Skip to main content
epernot
New Member
April 9, 2018
Question

Malformated CEF

  • April 9, 2018
  • 2 replies
  • 3160 views

Hello, 

 

From FortiWEB 5.4 to 5.8  the CEF  logs has been changed. 

The FortiWEB is sending the destination hostname with  " in the field, this is not supposed to be done that way because then arcsight doesnt eliminate the " from the hostname.  

 

Another issue it the fact that destination hostname sometime is a IP when there's already an IP in the destination address field.  

 

The CEF field "request" is supposed to contain the protocol, hostname/IP, port and path but now there's only the path in it. 

 

FortiWEB in the version 5.4 was way better than 5.8, is there a way to get the reasons why the logs are gettings such bad quality now ?  

 

 

Thanks 

Sad User

    2 replies

    emnoc
    New Member
    April 9, 2018

    Have you open a case with FTNT-support ? They could address the issues, and I'm assuming the format was different before the upgrade?

    epernot
    epernotAuthor
    New Member
    April 9, 2018

    I should ask my customer to open a ticket, he's doing it already , lets see the answer.

    I was open to see someone from fortinet replying because this is impacted many more customer. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.