ฟิลด์ของ FortiGate
log จาก FortiGate ถูกแปลงชื่อฟิลด์เป็นมาตรฐาน ECS ก่อนจัดเก็บ ค้นหาใน Explore สร้าง Alert Rule และสร้างแผงใน Workspace ด้วยชื่อ ECS ในหน้านี้ ฟิลด์ที่ไม่มีในตารางจะถูกเก็บด้วยชื่อเดิมที่ FortiGate ส่งมา
ตัวอย่าง
log traffic หนึ่งบรรทัดตามที่ FortiGate ส่งมา:
date=2026-09-24 time=10:15:32 devname="FGT-HQ" devid="FG100FTK19000001" logid="0000000013"
type="traffic" subtype="forward" level="notice" vd="root" srcip=10.0.1.25 srcport=52344
srcintf="port2" dstip=142.250.4.100 dstport=443 dstintf="wan1" dstcountry="United States"
sessionid=8812345 proto=6 action="accept" policyid=12 policyname="LAN-to-WAN" service="HTTPS"
duration=35 sentbyte=5120 rcvdbyte=48213 sentpkt=18 rcvdpkt=42 tz="+0700"
หลังแปลงแล้ว จะเห็นใน Explore เป็น:
timestamp 2026-09-24T10:15:32+07:00
vendor fortigate
devid FG100FTK19000001
type traffic
subtype forward
severity information
observer.hostname FGT-HQ
event.code 0000000013
event.id 8812345
event.action allow
event.duration 35000000000
source.ip 10.0.1.25
source.port 52344
source.bytes 5120
source.packets 18
destination.ip 142.250.4.100
destination.port 443
destination.bytes 48213
destination.packets 42
destination.geo.country_iso_code US
observer.ingress.interface.name port2
observer.egress.interface.name wan1
network.transport tcp
network.protocol https
rule.id 12
rule.name LAN-to-WAN
vd root
message traffic/forward/allow
log ต้นฉบับทั้งบรรทัดยังเก็บไว้ใน raw archive แยกต่างหาก ดาวน์โหลดได้จากหน้า Export แบบ Raw archive
ฟิลด์ที่มีในทุก log
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| timestamp | date + time + tz | เวลาที่อุปกรณ์บันทึก log ถ้าไม่มี tz จะถือเป็น UTC |
| vendor | — | ค่าคงที่ fortigate |
| devid | devid | Serial number ของอุปกรณ์ ใช้แยกว่า log มาจากเครื่องไหนและเป็นของ tenant ใด |
| type | type + subtype | หมวดของ log ดู ค่าของ type |
| subtype | subtype | หมวดย่อยตามที่ FortiGate ส่งมา ไม่แปลง |
| severity | severity หรือ level | ระดับความรุนแรง ดู การแปลงค่า severity |
| observer.hostname | devname | ชื่อเครื่อง FortiGate ที่ตั้งไว้ |
| event.code | logid | รหัสชนิดของ log (Log ID ใน FortiOS Log Reference) |
| event.id | sessionid | หมายเลข session ใช้รวม log หลายบรรทัดที่เป็น session เดียวกัน |
| message | logdesc / msg / activity | คำอธิบายของ log ถ้าไม่มีทั้งสามค่า จะเป็น type/subtype/event.action |
ค่าของ type
FortiGate แยก log ด้วย type และ subtype L-Flow รวมสองค่านี้เป็น type ค่าเดียว ใช้ค่าชุดเดียวกับ Sophos เพื่อให้ query เดียวใช้ได้กับทั้งสองยี่ห้อ
| type | มาจาก FortiGate | ความหมาย |
|---|
| traffic | type=traffic | การเชื่อมต่อที่ผ่าน firewall policy ทั้ง allow และ deny |
| app | utm + app-ctrl | Application Control ตรวจพบแอปพลิเคชัน |
