[ Introduction ] [ Tag structure ] [ How is the data sent to Devo? ] [ Table structure ]
Introduction
The tags beginning with cef0.fortinet
identify events in CEF format generated by Fortinet.
Tag structure
Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.
In this case, the valid data tables are:
Tags | Data tables |
---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
How is the data sent to Devo?
Learn more about CEF syslog format and how Devo tags these events in Technologies supported in CEF syslog format.
Table structure
These are the fields displayed in this table:
cef0.fortinet.fortiauthenticator
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
destinationServiceName |
| ||
msg |
| ||
deviceFacility |
| ||
suser |
| ||
dvc |
| ||
act |
| ||
deviceProcessName |
| ||
in |
| ||
rt |
| ||
out |
| ||
dtz |
| ||
deviceZoneID |
| ||
eventAnnotationAuditTrail |
| ||
eventAnnotationVersion |
| ||
eventAnnotationModificationTime |
| ||
art |
| ||
originalAgentAddress |
| ||
eventId |
| ||
at |
| ||
mrt |
| ||
customerURI |
| ||
originalAgentZoneURI |
| ||
assetCriticality |
| ||
eventAnnotationFlags |
| ||
agt |
| ||
modelConfidence |
| ||
aid |
| ||
amac |
| ||
deviceZoneExternalID |
| ||
Severity |
| ||
relevance |
| ||
av |
| ||
eventAnnotationStageUpdateTime |
| ||
locality |
| ||
ahost |
| ||
originalAgentVersion |
| ||
customerID |
| ||
atz |
| ||
originalAgentMacAddress |
| ||
originalAgentType |
| ||
deviceSeverity |
| ||
originalAgentId |
| ||
eventAnnotationManagerReceiptTime |
| ||
originalAgentHostName |
| ||
priority |
| ||
deviceZoneURI |
| ||
eventAnnotationEndTime |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cefTag |
rawMessage |
|
cef0.fortinet.fortigate
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
rawMessage |
| ✓ | |
hostchain |
| ✓ | |
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
act |
| ||
app |
| ||
cat |
| ||
c6a1Label |
| ||
c6a1 |
| ||
c6a2Label |
| ||
c6a2 |
| ||
c6a3Label |
| ||
c6a3 |
| ||
c6a4Label |
| ||
c6a4 |
| ||
cfp1Label |
| ||
cfp1 |
| ||
cfp2Label |
| ||
cfp2 |
| ||
cfp3Label |
| ||
cfp3 |
| ||
cfp4Label |
| ||
cfp4 |
| ||
cn1Label |
| ||
cn1 |
| ||
cn2Label |
| ||
cn2 |
| ||
cn3Label |
| ||
cn3 |
| ||
cnt |
| ||
cs1Label |
| ||
cs1 |
| ||
cs2Label |
| ||
cs2 |
| ||
cs3Label |
| ||
cs3 |
| ||
cs4Label |
| ||
cs4 |
| ||
cs5Label |
| ||
cs5 |
| ||
cs6Label |
| ||
cs6 |
| ||
destinationDnsDomain |
| ||
destinationServiceName |
| ||
destinationTranslatedAddress |
| ||
destinationTranslatedPort |
| ||
deviceCustomDate1Label |
| ||
deviceCustomDate1 |
| ||
deviceCustomDate2Label |
| ||
deviceCustomDate2 |
| ||
deviceDirection |
| ||
deviceDnsDomain |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceMacAddress |
| ||
deviceNtDomain |
| ||
deviceOutboundInterface |
| ||
deviceProcessName |
| ||
deviceTranslatedAddress |
| ||
dhost |
| ||
dmac |
| ||
dntdom |
| ||
dpid |
| ||
dpriv |
| ||
dproc |
| ||
dst |
| ||
duid |
| ||
duser |
| ||
dvchost |
| ||
dvc |
| ||
dvcpid |
| ||
end |
| ||
deviceFacility |
| ||
externalId |
| ||
fileCreateTime |
| ||
fileHash |
| ||
fileId |
| ||
fileModificationTime |
| ||
filePath |
| ||
filePermission |
| ||
fileType |
| ||
fname |
| ||
fsize |
| ||
in |
| ||
msg |
| ||
oldFileCreateTime |
| ||
oldFileHash |
| ||
oldFileId |
| ||
oldFileModificationTime |
| ||
oldFileName |
| ||
oldFilePath |
