Data Fields

This page references the various types of data fields utilized by the Elastic Stack in Security Onion.


We try to align with Elastic Common Schema (ECS) where possible.


For more information about ECS, please see

Template files

Fields are mapped to their proper type using template files found in /opt/so/conf/elasticsearch/templates/.