FortiEDR syslog messages
The following table shows the standard format that is used for each syslog type described in this document.
|
Syslog Field |
LEEF Field |
CEF Field1 |
CEF custom label value |
Description |
Data Type |
Length |
|---|---|---|---|---|---|---|
|
Organization |
Organization |
cs1 |
cs1Label=Organization |
Name of the organization the system event belongs to. |
String |
100 |
| Event ID |
EventId |
eventid |
— |
Security event ID automatically generated by the FortiEDR Manager. |
Integer |
10 |
|
Custom fields in CEF format (such as cs1) should be sent with the matching CEF custom label value in order to define the display label for this custom field to the consumer system. The message then includes the following two fields:
For example, for Organization “Marketing”, FortiEDR sends the following two CEF fields in the message: "cs1Label=Organization” and “cs1=Marketing”. |
||||||
The following sections list the FortiEDR 7.0 syslog messages.