Fortinet white logo
Fortinet white logo

Fabric log field descriptions

Fabric log field descriptions

The normalized fabric log fields are organized in the following categories.

Category

Description

base

Metadata as the proprietary fields of FortiAnalyzer.

data_source

Metadata as the data source fields of SIEM parser.

Application

Application data. Specifies the shared communication service and application's information used by hosts in a communications network.

Destination

Destination data. Represents movement through geographic space, from a source to a destination.

Event

Event data. Collected and stored by various tracking tools or methods in order to provide insights about user behavior, traffic patterns, and other metrics related to online events.

File

File data. Stores information to be used by a computer application or system.

Host

Host data. Stores information of a computer or other device that communicates with other hosts on a network.

Logon

Logon data. Defines metadata about the logon events.

Network

Network data. Defines metadata about network information seen in a typical OSI layer.

Process

Process data. Defines metadata about processes in an system. Isolated memory address space that is used to run a program.

Protocol

Protocol data. Defines metadata about protocol related information for transmitting/exchanging data between the devices.

Registry

Registry data. Defines metadata about Windows registry entries in a system.

Source

Source data. Represents movement through geographic space, from a source to a destination.

TLS

Transport Layer Security (TLS) data.

Threat

Threat data. Refers to a known list of malicious threat information.

User

User data. Defines metadata about users in a network environment.

The following tables list the available normalized fabric log fields in FortiAnalyzer 7.6.3.

base

Normalized fabric log field

Type

Description

adom_oid

uint32

ADOM ID from DVM for internal use.

dstepid

uint32

Endpoint ID used as key for FortiAnalyzer-DST-UEBA correlation.

dsteuid

uint32

End-user ID used as key for FortiAnalyzer-DST-UEBA correlation.

epid

uint32

Endpoint ID used as key for FortiAnalyzer-UEBA correlation.

euid

uint32

End-user ID used as key for FortiAnalyzer-UEBA correlation.

itime

uint32

Timestamp set by FortiAnalyzer when it receives the data.

loguid

uint64

Unique ID set by FortiAnalyzer on each log for internal use.

data_source

Normalized fabric log field

Type

Description

data_parsername

string

Parser name used for parsing data.

data_sourceid

string

Machine\Host\Device\VM ID for the data source.

data_sourcename

string

Machine\Host\Device\VM Name for the data source.

data_sourcetype

string

Data source type.

data_sourceversion

string

Data source version.

data_timestamp

uint32

Timestamp set by data source.

Application

Normalized fabric log field

Type

Description

app_action

string

The operation the user performed in the context of the application.

app_cat

string

Application category.

app_id

uint32

Application ID.

app_name

string

Application name.

app_proc

string

Process name.

app_ref

string

Reference for additional information about application.

app_service

string

Service name.

app_state

string

Application state.

app_ver

string

Application version.

Destination

Normalized fabric log field

Type

Description

dst_asset_id

string

Destination asset ID.

dst_domain

string

Destination domain name.

dst_geo

string

Destination geo.

dst_geo_city

string

Destination geo city information.

dst_geo_country

string

Destination geo country.

dst_geo_country_code

string

Destination geo country code.

dst_geo_latitude

string

Destination geo latitude.

dst_geo_longitude

string

Destination geo longitude.

dst_geo_region

string

Destination geo region.

dst_intf

string

Destination interface.

dst_intf_guid

string

GUID of the network interface which was used for authentication request.

dst_ip

ip

Destination IP.

dst_mac

string

Destination MAC.

dst_natip

ip

Destination NAT IP.

dst_natport

uint16

Destination NAT port.

dst_port

uint16

Destination port.

