Change log for FORTINET_FORTICLIENT
| Date | Changes |
|---|---|
| 2026-07-07 |
Enhancement: - event.idm.read_only_udm.additional.fields: Removed mapping of devid from event.idm.read_only_udm.additional.fields UDM field in order to introduce a more accurate mapping.- event.idm.read_only_udm.observer.asset_id: Mapped devid raw log field with event.idm.read_only_udm.observer.asset_id UDM field- event.idm.read_only_udm.principal.resource.name: Removed mapping of devname from event.idm.read_only_udm.principal.resource.name UDM field as it is a host generating event which is best fit to observer.- event.idm.read_only_udm.principal.resource.type: Removed mapping of devname from event.idm.read_only_udm.principal.resource.type UDM field as it is a host generating event which is best fit to observer.- event.idm.read_only_udm.observer.hostname and event.idm.read_only_udm.observer.asset.hostname: Mapped devname raw log field with event.idm.read_only_udm.observer.hostname and event.idm.read_only_udm.observer.asset.hostname UDM fields.- event.idm.read_only_udm.principal.ip, event.idm.read_only_udm.principal.asset.ip: Newly mapped tunnelip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip: Newly mapped remip raw log field with event.idm.read_only_udm.target.ip and event.idm.read_only_udm.target.asset.ip UDM fields.- event.idm.read_only_udm.metadata.description: Newly mapped logdesc and msg raw log fields with event.idm.read_only_udm.metadata.description UDM field.- event.idm.read_only_udm.security_result.detection_fields: Newly mapped craction, crlevel, crscore raw log fields with event.idm.read_only_udm.security_result.detection_fields UDM field.- event.idm.read_only_udm.network.session_id: Newly mapped tunnelid raw log field with event.idm.read_only_udm.network.session_id UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped appid, applist, incidentserialno, tunneltype, nextstat and apprisk raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.target.application: Newly mapped app raw log field with event.idm.read_only_udm.target.application UDM field.- event.idm.read_only_udm.network.direction: Added support for parsing direction raw log field with event.idm.read_only_udm.network.direction UDM field.
|
| 2026-06-26 |
Enhancement: - event.idm.read_only_udm.metadata.event_timestamp: Added support for parsing timezone offset from ts raw log field.- event.idm.read_only_udm.metadata.product_log_id: Newly mapped logid raw log field with event.idm.read_only_udm.metadata.product_log_id UDM field.- event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip: Newly mapped srcip raw log field with event.idm.read_only_udm.principal.ip and event.idm.read_only_udm.principal.asset.ip UDM fields.- event.idm.read_only_udm.principal.resource.attribute.labels: Newly mapped srcintf, srcintfrole raw log fields with event.idm.read_only_udm.principal.resource.attribute.labels UDM field.- event.idm.read_only_udm.target.resource.attribute.labels: Newly mapped dstintf, dstintfrole raw log fields with event.idm.read_only_udm.target.resource.attribute.labels UDM field.- event.idm.read_only_udm.principal.location.country_or_region: Newly mapped srccountry raw log field with event.idm.read_only_udm.principal.location.country_or_region UDM field.- event.idm.read_only_udm.target.location.country_or_region: Newly mapped dstcountry raw log field with event.idm.read_only_udm.target.location.country_or_region UDM field.- event.idm.read_only_udm.security_result.rule_id: Newly mapped policyid raw log field with event.idm.read_only_udm.security_result.rule_id UDM field.- event.idm.read_only_udm.security_result.rule_type: Newly mapped policytype raw log field with event.idm.read_only_udm.security_result.rule_type UDM field.- event.idm.read_only_udm.security_result.rule_name: Newly mapped policyname raw log field with event.idm.read_only_udm.security_result.rule_name UDM field.- event.idm.read_only_udm.principal.user.group_identifiers: Newly mapped group raw log field with event.idm.read_only_udm.principal.user.group_identifiers UDM field.- event.idm.read_only_udm.network.session_duration.seconds: Newly mapped duration raw log field with event.idm.read_only_udm.network.session_duration.seconds UDM field.