Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
amoureux
New Contributor

Interpreting bytes telemetry in Log99 of fortiproxy

Hi guys,

I need some assistance in clarifying some of the information I'm seeing in log 99 from my fortiproxy, particularly the rcvdbytes and sentbytes.

Question 1: Does the received bytes refer to the amount of bytes received by the fortiproxy from user or vice versa?

Question 2: Does the sent bytes refer to the amount of bytes sent by user to the dest or vice versa?

Question 3: Does the HTTP method or any other telemetry within the rawlogs that may affect the order of how we see the bytes?

This is crucial because it allows me to understand if there are potential malicious exfiltration happening in my environment.

Thanks!

2 Solutions
dingjerry_FTNT

Keep it in mind: 

 

The log is for the initiator/responder, not for FortiProxy itself.

Regards,

Jerry

View solution in original post

dingjerry_FTNT

Unfortunately, there is no such a doc for it. You may open a technical ticket to ask for a tech doc for it.

Regards,

Jerry

View solution in original post

6 REPLIES 6
dingjerry_FTNT

Hi @amoureux ,

 

Can you explain, or attach a screenshot of what log 99 is?

Regards,

Jerry
amoureux

dingjerry_FTNT

Thank you, @amoureux .

 

1) rcvdbyte is the bytes received for the initiator.

2) sentbyte is the bytes sent by the initiator.

3) I don't think so.

Regards,

Jerry
dingjerry_FTNT

Keep it in mind: 

 

The log is for the initiator/responder, not for FortiProxy itself.

Regards,

Jerry
amoureux

thanks a lot for the information. by any chance, is there a link/documentation to better clarify this? based on the ID99 documentation, i believe it only says received bytes without the relativity. i think the relativity from whether it is for fortiproxy itself or the initiator/responder is quite important esp for security monitoring purposes.  

dingjerry_FTNT

Unfortunately, there is no such a doc for it. You may open a technical ticket to ask for a tech doc for it.

Regards,

Jerry
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors