decoder name="fortinet-fortigate-fields-v7">
  3136. <parent>fortinet-fortigate-firewall</parent>
  3137. <regex>\s+switchproto="(\.*)"|\s+switchproto=(\.*)\s|\s+switchproto=(\.*)$</regex>
  3138. <order>switchproto</order>
  3139. </decoder>
  3140. <decoder name="fortinet-fortigate-fields-v7">
  3141. <parent>fortinet-fortigate-firewall</parent>
  3142. <regex>\s+switchsysteminterface="(\.*)"|\s+switchsysteminterface=(\.*)\s|\s+switchsysteminterface=(\.*)$</regex>
  3143. <order>switchsysteminterface</order>
  3144. </decoder>
  3145. <decoder name="fortinet-fortigate-fields-v7">
  3146. <parent>fortinet-fortigate-firewall</parent>
  3147. <regex>\s+switchtrunk="(\.*)"|\s+switchtrunk=(\.*)\s|\s+switchtrunk=(\.*)$</regex>
  3148. <order>switchtrunk</order>
  3149. </decoder>
  3150. <decoder name="fortinet-fortigate-fields-v7">
  3151. <parent>fortinet-fortigate-firewall</parent>
  3152. <regex>\s+switchtrunkinterface="(\.*)"|\s+switchtrunkinterface=(\.*)\s|\s+switchtrunkinterface=(\.*)$</regex>
  3153. <order>switchtrunkinterface</order>
  3154. </decoder>
  3155. <decoder name="fortinet-fortigate-fields-v7">
  3156. <parent>fortinet-fortigate-firewall</parent>
  3157. <regex>\s+sysuptime="(\.*)"|\s+sysuptime=(\.*)\s|\s+sysuptime=(\.*)$</regex>
  3158. <order>sysuptime</order>
  3159. </decoder>
  3160. <decoder name="fortinet-fortigate-fields-v7">
  3161. <parent>fortinet-fortigate-firewall</parent>
  3162. <regex>\s+tamac="(\.*)"|\s+tamac=(\.*)\s|\s+tamac=(\.*)$</regex>
  3163. <order>tamac</order>
  3164. </decoder>
  3165. <decoder name="fortinet-fortigate-fields-v7">
  3166. <parent>fortinet-fortigate-firewall</parent>
  3167. <regex>\s+threattype="(\.*)"|\s+threattype=(\.*)\s|\s+threattype=(\.*)$</regex>
  3168. <order>threattype</order>
  3169. </decoder>
  3170. <decoder name="fortinet-fortigate-fields-v7">
  3171. <parent>fortinet-fortigate-firewall</parent>
  3172. <regex>\s+ticket="(\.*)"|\s+ticket=(\.*)\s|\s+ticket=(\.*)$</regex>
  3173. <order>ticket</order>
  3174. </decoder>
  3175. <decoder name="fortinet-fortigate-fields-v7">
  3176. <parent>fortinet-fortigate-firewall</parent>
  3177. <regex>\s+time="(\.*)"|\s+time=(\.*)\s|\s+time=(\.*)$</regex>
  3178. <order>time</order>
  3179. </decoder>
  3180. <decoder name="fortinet-fortigate-fields-v7">
  3181. <parent>fortinet-fortigate-firewall</parent>
  3182. <regex>\s+timeoutdelete="(\.*)"|\s+timeoutdelete=(\.*)\s|\s+timeoutdelete=(\.*)$</regex>
  3183. <order>timeoutdelete</order>
  3184. </decoder>
  3185. <decoder name="fortinet-fortigate-fields-v7">
  3186. <parent>fortinet-fortigate-firewall</parent>
  3187. <regex>\s+timestamp="(\.*)"|\s+timestamp=(\.*)\s|\s+timestamp=(\.*)$</regex>
  3188. <order>timestamp</order>
  3189. </decoder>
  3190. <decoder name="fortinet-fortigate-fields-v7">
  3191. <parent>fortinet-fortigate-firewall</parent>
  3192. <regex>\s+tlsver="(\.*)"|\s+tlsver=(\.*)\s|\s+tlsver=(\.*)$</regex>
  3193. <order>tlsver</order>
  3194. </decoder>
  3195. <decoder name="fortinet-fortigate-fields-v7">
  3196. <parent>fortinet-fortigate-firewall</parent>
  3197. <regex>\s+to="(\.*)"|\s+to=(\.*)\s|\s+to=(\.*)$</regex>
  3198. <order>to</order>
  3199. </decoder>
  3200. <decoder name="fortinet-fortigate-fields-v7">
  3201. <parent>fortinet-fortigate-firewall</parent>
  3202. <regex>\s+to_vcluster="(\.*)"|\s+to_vcluster=(\.*)\s|\s+to_vcluster=(\.*)$</regex>
