Where: src = IP address of the source host dst = IP address of the destination host modsrc = Translated IP address of the source host. origdst = Original IP address of the destination host (before translation or the application of a virtual connection). srcport = source TCP/UDP port number modesrcport = Translated TCP/UDP source port number dstport = Destination TCP/UDP port number origdstport = Original port number of the destination TCP/UDP port (before translation or the application of a virtual connection).
I wanna know how can I name these fields to respect ECS !
The problem is what IP source should I name source.ip as there is 2 source IP (before and after address translation ), and then second one, what should I name it by respecting the ECS !
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.