Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

26 - LOG_ID_TRAFFIC_HTTP_TRANSACTION

26 - LOG_ID_TRAFFIC_HTTP_TRANSACTION

Message ID: 26

Message Description: LOG_ID_TRAFFIC_HTTP_TRANSACTION

Message Meaning: HTTP transaction

Type: Traffic

Category: http-transaction

Severity: Notice

Log Field Name

Description

Data Type

Length

wanout

WAN outgoing traffic in bytes

uint64

20

wanin

WAN incoming traffic in bytes

uint64

20

vd

Virtual domain name

string

32

utmaction

Security action performed by UTM

string

32

user

User name

string

256

url

URL

string

512

tz

Time zone

string

5

type

Log type

string

16

transid

uint32

10

tranport

NAT Destination Port

uint16

5

tranip

NAT Destination IP

ip

39

time

Time

string

8

subtype

Subtype of the traffic

string

20

statuscode

string

8

sslaction

Action taken by ssl-ssh-profile

string

26

srcuuid

UUID of the Source Address Object

string

37

srcport

Source protocol port number

uint16

5

srcip

Source IP address

ip

39

sessionid

Session ID

uint32

10

sentbyte

Sent Bytes

uint64

20

scheme

string

16

resptype

string

16

resptime

uint64

16

resplength

uint64

16

respfinishtime

uint64

16

reqtime

uint64

16

reqlength

uint64

16

referralurl

string

512

rcvdbyte

Received Bytes

uint64

20

poluuid

UUID of the Firewall Policy

string

37

policytype

Policy type

string

24

policyid

Firewall Policy ID

uint32

10

logid

Log ID

string

10

level

Log Level

string

11

lanout

LAN outgoing traffic in bytes

uint64

20

lanin

LAN incoming traffic in bytes

uint64

20

httpmethod

string

20

hostname

string

256

group

User group name

string

512

fwdsrv

string

64

eventtime

Epoch time in nanoseconds

uint64

20

emsconnection

string

8

duration

Duration of the session

uint32

10

dstuuid

UUID of the Destination Address Object

string

37

dstport

Destination Protocol Port Number

uint16

5

dstip

Destination IP Address

ip

39

devid

Device Serial Number

string

16

date

Date

string

10

countweb

Number of Web Filter logs associated with the session

uint32

10

countwaf

Number of WAF logs associated with the session

uint32

10

countvpatch

uint32

10

countssl

uint32

10

countssh

Number of SSH logs associated with the session

uint32

10

countsctpf

uint32

10

countips

Number of IPS logs associated with the session

uint32

10

counticap

uint32

10

countff

uint32

10

countemail

Number of Email logs associated with the session

uint32

10

countdns

Number of DNS Query logs associated with the session

uint32

10

countdlp

Number of DLP logs associated with the session

uint32

10

countcifs

uint32

10

countcasb

uint32

10

countav

Number of AV logs associated with the session

uint32

10

countapp

Number of App Ctrl logs associated with the session

uint32

10

clientdevicetags

string

512

clientdeviceowner

string

80

clientdeviceid

string

80

authserver

Remote Authentication server

string

64

apprisk

Application Risk Level

string

16

applist

Application Control profile (name)

string

64

appid

Application ID

uint32

10

appcat

Application category

string

64

appact

The security action from app control

string

16

app

Application Name

string

96

agent

User agent - eg. agent="Mozilla/5.0"

string

1024

action

The status of the session: deny - Session was denied accept - Allowed Forward session start - Session starts (log message was created when the session was created) dns - DNS query return error ip-conn - Failed connection attempts close - Local-traffic session allowed timeout - Allowed session was timeout client-rst - Session reset by client server-rst - Session reset by server

string

16

26 - LOG_ID_TRAFFIC_HTTP_TRANSACTION

26 - LOG_ID_TRAFFIC_HTTP_TRANSACTION

Message ID: 26

Message Description: LOG_ID_TRAFFIC_HTTP_TRANSACTION

Message Meaning: HTTP transaction

Type: Traffic

Category: http-transaction

Severity: Notice

Log Field Name

Description

Data Type

Length

wanout

WAN outgoing traffic in bytes

uint64

20

wanin

WAN incoming traffic in bytes

uint64

20

vd

Virtual domain name

string

32

utmaction

Security action performed by UTM

string

32

user

User name

string

256

url

URL

string

512

tz

Time zone

string

5

type

Log type

string

16

transid

uint32

10

tranport

NAT Destination Port

uint16

5

tranip

NAT Destination IP

ip

39

time

Time

string

8

subtype

Subtype of the traffic

string

20

statuscode

string

8

sslaction

Action taken by ssl-ssh-profile

string

26

srcuuid

UUID of the Source Address Object

string

37

srcport

Source protocol port number

uint16

5

srcip

Source IP address

ip

39

sessionid

Session ID

uint32

10

sentbyte

Sent Bytes

uint64

20

scheme

string

16

resptype

string

16

resptime

uint64

16

resplength

uint64

16

respfinishtime

uint64

16

reqtime

uint64

16

reqlength

uint64

16

referralurl

string

512

rcvdbyte

Received Bytes

uint64

20

poluuid

UUID of the Firewall Policy

string

37

policytype

Policy type

string

24

policyid

Firewall Policy ID

uint32

10

logid

Log ID

string

10

level

Log Level

string

11

lanout

LAN outgoing traffic in bytes

uint64

20

lanin

LAN incoming traffic in bytes

uint64

20

httpmethod

string

20

hostname

string

256

group

User group name

string

512

fwdsrv

string

64

eventtime

Epoch time in nanoseconds

uint64

20

emsconnection

string

8

duration

Duration of the session

uint32

10

dstuuid

UUID of the Destination Address Object

string

37

dstport

Destination Protocol Port Number

uint16

5

dstip

Destination IP Address

ip

39

devid

Device Serial Number

string

16

date

Date

string

10

countweb

Number of Web Filter logs associated with the session

uint32

10

countwaf

Number of WAF logs associated with the session

uint32

10

countvpatch

uint32

10

countssl

uint32

10

countssh

Number of SSH logs associated with the session

uint32

10

countsctpf

uint32

10

countips

Number of IPS logs associated with the session

uint32

10

counticap

uint32

10

countff

uint32

10

countemail

Number of Email logs associated with the session

uint32

10

countdns

Number of DNS Query logs associated with the session

uint32

10

countdlp

Number of DLP logs associated with the session

uint32

10

countcifs

uint32

10

countcasb

uint32

10

countav

Number of AV logs associated with the session

uint32

10

countapp

Number of App Ctrl logs associated with the session

uint32

10

clientdevicetags

string

512

clientdeviceowner

string

80

clientdeviceid

string

80

authserver

Remote Authentication server

string

64

apprisk

Application Risk Level

string

16

applist

Application Control profile (name)

string

64

appid

Application ID

uint32

10

appcat

Application category

string

64

appact

The security action from app control

string

16

app

Application Name

string

96

agent

User agent - eg. agent="Mozilla/5.0"

string

1024

action

The status of the session: deny - Session was denied accept - Allowed Forward session start - Session starts (log message was created when the session was created) dns - DNS query return error ip-conn - Failed connection attempts close - Local-traffic session allowed timeout - Allowed session was timeout client-rst - Session reset by client server-rst - Session reset by server

string

16