  3203. <order>to_vcluster</order>
  3204. </decoder>
  3205. <decoder name="fortinet-fortigate-fields-v7">
  3206. <parent>fortinet-fortigate-firewall</parent>
  3207. <regex>\s+total="(\.*)"|\s+total=(\.*)\s|\s+total=(\.*)$</regex>
  3208. <order>total</order>
  3209. </decoder>
  3210. <decoder name="fortinet-fortigate-fields-v7">
  3211. <parent>fortinet-fortigate-firewall</parent>
  3212. <regex>\s+totalsession="(\.*)"|\s+totalsession=(\.*)\s|\s+totalsession=(\.*)$</regex>
  3213. <order>totalsession</order>
  3214. </decoder>
  3215. <decoder name="fortinet-fortigate-fields-v7">
  3216. <parent>fortinet-fortigate-firewall</parent>
  3217. <regex>\s+traffic="(\.*)"|\s+traffic=(\.*)\s|\s+traffic=(\.*)$</regex>
  3218. <order>traffic</order>
  3219. </decoder>
  3220. <decoder name="fortinet-fortigate-fields-v7">
  3221. <parent>fortinet-fortigate-firewall</parent>
  3222. <regex>\s+trandisp="(\.*)"|\s+trandisp=(\.*)\s|\s+trandisp=(\.*)$</regex>
  3223. <order>trandisp</order>
  3224. </decoder>
  3225. <decoder name="fortinet-fortigate-fields-v7">
  3226. <parent>fortinet-fortigate-firewall</parent>
  3227. <regex>\s+tranip="(\.*)"|\s+tranip=(\.*)\s|\s+tranip=(\.*)$</regex>
  3228. <order>tranip</order>
  3229. </decoder>
  3230. <decoder name="fortinet-fortigate-fields-v7">
  3231. <parent>fortinet-fortigate-firewall</parent>
  3232. <regex>\s+tranport="(\.*)"|\s+tranport=(\.*)\s|\s+tranport=(\.*)$</regex>
  3233. <order>tranport</order>
  3234. </decoder>
  3235. <decoder name="fortinet-fortigate-fields-v7">
  3236. <parent>fortinet-fortigate-firewall</parent>
  3237. <regex>\s+transid="(\.*)"|\s+transid=(\.*)\s|\s+transid=(\.*)$</regex>
  3238. <order>transid</order>
  3239. </decoder>
  3240. <decoder name="fortinet-fortigate-fields-v7">
  3241. <parent>fortinet-fortigate-firewall</parent>
  3242. <regex>\s+transip="(\.*)"|\s+transip=(\.*)\s|\s+transip=(\.*)$</regex>
  3243. <order>transip</order>
  3244. </decoder>
  3245. <decoder name="fortinet-fortigate-fields-v7">
  3246. <parent>fortinet-fortigate-firewall</parent>
  3247. <regex>\s+translationid="(\.*)"|\s+translationid=(\.*)\s|\s+translationid=(\.*)$</regex>
  3248. <order>translationid</order>
  3249. </decoder>
  3250. <decoder name="fortinet-fortigate-fields-v7">
  3251. <parent>fortinet-fortigate-firewall</parent>
  3252. <regex>\s+transport="(\.*)"|\s+transport=(\.*)\s|\s+transport=(\.*)$</regex>
  3253. <order>transport</order>
  3254. </decoder>
  3255. <decoder name="fortinet-fortigate-fields-v7">
  3256. <parent>fortinet-fortigate-firewall</parent>
  3257. <regex>\s+trigger="(\.*)"|\s+trigger=(\.*)\s|\s+trigger=(\.*)$</regex>
  3258. <order>trigger</order>
  3259. </decoder>
  3260. <decoder name="fortinet-fortigate-fields-v7">
  3261. <parent>fortinet-fortigate-firewall</parent>
  3262. <regex>\s+trueclntip="(\.*)"|\s+trueclntip=(\.*)\s|\s+trueclntip=(\.*)$</regex>
  3263. <order>trueclntip</order>
  3264. </decoder>
  3265. <decoder name="fortinet-fortigate-fields-v7">
  3266. <parent>fortinet-fortigate-firewall</parent>
  3267. <regex>\s+tunnel="(\.*)"|\s+tunnel=(\.*)\s|\s+tunnel=(\.*)$</regex>
  3268. <order>tunnel</order>
  3269. </decoder>
  3270. <decoder name="fortinet-fortigate-fields-v7">
  3271. <parent>fortinet-fortigate-firewall</parent>
  3272. <regex>\s+tunnelid="(\.*)"|\s+tunnelid=(\.*)\s|\s+tunnelid=(\.*)$</regex>