Event

Normalized fabric log field

Type

Description

event_action

string

Main action taken.

event_cat

string

Event category.

event_count

uint32

The number of aggregated events.

event_creation_time

uint32

Original time when event/log was created as reported from the log source itself.

event_duration

uint32

The length/duration of the event in seconds (for example, 1 min is 60.0).

event_end_time

uint32

The time in which the event ended.

event_error

string

Information about an error.

event_error_code

uint32

Integer that defines a particular error.

event_id

uint32

Event\Log ID from data source.

event_message

string

Main message from data source or set by parser.

event_outcome

string

Event outcome.

event_policy

string

Event policy.

event_profile

string

Event profile.

event_ref

string

Reference for additional info about event.

event_report_url

string

URL of the full analysis report.

event_resource_group

string

The resource group to which the device generating the record belongs. This might be an AWS account, or an Azure subscription or Resource Group.

event_resource_id

string

The resource ID of the device generating the message.

event_severity

string

Event severity.

event_source

string

Data\Event source on Application layer.

event_start_time

uint32

The time in which the event stated.

event_status

string

Defines the status of a particular event.

event_status_code

uint32

Integer that defines a particular status.

event_subtype

string

Event subtype.

event_type

string

Event type.

event_uuid

string

Original unique ID specific to the log/event assigned to the event (not original).

event_vendor

string

The vendor of the product generating the event.

File

Normalized fabric log field

Type

Description

file_accessetime

uint32

File accessed time.

file_createtime

uint32

File create time.

file_ext

string

File extention.

file_hash

string

File hash.

file_hashtype

string

File hash type.

file_name

string

File name.

file_path

string

File path.

file_size

string

File size.

Host

Normalized fabric log field

Type

Description

host_classification

string

Host classification.

host_hwvendor

string

Host hardware vendor.

host_hwver

string

Host hardware version.

host_ip

ip

Host IP.

host_location

string

Host location.

host_mac

string

Hostname MAC.

host_model_name

string

Host model name.

host_name

string

Host name.

host_osfamily

string

Host OS family.

host_osname

string

Host OS name.

host_osver

string

Host OS version.

host_owner

string

Host owner.

host_type

string

Host type.

host_uid

string

EDR Agent ID such as FortiClient UID.

Logon

Normalized fabric log field

Type

Description

logon_authentication

string

The name of the authentication package which was used for the logon authentication process.

logon_device_claims

string

Logon device claims.

logon_guid

string

Logon GUID.

logon_id

string

Logon ID.

logon_server

string

Logon server name (it is a free text). The server name of the URL.

logon_srcip

ip

Logon remote IP. It could be user's IP, and a remote IP.

logon_transmitted_services

string

The list of transmitted services.

logon_type

string

Logon type.

logon_user_claims

string

Logon user claims.

logon_virtual_account

string

Logon virtual account information.

Network

Normalized fabric log field

Type

Description

net_direction

string

Network direction.

net_name

string

Network name.

net_payloadid

uint32

Network payload ID.

net_pktlosspct

string

The package loss percentage info.

net_proto

string

Network protocol.

net_rcvdpkts

uint64

Number of received packets.

net_recvbytes

uint64

Received bytes.

net_sentbytes

uint64

Sent bytes.

net_sentpkts

uint64

Number of sent packets.

net_sessionduration

uint32

Session duration.

net_sessionid

string

Session ID.

net_ssid

string

Network SSID.

Process

Normalized fabric log field

Type

Description

process_call_trace

string

Stack trace of where open process is called.

process_command_line

string

Command arguments that were were executed by the process in the endpoint.

process_company

string

Process company information.

process_guid

string

Process global unique identifer used to identify a process across other operating systems.

process_hash

string

Process hash value.

process_hash_type

string

Process hash type.

process_id

uint32

Process ID.

process_injected_address

string

The memory address where the subprocess is injected.

process_integrity_level

string

Process integrity level.

process_name

string

Process name.

process_parent_name

string

Process parent name.

process_status

string

Process hidden or other status information.

