# ECS common schema taxonomies for other sources

**URL:** <https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220>\
**Category:** SIEM\
**Created:** [April 15, 2020, 11:33pm UTC](https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220 "2020-04-15T23:33:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rossw](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rossw](https://discuss.elastic.co/u/rossw)\
**Post date:** [April 15, 2020, 11:33pm UTC](https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220/1 "2020-04-15T23:33:02Z")

</div>

Hi there  
We are looking at pushing events from a lot of our network and security devices into Elastic for storage, and utilising the SIEM functionality as well. We understand the requirement for ECS, and we have started using Logstash to transform the incoming data (mostly in custom syslog formats from the devices) into ECS.  
Rather than invent the wheel, is there a repository of taxonomies somewhere for different log source types (like the QRadar DSM concept)? Our devices include F5 devices, Fortigate firewalls, PA firewalls, Juniper switches and routers, lots of different types of cisco switches (with different log formats) etc. etc. etc. etc. etc.  
I'm hoping there is a repository of common "extended" ECS mappings that we can utilise, and add to.  
thanks  
Ross

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [April 16, 2020, 11:20am UTC](https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220/2 "2020-04-16T11:20:31Z")

</div>

Hi @rossw! While we don't currently have a repository of taxonomies, it's a great suggestion that we'll keep in mind. We are working on expanding support for new data sources, including many of the devices you've listed. However, the implementation guides for our [Cisco](https://github.com/elastic/beats/blob/master/filebeat/docs/modules/cisco.asciidoc) and [Palo Alto](https://github.com/elastic/beats/blob/master/filebeat/docs/modules/panw.asciidoc) Filebeat modules include the ECS field mappings which may serve as a reference for you.

As you transform your data to ECS, you may find the [ecs-mapper](https://github.com/elastic/ecs-mapper) tool helpful. It's an experimental tool, but allows you to map existing fields to ECS fields within a CSV and automatically generate the pipelines for you. We're currently soliciting feedback on the tool, so would love to hear your thoughts if you use it to generate the pipelines.

Hope that helps - if you have any additional questions, just let me know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2020, 11:20am UTC](https://discuss.elastic.co/t/ecs-common-schema-taxonomies-for-other-sources/228220/3 "2020-05-14T11:20:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
