﻿---
title: Juniper JUNOS fields
description: juniper fields. Module for parsing junipersrx syslog. 
url: https://www.elastic.co/elastic/docs-builder/docs/3016/reference/beats/filebeat/exported-fields-juniper
products:
  - Beats
  - Filebeat
applies_to:
  - Elastic Cloud Serverless: Generally available
  - Elastic Stack: Generally available
---

# Juniper JUNOS fields
juniper fields.

## juniper.srx

<applies-to>
  - Elastic Stack: Beta
</applies-to>

Module for parsing junipersrx syslog.
<definitions>
  <definition term="juniper.srx.reason">
    reason
    type: keyword
  </definition>
  <definition term="juniper.srx.connection_tag">
    connection tag
    type: keyword
  </definition>
  <definition term="juniper.srx.service_name">
    service name
    type: keyword
  </definition>
  <definition term="juniper.srx.nat_connection_tag">
    nat connection tag
    type: keyword
  </definition>
  <definition term="juniper.srx.src_nat_rule_type">
    src nat rule type
    type: keyword
  </definition>
  <definition term="juniper.srx.src_nat_rule_name">
    src nat rule name
    type: keyword
  </definition>
  <definition term="juniper.srx.dst_nat_rule_type">
    dst nat rule type
    type: keyword
  </definition>
  <definition term="juniper.srx.dst_nat_rule_name">
    dst nat rule name
    type: keyword
  </definition>
  <definition term="juniper.srx.protocol_id">
    protocol id
    type: keyword
  </definition>
  <definition term="juniper.srx.policy_name">
    policy name
    type: keyword
  </definition>
  <definition term="juniper.srx.session_id_32">
    session id 32
    type: keyword
  </definition>
  <definition term="juniper.srx.session_id">
    session id
    type: keyword
  </definition>
  <definition term="juniper.srx.outbound_packets">
    packets from client
    type: integer
  </definition>
  <definition term="juniper.srx.outbound_bytes">
    bytes from client
    type: integer
  </definition>
  <definition term="juniper.srx.inbound_packets">
    packets from server
    type: integer
  </definition>
  <definition term="juniper.srx.inbound_bytes">
    bytes from server
    type: integer
  </definition>
  <definition term="juniper.srx.elapsed_time">
    elapsed time
    type: date
  </definition>
  <definition term="juniper.srx.application">
    application
    type: keyword
  </definition>
  <definition term="juniper.srx.nested_application">
    nested application
    type: keyword
  </definition>
  <definition term="juniper.srx.username">
    username
    type: keyword
  </definition>
  <definition term="juniper.srx.roles">
    roles
    type: keyword
  </definition>
  <definition term="juniper.srx.encrypted">
    encrypted
    type: keyword
  </definition>
  <definition term="juniper.srx.application_category">
    application category
    type: keyword
  </definition>
  <definition term="juniper.srx.application_sub_category">
    application sub category
    type: keyword
  </definition>
  <definition term="juniper.srx.application_characteristics">
    application characteristics
    type: keyword
  </definition>
  <definition term="juniper.srx.secure_web_proxy_session_type">
    secure web proxy session type
    type: keyword
  </definition>
  <definition term="juniper.srx.peer_session_id">
    peer session id
    type: keyword
  </definition>
  <definition term="juniper.srx.peer_source_address">
    peer source address
    type: ip
  </definition>
  <definition term="juniper.srx.peer_source_port">
    peer source port
    type: integer
  </definition>
  <definition term="juniper.srx.peer_destination_address">
    peer destination address
    type: ip
  </definition>
  <definition term="juniper.srx.peer_destination_port">
    peer destination port
    type: integer
  </definition>
  <definition term="juniper.srx.hostname">
    hostname
    type: keyword
  </definition>
  <definition term="juniper.srx.src_vrf_grp">
    src_vrf_grp
    type: keyword
  </definition>
  <definition term="juniper.srx.dst_vrf_grp">
    dst_vrf_grp
    type: keyword
  </definition>
  <definition term="juniper.srx.icmp_type">
    icmp type
    type: integer
  </definition>
  <definition term="juniper.srx.process">
    process that generated the message
    type: keyword
  </definition>
  <definition term="juniper.srx.apbr_rule_type">
    apbr rule type
    type: keyword
  </definition>
  <definition term="juniper.srx.dscp_value">
    apbr rule type
    type: integer
  </definition>
  <definition term="juniper.srx.logical_system_name">
    logical system name
    type: keyword
  </definition>
  <definition term="juniper.srx.profile_name">
    profile name
    type: keyword
  </definition>
  <definition term="juniper.srx.routing_instance">
    routing instance
    type: keyword
  </definition>
  <definition term="juniper.srx.rule_name">
    rule name
    type: keyword
  </definition>
  <definition term="juniper.srx.uplink_tx_bytes">
    uplink tx bytes
    type: integer
  </definition>
  <definition term="juniper.srx.uplink_rx_bytes">
    uplink rx bytes
    type: integer
