0391-fortigate_rules.xml 448 KB


  1. <!--
  2. - Fortigate rules
  3. - Author: Alexander Tibor Assenheimer - github: alextibor
  4. - This program is a free software; you can redistribute it and/or modify it under the terms of GPLv2.
  5. - Rules create based on the Fortigate Log Reference from version 7.0.14, 7.2.7, 7.2.8 and 7.4.3
  6. -->
  7. <group name="fortigate,">
  8. <rule id="100010" level="4">
  9. <decoded_as>fortinet-fortigate-firewall</decoded_as>
  10. <description>Fortigate messages grouped</description>
  11. </rule>
  12. <rule id="100011" level="4">
  13. <!-- LOGID_ATTCK_ANOMALY_TCP_UDP -->
  14. <if_sid>100010</if_sid>
  15. <field name="logid">018432$</field>
  16. <description>Attack detected by UCP/TCP anomaly</description>
  17. <group>fortios.event.anomaly,fortios.category.anomaly,fortios.severity.alert</group>
  18. </rule>
  19. <rule id="100012" level="4">
  20. <!-- LOGID_ATTCK_ANOMALY_ICMP -->
  21. <if_sid>100010</if_sid>
  22. <field name="logid">018433$</field>
  23. <description>Attack detected by ICMP anomaly</description>
  24. <group>fortios.event.anomaly,fortios.category.anomaly,fortios.severity.alert</group>
  25. </rule>
  26. <rule id="100013" level="4">
  27. <!-- LOGID_ATTCK_ANOMALY_OTHERS -->
  28. <if_sid>100010</if_sid>
  29. <field name="logid">018434$</field>
  30. <description>Attack detected by other anomaly</description>
  31. <group>fortios.event.anomaly,fortios.category.anomaly,fortios.severity.alert</group>
  32. </rule>
  33. <rule id="100014" level="4">
  34. <!-- LOGID_APP_CTRL_IM_BASIC -->
  35. <if_sid>100010</if_sid>
  36. <field name="logid">028672$</field>
  37. <description>Application control IM-basic</description>
  38. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  39. </rule>
  40. <rule id="100015" level="4">
  41. <!-- LOGID_APP_CTRL_IM_BASIC_WITH_STATUS -->
  42. <if_sid>100010</if_sid>
  43. <field name="logid">028673$</field>
  44. <description>Application control IM</description>
  45. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  46. </rule>
  47. <rule id="100016" level="4">
  48. <!-- LOGID_APP_CTRL_IM_BASIC_WITH_COUNT -->
  49. <if_sid>100010</if_sid>
  50. <field name="logid">028674$</field>
  51. <description>Application control IM (chat message count)</description>
  52. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  53. </rule>
  54. <rule id="100017" level="4">
  55. <!-- LOGID_APP_CTRL_IM_FILE -->
  56. <if_sid>100010</if_sid>
  57. <field name="logid">028675$</field>
  58. <description>Application control IM (file)</description>
  59. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  60. </rule>
  61. <rule id="100018" level="4">
  62. <!-- LOGID_APP_CTRL_IM_CHAT -->
  63. <if_sid>100010</if_sid>
  64. <field name="logid">028676$</field>
  65. <description>Application control IM (chat)</description>
  66. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  67. </rule>
  68. <rule id="100019" level="4">
  69. <!-- LOGID_APP_CTRL_IM_CHAT_BLOCK -->
  70. <if_sid>100010</if_sid>
  71. <field name="logid">028677$</field>
  72. <description>Application control IM (chat blocked)</description>
  73. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  74. </rule>
  75. <rule id="100020" level="4">
  76. <!-- LOGID_APP_CTRL_IM_BLOCK -->
  77. <if_sid>100010</if_sid>
  78. <field name="logid">028678$</field>
  79. <description>Application control IM (blocked)</description>
  80. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  81. </rule>
  82. <rule id="100021" level="4">
  83. <!-- LOGID_APP_CTRL_IPS_PASS -->
  84. <if_sid>100010</if_sid>
  85. <field name="logid">028704$</field>
  86. <description>Application control (IPS) (pass)</description>
  87. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  88. </rule>
  89. <rule id="100022" level="4">
  90. <!-- LOGID_APP_CTRL_IPS_BLOCK -->
  91. <if_sid>100010</if_sid>
  92. <field name="logid">028705$</field>
  93. <description>Application control (IPS) (block)</description>
  94. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.warning</group>
  95. </rule>
  96. <rule id="100023" level="4">
  97. <!-- LOGID_APP_CTRL_IPS_RESET -->
  98. <if_sid>100010</if_sid>
  99. <field name="logid">028706$</field>
  100. <description>Application control (IPS) (reset)</description>
  101. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.warning</group>
  102. </rule>
  103. <rule id="100024" level="4">
  104. <!-- LOGID_APP_CTRL_SSH_PASS -->
  105. <if_sid>100010</if_sid>
  106. <field name="logid">028720$</field>
  107. <description>Application control IM (SSH) (pass)</description>
  108. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.information</group>
  109. </rule>
  110. <rule id="100025" level="4">
  111. <!-- LOGID_APP_CTRL_SSH_BLOCK -->
  112. <if_sid>100010</if_sid>
  113. <field name="logid">028721$</field>
  114. <description>Application control IM (SSH) (block)</description>
  115. <group>fortios.event.app-ctrl,fortios.category.signature,fortios.severity.warning</group>
  116. </rule>
  117. <rule id="100026" level="4">
  118. <!-- LOGID_APP_CTRL_PORT_ENF -->