  3273. <order>tunnelid</order>
  3274. </decoder>
  3275. <decoder name="fortinet-fortigate-fields-v7">
  3276. <parent>fortinet-fortigate-firewall</parent>
  3277. <regex>\s+tunnelip="(\.*)"|\s+tunnelip=(\.*)\s|\s+tunnelip=(\.*)$</regex>
  3278. <order>tunnelip</order>
  3279. </decoder>
  3280. <decoder name="fortinet-fortigate-fields-v7">
  3281. <parent>fortinet-fortigate-firewall</parent>
  3282. <regex>\s+tunneltype="(\.*)"|\s+tunneltype=(\.*)\s|\s+tunneltype=(\.*)$</regex>
  3283. <order>tunneltype</order>
  3284. </decoder>
  3285. <decoder name="fortinet-fortigate-fields-v7">
  3286. <parent>fortinet-fortigate-firewall</parent>
  3287. <regex>\s+type="(\.*)"|\s+type=(\.*)\s|\s+type=(\.*)$</regex>
  3288. <order>type</order>
  3289. </decoder>
  3290. <decoder name="fortinet-fortigate-fields-v7">
  3291. <parent>fortinet-fortigate-firewall</parent>
  3292. <regex>\s+tz="(\.*)"|\s+tz=(\.*)\s|\s+tz=(\.*)$</regex>
  3293. <order>tz</order>
  3294. </decoder>
  3295. <decoder name="fortinet-fortigate-fields-v7">
  3296. <parent>fortinet-fortigate-firewall</parent>
  3297. <regex>\s+ufseid="(\.*)"|\s+ufseid=(\.*)\s|\s+ufseid=(\.*)$</regex>
  3298. <order>ufseid</order>
  3299. </decoder>
  3300. <decoder name="fortinet-fortigate-fields-v7">
  3301. <parent>fortinet-fortigate-firewall</parent>
  3302. <regex>\s+ufseidaddr="(\.*)"|\s+ufseidaddr=(\.*)\s|\s+ufseidaddr=(\.*)$</regex>
  3303. <order>ufseidaddr</order>
  3304. </decoder>
  3305. <decoder name="fortinet-fortigate-fields-v7">
  3306. <parent>fortinet-fortigate-firewall</parent>
  3307. <regex>\s+uggsn="(\.*)"|\s+uggsn=(\.*)\s|\s+uggsn=(\.*)$</regex>
  3308. <order>uggsn</order>
  3309. </decoder>
  3310. <decoder name="fortinet-fortigate-fields-v7">
  3311. <parent>fortinet-fortigate-firewall</parent>
  3312. <regex>\s+ugsn="(\.*)"|\s+ugsn=(\.*)\s|\s+ugsn=(\.*)$</regex>
  3313. <order>ugsn</order>
  3314. </decoder>
  3315. <decoder name="fortinet-fortigate-fields-v7">
  3316. <parent>fortinet-fortigate-firewall</parent>
  3317. <regex>\s+ui="(\.*)"|\s+ui=(\.*)\s|\s+ui=(\.*)$</regex>
  3318. <order>ui</order>
  3319. </decoder>
  3320. <decoder name="fortinet-fortigate-fields-v7">
  3321. <parent>fortinet-fortigate-firewall</parent>
  3322. <regex>\s+uli="(\.*)"|\s+uli=(\.*)\s|\s+uli=(\.*)$</regex>
  3323. <order>uli</order>
  3324. </decoder>
  3325. <decoder name="fortinet-fortigate-fields-v7">
  3326. <parent>fortinet-fortigate-firewall</parent>
  3327. <regex>\s+ulimcc="(\.*)"|\s+ulimcc=(\.*)\s|\s+ulimcc=(\.*)$</regex>
  3328. <order>ulimcc</order>
  3329. </decoder>
  3330. <decoder name="fortinet-fortigate-fields-v7">
  3331. <parent>fortinet-fortigate-firewall</parent>
  3332. <regex>\s+ulimnc="(\.*)"|\s+ulimnc=(\.*)\s|\s+ulimnc=(\.*)$</regex>
  3333. <order>ulimnc</order>
  3334. </decoder>
  3335. <decoder name="fortinet-fortigate-fields-v7">
  3336. <parent>fortinet-fortigate-firewall</parent>
  3337. <regex>\s+unauthuser="(\.*)"|\s+unauthuser=(\.*)\s|\s+unauthuser=(\.*)$</regex>
  3338. <order>unauthuser</order>
  3339. </decoder>
  3340. <decoder name="fortinet-fortigate-fields-v7">
  3341. <parent>fortinet-fortigate-firewall</parent>
  3342. <regex>\s+unauthusersource="(\.*)"|\s+unauthusersource=(\.*)\s|\s+unauthusersource=(\.*)$</regex>
  3343. <order>unauthusersource</order>
  3344. </decoder>
