Fortinet white logo
Fortinet white logo

FortiEDR syslog messages

FortiEDR syslog messages

The following table shows the standard format that is used for each syslog type described in this document.

Syslog Field

LEEF Field

CEF Field1

CEF custom label value

Description

Data Type

Length

Organization

Organization

cs1

cs1Label=Organization

Name of the organization the system event belongs to.

String

100

Event ID

EventId

eventid

Security event ID automatically generated by the FortiEDR Manager.

Integer

10

Custom fields in CEF format (such as cs1) should be sent with the matching CEF custom label value in order to define the display label for this custom field to the consumer system. The message then includes the following two fields:

  1. CEF custom label value
  2. CEF field name (such as cs1) that holds the actual value of the field

For example, for Organization “Marketing”, FortiEDR sends the following two CEF fields in the message: "cs1Label=Organization” and “cs1=Marketing”.

The following sections list the FortiEDR 7.0 syslog messages.

FortiEDR syslog messages

FortiEDR syslog messages

The following table shows the standard format that is used for each syslog type described in this document.

Syslog Field

LEEF Field

CEF Field1

CEF custom label value

Description

Data Type

Length

Organization

Organization

cs1

cs1Label=Organization

Name of the organization the system event belongs to.

String

100

Event ID

EventId

eventid

Security event ID automatically generated by the FortiEDR Manager.

Integer

10

Custom fields in CEF format (such as cs1) should be sent with the matching CEF custom label value in order to define the display label for this custom field to the consumer system. The message then includes the following two fields:

  1. CEF custom label value
  2. CEF field name (such as cs1) that holds the actual value of the field

For example, for Organization “Marketing”, FortiEDR sends the following two CEF fields in the message: "cs1Label=Organization” and “cs1=Marketing”.

The following sections list the FortiEDR 7.0 syslog messages.