e. Anomaly
Records intrusion attempts.
Sample Event
date=2019-05-13 time=17:05:59 logid="0720018433" type="utm" subtype="anomaly" eventtype="anomaly" level="alert" vd="vdom1" eventtime=1557792359461869329 severity="critical" srcip=10.1.100.11 srccountry="Reserved" dstip=172.16.200.55 srcintf="port12" srcintfrole="undefined" sessionid=0 action="clear_session" proto=1 service="PING" count=1 attackk="icmp_flood" icmpid="0x1474" icmptype="0x08" icmpcode="0x00" attackid=16777316 policyid=1 policytype="DoS-policy" ref="http://www.fortinet.com/ids/VID16777316" msg="anomaly: icmp_flood, 51 > threshold 50" crscore=50 craction=4096 crlevel="critical"
Fields
Field | Description |
---|---|
DATE | Event date, in the format YYYY-MM-DD |
TIME | Event time, in the format HH:MM:SS |
SYSTEM | The source system |
TABLE | FortiGateAnomaly |
CRITICALITY |
|
LOGID | Unique 10-digit identifier (log type, subtype/event type and message ID) for that specific log and includes information about the log entry |
TYPE | Represented by the first two digits of the log ID |
SUBTYPE | Represented by the first/second two digits of the log ID |
EVENTTYPE | Represented by the second two digits of the log ID |
DEVNAME |
|
DEVID | Serial number of the device for the traffic's origin |
LEVEL | Security level rating |
VD | Name of the virtual domain in which the log message was recorded |
EVENTTIME | Epoch time the log was triggered by FortiGate |
SEVERITY | Severity |
SRCIP | Source IP |
SRCCOUNTRY |
|
DSTIP | Destination IP |
SRCINTF | Source interface |
SRCINTFROLE |
|
SESSIONID | Session ID |
ACTION | Action |
PROTO | Protocol |
SERVICE | Name of service |
COUNT | Count |
ATTACK | Attack |
ICMPID | ICMP ID |
ICMPTYPE | ICMP type |
ICMPCODE | ICMP code |
ATTACKID | Attack ID |
POLICYID | Policy ID |
POLICYTYPE |
|
REF | Reference |
MSG | Log Message |
CRSCORE | Client Reputation score |
CRACTION | Client Reputation action |
CRLEVEL | Client Reputation level |
SNAREDATAMAP | All other data in the event will be pushed to this field |
Notes
Log Message Reference Documentation: https://docs.fortinet.com/document/fortigate/6.4.2/fortios-log-message-reference