I regularly find Logs similar to these in Firewall logs This does not fall in any of the pre formatted log formats or am i missing something ? 2018-03-31T03:51:04.665490+05:30 10.208.39.10 <00: 0C:29:5E:77:8B>Mojo Wireless Manager v8.2.0-408 : Stop: Rogue Client [android-7cd0c22] is active. : 10.208.39.10://Locations/CDAC_OLD_BLDG/Second Floor : 2018-03-30T22:21:04+00:00 : High : 1263800 : 5 : 66 : 780 : Stop: Rogue Client [android-7cd0c22] is active. The Client's details are: MAC address [F8:A9:63:AE:FA:D6], user name [--], vendor [Compal-Info], RSSI [--] dBm.
2018-03-31T03:51:07.540494+05:30 10.208.39.10 <00: 0C:29:5E:77:8B>Mojo Wireless Manager v8.2.0-408 : Stop: Rogue Client [android-8ea8f5e] is active. : 10.208.39.10://Locations/CDAC_OLD_BLDG/Second Floor : 2018-03-30T22:11:07+00:00 : High : 1263805 : 5 : 66 : 780 : Stop: Rogue Client [android-8ea8f5e] is active. The Client's details are: MAC address [4C:18:9A:CB:44:9F], user name [--], vendor [Unknown], RSSI [--] dBm.
Do you happen to have Mojo APs and configured log output to the same syslog server you're getting from your FGT? These looks like Mojo's WIPS event log.
Yes We have Mojo Wireless AP's but I don't remember configuring WISP in syslogs servers, does it happen by default?
Then, you're asking a wrong group. Ask Mojo support instead. You need to understand how their WIPS feature work in order to understand their event log messages.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.