DLP log support for CEF
The following is an example of a DLP log on the FortiGate disk:
date=2018-12-27 time=14:29:36 logid="0954024576" type="utm" subtype="dlp" eventtype="dlp" level="warning" vd="vdom1" eventtime=1545949776 filteridx=1 dlpextra="test-dlp3" filtertype="file-type" filtercat="file" severity="medium" policyid=1 sessionid=12680 epoch=418303178 eventid=0 user="bob" srcip=10.1.100.11 srcport=33638 srcintf="port12" srcintfrole="undefined" dstip=172.18.62.158 dstport=80 dstintf="port11" dstintfrole="undefined" proto=6 service="HTTP" filetype="gif" direction="incoming" action="block" hostname="172.18.62.158" url="/dlp/flower.gif" agent="curl/7.47.0" filename="flower.gif" filesize=1209 profile="test-dlp"
The following is an example of a DLP log sent in CEF format to a syslog server:
Dec 27 14:29:36 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|24576|utm:dlp dlp block|4|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0954024576 cat=utm:dlp FTNTFGTsubtype=dlp FTNTFGTeventtype=dlp FTNTFGTlevel=warning FTNTFGTvd=vdom1 FTNTFGTeventtime=1545949776 FTNTFGTfilteridx=1 FTNTFGTdlpextra=test-dlp3 FTNTFGTfiltertype=file-type FTNTFGTfiltercat=file FTNTFGTseverity=medium FTNTFGTpolicyid=1 externalId=12680 FTNTFGTepoch=418303178 FTNTFGTeventid=0 duser=bob src=10.1.100.11 spt=33638 deviceInboundInterface=port12 FTNTFGTsrcintfrole=undefined dst=172.18.62.158 dpt=80 deviceOutboundInterface=port11 FTNTFGTdstintfrole=undefined proto=6 app=HTTP FTNTFGTfiletype=gif deviceDirection=0 act=block dhost=172.18.62.158 request=/dlp/flower.gif requestClientApplication=curl/7.47.0 fname=flower.gif fsize=1209 FTNTFGTprofile=test-dlp
The following table maps FortiOS log field names to CEF field names.
FortiOS Log Field Name |
CEF Field Name |
---|---|
filename |
fname |