  3345. <decoder name="fortinet-fortigate-fields-v7">
  3346. <parent>fortinet-fortigate-firewall</parent>
  3347. <regex>\s+unit="(\.*)"|\s+unit=(\.*)\s|\s+unit=(\.*)$</regex>
  3348. <order>unit</order>
  3349. </decoder>
  3350. <decoder name="fortinet-fortigate-fields-v7">
  3351. <parent>fortinet-fortigate-firewall</parent>
  3352. <regex>\s+upbandwidthmeasured="(\.*)"|\s+upbandwidthmeasured=(\.*)\s|\s+upbandwidthmeasured=(\.*)$</regex>
  3353. <order>upbandwidthmeasured</order>
  3354. </decoder>
  3355. <decoder name="fortinet-fortigate-fields-v7">
  3356. <parent>fortinet-fortigate-firewall</parent>
  3357. <regex>\s+upgradedevice="(\.*)"|\s+upgradedevice=(\.*)\s|\s+upgradedevice=(\.*)$</regex>
  3358. <order>upgradedevice</order>
  3359. </decoder>
  3360. <decoder name="fortinet-fortigate-fields-v7">
  3361. <parent>fortinet-fortigate-firewall</parent>
  3362. <regex>\s+upteid="(\.*)"|\s+upteid=(\.*)\s|\s+upteid=(\.*)$</regex>
  3363. <order>upteid</order>
  3364. </decoder>
  3365. <decoder name="fortinet-fortigate-fields-v7">
  3366. <parent>fortinet-fortigate-firewall</parent>
  3367. <regex>\s+url="(\.*)"|\s+url=(\.*)\s|\s+url=(\.*)$</regex>
  3368. <order>url</order>
  3369. </decoder>
  3370. <decoder name="fortinet-fortigate-fields-v7">
  3371. <parent>fortinet-fortigate-firewall</parent>
  3372. <regex>\s+urlfilteridx="(\.*)"|\s+urlfilteridx=(\.*)\s|\s+urlfilteridx=(\.*)$</regex>
  3373. <order>urlfilteridx</order>
  3374. </decoder>
  3375. <decoder name="fortinet-fortigate-fields-v7">
  3376. <parent>fortinet-fortigate-firewall</parent>
  3377. <regex>\s+urlfilterlist="(\.*)"|\s+urlfilterlist=(\.*)\s|\s+urlfilterlist=(\.*)$</regex>
  3378. <order>urlfilterlist</order>
  3379. </decoder>
  3380. <decoder name="fortinet-fortigate-fields-v7">
  3381. <parent>fortinet-fortigate-firewall</parent>
  3382. <regex>\s+urlsource="(\.*)"|\s+urlsource=(\.*)\s|\s+urlsource=(\.*)$</regex>
  3383. <order>urlsource</order>
  3384. </decoder>
  3385. <decoder name="fortinet-fortigate-fields-v7">
  3386. <parent>fortinet-fortigate-firewall</parent>
  3387. <regex>\s+urltype="(\.*)"|\s+urltype=(\.*)\s|\s+urltype=(\.*)$</regex>
  3388. <order>urltype</order>
  3389. </decoder>
  3390. <decoder name="fortinet-fortigate-fields-v7">
  3391. <parent>fortinet-fortigate-firewall</parent>
  3392. <regex>\s+used="(\.*)"|\s+used=(\.*)\s|\s+used=(\.*)$</regex>
  3393. <order>used</order>
  3394. </decoder>
  3395. <decoder name="fortinet-fortigate-fields-v7">
  3396. <parent>fortinet-fortigate-firewall</parent>
  3397. <regex>\s+used_for="(\.*)"|\s+used_for=(\.*)\s|\s+used_for=(\.*)$</regex>
  3398. <order>used_for</order>
  3399. </decoder>
  3400. <decoder name="fortinet-fortigate-fields-v7">
  3401. <parent>fortinet-fortigate-firewall</parent>
  3402. <regex>\s+user="(\.*)"|\s+user=(\.*)\s|\s+user=(\.*)$</regex>
  3403. <order>user</order>
  3404. </decoder>
  3405. <decoder name="fortinet-fortigate-fields-v7">
  3406. <parent>fortinet-fortigate-firewall</parent>
  3407. <regex>\s+user_data="(\.*)"|\s+user_data=(\.*)\s|\s+user_data=(\.*)$</regex>
  3408. <order>user_data</order>
  3409. </decoder>
  3410. <decoder name="fortinet-fortigate-fields-v7">
  3411. <parent>fortinet-fortigate-firewall</parent>
  3412. <regex>\s+useractivity="(\.*)"|\s+useractivity=(\.*)\s|\s+useractivity=(\.*)$</regex>
  3413. <order>useractivity</order>
