Unusual field usage in syslog records.
We use a Fortigate 200D with Firmwarw v.5.4.3,build1111(GA)
In "Log & Report", "Log Settings", "Remote Logging and Archiving"
"Send Logs to Syslog" is set on.
IP Address/FQDN: (is filled with the IP-address of a Graylog server.)
"Local Traffic Log" is set off.
"Event Logging" is set on
All event are set on.
The Graylog server receives the syslog records from the Fortigate.
But the format of the syslog records is unusual.
In the syslog record field "source" we expect the hostname of the Fortigate but the content is "date=2019-04-11".
Is this caused by a wrong setting?
Can we change this?
Or is this a bug?