Skip to main content
Skip table of contents

Syslog Fortinet FortiGate - V 2.0 : UTM : DLP

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : UTM : DLP

Base Rule

General DLP Message

Information

V 2.0 : DLP Fingerprint Document Source Error

Sub Rule

General Error

Error

V 2.0 : DLP Fingerprint Document Source Notice

Sub Rule

General DLP Message

Information

V 2.0 : UTM DLP Notif

Sub Rule

Data Leak Detected

Warning

V 2.0 : Data Leak Detected By Specified DLP Sensor

Sub Rule

Data Leak Detected

Warning

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

date

N/A

N/A

The date of the log entry.

time

N/A

N/A

The time of the log entry.

logid

<vmid>

Number

The unique identifier for the log entry.

type

<vendorinfo>

Text/String

The type of log event.

subtype

N/A

N/A

The subtype of the log event.

eventtype

N/A

N/A

The specific type of DLP event.

level

N/A

N/A

The severity level of the log event.

vd

<sessiontype>

Text/String

The virtual domain associated with the log event.

eventtime

N/A

N/A

The timestamp of the event.

filteridx

N/A

N/A

The index of the applied filter.

dlpextra

N/A

N/A

Extra information related to DLP, specifically file size.

filtertype

N/A

N/A

The type of filter applied.

filtercat

N/A

N/A

The category of the filter applied.

severity

<severity>

Text/String

The severity level of the DLP event.

policyid

<policy>

Number

The ID of the policy associated with the log event.

sessionid

<session>

Number

The ID of the session associated with the log event.

epoch

N/A

N/A

The epoch time of the event.

eventid

N/A

N/A

The ID of the event.

srcip

<sip>

IP Address

The source IP address of the communication.

srcport

<sport>

Number

The source port of the communication.

srcintf

<sinterface>

Text/String

The source interface.

srcintfrole

N/A

N/A

The role of the source interface.

dstip

<dip>

IP Address

The destination IP address of the communication.

dstport

<dport>

Number

The destination port of the communication.

dstintf

<dinterface>

Text/String

The destination interface.

dstintfrole

N/A

N/A

The role of the destination interface.

proto

<protnum>

Number

The protocol number (TCP in this case).

service

<protname>

Text/String

The service or protocol being used.

filetype

<objecttype>

Text/String

The type of file being transferred.

direction

N/A

N/A

The direction of the communication.

action

<action>

Text/String

The action taken by the system (blocking in this case).

hostname

<sname>

Text/String

The hostname associated with the communication.

url

<url>

Text/String

The URL accessed or requested.

agent

<useragent>

Text/String

The user agent or client used for the communication.

filename

<object>

Text/String

The name of the file being transferred.

filesize

N/A

N/A

The size of the file being transferred.

profile

N/A

N/A

The DLP profile or test applied.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.