Fortinet white logo
Fortinet white logo

Windows Event logs

Windows Event logs

FortiAnalyzer supports normalizing Windows Event logs as Fabric logs.

Note

The Windows Event Log Parser will only parse Windows event logs if:

  • the logs are sent from FortiClient to FortiAnalyzer, or

  • the syslog logs are sent from the Windows endpoint directly to FortiAnalyzer in JSON format.

The following field mapping applies:

Windows Event Log Field

Normalized Fabric Log Field

devid data_sourceid
data_sourcename data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
app_cat,channel app_cat
app_name,provider_name app_name
execution_pid app_proc
app_ref app_ref
version app_ver
domain_name dst_domain
dstcountry dst_geo
dstip dst_ip
sys_keywords event_action
event_id event_id
event_log,exch_log,event_json event_message
event_data_return_code,event_outcome event_outcome
event_profile event_profile
event_record_id,event_ref event_ref
event_severity,level event_severity
event_subtype,provider_name event_subtype
event_type,channel event_type
host_ip host_ip
host_name host_name
os_family host_osfamily
host_uid host_uid
mail_from mail_from
mail_subject mail_subject
net_direction net_direction
net_proto net_proto
net_sentbytes net_sentbytes
src_domain src_domain
srccountry src_geo
srcip,src_ip src_ip
user_domain,event_data_subj_domain_name user_domain
user_group user_group
user_id,event_data_subj_user_sid user_id
user_name,event_data_subj_user_name user_name

Windows Event logs

Windows Event logs

FortiAnalyzer supports normalizing Windows Event logs as Fabric logs.

Note

The Windows Event Log Parser will only parse Windows event logs if:

  • the logs are sent from FortiClient to FortiAnalyzer, or

  • the syslog logs are sent from the Windows endpoint directly to FortiAnalyzer in JSON format.

The following field mapping applies:

Windows Event Log Field

Normalized Fabric Log Field

devid data_sourceid
data_sourcename data_sourcename
data_sourcetype data_sourcetype
data_timestamp data_timestamp
app_cat,channel app_cat
app_name,provider_name app_name
execution_pid app_proc
app_ref app_ref
version app_ver
domain_name dst_domain
dstcountry dst_geo
dstip dst_ip
sys_keywords event_action
event_id event_id
event_log,exch_log,event_json event_message
event_data_return_code,event_outcome event_outcome
event_profile event_profile
event_record_id,event_ref event_ref
event_severity,level event_severity
event_subtype,provider_name event_subtype
event_type,channel event_type
host_ip host_ip
host_name host_name
os_family host_osfamily
host_uid host_uid
mail_from mail_from
mail_subject mail_subject
net_direction net_direction
net_proto net_proto
net_sentbytes net_sentbytes
src_domain src_domain
srccountry src_geo
srcip,src_ip src_ip
user_domain,event_data_subj_domain_name user_domain
user_group user_group
user_id,event_data_subj_user_sid user_id
user_name,event_data_subj_user_name user_name