V 2.0 : Event : Endpoint
General Endpoint Message
V 2.0 : Add Connection
Network Connection Established
V 2.0 : Close Connection
Client Connection Closed
Other Audit Success
Mapping with LogRhythm Schema
Device Key in Log Message
The date of the log event.
The time of the log event.
A unique identifier for the log event.
The type of log event. In this case, it is an event.
The subtype of the log event. In this case, it is an endpoint event.
The severity level of the log event. In this case, it is an information.
The vdom in which the log event occurred.
The time at which the log event occurred.
The description of the log event.
The action that was taken. In this case, it was an add.
The status of the action. In this case, it was a success.
The license limit for the FortiClient connection.
The type of FortiClient connection. In this case, it is a SSLVPN connection.
The type of FortiClient connection.
The number of FortiClient connections added.
The user who added the FortiClient connection.
The IP address of the FortiClient connection.
The name of the FortiClient connection.
The FortiClient connection ID.
The message associated with the log event.