  119. <if_sid>100010</if_sid>
  120. <field name="logid">028736$</field>
  121. <description>Application control port enforcement</description>
  122. <group>fortios.event.app-ctrl,fortios.category.port-violation,fortios.severity.warning</group>
  123. </rule>
  124. <rule id="100027" level="4">
  125. <!-- LOGID_APP_CTRL_PROTO_ENF -->
  126. <if_sid>100010</if_sid>
  127. <field name="logid">028737$</field>
  128. <description>Application control protocol enforcement</description>
  129. <group>fortios.event.app-ctrl,fortios.category.protocol-violation,fortios.severity.warning</group>
  130. </rule>
  131. <rule id="100028" level="4">
  132. <!-- LOG_ID_DLP_WARN -->
  133. <if_sid>100010</if_sid>
  134. <field name="logid">024576$</field>
  135. <description>Data leak detected by specified DLP sensor rule</description>
  136. <group>fortios.event.dlp,fortios.category.dlp,fortios.severity.warning</group>
  137. </rule>
  138. <rule id="100029" level="4">
  139. <!-- LOG_ID_DLP_NOTIF -->
  140. <if_sid>100010</if_sid>
  141. <field name="logid">024577$</field>
  142. <description>Data leak detected by specified DLP sensor rule</description>
  143. <group>fortios.event.dlp,fortios.category.dlp,fortios.severity.notice</group>
  144. </rule>
  145. <rule id="100030" level="4">
  146. <!-- LOG_ID_DLP_DOC_SOURCE -->
  147. <if_sid>100010</if_sid>
  148. <field name="logid">024578$</field>
  149. <description>DLP fingerprint document source notice</description>
  150. <group>fortios.event.dlp,fortios.category.dlp-docsource,fortios.severity.notice</group>
  151. </rule>
  152. <rule id="100031" level="4">
  153. <!-- LOG_ID_DLP_DOC_SOURCE_ERROR -->
  154. <if_sid>100010</if_sid>
  155. <field name="logid">024579$</field>
  156. <description>DLP fingerprint document source error</description>
  157. <group>fortios.event.dlp,fortios.category.dlp-docsource,fortios.severity.warning</group>
  158. </rule>
  159. <rule id="100032" level="4">
  160. <!-- LOG_ID_DNS_QUERY -->
  161. <if_sid>100010</if_sid>
  162. <field name="logid">054000$</field>
  163. <description>DNS query message</description>
  164. <group>fortios.event.dns,fortios.category.dns-query,fortios.severity.information</group>
  165. </rule>
  166. <rule id="100033" level="4">
  167. <!-- LOG_ID_DNS_RESOLV_ERROR -->
  168. <if_sid>100010</if_sid>
  169. <field name="logid">054200$</field>
  170. <description>DNS resolution error message</description>
  171. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.error</group>
  172. </rule>
  173. <rule id="100034" level="4">
  174. <!-- LOG_ID_DNS_URL_FILTER_BLOCK -->
  175. <if_sid>100010</if_sid>
  176. <field name="logid">054400$</field>
  177. <description>Domain blocked because it is in the domain-filter list</description>
  178. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.warning</group>
  179. </rule>
  180. <rule id="100035" level="4">
  181. <!-- LOG_ID_DNS_URL_FILTER_ALLOW -->
  182. <if_sid>100010</if_sid>
  183. <field name="logid">054401$</field>
  184. <description>Domain allowed because it is in the domain-filter list</description>
  185. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.information</group>
  186. </rule>
  187. <rule id="100036" level="4">
  188. <!-- LOG_ID_DNS_BOTNET_IP -->
  189. <if_sid>100010</if_sid>
  190. <field name="logid">054600$</field>
  191. <description>Domain blocked by DNS botnet C&amp;C (IP)</description>
  192. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.warning</group>
  193. </rule>
  194. <rule id="100037" level="4">
  195. <!-- LOG_ID_DNS_BOTNET_DOMAIN -->
  196. <if_sid>100010</if_sid>
  197. <field name="logid">054601$</field>
  198. <description>Domain blocked by DNS botnet C&amp;C (Domain)</description>
  199. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.warning</group>
  200. </rule>
  201. <rule id="100038" level="4">
  202. <!-- LOG_ID_DNS_FTGD_WARNING -->
  203. <if_sid>100010</if_sid>
  204. <field name="logid">054800$</field>
  205. <description>FortiGuard rating error warning</description>
  206. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.warning</group>
  207. </rule>
  208. <rule id="100039" level="4">
  209. <!-- LOG_ID_DNS_FTGD_ERROR -->
  210. <if_sid>100010</if_sid>
  211. <field name="logid">054801$</field>
  212. <description>FortiGuard rating error occurred</description>
  213. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.error</group>
  214. </rule>
  215. <rule id="100040" level="4">
  216. <!-- LOG_ID_DNS_FTGD_CAT_ALLOW -->
  217. <if_sid>100010</if_sid>
  218. <field name="logid">054802$</field>
  219. <description>Domain is monitored</description>
  220. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.notice</group>
  221. </rule>
  222. <rule id="100041" level="4">
  223. <!-- LOG_ID_DNS_FTGD_CAT_BLOCK -->
  224. <if_sid>100010</if_sid>
  225. <field name="logid">054803$</field>
  226. <description>Domain belongs to a denied category in policy</description>
  227. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.warning</group>
  228. </rule>
  229. <rule id="100042" level="4">
