Syslog Fortinet FortiGate - V 2.0 : Event : HA

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Event : HA

Base Rule

General HA Information

Information

V 2.0 : HA Sync ETDB

Sub Rule

General HA Information

Information

V 2.0 : HA Sync FLDB

Sub Rule

General HA Information

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

date

N/A

N/A

The date of the log event.

time

N/A

N/A

The time of the log event.

logid

<vmid>

Number

A unique identifier for the log event.

type

<vendorinfo>

Text/String

The type of log event. In this case, it is an event.

subtype

N/A

N/A

The subtype of the log event. In this case, it is a HA event.

level

<severity>

Text/String

The severity level of the log event. In this case, it is a critical.

vd

<sessiontype>

Text/String

The vdom in which the log event occurred.

eventtime

N/A

N/A

The time at which the log event occurred.

logdesc

N/A

N/A

The description of the log event.

msg

<subject>

Text/String

The message associated with the log event.

vcluster

N/A

N/A

The virtual cluster ID.

ha_group

<group>

Number

The HA group ID.

sn

<serialnumber>

Text/String

The serial number of the FortiGate that joined the virtual cluster.