FortiGate
StandardFortiGate enables you to collect and normalize FortiGate logs and analyze the information through dashboards and security reports. FortiGate dashboards provide visualization related to threats, web attacks, and malicious activities. The FortiGate compiled normalizers are compatible with CNDP.
Additionally, when Logpoint identifies malicious events with a potential risk to your environment, it triggers security alerts based on predetermined rules.
Enhancement
PLUG-1564587053
A new Login label is added to ensure consistent display of login events in normalized logs.
Bug Fix
PLUG-1663290922
When using FortiCEFCompiledNormalizer, the message_id was not visible, preventing alerts from being triggered.
Past Releases
FortiGate v5.4.0 ▾
Enhancement
PLUG-1564587053
A new Login label is added to ensure consistent display of login events in normalized logs.
Bug Fixes
PLUG-1568385792
FortiOS Compiled Normalizer misinterpreted key-value pairs as separate fields in logs, causing normalized fields to display incorrectly.
KB-2297078477
The FortiGate Compiled Normalizer displayed a Jinja error for fields containing a period (.), such as "ad.attack", which prevented successful network configuration.
KB-2476182210
In some cases, the Normalization ID (norm_id) was missing in FortiGate logs. This resulted in incorrect normalization of logs.
FortiGate v5.3.0 ▾
Enhancement
KB-18620
Added Syslog Collector based Fortigate log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
FortiGate v5.2.4 ▾
Enhancements
KB-18620
The policyname field is mapped as policy in FortiOSCompiledNormalizer.
KB-2159776129
The tz field value of a raw log is used to normalize log_ts field by FortiOSCompiledNormalizer.
KB-21015, KB-2159474766
Added protocol field and Query label in FortiCEFCompiledNormalizer and FortiOSCompiledNormalizer.
KB-21982
You can now configure a date format for FortiGate compiled normalizers using CompiledNormalizer Date Preference (CNDP). To learn how, go to CNDP .
Bug Fixes
KB-2117174508
The int key type of the destination_address field was incorrectly mapped as a string in FortiCEFCompiledNormalizer.
KB-1803468759
Some labels were not applied to the normalized Fortinet Firewall logs by FortiCEFCompiledNormalizer.
KB-1868569993
The ip_type field was not properly normalized by FortiOSCompiledNormalizer.
FortiGate v5.2.1 ▾
Enhancements
KB-1435560722
FortiOSCompiledNormalizer did not normalize FortiGate logs with values N/A.
KB-1648365381
The value of URL field was incorrectly normalized by FortiOSCompiledNormalizer.
KB-1364757813
Some FortiGate logs were not normalized by FortiOSCompiledNormalizer
FortiGate v5.2.0 ▾
Enhancements
KB-1377658220
The URL , Category , and Id fields are parsed from the message field in the FortiGate logs.
KB-1590663332
The utmaction field is now taken into account while applying labels for the FortiAnalyzer logs.
KB-1426459990
FortiOSCompiledNormalizer is updated to support FortiClient EMS logs. Also, the taxonomies of the FortiGate fields are changed. To learn more, go to the Appendix section in the Fortigate v5.2.0 guide .
Bug Fixes
KB-1429860303
Some FortiGate logs were not normalized by the LP_FortiAnalyzer .
KB-1403259107
Some FortiGate logs in the CEF format were not normalized by the FortiCEFCompiledNormalizer.
KB-1406459424
The URL field of some FortiGate logs were not properly normalized by the FortiOSCompiledNormalizer.
FortiGate v5.1.0 ▾
Enhancement
KB-1178251874, 52315
Added a new compiled normalizer FortiCEFCompiledNormalizer .
Bug Fixes
KB-1429860303
Some FortiGate logs were not normalized by the LP_FortiAnalyzer .
KB-1403259107
Some FortiGate logs in the CEF format were not normalized by the FortiCEFCompiledNormalizer.
KB-1406459424
The URL field of some FortiGate logs were not properly normalized by the FortiOSCompiledNormalizer.
FortiGate v3.6.0 ▾
Enhancement
A minor update has been done in the FortiGate's normalizer for better signature handling.
Key Information
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
One information is missing: Field "protocol" was renamed to protocol_id.