Mappings: Fortinet Appctrl2
Input | Value |
---|---|
Vendor | fortinet |
Product | fortinet |
Log Format | JSON |
Event ID Regex Pattern | app-ctrl |
Output | Value |
---|---|
Vendor | Fortinet |
Product | Fortigate |
Record Type | NetworkHTTP |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
device_ip | srcip | |
dstDevice_ip | dstip | |
dstPort | dstport | |
http_hostname | hostname | |
ipProtocol | proto | |
severity | apprisk | |
srcDevice_ip | srcip | |
srcPort | srcport | |
timestamp | eventtime | We expect the orginal record value of eventtime is in the format epoch |
user_username | user |