FortiAnalyzer-7 6 1-Fabric Normalization - Reference
FortiAnalyzer-7 6 1-Fabric Normalization - Reference
FortiAnalyzer 7.6.1
FORTINET DOCUMENT LIBRARY
https://docs.fortinet.com
FORTINET BLOG
https://blog.fortinet.com
FORTIGUARD LABS
https://www.fortiguard.com
FEEDBACK
Email: [email protected]
Change Log 4
FortiAnalyzer normalized Fabric logs 5
Fabric log field descriptions 5
FortiGate logs 14
FortiManager logs 18
FortiClient logs 19
FortiSandbox logs 22
FortiADC logs 24
FortiAnalyzer logs 26
FortiAuthenticator logs 27
FortiCache logs 29
FortiDDoS logs 31
FortiDeceptor logs 33
FortiEDR logs 34
FortiFirewall logs 36
FortiIsolator logs 38
FortiMail logs 39
FortiNAC logs 41
FortiNDR logs 43
FortiProxy logs 44
FortiSOAR logs 47
FortiSwitch logs 48
FortiWeb logs 49
Apache logs 51
Nginx logs 52
System logs 52
Ubuntu logs 53
Windows Event logs 54
Logs from different Fabric devices can be normalized on FortiAnalyzer. When one or more devices are added to a Fabric
ADOM and logs are sent to FortiAnalyzer, a SIEM database (siemdb) is automatically created for the ADOM. All logs are
inserted into the siemdb and displayed in Log View > Logs > All as normalized logs. This allows FortiAnalyzer
administrators to view logs from Fabric devices in one place with log fields that are consistent across the devices.
SIEM features are available with all VM models and most hardware models starting in 6.4.0 and later.
This reference guide includes supported Fabric devices and the log field correlations between Fabric devices and
FortiAnalyzer that are used to support normalized Fabric logs.
The normalized fabric log fields are organized in the following categories.
Category Description
Application Application data. Specifies the shared communication service and application's
information used by hosts in a communications network.
Event Event data. Collected and stored by various tracking tools or methods in order to
provide insights about user behavior, traffic patterns, and other metrics related to
online events.
Host Host data. Stores information of a computer or other device that communicates
with other hosts on a network.
Network Network data. Defines metadata about network information seen in a typical OSI
layer.
Process Process data. Defines metadata about processes in an system. Isolated memory
address space that is used to run a program.
Protocol Protocol data. Defines metadata about protocol related information for
transmitting/exchanging data between the devices.
Registry Registry data. Defines metadata about Windows registry entries in a system.
Category Description
Source Source data. Represents movement through geographic space, from a source to
a destination.
The following tables list the available normalized fabric log fields in FortiAnalyzer 7.6.1.
base
loguid uint64 Unique ID set by FortiAnalyzer on each log for internal use.
data_source
Application
app_action string The operation the user performed in the context of the application.
Destination
dst_intf_guid string GUID of the network interface which was used for authentication
request.
Event
event_creation_time uint32 Original time when event/log was created as reported from the log
source itself.
event_duration uint32 The length/duration of the event in seconds (for example, 1 min is
60.0).
event_resource_group string The resource group to which the device generating the record
belongs. This might be an AWS account, or an Azure subscription or
Resource Group.
event_uuid string Original unique ID specific to the log/event assigned to the event (not
original).
File
Host
Logon
logon_authentication string The name of the authentication package which was used for the logon
authentication process.
logon_server string Logon server name (it is a free text). The server name of the URL.
logon_srcip ip Logon remote IP. It could be user's IP, and a remote IP.
Network
Process
process_command_line string Command arguments that were were executed by the process in the
endpoint.
process_guid string Process global unique identifer used to identify a process across
other operating systems.
Protocol
dns_rejected string The server responded to the query but no answers were given.
dns_rtt uint32 Round trip time (RTT) of the DNS query to answer.
dns_transaction_id string Hexadecimal identifier assigned by the program that generated the
DNS query.
http_response_time uint32 The amount of time in milliseconds it took to receive a response in the
server.
http_status_code uint16 HTTP response status code. 1XX Informational codes; 2XX Success
codes; 3XX Redirection codes; 4XX Client error codes; 5XX Server
error codes.