  230. <!-- LOG_ID_DNS_SAFE_SEARCH -->
  231. <if_sid>100010</if_sid>
  232. <field name="logid">054804$</field>
  233. <description>DNS Safe Search enforced</description>
  234. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.notice</group>
  235. </rule>
  236. <rule id="100043" level="4">
  237. <!-- LOG_ID_DNS_LOCAL -->
  238. <if_sid>100010</if_sid>
  239. <field name="logid">054805$</field>
  240. <description>DNS local query</description>
  241. <group>fortios.event.dns,fortios.category.dns-response,fortios.severity.information</group>
  242. </rule>
  243. <rule id="100044" level="4">
  244. <!-- LOGID_ANTISPAM_EMAIL_NOTIF -->
  245. <if_sid>100010</if_sid>
  246. <field name="logid">020480$</field>
  247. <description>SPAM notification</description>
  248. <group>fortios.event.emailfilter,fortios.category.spam,fortios.severity.notice</group>
  249. </rule>
  250. <rule id="100045" level="4">
  251. <!-- LOGID_EMAIL_GENERAL_NOTIF -->
  252. <if_sid>100010</if_sid>
  253. <field name="logid">020481$</field>
  254. <description>Email message</description>
  255. <group>fortios.event.emailfilter,fortios.category.email,fortios.severity.information</group>
  256. </rule>
  257. <rule id="100046" level="4">
  258. <!-- LOGID_ANTISPAM_EMAIL_BWORD_NOTIF -->
  259. <if_sid>100010</if_sid>
  260. <field name="logid">020482$</field>
  261. <description>Banned word notification</description>
  262. <group>fortios.event.emailfilter,fortios.category.bannedword,fortios.severity.notice</group>
  263. </rule>
  264. <rule id="100047" level="4">
  265. <!-- LOGID_ANTISPAM_FTGD_ERR -->
  266. <if_sid>100010</if_sid>
  267. <field name="logid">020509$</field>
  268. <description>FortiGuard error message</description>
  269. <group>fortios.event.emailfilter,fortios.category.ftgd_err,fortios.severity.notice</group>
  270. </rule>
  271. <rule id="100048" level="4">
  272. <!-- LOGID_ANTISPAM_EMAIL_WEBMAIL_NOTIF -->
  273. <if_sid>100010</if_sid>
  274. <field name="logid">020510$</field>
  275. <description>Webmail message</description>
  276. <group>fortios.event.emailfilter,fortios.category.webmail,fortios.severity.information</group>
  277. </rule>
  278. <rule id="100049" level="4">
  279. <!-- LOG_ID_DOMAIN_UNRESOLVABLE -->
  280. <if_sid>100010</if_sid>
  281. <field name="logid">020002$</field>
  282. <description>Domain name of alert email sender unresolvable</description>
  283. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  284. </rule>
  285. <rule id="100050" level="4">
  286. <!-- LOG_ID_MAIL_SENT_FAIL -->
  287. <if_sid>100010</if_sid>
  288. <field name="logid">020003$</field>
  289. <description>Alert email send status failed</description>
  290. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  291. </rule>
  292. <rule id="100051" level="4">
  293. <!-- LOG_ID_POLICY_TOO_BIG -->
  294. <if_sid>100010</if_sid>
  295. <field name="logid">020004$</field>
  296. <description>Policy too big for installation</description>
  297. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  298. </rule>
  299. <rule id="100052" level="4">
  300. <!-- LOG_ID_PPP_LINK_UP -->
  301. <if_sid>100010</if_sid>
  302. <field name="logid">020005$</field>
  303. <description>Modem PPP link up</description>
  304. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  305. </rule>
  306. <rule id="100053" level="4">
  307. <!-- LOG_ID_PPP_LINK_DOWN -->
  308. <if_sid>100010</if_sid>
  309. <field name="logid">020006$</field>
  310. <description>Modem PPP link down</description>
  311. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  312. </rule>
  313. <rule id="100054" level="4">
  314. <!-- LOG_ID_SOCKET_EXHAUSTED -->
  315. <if_sid>100010</if_sid>
  316. <field name="logid">020007$</field>
  317. <description>Socket is exhausted</description>
  318. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  319. </rule>
  320. <rule id="100055" level="4">
  321. <!-- LOG_ID_POLICY6_TOO_BIG -->
  322. <if_sid>100010</if_sid>
  323. <field name="logid">020008$</field>
  324. <description>IPv6 policy too big for installation</description>
  325. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  326. </rule>
  327. <rule id="100056" level="4">
  328. <!-- LOG_ID_KERNEL_ERROR -->
  329. <if_sid>100010</if_sid>
  330. <field name="logid">020010$</field>
  331. <description>Kernel error</description>
  332. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  333. </rule>
  334. <rule id="100057" level="4">
  335. <!-- LOG_ID_MODEM_EXCEED_REDIAL_COUNT -->
  336. <if_sid>100010</if_sid>
  337. <field name="logid">020016$</field>
  338. <description>Modem exceeded redial limit</description>
  339. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  340. </rule>
  341. <rule id="100058" level="4">
  342. <!-- LOG_ID_MODEM_FAIL_TO_OPEN -->
  343. <if_sid>100010</if_sid>
  344. <field name="logid">020017$</field>
  345. <description>Modem failed to open</description>
  346. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  347. </rule>
  348. <rule id="100059" level="4">
  349. <!-- LOG_ID_MODEM_USB_DETECTED -->
