Fortinet black logo

FortiOS Log Message Reference

Traffic log support for CEF

Traffic log support for CEF

Following is an example of a traffic log on the FortiGate disk:

date=2016-02-12 time=11:11:29 logid=0000000013 type=traffic subtype=forward level=notice vd=vdom1 srcip=192.168.1.183 srcname="192.168.1.183" srcport=45719 srcintf="port15" dstip=192.168.70.184 dstname="192.168.70.184" dstport=80 dstintf="port19" poluuid=61c4243a-34ba-51e5-c32a-3859389a5162 sessionid=56633 proto=6 action=close policyid=10 dstcountry="Reserved" srccountry="Reserved" trandisp=snat transip=192.168.70.214 transport=45719 service="HTTP" appid=38783 app="Wget.Like" appcat="General.Interest" apprisk=low applist="default" appact=detected duration=7 sentbyte=398 rcvdbyte=1605 sentpkt=5 rcvdpkt=5 utmaction=block countav=1 countapp=1 crscore=50 craction=2 utmref=65502-0

Following is an example of an event log sent in CEF format to a syslog server:

Feb 12 11:11:30 syslog-800c CEF:0|Fortinet|Fortigate|v5.6.0|00013|traffic:forward close|3|FTNTFGTlogid=0000000013 cat=traffic:forward FTNTFGTsubtype=forward FTNTFGTlevel=notice FTNTFGTvd=vdom1 src=192.168.1.183 shost=192.168.1.183 spt=45719 deviceInboundInterface=port15 dst=192.168.70.184 dhost=192.168.70.184 dpt=80 deviceOutboundInterface=port19 FTNTFGTpoluuid=61c4243a-34ba-51e5-c32a-3859389a5162 externalId=56633 proto=6 act=close cs5=10 cs5Label=Policy Id FTNTFGTdstcountry=Reserved FTNTFGTsrccountry=Reserved FTNTFGTtrandisp=snat sourceTranslatedAddress=192.168.70.214 sourceTranslatedPort=45719 app=HTTP FTNTFGTappid=38783 FTNTFGTapp=Wget.Like FTNTFGTappcat=General.Interest FTNTFGTapprisk=low FTNTFGTapplist=default FTNTFGTappact=detected cn1=7 cn1Label=Duration out=398 in=1605 cn2=5 cn2Label=Packets Sent cn3=5 cn3Label=Packets Received FTNTFGTutmaction=block FTNTFGTcountav=1 FTNTFGTcountapp=1 FTNTFGTcrscore=50 FTNTFGTcraction=2

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

type: subtype

cat

srcip

src

srcport

spt

srcintf

deviceInboundInterface

dstip

dst

dstname

dhost

dstport

dpt

dstintf

deviceOutboundInterface

sessionid

externalID

proto

proto

action

act

policyid

cs5=xx cs5Label=Policy Id

transip

sourceTranslatedAddress

transport

sourceTranslatedPort

service

app

duration

cn1=xx cn1Label=Duration

sentbyte

out

rcvdbyte

in

sentpkt

cn2=xx cn2Label=Packets Sent

rcvdpkt

cn3=xx cn3Label=Packets Received

Traffic log support for CEF

Following is an example of a traffic log on the FortiGate disk:

date=2016-02-12 time=11:11:29 logid=0000000013 type=traffic subtype=forward level=notice vd=vdom1 srcip=192.168.1.183 srcname="192.168.1.183" srcport=45719 srcintf="port15" dstip=192.168.70.184 dstname="192.168.70.184" dstport=80 dstintf="port19" poluuid=61c4243a-34ba-51e5-c32a-3859389a5162 sessionid=56633 proto=6 action=close policyid=10 dstcountry="Reserved" srccountry="Reserved" trandisp=snat transip=192.168.70.214 transport=45719 service="HTTP" appid=38783 app="Wget.Like" appcat="General.Interest" apprisk=low applist="default" appact=detected duration=7 sentbyte=398 rcvdbyte=1605 sentpkt=5 rcvdpkt=5 utmaction=block countav=1 countapp=1 crscore=50 craction=2 utmref=65502-0

Following is an example of an event log sent in CEF format to a syslog server:

Feb 12 11:11:30 syslog-800c CEF:0|Fortinet|Fortigate|v5.6.0|00013|traffic:forward close|3|FTNTFGTlogid=0000000013 cat=traffic:forward FTNTFGTsubtype=forward FTNTFGTlevel=notice FTNTFGTvd=vdom1 src=192.168.1.183 shost=192.168.1.183 spt=45719 deviceInboundInterface=port15 dst=192.168.70.184 dhost=192.168.70.184 dpt=80 deviceOutboundInterface=port19 FTNTFGTpoluuid=61c4243a-34ba-51e5-c32a-3859389a5162 externalId=56633 proto=6 act=close cs5=10 cs5Label=Policy Id FTNTFGTdstcountry=Reserved FTNTFGTsrccountry=Reserved FTNTFGTtrandisp=snat sourceTranslatedAddress=192.168.70.214 sourceTranslatedPort=45719 app=HTTP FTNTFGTappid=38783 FTNTFGTapp=Wget.Like FTNTFGTappcat=General.Interest FTNTFGTapprisk=low FTNTFGTapplist=default FTNTFGTappact=detected cn1=7 cn1Label=Duration out=398 in=1605 cn2=5 cn2Label=Packets Sent cn3=5 cn3Label=Packets Received FTNTFGTutmaction=block FTNTFGTcountav=1 FTNTFGTcountapp=1 FTNTFGTcrscore=50 FTNTFGTcraction=2

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

type: subtype

cat

srcip

src

srcport

spt

srcintf

deviceInboundInterface

dstip

dst

dstname

dhost

dstport

dpt

dstintf

deviceOutboundInterface

sessionid

externalID

proto

proto

action

act

policyid

cs5=xx cs5Label=Policy Id

transip

sourceTranslatedAddress

transport

sourceTranslatedPort

service

app

duration

cn1=xx cn1Label=Duration

sentbyte

out

rcvdbyte

in

sentpkt

cn2=xx cn2Label=Packets Sent

rcvdpkt

cn3=xx cn3Label=Packets Received