References

Browse and search all of our SIEM field references in one place.

Apache
HTTP Server (httpd)
Apache HTTP Server is the world's most-used open-source web server for delivering static and dynamic web content on Linux, Windows and macOS.
Fields
21
Atlassian
Confluence Cloud
Atlassian Confluence Cloud is a SaaS wiki and collaboration platform for creating, sharing and organising team knowledge.
Fields
32
Barracuda
Firewall
Barracuda CloudGen Firewall is a next-generation firewall platform that combines advanced threat prevention with SD-WAN traffic optimisation for distributed networks.
Fields
44
Barracuda
Mailhub
Barracuda Email Security Gateway is a dedicated mail-security appliance that filters spam, malware and phishing before messages reach the mail server.
Fields
22
Barracuda
Web Application Firewall
Barracuda Web Application Firewall is a hardware or virtual appliance that shields web applications from OWASP Top 10 attacks, bots and DDoS traffic.
Fields
51
Bitdefender
GravityZone
Bitdefender GravityZone is a unified endpoint-protection platform delivering antivirus, EDR and hardening for Windows, macOS and Linux systems.
Fields
199
Cisco
Adaptive Security Appliances (ASA)
Cisco ASA is a stateful firewall and VPN appliance family used to protect enterprise networks and remote-access connections.
Fields
59
Cisco
Meraki
Cisco Meraki is a cloud-managed networking portfolio covering security appliances, switches and Wi-Fi access points administered via the Meraki Dashboard.
Fields
70
Citrix
NetScaler ADC
Citrix NetScaler ADC is an application-delivery controller providing load-balancing, SSL VPN and web-application-firewall services.
Fields
75
Consistec
Caplon
Consistec Caplon is a network analytics platform that performs deep-packet inspection, SLA monitoring and anomaly detection in real time.
Fields
39
Enginsight
Advanced Persistent Threats (APT)
Enginsight APT is a behavioural analytics engine that detects advanced persistent threats across endpoints and network traffic.
Fields
12
Enginsight
File Integrity Monitoring (FIM)
Enginsight FIM (File Integrity Monitoring) tracks critical file and registry changes to spot tampering or misuse.
Fields
15
Enginsight
Intrusion Detection System (IDS)
Enginsight IDS is a host-based intrusion-detection system providing signature and anomaly alerts for OS and application activity.
Fields
14
Enginsight
Loggernaut (SIEM)
Enginsight Loggernaut is the ingestion and retention service that normalises, parses and stores customer log data.
Fields
22
Enginsight
SIEM Incidents
Enginsight SIEM Incidents are correlated alert records that bundle related events into actionable cases for analysts.
Fields
8
Enginsight
Shield (IPS)
Enginsight Shield is an inline intrusion-prevention system that blocks exploits and anomalies in real time.
Fields
21
Extreme Networks
ExtremeCloud IQ
ExtremeCloud IQ is Extreme Networks' cloud platform for provisioning, monitoring and securing wired and wireless infrastructure.
Fields
54
F5 Networks
BIG-IP ASM
F5 BIG-IP ASM (Advanced WAF) is F5's web-application firewall module for the BIG-IP ADC platform, providing signature, behavioural and bot defence.
Fields
35
F5 Networks
NGINX
NGINX is a high-performance open-source web server and reverse proxy used for HTTP, HTTPS, TCP and UDP traffic.
Fields
19
Microsoft
Defender
Microsoft Defender for Endpoint is Microsoft's built-in antivirus and EDR solution for Windows, macOS, Linux and mobile.
Fields
105
Microsoft
Microsoft 365
Microsoft 365 Unified Audit is Microsoft's consolidated log source covering Exchange Online, SharePoint, Teams and Entra ID.
Fields
255
Microsoft
Windows Event Log
Windows Event Log is the native logging subsystem that records system, security, application and custom provider events.
Fields
380
CEF
CEF (Common Event Format) is ArcSight's vendor-neutral log standard that encodes security events as structured key-value pairs.
Fields
128
ESET PROTECT
ESET PROTECT is ESET's central management console for its endpoint-security suite, covering malware defence, firewall and device control.