  350. <if_sid>100010</if_sid>
  351. <field name="logid">020020$</field>
  352. <description>USB modem detected</description>
  353. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  354. </rule>
  355. <rule id="100060" level="4">
  356. <!-- LOG_ID_MAIL_RESENT -->
  357. <if_sid>100010</if_sid>
  358. <field name="logid">020021$</field>
  359. <description>Alert email resent</description>
  360. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  361. </rule>
  362. <rule id="100061" level="4">
  363. <!-- LOG_ID_MODEM_USB_REMOVED -->
  364. <if_sid>100010</if_sid>
  365. <field name="logid">020022$</field>
  366. <description>USB modem removed</description>
  367. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  368. </rule>
  369. <rule id="100062" level="4">
  370. <!-- LOG_ID_MODEM_USBLTE_DETECTED -->
  371. <if_sid>100010</if_sid>
  372. <field name="logid">020023$</field>
  373. <description>USB LTE modem detected</description>
  374. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  375. </rule>
  376. <rule id="100063" level="4">
  377. <!-- LOG_ID_MODEM_USBLTE_REMOVED -->
  378. <if_sid>100010</if_sid>
  379. <field name="logid">020024$</field>
  380. <description>USB LTE modem removed</description>
  381. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  382. </rule>
  383. <rule id="100064" level="4">
  384. <!-- LOG_ID_REPORTD_REPORT_SUCCESS -->
  385. <if_sid>100010</if_sid>
  386. <field name="logid">020025$</field>
  387. <description>Report generated successfully</description>
  388. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  389. </rule>
  390. <rule id="100065" level="4">
  391. <!-- LOG_ID_REPORTD_REPORT_FAILURE -->
  392. <if_sid>100010</if_sid>
  393. <field name="logid">020026$</field>
  394. <description>Report generation failed</description>
  395. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  396. </rule>
  397. <rule id="100066" level="4">
  398. <!-- LOG_ID_REPORT_RECREATE_DB -->
  399. <if_sid>100010</if_sid>
  400. <field name="logid">020028$</field>
  401. <description>Report database recreated</description>
  402. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  403. </rule>
  404. <rule id="100067" level="4">
  405. <!-- LOG_ID_RAD_OUT_OF_MEM -->
  406. <if_sid>100010</if_sid>
  407. <field name="logid">020031$</field>
  408. <description>RADVD out of memory</description>
  409. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  410. </rule>
  411. <rule id="100068" level="4">
  412. <!-- LOG_ID_RAD_NOT_FOUND -->
  413. <if_sid>100010</if_sid>
  414. <field name="logid">020032$</field>
  415. <description>RADVD interface not found</description>
  416. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  417. </rule>
  418. <rule id="100069" level="4">
  419. <!-- LOG_ID_RAD_MOBILE_IPV6 -->
  420. <if_sid>100010</if_sid>
  421. <field name="logid">020033$</field>
  422. <description>RADVD mobile IPv6 extensions used</description>
  423. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  424. </rule>
  425. <rule id="100070" level="4">
  426. <!-- LOG_ID_RAD_IPV6_OUT_OF_RANGE -->
  427. <if_sid>100010</if_sid>
  428. <field name="logid">020034$</field>
  429. <description>RADVD mobile IPv6 MinRtrAdvInterval out of range</description>
  430. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  431. </rule>
  432. <rule id="100071" level="4">
  433. <!-- LOG_ID_RAD_MIN_OUT_OF_RANGE -->
  434. <if_sid>100010</if_sid>
  435. <field name="logid">020035$</field>
  436. <description>RADVD MinRtrAdvInterval out of range</description>
  437. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  438. </rule>
  439. <rule id="100072" level="4">
  440. <!-- LOG_ID_RAD_MAX_OUT_OF_RANGE -->
  441. <if_sid>100010</if_sid>
  442. <field name="logid">020036$</field>
  443. <description>RADVD mobile IPv6 MaxRtrAdvInterval out of range</description>
  444. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  445. </rule>
  446. <rule id="100073" level="4">
  447. <!-- LOG_ID_RAD_MAX_ADV_OUT_OF_RANGE -->
  448. <if_sid>100010</if_sid>
  449. <field name="logid">020037$</field>
  450. <description>RADVD MaxRtrAdvInterval out of range</description>
  451. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  452. </rule>
  453. <rule id="100074" level="4">
  454. <!-- LOG_ID_RAD_MTU_TOO_SMALL -->
  455. <if_sid>100010</if_sid>
  456. <field name="logid">020039$</field>
  457. <description>RADVD AdvLinkMTU too small</description>
  458. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  459. </rule>
  460. <rule id="100075" level="4">
  461. <!-- LOG_ID_RAD_TIME_TOO_SMALL -->
  462. <if_sid>100010</if_sid>
  463. <field name="logid">020040$</field>
  464. <description>RADVD AdvReachableTime too small</description>
  465. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  466. </rule>
  467. <rule id="100076" level="4">
  468. <!-- LOG_ID_RAD_HOP_OUT_OF_RANGE -->
  469. <if_sid>100010</if_sid>
  470. <field name="logid">020041$</field>
  471. <description>RADVD AdvCurHopLimit too big</description>
  472. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  473. </rule>
