VoIP log support for CEF
The following is an example of an VoIP log on the FortiGate disk:
date=2018-12-27 time=16:47:09 logid="0814044032" type="utm" subtype="voip" eventtype="voip" level="information" vd="vdom1" eventtime=1545958028 session_id=18975 epoch=0 event_id=6857 srcip=10.1.100.11 src_port=5060 dstip=172.16.200.55 dst_port=5060 proto=17 src_int="port12" dst_int="port11" policy_id=1 profile="default" voip_proto="sip" kind="call" action="permit" status="start" duration=0 dir="session_origin" call_id="3444-13134@127.0.0.1" from="sip:sipp@127.0.0.1:5060" to="sip:service@172.16.200.55:5060"
The following is an example of an VoIP sent in CEF format to a syslog server:
Dec 27 16:47:08 FGT-A-LOG CEF: 0|Fortinet|Fortigate|v6.0.3|44032|utm:voip voip permit start|2|deviceExternalId=FGT5HD3915800610 FTNTFGTlogid=0814044032 cat=utm:voip FTNTFGTsubtype=voip FTNTFGTeventtype=voip FTNTFGTlevel=information FTNTFGTvd=vdom1 FTNTFGTeventtime=1545958028 externalId=18975 FTNTFGTepoch=0 FTNTFGTevent_id=6857 src=10.1.100.11 spt=5060 dst=172.16.200.55 dpt=5060 proto=17 deviceInboundInterface=port12 deviceOutboundInterface=port11 FTNTFGTpolicy_id=1 FTNTFGTprofile=default FTNTFGTvoip_proto=sip FTNTFGTkind=call act=permit outcome=start FTNTFGTduration=0 FTNTFGTdir=session_origin FTNTFGTcall_id=3444-13134@127.0.0.1 suser=sip:sipp@127.0.0.1:5060 duser=sip:service@172.16.200.55:5060
The following table maps FortiOS log field names to CEF field names.
FortiOS Log Field Name |
CEF Field Name |
---|---|
status |
outcome |
from |
suser |
to |
duser |