Fortinet white logo
Fortinet white logo

FortiOS Log Message Reference

61001 - LOG_ID_SSH_COMMAND_BLOCK_ALERT

61001 - LOG_ID_SSH_COMMAND_BLOCK_ALERT

Message ID: 61001

Message Description: LOG_ID_SSH_COMMAND_BLOCK_ALERT

Message Meaning: SSH shell command is blocked

Type: SSH

Category: ssh-command

Severity: Alert

Log Field Name

Description

Data Type

Length

vd

Virtual Domain Name

string

32

user

User name for authentication

string

256

unauthusersource

Unauthenticated User Source

string

66

unauthuser

Unauthenticated User

string

66

tz

Time zone

string

5

type

Log type

string

16

time

Time

string

8

subtype

Log subtype

string

20

srcuuid

string

37

srcport

Source Port

uint16

5

srcip

Source IP

ip

39

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcintf

Source Interface

string

32

srcdomain

string

255

srccountry

string

64

severity

Severity level of shell command

string

8

sessionid

Session ID

uint32

10

proto

Protocol number

uint8

3

profile

Full profile name

string

64

poluuid

string

37

policytype

string

24

policyid

Policy ID

uint32

10

login

SSH login Name

string

128

logid

Log ID

string

10

level

Log level

string

11

hostkeystatus

string

15

group

Group name for authentication

string

512

fctuid

FortiClient UID

string

32

eventtype

Event Type

string

32

eventtime

Event time

uint64

20

dstuuid

string

37

dstuser

string

256

dstport

Destination Port

uint16

5

dstip

Destination IP

ip

39

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstintf

Destination Interface

string

32

dstcountry

string

64

direction

Direction of session

string

4096

devid

Device ID

string

16

date

Date

string

10

command

Shell command

string

256

channeltype

Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp

string

15

action

The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked

string

17

61001 - LOG_ID_SSH_COMMAND_BLOCK_ALERT

61001 - LOG_ID_SSH_COMMAND_BLOCK_ALERT

Message ID: 61001

Message Description: LOG_ID_SSH_COMMAND_BLOCK_ALERT

Message Meaning: SSH shell command is blocked

Type: SSH

Category: ssh-command

Severity: Alert

Log Field Name

Description

Data Type

Length

vd

Virtual Domain Name

string

32

user

User name for authentication

string

256

unauthusersource

Unauthenticated User Source

string

66

unauthuser

Unauthenticated User

string

66

tz

Time zone

string

5

type

Log type

string

16

time

Time

string

8

subtype

Log subtype

string

20

srcuuid

string

37

srcport

Source Port

uint16

5

srcip

Source IP

ip

39

srcintfrole

Source Interface's assigned role (LAN, WAN, etc.)

string

10

srcintf

Source Interface

string

32

srcdomain

string

255

srccountry

string

64

severity

Severity level of shell command

string

8

sessionid

Session ID

uint32

10

proto

Protocol number

uint8

3

profile

Full profile name

string

64

poluuid

string

37

policytype

string

24

policyid

Policy ID

uint32

10

login

SSH login Name

string

128

logid

Log ID

string

10

level

Log level

string

11

hostkeystatus

string

15

group

Group name for authentication

string

512

fctuid

FortiClient UID

string

32

eventtype

Event Type

string

32

eventtime

Event time

uint64

20

dstuuid

string

37

dstuser

string

256

dstport

Destination Port

uint16

5

dstip

Destination IP

ip

39

dstintfrole

Destination Interface's assigned role (LAN, WAN, etc.)

string

10

dstintf

Destination Interface

string

32

dstcountry

string

64

direction

Direction of session

string

4096

devid

Device ID

string

16

date

Date

string

10

command

Shell command

string

256

channeltype

Type of Channel: x11, shell, exec, tcp-fprward, tun-forward, sftp. scp

string

15

action

The status of the ssh-channel: passthrough - channel is allowed blocked - channel is blocked

string

17