Fortinet black logo

FortiOS Log Message Reference

DLP log support for CEF

DLP log support for CEF

The following is an example of a DLP log on the FortiGate disk:

date=2018-12-27 time=14:29:36 logid="0954024576" type="utm" subtype="dlp" eventtype="dlp" level="warning" vd="vdom1" eventtime=1545949776 filteridx=1 dlpextra="test-dlp3" filtertype="file-type" filtercat="file" severity="medium" policyid=1 sessionid=12680 epoch=418303178 eventid=0 user="bob" srcip=10.1.100.11 srcport=33638 srcintf="port12" srcintfrole="undefined" dstip=172.18.62.158 dstport=80 dstintf="port11" dstintfrole="undefined" proto=6 service="HTTP" filetype="gif" direction="incoming" action="block" hostname="172.18.62.158" url="/dlp/flower.gif" agent="curl/7.47.0" filename="flower.gif" filesize=1209 profile="test-dlp"

The following is an example of a DLP log sent in CEF format to a syslog server:

Dec 27 14:29:36 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|24576|utm:dlp dlp block|4|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0954024576 cat=utm:dlp FTNTFGTsubtype=dlp FTNTFGTeventtype=dlp FTNTFGTlevel=warning FTNTFGTvd=vdom1 FTNTFGTeventtime=1545949776 FTNTFGTfilteridx=1 FTNTFGTdlpextra=test-dlp3 FTNTFGTfiltertype=file-type FTNTFGTfiltercat=file FTNTFGTseverity=medium FTNTFGTpolicyid=1 externalId=12680 FTNTFGTepoch=418303178 FTNTFGTeventid=0 duser=bob src=10.1.100.11 spt=33638 deviceInboundInterface=port12 FTNTFGTsrcintfrole=undefined dst=172.18.62.158 dpt=80 deviceOutboundInterface=port11 FTNTFGTdstintfrole=undefined proto=6 app=HTTP FTNTFGTfiletype=gif deviceDirection=0 act=block dhost=172.18.62.158 request=/dlp/flower.gif requestClientApplication=curl/7.47.0 fname=flower.gif fsize=1209 FTNTFGTprofile=test-dlp

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

filename

fname

DLP log support for CEF

The following is an example of a DLP log on the FortiGate disk:

date=2018-12-27 time=14:29:36 logid="0954024576" type="utm" subtype="dlp" eventtype="dlp" level="warning" vd="vdom1" eventtime=1545949776 filteridx=1 dlpextra="test-dlp3" filtertype="file-type" filtercat="file" severity="medium" policyid=1 sessionid=12680 epoch=418303178 eventid=0 user="bob" srcip=10.1.100.11 srcport=33638 srcintf="port12" srcintfrole="undefined" dstip=172.18.62.158 dstport=80 dstintf="port11" dstintfrole="undefined" proto=6 service="HTTP" filetype="gif" direction="incoming" action="block" hostname="172.18.62.158" url="/dlp/flower.gif" agent="curl/7.47.0" filename="flower.gif" filesize=1209 profile="test-dlp"

The following is an example of a DLP log sent in CEF format to a syslog server:

Dec 27 14:29:36 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|24576|utm:dlp dlp block|4|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0954024576 cat=utm:dlp FTNTFGTsubtype=dlp FTNTFGTeventtype=dlp FTNTFGTlevel=warning FTNTFGTvd=vdom1 FTNTFGTeventtime=1545949776 FTNTFGTfilteridx=1 FTNTFGTdlpextra=test-dlp3 FTNTFGTfiltertype=file-type FTNTFGTfiltercat=file FTNTFGTseverity=medium FTNTFGTpolicyid=1 externalId=12680 FTNTFGTepoch=418303178 FTNTFGTeventid=0 duser=bob src=10.1.100.11 spt=33638 deviceInboundInterface=port12 FTNTFGTsrcintfrole=undefined dst=172.18.62.158 dpt=80 deviceOutboundInterface=port11 FTNTFGTdstintfrole=undefined proto=6 app=HTTP FTNTFGTfiletype=gif deviceDirection=0 act=block dhost=172.18.62.158 request=/dlp/flower.gif requestClientApplication=curl/7.47.0 fname=flower.gif fsize=1209 FTNTFGTprofile=test-dlp

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

filename

fname