Fortinet black logo

FortiOS Log Message Reference

Webfilter log support for CEF

Webfilter log support for CEF

The following is an example of a webfilter log on the FortiGate disk:

date=2018-12-27 time=11:23:50 logid="0316013056" type="utm" subtype="webfilter" eventtype="ftgd_blk" level="warning" vd="vdom1" eventtime=1545938629 policyid=1 sessionid=764 user="bob" srcip=10.1.100.11 srcport=59194 srcintf="port12" srcintfrole="undefined" dstip=185.230.61.185 dstport=80 dstintf="port11" dstintfrole="undefined" proto=6 service="HTTP" hostname="ambrishsriv.wixsite.com" profile="g-default" action="blocked" reqtype="direct" url="/bizsquads" sentbyte=96 rcvdbyte=0 direction="outgoing" msg="URL belongs to a denied category in policy" method="domain" cat=26 catdesc="Malicious Websites" crscore=60 crlevel="high"

The following is an example of a webfilter log sent in CEF format to a syslog server:

Dec 27 11:23:49 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|13056|utm:webfilter ftgd_blk blocked|4|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0316013056 cat=utm:webfilter FTNTFGTsubtype=webfilter FTNTFGTeventtype=ftgd_blk FTNTFGTlevel=warning FTNTFGTvd=vdom1 FTNTFGTeventtime=1545938629 FTNTFGTpolicyid=1 externalId=764 duser=bob src=10.1.100.11 spt=59194 deviceInboundInterface=port12 FTNTFGTsrcintfrole=undefined dst=185.230.61.185 dpt=80 deviceOutboundInterface=port11 FTNTFGTdstintfrole=undefined proto=6 app=HTTP dhost=ambrishsriv.wixsite.com FTNTFGTprofile=g-default act=blocked FTNTFGTreqtype=direct request=/bizsquads out=96 in=0 deviceDirection=1 msg=URL belongs to a denied category in policy FTNTFGTmethod=domain FTNTFGTcat=26 requestContext=Malicious Websites FTNTFGTcrscore=60 FTNTFGTcrlevel=high

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

hostname

dhost

catdesc

requestContext

Webfilter log support for CEF

The following is an example of a webfilter log on the FortiGate disk:

date=2018-12-27 time=11:23:50 logid="0316013056" type="utm" subtype="webfilter" eventtype="ftgd_blk" level="warning" vd="vdom1" eventtime=1545938629 policyid=1 sessionid=764 user="bob" srcip=10.1.100.11 srcport=59194 srcintf="port12" srcintfrole="undefined" dstip=185.230.61.185 dstport=80 dstintf="port11" dstintfrole="undefined" proto=6 service="HTTP" hostname="ambrishsriv.wixsite.com" profile="g-default" action="blocked" reqtype="direct" url="/bizsquads" sentbyte=96 rcvdbyte=0 direction="outgoing" msg="URL belongs to a denied category in policy" method="domain" cat=26 catdesc="Malicious Websites" crscore=60 crlevel="high"

The following is an example of a webfilter log sent in CEF format to a syslog server:

Dec 27 11:23:49 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|13056|utm:webfilter ftgd_blk blocked|4|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0316013056 cat=utm:webfilter FTNTFGTsubtype=webfilter FTNTFGTeventtype=ftgd_blk FTNTFGTlevel=warning FTNTFGTvd=vdom1 FTNTFGTeventtime=1545938629 FTNTFGTpolicyid=1 externalId=764 duser=bob src=10.1.100.11 spt=59194 deviceInboundInterface=port12 FTNTFGTsrcintfrole=undefined dst=185.230.61.185 dpt=80 deviceOutboundInterface=port11 FTNTFGTdstintfrole=undefined proto=6 app=HTTP dhost=ambrishsriv.wixsite.com FTNTFGTprofile=g-default act=blocked FTNTFGTreqtype=direct request=/bizsquads out=96 in=0 deviceDirection=1 msg=URL belongs to a denied category in policy FTNTFGTmethod=domain FTNTFGTcat=26 requestContext=Malicious Websites FTNTFGTcrscore=60 FTNTFGTcrlevel=high

The following table maps FortiOS log field names to CEF field names.

FortiOS Log Field Name

CEF Field Name

hostname

dhost

catdesc

requestContext