Skip to main content
Skip table of contents

LSO FortiGate - Event : Switch-Controller

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Header : Severity

<severity>

N/A

date

N/A

N/A

time

N/A

N/A

eventtime

N/A

N/A

tz

N/A

N/A

logid

<vmid>

<vmid>

type

N/A

<vendorinfo>

subtype

N/A

N/A

level

N/A

<severity>

vd

<login>

N/A

logdesc

<object>

N/A

user

<account>

<login>

sn

<serialnumber>

<serialnumber>

name

N/A

N/A

msg

<subject>

<subject>

ui

N/A

<sinterface>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1012323

Event : Switch-Controller

Base Rule

Switch Information

Information

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Event

Classification

1013184

V 2.0 : Event : Switch-Controller

Base Rule

General Firewall Event

Information

V 2.0 : LOG_ID_FGT_SWITCH_LOG_DISCOVER

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_LOG_AUTH

Sub Rule

Authentication Activity

Authentication Success

V 2.0 : LOG_ID_FGT_SWITCH_LOG_DEAUTH

Sub Rule

Privilege Revoked

Access Revoked

V 2.0 : LOG_ID_FGT_SWITCH_LOG_DELETE

Sub Rule

Object Deleted/Removed

Access Success

V 2.0 : LOG_ID_FGT_SWITCH_LOG_TUNNEL_UP

Sub Rule

General TUNNEL Message

Information

V 2.0 : LOG_ID_FGT_SWITCH_LOG_TUNNEL_DOWN

Sub Rule

Connection Is Down

Error

V 2.0 : LOG_ID_FGT_SWITCH_PUSH_IMAGE

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_STAGE_IMAGE

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_DISABLE_DISCOVERY

Sub Rule

Feature Disabled

Information

V 2.0 : LOG_ID_FGT_SWITCH_LOG_WARNING

Sub Rule

General Warning

Warning

V 2.0 : LOG_ID_FGT_SWITCH_EXPORT_POOL

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_EXPORT_VDOM

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_REQUEST_PORT

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_RETURN_PORT

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_MAC_ADD

Sub Rule

Object Added

Access Success

V 2.0 : LOG_ID_FGT_SWITCH_MAC_DEL

Sub Rule

Object Deleted/Removed

Access Success

V 2.0 : LOG_ID_FGT_SWITCH_MAC_MOVE

Sub Rule

MAC Move Notification Feature Info Msg

Information

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_SWC

Sub Rule

Switch Information

Information

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_POE

Sub Rule

General Critical

Critical

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_LINK

Sub Rule

General Critical

Critical

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_STP

Sub Rule

Spanning Tree Alert

Critical

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_SWITCH

Sub Rule

General Critical

Critical

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_ROUTER

Sub Rule

General Critical

Critical

V 2.0 : LOG_ID_FGT_SWITCH_GROUP_SYSTEM

Sub Rule

General Critical

Critical

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.