L-Flow›Log Sources›FortiGate fields

ฟิลด์ของ FortiGate

log จาก FortiGate ถูกแปลงชื่อฟิลด์เป็นมาตรฐาน ECS ก่อนจัดเก็บ ค้นหาใน Explore สร้าง Alert Rule และสร้างแผงใน Workspace ด้วยชื่อ ECS ในหน้านี้ ฟิลด์ที่ไม่มีในตารางจะถูกเก็บด้วยชื่อเดิมที่ FortiGate ส่งมา

ตัวอย่าง

log traffic หนึ่งบรรทัดตามที่ FortiGate ส่งมา:

date=2026-09-24 time=10:15:32 devname="FGT-HQ" devid="FG100FTK19000001" logid="0000000013"
type="traffic" subtype="forward" level="notice" vd="root" srcip=10.0.1.25 srcport=52344
srcintf="port2" dstip=142.250.4.100 dstport=443 dstintf="wan1" dstcountry="United States"
sessionid=8812345 proto=6 action="accept" policyid=12 policyname="LAN-to-WAN" service="HTTPS"
duration=35 sentbyte=5120 rcvdbyte=48213 sentpkt=18 rcvdpkt=42 tz="+0700"

หลังแปลงแล้ว จะเห็นใน Explore เป็น:

timestamp                          2026-09-24T10:15:32+07:00
vendor                             fortigate
devid                              FG100FTK19000001
type                               traffic
subtype                            forward
severity                           information
observer.hostname                  FGT-HQ
event.code                         0000000013
event.id                           8812345
event.action                       allow
event.duration                     35000000000
source.ip                          10.0.1.25
source.port                        52344
source.bytes                       5120
source.packets                     18
destination.ip                     142.250.4.100
destination.port                   443
destination.bytes                  48213
destination.packets                42
destination.geo.country_iso_code   US
observer.ingress.interface.name    port2
observer.egress.interface.name     wan1
network.transport                  tcp
network.protocol                   https
rule.id                            12
rule.name                          LAN-to-WAN
vd                                 root
message                            traffic/forward/allow

log ต้นฉบับทั้งบรรทัดยังเก็บไว้ใน raw archive แยกต่างหาก ดาวน์โหลดได้จากหน้า Export แบบ Raw archive

ฟิลด์ที่มีในทุก log

ฟิลด์ ECSมาจากความหมาย
timestampdate + time + tzเวลาที่อุปกรณ์บันทึก log ถ้าไม่มี tz จะถือเป็น UTC
vendor—ค่าคงที่ fortigate
deviddevidSerial number ของอุปกรณ์ ใช้แยกว่า log มาจากเครื่องไหนและเป็นของ tenant ใด
typetype + subtypeหมวดของ log ดู ค่าของ type
subtypesubtypeหมวดย่อยตามที่ FortiGate ส่งมา ไม่แปลง
severityseverity หรือ levelระดับความรุนแรง ดู การแปลงค่า severity
observer.hostnamedevnameชื่อเครื่อง FortiGate ที่ตั้งไว้
event.codelogidรหัสชนิดของ log (Log ID ใน FortiOS Log Reference)
event.idsessionidหมายเลข session ใช้รวม log หลายบรรทัดที่เป็น session เดียวกัน
messagelogdesc / msg / activityคำอธิบายของ log ถ้าไม่มีทั้งสามค่า จะเป็น type/subtype/event.action

ค่าของ type

FortiGate แยก log ด้วย type และ subtype L-Flow รวมสองค่านี้เป็น type ค่าเดียว ใช้ค่าชุดเดียวกับ Sophos เพื่อให้ query เดียวใช้ได้กับทั้งสองยี่ห้อ

typeมาจาก FortiGateความหมาย
traffictype=trafficการเชื่อมต่อที่ผ่าน firewall policy ทั้ง allow และ deny
apputm + app-ctrlApplication Control ตรวจพบแอปพลิเคชัน
webfilterutm + webfilterการเข้าเว็บที่ผ่าน Web Filter
ipsutm + ipsIPS ตรวจพบรูปแบบการโจมตี
antivirusutm + virusAntivirus ตรวจพบไฟล์อันตราย
dlputm + dlpData Leak Prevention ตรวจพบข้อมูลที่ห้ามส่งออก
emailfilterutm + emailfilterEmail Filter (spam, ไฟล์แนบ)
voiputm + voipVoIP/SIP inspection
utmutm + อื่นๆUTM subtype อื่นที่ยังไม่ได้แยกหมวด
vpnevent + vpnIPsec/SSL VPN tunnel ขึ้น ลง และการยืนยันตัวตน
authevent + user, event + system (login/logout)การเข้าสู่ระบบของผู้ใช้ และการ login/logout ของผู้ดูแล FortiGate
systemevent + system, event + haการเปลี่ยนค่าตั้ง เหตุการณ์ระบบ และ HA
sdwanevent + router, event + sd-wanเส้นทางและ SD-WAN health check
endpointevent + endpointFortiClient ที่เชื่อมกับ FortiGate
eventevent + อื่นๆEvent subtype อื่นที่ยังไม่ได้แยกหมวด

