Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

18432 - LOGID_ATTCK_ANOMALY_TCP_UDP

18432 - LOGID_ATTCK_ANOMALY_TCP_UDP

Message ID: 18432

Message Description: LOGID_ATTCK_ANOMALY_TCP_UDP

Message Meaning: Attack detected by UDP/TCP anomaly

Type: Anomaly

Category: anomaly

Severity: Alert

Log Field Name

Description

Data Type

Length

vrf

Virtual router forwarding

uint16

3

vd

Virtual Domain Name

string

32

user

User

string

256

unauthusersource

Unauthenticated user source

string

66

unauthuser

Unauthenticated user

string

66

tz

Time zone

string

5

type

Log Type

string

16

time

Time

string

8

subtype

Log Subtype

string

20

srcport

Source Port

uint16

5

srcip

Source IP

ip

39

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcintf

Source Interface

string

64

srcdomain

string

255

srccountry

Country name for Source IP

string

64

severity

Severity

string

8

sessionid

Session ID

uint32

10

service

Name of Service

string

80

ref

Reference

string

4096

proto

Protocol

uint8

3

policytype

Policy type

string

24

policyid

Policy ID

uint32

10

msg

Log Message

string

518

logid

Log ID

string

10

level

Log Level

string

11

group

User Group Name

string

512

fctuid

FortiClient UID

string

32

eventtype

Event Type

string

32

eventtime

Time when detection occured

uint64

20

dstport

Destination Port

uint16

5

dstip

Destination IP

ip

39

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstintf

Destination Interface

string

64

dstcountry

string

64

devid

Deivce ID

string

16

date

Date

string

10

crscore

Client Reputation Score

uint32

10

crlevel

Client Reputation Level

string

10

craction

Client Reputation Action

uint32

10

count

Count

uint32

10

attackid

Attack ID

uint32

10

attack

Attack

string

256

action

Action

string

16

18432 - LOGID_ATTCK_ANOMALY_TCP_UDP

18432 - LOGID_ATTCK_ANOMALY_TCP_UDP

Message ID: 18432

Message Description: LOGID_ATTCK_ANOMALY_TCP_UDP

Message Meaning: Attack detected by UDP/TCP anomaly

Type: Anomaly

Category: anomaly

Severity: Alert

Log Field Name

Description

Data Type

Length

vrf

Virtual router forwarding

uint16

3

vd

Virtual Domain Name

string

32

user

User

string

256

unauthusersource

Unauthenticated user source

string

66

unauthuser

Unauthenticated user

string

66

tz

Time zone

string

5

type

Log Type

string

16

time

Time

string

8

subtype

Log Subtype

string

20

srcport

Source Port

uint16

5

srcip

Source IP

ip

39

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcintf

Source Interface

string

64

srcdomain

string

255

srccountry

Country name for Source IP

string

64

severity

Severity

string

8

sessionid

Session ID

uint32

10

service

Name of Service

string

80

ref

Reference

string

4096

proto

Protocol

uint8

3

policytype

Policy type

string

24

policyid

Policy ID

uint32

10

msg

Log Message

string

518

logid

Log ID

string

10

level

Log Level

string

11

group

User Group Name

string

512

fctuid

FortiClient UID

string

32

eventtype

Event Type

string

32

eventtime

Time when detection occured

uint64

20

dstport

Destination Port

uint16

5

dstip

Destination IP

ip

39

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstintf

Destination Interface

string

64

dstcountry

string

64

devid

Deivce ID

string

16

date

Date

string

10

crscore

Client Reputation Score

uint32

10

crlevel

Client Reputation Level

string

10

craction

Client Reputation Action

uint32

10

count

Count

uint32

10

attackid

Attack ID

uint32

10

attack

Attack

string

256

action

Action

string

16