Fortinet black logo

FortiOS Log Message Reference

18432 - LOGID_ATTCK_ANOMALY_TCP_UDP

Message ID: 18432

Message Description: LOGID_ATTCK_ANOMALY_TCP_UDP

Message Meaning: Attack detected by UCP/TCP anomaly

Type: Anomaly

Category: ANOMALY

Severity: Alert

Log Field Name

Description

Data Type

Length

action

Action

string

16

attack

Attack

string

256

attackid

Attack ID

uint32

10

count

Count

uint32

10

craction

Client Reputation Action

uint32

10

crlevel

Client Reputation Level

string

10

crscore

Client Reputation Score

uint32

10

date

Date

string

10

devid

Deivce ID

string

16

dstintf

Destination Interface

string

64

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP

ip

39

dstport

Destination Port

uint16

5

eventtime

Time when detection occured

uint64

20

eventtype

Event Type

string

32

fctuid

FortiClient UID

string

32

group

User Group Name

string

64

level

Log Level

string

11

logid

Log ID

string

10

msg

Log Message

string

518

policyid

Policy ID

uint32

10

policytype

Policy type

string

24

proto

Protocol

uint8

3

ref

Reference

string

4096

service

Name of Service

string

80

sessionid

Session ID

uint32

10

severity

Severity

string

8

srccountry

Country name for Source IP

string

64

srcdomain

string

255

srcintf

Source Interface

string

64

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP

ip

39

srcport

Source Port

uint16

5

subtype

Log Subtype

string

20

time

Time

string

8

type

Log Type

string

16

tz

Time zone

string

5

unauthuser

Unauthenticated user

string

66

unauthusersource

Unauthenticated user source

string

66

user

User

string

256

vd

Virtual Domain Name

string

32

vrf

Virtual router forwarding

uint8

3

Message ID: 18432

Message Description: LOGID_ATTCK_ANOMALY_TCP_UDP

Message Meaning: Attack detected by UCP/TCP anomaly

Type: Anomaly

Category: ANOMALY

Severity: Alert

Log Field Name

Description

Data Type

Length

action

Action

string

16

attack

Attack

string

256

attackid

Attack ID

uint32

10

count

Count

uint32

10

craction

Client Reputation Action

uint32

10

crlevel

Client Reputation Level

string

10

crscore

Client Reputation Score

uint32

10

date

Date

string

10

devid

Deivce ID

string

16

dstintf

Destination Interface

string

64

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP

ip

39

dstport

Destination Port

uint16

5

eventtime

Time when detection occured

uint64

20

eventtype

Event Type

string

32

fctuid

FortiClient UID

string

32

group

User Group Name

string

64

level

Log Level

string

11

logid

Log ID

string

10

msg

Log Message

string

518

policyid

Policy ID

uint32

10

policytype

Policy type

string

24

proto

Protocol

uint8

3

ref

Reference

string

4096

service

Name of Service

string

80

sessionid

Session ID

uint32

10

severity

Severity

string

8

srccountry

Country name for Source IP

string

64

srcdomain

string

255

srcintf

Source Interface

string

64

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP

ip

39

srcport

Source Port

uint16

5

subtype

Log Subtype

string

20

time

Time

string

8

type

Log Type

string

16

tz

Time zone

string

5

unauthuser

Unauthenticated user

string

66

unauthusersource

Unauthenticated user source

string

66

user

User

string

256

vd

Virtual Domain Name

string

32

vrf

Virtual router forwarding

uint8

3