Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

8721 - MESGID_SWITCH_PROTO_NOTIF

8721 - MESGID_SWITCH_PROTO_NOTIF

Message ID: 8721

Message Description: MESGID_SWITCH_PROTO_NOTIF

Message Meaning: Switching protocols request (notice)

Type: AV

Category: SWITCHPROTO

Severity: Notice

Log Field Name

Description

Data Type

Length

action

The status of the session: blocked - Blocked infected file by AV engine passthrough - Allowed by AV engine monitored - Log, but do NOT block infected file analytics - Submitted to Sandbox for analysis

string

18

agent

User agent - eg. agent="Mozilla/5.0"

string

64

authserver

Server used to authenticate the involved user

string

64

craction

Threat Weight action

uint32

10

crlevel

Threat Weight Level

string

10

crscore

Threat Weight Score

uint32

10

date

Date

string

10

devid

string

16

direction

Message/packets direction

string

8

dstauthserver

string

64

dstcountry

string

64

dstintf

Destination Interface

string

32

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP Address

ip

39

dstport

Destination Port

uint16

5

dstuser

string

256

dstuuid

string

37

eventtime

Time when detection occured

uint64

20

eventtype

Event type of AV

string

32

fctuid

Forticlient user ID

string

32

from

Email address from the Email Headers (IMAP/POP3/SMTP)

string

128

group

Group name (authentication)

string

64

level

Log level

string

11

logid

Log ID

string

10

msg

Log message

string

4096

pdstport

uint16

5

policyid

Policy ID

uint32

10

policytype

string

24

poluuid

string

37

profile

The name of the profile that was used to detect and take action

string

64

proto

Protocol number

uint8

3

psrcport

uint16

5

service

Proxy service which scanned this traffic

string

5

sessionid

Session ID

uint32

10

srccountry

string

64

srcdomain

string

255

srcintf

Source Interface

string

32

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP Address

ip

39

srcport

Source Port

uint16

5

srcuuid

string

37

subservice

string

16

subtype

Subtype of the virus log

string

20

switchproto

Protocol used on the switch

string

128

time

Time

string

8

to

Email address(es) from the Email Headers (IMAP/POP3/SMTP)

string

512

type

Log type

string

16

tz

Time Zone

string

5

unauthuser

string

66

unauthusersource

string

66

url

The URL address

string

512

user

Username (authentication)

string

256

vd

VDOM name

string

32

vrf

uint8

3

8721 - MESGID_SWITCH_PROTO_NOTIF

8721 - MESGID_SWITCH_PROTO_NOTIF

Message ID: 8721

Message Description: MESGID_SWITCH_PROTO_NOTIF

Message Meaning: Switching protocols request (notice)

Type: AV

Category: SWITCHPROTO

Severity: Notice

Log Field Name

Description

Data Type

Length

action

The status of the session: blocked - Blocked infected file by AV engine passthrough - Allowed by AV engine monitored - Log, but do NOT block infected file analytics - Submitted to Sandbox for analysis

string

18

agent

User agent - eg. agent="Mozilla/5.0"

string

64

authserver

Server used to authenticate the involved user

string

64

craction

Threat Weight action

uint32

10

crlevel

Threat Weight Level

string

10

crscore

Threat Weight Score

uint32

10

date

Date

string

10

devid

string

16

direction

Message/packets direction

string

8

dstauthserver

string

64

dstcountry

string

64

dstintf

Destination Interface

string

32

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP Address

ip

39

dstport

Destination Port

uint16

5

dstuser

string

256

dstuuid

string

37

eventtime

Time when detection occured

uint64

20

eventtype

Event type of AV

string

32

fctuid

Forticlient user ID

string

32

from

Email address from the Email Headers (IMAP/POP3/SMTP)

string

128

group

Group name (authentication)

string

64

level

Log level

string

11

logid

Log ID

string

10

msg

Log message

string

4096

pdstport

uint16

5

policyid

Policy ID

uint32

10

policytype

string

24

poluuid

string

37

profile

The name of the profile that was used to detect and take action

string

64

proto

Protocol number

uint8

3

psrcport

uint16

5

service

Proxy service which scanned this traffic

string

5

sessionid

Session ID

uint32

10

srccountry

string

64

srcdomain

string

255

srcintf

Source Interface

string

32

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP Address

ip

39

srcport

Source Port

uint16

5

srcuuid

string

37

subservice

string

16

subtype

Subtype of the virus log

string

20

switchproto

Protocol used on the switch

string

128

time

Time

string

8

to

Email address(es) from the Email Headers (IMAP/POP3/SMTP)

string

512

type

Log type

string

16

tz

Time Zone

string

5

unauthuser

string

66

unauthusersource

string

66

url

The URL address

string

512

user

Username (authentication)

string

256

vd

VDOM name

string

32

vrf

uint8

3