/
e. Wireless

e. Wireless

Sample Event

date=2019-05-13 time=11:30:08 logid="0104043568" type="event" subtype="wireless" level="warning" vd="vdom1" eventtime=1557772208134721423 logdesc="Fake AP on air" ssid="fortinet" bssid="90:6c:ac:89:e1:fa" aptype=0 rate=130 radioband="802.11n" channel=6 action="fake-ap-on-air" manuf="Fortinet, Inc." security="WPA2 Personal" encryption="AES" signal=-93 noise=-95 live=353938 age=505 onwire="no" detectionmethod="N/A" stamac="N/A" apscan="N/A" sndetected="N/A" radioiddetected=0 stacount=0 snclosest="FP320C3X17001909" radioidclosest=0 apstatus=0 msg="Fake AP On-air fortinet 90:6c:ac:89:e1:fa chan 6 live 353938 age 505"

Fields

Field

Description

Field

Description

DATE

Event date, in the format YYYY-MM-DD

TIME

Event time, in the format HH:MM:SS

SYSTEM

The source system

TABLE

FortiGateEventWireless

CRITICALITY

 

LOGID  

Unique 10-digit identifier (log type, subtype/event type and message ID) for that specific log and includes information about the log entry.

TYPE  

Represented by the first two digits of the log ID

SUBTYPE  

Represented by the first/second two digits of the log ID

EVENTTYPE  

Represented by the second two digits of the log ID

DEVNAME  

 

DEVID  

Serial number of the device for the traffic's origin

LEVEL  

Security level rating

VD  

Name of the virtual domain in which the log message was recorded

EVENTTIME  

Epoch time the log was triggered by FortiGate

LOGDESC

Log description

SSID

Service Set ID

BSSID

Base Service Set ID

APTYPE

AP Type

RATE

 

RADIOBAND

Radio Band

CHANNEL

Channel

ACTION

Action

MANUF

Manufacturer name

SECURITY

 

ENCRYPTION

Encryption method

SIGNAL

Signal

NOISE

 

LIVE

Time in seconds

AGE

Time in seconds - time passed since last seen

ONWIRE

A flag to indicate if the AP is onwire or not

DETECTIONMETHOD

Detection method

STAMAC

Station/Client MAC address

APSCAN

The name of the AP, which scanned and detected the rogue AP

SNDETECTED

SN of the AP which detected the rogue AP

RADIOIDDETECTED

Radio ID on the AP which detected the rogue AP

STACOUNT

Number of stations/clients

SNCLOSEST

SN of the AP closest to the rogue AP

RADIOIDCLOSEST

Radio ID on the AP closest the rogue AP

APSTATUS

Access Point Status

MSG

Log message

SNAREDATAMAP

All other data in the event will be pushed to this field

Notes

Log Message Reference Documentation: https://docs.fortinet.com/document/fortigate/6.4.2/fortios-log-message-reference

 

Related content