Registry
registry_hive_path string A hive is a logical group of keys, subkeys, and values in the registry
that has a set of supporting files loaded into memory when the
operating system is started or a user logs in.
registry_key_access_rights string The Windows security model enables you to control access to registry
keys. The valid access rights for registry keys.
registry_key_name string This field contains the key name without the full path. Take in
consideration the name of the key value in the registry key path.
registry_key_path string Next-level down from registry root-keys. This field contains the full
path of a registry key.
registry_root_key string Root-Keys are the root, or primary divisions, of the registry. They do
not contain configuration data; they contain the keys, subkeys, and
values in which the data is stored.
registry_value_data string Each registry key value consists of a value name and its associated
data. Registry key value data store the actual configuration data for
the operating system and the programs that run on the system.
registry_value_name string Registry values are the lowest-level element in the registry. They
appear in the right pane of the registry editor window.
Source
src_intf_guid string GUID of the network interface which was used for authentication
request.
TLS
tls_cipher string The cipher (encryption) parameters used to make the TLS
connection.
tls_curve string Elliptic curve the server chose when using ECDH/ECDHE.
tls_established string Indicates if the session has been established successfully, or if it was
aborted during the handshake.
tls_next_protocol string Next protocol the server chose using the application layer next
protocol extension, if present.
tls_resumed string If the session was resumed from previous established connection.
tls_server_name string The name of the requested server/destination; this should be copied
to dst_host_name.
Threat
User
FortiGate logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
appact app_action
appcat app_cat
appid app_id
app,saasapp app_name
service app_service
qname dns_query
dns_querytype dns_querytype
ipaddr dns_response
hostname dst_domain
dstssid dst_asset_id
dstcountry dst_geo
dstcity dst_geo_city
dstcountry dst_geo_country
dst_info dst_intf
dstip,dst_ip dst_ip
dstmac dst_mac
dst_natip,tranip dst_natip
dst_natport,tranport dst_natport
dstport,dst_port dst_port
action event_action
eventtime event_creation_time
event_id event_id
event_message event_message
error event_outcome
event_policy event_policy
applist,profile event_profile
event_ref event_ref
level event_severity
subtype event_subtype
type event_type
catdesc,videocategoryname,activitycategory event_cat
ap,sn event_resource_id
vap event_source
filetype file_ext
analyticscksum,filehash file_hash
filename,file file_name
filesize file_size
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
srccountry host_location
host_mac host_mac
host_name host_name
srcfamily host_osfamily
host_osname host_osname
host_osver host_osver
user host_owner
host_type host_type
srcuuid host_uid
httpmethod http_method
referralurl http_referer
url http_url
agent http_useragent
srcssid net_name
proto net_proto
rcvdpkt,rcvdp net_rcvdpkts
rcvdbyte,rcvdb net_recvbytes
sentbyte,sentb net_sentbytes
sentpkt,sentp net_sentpkts
duration,dur net_sessionduration
sessionid net_sessionid
srcssid net_ssid
pid process_id
srcssid src_asset_id
srcname src_domain
srccountry src_geo
srccity src_geo_city
srccountry src_geo_country
source_info src_intf
srcip,src_ip src_ip
srcmac src_mac
src_natip,transip src_natip
src_natport,transport src_natport
srcport,src_port src_port
threat_action threat_action
threat_direction threat_direction
threat_id threat_id
threat_name threat_name
threat_pattern threat_pattern
threat_ref threat_ref
crscore threat_score
threat_severity threat_severity
threat_type threat_type
group,unauthusersource user_group
user,unauthuser user_id
FortiManager logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
script app_ref
service app_service
state app_state
dstcountry dst_geo
action,event_action event_action
event_id event_id
msg,constmsg event_message
desc event_outcome
desc event_profile
event_message,authmsg event_ref
level,pri event_severity
subtype event_subtype
type,eventtype event_type
start_time event_start_time
end_time event_end_time
file,remote_filename file_name
log_path file_path
log_size file_size
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
