Sample event message for Fortinet FortiWeb Firewall

Use these sample event messages to verify a successful integration with IBM QRadar.

Events

The following sample event message shows Sample Logs that are collected from Fortinet FortiWeb Firewall

Sample 1
<190>date=2025-07-05 time=21:36:50 log_id=10000016 msg_id=000000001638 device_id=FAAB00UNLICENSED eventtime=1751780210917712789 vd="root" timezone="(GMT-8:00)Pacific Time(US&Canada)" timezone_dayst="GMT+8" type=event subtype="system" pri=information trigger_policy="N/A" user=admin ui=GUI action=login status=success msg="User admin logged in successfully from GUI->HTTPS(10.0.20.0)"
Table 1. Highlighted values in the Fortinet FortiWeb event type sample event.
QRadar field name Highlighted payload field name
Event ID log_id
Source IP parsed from msg part if IP is present (10.0.20.0)
Username user
Severity pri
Device Time eventtime
Sample 2
<190>date=2022-07-09 time=06:59:42 log_id=20000002 msg_id=000034349837 device_id=FV3K1E3216000005 vd="root" timezone="(GMT-8:00)Pacific Time(US&Canada)" timezone_dayst="GMTa+7" type=attack pri=alert main_type="Protected Hostnames" sub_type="N/A" trigger_policy="N/A" severity_level=Low proto=tcp service=http backend_service=unknown action=Alert_Deny policy="FWB_Policy_Default_AutoTest" src=10.0.0.1 src_port=56756 dst=10.0.0.2 dst_port=80 http_method=get http_url="/autotest/dwg/test.html" http_host="fortinet.fortiweb.example.com" http_agent="python-for-fortiweb" http_session_id=none msg="HTTP Host Violation" signature_subclass="N/A" signature_id="N/A" signature_cve_id="N/A" srccountry="Reserved" content_switch_name="none" server_pool_name="FortiWeb_server_test_pool" false_positive_mitigation="none" user_name=”testuser" monitor_status="Disabled" http_refer="none" http_version="1.x" dev_id="none" es=0 threat_weight=100 history_threat_weight=0 threat_level=Severe ftp_mode="N/A" ftp_cmd="N/A" cipher_suite="none" ml_log_hmm_probability=0.000000 ml_log_sample_prob_mean=0.000000 ml_log_sample_arglen_mean=0.000000 ml_log_arglen=0 ml_svm_log_main_types=0 ml_svm_log_match_types="none" ml_svm_accuracy="none" ml_domain_index=0 ml_url_dbid=0 ml_arg_dbid=0 ml_allow_method="none" owasp_top10="A05:2021-Security Misconfiguration" bot_info="none" client_level="Unidentified" x509_cert_subject="none"
Table 2. Highlighted values in the Fortinet FortiWeb attack type sample event.
QRadar field name Highlighted payload field name
Event ID log_id
Source IP src
Source Port src port
Destination IP dst
Destination Port dst_port
Username user_name
Severity severity_level
Device Time date + time
Sample 3
<190>date=2023-08-13 time=17:53:05 log_id=30002000 msg_id=000000761559 device_id=FAAB02TM22001887 eventtime=1691920385711464343 vd="root" timezone="(GMT+8:00)Taipei" timezone_dayst="GMTe-8" type=traffic subtype="ftp" pri=notice proto=tcp service=ftps status=success reason=none policy="ftp" original_src=10.0.4.1 src=10.0.4.1 src_port=37708 dst=10.0.4.2 dst_port=21 http_request_time=0 http_response_time=0 http_request_bytes=0 http_response_bytes=143 http_method=OTHERS http_url="none" http_agent="none" http_retcode=220 msg="FTPS OTHERS from 10.0.12.0:37708 to 10.0.10.0:21" original_srccountry="Sweden" srccountry="Sweden" content_switch_name="none" server_pool_name="ftp-10.0.0.18" http_host="none" user_name="testuser" http_refer="none" http_version="Unknown" dev_id=none cipher_suite="none" x509_cert_subject="none"
Table 3. Highlighted values in the Fortinet FortiWeb traffic type sample event.
QRadar field name Highlighted payload field name
Event ID log_id
Source IP src
Source Port src port
Destination IP dst
Destination Port dst_port
Username user_name
Severity pri
Device Time eventtime