  474. <rule id="100077" level="4">
  475. <!-- LOG_ID_RAD_DFT_HOP_OUT_OF_RANGE -->
  476. <if_sid>100010</if_sid>
  477. <field name="logid">020042$</field>
  478. <description>RADVD AdvCurHopLimit out of range</description>
  479. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  480. </rule>
  481. <rule id="100078" level="4">
  482. <!-- LOG_ID_RAD_AGENT_OUT_OF_RANGE -->
  483. <if_sid>100010</if_sid>
  484. <field name="logid">020043$</field>
  485. <description>RADVD HomeAgentLifetime out of range</description>
  486. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  487. </rule>
  488. <rule id="100079" level="4">
  489. <!-- LOG_ID_RAD_AGENT_FLAG_NOT_SET -->
  490. <if_sid>100010</if_sid>
  491. <field name="logid">020044$</field>
  492. <description>RADVD AdvHomeAgentFlag not set</description>
  493. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  494. </rule>
  495. <rule id="100080" level="4">
  496. <!-- LOG_ID_RAD_PREFIX_TOO_LONG -->
  497. <if_sid>100010</if_sid>
  498. <field name="logid">020045$</field>
  499. <description>RADVD invalid prefix length</description>
  500. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  501. </rule>
  502. <rule id="100081" level="4">
  503. <!-- LOG_ID_RAD_PREF_TIME_TOO_SMALL -->
  504. <if_sid>100010</if_sid>
  505. <field name="logid">020046$</field>
  506. <description>RADVD AdvValidLifetime less than AdvPreferredLifetime</description>
  507. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  508. </rule>
  509. <rule id="100082" level="4">
  510. <!-- LOG_ID_RAD_INV_ICMPV6_TYPE -->
  511. <if_sid>100010</if_sid>
  512. <field name="logid">020061$</field>
  513. <description>RADVD received unwanted ICMPv6 packet</description>
  514. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  515. </rule>
  516. <rule id="100083" level="4">
  517. <!-- LOG_ID_RAD_INV_ICMPV6_RA_LEN -->
  518. <if_sid>100010</if_sid>
  519. <field name="logid">020062$</field>
  520. <description>RADVD received ICMPv6 RA packet with invalid length</description>
  521. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  522. </rule>
  523. <rule id="100084" level="4">
  524. <!-- LOG_ID_RAD_ICMPV6_NO_SRC_ADDR -->
  525. <if_sid>100010</if_sid>
  526. <field name="logid">020063$</field>
  527. <description>RADVD received ICMPv6 RA packet with non-link local source address</description>
  528. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  529. </rule>
  530. <rule id="100085" level="4">
  531. <!-- LOG_ID_RAD_INV_ICMPV6_RS_LEN -->
  532. <if_sid>100010</if_sid>
  533. <field name="logid">020064$</field>
  534. <description>RADVD received ICMPv6 RS packet with invalid length</description>
  535. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  536. </rule>
  537. <rule id="100086" level="4">
  538. <!-- LOG_ID_RAD_INV_ICMPV6_CODE -->
  539. <if_sid>100010</if_sid>
  540. <field name="logid">020065$</field>
  541. <description>RADVD received ICMPv6 RS/RA packet with invalid code</description>
  542. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  543. </rule>
  544. <rule id="100087" level="4">
  545. <!-- LOG_ID_RAD_INV_ICMPV6_HOP -->
  546. <if_sid>100010</if_sid>
  547. <field name="logid">020066$</field>
  548. <description>RADVD received ICMPv6 RS/RA packet with invalid hop limit</description>
  549. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  550. </rule>
  551. <rule id="100088" level="4">
  552. <!-- LOG_ID_RAD_MISMATCH_HOP -->
  553. <if_sid>100010</if_sid>
  554. <field name="logid">020067$</field>
  555. <description>RADVD local AdvCurHopLimit disagrees with remote site</description>
  556. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  557. </rule>
  558. <rule id="100089" level="4">
  559. <!-- LOG_ID_RAD_MISMATCH_MGR_FLAG -->
  560. <if_sid>100010</if_sid>
  561. <field name="logid">020068$</field>
  562. <description>RADVD local AdvManagedFlag disagrees with remote site</description>
  563. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  564. </rule>
  565. <rule id="100090" level="4">
  566. <!-- LOG_ID_RAD_MISMATCH_OTH_FLAG -->
  567. <if_sid>100010</if_sid>
  568. <field name="logid">020069$</field>
  569. <description>RADVD local AdvOtherConfigFlag disagrees with remote site</description>
  570. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  571. </rule>
  572. <rule id="100091" level="4">
  573. <!-- LOG_ID_RAD_MISMATCH_TIME -->
  574. <if_sid>100010</if_sid>
  575. <field name="logid">020070$</field>
  576. <description>RADVD local AdvReachableTime disagrees with remote site</description>
  577. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  578. </rule>
  579. <rule id="100092" level="4">
  580. <!-- LOG_ID_RAD_MISMATCH_TIMER -->
  581. <if_sid>100010</if_sid>
  582. <field name="logid">020071$</field>
  583. <description>RADVD local AdvRetransTimer disagrees with remote site</description>
  584. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  585. </rule>
  586. <rule id="100093" level="4">
  587. <!-- LOG_ID_RAD_EXTRA_DATA -->
  588. <if_sid>100010</if_sid>
