Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ezavala
New Contributor

waf Signatures - eventid information??

Hello, I want to understand some logs of WAF and I don't find any information about it the ID of LOG

 

Example: a WAF log with id 50140004 Generix Attacks

 

LOG

type=utm subtype=waf level=warning vd=root eventtype=waf-signature  service=HTTP action=blocked profile="Web Application Firewall" severity=high eventid=50140004 msg="Generic Attacks" agent=Firefox/5.0 direction=request

4 REPLIES 4
packetpusher
Contributor

I am curious as well.

TKucera

hmtay_FTNT
Staff
Staff

http://help.fortinet.com/fweb/570/Content/FortiWeb/fortiweb-admin/web_protection.htm

 

Here's an explanation of all the possible values.

 

Homing

dgipaul

CLI:

fortihost # config global
fortihost (global) # diagnose waf dump | grep 90300017
90300017 - This signature prevents attackers from obtaining file and folder names using a tilde character "~" in a get request .
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors