Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

61003 - LOG_ID_SSH_COMMAND_PASS_ALERT

61003 - LOG_ID_SSH_COMMAND_PASS_ALERT

Message ID: 61003

Message Description: LOG_ID_SSH_COMMAND_PASS_ALERT

Message Meaning: SSH shell command is detected

Type: SSH

Category: ssh-command

Severity: Alert

Log Field Name

Description

Data Type

Length

action

The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked

string

17

channeltype

Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp

string

15

command

Shell command

string

256

date

Date

string

10

devid

Device ID

string

16

direction

Direction of session

string

4096

dstintf

Destination Interface

string

32

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP

ip

39

dstport

Destination Port

uint16

5

eventtime

Event time

uint64

20

eventtype

Event Type

string

32

fctuid

FortiClient UID

string

32

group

Group name for authentication

string

64

level

Log level

string

11

logid

Log ID

string

10

login

SSH login Name

string

128

policyid

Policy ID

uint32

10

profile

Full profile name

string

64

proto

Protocol number

uint8

3

sessionid

Session ID

uint32

10

severity

Severity level of shell command

string

8

srcdomain

string

255

srcintf

Source Interface

string

32

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP

ip

39

srcport

Source Port

uint16

5

subtype

Log subtype

string

20

time

Time

string

8

type

Log type

string

16

tz

Time zone

string

5

unauthuser

Unauthenticated User

string

66

unauthusersource

Unauthenticated User Source

string

66

user

User name for authentication

string

256

vd

Virtual Domain Name

string

32

61003 - LOG_ID_SSH_COMMAND_PASS_ALERT

61003 - LOG_ID_SSH_COMMAND_PASS_ALERT

Message ID: 61003

Message Description: LOG_ID_SSH_COMMAND_PASS_ALERT

Message Meaning: SSH shell command is detected

Type: SSH

Category: ssh-command

Severity: Alert

Log Field Name

Description

Data Type

Length

action

The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked

string

17

channeltype

Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp

string

15

command

Shell command

string

256

date

Date

string

10

devid

Device ID

string

16

direction

Direction of session

string

4096

dstintf

Destination Interface

string

32

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP

ip

39

dstport

Destination Port

uint16

5

eventtime

Event time

uint64

20

eventtype

Event Type

string

32

fctuid

FortiClient UID

string

32

group

Group name for authentication

string

64

level

Log level

string

11

logid

Log ID

string

10

login

SSH login Name

string

128

policyid

Policy ID

uint32

10

profile

Full profile name

string

64

proto

Protocol number

uint8

3

sessionid

Session ID

uint32

10

severity

Severity level of shell command

string

8

srcdomain

string

255

srcintf

Source Interface

string

32

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP

ip

39

srcport

Source Port

uint16

5

subtype

Log subtype

string

20

time

Time

string

8

type

Log type

string

16

tz

Time zone

string

5

unauthuser

Unauthenticated User

string

66

unauthusersource

Unauthenticated User Source

string

66

user

User name for authentication

string

256

vd

Virtual Domain Name

string

32