| webfilter | utm + webfilter | การเข้าเว็บที่ผ่าน Web Filter |
| ips | utm + ips | IPS ตรวจพบรูปแบบการโจมตี |
| antivirus | utm + virus | Antivirus ตรวจพบไฟล์อันตราย |
| dlp | utm + dlp | Data Leak Prevention ตรวจพบข้อมูลที่ห้ามส่งออก |
| emailfilter | utm + emailfilter | Email Filter (spam, ไฟล์แนบ) |
| voip | utm + voip | VoIP/SIP inspection |
| utm | utm + อื่นๆ | UTM subtype อื่นที่ยังไม่ได้แยกหมวด |
| vpn | event + vpn | IPsec/SSL VPN tunnel ขึ้น ลง และการยืนยันตัวตน |
| auth | event + user, event + system (login/logout) | การเข้าสู่ระบบของผู้ใช้ และการ login/logout ของผู้ดูแล FortiGate |
| system | event + system, event + ha | การเปลี่ยนค่าตั้ง เหตุการณ์ระบบ และ HA |
| sdwan | event + router, event + sd-wan | เส้นทางและ SD-WAN health check |
| endpoint | event + endpoint | FortiClient ที่เชื่อมกับ FortiGate |
| event | event + อื่นๆ | Event subtype อื่นที่ยังไม่ได้แยกหมวด |
ฟิลด์ของการเชื่อมต่อ
มีใน log ที่เกี่ยวกับการเชื่อมต่อ ได้แก่ traffic และ UTM ทุกหมวด
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| source.ip | srcip | IP ต้นทาง |
| source.port | srcport | พอร์ตต้นทาง |
| source.mac | srcmac | MAC address ต้นทาง |
| destination.ip | dstip | IP ปลายทาง |
| destination.port | dstport | พอร์ตปลายทาง |
| destination.mac | dstmac | MAC address ปลายทาง |
| source.bytes | sentbyte | จำนวน byte ที่ต้นทางส่งออก |
| destination.bytes | rcvdbyte | จำนวน byte ที่ต้นทางได้รับกลับ |
| source.packets | sentpkt | จำนวน packet ที่ต้นทางส่งออก |
| destination.packets | rcvdpkt | จำนวน packet ที่ต้นทางได้รับกลับ |
| source.geo.country_iso_code | srccountry | ประเทศของ IP ต้นทาง แปลงจากชื่อประเทศเป็นรหัส 2 ตัวอักษร ดู ประเทศ |
| destination.geo.country_iso_code | dstcountry | ประเทศของ IP ปลายทาง แปลงแบบเดียวกัน |
| source.nat.ip | transip | IP ต้นทางหลังทำ SNAT |
| source.nat.port | transport | พอร์ตต้นทางหลังทำ SNAT |
| destination.nat.ip | tranip | IP ปลายทางหลังทำ DNAT (VIP) |
| destination.nat.port | tranport | พอร์ตปลายทางหลังทำ DNAT |
| observer.ingress.interface.name | srcintf | interface ที่ traffic เข้ามา |
| observer.egress.interface.name | dstintf | interface ที่ traffic ออกไป |
| network.transport | proto | โปรโตคอลชั้น transport แปลงจากหมายเลขเป็นชื่อ ดู โปรโตคอล |
| network.protocol | service | ชื่อ service ตามที่ตั้งใน FortiGate เป็นตัวพิมพ์เล็ก เช่น https, dns |
| event.action | action | ผลของ policy accept แปลงเป็น allow ค่าอื่น (deny, close, timeout, server-rst ฯลฯ) ไม่แปลง |
| event.duration | duration | ระยะเวลาของ session หน่วยเป็น nanosecond (FortiGate ส่งมาเป็นวินาที) |
| rule.id | policyid | หมายเลข firewall policy ที่ตรงกับ traffic นี้ |
| rule.name | policyname | ชื่อ firewall policy |
| rule.uuid | poluuid | UUID ของ firewall policy |