userfrom host_location
host_mac host_mac
device,remote_host,host_name host_name
host_osname host_osname
sw_version host_osver
host_type host_type
dev_oid host_uid
url http_url
session_id,sid net_sessionid
srccountry src_geo
remote_ip src_ip
remote_port src_port
user_type user_classification
use_mb user_group
userid user_id
address user_location
user user_name
adminprof user_role
FortiClient logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
fctver data_sourceversion
data_timestamp data_timestamp
cat app_cat
appid app_id
app app_name
srcproduct app_proc
fgtserial,appvendor app_ref
service,ae_api,ems_service_info app_service
endpoint_status app_state
appversion,fctver app_ver
remotename dst_domain
dstcountry dst_geo
dstcountry dst_geo_country
dstip,remoteip,destinationip dst_ip
dstport,remoteport,destinationport dst_port
action event_action
logid event_id
msg,affected_prod_list event_message
status,epenfeatures event_outcome
ruleid,policyname event_policy
usingpolicy event_profile
endpoint_features_info,clientfeature event_ref
level event_severity
event_subtype event_subtype
type event_type
filetype file_ext
checksum file_hash
file file_name
path file_path
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
device_ip,regip,host_ip host_ip
devicemac,mac,host_mac host_mac
hostname,device_name,host_name host_name
os,host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
vpntype http_method
social_srvc http_referer
url http_url
direction net_direction
proto net_proto
rcvdbyte net_recvbytes
sentbyte net_sentbytes
sessionid net_sessionid
processname process_name
domain src_domain
srccountry src_geo
srccountry src_geo_country
srcip src_ip
devicemac,mac src_mac
srcport src_port
threat_action threat_action
threat_id threat_id
threat_name threat_name
threat_pattern threat_pattern
threat_ref threat_ref
threat_severity threat_severity
threat_type threat_type
social_srvc user_authtype
domain user_domain
social_email user_email
uid,vpnuser user_id
user user_name
pcdomain user_org
social_phone user_phone
social_user user_social
FortiSandbox logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
vmos app_cat
jobid,sid app_id
vmname app_name
pid app_proc
rsrc app_ref
service app_service
vmkey app_ver
dstcountry dst_geo
dstcountry dst_geo_country
dstip dst_ip
dstport dst_port
concat_eventaction,snmpaction event_action
etime event_creation_time
logid,log_id event_id
msg event_message
letype event_ref
level event_severity
subtype event_subtype
type event_type
ftype file_ext
file_hash file_hash
file_hash_type file_hashtype
fname file_name
filepath file_path
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
hostname,host,host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
url http_url
emlsndr mail_from
subject mail_subject
emlrcvr mail_to
proto net_proto
srccountry src_geo
srccountry src_geo_country
srcip src_ip
srcport src_port
attackname,mname threat_name
risk threat_severity
stype user_classification
ui user_domain
email user_email
user,unauthuser,suser user_id
FortiADC logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
dm_appid app_id
service app_service
dns_req dns_query
dns_resp dns_response
dst dst_domain
dstcountry dst_geo
dst_port dst_port
action event_action
duration event_duration
msg_id event_id
msg event_message
status event_outcome
policy event_policy
logdesc event_profile
cfgattr event_ref
level,pri event_severity
subtype event_subtype
type event_type
quar_file_name,smtp_attachname file_name
http_host,dm_orihost host_name
http_cookie http_cookie
http_method http_method
http_referer http_referer
http_retcode http_status_code
http_url http_url
http_agent http_useragent
smtp_from mail_from
smtp_bodylen mail_size
smtp_subject mail_subject
smtp_to mail_to
proto net_proto
ibytes net_recvbytes
obytes net_sentbytes
dm_sessionid net_sessionid
src src_domain
srccountry src_geo
src_port src_port
threat_action threat_action
threat_direction threat_direction
threat_id threat_id
threat_name threat_name
threat_pattern threat_pattern
threat_ref threat_ref
threat_score threat_score
threat_severity threat_severity
threat_type threat_type
auth_status user_authtype
usergrp user_group
user user_id
ftp_username user_name
FortiAnalyzer logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
script app_ref
service app_service
state app_state
dstcountry dst_geo
action,event_action event_action
event_id event_id
msg,constmsg event_message
desc event_outcome
desc event_profile
