Skip to main content
Skip table of contents

LSO FortiAnalyzer - UTM : Virus

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Header: Severity

<severity>

N/A

logid

<vmid>
<tag1>

N/A

eventtype

<status>

N/A

srcip

<sip>

N/A

dstip

<dip>

N/A

srcport

<sport>

N/A

dstport

<dport>

N/A

msg

<subject>

N/A

action

<action>

N/A

service

<protname>

N/A

sessionid

<session>

N/A

srcintf

<sinterface>

N/A

dstintf

<dinterface>

N/A

proto

<protnum>

N/A

filename

<object>

N/A

quarskip

<vendorinfo>

N/A

virus

<threatname>

N/A

dtype

<objecttype>

N/A

filetype

<objectname>

N/A

url

<url>

N/A

profile

<policy>

N/A

agent

<useragent>

N/A

analyticscksum

<hash>

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1010168

UTM : Virus

Base Rule

General Virus Filename Information

Information

Virus Infect Warning

Sub Rule

General Virus Infected Warning

Warning

Malware Traffic Allowed By AntiVirus

Sub Rule

General Virus Infected Notice

Information

MIME Header Detected To Have A Virus And Blocked

Sub Rule

Detected Malware Activity

Malware

MIME Header Infected And Passed

Sub Rule

MIME Intercepted

Activity

File Is An Executable

Sub Rule

HTTP Executable Transfer

Activity

File Is An Executable

Sub Rule

HTTP Executable Transfer

Activity

FortiGate Unit Blocked A File

Sub Rule

Blocked Message

Failed Activity

FortiGate Unit Blocked A File

Sub Rule

Blocked Message

Failed Activity

FortiGate Unit Blocked A File

Sub Rule

Blocked Message

Failed Activity

FortiGate Unit Blocked A File

Sub Rule

Blocked Message

Failed Activity

FortiGate Unit Blocked A Virus Command

Sub Rule

Unknown Command

Other Security

FortiGate Unit Intercepted A File Containing Virus

Sub Rule

File Intercepted

Activity

FortiGate Unit Intercepted A File (MIME)

Sub Rule

File Intercepted

Activity

File Exempted

Sub Rule

File Exempted

Information

File Exempted

Sub Rule

File Exempted

Information

MMS Content Checksum Blocked An Infected File

Sub Rule

Checksum Warning

Warning

MMS Content Checksum Was Matched

Sub Rule

General Checksum Information

Information

Defined File Size Limit Was Exceeded

Sub Rule

Limit Exceeded

Warning

File Size Limit Was Exceeded

Sub Rule

Limit Exceeded

Warning

File (MIME) Size Exceed The Defined Size Limit

Sub Rule

Limit Exceeded

Warning

File (MIME) Size Exceed The Defined Size Limit

Sub Rule

Limit Exceeded

Warning

Switching Protocols Request

Sub Rule

Protocol Change Requested

Information

Switching Protocols Request

Sub Rule

Protocol Change Requested

Information

File Reached The Uncompressed Nested Limit

Sub Rule

Limit Exceeded

Warning

File Reached The Uncompressed Nested Limit

Sub Rule

Limit Exceeded

Warning

Archived File Is Corrupted

Sub Rule

Data Corrupt

Warning

Archived File Is Encrypted

Sub Rule

Encrypted Files Detected

Activity

Corrupted Archive

Sub Rule

Data Corrupt

Warning

Corrupted Archive

Sub Rule

Data Corrupt

Warning

File Is A Multipart Archive

Sub Rule

Archive Message

Information

File Is A Multipart Archive

Sub Rule

Archive Message

Information

File Is A Nested Archived File

Sub Rule

Archive Message

Information

File Is An Archived Type Unhandled

Sub Rule

Archive Message

Information

Archived File Is Oversized

Sub Rule

Limit Exceeded

Warning

Archived File Is Oversized

Sub Rule

Limit Exceeded

Warning

Unhandled Archive

Sub Rule

Object Not Archived

Warning

Unhandled Archive

Sub Rule

Archive Message

Information

AV Engine Load Failed

Sub Rule

Onload Failure

Error

Partially Corrupted Archive

Sub Rule

Data Corrupt

Warning

Partially Corrupted Archive

Sub Rule

Data Corrupt

Warning

Exceeded Archive Files Limit

Sub Rule

Limit Exceeded

Warning

Exceeded Archive Files Limit

Sub Rule

File Size Exceeds Limit

Activity

Archive Scan Timeout

Sub Rule

Timeout

Warning

Archive Scan Timeout

Sub Rule

Timeout

Warning

File Submitted To Sandbox

Sub Rule

File Monitoring Event - Permissions

Access Success

File Reported Infected

Sub Rule

General Virus Infected Warning

Warning

File Reported Infected

Sub Rule

General Virus Infected

Information

File Reported Infected

Sub Rule

General Virus Infected Warning

Warning

File Reported Infected

Sub Rule

General Virus Infected

Information

File Verdict Returned

Sub Rule

Results Returned

Information

Active Content Detected By Content Disarm Engine

Sub Rule

General WebFilter Content

Information

File Was Disarmed By Content Disarm Engine

Sub Rule

File Unavailable

Warning

Botnet C&C Communication

Sub Rule

InterProcessor Communication Warning

Warning

Botnet C&C Communication

Sub Rule

Interprocess Communication

Information

LogRhythm Default v2.0

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.