Use these sample event messages to verify a successful integration with IBM
QRadar.
Events
The following sample event message shows Sample Logs that are collected from Fortinet
FortiMail
Sample
1date=2013-02-25 time=07:01:34 device_id=FE100C3909600504 log_id=0200025843 type=statistics pri=information session_id=\"r1PF1YTh025836-r1PF1YTh025836\" client_name=\"10.0.0.1\" dst_ip=\"10.0.0.2\" endpoint=\"\" from=\"aaa@bbb.com\" to=\"user1@example.com\" polid=\"0:1:0\" domain=\"\" subject=\"\" mailer=\"proxy\" transfer_time=\"\" scan_time=\"\" resolved=\"\" direction=\"unknown\" virus=\"\" disposition=\"0x200\" classifier=\"0x17\" message_length=\"199986\"
Table 1. Highlighted values in the Fortinet FortiMail
statistics type sample event.
| QRadar field
name |
Highlighted payload field name |
| Event ID |
classifier |
| Source IP |
client_nane |
| Destination IP |
dst_ip |
| Username |
from |
| Severity |
pri |
| Device Time |
Date and time (concate) |
Sample
2date=2012-08-09 time=12:42:48 device_id=FE100C3909600504 log_id=0000000920 type=kevent subtype=config pri=information user=admin ui=10.0.0.26 module=unknown submodule=unknown msg=\"user testUser login successfully from CLI\"
Table 2. Highlighted values in the Fortinet FortiMail
kevent type sample event.
| QRadar field
name |
Highlighted payload field name |
| Event ID |
msg |
| Source IP |
ui |
| Username |
user |
| Severity |
pri |
| Device Time |
Date and tmie (concate) |
Sample
3date=2024-04-20 time=14:33:26 device_id=FEccc504 log_id=0000 type=spam pri=information session_id=\"q6Kxxx8097-q6Kccccc97\" client_name=\"[10.0.0.1]\" dst_ip=\"10.0.0.2\" from=\"syntax@www.ca\" to=\"user1@1.ca\" subject=\"Email test\" msg=\"Detected by BannedWord test\"
Table 3. Highlighted values in the Fortinet FortiMail
spam type sample event.
| QRadar field
name |
Highlighted payload field name |
| Event ID |
type |
| Source IP |
client_name |
| Destination IP |
dst_ip |
| Username |
from |
| Severity |
pri |
| Device Time |
Date and time (concate) |
Sample
4date=2024-04-24 time=17:07:42 device_id=FE1055500504 log_id=100000924 type=virus subtype=infected pri=information from=\"syntax@www.ca\" to=\"user2@1.ca\" src=10.0.01 session_id=\"q6OL7fsQ018870-q6OL7fsR018870\" msg=\"The file inline-16-69.dat is infected with EICAR_TEST_FILE.\"
Table 4. Highlighted values in the Fortinet FortiMail
virus type sample event.
| QRadar field
name |
Highlighted payload field name |
| Event ID |
type/subtype |
| Source IP |
src |
| Username |
from |
| Severity |
pri |
| Device Time |
Date and time (concate) |
Sample
5date=2012-08-09 time=10:45:27 device_id=FE100C3909600504 log_id=0400005355 type=encrypt pri=information session_id=\"q7aa7017-q7aaa74\" msg=\"User user1@1.ca read secure message, id:'q7117017-q7911101474', sent from: 'user2@2.ca', subject: 'ppt file'\"
Table 5. Highlighted values in the Fortinet FortiMail
encrypt type sample event.
| QRadar field
name |
Highlighted payload field name |
| Event ID |
msg |
| Username |
from |
| Severity |
pri |
| Device Time |
Date and time (concate) |
Sample
6date=2024-05-24 time=17:22:17 device_id=FE10333504 log_id=103032255 type=event subtype=webmail pri=information from=\"syntax@www.ca\" to=\"user2@1.ca\" src=10.0.0.1 session_id=\"333-3333\" msg=\"User testUser from 10.0.0.1 logged in
Table 6. Highlighted values in the Fortinet FortiMail
encrypt type sample event.
| QRadar field
name |
Highlighted payload field name |
| Event ID |
msg |
| Source IP |
src |
| Username |
from |
| Severity |
pri |
| Device Time |
Date and time (concate) |