Fortinet black logo

Appendix A - Log Field Diff - 7.2.2 and 7.4.0

Appendix A - Log Field Diff - 7.2.2 and 7.4.0

Refer to the FortiManager & Analyzer Event Log Reference Guide for a complete list of log field details related to version 7.4. This section covers changes applicable to the 7.4.0 version only. It is recommended you keep both the 7.2.2 and 7.4.0 FortiManager & FortiAnalyzer Event Log Reference Guides available for a comparison of log field delta between the versions.

For all reference purposes, in the tables provided below (see tables), the term Removed indicates a log field was removed in version 7.4.0 but exists in version 7.2.2. Similarly, the term Added indicates a log field was added in version 7.4.0 but does not exist in version 7.2.2.

Event

The following tables provide a list of log fields that were added or removed from the Event log subtypes in FortiManager and FortiAnalyzer version 7.4.0.

AID Log Messages

Message ID

Message

Change

49003

LOG_ID_config

Message ID removed

49004

LOG_ID_ui

Message ID removed

DVM Log Messages

Message ID

Message

Change

31013

LOG_ID_workflow_db_reset

Message ID added

FAZSYS Log Messages

Message ID

Message

Change

37039

LOG_ID_fluentd_fail

Message ID added

37040

LOG_ID_fluentd_info

Message ID added

INCIDENT Log Messages

Message ID

Message

Change

50002

LOG_ID_attachment_deleted

Message ID removed

LOGGING Log Messages

Message ID

Message

Change

39013

LOG_ID_dup_logs_detect

Message ID added

SYSTEM

Field

Change

disk2usage Field added

diskusage

Field added

max_adoms

Field added

SYSTEM Log Messages

Message ID

Message

Change

10090

LOG_ID_ssh_server_regen_hostkeys

Message ID added

10091

LOG_ID_license_warn

Message ID added

10092

LOG_ID_license_expired

Message ID added

10093

LOG_ID_adom_perf_stats_notify

Message ID added

10094

LOG_ID_benchmark_io_perf

Message ID added

APPEVENT

The following tables provide a list of log fields that were added or removed from the Application log subtypes in FortiManager and FortiAnalyzer version 7.4.0.

DISKQUOTA

Field

Change

diskusage Field added

DISKQUOTA Log Messages

Message ID

Message

Change

220003

Quota_Usage_Warn

Message ID added

SYSTEM

Field

Change

changes Field added

lograte

Field added

logratelimit

Field added

operation

Field added

performed_on

Field added

SYSTEM Log Messages

Message ID

Message

Change

220004

Perf_Stats_Notify

Message ID added

Appendix A - Log Field Diff - 7.2.2 and 7.4.0

Refer to the FortiManager & Analyzer Event Log Reference Guide for a complete list of log field details related to version 7.4. This section covers changes applicable to the 7.4.0 version only. It is recommended you keep both the 7.2.2 and 7.4.0 FortiManager & FortiAnalyzer Event Log Reference Guides available for a comparison of log field delta between the versions.

For all reference purposes, in the tables provided below (see tables), the term Removed indicates a log field was removed in version 7.4.0 but exists in version 7.2.2. Similarly, the term Added indicates a log field was added in version 7.4.0 but does not exist in version 7.2.2.

Event

The following tables provide a list of log fields that were added or removed from the Event log subtypes in FortiManager and FortiAnalyzer version 7.4.0.

AID Log Messages

Message ID

Message

Change

49003

LOG_ID_config

Message ID removed

49004

LOG_ID_ui

Message ID removed

DVM Log Messages

Message ID

Message

Change

31013

LOG_ID_workflow_db_reset

Message ID added

FAZSYS Log Messages

Message ID

Message

Change

37039

LOG_ID_fluentd_fail

Message ID added

37040

LOG_ID_fluentd_info

Message ID added

INCIDENT Log Messages

Message ID

Message

Change

50002

LOG_ID_attachment_deleted

Message ID removed

LOGGING Log Messages

Message ID

Message

Change

39013

LOG_ID_dup_logs_detect

Message ID added

SYSTEM

Field

Change

disk2usage Field added

diskusage

Field added

max_adoms

Field added

SYSTEM Log Messages

Message ID

Message

Change

10090

LOG_ID_ssh_server_regen_hostkeys

Message ID added

10091

LOG_ID_license_warn

Message ID added

10092

LOG_ID_license_expired

Message ID added

10093

LOG_ID_adom_perf_stats_notify

Message ID added

10094

LOG_ID_benchmark_io_perf

Message ID added

APPEVENT

The following tables provide a list of log fields that were added or removed from the Application log subtypes in FortiManager and FortiAnalyzer version 7.4.0.

DISKQUOTA

Field

Change

diskusage Field added

DISKQUOTA Log Messages

Message ID

Message

Change

220003

Quota_Usage_Warn

Message ID added

SYSTEM

Field

Change

changes Field added

lograte

Field added

logratelimit

Field added

operation

Field added

performed_on

Field added

SYSTEM Log Messages

Message ID

Message

Change

220004

Perf_Stats_Notify

Message ID added