event_message,authmsg event_ref
level,pri event_severity
subtype event_subtype
type,eventtype event_type
start_time event_start_time
end_time event_end_time
file,remote_filename file_name
log_path file_path
log_size file_size
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
userfrom host_location
host_mac host_mac
device,remote_host,host_name host_name
host_osname host_osname
sw_version host_osver
host_type host_type
dev_oid host_uid
url http_url
session_id,sid net_sessionid
srccountry src_geo
remote_ip src_ip
remote_port src_port
user_type user_classification
use_mb user_group
userid user_id
address user_location
user user_name
adminprof user_role
FortiAuthenticator logs
devid data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
status app_state
dstcountry dst_geo
dstcountry dst_geo_country
action event_action
logid event_id
msg event_message
logdesc event_profile
faclogindex event_ref
level event_severity
subtype event_subtype
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
nas,host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
srccountry src_geo
srccountry src_geo_country
user user_id
FortiCache logs
devid data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
appcat,app_cat,monitor-type,webfilter_catdesc app_cat
appid,webfilter_cat_id app_id
app,applist,app_list,monitor-name,webfilter_mode app_name
appact,app_action,cloudaction app_state
request_info dns_query
scheme dns_querytype
response_info dns_response
dst_int dst_domain
dstcountry dst_geo
dstcountry dst_geo_country
dstintf dst_intf
dstip dst_ip
tranip dst_natip
dstport dst_port
action event_action
logid event_id
msg,logdesc event_message
log_rate_info event_outcome
ips_attack_id event_policy
ips_profile,spam_profile event_profile
level,ips_severity event_severity
subtype,messagetype,message_type event_subtype
type,eventtype event_type
filetype,spam_file_type file_ext
checksum file_hash
virus_file_hashtype file_hashtype
filename,spam_subject,filesize file_name
spam_file_size,filesize file_size
host_info,host_classification host_classification
osgen,os_gen,osvendor,host_hwvendor host_hwvendor
host_hwver host_hwver
ip,host_ip host_ip
srccountry host_location
mastersrcmac,host_mac host_mac
hostname,host_name host_name
osfamily host_osfamily
osname,os,host_osname host_osname
osversion,host_osver host_osver
hostname host_owner
devtype,host_type host_type
host_uid host_uid
method http_method
url,webfilter_url_list http_url
agent http_useragent
collectedemail,from mail_from
spam_file_size mail_size
spam_subject mail_subject
to mail_to
vpntype,direction net_direction
vpn net_name
policyid net_payloadid
proto net_proto
rcvdpkt net_rcvdpkts
rcvdbyte net_recvbytes
sentbyte,bandwidth net_sentbytes
sentpkt net_sentpkts
duration net_sessionduration
sessionid net_sessionid
srcssid net_ssid
src_int src_domain
srccountry src_geo
srccountry src_geo_country
srcintf src_intf
srcip src_ip
srcmac src_mac
transip src_natip
transport src_natport
srcport src_port
threat_action threat_action
threat_id threat_id
threat_name threat_name
threat_pattern threat_pattern
threat_ref threat_ref
threat_severity threat_severity
threat_type threat_type
group user_group
custom,clouduser user_id
user user_name
FortiDDoS logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
status app_state
dstcountry dst_geo
dstcountry dst_geo_country
dip dst_ip
dport dst_port
action event_action
msg_id,log_id event_id
msg event_message
detail event_outcome
attack_observed_profile event_profile
event_state_disp event_ref
level event_severity
subtype event_subtype
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
subnet_name net_name
srccountry src_geo
srccountry src_geo_country
sip src_ip
sport src_port
attack_desc threat_action
attack_direction threat_direction
evecode threat_id
uniqueid threat_name
detail threat_ref
FortiDeceptor logs
devid data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
service app_service
dstcountry dst_geo
dstcountry dst_geo_country
victimip dst_ip
action event_action
eventid event_id
msg event_message
status event_outcome
level event_severity
subtype event_subtype
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
srccountry src_geo
srccountry src_geo_country
attackerip src_ip
attackerport src_port
botnetname,attackname threat_name
user user_id
username user_name
FortiEDR logs
devid data_sourceid
device_name,devid data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
component_type app_cat
data_id app_id
