Sample event message for Fortinet FortiMail

Use these sample event messages to verify a successful integration with IBM QRadar.

Events

The following sample event message shows Sample Logs that are collected from Fortinet FortiMail

Sample 1
date=2013-02-25 time=07:01:34 device_id=FE100C3909600504 log_id=0200025843 type=statistics pri=information session_id=\"r1PF1YTh025836-r1PF1YTh025836\" client_name=\"10.0.0.1\" dst_ip=\"10.0.0.2\" endpoint=\"\" from=\"aaa@bbb.com\" to=\"user1@example.com\" polid=\"0:1:0\" domain=\"\" subject=\"\" mailer=\"proxy\" transfer_time=\"\" scan_time=\"\" resolved=\"\" direction=\"unknown\" virus=\"\" disposition=\"0x200\" classifier=\"0x17\" message_length=\"199986\"
Table 1. Highlighted values in the Fortinet FortiMail statistics type sample event.
QRadar field name Highlighted payload field name
Event ID classifier
Source IP client_nane
Destination IP dst_ip
Username from
Severity pri
Device Time Date and time (concate)
Sample 2
date=2012-08-09 time=12:42:48 device_id=FE100C3909600504 log_id=0000000920 type=kevent subtype=config pri=information user=admin ui=10.0.0.26 module=unknown submodule=unknown msg=\"user testUser login successfully from CLI\"
Table 2. Highlighted values in the Fortinet FortiMail kevent type sample event.
QRadar field name Highlighted payload field name
Event ID msg
Source IP ui
Username user
Severity pri
Device Time Date and tmie (concate)
Sample 3
date=2024-04-20 time=14:33:26 device_id=FEccc504 log_id=0000 type=spam pri=information session_id=\"q6Kxxx8097-q6Kccccc97\" client_name=\"[10.0.0.1]\" dst_ip=\"10.0.0.2\" from=\"syntax@www.ca\" to=\"user1@1.ca\" subject=\"Email test\" msg=\"Detected by BannedWord test\"
Table 3. Highlighted values in the Fortinet FortiMail spam type sample event.
QRadar field name Highlighted payload field name
Event ID type
Source IP client_name
Destination IP dst_ip
Username from
Severity pri
Device Time Date and time (concate)
Sample 4
date=2024-04-24 time=17:07:42 device_id=FE1055500504 log_id=100000924 type=virus subtype=infected pri=information from=\"syntax@www.ca\" to=\"user2@1.ca\" src=10.0.01 session_id=\"q6OL7fsQ018870-q6OL7fsR018870\" msg=\"The file inline-16-69.dat is infected with EICAR_TEST_FILE.\"
Table 4. Highlighted values in the Fortinet FortiMail virus type sample event.
QRadar field name Highlighted payload field name
Event ID type/subtype
Source IP src
Username from
Severity pri
Device Time Date and time (concate)
Sample 5
date=2012-08-09 time=10:45:27 device_id=FE100C3909600504 log_id=0400005355 type=encrypt pri=information session_id=\"q7aa7017-q7aaa74\" msg=\"User user1@1.ca read secure message, id:'q7117017-q7911101474', sent from: 'user2@2.ca', subject: 'ppt file'\"
Table 5. Highlighted values in the Fortinet FortiMail encrypt type sample event.
QRadar field name Highlighted payload field name
Event ID msg
Username from
Severity pri
Device Time Date and time (concate)
Sample 6
date=2024-05-24 time=17:22:17 device_id=FE10333504 log_id=103032255 type=event subtype=webmail pri=information from=\"syntax@www.ca\" to=\"user2@1.ca\" src=10.0.0.1 session_id=\"333-3333\" msg=\"User testUser from 10.0.0.1 logged in
Table 6. Highlighted values in the Fortinet FortiMail encrypt type sample event.
QRadar field name Highlighted payload field name
Event ID msg
Source IP src
Username from
Severity pri
Device Time Date and time (concate)