  </definition>
  <definition term="juniper.srx.obj">
    url path
    type: keyword
  </definition>
  <definition term="juniper.srx.url">
    url domain
    type: keyword
  </definition>
  <definition term="juniper.srx.profile">
    filter profile
    type: keyword
  </definition>
  <definition term="juniper.srx.category">
    filter category
    type: keyword
  </definition>
  <definition term="juniper.srx.filename">
    filename
    type: keyword
  </definition>
  <definition term="juniper.srx.temporary_filename">
    temporary_filename
    type: keyword
  </definition>
  <definition term="juniper.srx.name">
    name
    type: keyword
  </definition>
  <definition term="juniper.srx.error_message">
    error_message
    type: keyword
  </definition>
  <definition term="juniper.srx.error_code">
    error_code
    type: keyword
  </definition>
  <definition term="juniper.srx.action">
    action
    type: keyword
  </definition>
  <definition term="juniper.srx.protocol">
    protocol
    type: keyword
  </definition>
  <definition term="juniper.srx.protocol_name">
    protocol name
    type: keyword
  </definition>
  <definition term="juniper.srx.type">
    type
    type: keyword
  </definition>
  <definition term="juniper.srx.repeat_count">
    repeat count
    type: integer
  </definition>
  <definition term="juniper.srx.alert">
    repeat alert
    type: keyword
  </definition>
  <definition term="juniper.srx.message_type">
    message type
    type: keyword
  </definition>
  <definition term="juniper.srx.threat_severity">
    threat severity
    type: keyword
  </definition>
  <definition term="juniper.srx.application_name">
    application name
    type: keyword
  </definition>
  <definition term="juniper.srx.attack_name">
    attack name
    type: keyword
  </definition>
  <definition term="juniper.srx.index">
    index
    type: keyword
  </definition>
  <definition term="juniper.srx.message">
    mesagge
    type: keyword
  </definition>
  <definition term="juniper.srx.epoch_time">
    epoch time
    type: date
  </definition>
  <definition term="juniper.srx.packet_log_id">
    packet log id
    type: integer
  </definition>
  <definition term="juniper.srx.export_id">
    packet log id
    type: integer
  </definition>
  <definition term="juniper.srx.ddos_application_name">
    ddos application name
    type: keyword
  </definition>
  <definition term="juniper.srx.connection_hit_rate">
    connection hit rate
    type: integer
  </definition>
  <definition term="juniper.srx.time_scope">
    time scope
    type: keyword
  </definition>
  <definition term="juniper.srx.context_hit_rate">
    context hit rate
    type: integer
  </definition>
  <definition term="juniper.srx.context_value_hit_rate">
    context value hit rate
    type: integer
  </definition>
  <definition term="juniper.srx.time_count">
    time count
    type: integer
  </definition>
  <definition term="juniper.srx.time_period">
    time period
    type: integer
  </definition>
  <definition term="juniper.srx.context_value">
    context value
    type: keyword
  </definition>
  <definition term="juniper.srx.context_name">
    context name
    type: keyword
  </definition>
  <definition term="juniper.srx.ruleebase_name">
    ruleebase name
    type: keyword
  </definition>
  <definition term="juniper.srx.verdict_source">
    verdict source
    type: keyword
  </definition>
  <definition term="juniper.srx.verdict_number">
    verdict number
    type: integer
  </definition>
  <definition term="juniper.srx.file_category">
    file category
    type: keyword
  </definition>
  <definition term="juniper.srx.sample_sha256">
    sample sha256
    type: keyword
  </definition>
  <definition term="juniper.srx.malware_info">
    malware info
    type: keyword
  </definition>
  <definition term="juniper.srx.client_ip">
    client ip
    type: ip
  </definition>
  <definition term="juniper.srx.tenant_id">
    tenant id
    type: keyword
  </definition>
  <definition term="juniper.srx.timestamp">
    timestamp
    type: date
  </definition>
  <definition term="juniper.srx.th">
    th
    type: keyword
  </definition>
  <definition term="juniper.srx.status">
    status
    type: keyword
  </definition>
  <definition term="juniper.srx.state">
    state
    type: keyword
  </definition>
  <definition term="juniper.srx.file_hash_lookup">
    file hash lookup
    type: keyword
  </definition>
  <definition term="juniper.srx.file_name">
    file name
    type: keyword
  </definition>
  <definition term="juniper.srx.action_detail">
    action detail
    type: keyword
  </definition>
  <definition term="juniper.srx.sub_category">
    sub category
    type: keyword
  </definition>
  <definition term="juniper.srx.feed_name">
    feed name
    type: keyword
  </definition>
  <definition term="juniper.srx.occur_count">
    occur count
    type: integer
  </definition>
  <definition term="juniper.srx.tag">
    system log message tag, which uniquely identifies the message.
    type: keyword
  </definition>
</definitions>