Description | This article DESCRIBES the behavior of FortiGate adding prefix 'FTNTFGT' while sending logs to the syslog server in 'cef' format. This behavior is observed specifically in the Azure platform of FortiGate-VM. |
Scope | FortiGate-VM Azure. |
Solution |
FortiGate can send logs to the syslog server with the 'cef' format, and the configuration can be simply done from CLI 'config log syslog setting' shared in the article Technical Note: FortiGate Logs can be sent to syslog servers in Common Event Format
Aug 26 10:04:07 adminlab CEF: 0|Fortinet|Fortigate|v7.4.8|00013|traffic:forward close|3|deviceExternalId=FGVM4VTMxxxxxx FTNTFGTeventtime=1756191456786479808 FTNTFGTtz=+0300 FTNTFGTlogid=0000000013 cat=traffic:forward FTNTFGTsubtype=forward FTNTFGTlevel=notice FTNTFGTvd=root src=10.230.152.196 spt=55680 deviceInboundInterface=port2 FTNTFGTsrcintfrole=undefined dst=60.115.98.89 dpt=443 deviceOutboundInterface=port1 FTNTFGTdstintfrole=undefined FTNTFGTsrccountry=Reserved FTNTFGTdstinetsvc=Microsoft-Azure FTNTFGTdstcountry=Slovakia FTNTFGTdstregion=EAST FTNTFGTdstreputation=4 externalId=16749651 proto=6 act=close FTNTFGTpolicyid=54 FTNTFGTpolicytype=policy FTNTFGTpoluuid=9c12de76-6945-51f0-7854-44fa94fd9ebb FTNTFGTpolicyname=TestPolicy app=Microsoft-Azure FTNTFGTtrandisp=snat sourceTranslatedAddress=10.10.80.56 sourceTranslatedPort=58120 FTNTFGTappid=34654 FTNTFGTapp=Microsoft.Azure FTNTFGTappcat=Cloud.IT FTNTFGTapprisk=medium FTNTFGTapplist=block-high-risk FTNTFGTduration=1 FTNTFGTsentpkt=10 FTNTFGTrcvdpkt=10 FTNTFGTutmaction=allow FTNTFGTcountapp=1
In some units, the prefix can also be observed as 'FortinetFortiGate' instead of 'FTNTFGT', and these prefixes are hardcoded, which cannot be changed through CLI. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.