According to the mapping file corelight-ds-component_template-main_logs-mappings, MAC addresses are "copied to" related.mac.
This is the case for :
- source.mac
- destination.mac
- radius.mac
- host.mac
- radius.mac
However related.mac seems to not be ECS compliant. See Elastic documentation.
What do you think about using related.hosts instead ? The same mapping file is already using related.hosts for 11 other fields.
related.hosts : All hostnames or other host identifiers seen on your event. [...]