component_name app_name
autonomous_system app_ref
device_state app_state
dstcountry dst_geo
dstcountry dst_geo_country
action event_action
event_id event_id
event_message event_message
destination event_outcome
rule_list event_policy
severity event_severity
classification event_subtype
event_type event_type
last_seen file_accessetime
first_seen file_createtime
process_hash file_hash
process_name,script,remediation_files file_name
process_path,script_path file_path
source_ip host_ip
mac_address host_mac
device_name host_name
operating_system host_osname
remote_connection http_method
process_path process_call_trace
process_hash process_hash
process_name process_name
process_type process_company
organization src_domain
country,srccountry src_geo
country,srccountry src_geo_country
source_ip src_ip
action threat_action
siem_threat_name threat_name
siem_threat_pattern threat_pattern
siem_threat_type threat_type
users user_id
user_name user_name
FortiFirewall logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
appact app_action
appcat,app_cat,app-type app_cat
appid app_id
app app_name
service app_service
appact,app_action app_state
dns_name dns_querytype
dns_ip dns_server
dstname dst_domain
dstssid dst_asset_id
dstcountry,dst_country dst_geo
dstcity dst_geo_city
dstcountry,dst_country dst_geo_country
dstregion dst_geo_region
dstintf,dst_int dst_intf
dstip,dst dst_ip
dstmac dst_mac
dstport,dst_port dst_port
action,status event_action
msg event_message
policyid event_policy
alert,error event_profile
level event_severity
subtype event_subtype
type event_type
processtime file_accessetime
hash file_hash
file file_name
filesize file_size
srchwvendor host_hwvendor
srchwversion host_hwver
mac host_mac
hostname host_name
srcfamily host_osfamily
osname host_osname
osversion host_osver
devtype host_type
vpntype http_method
vpn http_referer
url http_url
agent http_useragent
from mail_from
to mail_to
direction net_direction
rcvdpkt,rcvd_pkt net_rcvdpkts
rcvdbyte,rcvd net_recvbytes
sentbyte,sent net_sentbytes
sentpkt,sent_pkt net_sentpkts
duration net_sessionduration
sessionid,SN net_sessionid
ssid net_ssid
srcssid src_asset_id
srcname,srcdomain src_domain
srccountry,src_country src_geo
srccity src_geo_city
srccountry,src_country src_geo_country
srcregion src_geo_region
srcintf,src_int src_intf
srcip,src src_ip
srcmac src_mac
srcport,src_port src_port
utmaction threat_action
virus,attack,attackname,attack_name,vulnname threat_name
securitymode threat_pattern
security threat_severity
group user_group
user,carrier_ep user_id
unauthuser,dstunauthuser user_name
FortiIsolator logs
devid data_sourceid
data_sourcename data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
browsertype app_name
pid app_proc
browserver app_ver
dstcountry dst_geo
dstcountry dst_geo_country
avaction,wfaction event_action
eventtime event_creation_time
msg event_message
avresult event_outcome
avblockreason event_policy
avengine,wfprofile,icapprofile,iprofile,clicmd event_profile
event_severity event_severity
subtype event_subtype
type event_type
filepath file_path
filesize file_size
protocol http_method
dsturl http_url
sessionid net_sessionid
srccountry src_geo
srccountry src_geo_country
clientip src_ip
usertype user_classification
user user_id
FortiMail logs
devid,device_id data_sourceid
data_sourcename data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
dstcountry dst_geo
dst_ip dst_ip
concat_eventaction,disposition event_action
scan_time event_creation_time
logid,log_id event_id
msg event_message
polid event_policy
classifier event_profile
event_message event_ref
pri event_severity
subtype event_subtype
type event_type
file_hash file_hash
file_hash_type file_hashtype
file_name file_name
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
mail_from mail_from
message_length mail_size
subject mail_subject
to mail_to
direction net_direction
session_id net_sessionid
client_name src_domain
location,srccountry src_geo
client_ip src_ip
threat_name threat_name
threat_pattern threat_pattern
ui,domain_name user_domain
user,user_name user_id
FortiNAC logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
sn app_name
agentplat app_service
mailstate app_state
agentver,fwver app_ver
dstcountry dst_geo
dstcountry dst_geo_country
action event_action
msg event_message
severity event_severity
subtype event_subtype
type event_type
lastactivitytime file_accessetime
createtime file_createtime
imagetype file_ext
element,label,host_classification host_classification