  589. <field name="logid">020072$</field>
  590. <description>RADVD extra data in RA packet found</description>
  591. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  592. </rule>
  593. <rule id="100094" level="4">
  594. <!-- LOG_ID_RAD_NO_OPT_DATA -->
  595. <if_sid>100010</if_sid>
  596. <field name="logid">020073$</field>
  597. <description>RADVD RA packet option length zero</description>
  598. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  599. </rule>
  600. <rule id="100095" level="4">
  601. <!-- LOG_ID_RAD_INV_OPT_LEN -->
  602. <if_sid>100010</if_sid>
  603. <field name="logid">020074$</field>
  604. <description>RADVD RA packet option length greater than total length</description>
  605. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  606. </rule>
  607. <rule id="100096" level="4">
  608. <!-- LOG_ID_RAD_MISMATCH_MTU -->
  609. <if_sid>100010</if_sid>
  610. <field name="logid">020075$</field>
  611. <description>RADVD local AdvLinkMTU disagrees with remote site</description>
  612. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  613. </rule>
  614. <rule id="100097" level="4">
  615. <!-- LOG_ID_RAD_MISMATCH_PREF_TIME -->
  616. <if_sid>100010</if_sid>
  617. <field name="logid">020077$</field>
  618. <description>Interface AdvPreferredLifetime on our interface does not agree with a remote site</description>
  619. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  620. </rule>
  621. <rule id="100098" level="4">
  622. <!-- LOG_ID_RAD_INV_OPT -->
  623. <if_sid>100010</if_sid>
  624. <field name="logid">020078$</field>
  625. <description>RADVD found invalid option in RA packet from remote site</description>
  626. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  627. </rule>
  628. <rule id="100099" level="4">
  629. <!-- LOG_ID_RAD_FAIL_TO_RCV -->
  630. <if_sid>100010</if_sid>
  631. <field name="logid">020080$</field>
  632. <description>RADVD receive message failed</description>
  633. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  634. </rule>
  635. <rule id="100100" level="4">
  636. <!-- LOG_ID_RAD_INV_HOP -->
  637. <if_sid>100010</if_sid>
  638. <field name="logid">020081$</field>
  639. <description>RADVD received invalid IPv6 hop limit</description>
  640. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  641. </rule>
  642. <rule id="100101" level="4">
  643. <!-- LOG_ID_RAD_INV_PKTINFO -->
  644. <if_sid>100010</if_sid>
  645. <field name="logid">020082$</field>
  646. <description>RADVD received invalid IPv6 packet info</description>
  647. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  648. </rule>
  649. <rule id="100102" level="4">
  650. <!-- LOG_ID_RAD_FAIL_TO_CHECK -->
  651. <if_sid>100010</if_sid>
  652. <field name="logid">020083$</field>
  653. <description>RADVD all-routers membership check failed</description>
  654. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  655. </rule>
  656. <rule id="100103" level="4">
  657. <!-- LOG_ID_RAD_FAIL_TO_SEND -->
  658. <if_sid>100010</if_sid>
  659. <field name="logid">020084$</field>
  660. <description>RADVD send message failed</description>
  661. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  662. </rule>
  663. <rule id="100104" level="4">
  664. <!-- LOG_ID_SESSION_CLASH -->
  665. <if_sid>100010</if_sid>
  666. <field name="logid">020085$</field>
  667. <description>Session clashed</description>
  668. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  669. </rule>
  670. <rule id="100105" level="4">
  671. <!-- LOG_ID_INTF_LINK_STA_CHG -->
  672. <if_sid>100010</if_sid>
  673. <field name="logid">020090$</field>
  674. <description>Interface link status changed</description>
  675. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  676. </rule>
  677. <rule id="100106" level="4">
  678. <!-- LOG_ID_INTF_STA_CHG -->
  679. <if_sid>100010</if_sid>
  680. <field name="logid">020099$</field>
  681. <description>Interface status changed</description>
  682. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  683. </rule>
  684. <rule id="100107" level="4">
  685. <!-- LOG_ID_WEB_CAT_UPDATED -->
  686. <if_sid>100010</if_sid>
  687. <field name="logid">020100$</field>
  688. <description>FortiGuard web filter category list updated</description>
  689. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  690. </rule>
  691. <rule id="100108" level="4">
  692. <!-- LOG_ID_WEB_LIC_EXPIRE -->
  693. <if_sid>100010</if_sid>
  694. <field name="logid">020101$</field>
  695. <description>FortiGuard web filter license expiring</description>
  696. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  697. </rule>
  698. <rule id="100109" level="4">
  699. <!-- LOG_ID_SPAM_LIC_EXPIRE -->
  700. <if_sid>100010</if_sid>
  701. <field name="logid">020102$</field>
  702. <description>FortiGuard antispam license expiring</description>
  703. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  704. </rule>
  705. <rule id="100110" level="4">
  706. <!-- LOG_ID_AV_LIC_EXPIRE -->
  707. <if_sid>100010</if_sid>
  708. <field name="logid">020103$</field>
  709. <description>FortiGuard antivirus license expiring</description>
