Fortimanager Log Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Fortimanager Log Messages

Base Rule

General Information

Information

User SSH Logon Failure

Sub Rule

Denied SSH Session

Warning

Connection Reset By Peer

Sub Rule

Connection Reset

Network Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

logid

<vmid>

Number

It is a unique 10-digit identifier for that specific log.


<severity>

Text\String

Each log entry contains a Level (level) field that indicates the estimated severity of the event.

remote_ip

<sip>

IP Address

N/A

remote_port

<sport>

Number

N/A

user

<login>

Text\String

N/A

msg

<subject>

Text\String

N/A