Skip to main content
Skip table of contents

Syslog Fortinet FortiGate - V 2.0 : UTM : WAF

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0: UTM: WAF

Base Rule

General Firewall Event

Information

V 2.0: WAF_SIGNATURE_BLOCK

Sub Rule

Traffic Denied by WAF

Network Deny

V 2.0: WAF_SIGNATURE_PASS

Sub Rule

Traffic Allowed by WAF

Network Allow

V 2.0: WAF_SIGNATURE_ERASE

Sub Rule

General Firewall Log

Network Traffic

V 2.0: WAF_CUSTOM_SIGNATURE_BLOCK

Sub Rule

Traffic Denied by WAF

Network Deny

V 2.0: WAF_CUSTOM_SIGNATURE_PASS

Sub Rule

Traffic Allowed by WAF

Network Allow

V 2.0: WAF_METHOD_BLOCK

Sub Rule

Traffic Denied by WAF

Network Deny

V 2.0: WAF_ADDRESS_LIST_BLOCK

Sub Rule

Traffic Denied by WAF

Network Deny

V 2.0: WAF_CONSTRAINTS_BLOCK

Sub Rule

Traffic Denied by WAF

Network Deny

V 2.0: WAF_CONSTRAINTS_PASS

Sub Rule

Traffic Allowed by WAF

Network Allow

V 2.0: WAF_URL_ACCESS_PERMIT

Sub Rule

Traffic Allowed by WAF

Network Allow

V 2.0: WAF_URL_ACCESS_BYPASS

Sub Rule

Traffic Allowed by WAF

Network Allow

V 2.0: WAF_URL_ACCESS_BLOCK

Sub Rule

Traffic Denied by WAF

Network Deny

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

date

N/A

N/A

The date of the event.

time

N/A

N/A

The time of the event.

devname

<sname>

Text/String

N/A

devid

N/A

N/A

N/A

eventtime

N/A

N/A

N/A

tz

N/A

N/A

N/A

logid

<vmid>

Number

The log ID.

type

<vendorinfo>

Text/String

The type of event.

subtype

N/A

N/A

The subtype of the event.

eventtype

N/A

N/A

The specific type of WAF event.

level

N/A

N/A

The level of the event.

vd

<sessiontype>

Text/String

N/A

policyid

<policy>

Number

The policy ID

poluuid

N/A

N/A

The policy UID

policytype

N/A

N/A

The policy Type

sessionid

<session>

Number

The ID of the session associated with the log event.

profile

N/A

N/A

N/A

srcip

<sip>

IP Address

The source IP address.

srcport

<sport>

Number

The source port.

srccountry

N/A

N/A

The source country.

srcuuid

N/A

N/A

N/A

dstip

<dip>

IP Address

The destination IP address.

dstport

<dport>

Number

The destination port.

dstcountry

N/A

N/A

The destination country.

dstuuid

N/A

N/A

N/A

srcintf

<sinterface>

Text/String

The source interface.

srcintfrole

N/A

N/A

The source interface role.

dstintf

<dinterface>

Text/String

The destination interface.

dstintfrole

N/A

N/A

The destination interface role.

proto

<protnum>

Number

The protocol.

service

<protname>

Text/String

N/A

url

<url>

Text/String

N/A

severity

<severity>

Text/String

N/A

action

<action>

Text/String

N/A

direction

N/A

N/A

N/A

agent

<useragent>

Text/String

N/A

constraint

N/A

N/A

N/A

eventid

N/A

N/A

N/A

msg

<subject>

Text/String

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.