| Description |
This article describes a way to find field filter names for automation triggers. |
| Scope |
FortiGate. |
| Solution |
Automation stitch trigger can be configured with FortiOS Event Log and can be narrowed down with a field filter. To use the field name, the value can be found within the log file downloaded from FortiGate.
The 'field name' value can be found in a log file. Navigate under Log&Report -> System events. An example log entries look like this:
date=2024-09-18 time=09:50:44 eventtime=1726609844353314943 logid="0100022813" type="event" subtype="system" level="notice" vd="root" logdesc="Scanunit reloaded AV Database" action="update" msg="scanunit=manager pid=2673 cause='signal' AV database reload requested 1 times by updated (pid 2675) successful"
For the full reference of values that can be used in 'field name', refer to the 'Log Messages' reference document (ensure to select the applicable FortiOS version): Log Messages
The Field Filter(s) function in the Event Handler does not directly support logical negation operators in FortiGate. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.