FortiGate logs
FortiAnalyzer supports normalizing FortiGate logs as Fabric logs.
The following field mapping applies:
|
FortiGate Log Field |
Normalized Fabric Log Field |
|---|---|
| devid,device_id | data_sourceid |
| data_source_name | data_sourcename |
| slot | data_sourcenode |
| data_sourcetype | data_sourcetype |
| vd | data_sourcevdom |
| data_timestamp | data_timestamp |
| accessctrl,accessproxy | app_access |
| appact | app_action |
| appcat | app_cat |
| keyword,sensitivity | app_data |
| appid | app_id |
| app,appname,apps,saasapp | app_name |
| moscodec | app_proc |
| hash,id,name,type | app_risk |
| service,saasinfo | app_service |
| apstatus | app_state |
| fctver | app_ver |
| cloudaction | cloud_appaction |
| saasname | cloud_appname |
| used | dhcp_used |
| qname | dns_query |
| dns_querytype | dns_querytype |
| ipaddr | dns_response |
| dstssid,dstuuid | dst_asset_id |
| domain,hostname | dst_domain |
| dstgeoid | dst_geo |
| dstcity | dst_geo_city |
| dstcountry | dst_geo_country |
| dst_info,dstintf | dst_intf |
| dstintfrole | dst_intf_role |
| dstip,dst_ip,locip | dst_ip |
| dstmac | dst_mac |
| dst_natip,tranip | dst_natip |
| dst_natport,tranport | dst_natport |
| dstport,dst_port | dst_port |
| action,utmaction | event_action |
| catdesc,videocategoryname,activitycategory,cat,catdesc,category,utmevent | event_cat |
| total | event_count |
| eventtime,time | event_creation_time |
| event_id,logid,vwlid | event_id |
| event_message,dhcp_msg,msg | event_message |
| name,logdesc | event_name |
| error,result | event_outcome |
| event_policy,policyname,usingpolicy | event_policy |
| policyid | event_policyid |
| policytype | event_policytype |
| applist,profile | event_profile |
| event_ref,reason | event_ref |
| ap,sn | event_resource_id |
| fsaverdict,level,severity | event_severity |
| vap,channel | event_source |
| scantime | event_start_time |
| quarskip,status | event_status |
| state | event_status_code |
| subtype | event_subtype |
| type,eventtype,kind | event_type |
| cfgtid,logid,poluuid,uid | event_uuid |
| manuf | event_vendor |
| filetype | file_ext |
| analyticscksum,filehash | file_hash |
| filename,file | file_name |
| filesize | file_size |
| host_classification | host_classification |
| sn,tags,vendorurl | host_data |
| host_hwvendor,srchwvendor | host_hwvendor |
| host_hwver,srchwversion | host_hwver |
| host_ip,deviceip | host_ip |
| srccountry | host_location |
| host_mac,mac,devicemac,bssid | host_mac |
| module,srcproduct | host_model_name |
| host_name,hostname | host_name |
| srcfamily,os | host_osfamily |
| host_osname,osname | host_osname |
| host_osver,srcswversion | host_osver |
| user,dstowner | host_owner |
| cpu,disk,mem | host_perf_stats |
| host_type | host_type |
| srcuuid,fctuid | host_uid |
| httpmethod,method | http_method |
| referralurl | http_referer |
| url | http_url |
| agent | http_useragent |
| ui | logon_ui |
| to | mail_to |
| apn,name,onwire,radioband,sn | net_accesspoint |
| direction | net_direction |
| srcssid | net_name |
| bandwidth,erate,orate,setuprate,totalsession,trate | net_perf_stats |
| packetloss | net_pktlosspct |
| proto | net_proto |
| rcvdpkt,rcvdp | net_rcvdpkts |
| rcvdbyte,rcvdb,inbandwidthused | net_recvbytes |
| rcvddelta | net_recvdelta |
| ip,name | net_remote_server |
| bibandwidthused,downbandwidthmeasured,healthcheck,jitter,latency,moscodec,mosvalue,speedtestserver,upbandwidthmeasured,vwlid | net_sdwan |
| sentbyte,sentb,outbandwidthused,rate | net_sentbytes |
| sentdelta | net_sentdelta |
| sentpkt,sentp | net_sentpkts |
| duration,dur | net_sessionduration |
| sessionid | net_sessionid |
| shaperdroprcvdbyte,shaperdropsentbyte,shaperperipdropbyte,shaperperipname,shaperrcvdname,shapingpolicyid,shapingpolicyname | net_shaper |
| srcssid,ssid | net_ssid |
| id,ip,type,vpn,vpntype | net_tunnel |
| u-bytes,u-pkts | net_userdata |
| rsrq,rssi,security,securitymode,signal,sinr,sn | net_wlan |
| pid | process_id |
| srcssid | src_asset_id |
| srcname | src_domain |
| srcgeoid | src_geo |
| srccity | src_geo_city |
| srccountry | src_geo_country |
| source_info,srcintf,interface | src_intf |
| srcintfrole | src_intf_role |
| srcip,src_ip | src_ip |
| srcmac,stamac | src_mac |
| src_natip,transip | src_natip |
| src_natport,transport | src_natport |
| srcport,src_port | src_port |
| threat_action | threat_action |
| vulncat | threat_category |
| threatcnts | threat_count |
| cveid | threat_cveid |
| threat_direction | threat_direction |
| threat_id | threat_id |
| category,infoid,name,scantime,score,wfcatid | threat_ioc |
| threat_name | threat_name |
| threat_pattern | threat_pattern |
| threat_ref | threat_ref |
| crscore | threat_score |
| threat_severity | threat_severity |
| threat_type | threat_type |
| id,name,severity,type,weight | threat_rawlog |
| community | user_classification |
| collectedemail | user_email |
| group,unauthusersource | user_group |
| user,unauthuser | user_id |
| user,initiator | user_name |
| role | user_role |
| unauthuser | user_unauthuser |
| xauthgroup | user_xauthgroup |
| xauthuser | user_xauthuser |