Protocol

Normalized fabric log field

Type

Description

dns_additional_name

string

DNS additional name.

dns_query

string

DNS query data.

dns_query_class

string

DNS query class.

dns_querytype

string

DNS query type.

dns_rejected

string

The server responded to the query but no answers were given.

dns_response

string

DNS response data.

dns_rtt

uint32

Round trip time (RTT) of the DNS query to answer.

dns_server

string

DNS server name.

dns_transaction_id

string

Hexadecimal identifier assigned by the program that generated the DNS query.

http_cookie

string

HTTP cookie.

http_method

string

HTTP method.

http_referer

string

HTTP referer.

http_response_body

string

The raw HTTP (response) body.

http_response_time

uint32

The amount of time in milliseconds it took to receive a response in the server.

http_status_code

uint16

HTTP response status code. 1XX Informational codes; 2XX Success codes; 3XX Redirection codes; 4XX Client error codes; 5XX Server error codes.

http_status_message

string

HTTP server reply message.

http_url

string

HTTP URL.

http_useragent

string

HTTP user agent.

http_version

string

HTTP request version.

mail_attachment

string

Mail attachment.

mail_from

string

Mail from.

mail_size

uint32

Mail size.

mail_subject

string

Mail subject.

mail_to

string

Mail to.

Registry

Normalized fabric log field

Type

Description

registry_hive_path

string

A hive is a logical group of keys, subkeys, and values in the registry that has a set of supporting files loaded into memory when the operating system is started or a user logs in.

registry_key_access_rights

string

The Windows security model enables you to control access to registry keys. The valid access rights for registry keys.

registry_key_name

string

This field contains the key name without the full path. Take in consideration the name of the key value in the registry key path.

registry_key_path

string

Next-level down from registry root-keys. This field contains the full path of a registry key.

registry_root_key

string

Root-Keys are the root, or primary divisions, of the registry. They do not contain configuration data; they contain the keys, subkeys, and values in which the data is stored.

registry_value_data

string

Each registry key value consists of a value name and its associated data. Registry key value data store the actual configuration data for the operating system and the programs that run on the system.

registry_value_name

string

Registry values are the lowest-level element in the registry. They appear in the right pane of the registry editor window.

Source

Normalized fabric log field

Type

Description

src_asset_id

string

Source asset id.

src_domain

string

Source domain.

src_geo

string

Source geo.

src_geo_city

string

Source geo city information.

src_geo_country

string

Source geo country.

src_geo_country_code

string

Source geo country code.

src_geo_latitude

string

Source geo latitude.

src_geo_longitude

string

Source geo longitude.

src_geo_region

string

Source geo region.

src_intf

string

Source interface.

src_intf_guid

string

GUID of the network interface which was used for authentication request.

src_ip

ip

Source IP.

src_mac

string

Source MAC

src_natip

ip

Source NAT IP.

src_natport

uint16

Source NAT port.

src_port

uint16

Source port.

TLS

Normalized fabric log field

Type

Description

tls_cipher

string

The cipher (encryption) parameters used to make the TLS connection.

tls_curve

string

Elliptic curve the server chose when using ECDH/ECDHE.

tls_established

string

Indicates if the session has been established successfully, or if it was aborted during the handshake.

tls_next_protocol

string

Next protocol the server chose using the application layer next protocol extension, if present.

tls_resumed

string

If the session was resumed from previous established connection.

tls_server_name

string

The name of the requested server/destination; this should be copied to dst_host_name.

tls_version

string

Version of TLS/SSL used (SSLv3.0, TLSv1.1, TLSv1.2, or TLSv1.3).

Threat

Normalized fabric log field

Type

Description

threat_action

string

Threat action.

threat_category

string

Threat category provided by the alert.

threat_direction

string

Threat direction.

threat_id

string

Threat ID.

threat_message

string

Threat message provided by the alert.

threat_name

string

Threat name.

threat_pattern

string

Threat pattern.

threat_ref

string

Threat reference.

threat_score

uint32

Threat score.

threat_severity

string

Threat severity.

threat_type

string

Threat type.

User

Normalized fabric log field

Type

Description

user_authtype

string

User authtype.

user_classification

string

User importance as per data source.

user_domain

string

User domain.

user_email

string

User email.

user_group

string

User group.

user_id

string

User's ID/username (login).

user_location

string

User location info.

user_name

string

User's full name.

user_org

string

User organization.

user_phone

string

User phone number.

user_role

string

User role.

user_social

string

User's social account information.