  3414. </decoder>
  3415. <decoder name="fortinet-fortigate-fields-v7">
  3416. <parent>fortinet-fortigate-firewall</parent>
  3417. <regex>\s+useralt="(\.*)"|\s+useralt=(\.*)\s|\s+useralt=(\.*)$</regex>
  3418. <order>useralt</order>
  3419. </decoder>
  3420. <decoder name="fortinet-fortigate-fields-v7">
  3421. <parent>fortinet-fortigate-firewall</parent>
  3422. <regex>\s+usgsn="(\.*)"|\s+usgsn=(\.*)\s|\s+usgsn=(\.*)$</regex>
  3423. <order>usgsn</order>
  3424. </decoder>
  3425. <decoder name="fortinet-fortigate-fields-v7">
  3426. <parent>fortinet-fortigate-firewall</parent>
  3427. <regex>\s+utmaction="(\.*)"|\s+utmaction=(\.*)\s|\s+utmaction=(\.*)$</regex>
  3428. <order>utmaction</order>
  3429. </decoder>
  3430. <decoder name="fortinet-fortigate-fields-v7">
  3431. <parent>fortinet-fortigate-firewall</parent>
  3432. <regex>\s+vap="(\.*)"|\s+vap=(\.*)\s|\s+vap=(\.*)$</regex>
  3433. <order>vap</order>
  3434. </decoder>
  3435. <decoder name="fortinet-fortigate-fields-v7">
  3436. <parent>fortinet-fortigate-firewall</parent>
  3437. <regex>\s+vapmode="(\.*)"|\s+vapmode=(\.*)\s|\s+vapmode=(\.*)$</regex>
  3438. <order>vapmode</order>
  3439. </decoder>
  3440. <decoder name="fortinet-fortigate-fields-v7">
  3441. <parent>fortinet-fortigate-firewall</parent>
  3442. <regex>\s+vcluster="(\.*)"|\s+vcluster=(\.*)\s|\s+vcluster=(\.*)$</regex>
  3443. <order>vcluster</order>
  3444. </decoder>
  3445. <decoder name="fortinet-fortigate-fields-v7">
  3446. <parent>fortinet-fortigate-firewall</parent>
  3447. <regex>\s+vcluster_member="(\.*)"|\s+vcluster_member=(\.*)\s|\s+vcluster_member=(\.*)$</regex>
  3448. <order>vcluster_member</order>
  3449. </decoder>
  3450. <decoder name="fortinet-fortigate-fields-v7">
  3451. <parent>fortinet-fortigate-firewall</parent>
  3452. <regex>\s+vcluster_state="(\.*)"|\s+vcluster_state=(\.*)\s|\s+vcluster_state=(\.*)$</regex>
  3453. <order>vcluster_state</order>
  3454. </decoder>
  3455. <decoder name="fortinet-fortigate-fields-v7">
  3456. <parent>fortinet-fortigate-firewall</parent>
  3457. <regex>\s+vd="(\.*)"|\s+vd=(\.*)\s|\s+vd=(\.*)$</regex>
  3458. <order>vd</order>
  3459. </decoder>
  3460. <decoder name="fortinet-fortigate-fields-v7">
  3461. <parent>fortinet-fortigate-firewall</parent>
  3462. <regex>\s+vdname="(\.*)"|\s+vdname=(\.*)\s|\s+vdname=(\.*)$</regex>
  3463. <order>vdname</order>
  3464. </decoder>
  3465. <decoder name="fortinet-fortigate-fields-v7">
  3466. <parent>fortinet-fortigate-firewall</parent>
  3467. <regex>\s+vendor="(\.*)"|\s+vendor=(\.*)\s|\s+vendor=(\.*)$</regex>
  3468. <order>vendor</order>
  3469. </decoder>
  3470. <decoder name="fortinet-fortigate-fields-v7">
  3471. <parent>fortinet-fortigate-firewall</parent>
  3472. <regex>\s+vendorurl="(\.*)"|\s+vendorurl=(\.*)\s|\s+vendorurl=(\.*)$</regex>
  3473. <order>vendorurl</order>
  3474. </decoder>
  3475. <decoder name="fortinet-fortigate-fields-v7">
  3476. <parent>fortinet-fortigate-firewall</parent>
  3477. <regex>\s+version="(\.*)"|\s+version=(\.*)\s|\s+version=(\.*)$</regex>
  3478. <order>version</order>
  3479. </decoder>
  3480. <decoder name="fortinet-fortigate-fields-v7">
  3481. <parent>fortinet-fortigate-firewall</parent>
  3482. <regex>\s+versionmax="(\.*)"|\s+versionmax=(\.*)\s|\s+versionmax=(\.*)$</regex>
  3483. <order>versionmax</order>
  3484. </decoder>
