Skip to main content
Skip table of contents

Syslog Fortinet FortiGate - V 2.0 : UTM : VOIP

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0: UTM: VOIP

Base Rule

General Firewall Event

Information

V 2.0: Voip SIP

Sub Rule

VoIP SIP Message

Information

V 2.0: LOGID_EVENT_VOIP_SIP_BLOCK

Sub Rule

Access Blocked

Information

V 2.0: LOGID_EVENT_VOIP_SIP_FUZZING

Sub Rule

Session Stopped

Other Audit Success

V 2.0: LOGID_EVENT_VOIP_SCCP_REGISTER

Sub Rule

Device Registered

Other Audit Success

V 2.0: LOGID_EVENT_VOIP_SCCP_UNREGISTER

Sub Rule

Device Unregistered

Warning

V 2.0: LOGID_EVENT_VOIP_SCCP_CALL_BLOCK

Sub Rule

VoIP SCCP Call Block Message

Information

V 2.0: LOGID_EVENT_VOIP_SCCP_CALL_INFO

Sub Rule

VoIP SCCP Call Block Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

logver

<version>

Number

N/A

timestamp

N/A

N/A

N/A

devname

<sname>

Text/String

N/A

devid

N/A

N/A

N/A

vd

<sessiontype>

Text/String

N/A

date

N/A

N/A

The date of the event.

time

N/A

N/A

The time of the event.

eventtime

N/A

N/A

N/A

tz

N/A

N/A

N/A

logid

<vmid>

Number

The log ID.

type

<vendorinfo>

Text/String

The type of event.

subtype

N/A

N/A

The subtype of the event.

eventtype

N/A

N/A

The specific type of VOIP event.

level

<severity>

Text/String

The level of the event.

session_id

<session>

Number

The ID of the session associated with the log event.

epoch

N/A

N/A

N/A

event_id

N/A

N/A

N/A

srcip

<sip>

IP Address

The source IP address.

src_port

<sport>

Number

The source port.

dstip

<dip>

IP Address

The destination IP address.

dst_port

<dport>

Number

The destination port.

proto

<protnum>

Number

The protocol.

src_int

N/A

N/A

The source interface.

dst_int

N/A

N/A

The destination interface.

policy_id

<policy>

Number

The policy ID.

profile

N/A

N/A

N/A

voip_proto

<protname>

Text/String

N/A

kind

N/A

N/A

N/A

action

<action>

Text/String

N/A

status

<status>

Text/String

N/A

duration

<seconds>

Number

N/A

dir

N/A

N/A

N/A

call_id

N/A

N/A

N/A

from

<sender>

Text/String

N/A

to

<recipient>

Text/String

N/A

logsrc

N/A

N/A

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.