61003 - LOG_ID_SSH_COMMAND_PASS_ALERT
Message ID: 61003
Message Description: LOG_ID_SSH_COMMAND_PASS_ALERT
Message Meaning: SSH shell command is detected
Type: SSH
Category: ssh-command
Severity: Alert
Log Field Name |
Description |
Data Type |
Length |
---|---|---|---|
vd |
Virtual Domain Name |
string |
32 |
user |
User name for authentication |
string |
256 |
unauthusersource |
Unauthenticated User Source |
string |
66 |
unauthuser |
Unauthenticated User |
string |
66 |
tz |
Time zone |
string |
5 |
type |
Log type |
string |
16 |
time |
Time |
string |
8 |
subtype |
Log subtype |
string |
20 |
srcuuid |
|
string |
37 |
srcport |
Source Port |
uint16 |
5 |
srcip |
Source IP |
ip |
39 |
srcintfrole |
Source Interface's assigned role (LAN, WAN, etc.) |
string |
10 |
srcintf |
Source Interface |
string |
32 |
srcdomain |
|
string |
255 |
srccountry |
|
string |
64 |
severity |
Severity level of shell command |
string |
8 |
sessionid |
Session ID |
uint32 |
10 |
proto |
Protocol number |
uint8 |
3 |
profile |
Full profile name |
string |
64 |
poluuid |
|
string |
37 |
policytype |
|
string |
24 |
policyid |
Policy ID |
uint32 |
10 |
login |
SSH login Name |
string |
128 |
logid |
Log ID |
string |
10 |
level |
Log level |
string |
11 |
hostkeystatus |
|
string |
15 |
group |
Group name for authentication |
string |
512 |
fctuid |
FortiClient UID |
string |
32 |
eventtype |
Event Type |
string |
32 |
eventtime |
Event time |
uint64 |
20 |
dstuuid |
|
string |
37 |
dstuser |
|
string |
256 |
dstport |
Destination Port |
uint16 |
5 |
dstip |
Destination IP |
ip |
39 |
dstintfrole |
Destination Interface's assigned role (LAN, WAN, etc.) |
string |
10 |
dstintf |
Destination Interface |
string |
32 |
dstcountry |
|
string |
64 |
direction |
Direction of session |
string |
4096 |
devid |
Device ID |
string |
16 |
date |
Date |
string |
10 |
command |
Shell command |
string |
256 |
channeltype |
Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp |
string |
15 |
action |
The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked |
string |
17 |