Traffic log support for CEF
Following is an example of a traffic log on the FortiGate disk:
date=2016-02-12 time=11:11:29 logid=0000000013 type=traffic subtype=forward level=notice vd=vdom1 srcip=192.168.1.183 srcname="192.168.1.183" srcport=45719 srcintf="port15" dstip=192.168.70.184 dstname="192.168.70.184" dstport=80 dstintf="port19" poluuid=61c4243a-34ba-51e5-c32a-3859389a5162 sessionid=56633 proto=6 action=close policyid=10 dstcountry="Reserved" srccountry="Reserved" trandisp=snat transip=192.168.70.214 transport=45719 service="HTTP" appid=38783 app="Wget.Like" appcat="General.Interest" apprisk=low applist="default" appact=detected duration=7 sentbyte=398 rcvdbyte=1605 sentpkt=5 rcvdpkt=5 utmaction=block countav=1 countapp=1 crscore=50 craction=2 utmref=65502-0
Following is an example of an event log sent in CEF format to a syslog server:
Feb 12 11:11:30 syslog-800c CEF:0|Fortinet|Fortigate|v5.6.0|00013|traffic:forward close|3|FTNTFGTlogid=0000000013 cat=traffic:forward FTNTFGTsubtype=forward FTNTFGTlevel=notice FTNTFGTvd=vdom1 src=192.168.1.183 shost=192.168.1.183 spt=45719 deviceInboundInterface=port15 dst=192.168.70.184 dhost=192.168.70.184 dpt=80 deviceOutboundInterface=port19 FTNTFGTpoluuid=61c4243a-34ba-51e5-c32a-3859389a5162 externalId=56633 proto=6 act=close cs5=10 cs5Label=Policy Id FTNTFGTdstcountry=Reserved FTNTFGTsrccountry=Reserved FTNTFGTtrandisp=snat sourceTranslatedAddress=192.168.70.214 sourceTranslatedPort=45719 app=HTTP FTNTFGTappid=38783 FTNTFGTapp=Wget.Like FTNTFGTappcat=General.Interest FTNTFGTapprisk=low FTNTFGTapplist=default FTNTFGTappact=detected cn1=7 cn1Label=Duration out=398 in=1605 cn2=5 cn2Label=Packets Sent cn3=5 cn3Label=Packets Received FTNTFGTutmaction=block FTNTFGTcountav=1 FTNTFGTcountapp=1 FTNTFGTcrscore=50 FTNTFGTcraction=2
The following table maps FortiOS log field names to CEF field names.
FortiOS Log Field Name |
CEF Field Name |
---|---|
type: subtype |
cat |
srcip |
src |
srcport |
spt |
srcintf |
deviceInboundInterface |
dstip |
dst |
dstname |
dhost |
dstport |
dpt |
dstintf |
deviceOutboundInterface |
sessionid |
externalID |
proto |
proto |
action |
act |
policyid |
cs5=xx cs5Label=Policy Id |
transip |
sourceTranslatedAddress |
transport |
sourceTranslatedPort |
service |
app |
duration |
cn1=xx cn1Label=Duration |
sentbyte |
out |
rcvdbyte |
in |
sentpkt |
cn2=xx cn2Label=Packets Sent |
rcvdpkt |
cn3=xx cn3Label=Packets Received |