Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

FortiGate

Standard

FortiGate enables you to collect and normalize FortiGate logs and analyze the information through dashboards and security reports. FortiGate dashboards provide visualization related to threats, web attacks, and malicious activities. The FortiGate compiled normalizers are compatible with CNDP.

Additionally, when Logpoint identifies malicious events with a potential risk to your environment, it triggers security alerts based on predetermined rules.

Release Details

Version: 5.4.2
Release date: July 31, 2025
Supported On: Logpoint v7.4.0 or later
SHA 256: a5b826ecbd806850f123a272cdd1c131e94d854b7e982e5be3e361218d71bc97
FortiGate guide
Download

Enhancement

PLUG-1564587053
A new Login label is added to ensure consistent display of login events in normalized logs.

Bug Fix

PLUG-1663290922
When using FortiCEFCompiledNormalizer, the message_id was not visible, preventing alerts from being triggered.

Past Releases

FortiGate v5.4.0 ▾
Version: 5.4.0
Release date: May 15, 2025
Supported On: Logpoint v7.4.0
SHA 256: 065813c0060bcb7c693c2ffedc9cb83339f0ef45b06026f1a8c8cde7e40d5919
Download

Enhancement

PLUG-1564587053
A new Login label is added to ensure consistent display of login events in normalized logs.

Bug Fixes

PLUG-1568385792
FortiOS Compiled Normalizer misinterpreted key-value pairs as separate fields in logs, causing normalized fields to display incorrectly.
KB-2297078477
The FortiGate Compiled Normalizer displayed a Jinja error for fields containing a period (.), such as "ad.attack", which prevented successful network configuration.
KB-2476182210
In some cases, the Normalization ID (norm_id) was missing in FortiGate logs. This resulted in incorrect normalization of logs.
FortiGate v5.3.0 ▾
Version: 5.3.0
Release date: May 07, 2024
Supported On: Logpoint v6.7.0 or later
SHA 256: 7fc6e7a22ffec12130846596500248cff851301e5463151b757c23b8c873003a
Download

Enhancement

KB-18620
Added Syslog Collector based Fortigate log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
FortiGate v5.2.4 ▾
Version: 5.2.4
Release date: December 18, 2023
Supported On: Logpoint v6.7.0 or later
SHA 256: 949e5c4a5ae1651d0cf718adcb16c21f280958ade8ac339e4963c0c51e157271
Download

Enhancements

KB-18620
The policyname field is mapped as policy in FortiOSCompiledNormalizer.
KB-2159776129
The tz field value of a raw log is used to normalize log_ts field by FortiOSCompiledNormalizer.
KB-21015, KB-2159474766
Added protocol field and Query label in FortiCEFCompiledNormalizer and FortiOSCompiledNormalizer.
KB-21982
You can now configure a date format for FortiGate compiled normalizers using CompiledNormalizer Date Preference (CNDP). To learn how, go to CNDP .

Bug Fixes

KB-2117174508
The int key type of the destination_address field was incorrectly mapped as a string in FortiCEFCompiledNormalizer.
KB-1803468759
Some labels were not applied to the normalized Fortinet Firewall logs by FortiCEFCompiledNormalizer.
KB-1868569993
The ip_type field was not properly normalized by FortiOSCompiledNormalizer.
FortiGate v5.2.1 ▾
Version: 5.2.1
Release date: 08 Aug, 2022
Supported On: Logpoint v6.7.0 or later
SHA 256: 9ca6035796e4875faedfa42b6403000b76b7390361c01a0b38d6cc2f18d71305
Download

Enhancements

KB-1435560722
FortiOSCompiledNormalizer did not normalize FortiGate logs with values N/A.
KB-1648365381
The value of URL field was incorrectly normalized by FortiOSCompiledNormalizer.
KB-1364757813
Some FortiGate logs were not normalized by FortiOSCompiledNormalizer
FortiGate v5.2.0 ▾
Version: 5.2.0

Enhancements

KB-1377658220
The URL , Category , and Id fields are parsed from the message field in the FortiGate logs.
KB-1590663332
The utmaction field is now taken into account while applying labels for the FortiAnalyzer logs.
KB-1426459990
FortiOSCompiledNormalizer is updated to support FortiClient EMS logs. Also, the taxonomies of the FortiGate fields are changed. To learn more, go to the Appendix section in the Fortigate v5.2.0 guide .

Bug Fixes

KB-1429860303
Some FortiGate logs were not normalized by the LP_FortiAnalyzer .
KB-1403259107
Some FortiGate logs in the CEF format were not normalized by the FortiCEFCompiledNormalizer.
KB-1406459424
The URL field of some FortiGate logs were not properly normalized by the FortiOSCompiledNormalizer.
FortiGate v5.1.0 ▾
Version: 5.1.0

Enhancement

KB-1178251874, 52315
Added a new compiled normalizer FortiCEFCompiledNormalizer .

Bug Fixes

KB-1429860303
Some FortiGate logs were not normalized by the LP_FortiAnalyzer .
KB-1403259107
Some FortiGate logs in the CEF format were not normalized by the FortiCEFCompiledNormalizer.
KB-1406459424
The URL field of some FortiGate logs were not properly normalized by the FortiOSCompiledNormalizer.
FortiGate v3.6.0 ▾
Version: 3.6.0
Release date: May 05, 2020
SHA 256: e807703e43ea9a4cd639d0242702c0d5b05e71735eb9f9ca473ca52707a874f5
Download

Enhancement

A minor update has been done in the FortiGate's normalizer for better signature handling.

Key Information

alert rules

Support

If you have any questions or require assistance, create a support ticket.

Comments

  • Avatar
    Hans Vedder
    March 02, 2020 08:07

    One information is missing: Field "protocol" was renamed to protocol_id.

    Comment actions Permalink

Article is closed for comments.

Follow

Related articles

  • Universal Normalizer
  • Free IPA
  • Crowdstrike
  • Lookup
  • Panda Antivirus
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.