vendorname,vendoroid,host_hwvendor host_hwvendor
hwtype,host_hwver host_hwver
ip,host_ip host_ip
location host_location
mac,host_mac host_mac
hostname,name,host_name host_name
os,host_osname host_osname
fwver,host_osver host_osver
owner host_owner
endpointtype,devtype,cat,host_type host_type
endpointid,vendoroid host_uid
srccountry src_geo
srccountry src_geo_country
portid src_port
usertype user_classification
adminprofile user_domain
email user_email
userid,user user_id
user_geo user_location
user_username user_name
org user_org
user_phone user_phone
position user_role
user_social user_social
FortiNDR logs
devid data_sourceid
device_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
status app_state
dstcountry dst_geo
dstcountry dst_geo_country
action event_action
eventtime event_creation_time
logid event_id
level event_severity
devicetype event_source
subtype event_subtype
type event_type
filetype file_ext
file_hash file_hash
file_hashtype file_hashtype
fileid file_name
filesize file_size
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
devhost,host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
fossn src_asset_id
srccountry src_geo
srccountry src_geo_country
victimip src_ip
victimport src_port
malwarefamily threat_category
virusname,vname threat_name
url,filetype threat_pattern
risklevel threat_severity
scenariotype threat_type
user user_id
FortiProxy logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
appact app_action
appcat app_cat
appid app_id
app app_name
daemon,pid app_proc
service app_service
state app_state
qname dns_query
qtype dns_querytype
hostname dst_domain
dstssid dst_asset_id
dstcountry dst_geo
dstcity dst_geo_city
dstcountry dst_geo_country
dstregion dst_geo_region
dst_info dst_intf
dstip dst_ip
dstmac dst_mac
tranip dst_natip
tranport dst_natport
dstport,dst_port dst_port
action event_action
eventtime event_creation_time
logid,log_id event_id
msg event_message
error event_outcome
policyid event_policy
applist event_profile
level event_severity
subtype event_subtype
type event_type
filetype file_ext
hash,checksum file_hash
file,filename file_name
path file_path
filesize file_size
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
mastersrcmac,host_mac host_mac
srcname,host_name host_name
osname,host_osname host_osname
osversion,host_osver host_osver
devtype,host_type host_type
srcuuid host_uid
url http_url
agent http_useragent
from mail_from
size mail_size
subject mail_subject
to mail_to
direction net_direction
srcssid net_name
proto net_proto
rcvdpkt net_rcvdpkts
rcvdbyte net_recvbytes
sentbyte net_sentbytes
sentpkt net_sentpkts
duration net_sessionduration
sessionid,session_id net_sessionid
ssid net_ssid
srcname src_domain
srccountry src_geo
srccity src_geo_city
srccountry src_geo_country
srcregion src_geo_region
src_info src_intf
srcip src_ip
srcmac,source_mac src_mac
transip src_natip
transport src_natport
srcport,src_port src_port
sslaction threat_action
direction threat_direction
vulnid,virusid,attackid threat_id
vulnname,virus,attack threat_name
attackcontext threat_pattern
ref,cveid threat_ref
auditscore threat_score
severity threat_severity
threattype threat_type
group,unauthusersource user_group
user,unauthuser,clouduser user_id
FortiSOAR logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp,dtime data_timestamp
FSR_NAME app_name
service_name app_service
FSR_VER app_ver
dstcountry dst_geo
dstcountry dst_geo_country
event_id event_id
event_message event_message
event_profile event_profile
event_severity event_severity
event_subtype event_subtype
event_type event_type
host_classification host_classification
host_name host_name
srccountry src_geo
srccountry src_geo_country
src_ip src_ip
user_id user_id
user_name user_name
FortiSwitch logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
dstcountry dst_geo
dstcountry dst_geo_country
dstip dst_ip
action event_action
logid,log_id event_id
msg event_message
status event_outcome
profile,reason event_profile
level,pri event_severity
subtype event_subtype
type event_type
ui http_url
mirror-session net_sessionid
srccountry src_geo
srccountry src_geo_country
switch.interface src_intf
srcip,auto-ip src_ip
switch.physical-port,port src_port
userfrom user_group
user user_id
FortiWeb logs
devid,device_id data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
service,backend_service,server_pool_name app_service
http_host dst_domain
dstcountry dst_geo
dstcountry dst_geo_country