ฟิลด์ของการเชื่อมต่อ

มีใน log ที่เกี่ยวกับการเชื่อมต่อ ได้แก่ traffic และ UTM ทุกหมวด

ฟิลด์ ECSมาจากความหมาย
source.ipsrcipIP ต้นทาง
source.portsrcportพอร์ตต้นทาง
source.macsrcmacMAC address ต้นทาง
destination.ipdstipIP ปลายทาง
destination.portdstportพอร์ตปลายทาง
destination.macdstmacMAC address ปลายทาง
source.bytessentbyteจำนวน byte ที่ต้นทางส่งออก
destination.bytesrcvdbyteจำนวน byte ที่ต้นทางได้รับกลับ
source.packetssentpktจำนวน packet ที่ต้นทางส่งออก
destination.packetsrcvdpktจำนวน packet ที่ต้นทางได้รับกลับ
source.geo.country_iso_codesrccountryประเทศของ IP ต้นทาง แปลงจากชื่อประเทศเป็นรหัส 2 ตัวอักษร ดู ประเทศ
destination.geo.country_iso_codedstcountryประเทศของ IP ปลายทาง แปลงแบบเดียวกัน
source.nat.iptransipIP ต้นทางหลังทำ SNAT
source.nat.porttransportพอร์ตต้นทางหลังทำ SNAT
destination.nat.iptranipIP ปลายทางหลังทำ DNAT (VIP)
destination.nat.porttranportพอร์ตปลายทางหลังทำ DNAT
observer.ingress.interface.namesrcintfinterface ที่ traffic เข้ามา
observer.egress.interface.namedstintfinterface ที่ traffic ออกไป
network.transportprotoโปรโตคอลชั้น transport แปลงจากหมายเลขเป็นชื่อ ดู โปรโตคอล
network.protocolserviceชื่อ service ตามที่ตั้งใน FortiGate เป็นตัวพิมพ์เล็ก เช่น https, dns
event.actionactionผลของ policy accept แปลงเป็น allow ค่าอื่น (deny, close, timeout, server-rst ฯลฯ) ไม่แปลง
event.durationdurationระยะเวลาของ session หน่วยเป็น nanosecond (FortiGate ส่งมาเป็นวินาที)
rule.idpolicyidหมายเลข firewall policy ที่ตรงกับ traffic นี้
rule.namepolicynameชื่อ firewall policy
rule.uuidpoluuidUUID ของ firewall policy
Note:ใน log ประเภท ips ฟิลด์ rule.id และ rule.name คือ signature ของ IPS ไม่ใช่ firewall policy ดู IPS

ฟิลด์เฉพาะแต่ละ type

app

ฟิลด์ ECSมาจากความหมาย
network.applicationappชื่อแอปพลิเคชันที่ตรวจพบ
destination.domainhostnameโดเมนปลายทาง
appcatappcatหมวดของแอปพลิเคชัน ไม่แปลงชื่อ
appriskappriskระดับความเสี่ยงของแอป (low, elevated, medium, high, critical) ไม่แปลงชื่อ

webfilter

ฟิลด์ ECSมาจากความหมาย
url.originalurlURL ที่เข้าถึง
url.domainhostnameโดเมนที่เข้าถึง ถ้าไม่มี hostname จะดึงโดเมนออกจาก URL
categorycatdescชื่อหมวดเว็บของ FortiGuard เช่น Search Engines and Portals (รหัสหมวด cat ถูกตัดทิ้ง)

ips

ฟิลด์ ECSมาจากความหมาย
rule.idattackidหมายเลข signature ของ IPS (แทนที่หมายเลข firewall policy)
rule.nameattackชื่อ signature ถ้าไม่มี จะไม่มีฟิลด์นี้ ไม่ใช้ชื่อ policy แทน
rule.referencerefลิงก์อธิบาย signature ของ FortiGuard
user.nameuserผู้ใช้ที่ยืนยันตัวตนแล้ว (ถ้ามี)

antivirus

ฟิลด์ ECSมาจากความหมาย
file.namefilenameชื่อไฟล์ที่ตรวจพบ
file.hash.sha256checksumค่า hash ของไฟล์
threat.indicator.namevirusชื่อมัลแวร์
user.nameuserผู้ใช้ที่ยืนยันตัวตนแล้ว (ถ้ามี)

emailfilter

ฟิลด์ ECSมาจากความหมาย
email.from.addressfromผู้ส่ง
email.to.addresstoผู้รับ
email.subjectsubjectหัวเรื่อง
file.namefilenameชื่อไฟล์แนบ
threat.indicator.namevirusชื่อมัลแวร์ในไฟล์แนบ
user.nameuserผู้ใช้

dlp

ฟิลด์ ECSมาจากความหมาย
rule.namefilternameชื่อ DLP filter ที่ตรงกับเนื้อหา
file.namefilenameชื่อไฟล์
user.nameuserผู้ใช้
user.group.namegroupกลุ่มของผู้ใช้
email.from.addressfrom หรือ senderผู้ส่ง (กรณีเป็นอีเมล)
email.to.addressto หรือ recipientผู้รับ (กรณีเป็นอีเมล)
email.subjectsubjectหัวเรื่องอีเมล
url.originalurlURL (กรณีเป็นเว็บ)
url.domainhostnameโดเมน (กรณีเป็นเว็บ)

