Fortinet white logo
Fortinet white logo

FortiGate logs

FortiGate logs

FortiAnalyzer supports normalizing FortiGate logs as Fabric logs.

The following field mapping applies:

FortiGate Log Field

Normalized Fabric Log Field

devid,device_id data_sourceid
data_source_name data_sourcename
slot data_sourcenode
data_sourcetype data_sourcetype
vd data_sourcevdom
data_timestamp data_timestamp
accessctrl,accessproxy app_access
appact app_action
appcat app_cat
keyword,sensitivity app_data
appid app_id
app,appname,apps,saasapp app_name
moscodec app_proc
hash,id,name,type app_risk
service,saasinfo app_service
apstatus app_state
fctver app_ver
cloudaction cloud_appaction
saasname cloud_appname
used dhcp_used
qname dns_query
dns_querytype dns_querytype
ipaddr dns_response
dstssid,dstuuid dst_asset_id
domain,hostname dst_domain
dstgeoid dst_geo
dstcity dst_geo_city
dstcountry dst_geo_country
dst_info,dstintf dst_intf
dstintfrole dst_intf_role
dstip,dst_ip,locip dst_ip
dstmac dst_mac
dst_natip,tranip dst_natip
dst_natport,tranport dst_natport
dstport,dst_port dst_port
action,utmaction event_action
catdesc,videocategoryname,activitycategory,cat,catdesc,category,utmevent event_cat
total event_count
eventtime,time event_creation_time
event_id,logid,vwlid event_id
event_message,dhcp_msg,msg event_message
name,logdesc event_name
error,result event_outcome
event_policy,policyname,usingpolicy event_policy
policyid event_policyid
policytype event_policytype
applist,profile event_profile
event_ref,reason event_ref
ap,sn event_resource_id
fsaverdict,level,severity event_severity
vap,channel event_source
scantime event_start_time
quarskip,status event_status
state event_status_code
subtype event_subtype
type,eventtype,kind event_type
cfgtid,logid,poluuid,uid event_uuid
manuf event_vendor
filetype file_ext
analyticscksum,filehash file_hash
filename,file file_name
filesize file_size
host_classification host_classification
sn,tags,vendorurl host_data
host_hwvendor,srchwvendor host_hwvendor
host_hwver,srchwversion host_hwver
host_ip,deviceip host_ip
srccountry host_location
host_mac,mac,devicemac,bssid host_mac
module,srcproduct host_model_name
host_name,hostname host_name
srcfamily,os host_osfamily
host_osname,osname host_osname
host_osver,srcswversion host_osver
user,dstowner host_owner
cpu,disk,mem host_perf_stats
host_type host_type
srcuuid,fctuid host_uid
httpmethod,method http_method
referralurl http_referer
url http_url
agent http_useragent
ui logon_ui
to mail_to
apn,name,onwire,radioband,sn net_accesspoint
direction net_direction
srcssid net_name
bandwidth,erate,orate,setuprate,totalsession,trate net_perf_stats
packetloss net_pktlosspct
proto net_proto
rcvdpkt,rcvdp net_rcvdpkts
rcvdbyte,rcvdb,inbandwidthused net_recvbytes
rcvddelta net_recvdelta
ip,name net_remote_server
bibandwidthused,downbandwidthmeasured,healthcheck,jitter,latency,moscodec,mosvalue,speedtestserver,upbandwidthmeasured,vwlid net_sdwan
sentbyte,sentb,outbandwidthused,rate net_sentbytes
sentdelta net_sentdelta
sentpkt,sentp net_sentpkts
duration,dur net_sessionduration
sessionid net_sessionid
shaperdroprcvdbyte,shaperdropsentbyte,shaperperipdropbyte,shaperperipname,shaperrcvdname,shapingpolicyid,shapingpolicyname net_shaper
srcssid,ssid net_ssid
id,ip,type,vpn,vpntype net_tunnel
u-bytes,u-pkts net_userdata
rsrq,rssi,security,securitymode,signal,sinr,sn net_wlan
pid process_id
srcssid src_asset_id
srcname src_domain
srcgeoid src_geo
srccity src_geo_city
srccountry src_geo_country
source_info,srcintf,interface src_intf
srcintfrole src_intf_role
srcip,src_ip src_ip
srcmac,stamac src_mac
src_natip,transip src_natip
src_natport,transport src_natport
srcport,src_port src_port
threat_action threat_action
vulncat threat_category
threatcnts threat_count
cveid threat_cveid
threat_direction threat_direction
threat_id threat_id
category,infoid,name,scantime,score,wfcatid threat_ioc
threat_name threat_name
threat_pattern threat_pattern
threat_ref threat_ref
crscore threat_score
threat_severity threat_severity
threat_type threat_type
id,name,severity,type,weight threat_rawlog
community user_classification
collectedemail user_email
group,unauthusersource user_group
user,unauthuser user_id
user,initiator user_name
role user_role
unauthuser user_unauthuser
xauthgroup user_xauthgroup
xauthuser user_xauthuser

FortiGate logs

FortiGate logs

FortiAnalyzer supports normalizing FortiGate logs as Fabric logs.

