LSO FortiAnalyzer - Traffic : Local
Vendor Documentation
FortiAnalyzer event log message example | Log Message Reference FortiAnalyzer application log message example | Log Message Reference |
Log Fields and Parsing
This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.
Log Field | LogRhythm Default | LogRhythm Default v2.0 |
---|---|---|
devname | <subject> | N/A |
logid | <vmid> | N/A |
srcip | <sip> | N/A |
srcport | <sport> | N/A |
srcintf | <sinterface> | N/A |
dstip | <dip> | N/A |
dstport | <dport> | N/A |
dstintf | <dinterface> | N/A |
sessionid | <session> | N/A |
proto | <protnum> | N/A |
action | <action> | N/A |
policyid | <policy> | N/A |
policytype | <reason> | N/A |
sentbyte | <bytesout> | N/A |
rcvdbyte | <bytesin> | N/A |
sentpkt | <packetsout> | N/A |
rcvdpkt | <packetsin> | N/A |
appcat | <objectname> | N/A |
srcmac | <smac> | N/A |
Log Processing Settings
This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.
LogRhythm Default
Regex ID | Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|---|
1012447 | Traffic : Local | Base Rule | General Traffic Log | Network Traffic |
Traffic Local Accepted | Sub Rule | Traffic Allowed by Network Firewall | Network Allow | |
Traffic Local Deny | Sub Rule | Traffic Denied by Network Firewall | Network Deny | |
Traffic Local Closed | Sub Rule | General Traffic Other Notice | Information | |
Local Traffic Timeout | Sub Rule | Session Disconnected | Information | |
Local Traffic Accepted | Sub Rule | Traffic Allowed by Network Firewall | Network Allow | |
Forward Traffic Deny | Sub Rule | Traffic Denied by Network Firewall | Network Deny | |
LOG_ID_TRAFFIC_START_LOCAL | Sub Rule | TCP Traffic Allowed | Network Traffic |
LogRhythm Default v2.0
N/A