dst_info dst_intf
dst dst_ip
dstport,dst_port dst_port
action event_action
logid,log_id event_id
msg event_message
status event_outcome
trigger_policy,policy event_policy
pri,severity_level event_severity
subtype event_subtype
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
host_name host_name
host_osname host_osname
host_osver host_osver
devtype,host_type host_type
host_uid host_uid
http_method http_method
http_refer http_referer
http_url http_url
http_agent http_useragent
proto net_proto
srccountry,original_srccountry src_geo
srccountry,original_srccountry src_geo_country
ui src_intf
src src_ip
srcport,src_port src_port
threat_action threat_action
direction threat_direction
main_type threat_name
signature_info,bot_info threat_pattern
threat_weight threat_score
threat_level threat_severity
threat_type threat_type
user user_id
user_name user_name
Apache logs
devid data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
app_name app_name
pid app_proc
service app_service
message event_message
file_name file_name
host_ip host_ip
host_name host_name
http_method http_method
http_referer http_referer
http_url http_url
http_useragent http_useragent
http_status_code http_status_code
Nginx logs
devid data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
app_name app_name
message event_message
host_ip host_ip
host_name host_name
http_method http_method
http_referer http_referer
http_url http_url
http_useragent http_useragent
System logs
devid,device_id data_sourceid
host_name,devid data_sourcename
data_sourcetype data_sourcetype
dtime data_timestamp
app_cat app_cat
service app_service
dstcountry dst_geo_country
dstip dst_ip
message,cleaned_msg,msg event_message
level event_severity
type event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
srccountry src_geo_country
srcip src_ip
Ubuntu logs
The Ubuntu Syslog Parser will only parse Ubuntu logs if they are sent from FortiClient.
devid data_sourceid
data_source_name data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
app_name app_name
pid app_proc
service app_service
dst_info dst_intf
event_action event_action
message event_message
log_level event_severity
ext_eventsubtype event_subtype
ext_eventtype event_type
host_classification host_classification
host_hwvendor host_hwvendor
host_hwver host_hwver
host_ip host_ip
host_mac host_mac
hostname,host_name host_name
host_osname host_osname
host_osver host_osver
host_type host_type
host_uid host_uid
ip src_ip
srcmac src_mac
The Windows Event Log Parser will only parse Windows event logs if:
l the logs are sent from FortiClient to FortiAnalyzer, or
l the syslog logs are sent from the Windows endpoint directly to FortiAnalyzer in JSON
format.
devid data_sourceid
data_sourcename data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
app_cat,channel app_cat
app_name,provider_name app_name
execution_pid app_proc
app_ref app_ref
version app_ver
domain_name dst_domain
dstcountry dst_geo
dstcountry dst_geo_country
dstip dst_ip
sys_keywords event_action
event_id event_id
event_log,exch_log,event_json event_message
event_data_return_code,event_outcome event_outcome
event_profile event_profile
event_record_id,event_ref event_ref
event_severity,level event_severity
event_subtype,provider_name event_subtype
event_type,channel event_type
event_source,provider_name event_source
host_ip host_ip
host_name host_name
os_family host_osfamily
host_uid host_uid
logon_authentication logon_authentication
logon_id logon_id
event_data_subj_user_name logon_user_claims
mail_from mail_from
mail_subject mail_subject
net_direction net_direction
net_proto net_proto
net_sentbytes net_sentbytes
process_id process_id
process_name process_name
parent_process_name process_parent_name
process_status process_status
src_domain src_domain
srccountry src_geo
srccountry src_geo_country
srcip,src_ip src_ip
user_domain user_domain
user_group user_group
user_id user_id
user_name user_name
Copyright© 2024 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein
may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were
attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance
results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract,
signed by Fortinet’s Chief Legal Officer, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only
the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal
conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change,
modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.