Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents
maxLevel2
minLevel2
typeflat

...

The full tag must have at least two levels, although most require three and four levels. The first two are fixed as firewall.fortinet. The third level identifies the technology type and must be one of eventtraffic, ips, utm, or anomaly. The fourth element is not always required but is usually fixed and may be automatically generated by the Devo relay rule. 

technologyTechnology

brandBrand

typeType

subtypeSubtype

firewall

fortinet

  • event
  • traffic
  • ips
  • utm
  • anomaly

may be fixed and required

...

  • firewall.fortinet
  • firewall.fortinet.anomaly.anomaly
  • firewall.fortinet.event
  • firewall.fortinet.event.admin
  • firewall.fortinet.event.config
  • firewall.fortinet.event.dhcp
  • firewall.fortinet.event.dns
  • firewall.fortinet.event.ha
  • firewall.fortinet.event.his-performance
  • firewall.fortinet.event.ipsec
  • firewall.fortinet.event.pattern
  • firewall.fortinet.event.perf-historical
  • firewall.fortinet.event.sslvpn-session
  • firewall.fortinet.event.sslvpn-user
  • firewall.fortinet.event.system
  • firewall.fortinet.event.user
  • firewall.fortinet.event.vpn
  • firewall.fortinet.event.wireless
  • firewall.fortinet.ips.anomaly
  • firewall.fortinet.traffic
  • firewall.fortinet.traffic.forward
  • firewall.fortinet.traffic.local
  • firewall.fortinet.traffic.multicast
  • firewall.fortinet.traffic.other
  • firewall.fortinet.traffic.violation
  • firewall.fortinet.utm.app-ctrl
  • firewall.fortinet.utm.dns
  • firewall.fortinet.utm.emailfilter
  • firewall.fortinet.utm.ips
  • firewall.fortinet.utm.virus
  • firewall.fortinet.utm.webfilter

...

For more details about FortiGate logging, see the vendor documentation.

...

Log samples

The following are sample logs sent to each of the firewall.fortinet data tables. Also, find how the information will be parsed in your data table under each sample log.

Note
titleExtra columns

Fields marked as Extra in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as Extra when you perform a query so they can be easily identified. Learn more about this in Selecting unrevealed columns.

firewall.fortinet.utm.dns

Code Block
2022-02-15 12:24:44.189 localhost=127.0.0.1 firewall.fortinet.utm.dns: date=2022-02-11,time=01:52:55,devname="Some dev",devid="AAA11AA21081637",eventtime=1644558775402818899,tz="-0400",logid="1500054000",type="utm",subtype="dns",eventtype="dns-query",level="information",vd="root",policyid=3,sessionid=35603897,srcip=127.67.86.9,srcport=49097,srcintf="internal",srcintfrole="lan",dstip=127.199.197.189,dstport=53,dstintf="wan1",dstintfrole="wan",proto=17,profile="default",xid=15477,qname="some_query",qtype="A",qtypeval=1,qclass="IN"

And this is how the log would be parsed:

Field

Value

Type

Extra fields

eventdate

2022-02-15 12:24:44.189

timestamp


hostname

localhost

str


serverdate

2022-02-11 00:00:00.0

timestamp


servertime

01:52:55

str


devname

Some dev

str


devid

AAA11AA21081637

str


eventtime

1644558775402818899

int8


tz

-0400

str


logid

1500054000

str


type

utm

str


subtype

dns

str


eventtype

dns-query

str


level2

information

str


vd

root

str


policyid

3

int4


sessionid

35603897

str


srcip

127.67.86.9

ip4


srcport

49097

str


srcintf

internal

str


srcintfrole

lan

str


dstip

127.199.197.189

ip4


dstport

53

str


dstintf

wan1

str


dstintfrole

wan

str


proto

17

int4


profile

default

str


xid

15477

str


qname

some_query

str


qtype

A

str


qtypeval

1

str


qclass

IN

str


ipaddr

null

str


msg

null

str


action

null

str


cat

null

str


catdesc

null

str


hostchain

localhost=127.0.0.1

str

tag

firewall.fortinet.utm.dns

str

rawMessage

date=2022-02-11,time=01:52:55,devname="Some dev",devid="AAA11AA21081637",eventtime=1644558775402818899,tz="-0400",logid="1500054000",type="utm",subtype="dns",eventtype="dns-query",level="information",vd="root",policyid=3,sessionid=35603897,srcip=127.67.86.9,srcport=49097,srcintf="internal",srcintfrole="lan",dstip=127.199.197.189,dstport=53,dstintf="wan1",dstintfrole="wan",proto=17,profile="default",xid=15477,qname="some_query",qtype="A",qtypeval=1,qclass="IN"

str