vpn

ฟิลด์ ECSมาจากความหมาย
user.nameuser, unauthuser หรือ xauthuserผู้ใช้ VPN ใช้ค่าแรกที่มีตามลำดับนี้
user.group.namegroupกลุ่มของผู้ใช้
source.ipremipIP ของฝั่งผู้ใช้หรือ peer ระยะไกล
source.portremportพอร์ตของฝั่งระยะไกล
destination.iplocipIP ของ FortiGate ที่รับการเชื่อมต่อ
destination.portlocportพอร์ตของ FortiGate
source.nat.ipassignipIP ที่ FortiGate แจกให้ผู้ใช้ใน tunnel
rule.namephase2_nameชื่อ IPsec phase 2
event.reasonreason หรือ error_reasonเหตุผลของเหตุการณ์ เช่น สาเหตุที่เชื่อมต่อไม่สำเร็จ
event.outcomeactionsuccess เมื่อ tunnel ขึ้นหรือลงตามปกติ, failure เมื่อ action มีคำว่า fail, error หรือ denied

auth

ฟิลด์ ECSมาจากความหมาย
user.nameuser หรือ unauthuserชื่อผู้ใช้ที่เข้าสู่ระบบ
user.group.namegroupกลุ่มของผู้ใช้
event.reasonreasonเหตุผล เช่น รหัสผ่านผิด
event.outcomestatus แล้วจึง actionsuccess หรือ failure ใช้ status ก่อน ถ้าไม่มีจึงดูจาก action (login = success, login-failed = failure)

system

ฟิลด์ ECSมาจากความหมาย
user.nameuser หรือ unauthuserผู้ดูแลที่ทำรายการ
user.group.namegroupกลุ่มของผู้ใช้
event.reasonreasonเหตุผลของเหตุการณ์

endpoint

ฟิลด์ ECSมาจากความหมาย
user.nameuserผู้ใช้บนเครื่อง
host.namehostnameชื่อเครื่องที่ติดตั้ง FortiClient
source.ipipIP ของเครื่อง
agent.idforticlient_idรหัส FortiClient
event.reasonreasonเหตุผลของเหตุการณ์

การแปลงค่า

severity

ใช้ severity ของ log ก่อน ถ้าไม่มี (log ประเภท event) จะใช้ level แล้วแปลงเป็น 5 ระดับ ค่าที่ไม่อยู่ในตารางจะเก็บตามเดิมเป็นตัวพิมพ์เล็ก

severityค่าจาก FortiGate
criticalcritical, crit, emergency
highhigh, alert, error
mediummedium, med, warning, warn
lowlow, minor
informationinformation, info, notice, debug

โปรโตคอล

proto เป็นหมายเลข IP protocol แปลงเป็นชื่อตามตารางนี้ หมายเลขอื่นเก็บเป็นตัวเลขตามเดิม

network.transportproto
icmp1
tcp6
udp17
gre47
esp50
ah51
ipv6-icmp58
ospf89
sctp132

ประเทศ

FortiGate ส่งชื่อประเทศเต็ม เช่น United States L-Flow แปลงเป็นรหัส ISO 3166-1 สองตัวอักษร เช่น US เพื่อให้ค้นด้วย destination.geo.country_iso_code:US ได้

ค่าที่ไม่ใช่ชื่อประเทศจริง เช่น Reserved (IP ภายในหรือ IP สงวน) และ Anonymous Proxyจะเก็บตามที่ FortiGate ส่งมา

เวลา

timestamp สร้างจาก date, time และ tz ของ log เช่น tz="+0700" ถ้า FortiGate ไม่ส่ง tz เวลาจะถูกตีความเป็น UTC ซึ่งอาจทำให้เวลาคลาดไปเท่ากับ timezone ของอุปกรณ์

ฟิลด์ที่ไม่ได้แปลงชื่อ

ฟิลด์อื่นทั้งหมดที่ FortiGate ส่งมาจะถูกเก็บด้วยชื่อเดิม เช่น vd (VDOM), appcat, apprisk, crscore, craction, countapp และ utmaction ค่าเหล่านี้ค้นหาได้ตามปกติ ความหมายของแต่ละฟิลด์ดูได้ใน FortiOS Log Reference ของเวอร์ชันที่ใช้

ฟิลด์ต้นฉบับที่ถูกแปลงแล้ว (เช่น srcip, policyid) จะไม่มีอยู่ในข้อมูลที่เก็บ ให้ค้นด้วยชื่อ ECS แทน ส่วน level, logdesc, msg, cat, date, time และ tz ถูกรวมเข้าฟิลด์อื่นแล้วจึงไม่มีแยก

ตั้งค่าการส่ง log จาก FortiGate ดูที่ FortiGate · เทียบกับ Sophos ดูที่ ฟิลด์ของ Sophos