- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Interpreting bytes telemetry in Log99 of fortiproxy
Hi guys,
I need some assistance in clarifying some of the information I'm seeing in log 99 from my fortiproxy, particularly the rcvdbytes and sentbytes.
Question 1: Does the received bytes refer to the amount of bytes received by the fortiproxy from user or vice versa?
Question 2: Does the sent bytes refer to the amount of bytes sent by user to the dest or vice versa?
Question 3: Does the HTTP method or any other telemetry within the rawlogs that may affect the order of how we see the bytes?
This is crucial because it allows me to understand if there are potential malicious exfiltration happening in my environment.
Thanks!
Solved! Go to Solution.
- Labels:
-
FortiProxy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, @amoureux .
1) rcvdbyte is the bytes received for the initiator.
2) sentbyte is the bytes sent by the initiator.
3) I don't think so.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Keep it in mind:
The log is for the initiator/responder, not for FortiProxy itself.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately, there is no such a doc for it. You may open a technical ticket to ask for a tech doc for it.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thanks for the reply.
I'm referring to this - 99 - LOG_ID_TRAFFIC_HTTP_TRANSACTION | FortiProxy 7.6.0 | Fortinet Document Library
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, @amoureux .
1) rcvdbyte is the bytes received for the initiator.
2) sentbyte is the bytes sent by the initiator.
3) I don't think so.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Keep it in mind:
The log is for the initiator/responder, not for FortiProxy itself.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks a lot for the information. by any chance, is there a link/documentation to better clarify this? based on the ID99 documentation, i believe it only says received bytes without the relativity. i think the relativity from whether it is for fortiproxy itself or the initiator/responder is quite important esp for security monitoring purposes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately, there is no such a doc for it. You may open a technical ticket to ask for a tech doc for it.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can I ask how do I raise a technical ticket for this? Thanks in advance.
Created on ‎03-19-2025 09:10 PM Edited on ‎03-19-2025 09:10 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @amoureux ,
1) You need to register an account on https://support.fortinet.com/
2) You need to register this device in this account;
3) You need to apply a valid support contract to the device.
Then please follow the instructions in this doc to create a ticket:
Jerry