Note:ใน log ประเภท
ips ฟิลด์
rule.id และ
rule.name คือ signature ของ IPS ไม่ใช่ firewall policy ดู
IPS ฟิลด์เฉพาะแต่ละ type
app
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| network.application | app | ชื่อแอปพลิเคชันที่ตรวจพบ |
| destination.domain | hostname | โดเมนปลายทาง |
| appcat | appcat | หมวดของแอปพลิเคชัน ไม่แปลงชื่อ |
| apprisk | apprisk | ระดับความเสี่ยงของแอป (low, elevated, medium, high, critical) ไม่แปลงชื่อ |
webfilter
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| url.original | url | URL ที่เข้าถึง |
| url.domain | hostname | โดเมนที่เข้าถึง ถ้าไม่มี hostname จะดึงโดเมนออกจาก URL |
| category | catdesc | ชื่อหมวดเว็บของ FortiGuard เช่น Search Engines and Portals (รหัสหมวด cat ถูกตัดทิ้ง) |
ips
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| rule.id | attackid | หมายเลข signature ของ IPS (แทนที่หมายเลข firewall policy) |
| rule.name | attack | ชื่อ signature ถ้าไม่มี จะไม่มีฟิลด์นี้ ไม่ใช้ชื่อ policy แทน |
| rule.reference | ref | ลิงก์อธิบาย signature ของ FortiGuard |
| user.name | user | ผู้ใช้ที่ยืนยันตัวตนแล้ว (ถ้ามี) |
antivirus
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| file.name | filename | ชื่อไฟล์ที่ตรวจพบ |
| file.hash.sha256 | checksum | ค่า hash ของไฟล์ |
| threat.indicator.name | virus | ชื่อมัลแวร์ |
| user.name | user | ผู้ใช้ที่ยืนยันตัวตนแล้ว (ถ้ามี) |
emailfilter
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| email.from.address | from | ผู้ส่ง |
| email.to.address | to | ผู้รับ |
| email.subject | subject | หัวเรื่อง |
| file.name | filename | ชื่อไฟล์แนบ |
| threat.indicator.name | virus | ชื่อมัลแวร์ในไฟล์แนบ |
| user.name | user | ผู้ใช้ |
dlp
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| rule.name | filtername | ชื่อ DLP filter ที่ตรงกับเนื้อหา |
| file.name | filename | ชื่อไฟล์ |
| user.name | user | ผู้ใช้ |
| user.group.name | group | กลุ่มของผู้ใช้ |
| email.from.address | from หรือ sender | ผู้ส่ง (กรณีเป็นอีเมล) |
| email.to.address | to หรือ recipient | ผู้รับ (กรณีเป็นอีเมล) |
| email.subject | subject | หัวเรื่องอีเมล |
| url.original | url | URL (กรณีเป็นเว็บ) |
| url.domain | hostname | โดเมน (กรณีเป็นเว็บ) |
vpn
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| user.name | user, unauthuser หรือ xauthuser | ผู้ใช้ VPN ใช้ค่าแรกที่มีตามลำดับนี้ |
| user.group.name | group | กลุ่มของผู้ใช้ |
| source.ip | remip | IP ของฝั่งผู้ใช้หรือ peer ระยะไกล |
| source.port | remport | พอร์ตของฝั่งระยะไกล |
| destination.ip | locip | IP ของ FortiGate ที่รับการเชื่อมต่อ |
| destination.port | locport | พอร์ตของ FortiGate |
| source.nat.ip | assignip | IP ที่ FortiGate แจกให้ผู้ใช้ใน tunnel |
| rule.name | phase2_name | ชื่อ IPsec phase 2 |
