I work on my Diploma, I am creating solution for analyze "raw" logs. In the present step I need to do identification login/logout/failed_login for this I need list of all records that can be in "msg" or "action" field, or any other marks of this actions in VPN session. Anybody can help me?
ID: 39424
name: LOG_ID_EVENT_SSL_VPN_USER_TUNNEL_UP
action: tunnel-up
msg: SSL tunnel established
event: SSL VPN tunnel up
------------------------------------------------
ID 39947
Name LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_UP
action: tunnel-up
msg: SSL tunnel established
event: SSL VPN tunnel up
------------------------------------------------
ID: 39426
name: LOG_ID_EVENT_SSL_VPN_USER_SSL_LOGIN_FAIL
action: ssl-login-fail
msg: SSL user failed to logged in
event: SSL VPN login fail
------------------------------------------------
ID: 39943
name: LOG_ID_EVENT_SSL_VPN_SESSION_NEW_CON
action: ssl-new-con
msg: SSL new connection
event: SSL VPN new connection
------------------------------------------------
ID 39948
name: LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_DOWN
action: tunnel-down
SSL tunnel shutdown
event: SSL VPN tunnel down
------------------------------------------------
ID 39425
name: LOG_ID_EVENT_SSL_VPN_USER_TUNNEL_DOWN
action: tunnel-down
SSL tunnel shutdown
event: SSL VPN tunnel down
For full information:
https://docs.fortinet.com/document/fortigate/7.4.3/fortios-log-message-reference/39947/39947-log-id-...
Good luck for you diploma!
User | Count |
---|---|
1906 | |
1141 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.