Skip to main content
Skip table of contents

V 2.0 : FG VPN-1 & Firewall-1 Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : FG VPN-1 & Firewall-1 EventsBase RuleGeneral Network TrafficNetwork Traffic
V 2.0 : Firewall Message DroppedSub RuleTraffic Denied by Network FirewallNetwork Deny
V 2.0 : Firewall Message RejectedSub RuleTraffic Denied by Network FirewallNetwork Deny
V 2.0 : Firewall Message AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0 : Firewall Message BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
V 2.0 : Firewall Message AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/AN/A
Product<vmid>Text/StringProduct name
OriginipN/AN/AIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>Text/StringN/A
SIP<sip>IP AddressSource IP
SPort<sport>NumberSource host port number
DIP<dip>IP AddressDestination IP
dport<dport>NumberDestination host port number
protocol<protnum>NumberProtocol detected on the connection
ifname<sinterface>Text/StringThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AN/A
Reason<reason>Text/StringInformation on the error occurred
RuleN/AN/AN/A
InfoN/AN/AN/A
XlateSIP<snatip>IP AddressN/A
XlateSport<snatport>NumberN/A
XlateDIP<dnatip>IP AddressN/A
XlateDPort<dnatport>NumberN/A
UserN/AN/ASource user name
alertN/AN/AN/A
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AN/A
rule_nameN/AN/AAccess rule name
UrlN/AN/AN/A
src_machine_name<sname>Text/StringMachine name of the source
dst_machine_name<dname>Text/StringMachine name of the target
src_user_name<login>Text/StringUser name of the source
dst_user_name<account>Text/StringUser name of the target
Query_snidN/AN/AN/A
OriginZoneN/AN/AIndicates whether the source zone is internal or external 
ImpactedZoneN/AN/AIndicates whether the destination zone is internal or external
ServiceN/AN/AConnection destination int/service int
conn_directionN/AN/ADetermines the direction of the connection
contextnumN/AN/AN/A
flagsN/AN/ACheckpoint internal field
logidN/AN/AN/A
loguidN/AN/AUUID of unified logs 
originsicnameN/AN/AMachine SIC 
sequencenumN/AN/ANumber added to order logs with the same Linux timestamp and origin
versionN/AN/ASoftware/hardware version
__nsonsN/AN/AN/A
__p_dportN/AN/AN/A
__policy_id_tag

<policy>

Text/StringCheckpoint internal field
__posN/AN/AN/A
bytesN/AN/AN/A
client_inbound_bytes<bytesout>NumberNumber of bytes received during connection
client_inbound_interfaceN/AN/AN/A
client_inbound_packets<itemsout>NumberNumber of packets received during connection
client_outbound_bytes<bytesin>NumberNumber of bytes sent during connection
client_outbound_interfaceN/AN/AN/A
client_outbound_packets<itemsin>NumberNumber of packets sent during connection
context_numN/AN/AN/A
dst_user_dnN/AN/AN/A
elapsedN/AN/AN/A
fg-1_client_in_rule_nameN/AN/AN/A
fg-1_client_out_rule_nameN/AN/AN/A
fg-1_server_in_rule_nameN/AN/AN/A
fg-1_server_out_rule_nameN/AN/AN/A
hll_keyN/AN/AN/A
lastupdatetimeN/AN/AN/A
layer_nameN/AN/AN/A
layer_uuidN/AN/AN/A
match_idN/AN/AN/A
parent_ruleN/AN/AN/A
rule_actionN/AN/AN/A
rule_uidN/AN/AAccess policy rule ID on which the connection was matched
nat_addtnl_rulenumN/AN/AN/A
nat_rulenumN/AN/AN/A
packetsN/AN/AN/A
segment_timeN/AN/AN/A
server_inbound_bytesN/AN/AN/A
server_inbound_interfaceN/AN/AN/A
server_inbound_packetsN/AN/AN/A
server_outbound_bytesN/AN/AN/A
server_outbound_interfaceN/AN/AN/A
server_outbound_packetsN/AN/AN/A
sig_idN/AN/AN/A
src_user_dnN/AN/AN/A
start_timeN/AN/AAction start time of the connection
https_inspection_actionN/AN/AN/A
vpn_feature_nameN/AN/AN/A
communityN/AN/AN/A
encryption_failure:N/AN/AN/A
methods:N/AN/AN/A
partnerN/AN/AN/A
peer_gatewayN/AN/AN/A
scheme:N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.