| ||
oldFilePermission |
| ||
oldFileSize |
| ||
oldFileType |
| ||
outcome |
| ||
out |
| ||
proto |
| ||
reason |
| ||
requestClientApplication |
| ||
requestCookies |
| ||
requestMethod |
| ||
request |
| ||
rt |
| ||
shost |
| ||
smac |
| ||
sntdom |
| ||
sourceDnsDomain |
| ||
sourceServiceName |
| ||
sourceTranslatedAddress |
| ||
sourceTranslatedPort |
| ||
spid |
| ||
spriv |
| ||
sproc |
| ||
spt |
| ||
src |
| ||
start |
| ||
suid |
| ||
suser |
| ||
catdt |
| ||
deviceDomain |
| ||
deviceSeverity |
| ||
dpt |
| ||
dtz |
| ||
dvcmac |
| ||
endTime |
| ||
eventId |
| ||
flexNumber1 |
| ||
flexNumber1Label |
| ||
flexNumber2 |
| ||
flexNumber2Label |
| ||
flexString1 |
| ||
flexString1Label |
| ||
flexString2 |
| ||
flexString2Label |
| ||
modelConfidence |
| ||
priority |
| ||
relevance |
| ||
requestContext |
| ||
sessionId |
| ||
slat |
| ||
slong |
| ||
dlat |
| ||
dlong |
| ||
sourceGeoCountryCode |
| ||
sourceGeoLocationInfo |
| ||
sourceGeoPostalCode |
| ||
sourceGeoRegionCode |
| ||
destinationGeoCountryCode |
| ||
destinationGeoLocationInfo |
| ||
destinationGeoPostalCode |
| ||
destinationGeoRegionCode |
| ||
agt |
| ||
ahost |
| ||
art |
| ||
atz |
| ||
mrt |
| ||
categoryBehavior |
| ||
categoryCustomFormatField |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
categoryTechnique |
| ||
categoryTupleDescription |
| ||
assetCriticality |
| ||
customerID |
| ||
customerURI |
| ||
tag |
| ✓ | cefTag |
cef0.fortinet.fortigate200e
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
act |
| ||
app |
| ||
cat |
| ||
c6a4Label |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceOutboundInterface |
| ||
dst |
| ||
dpt |
| ||
dvchost |
| ||
in |
| ||
out |
| ||
proto |
| ||
rt |
| ||
shost |
| ||
sourceTranslatedAddress |
| ||
sourceTranslatedPort |
| ||
src |
| ||
spt |
| ||
agentZoneURI |
| ||
agt |
| ||
ahost |
| ||
aid |
| ||
amac |
| ||
art |
| ||
at |
| ||
atz |
| ||
av |
| ||
categoryBehavior |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
customerURI |
| ||
destinationZoneURI |
| ||
deviceSeverity |
| ||
dtz |
| ||
eventId |
| ||
geid |
| ||
sourceTranslatedZoneURI |
| ||
sourceZoneURI |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cefTag |
rawMessage |
| ✓ |
cef0.fortinet.fortigate300d
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
act |
| ||
app |
| ||
cat |
| ||
c6a4Label |
| ||
cnt |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceOutboundInterface |
| ||
dhost |
| ||
dst |
| ||
dpt |
| ||
dvchost |
| ||
in |
| ||
msg |
| ||
out |
| ||
proto |
| ||
request |
| ||
rt |
| ||
shost |
| ||
sourceTranslatedAddress |
| ||
src |
| ||
start |
| ||
agentZoneURI |
| ||
agt |
| ||
ahost |
| ||
aid |
| ||
amac |
| ||
art |
| ||
at |
| ||
atz |
| ||
av |
| ||
categoryBehavior |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
customerURI |
| ||
destinationZoneURI |
| ||
deviceSeverity |
| ||
dtz |
| ||
eventId |
| ||
geid |
| ||
sourceTranslatedZoneURI |
| ||
sourceZoneURI |
| ||
type |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cefTag |
rawMessage |
| ✓ |
cef0.fortinet.fortigate400e
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
act |
| ||
app |
| ||
cat |
| ||
c6a4Label |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceOutboundInterface |
| ||
dhost |
| ||
dst |
| ||
dpt |
| ||
dvchost |
| ||
in |
| ||
out |
| ||
proto |
