e. Wireless
Sample Event
date=2019-05-13 time=11:30:08 logid="0104043568" type="event" subtype="wireless" level="warning" vd="vdom1" eventtime=1557772208134721423 logdesc="Fake AP on air" ssid="fortinet" bssid="90:6c:ac:89:e1:fa" aptype=0 rate=130 radioband="802.11n" channel=6 action="fake-ap-on-air" manuf="Fortinet, Inc." security="WPA2 Personal" encryption="AES" signal=-93 noise=-95 live=353938 age=505 onwire="no" detectionmethod="N/A" stamac="N/A" apscan="N/A" sndetected="N/A" radioiddetected=0 stacount=0 snclosest="FP320C3X17001909" radioidclosest=0 apstatus=0 msg="Fake AP On-air fortinet 90:6c:ac:89:e1:fa chan 6 live 353938 age 505"
Fields
Field | Description |
---|---|
DATE | Event date, in the format YYYY-MM-DD |
TIME | Event time, in the format HH:MM:SS |
SYSTEM | The source system |
TABLE | FortiGateEventWireless |
CRITICALITY |
|
LOGID | Unique 10-digit identifier (log type, subtype/event type and message ID) for that specific log and includes information about the log entry. |
TYPE | Represented by the first two digits of the log ID |
SUBTYPE | Represented by the first/second two digits of the log ID |
EVENTTYPE | Represented by the second two digits of the log ID |
DEVNAME |
|
DEVID | Serial number of the device for the traffic's origin |
LEVEL | Security level rating |
VD | Name of the virtual domain in which the log message was recorded |
EVENTTIME | Epoch time the log was triggered by FortiGate |
LOGDESC | Log description |
SSID | Service Set ID |
BSSID | Base Service Set ID |
APTYPE | AP Type |
RATE |
|
RADIOBAND | Radio Band |
CHANNEL | Channel |
ACTION | Action |
MANUF | Manufacturer name |
SECURITY |
|
ENCRYPTION | Encryption method |
SIGNAL | Signal |
NOISE |
|
LIVE | Time in seconds |
AGE | Time in seconds - time passed since last seen |
ONWIRE | A flag to indicate if the AP is onwire or not |
DETECTIONMETHOD | Detection method |
STAMAC | Station/Client MAC address |
APSCAN | The name of the AP, which scanned and detected the rogue AP |
SNDETECTED | SN of the AP which detected the rogue AP |
RADIOIDDETECTED | Radio ID on the AP which detected the rogue AP |
STACOUNT | Number of stations/clients |
SNCLOSEST | SN of the AP closest to the rogue AP |
RADIOIDCLOSEST | Radio ID on the AP closest the rogue AP |
APSTATUS | Access Point Status |
MSG | Log message |
SNAREDATAMAP | All other data in the event will be pushed to this field |
Notes
Log Message Reference Documentation: https://docs.fortinet.com/document/fortigate/6.4.2/fortios-log-message-reference