Fabric log field descriptions

Fabric log field descriptions

The normalized fabric log fields are organized in the following categories.

Category

Description

base

Metadata as the proprietary fields of FortiAnalyzer.

data_source

Metadata as the data source fields of SIEM parser.

Application

Application data. Specifies the shared communication service and application's information used by hosts in a communications network.

Destination

Destination data. Represents movement through geographic space, from a source to a destination.

Event

Event data. Collected and stored by various tracking tools or methods in order to provide insights about user behavior, traffic patterns, and other metrics related to online events.

File

File data. Stores information to be used by a computer application or system.

Host

Host data. Stores information of a computer or other device that communicates with other hosts on a network.

Logon

Logon data. Defines metadata about the logon events.

Network

Network data. Defines metadata about network information seen in a typical OSI layer.

Process

Process data. Defines metadata about processes in an system. Isolated memory address space that is used to run a program.

Protocol

Protocol data. Defines metadata about protocol related information for transmitting/exchanging data between the devices.

Registry

Registry data. Defines metadata about Windows registry entries in a system.

Source

Source data. Represents movement through geographic space, from a source to a destination.

TLS

Transport Layer Security (TLS) data.

Threat

Threat data. Refers to a known list of malicious threat information.

User

User data. Defines metadata about users in a network environment.

The following tables list the available normalized fabric log fields in FortiAnalyzer 7.6.3.

base

Normalized fabric log field

Type

Description

adom_oid

uint32

ADOM ID from DVM for internal use.

dstepid

uint32

Endpoint ID used as key for FortiAnalyzer-DST-UEBA correlation.

dsteuid

uint32

End-user ID used as key for FortiAnalyzer-DST-UEBA correlation.

epid

uint32

Endpoint ID used as key for FortiAnalyzer-UEBA correlation.

euid

uint32

End-user ID used as key for FortiAnalyzer-UEBA correlation.

itime

uint32

Timestamp set by FortiAnalyzer when it receives the data.

loguid

uint64

Unique ID set by FortiAnalyzer on each log for internal use.

data_source

Normalized fabric log field

Type

Description

data_parsername

string

Parser name used for parsing data.

data_sourceid

string

Machine\Host\Device\VM ID for the data source.

data_sourcename

string

Machine\Host\Device\VM Name for the data source.

data_sourcetype

string

Data source type.

data_sourceversion

string

Data source version.

data_timestamp

uint32

Timestamp set by data source.

Application

Normalized fabric log field

Type

Description

app_action

string

The operation the user performed in the context of the application.

app_cat

string

Application category.

app_id

uint32

Application ID.

app_name

string

Application name.

app_proc

string

Process name.

app_ref

string

Reference for additional information about application.

app_service

string

Service name.

app_state

string

Application state.

app_ver

string

Application version.

Destination

Normalized fabric log field

Type

Description

dst_asset_id

string

Destination asset ID.

dst_domain

string

Destination domain name.

dst_geo

string

Destination geo.

dst_geo_city

string

Destination geo city information.

dst_geo_country

string

Destination geo country.

dst_geo_country_code

string

Destination geo country code.

dst_geo_latitude

string

Destination geo latitude.

dst_geo_longitude

string

Destination geo longitude.

dst_geo_region

string

Destination geo region.

dst_intf

string

Destination interface.

dst_intf_guid

string

GUID of the network interface which was used for authentication request.

dst_ip

ip

Destination IP.

dst_mac

string

Destination MAC.

dst_natip

ip

Destination NAT IP.

dst_natport

uint16

Destination NAT port.

dst_port

uint16

Destination port.