  3485. <decoder name="fortinet-fortigate-fields-v7">
  3486. <parent>fortinet-fortigate-firewall</parent>
  3487. <regex>\s+versionmin="(\.*)"|\s+versionmin=(\.*)\s|\s+versionmin=(\.*)$</regex>
  3488. <order>versionmin</order>
  3489. </decoder>
  3490. <decoder name="fortinet-fortigate-fields-v7">
  3491. <parent>fortinet-fortigate-firewall</parent>
  3492. <regex>\s+videocategoryid="(\.*)"|\s+videocategoryid=(\.*)\s|\s+videocategoryid=(\.*)$</regex>
  3493. <order>videocategoryid</order>
  3494. </decoder>
  3495. <decoder name="fortinet-fortigate-fields-v7">
  3496. <parent>fortinet-fortigate-firewall</parent>
  3497. <regex>\s+videocategoryname="(\.*)"|\s+videocategoryname=(\.*)\s|\s+videocategoryname=(\.*)$</regex>
  3498. <order>videocategoryname</order>
  3499. </decoder>
  3500. <decoder name="fortinet-fortigate-fields-v7">
  3501. <parent>fortinet-fortigate-firewall</parent>
  3502. <regex>\s+videochannelid="(\.*)"|\s+videochannelid=(\.*)\s|\s+videochannelid=(\.*)$</regex>
  3503. <order>videochannelid</order>
  3504. </decoder>
  3505. <decoder name="fortinet-fortigate-fields-v7">
  3506. <parent>fortinet-fortigate-firewall</parent>
  3507. <regex>\s+videodesc="(\.*)"|\s+videodesc=(\.*)\s|\s+videodesc=(\.*)$</regex>
  3508. <order>videodesc</order>
  3509. </decoder>
  3510. <decoder name="fortinet-fortigate-fields-v7">
  3511. <parent>fortinet-fortigate-firewall</parent>
  3512. <regex>\s+videoid="(\.*)"|\s+videoid=(\.*)\s|\s+videoid=(\.*)$</regex>
  3513. <order>videoid</order>
  3514. </decoder>
  3515. <decoder name="fortinet-fortigate-fields-v7">
  3516. <parent>fortinet-fortigate-firewall</parent>
  3517. <regex>\s+videoinfosource="(\.*)"|\s+videoinfosource=(\.*)\s|\s+videoinfosource=(\.*)$</regex>
  3518. <order>videoinfosource</order>
  3519. </decoder>
  3520. <decoder name="fortinet-fortigate-fields-v7">
  3521. <parent>fortinet-fortigate-firewall</parent>
  3522. <regex>\s+videotitle="(\.*)"|\s+videotitle=(\.*)\s|\s+videotitle=(\.*)$</regex>
  3523. <order>videotitle</order>
  3524. </decoder>
  3525. <decoder name="fortinet-fortigate-fields-v7">
  3526. <parent>fortinet-fortigate-firewall</parent>
  3527. <regex>\s+violations="(\.*)"|\s+violations=(\.*)\s|\s+violations=(\.*)$</regex>
  3528. <order>violations</order>
  3529. </decoder>
  3530. <decoder name="fortinet-fortigate-fields-v7">
  3531. <parent>fortinet-fortigate-firewall</parent>
  3532. <regex>\s+vip="(\.*)"|\s+vip=(\.*)\s|\s+vip=(\.*)$</regex>
  3533. <order>vip</order>
  3534. </decoder>
  3535. <decoder name="fortinet-fortigate-fields-v7">
  3536. <parent>fortinet-fortigate-firewall</parent>
  3537. <regex>\s+virtual="(\.*)"|\s+virtual=(\.*)\s|\s+virtual=(\.*)$</regex>
  3538. <order>virtual</order>
  3539. </decoder>
  3540. <decoder name="fortinet-fortigate-fields-v7">
  3541. <parent>fortinet-fortigate-firewall</parent>
  3542. <regex>\s+virus="(\.*)"|\s+virus=(\.*)\s|\s+virus=(\.*)$</regex>
  3543. <order>virus</order>
  3544. </decoder>
  3545. <decoder name="fortinet-fortigate-fields-v7">
  3546. <parent>fortinet-fortigate-firewall</parent>
  3547. <regex>\s+viruscat="(\.*)"|\s+viruscat=(\.*)\s|\s+viruscat=(\.*)$</regex>
  3548. <order>viruscat</order>
  3549. </decoder>
  3550. <decoder name="fortinet-fortigate-fields-v7">
  3551. <parent>fortinet-fortigate-firewall</parent>
  3552. <regex>\s+virusid="(\.*)"|\s+virusid=(\.*)\s|\s+virusid=(\.*)$</regex>
