Fortinet black logo

FortiNDR logs

FortiNDR logs

FortiAnalyzer supports normalizing FortiNDR logs as Fabric logs.

The following field mapping applies:

FortiNDR Log Field

Normalized Fabric Log Field

loguid,id loguid
epid epid
euid euid
devid data_sourceid
device_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
status app_state
action event_action
logid event_id
level event_severity
subtype event_subtype
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
devhost,host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
victimip src_ip
victimport src_port
virusname threat_name
url,filetype threat_pattern
risklevel threat_severity
scenariotype threat_type
user user_id

FortiNDR logs

FortiAnalyzer supports normalizing FortiNDR logs as Fabric logs.

The following field mapping applies:

FortiNDR Log Field

Normalized Fabric Log Field

loguid,id loguid
epid epid
euid euid
devid data_sourceid
device_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
status app_state
action event_action
logid event_id
level event_severity
subtype event_subtype
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
devhost,host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
victimip src_ip
victimport src_port
virusname threat_name
url,filetype threat_pattern
risklevel threat_severity
scenariotype threat_type
user user_id