Event

Normalized fabric log field

Type

Description

event_action

string

Main action taken.

event_cat

string

Event category.

event_count

uint32

The number of aggregated events.

event_creation_time

uint32

Original time when event/log was created as reported from the log source itself.

event_duration

uint32

The length/duration of the event in seconds (for example, 1 min is 60.0).

event_end_time

uint32

The time in which the event ended.

event_error

string

Information about an error.

event_error_code

uint32

Integer that defines a particular error.

event_id

uint32

Event\Log ID from data source.

event_message

string

Main message from data source or set by parser.

event_outcome

string

Event outcome.

event_policy

string

Event policy.

event_profile

string

Event profile.

event_ref

string

Reference for additional info about event.

event_report_url

string

URL of the full analysis report.

event_resource_group

string

The resource group to which the device generating the record belongs. This might be an AWS account, or an Azure subscription or Resource Group.

event_resource_id

string

The resource ID of the device generating the message.

event_severity

string

Event severity.

event_source

string

Data\Event source on Application layer.

event_start_time

uint32

The time in which the event stated.

event_status

string

Defines the status of a particular event.

event_status_code

uint32

Integer that defines a particular status.

event_subtype

string

Event subtype.

event_type

string

Event type.

event_uuid

string

Original unique ID specific to the log/event assigned to the event (not original).

event_vendor

string

The vendor of the product generating the event.

File

Normalized fabric log field

Type

Description

file_accessetime

uint32

File accessed time.

file_createtime

uint32

File create time.

file_ext

string

File extention.

file_hash

string

File hash.

file_hashtype

string

File hash type.

file_name

string

File name.

file_path

string

File path.

file_size

string

File size.

Host

Normalized fabric log field

Type

Description

host_classification

string

Host classification.

host_hwvendor

string

Host hardware vendor.

host_hwver

string

Host hardware version.

host_ip

ip

Host IP.

host_location

string

Host location.

host_mac

string

Hostname MAC.

host_model_name

string

Host model name.

host_name

string

Host name.

host_osfamily

string

Host OS family.

host_osname

string

Host OS name.

host_osver

string

Host OS version.

host_owner

string

Host owner.

host_type

string

Host type.

host_uid

string

EDR Agent ID such as FortiClient UID.

Logon

Normalized fabric log field

Type

Description

logon_authentication

string

The name of the authentication package which was used for the logon authentication process.

logon_device_claims

string

Logon device claims.

logon_guid

string

Logon GUID.

logon_id

string

Logon ID.

logon_server

string

Logon server name (it is a free text). The server name of the URL.

logon_srcip

ip

Logon remote IP. It could be user's IP, and a remote IP.

logon_transmitted_services

string

The list of transmitted services.

logon_type

string

Logon type.

logon_user_claims

string

Logon user claims.

logon_virtual_account

string

Logon virtual account information.

Network

Normalized fabric log field

Type

Description

net_direction

string

Network direction.

net_name

string

Network name.

net_payloadid

uint32

Network payload ID.

net_pktlosspct

string

The package loss percentage info.

net_proto

string

Network protocol.

net_rcvdpkts

uint64

Number of received packets.

net_recvbytes

uint64

Received bytes.

net_sentbytes

uint64

Sent bytes.

net_sentpkts

uint64

Number of sent packets.

net_sessionduration

uint32

Session duration.

net_sessionid

string

Session ID.

net_ssid

string

Network SSID.

Process

Normalized fabric log field

Type

Description

process_call_trace

string

Stack trace of where open process is called.

process_command_line

string

Command arguments that were were executed by the process in the endpoint.

process_company

string

Process company information.

process_guid

string

Process global unique identifer used to identify a process across other operating systems.

process_hash

string

Process hash value.

process_hash_type

string

Process hash type.

process_id

uint32

Process ID.

process_injected_address

string

The memory address where the subprocess is injected.

process_integrity_level

string

Process integrity level.

process_name

string

Process name.

process_parent_name

string

Process parent name.

process_status

string

Process hidden or other status information.

