Fortinet white logo
Fortinet white logo

Log Message Reference

61002 - LOG_ID_SSH_COMMAND_PASS

61002 - LOG_ID_SSH_COMMAND_PASS

Message ID: 61002

Message Description: LOG_ID_SSH_COMMAND_PASS

Message Meaning: SSH shell command is detected

Type: ssh

Category: ssh-command

Severity: Notice

Log Field Name

Description

Data Type

Length

action

The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked

string

17

channeltype

Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp

string

15

command

Shell command

string

256

date

Date

string

10

devid

Device ID

string

16

direction

Direction of session

string

4096

dstcountry

string

64

dstintf

Destination Interface

string

32

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP

ip

39

dstport

Destination Port

uint16

5

dstuser

string

256

dstuuid

string

37

eventtime

Event time

uint64

20

eventtype

Event Type

string

32

fctuid

FortiClient UID

string

32

group

Group name for authentication

string

512

hostkeystatus

string

15

level

Log level

string

11

logid

Log ID

string

10

login

SSH login Name

string

128

policyid

Policy ID

uint32

10

policytype

string

24

profile

Full profile name

string

64

proto

Protocol number

uint8

3

sessionid

Session ID

uint32

10

severity

Severity level of shell command

string

8

srccountry

string

64

srcdomain

string

255

srcintf

Source Interface

string

32

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP

ip

39

srcport

Source Port

uint16

5

srcuuid

string

37

subtype

Log subtype

string

20

time

Time

string

8

type

Log type

string

16

tz

Time zone

string

5

unauthuser

Unauthenticated User

string

66

unauthusersource

Unauthenticated User Source

string

66

user

User name for authentication

string

256

vd

Virtual Domain Name

string

32

61002 - LOG_ID_SSH_COMMAND_PASS

61002 - LOG_ID_SSH_COMMAND_PASS

Message ID: 61002

Message Description: LOG_ID_SSH_COMMAND_PASS

Message Meaning: SSH shell command is detected

Type: ssh

Category: ssh-command

Severity: Notice

Log Field Name

Description

Data Type

Length

action

The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked

string

17

channeltype

Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp

string

15

command

Shell command

string

256

date

Date

string

10

devid

Device ID

string

16

direction

Direction of session

string

4096

dstcountry

string

64

dstintf

Destination Interface

string

32

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstip

Destination IP

ip

39

dstport

Destination Port

uint16

5

dstuser

string

256

dstuuid

string

37

eventtime

Event time

uint64

20

eventtype

Event Type

string

32

fctuid

FortiClient UID

string

32

group

Group name for authentication

string

512

hostkeystatus

string

15

level

Log level

string

11

logid

Log ID

string

10

login

SSH login Name

string

128

policyid

Policy ID

uint32

10

policytype

string

24

profile

Full profile name

string

64

proto

Protocol number

uint8

3

sessionid

Session ID

uint32

10

severity

Severity level of shell command

string

8

srccountry

string

64

srcdomain

string

255

srcintf

Source Interface

string

32

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcip

Source IP

ip

39

srcport

Source Port

uint16

5

srcuuid

string

37

subtype

Log subtype

string

20

time

Time

string

8

type

Log type

string

16

tz

Time zone

string

5

unauthuser

Unauthenticated User

string

66

unauthusersource

Unauthenticated User Source

string

66

user

User name for authentication

string

256

vd

Virtual Domain Name

string

32