# Jsonify fortigate

**URL:** https://discuss.elastic.co/t/jsonify-fortigate/358391
**Category:** Kibana
**Created:** [April 29, 2024, 5:01am UTC](https://discuss.elastic.co/t/jsonify-fortigate/358391 "2024-04-29T05:01:34Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![m\_pahlevanzadeh](https://avatars.discourse-cdn.com/v4/letter/m/8e7dd6/32.png) [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)
#### Post date: [April 29, 2024, 5:01am UTC](https://discuss.elastic.co/t/jsonify-fortigate/358391/1 "2024-04-29T05:01:34Z")

</div>

I visit the following page:

> **[Fortinet module | Filebeat Reference \[8.13\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-fortinet.html)**

At end of above line, it mentioned to fortinet fields.  
My scenario:  
I get fortiGate syslog and I can put into elastics. Now I want to jsonify , because I need to search according in kibana.  
Question:  
How can I assign real fortinet fields to real fields?

**UPDATE:**  
For example : Fortinet Field action is exists. And ECS Field evemt.action exists too. How and Where I assign them togeter?

---

<div class="post-metadata">

### Author: ![m\_pahlevanzadeh](https://avatars.discourse-cdn.com/v4/letter/m/8e7dd6/32.png) [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)
#### Post date: [April 29, 2024, 7:32am UTC](https://discuss.elastic.co/t/jsonify-fortigate/358391/2 "2024-04-29T07:32:00Z")

</div>

You have to write filter with mapping.