  710. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  711. </rule>
  712. <rule id="100111" level="4">
  713. <!-- LOG_ID_IPS_LIC_EXPIRE -->
  714. <if_sid>100010</if_sid>
  715. <field name="logid">020104$</field>
  716. <description>FortiGuard IPS license expiring</description>
  717. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  718. </rule>
  719. <rule id="100112" level="4">
  720. <!-- LOG_ID_LOG_UPLOAD_ERR -->
  721. <if_sid>100010</if_sid>
  722. <field name="logid">020107$</field>
  723. <description>Log upload error</description>
  724. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  725. </rule>
  726. <rule id="100113" level="4">
  727. <!-- LOG_ID_LOG_UPLOAD_DONE -->
  728. <if_sid>100010</if_sid>
  729. <field name="logid">020108$</field>
  730. <description>Log upload completed</description>
  731. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  732. </rule>
  733. <rule id="100114" level="4">
  734. <!-- LOG_ID_WEB_LIC_EXPIRED -->
  735. <if_sid>100010</if_sid>
  736. <field name="logid">020109$</field>
  737. <description>FortiGuard web filter license expired</description>
  738. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  739. </rule>
  740. <rule id="100115" level="4">
  741. <!-- LOG_ID_IPSA_DOWNLOAD_FAIL -->
  742. <if_sid>100010</if_sid>
  743. <field name="logid">020113$</field>
  744. <description>IPSA database download failed</description>
  745. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  746. </rule>
  747. <rule id="100116" level="4">
  748. <!-- LOG_ID_IPSA_SELFTEST_FAIL -->
  749. <if_sid>100010</if_sid>
  750. <field name="logid">020114$</field>
  751. <description>IPSA disabled: self test failed</description>
  752. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  753. </rule>
  754. <rule id="100117" level="4">
  755. <!-- LOG_ID_IPSA_STATUSUPD_FAIL -->
  756. <if_sid>100010</if_sid>
  757. <field name="logid">020115$</field>
  758. <description>IPSA driver update failed</description>
  759. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  760. </rule>
  761. <rule id="100118" level="4">
  762. <!-- LOG_ID_SPAM_LIC_EXPIRED -->
  763. <if_sid>100010</if_sid>
  764. <field name="logid">020116$</field>
  765. <description>FortiGuard antispam license expired</description>
  766. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  767. </rule>
  768. <rule id="100119" level="4">
  769. <!-- LOG_ID_AV_LIC_EXPIRED -->
  770. <if_sid>100010</if_sid>
  771. <field name="logid">020117$</field>
  772. <description>FortiGuard antivirus license expired</description>
  773. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  774. </rule>
  775. <rule id="100120" level="4">
  776. <!-- LOG_ID_WEBF_STATUS_REACH -->
  777. <if_sid>100010</if_sid>
  778. <field name="logid">020118$</field>
  779. <description>FortiGuard webfilter reachable</description>
  780. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  781. </rule>
  782. <rule id="100121" level="4">
  783. <!-- LOG_ID_WEBF_STATUS_UNREACH -->
  784. <if_sid>100010</if_sid>
  785. <field name="logid">020119$</field>
  786. <description>FortiGuard webfilter unreachable</description>
  787. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  788. </rule>
  789. <rule id="100122" level="4">
  790. <!-- LOG_ID_FMGC_LIC_EXPIRE -->
  791. <if_sid>100010</if_sid>
  792. <field name="logid">020120$</field>
  793. <description>FortiManager Cloud license expiring</description>
  794. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  795. </rule>
  796. <rule id="100123" level="4">
  797. <!-- LOG_ID_FAZC_LIC_EXPIRE -->
  798. <if_sid>100010</if_sid>
  799. <field name="logid">020121$</field>
  800. <description>FortiAnalyzer Cloud license expiring</description>
  801. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  802. </rule>
  803. <rule id="100124" level="4">
  804. <!-- LOG_ID_SWNO_LIC_EXPIRE -->
  805. <if_sid>100010</if_sid>
  806. <field name="logid">020122$</field>
  807. <description>SD-WAN Overlay Controller license expiring</description>
  808. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  809. </rule>
  810. <rule id="100125" level="4">
  811. <!-- LOG_ID_SWNM_LIC_EXPIRE -->
  812. <if_sid>100010</if_sid>
  813. <field name="logid">020123$</field>
  814. <description>SD-WAN Monitoring license expiring</description>
  815. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  816. </rule>
  817. <rule id="100126" level="4">
  818. <!-- LOG_ID_VMLS_LIC_EXPIRE -->
  819. <if_sid>100010</if_sid>
  820. <field name="logid">020124$</field>
  821. <description>VM-S license expiring</description>
  822. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  823. </rule>
  824. <rule id="100127" level="4">
  825. <!-- LOG_ID_SFAS_LIC_EXPIRE -->
  826. <if_sid>100010</if_sid>
  827. <field name="logid">020125$</field>
  828. <description>Security Rating license expiring</description>
  829. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  830. </rule>
  831. <rule id="100128" level="4">
  832. <!-- LOG_ID_IPMC_LIC_EXPIRE -->
