Windows Event logs
FortiAnalyzer supports normalizing Windows Event logs as Fabric logs.
|
|
The Windows Event Log Parser will only parse Windows event logs if:
|
The following field mapping applies:
|
Windows Event Log Field |
Normalized Fabric Log Field |
|---|---|
| devid | data_sourceid |
| data_sourcename | data_sourcename |
| data_sourcetype | data_sourcetype |
| data_timestamp | data_timestamp |
| app_cat,channel | app_cat |
| app_name,provider_name | app_name |
| execution_pid | app_proc |
| app_ref | app_ref |
| version | app_ver |
| domain_name | dst_domain |
| dstcountry | dst_geo |
| dstip | dst_ip |
| sys_keywords | event_action |
| event_id | event_id |
| event_log,exch_log,event_json | event_message |
| event_data_return_code,event_outcome | event_outcome |
| event_profile | event_profile |
| event_record_id,event_ref | event_ref |
| event_severity,level | event_severity |
| event_subtype,provider_name | event_subtype |
| event_type,channel | event_type |
| host_ip | host_ip |
| host_name | host_name |
| os_family | host_osfamily |
| host_uid | host_uid |
| mail_from | mail_from |
| mail_subject | mail_subject |
| net_direction | net_direction |
| net_proto | net_proto |
| net_sentbytes | net_sentbytes |
| src_domain | src_domain |
| srccountry | src_geo |
| srcip,src_ip | src_ip |
| user_domain,event_data_subj_domain_name | user_domain |
| user_group | user_group |
| user_id,event_data_subj_user_sid | user_id |
| user_name,event_data_subj_user_name | user_name |