| ||
rt |
| ||
shost |
| ||
sourceTranslatedAddress |
| ||
sourceTranslatedPort |
| ||
src |
| ||
spt |
| ||
agentZoneURI |
| ||
agt |
| ||
ahost |
| ||
aid |
| ||
amac |
| ||
art |
| ||
at |
| ||
atz |
| ||
av |
| ||
categoryBehavior |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
destinationZoneURI |
| ||
deviceSeverity |
| ||
dtz |
| ||
eventId |
| ||
geid |
| ||
sourceTranslatedZoneURI |
| ||
sourceZoneURI |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cefTag |
rawMessage |
| ✓ |
cef0.fortinet.fortigate600e
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
rt |
| ||
eventId |
| ||
msg |
| ||
app |
| ||
proto |
| ||
in |
| ||
out |
| ||
categorySignificance |
| ||
categoryBehavior |
| ||
categoryDeviceGroup |
| ||
categoryOutcome |
| ||
categoryObject |
| ||
art |
| ||
cat |
| ||
deviceSeverity |
| ||
act |
| ||
src |
| ||
sourceZoneURI |
| ||
spt |
| ||
dhost |
| ||
dst |
| ||
destinationZoneURI |
| ||
dpt |
| ||
request |
| ||
requestContext |
| ||
c6a4Label |
| ||
ahost |
| ||
agt |
| ||
agentZoneURI |
| ||
amac |
| ||
av |
| ||
atz |
| ||
at |
| ||
dvchost |
| ||
dtz |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceOutboundInterface |
| ||
aid |
| ||
geid |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cefTag |
rawMessage |
| ✓ |
cef0.fortinet.fortigate60e
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priorityCode |
| ||
cefTag |
| ||
cefVersion |
| ||
embDeviceVendor |
| ||
embDeviceProduct |
| ||
deviceVersion |
| ||
signatureID |
| ||
name |
| ||
severity |
| ||
_cefVer |
| ||
act |
| ||
app |
| ||
cat |
| ||
c6a4Label |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceOutboundInterface |
| ||
dst |
| ||
dpt |
| ||
dvchost |
| ||
in |
| ||
out |
| ||
proto |
| ||
rt |
| ||
shost |
| ||
src |
| ||
spt |
| ||
agentZoneURI |
| ||
agt |
| ||
ahost |
| ||
aid |
| ||
amac |
| ||
art |
| ||
at |
| ||
atz |
| ||
av |
| ||
categoryBehavior |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
customerURI |
| ||
destinationZoneURI |
| ||
deviceSeverity |
| ||
dtz |
| ||
eventId |
| ||
geid |
| ||
sourceZoneURI |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cefTag |
rawMessage |
| ✓ |
cef0.fortinet.fortigateAll
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
source |
| ||
_cefVer |
| ||
fwname |
| ||
act |
| ||
app |
| ||
cat |
| ||
c6a4Label |
| ||
deviceExternalId |
| ||
deviceInboundInterface |
| ||
deviceOutboundInterface |
| ||
dst |
| ||
dpt |
| ||
dvchost |
| ||
in |
| ||
out |
| ||
proto |
| ||
rt |
| ||
src |
| ||
spt |
| ||
agt |
| ||
ahost |
| ||
art |
| ||
atz |
| ||
categoryBehavior |
| ||
categoryDeviceGroup |
| ||
categoryObject |
| ||
categoryOutcome |
| ||
categorySignificance |
| ||
deviceSeverity |
| ||
dtz |
| ||
eventId |
| ||
rawMessage |
| ✓ | rawSource |
hostchain |
| ✓ | |
tag |
| ✓ |
cef0.fortinet.fortinacVmCa
Field | Type | Extra field | Source field name |
---|---|---|---|
eventdate |
| ||
hostname |
| ||
priority_code |
| ||
cef_tag |
| ||
cef_version |
| ||
emb_device_vendor |
| ||
emb_device_product |
| ||
device_version |
| ||
signature_id |
| ||
name |
| ||
severity |
| ||
category |
| ||
message |
| ||
device_receipt_time |
| ||
source_hostname |
| ||
source_ip |
| ||
source_mac |
| ||
source_user_id |
| ||
cs1Label |
| ||
cs1 |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | cef_tag |
rawMessage |
| ✓ |