Fabric log field descriptions
The normalized fabric log fields are organized in the following categories.
|
Category |
Description |
|---|---|
|
Metadata as the proprietary fields of FortiAnalyzer. |
|
|
Metadata as the data source fields of SIEM parser. |
|
|
Application data. Specifies the shared communication service and application's information used by hosts in a communications network. |
|
|
Destination data. Represents movement through geographic space, from a source to a destination. |
|
|
Event data. Collected and stored by various tracking tools or methods in order to provide insights about user behavior, traffic patterns, and other metrics related to online events. |
|
|
File data. Stores information to be used by a computer application or system. |
|
|
Host data. Stores information of a computer or other device that communicates with other hosts on a network. |
|
|
Logon data. Defines metadata about the logon events. |
|
|
Network data. Defines metadata about network information seen in a typical OSI layer. |
|
|
Process data. Defines metadata about processes in an system. Isolated memory address space that is used to run a program. |
|
|
Protocol data. Defines metadata about protocol related information for transmitting/exchanging data between the devices. |
|
|
Registry data. Defines metadata about Windows registry entries in a system. |
|
|
Source data. Represents movement through geographic space, from a source to a destination. |
|
|
Transport Layer Security (TLS) data. |
|
|
Threat data. Refers to a known list of malicious threat information. |
|
|
User data. Defines metadata about users in a network environment. |
The following tables list the available normalized fabric log fields in FortiAnalyzer 7.6.3.
base
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
adom_oid |
uint32 |
ADOM ID from DVM for internal use. |
|
dstepid |
uint32 |
Endpoint ID used as key for FortiAnalyzer-DST-UEBA correlation. |
|
dsteuid |
uint32 |
End-user ID used as key for FortiAnalyzer-DST-UEBA correlation. |
|
epid |
uint32 |
Endpoint ID used as key for FortiAnalyzer-UEBA correlation. |
|
euid |
uint32 |
End-user ID used as key for FortiAnalyzer-UEBA correlation. |
|
itime |
uint32 |
Timestamp set by FortiAnalyzer when it receives the data. |
|
loguid |
uint64 |
Unique ID set by FortiAnalyzer on each log for internal use. |
data_source
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
data_parsername |
string |
Parser name used for parsing data. |
|
data_sourceid |
string |
Machine\Host\Device\VM ID for the data source. |
|
data_sourcename |
string |
Machine\Host\Device\VM Name for the data source. |
|
data_sourcetype |
string |
Data source type. |
|
data_sourceversion |
string |
Data source version. |
|
data_timestamp |
uint32 |
Timestamp set by data source. |
Application
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
app_action |
string |
The operation the user performed in the context of the application. |
|
app_cat |
string |
Application category. |
|
app_id |
uint32 |
Application ID. |
|
app_name |
string |
Application name. |
|
app_proc |
string |
Process name. |
|
app_ref |
string |
Reference for additional information about application. |
|
app_service |
string |
Service name. |
|
app_state |
string |
Application state. |
|
app_ver |
string |
Application version. |
Destination
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
dst_asset_id |
string |
Destination asset ID. |
|
dst_domain |
string |
Destination domain name. |
|
dst_geo |
string |
Destination geo. |
|
dst_geo_city |
string |
Destination geo city information. |
|
dst_geo_country |
string |
Destination geo country. |
|
dst_geo_country_code |
string |
Destination geo country code. |
|
dst_geo_latitude |
string |
Destination geo latitude. |
|
dst_geo_longitude |
string |
Destination geo longitude. |
|
dst_geo_region |
string |
Destination geo region. |
|
dst_intf |
string |
Destination interface. |
|
dst_intf_guid |
string |
GUID of the network interface which was used for authentication request. |
|
dst_ip |
ip |
Destination IP. |
|
dst_mac |
string |
Destination MAC. |
|
dst_natip |
ip |
Destination NAT IP. |
|
dst_natport |
uint16 |
Destination NAT port. |
|
dst_port |
uint16 |
Destination port. |
Event
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
event_action |
string |
Main action taken. |
|
event_cat |
string |
Event category. |
|
event_count |
uint32 |
The number of aggregated events. |
|
event_creation_time |
uint32 |
Original time when event/log was created as reported from the log source itself. |
|
event_duration |
uint32 |
The length/duration of the event in seconds (for example, 1 min is 60.0). |
|
event_end_time |
uint32 |
The time in which the event ended. |
|
event_error |
string |
Information about an error. |
|
event_error_code |
uint32 |
Integer that defines a particular error. |
|
event_id |
uint32 |
Event\Log ID from data source. |
|
event_message |
string |
Main message from data source or set by parser. |
|
event_outcome |
