Hello,
From FortiWEB 5.4 to 5.8 the CEF logs has been changed.
The FortiWEB is sending the destination hostname with " in the field, this is not supposed to be done that way because then arcsight doesnt eliminate the " from the hostname.
Another issue it the fact that destination hostname sometime is a IP when there's already an IP in the destination address field.
The CEF field "request" is supposed to contain the protocol, hostname/IP, port and path but now there's only the path in it.
FortiWEB in the version 5.4 was way better than 5.8, is there a way to get the reasons why the logs are gettings such bad quality now ?
Thanks
Sad User
Have you open a case with FTNT-support ? They could address the issues, and I'm assuming the format was different before the upgrade?
PCNSE
NSE
StrongSwan
I should ask my customer to open a ticket, he's doing it already , lets see the answer.
I was open to see someone from fortinet replying because this is impacted many more customer.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.