Fortinet black logo

FortiOS Log Message Reference

VoIP log support for CEF

The following is an example of an VoIP log on the FortiGate disk:

date=2018-12-27 time=16:47:09 logid="0814044032" type="utm" subtype="voip" eventtype="voip" level="information" vd="vdom1" eventtime=1545958028 session_id=18975 epoch=0 event_id=6857 srcip=10.1.100.11 src_port=5060 dstip=172.16.200.55 dst_port=5060 proto=17 src_int="port12" dst_int="port11" policy_id=1 profile="default" voip_proto="sip" kind="call" action="permit" status="start" duration=0 dir="session_origin" call_id="3444-13134@127.0.0.1" from="sip:sipp@127.0.0.1:5060" to="sip:service@172.16.200.55:5060"

The following is an example of an VoIP sent in CEF format to a syslog server:

Dec 27 16:47:08 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|44032|utm:voip voip permit start|2|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0814044032 cat=utm:voip FTNTFGTsubtype=voip FTNTFGTeventtype=voip FTNTFGTlevel=information FTNTFGTvd=vdom1 FTNTFGTeventtime=1545958028 externalId=18975 FTNTFGTepoch=0 FTNTFGTevent_id=6857 src=10.1.100.11 spt=5060 dst=172.16.200.55 dpt=5060 proto=17 deviceInboundInterface=port12 deviceOutboundInterface=port11 FTNTFGTpolicy_id=1 FTNTFGTprofile=default FTNTFGTvoip_proto=sip FTNTFGTkind=call act=permit outcome=start FTNTFGTduration=0 FTNTFGTdir=session_origin FTNTFGTcall_id=3444-13134@127.0.0.1 suser=sip:sipp@127.0.0.1:5060 duser=sip:service@172.16.200.55:5060

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

status

outcome

from

suser

to

duser

The following is an example of an VoIP log on the FortiGate disk:

date=2018-12-27 time=16:47:09 logid="0814044032" type="utm" subtype="voip" eventtype="voip" level="information" vd="vdom1" eventtime=1545958028 session_id=18975 epoch=0 event_id=6857 srcip=10.1.100.11 src_port=5060 dstip=172.16.200.55 dst_port=5060 proto=17 src_int="port12" dst_int="port11" policy_id=1 profile="default" voip_proto="sip" kind="call" action="permit" status="start" duration=0 dir="session_origin" call_id="3444-13134@127.0.0.1" from="sip:sipp@127.0.0.1:5060" to="sip:service@172.16.200.55:5060"

The following is an example of an VoIP sent in CEF format to a syslog server:

Dec 27 16:47:08 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|44032|utm:voip voip permit start|2|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0814044032 cat=utm:voip FTNTFGTsubtype=voip FTNTFGTeventtype=voip FTNTFGTlevel=information FTNTFGTvd=vdom1 FTNTFGTeventtime=1545958028 externalId=18975 FTNTFGTepoch=0 FTNTFGTevent_id=6857 src=10.1.100.11 spt=5060 dst=172.16.200.55 dpt=5060 proto=17 deviceInboundInterface=port12 deviceOutboundInterface=port11 FTNTFGTpolicy_id=1 FTNTFGTprofile=default FTNTFGTvoip_proto=sip FTNTFGTkind=call act=permit outcome=start FTNTFGTduration=0 FTNTFGTdir=session_origin FTNTFGTcall_id=3444-13134@127.0.0.1 suser=sip:sipp@127.0.0.1:5060 duser=sip:service@172.16.200.55:5060

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

status

outcome

from

suser

to

duser