string |
Event outcome. |
|
event_policy |
string |
Event policy. |
|
event_profile |
string |
Event profile. |
|
event_ref |
string |
Reference for additional info about event. |
|
event_report_url |
string |
URL of the full analysis report. |
|
event_resource_group |
string |
The resource group to which the device generating the record belongs. This might be an AWS account, or an Azure subscription or Resource Group. |
|
event_resource_id |
string |
The resource ID of the device generating the message. |
|
event_severity |
string |
Event severity. |
|
event_source |
string |
Data\Event source on Application layer. |
|
event_start_time |
uint32 |
The time in which the event stated. |
|
event_status |
string |
Defines the status of a particular event. |
|
event_status_code |
uint32 |
Integer that defines a particular status. |
|
event_subtype |
string |
Event subtype. |
|
event_type |
string |
Event type. |
|
event_uuid |
string |
Original unique ID specific to the log/event assigned to the event (not original). |
|
event_vendor |
string |
The vendor of the product generating the event. |
File
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
file_accessetime |
uint32 |
File accessed time. |
|
file_createtime |
uint32 |
File create time. |
|
file_ext |
string |
File extention. |
|
file_hash |
string |
File hash. |
|
file_hashtype |
string |
File hash type. |
|
file_name |
string |
File name. |
|
file_path |
string |
File path. |
|
file_size |
string |
File size. |
Host
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
host_classification |
string |
Host classification. |
|
host_hwvendor |
string |
Host hardware vendor. |
|
host_hwver |
string |
Host hardware version. |
|
host_ip |
ip |
Host IP. |
|
host_location |
string |
Host location. |
|
host_mac |
string |
Hostname MAC. |
|
host_model_name |
string |
Host model name. |
|
host_name |
string |
Host name. |
|
host_osfamily |
string |
Host OS family. |
|
host_osname |
string |
Host OS name. |
|
host_osver |
string |
Host OS version. |
|
host_owner |
string |
Host owner. |
|
host_type |
string |
Host type. |
|
host_uid |
string |
EDR Agent ID such as FortiClient UID. |
Logon
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
logon_authentication |
string |
The name of the authentication package which was used for the logon authentication process. |
|
logon_device_claims |
string |
Logon device claims. |
|
logon_guid |
string |
Logon GUID. |
|
logon_id |
string |
Logon ID. |
|
logon_server |
string |
Logon server name (it is a free text). The server name of the URL. |
|
logon_srcip |
ip |
Logon remote IP. It could be user's IP, and a remote IP. |
|
logon_transmitted_services |
string |
The list of transmitted services. |
|
logon_type |
string |
Logon type. |
|
logon_user_claims |
string |
Logon user claims. |
|
logon_virtual_account |
string |
Logon virtual account information. |
Network
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
net_direction |
string |
Network direction. |
|
net_name |
string |
Network name. |
|
net_payloadid |
uint32 |
Network payload ID. |
|
net_pktlosspct |
string |
The package loss percentage info. |
|
net_proto |
string |
Network protocol. |
|
net_rcvdpkts |
uint64 |
Number of received packets. |
|
net_recvbytes |
uint64 |
Received bytes. |
|
net_sentbytes |
uint64 |
Sent bytes. |
|
net_sentpkts |
uint64 |
Number of sent packets. |
|
net_sessionduration |
uint32 |
Session duration. |
|
net_sessionid |
string |
Session ID. |
|
net_ssid |
string |
Network SSID. |
Process
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
process_call_trace |
string |
Stack trace of where open process is called. |
|
process_command_line |
string |
Command arguments that were were executed by the process in the endpoint. |
|
process_company |
string |
Process company information. |
|
process_guid |
string |
Process global unique identifer used to identify a process across other operating systems. |
|
process_hash |
string |
Process hash value. |
|
process_hash_type |
string |
Process hash type. |
|
process_id |
uint32 |
Process ID. |
|
process_injected_address |
string |
The memory address where the subprocess is injected. |
|
process_integrity_level |
string |
Process integrity level. |
|
process_name |
string |
Process name. |
|
process_parent_name |
string |
Process parent name. |
|
process_status |
string |
Process hidden or other status information. |
Protocol
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
dns_additional_name |
string |
DNS additional name. |
|
dns_query |
string |
DNS query data. |
|
dns_query_class |
string |
DNS query class. |
|
dns_querytype |
string |
DNS query type. |
|
dns_rejected |
string |
The server responded to the query but no answers were given. |
|
dns_response |
string |
DNS response data. |
|
dns_rtt |
uint32 |
Round trip time (RTT) of the DNS query to answer. |
|
dns_server |
string |
DNS server name. |
|
dns_transaction_id |
string |
Hexadecimal identifier assigned by the program that generated the DNS query. |
