Document toolboxDocument toolbox

iam.fortinet

Introduction

The tags beginning with iam.fortinet identify events generated by Fortinet.

Valid tags and data tables 

The full tag must have at least four levels. The first two are fixed as iam.fortinet. The third level identifies the type of events sent. The fourth indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Fortinet

iam.fortinet.fortiauthenticator.events

iam.fortinet.fortiauthenticator.events

For more information, read more about Devo tags.

Table structure

These are the fields displayed in this table:

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

category

str

 

 

 

subcategory

str

 

 

 

typeid

str

 

 

 

level

str

 

 

 

user

str

 

 

 

nas

str

 

 

 

action

str

 

 

 

status

str

 

 

 

message

str

ifthenelse(isnotnull(msg), msg, message_aux)

msg

message_aux

 

time

str

 

 

 

timestamp

timestamp

 

 

 

devname

str

 

 

 

devid

str

 

 

 

vd

str

 

 

 

faclogindex

str

 

 

 

logdesc

str

 

 

 

userip

ip4

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

rawSource

✓