  3553. <order>virusid</order>
  3554. </decoder>
  3555. <decoder name="fortinet-fortigate-fields-v7">
  3556. <parent>fortinet-fortigate-firewall</parent>
  3557. <regex>\s+vlan="(\.*)"|\s+vlan=(\.*)\s|\s+vlan=(\.*)$</regex>
  3558. <order>vlan</order>
  3559. </decoder>
  3560. <decoder name="fortinet-fortigate-fields-v7">
  3561. <parent>fortinet-fortigate-firewall</parent>
  3562. <regex>\s+voip="(\.*)"|\s+voip=(\.*)\s|\s+voip=(\.*)$</regex>
  3563. <order>voip</order>
  3564. </decoder>
  3565. <decoder name="fortinet-fortigate-fields-v7">
  3566. <parent>fortinet-fortigate-firewall</parent>
  3567. <regex>\s+voip_proto="(\.*)"|\s+voip_proto=(\.*)\s|\s+voip_proto=(\.*)$</regex>
  3568. <order>voip_proto</order>
  3569. </decoder>
  3570. <decoder name="fortinet-fortigate-fields-v7">
  3571. <parent>fortinet-fortigate-firewall</parent>
  3572. <regex>\s+vpn="(\.*)"|\s+vpn=(\.*)\s|\s+vpn=(\.*)$</regex>
  3573. <order>vpn</order>
  3574. </decoder>
  3575. <decoder name="fortinet-fortigate-fields-v7">
  3576. <parent>fortinet-fortigate-firewall</parent>
  3577. <regex>\s+vpntunnel="(\.*)"|\s+vpntunnel=(\.*)\s|\s+vpntunnel=(\.*)$</regex>
  3578. <order>vpntunnel</order>
  3579. </decoder>
  3580. <decoder name="fortinet-fortigate-fields-v7">
  3581. <parent>fortinet-fortigate-firewall</parent>
  3582. <regex>\s+vpntype="(\.*)"|\s+vpntype=(\.*)\s|\s+vpntype=(\.*)$</regex>
  3583. <order>vpntype</order>
  3584. </decoder>
  3585. <decoder name="fortinet-fortigate-fields-v7">
  3586. <parent>fortinet-fortigate-firewall</parent>
  3587. <regex>\s+vrf="(\.*)"|\s+vrf=(\.*)\s|\s+vrf=(\.*)$</regex>
  3588. <order>vrf</order>
  3589. </decoder>
  3590. <decoder name="fortinet-fortigate-fields-v7">
  3591. <parent>fortinet-fortigate-firewall</parent>
  3592. <regex>\s+vulncat="(\.*)"|\s+vulncat=(\.*)\s|\s+vulncat=(\.*)$</regex>
  3593. <order>vulncat</order>
  3594. </decoder>
  3595. <decoder name="fortinet-fortigate-fields-v7">
  3596. <parent>fortinet-fortigate-firewall</parent>
  3597. <regex>\s+vulncnt="(\.*)"|\s+vulncnt=(\.*)\s|\s+vulncnt=(\.*)$</regex>
  3598. <order>vulncnt</order>
  3599. </decoder>
  3600. <decoder name="fortinet-fortigate-fields-v7">
  3601. <parent>fortinet-fortigate-firewall</parent>
  3602. <regex>\s+vulnid="(\.*)"|\s+vulnid=(\.*)\s|\s+vulnid=(\.*)$</regex>
  3603. <order>vulnid</order>
  3604. </decoder>
  3605. <decoder name="fortinet-fortigate-fields-v7">
  3606. <parent>fortinet-fortigate-firewall</parent>
  3607. <regex>\s+vulnname="(\.*)"|\s+vulnname=(\.*)\s|\s+vulnname=(\.*)$</regex>
  3608. <order>vulnname</order>
  3609. </decoder>
  3610. <decoder name="fortinet-fortigate-fields-v7">
  3611. <parent>fortinet-fortigate-firewall</parent>
  3612. <regex>\s+vulnresult="(\.*)"|\s+vulnresult=(\.*)\s|\s+vulnresult=(\.*)$</regex>
  3613. <order>vulnresult</order>
  3614. </decoder>
  3615. <decoder name="fortinet-fortigate-fields-v7">
  3616. <parent>fortinet-fortigate-firewall</parent>
  3617. <regex>\s+vwlid="(\.*)"|\s+vwlid=(\.*)\s|\s+vwlid=(\.*)$</regex>
  3618. <order>vwlid</order>
  3619. </decoder>
  3620. <decoder name="fortinet-fortigate-fields-v7">
  3621. <parent>fortinet-fortigate-firewall</parent>
  3622. <regex>\s+vwlname="(\.*)"|\s+vwlname=(\.*)\s|\s+vwlname=(\.*)$</regex>
  3623. <order>vwlname</order>
  3624. </decoder>