| event.reason | reason หรือ error_reason | เหตุผลของเหตุการณ์ เช่น สาเหตุที่เชื่อมต่อไม่สำเร็จ |
| event.outcome | action | success เมื่อ tunnel ขึ้นหรือลงตามปกติ, failure เมื่อ action มีคำว่า fail, error หรือ denied |
auth
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| user.name | user หรือ unauthuser | ชื่อผู้ใช้ที่เข้าสู่ระบบ |
| user.group.name | group | กลุ่มของผู้ใช้ |
| event.reason | reason | เหตุผล เช่น รหัสผ่านผิด |
| event.outcome | status แล้วจึง action | success หรือ failure ใช้ status ก่อน ถ้าไม่มีจึงดูจาก action (login = success, login-failed = failure) |
system
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| user.name | user หรือ unauthuser | ผู้ดูแลที่ทำรายการ |
| user.group.name | group | กลุ่มของผู้ใช้ |
| event.reason | reason | เหตุผลของเหตุการณ์ |
endpoint
| ฟิลด์ ECS | มาจาก | ความหมาย |
|---|
| user.name | user | ผู้ใช้บนเครื่อง |
| host.name | hostname | ชื่อเครื่องที่ติดตั้ง FortiClient |
| source.ip | ip | IP ของเครื่อง |
| agent.id | forticlient_id | รหัส FortiClient |
| event.reason | reason | เหตุผลของเหตุการณ์ |
การแปลงค่า
severity
ใช้ severity ของ log ก่อน ถ้าไม่มี (log ประเภท event) จะใช้ level แล้วแปลงเป็น 5 ระดับ ค่าที่ไม่อยู่ในตารางจะเก็บตามเดิมเป็นตัวพิมพ์เล็ก
| severity | ค่าจาก FortiGate |
|---|
| critical | critical, crit, emergency |
| high | high, alert, error |
| medium | medium, med, warning, warn |
| low | low, minor |
| information | information, info, notice, debug |
โปรโตคอล
proto เป็นหมายเลข IP protocol แปลงเป็นชื่อตามตารางนี้ หมายเลขอื่นเก็บเป็นตัวเลขตามเดิม
| network.transport | proto |
|---|
| icmp | 1 |
| tcp | 6 |
| udp | 17 |
| gre | 47 |
| esp | 50 |
| ah | 51 |
| ipv6-icmp | 58 |
| ospf | 89 |
| sctp | 132 |
ประเทศ
FortiGate ส่งชื่อประเทศเต็ม เช่น United States L-Flow แปลงเป็นรหัส ISO 3166-1 สองตัวอักษร เช่น US เพื่อให้ค้นด้วย destination.geo.country_iso_code:US ได้
ค่าที่ไม่ใช่ชื่อประเทศจริง เช่น Reserved (IP ภายในหรือ IP สงวน) และ Anonymous Proxyจะเก็บตามที่ FortiGate ส่งมา
เวลา
timestamp สร้างจาก date, time และ tz ของ log เช่น tz="+0700" ถ้า FortiGate ไม่ส่ง tz เวลาจะถูกตีความเป็น UTC ซึ่งอาจทำให้เวลาคลาดไปเท่ากับ timezone ของอุปกรณ์
ฟิลด์ที่ไม่ได้แปลงชื่อ
ฟิลด์อื่นทั้งหมดที่ FortiGate ส่งมาจะถูกเก็บด้วยชื่อเดิม เช่น vd (VDOM), appcat, apprisk, crscore, craction, countapp และ utmaction ค่าเหล่านี้ค้นหาได้ตามปกติ ความหมายของแต่ละฟิลด์ดูได้ใน FortiOS Log Reference ของเวอร์ชันที่ใช้
ฟิลด์ต้นฉบับที่ถูกแปลงแล้ว (เช่น srcip, policyid) จะไม่มีอยู่ในข้อมูลที่เก็บ ให้ค้นด้วยชื่อ ECS แทน ส่วน level, logdesc, msg, cat, date, time และ tz ถูกรวมเข้าฟิลด์อื่นแล้วจึงไม่มีแยก
ตั้งค่าการส่ง log จาก FortiGate ดูที่ FortiGate · เทียบกับ Sophos ดูที่ ฟิลด์ของ Sophos