PROGRAM field explanation

Kibana,elasticsearch-7.6.1-1, syslog-ng-3.24.1-1 sends logs via http://localhost:9200/_bulk.
I have issue with dynamic field (I assume) PROGRAM.
From 2 different systems PROGRAM in kibana is mapped as date. What PROGRAM label should represent? I assumed program should map as "syslog-ng" or such not as date? TXS
e.g. kibana output:
SOURCE: s_udp PROGRAM: 2020/03/26