The following field mapping applies:

FortiGate Log Field

Normalized Fabric Log Field

devid,device_id data_sourceid
data_source_name data_sourcename
slot data_sourcenode
data_sourcetype data_sourcetype
vd data_sourcevdom
data_timestamp data_timestamp
accessctrl,accessproxy app_access
appact app_action
appcat app_cat
keyword,sensitivity app_data
appid app_id
app,appname,apps,saasapp app_name
moscodec app_proc
hash,id,name,type app_risk
service,saasinfo app_service
apstatus app_state
fctver app_ver
cloudaction cloud_appaction
saasname cloud_appname
used dhcp_used
qname dns_query
dns_querytype dns_querytype
ipaddr dns_response
dstssid,dstuuid dst_asset_id
domain,hostname dst_domain
dstgeoid dst_geo
dstcity dst_geo_city
dstcountry dst_geo_country
dst_info,dstintf dst_intf
dstintfrole dst_intf_role
dstip,dst_ip,locip dst_ip
dstmac dst_mac
dst_natip,tranip dst_natip
dst_natport,tranport dst_natport
dstport,dst_port dst_port
action,utmaction event_action
catdesc,videocategoryname,activitycategory,cat,catdesc,category,utmevent event_cat
total event_count
eventtime,time event_creation_time
event_id,logid,vwlid event_id
event_message,dhcp_msg,msg event_message
name,logdesc event_name
error,result event_outcome
event_policy,policyname,usingpolicy event_policy
policyid event_policyid
policytype event_policytype
applist,profile event_profile
event_ref,reason event_ref
ap,sn event_resource_id
fsaverdict,level,severity event_severity
vap,channel event_source
scantime event_start_time
quarskip,status event_status
state event_status_code
subtype event_subtype
type,eventtype,kind event_type
cfgtid,logid,poluuid,uid event_uuid
manuf event_vendor
filetype file_ext
analyticscksum,filehash file_hash
filename,file file_name
filesize file_size
host_classification host_classification
sn,tags,vendorurl host_data
host_hwvendor,srchwvendor host_hwvendor
host_hwver,srchwversion host_hwver
host_ip,deviceip host_ip
srccountry host_location
host_mac,mac,devicemac,bssid host_mac
module,srcproduct host_model_name
host_name,hostname host_name
srcfamily,os host_osfamily
host_osname,osname host_osname
host_osver,srcswversion host_osver
user,dstowner host_owner
cpu,disk,mem host_perf_stats
host_type host_type
srcuuid,fctuid host_uid
httpmethod,method http_method
referralurl http_referer
url http_url
agent http_useragent
ui logon_ui
to mail_to
apn,name,onwire,radioband,sn net_accesspoint
direction net_direction
srcssid net_name
bandwidth,erate,orate,setuprate,totalsession,trate net_perf_stats
packetloss net_pktlosspct
proto net_proto
rcvdpkt,rcvdp net_rcvdpkts
rcvdbyte,rcvdb,inbandwidthused net_recvbytes
rcvddelta net_recvdelta
ip,name net_remote_server
bibandwidthused,downbandwidthmeasured,healthcheck,jitter,latency,moscodec,mosvalue,speedtestserver,upbandwidthmeasured,vwlid net_sdwan
sentbyte,sentb,outbandwidthused,rate net_sentbytes
sentdelta net_sentdelta
sentpkt,sentp net_sentpkts
duration,dur net_sessionduration
sessionid net_sessionid
shaperdroprcvdbyte,shaperdropsentbyte,shaperperipdropbyte,shaperperipname,shaperrcvdname,shapingpolicyid,shapingpolicyname net_shaper
srcssid,ssid net_ssid
id,ip,type,vpn,vpntype net_tunnel
u-bytes,u-pkts net_userdata
rsrq,rssi,security,securitymode,signal,sinr,sn net_wlan
pid process_id
srcssid src_asset_id
srcname src_domain
srcgeoid src_geo
srccity src_geo_city
srccountry src_geo_country
source_info,srcintf,interface src_intf
srcintfrole src_intf_role
srcip,src_ip src_ip
srcmac,stamac src_mac
src_natip,transip src_natip
src_natport,transport src_natport
srcport,src_port src_port
threat_action threat_action
vulncat threat_category
threatcnts threat_count
cveid threat_cveid
threat_direction threat_direction
threat_id threat_id
category,infoid,name,scantime,score,wfcatid threat_ioc
threat_name threat_name
threat_pattern threat_pattern
threat_ref threat_ref
crscore threat_score
threat_severity threat_severity
threat_type threat_type
id,name,severity,type,weight threat_rawlog
community user_classification
collectedemail user_email
group,unauthusersource user_group
user,unauthuser user_id
user,initiator user_name
role user_role
unauthuser user_unauthuser
xauthgroup user_xauthgroup
xauthuser user_xauthuser