Output Dictionary
The Output Dictionary is the translation layer of NFO. Every downstream platform (Splunk, Sentinel, Elasticsearch, and others) has its own preferred naming convention for network fields. The Dictionary maps NFO's output field names to the schema your destination expects, so you can match an existing schema without changing anything upstream.
To access it, navigate to the Services page and select the Output Dictionary tab.

Custom field names, when specified, apply to both syslog key=value pairs and JSON field names.
Click the Output dictionary link and override the names you want, or download the entire list as a CSV file, edit it, and upload it back.
