Skip to main content
sbertini
New Member
February 15, 2016
Question

unauthuser in log

  • February 15, 2016
  • 1 reply
  • 4324 views

Hello all,

we analyze logs from out fortigate 100D and we notice that on every line we have this two param

 

unauthuser="aaaa@bbbb.it" unauthusersource="pop3"

 

aaaa@bbbb.it doesn't exist as user on firewall.

How could be possible that it record on every log line? Where firewall get it?

 

Thanks

    1 reply

    digimetrica
    New Member
    May 11, 2016

    have you found some informations about it?

    I opened a ticket cause im noticing this kind of unauthuser a lot.

    I have no clue cause this traffic is from and to verious IPs and it is not an attack. I called my customer and it was legit. It seems to be logged no matter what