  3625. <decoder name="fortinet-fortigate-fields-v7">
  3626. <parent>fortinet-fortigate-firewall</parent>
  3627. <regex>\s+vwlquality="(\.*)"|\s+vwlquality=(\.*)\s|\s+vwlquality=(\.*)$</regex>
  3628. <order>vwlquality</order>
  3629. </decoder>
  3630. <decoder name="fortinet-fortigate-fields-v7">
  3631. <parent>fortinet-fortigate-firewall</parent>
  3632. <regex>\s+vwlservice="(\.*)"|\s+vwlservice=(\.*)\s|\s+vwlservice=(\.*)$</regex>
  3633. <order>vwlservice</order>
  3634. </decoder>
  3635. <decoder name="fortinet-fortigate-fields-v7">
  3636. <parent>fortinet-fortigate-firewall</parent>
  3637. <regex>\s+vwpvlanid="(\.*)"|\s+vwpvlanid=(\.*)\s|\s+vwpvlanid=(\.*)$</regex>
  3638. <order>vwpvlanid</order>
  3639. </decoder>
  3640. <decoder name="fortinet-fortigate-fields-v7">
  3641. <parent>fortinet-fortigate-firewall</parent>
  3642. <regex>\s+waf="(\.*)"|\s+waf=(\.*)\s|\s+waf=(\.*)$</regex>
  3643. <order>waf</order>
  3644. </decoder>
  3645. <decoder name="fortinet-fortigate-fields-v7">
  3646. <parent>fortinet-fortigate-firewall</parent>
  3647. <regex>\s+wanin="(\.*)"|\s+wanin=(\.*)\s|\s+wanin=(\.*)$</regex>
  3648. <order>wanin</order>
  3649. </decoder>
  3650. <decoder name="fortinet-fortigate-fields-v7">
  3651. <parent>fortinet-fortigate-firewall</parent>
  3652. <regex>\s+waninfo="(\.*)"|\s+waninfo=(\.*)\s|\s+waninfo=(\.*)$</regex>
  3653. <order>waninfo</order>
  3654. </decoder>
  3655. <decoder name="fortinet-fortigate-fields-v7">
  3656. <parent>fortinet-fortigate-firewall</parent>
  3657. <regex>\s+wanoptapptype="(\.*)"|\s+wanoptapptype=(\.*)\s|\s+wanoptapptype=(\.*)$</regex>
  3658. <order>wanoptapptype</order>
  3659. </decoder>
  3660. <decoder name="fortinet-fortigate-fields-v7">
  3661. <parent>fortinet-fortigate-firewall</parent>
  3662. <regex>\s+wanout="(\.*)"|\s+wanout=(\.*)\s|\s+wanout=(\.*)$</regex>
  3663. <order>wanout</order>
  3664. </decoder>
  3665. <decoder name="fortinet-fortigate-fields-v7">
  3666. <parent>fortinet-fortigate-firewall</parent>
  3667. <regex>\s+weakwepiv="(\.*)"|\s+weakwepiv=(\.*)\s|\s+weakwepiv=(\.*)$</regex>
  3668. <order>weakwepiv</order>
  3669. </decoder>
  3670. <decoder name="fortinet-fortigate-fields-v7">
  3671. <parent>fortinet-fortigate-firewall</parent>
  3672. <regex>\s+webfilter="(\.*)"|\s+webfilter=(\.*)\s|\s+webfilter=(\.*)$</regex>
  3673. <order>webfilter</order>
  3674. </decoder>
  3675. <decoder name="fortinet-fortigate-fields-v7">
  3676. <parent>fortinet-fortigate-firewall</parent>
  3677. <regex>\s+webmailprovider="(\.*)"|\s+webmailprovider=(\.*)\s|\s+webmailprovider=(\.*)$</regex>
  3678. <order>webmailprovider</order>
  3679. </decoder>
  3680. <decoder name="fortinet-fortigate-fields-v7">
  3681. <parent>fortinet-fortigate-firewall</parent>
  3682. <regex>\s+wscode="(\.*)"|\s+wscode=(\.*)\s|\s+wscode=(\.*)$</regex>
  3683. <order>wscode</order>
  3684. </decoder>
  3685. <decoder name="fortinet-fortigate-fields-v7">
  3686. <parent>fortinet-fortigate-firewall</parent>
  3687. <regex>\s+xauthgroup="(\.*)"|\s+xauthgroup=(\.*)\s|\s+xauthgroup=(\.*)$</regex>
  3688. <order>xauthgroup</order>
  3689. </decoder>
  3690. <decoder name="fortinet-fortigate-fields-v7">
  3691. <parent>fortinet-fortigate-firewall</parent>
  3692. <regex>\s+xauthuser="(\.*)"|\s+xauthuser=(\.*)\s|\s+xauthuser=(\.*)$</regex>
  3693. <order>xauthuser</order>
  3694. </decoder>