Technical Tip: CEF log field with wrong format in syslog server
| Description | This article describes the wrong CEF field name for the original log field. Once the FortiGate sends log to the syslog server the format should be changed with suggested field name. |
| Scope | FortiGate, FortiGateVM Azure. |
| Solution | When FortiGate sends logs from FortiOS to any remote or local syslog server the log format changes for CEF and the CEF fields parameters replace them. config log syslogd setting
In some cases the log field does not change to the recommended format as following example:
.. FTNTFGTlevel=notice FTNTFGTvd=root src=10.120.152.189 spt=54320 deviceInboundInterface=port2
Here the CEF log field 'action' changed into 'act' which is a wrong format which is related to FortiOS. The issue is being fixed in FortiOS version 7.4.10, 7.6.5 and 8.0.0. It is requested to open a ticket to the Fortinet TAC if the same or similar issues are observed with the CEF format log field. |
