FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
duenlim
Staff
Staff
Article Id 212853
Description

This article describes that in the FortiOS Log Message Reference 6.4.9 or 6.2.x, the 'sn' is 'Serial Number':

https://docs.fortinet.com/document/fortigate/6.4.9/fortios-log-message-reference/32001/32001-log-id-...
https://docs.fortinet.com/document/fortigate/6.2.10/fortios-log-message-reference/32001/32001-log-id...

Scope

But the actual log shows 'sn' field does not display the 'Serial Number'.

 

Admin login successful log:


date=2022-05-11 time=17:24:28 eventtime=1652261068911558863 tz="+0800" logid="0100032001" type="event" subtype="system" level="information" vd="root" logdesc="Admin login successful" sn="1652261068" user="admin" ui="https(10.176.2.173)" method="https" srcip=10.176.2.173 dstip=10.176.2.171 action="login" status="success" reason="none" profile="super_admin" msg="Administrator admin logged in successfully from https(10.176.2.173)"

Solution

The 'sn' in login/logout log means that the login/logout event serial number in Admin login/logout log, is not the actual serial number. 

 

It is confirmed that there is no serial number in login/logout log.

The 'sn' field for login/out event it is used to correlate login/logout events.

Contributors