Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 726 Bytes

b722f175-2dd7-4509-b97f-63de578cbb59.md

File metadata and controls

35 lines (28 loc) · 726 Bytes

Mappings: Fortinet Appctrl2

Input Requirements

Input Value
Vendor fortinet
Product fortinet
Log Format JSON
Event ID Regex Pattern app-ctrl

Record Output

Output Value
Vendor Fortinet
Product Fortigate
Record Type NetworkHTTP

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
device_ip srcip
dstDevice_ip dstip
dstPort dstport
http_hostname hostname
ipProtocol proto
severity apprisk
srcDevice_ip srcip
srcPort srcport
timestamp eventtime We expect the orginal record value of eventtime is in the format epoch
user_username user