|
http_cookie |
string |
HTTP cookie. |
|
http_method |
string |
HTTP method. |
|
http_referer |
string |
HTTP referer. |
|
http_response_body |
string |
The raw HTTP (response) body. |
|
http_response_time |
uint32 |
The amount of time in milliseconds it took to receive a response in the server. |
|
http_status_code |
uint16 |
HTTP response status code. 1XX Informational codes; 2XX Success codes; 3XX Redirection codes; 4XX Client error codes; 5XX Server error codes. |
|
http_status_message |
string |
HTTP server reply message. |
|
http_url |
string |
HTTP URL. |
|
http_useragent |
string |
HTTP user agent. |
|
http_version |
string |
HTTP request version. |
|
mail_attachment |
string |
Mail attachment. |
|
mail_from |
string |
Mail from. |
|
mail_size |
uint32 |
Mail size. |
|
mail_subject |
string |
Mail subject. |
|
mail_to |
string |
Mail to. |
Registry
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
registry_hive_path |
string |
A hive is a logical group of keys, subkeys, and values in the registry that has a set of supporting files loaded into memory when the operating system is started or a user logs in. |
|
registry_key_access_rights |
string |
The Windows security model enables you to control access to registry keys. The valid access rights for registry keys. |
|
registry_key_name |
string |
This field contains the key name without the full path. Take in consideration the name of the key value in the registry key path. |
|
registry_key_path |
string |
Next-level down from registry root-keys. This field contains the full path of a registry key. |
|
registry_root_key |
string |
Root-Keys are the root, or primary divisions, of the registry. They do not contain configuration data; they contain the keys, subkeys, and values in which the data is stored. |
|
registry_value_data |
string |
Each registry key value consists of a value name and its associated data. Registry key value data store the actual configuration data for the operating system and the programs that run on the system. |
|
registry_value_name |
string |
Registry values are the lowest-level element in the registry. They appear in the right pane of the registry editor window. |
Source
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
src_asset_id |
string |
Source asset id. |
|
src_domain |
string |
Source domain. |
|
src_geo |
string |
Source geo. |
|
src_geo_city |
string |
Source geo city information. |
|
src_geo_country |
string |
Source geo country. |
|
src_geo_country_code |
string |
Source geo country code. |
|
src_geo_latitude |
string |
Source geo latitude. |
|
src_geo_longitude |
string |
Source geo longitude. |
|
src_geo_region |
string |
Source geo region. |
|
src_intf |
string |
Source interface. |
|
src_intf_guid |
string |
GUID of the network interface which was used for authentication request. |
|
src_ip |
ip |
Source IP. |
|
src_mac |
string |
Source MAC |
|
src_natip |
ip |
Source NAT IP. |
|
src_natport |
uint16 |
Source NAT port. |
|
src_port |
uint16 |
Source port. |
TLS
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
tls_cipher |
string |
The cipher (encryption) parameters used to make the TLS connection. |
|
tls_curve |
string |
Elliptic curve the server chose when using ECDH/ECDHE. |
|
tls_established |
string |
Indicates if the session has been established successfully, or if it was aborted during the handshake. |
|
tls_next_protocol |
string |
Next protocol the server chose using the application layer next protocol extension, if present. |
|
tls_resumed |
string |
If the session was resumed from previous established connection. |
|
tls_server_name |
string |
The name of the requested server/destination; this should be copied to dst_host_name. |
|
tls_version |
string |
Version of TLS/SSL used (SSLv3.0, TLSv1.1, TLSv1.2, or TLSv1.3). |
Threat
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
threat_action |
string |
Threat action. |
|
threat_category |
string |
Threat category provided by the alert. |
|
threat_direction |
string |
Threat direction. |
|
threat_id |
string |
Threat ID. |
|
threat_message |
string |
Threat message provided by the alert. |
|
threat_name |
string |
Threat name. |
|
threat_pattern |
string |
Threat pattern. |
|
threat_ref |
string |
Threat reference. |
|
threat_score |
uint32 |
Threat score. |
|
threat_severity |
string |
Threat severity. |
|
threat_type |
string |
Threat type. |
User
|
Normalized fabric log field |
Type |
Description |
|---|---|---|
|
user_authtype |
string |
User authtype. |
|
user_classification |
string |
User importance as per data source. |
|
user_domain |
string |
User domain. |
|
user_email |
string |
User email. |
|
user_group |
string |
User group. |
|
user_id |
string |
User's ID/username (login). |
|
user_location |
string |
User location info. |
|
user_name |
string |
User's full name. |
|
user_org |
string |
User organization. |
|
user_phone |
string |
User phone number. |
|
user_role |
string |
User role. |
|
user_social |
string |
User's social account information. |