# ECS Field Name (Fortigate Dataset)

**URL:** https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492
**Category:** Logstash
**Created:** [September 20, 2023, 10:01pm UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492 "2023-09-20T22:01:44Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)
#### Post date: [September 20, 2023, 10:01pm UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492/1 "2023-09-20T22:01:44Z")

</div>

I am collecting Fortigate logs with the Elastic Agent and the Fortigate integration. These are then being shipped to Logstash for some custom enrichment before being pushed to Elastic Cloud. One of the custom enrichment fields is adding the field `source.user.account` with the value from `source.user.name` for later translation. However, I cannot find the correct syntax for the source field.

In an event, the field name is `souce.user.name`, which is the same in the JSON viewer, here is a screenshot of it:

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a38e38f3b53e81089bb6597400e839cf4e993f0.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3db89cff9b1eaf94917bbcd373a930d45a13fd08.png)

However, I have tried the below variations with zero success.

```auto
source.user.name
[source.user.name]
[source.user][name]
[source][user.name]
[source][user][name]
source.user.name.text
[source.user.name.text]
[source.user][name][text]
[source][user.name][text]
[source][user][name][text]
user.name
[user.name]
[user][name]

```

The weird thing is, I've put the add field action behind a logic condition using `if "source.user.name" { }` and the add field action initiates, meaning `source.user.name` is present, but it is adding the literal value in the right side of the `add_field` setting. For example, this:

```auto
      mutate {
        add_field => {
          "[source][user][account]" => "%{[source][user][name][text]}"
        }
      }

```

results in this:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/4/643601b7edb44de7aa5411b2ad105b7dfccd65cf.png)

---

<div class="post-metadata">

### Author: ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)
#### Post date: [September 20, 2023, 10:53pm UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492/2 "2023-09-20T22:53:36Z")

</div>

I guess the pipeline config would help...it's gone through a few iterations, but it's still doing the same thing.

```auto
filter {
  if [data_stream][namespace] == "fortigate" {
    if "[user][name]" {
      mutate {
        add_field => {
          "[source][user][full_name]" => "%{[user][name]}"
        }
      }
    }
  }
}

```

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/454fb0512b61016c30d3186eef02b2f3e95f7768.png)

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 21, 2023, 1:21am UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492/3 "2023-09-21T01:21:30Z")

</div>

> [@wwalker](#):
>
> I am collecting Fortigate logs with the Elastic Agent and the Fortigate integration. These are then being shipped to Logstash for some custom enrichment before being pushed to Elastic Cloud.

Can you provide more context about how you are sending the logs and what you are doing in Logstash?

The Elastic Agent and its integrations uses Elasticsearch Ingest pipelines to parse the data, you won't have any parsed field in Logstash so it is not clear what you are trying to enrich and how.

---

<div class="post-metadata">

### Author: ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)
#### Post date: [September 22, 2023, 5:19pm UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492/4 "2023-09-22T17:19:13Z")

</div>

Elastic Agent outputting to logstash then logstash sending it to Elastic Cloud. This setup is being recommended by Elastic itself. I want to enrich the event data with additional information using the translate filter.

Your comment gave me the idea to output the events to file and see what they look like. Turns out the agent outputs a JSON formatted event with fields related to the agent, ECS, and a couple other things. It places the original, unparsed event in the message field and then ships it to Elastic for the ingest pipeline to parse.

Since the source of my translations is information only available in my environment, I modified the Logstash pipeline to copy the message field, parse the copied field and place the new fields under the temp field (`temp.firewall.name` for example), and then from here I can run my translations. Once I've finished all my enrichments, I delete the temp object, removing all the temporarily parsed fields.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 20, 2023, 5:19pm UTC](https://discuss.elastic.co/t/ecs-field-name-fortigate-dataset/343492/5 "2023-10-20T17:19:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