Protocol

Normalized fabric log field

Type

Description

dns_additional_name

string

DNS additional name.

dns_query

string

DNS query data.

dns_query_class

string

DNS query class.

dns_querytype

string

DNS query type.

dns_rejected

string

The server responded to the query but no answers were given.

dns_response

string

DNS response data.

dns_rtt

uint32

Round trip time (RTT) of the DNS query to answer.

dns_server

string

DNS server name.

dns_transaction_id

string

Hexadecimal identifier assigned by the program that generated the DNS query.

http_cookie

string

HTTP cookie.

http_method

string

HTTP method.

http_referer

string

HTTP referer.

http_response_body

string

The raw HTTP (response) body.

http_response_time

uint32

The amount of time in milliseconds it took to receive a response in the server.

http_status_code

uint16

HTTP response status code. 1XX Informational codes; 2XX Success codes; 3XX Redirection codes; 4XX Client error codes; 5XX Server error codes.

http_status_message

string

HTTP server reply message.

http_url

string

HTTP URL.

http_useragent

string

HTTP user agent.

http_version

string

HTTP request version.

mail_attachment

string

Mail attachment.

mail_from

string

Mail from.

mail_size

uint32

Mail size.

mail_subject

string

Mail subject.

mail_to

string

Mail to.

Registry

Normalized fabric log field

Type

Description

registry_hive_path

string

A hive is a logical group of keys, subkeys, and values in the registry that has a set of supporting files loaded into memory when the operating system is started or a user logs in.

registry_key_access_rights

string

The Windows security model enables you to control access to registry keys. The valid access rights for registry keys.

registry_key_name

string

This field contains the key name without the full path. Take in consideration the name of the key value in the registry key path.

registry_key_path

string

Next-level down from registry root-keys. This field contains the full path of a registry key.

registry_root_key

string

Root-Keys are the root, or primary divisions, of the registry. They do not contain configuration data; they contain the keys, subkeys, and values in which the data is stored.

registry_value_data

string

Each registry key value consists of a value name and its associated data. Registry key value data store the actual configuration data for the operating system and the programs that run on the system.

registry_value_name

string

Registry values are the lowest-level element in the registry. They appear in the right pane of the registry editor window.

Source

Normalized fabric log field

Type

Description

src_asset_id

string

Source asset id.

src_domain

string

Source domain.

src_geo

string

Source geo.

src_geo_city

string

Source geo city information.

src_geo_country

string

Source geo country.

src_geo_country_code

string

Source geo country code.

src_geo_latitude

string

Source geo latitude.

src_geo_longitude

string

Source geo longitude.

src_geo_region

string

Source geo region.

src_intf

string

Source interface.

src_intf_guid

string

GUID of the network interface which was used for authentication request.

src_ip

ip

Source IP.

src_mac

string

Source MAC

src_natip

ip

Source NAT IP.

src_natport

uint16

Source NAT port.

src_port

uint16

Source port.

TLS

Normalized fabric log field

Type

Description

tls_cipher

string

The cipher (encryption) parameters used to make the TLS connection.

tls_curve

string

Elliptic curve the server chose when using ECDH/ECDHE.

tls_established

string

Indicates if the session has been established successfully, or if it was aborted during the handshake.

tls_next_protocol

string

Next protocol the server chose using the application layer next protocol extension, if present.

tls_resumed

string

If the session was resumed from previous established connection.

tls_server_name

string

The name of the requested server/destination; this should be copied to dst_host_name.

tls_version

string

Version of TLS/SSL used (SSLv3.0, TLSv1.1, TLSv1.2, or TLSv1.3).

Threat

Normalized fabric log field

Type

Description

threat_action

string

Threat action.

threat_category

string

Threat category provided by the alert.

threat_direction

string

Threat direction.

threat_id

string

Threat ID.

threat_message

string

Threat message provided by the alert.

threat_name

string

Threat name.

threat_pattern

string

Threat pattern.

threat_ref

string

Threat reference.

threat_score

uint32

Threat score.

threat_severity

string

Threat severity.

threat_type

string

Threat type.

User

Normalized fabric log field

Type

Description

user_authtype

string

User authtype.

user_classification

string

User importance as per data source.

user_domain

string

User domain.

user_email

string

User email.

user_group

string

User group.

user_id

string

User's ID/username (login).

user_location

string

User location info.

user_name

string

User's full name.

user_org

string

User organization.

user_phone

string

User phone number.

user_role

string

User role.

user_social

string

User's social account information.