Fields
68
File
File ingestion represents plain-text log files imported from disk or network shares-ideal for custom applications or legacy devices.
Fields
4
FortiSIEM
FortiSIEM is Fortinet's security-information-and-event-management system, providing log aggregation, correlation and automated incident response.
Fields
72
Fortinet FortiGate
Fortinet FortiGate is a next-generation firewall platform that unifies IPS, web filtering, antivirus, SD-WAN and VPN services.
Fields
741
G DATA
G DATA Endpoint Security is a multilayered antivirus and behavior-blocking suite for Windows, macOS and Linux desktops and servers.
Fields
47
Generic Fields (Unified Schema)
The "gen" namespace contains vendor-agnostic key names-such as src.ip, dest.port or event.time-used to map equivalent values across all log sources. It acts as the canonical schema layer so searches, correlations and dashboards work no matter where the data originated.
Fields
73
ISC DHCPd
ISC dhcpd is the reference open-source DHCP server for dynamically assigning IPv4/IPv6 addresses and options to clients.
Fields
8
LANCOM
LANCOM Systems routers, WLAN controllers and access points provide secure site-to-site VPN, enterprise Wi-Fi and SD-WAN for SMEs.
Fields
44
LANCOM Cloud
LANCOM Management Cloud is a SaaS platform for orchestrating firmware, policies and analytics across LANCOM network devices.
Fields
55
MITRE ATT&CK
MITRE ATT&CK is a community-driven knowledge base mapping adversary tactics, techniques and procedures for threat modelling.
Fields
5
OpenSSH
OpenSSH is the de-facto standard secure-shell implementation for encrypted remote login and file transfer.
Fields
9
Palo Alto Networks
Palo Alto Networks Next-Generation Firewall provides Layer-7 traffic control, threat prevention and cloud sandboxing via WildFire.
Fields
280
Postfix
Postfix is a widely-used open-source SMTP server for sending and receiving e-mail on Unix-like systems.
Fields
7
Relay Log Forwarder
Relay Log Forwarder denotes any generic syslog relay that forwards messages without altering the original format.
Fields
14
SentinelOne
SentinelOne Singularity is an AI-powered endpoint-detection-and-response platform with autonomous remediation.
Fields
175
SonicWall
SonicWall Next-Generation Firewall appliances secure SMB and enterprise networks with IPS, antivirus, and SSL inspection.
Fields
90
Sophos
Sophos Intercept X and XGS Firewall provide unified endpoint and network security with deep-learning malware detection.
Fields
368
Squid Proxy
Squid is an open-source forward proxy and web cache supporting HTTP, HTTPS and FTP.
Fields
15
Standard
Standard represents generic system or application logs that conform to the SIEM's base schema but lack vendor context.
Fields
23
Syslog
Syslog is the standard message-logging protocol (RFC 3164/5424) for Unix-like operating systems and network devices.
Fields
14
Sysmon
Microsoft Sysmon is an advanced Windows event provider that records process, network and registry activity for forensics.
Fields
89
Trend Micro Apex One
Trend Micro Apex One is an endpoint-protection platform combining antivirus, EDR and virtual patching.
Fields
76
Unbound DNS
Unbound is a validating, recursive and caching DNS resolver focused on privacy and DNSSEC support.
Fields
17
WatchGuard Firebox
WatchGuard Firebox is a unified threat-management firewall that adds IPS, antivirus and web filtering to edge security.
Fields
195
genua pf
genua genuscreen (pf) is a German high-assurance firewall that combines stateful packet filtering with IPSec VPN and monitoring.
Fields
17
macOS Logs
macOS Unified Logging is Apple's system-wide log framework capturing kernel, system and application telemetry on macOS hosts.
Fields
23
pfSense
pfSense is an open-source firewall and router OS based on FreeBSD offering stateful packet filtering and VPN services.
Fields
37
strongSwan
strongSwan is an open-source IPSec VPN solution supporting IKE v1/v2 for site-to-site and remote access tunnels.
Fields
27