- event.idm.read_only_udm.network.sent_packets: Newly mapped sentpkt raw log field with event.idm.read_only_udm.network.sent_packets UDM field.- event.idm.read_only_udm.network.received_packets: Newly mapped rcvdpkt raw log field with event.idm.read_only_udm.network.received_packets UDM field.- event.idm.read_only_udm.security_result.severity: Mapped level raw log field with event.idm.read_only_udm.security_result.severity UDM field.- event.idm.read_only_udm.security_result.category_details: Mapped appcat raw log field with event.idm.read_only_udm.security_result.category_details UDM field.- event.idm.read_only_udm.security_result.action and event.idm.read_only_udm.security_result.action_details: Newly mapped action raw log field with event.idm.read_only_udm.security_result.action and event.idm.read_only_udm.security_result.action_details UDM fields.- event.idm.read_only_udm.intermediary.hostname: Newly mapped authserver raw log field with event.idm.read_only_udm.intermediary.hostname UDM field.- event.idm.read_only_udm.additional.fields: Newly mapped vd, poluuid, trandisp, service raw log fields with event.idm.read_only_udm.additional.fields UDM field.- event.idm.read_only_udm.metadata.event_type: Setting the value of event.idm.read_only_udm.metadata.event_type to NETWORK_CONNECTION when principal machine details and target machine details present else setting it to STATUS_UPDATE when principal machine details are present.
|
| 2025-01-13 |
Enhancement: - Added support for mapping service to network.application_protocol.
|
| 2023-12-29 |
Enhancement: - Changed mapping of SubjectUserName from principal.user.userid to additional.fields.- Changed mapping of uid from principal.user.userid to principal.user.product_object_id.- If uid is not present, mapped fctuid to principal.user.product_object_id.- Mapped user to principal.user.userid on the top of its mapping to principal.user.user_display_name.
|
| 2023-11-30 |
Enhancement: - Added a Grok pattern to parse the new logType. - Added a Grok pattern to parse the new XML part. - If devname is not null, set principal.resource.type to DEVICE.- Mapped devname to principal.resource.name.- Mapped itime to additional.fields.- Mapped fctsn to additional.fields.- Mapped logver to additional.fields.- Mapped id to metadata.product_log_id.- Mapped subtype to principal.resource.resource_subtype.- Mapped eventtype to metadata.product_event_type.- Mapped level to security_result.severity.- Mapped pcdomain to principal.administrative_domain.- Mapped site additional.fields.- Mapped fctver additional.fields.- Mapped sessionid to network.session_id.- Mapped srcname to principal.resource.attribute.labels.- Mapped srcproduct to principal.application.- Mapped srcport principal.port.- Mapped direction to network.direction.- Mapped dstip to target.ip.- Mapped remotename to target.hostname.- Mapped dstport to target.port.- Mapped proto to network.ip_protocol- Mapped rcvdbyte to network.received_bytes.- Mapped sentbyte to network.sent_bytes.- Mapped utmaction to security_result.description.- Mapped sec_action to security_result.action.- Mapped utmevent to security_result.category_details.- Mapped threat to security_result.threat_name.- Mapped service to network.application_protocol.- Mapped url to principal.url.- Mapped userinitiated to security_result.detection_fields.- Mapped browsetime to additional.fields.- Mapped date and time to metadata.event_timestamp".- Mapped timestamp to metadata.collected_timestamp.- Mapped client_ip to principal.ip.- Mapped source_ver to principal.platform_version.- Mapped source_type to principal.resource.attribute.labels.- Mapped type to principal.resource.attribute.labels.- Mapped event_id to additional.fields.- Mapped ThreadID to additional.fields.- Mapped SubjectLogonId to additional.fields.- Mapped fctuid to principal.user.product_object_id.- Mapped source_ver to principal.platform_version.- Mapped ProviderGuid to principal.resource.product_object_id.- Mapped ProcessId to principal.process.pid.- Mapped SubjectUserSid to principal.user.windows_sid.- Mapped SubjectUserName to principal.user.userid.
|
| 2023-10-27 | - Newly created parser. |