Skip to main content
Skip table of contents

Syslog Fortinet FortiGate - V 2.0 : UTM : VOIP

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : UTM : VOIP

Base Rule

General Firewall Event

Information

V 2.0 : Voip SIP

Sub Rule

VoIP SIP Message

Information

V 2.0 : LOGID_EVENT_VOIP_SIP_BLOCK

Sub Rule

Access Blocked

Information

V 2.0 : LOGID_EVENT_VOIP_SIP_FUZZING

Sub Rule

Session Stopped

Other Audit Success

V 2.0 : LOGID_EVENT_VOIP_SCCP_REGISTER

Sub Rule

Device Registered

Other Audit Success

V 2.0 : LOGID_EVENT_VOIP_SCCP_UNREGISTER

Sub Rule

Device Unregistered

Warning

V 2.0 : LOGID_EVENT_VOIP_SCCP_CALL_BLOCK

Sub Rule

VoIP SCCP Call Block Message

Information

V 2.0 : LOGID_EVENT_VOIP_SCCP_CALL_INFO

Sub Rule

VoIP SCCP Call Block Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

logver

<version>

Number

N/A

timestamp

N/A

N/A

N/A

devname

<sname>

Text/String

N/A

devid

N/A

N/A

N/A

vd

N/A

N/A

N/A

date

N/A

N/A

N/A

time

N/A

N/A

N/A

eventtime

N/A

N/A

N/A

tz

N/A

N/A

N/A

logid

<vmid>

Number

N/A

type

<vendorinfo>

Text/String

N/A

subtype

N/A

N/A

N/A

eventtype

N/A

N/A

N/A

level

<severity>

Text/String

N/A

session_id

<session>

Number

N/A

epoch

N/A

N/A

N/A

event_id

N/A

N/A

N/A

srcip

<sip>

IP Address

N/A

src_port

<sport>

Number

N/A

dstip

<dip>

IP Address

N/A

dst_port

<dport>

Number

N/A

proto

<protnum>

Number

N/A

src_int

N/A

N/A

N/A

dst_int

N/A

N/A

N/A

policy_id

<policy>

Number

N/A

profile

N/A

N/A

N/A

voip_proto

<protname>

Text/String

N/A

kind

N/A

N/A

N/A

action

<action>

Text/String

N/A

status

<status>

Text/String

N/A

duration

<seconds>

Number

N/A

dir

N/A

N/A

N/A

call_id

N/A

N/A

N/A

from

<sender>

Text/String

N/A

to

<recipient>

Text/String

N/A

logsrc

N/A

N/A

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.