System logs
FortiAnalyzer supports normalizing System logs as Fabric logs.
The following field mapping applies:
|
System Log Field |
Normalized Fabric Log Field |
|---|---|
| loguid,id | loguid |
| epid | epid |
| euid | euid |
| devid,device_id | data_sourceid |
| host_name,devid | data_sourcename |
| data_sourcetype | data_sourcetype |
| app_cat | app_cat |
| service | app_service |
| message,msg | event_message |
| level | event_severity |
| type | event_type |
| host_classification | host_classification |
| host_hwvendor | host_hwvendor |
| host_hwver | host_hwver |
| host_ip | host_ip |
| host_mac | host_mac |
| host_name | host_name |
| host_osname | host_osname |
| host_osver | host_osver |
| host_type | host_type |
| host_uid | host_uid |