  833. <if_sid>100010</if_sid>
  834. <field name="logid">020126$</field>
  835. <description>IPAM Controller license expiring</description>
  836. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  837. </rule>
  838. <rule id="100129" level="4">
  839. <!-- LOG_ID_IOTH_LIC_EXPIRE -->
  840. <if_sid>100010</if_sid>
  841. <field name="logid">020127$</field>
  842. <description>IoT device identification license expiring</description>
  843. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  844. </rule>
  845. <rule id="100130" level="4">
  846. <!-- LOG_ID_FSAC_LIC_EXPIRE -->
  847. <if_sid>100010</if_sid>
  848. <field name="logid">020128$</field>
  849. <description>FortiSandbox Cloud license expiring</description>
  850. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  851. </rule>
  852. <rule id="100131" level="4">
  853. <!-- LOG_ID_AFAC_LIC_EXPIRE -->
  854. <if_sid>100010</if_sid>
  855. <field name="logid">020129$</field>
  856. <description>FortiAnalyzer Cloud premium license expiring</description>
  857. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  858. </rule>
  859. <rule id="100132" level="4">
  860. <!-- LOG_ID_EMSC_ACC_LIC_EXPIRE -->
  861. <if_sid>100010</if_sid>
  862. <field name="logid">020130$</field>
  863. <description>FortiClient EMS Cloud license expiring</description>
  864. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  865. </rule>
  866. <rule id="100133" level="4">
  867. <!-- LOG_ID_FMGC_ACC_LIC_EXPIRE -->
  868. <if_sid>100010</if_sid>
  869. <field name="logid">020131$</field>
  870. <description>FortiManager Cloud Account Level license expiring</description>
  871. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  872. </rule>
  873. <rule id="100134" level="4">
  874. <!-- LOG_ID_FSAP_ACC_LIC_EXPIRE -->
  875. <if_sid>100010</if_sid>
  876. <field name="logid">020132$</field>
  877. <description>FortiSandbox Cloud Account Level license expiring</description>
  878. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  879. </rule>
  880. <rule id="100135" level="4">
  881. <!-- LOG_ID_FIREWALL_POLICY_EXPIRE -->
  882. <if_sid>100010</if_sid>
  883. <field name="logid">020133$</field>
  884. <description>Firewall policy expiring</description>
  885. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  886. </rule>
  887. <rule id="100136" level="4">
  888. <!-- LOG_ID_FIREWALL_POLICY_EXPIRED -->
  889. <if_sid>100010</if_sid>
  890. <field name="logid">020134$</field>
  891. <description>Firewall policy expired</description>
  892. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  893. </rule>
  894. <rule id="100137" level="4">
  895. <!-- LOG_ID_FAIS_LIC_EXPIRE -->
  896. <if_sid>100010</if_sid>
  897. <field name="logid">020135$</field>
  898. <description>FortiGuard AI-Based Sandbox Service license expiring</description>
  899. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  900. </rule>
  901. <rule id="100138" level="4">
  902. <!-- LOG_ID_FIPS_SELF_TEST -->
  903. <if_sid>100010</if_sid>
  904. <field name="logid">020200$</field>
  905. <description>FIPS CC self-test initiated</description>
  906. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  907. </rule>
  908. <rule id="100139" level="4">
  909. <!-- LOG_ID_FIPS_SELF_ALL_TEST -->
  910. <if_sid>100010</if_sid>
  911. <field name="logid">020201$</field>
  912. <description>FIPS ALL CC self-tests initiated</description>
  913. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  914. </rule>
  915. <rule id="100140" level="4">
  916. <!-- LOG_ID_DISK_FORMAT_ERROR -->
  917. <if_sid>100010</if_sid>
  918. <field name="logid">020202$</field>
  919. <description>Disk partitioning or formatting Error</description>
  920. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  921. </rule>
  922. <rule id="100141" level="4">
  923. <!-- LOG_ID_DAEMON_SHUTDOWN -->
  924. <if_sid>100010</if_sid>
  925. <field name="logid">020203$</field>
  926. <description>Daemon shutdown</description>
  927. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  928. </rule>
  929. <rule id="100142" level="4">
  930. <!-- LOG_ID_DAEMON_START -->
  931. <if_sid>100010</if_sid>
  932. <field name="logid">020204$</field>
  933. <description>Daemon started</description>
  934. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  935. </rule>
  936. <rule id="100143" level="4">
  937. <!-- LOG_ID_DISK_FORMAT_REQ -->
  938. <if_sid>100010</if_sid>
  939. <field name="logid">020205$</field>
  940. <description>Format disk requested</description>
  941. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  942. </rule>
  943. <rule id="100144" level="4">
  944. <!-- LOG_ID_DISK_SCAN_REQ -->
  945. <if_sid>100010</if_sid>
  946. <field name="logid">020206$</field>
  947. <description>Scan disk requested</description>
  948. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  949. </rule>
  950. <rule id="100145" level="4">
  951. <!-- LOG_ID_RAD_MISMATCH_VALID_TIME -->
  952. <if_sid>100010</if_sid>
  953. <field name="logid">020207$</field>
  954. <description>RADVD local AdvValidLifetime disagrees with remote site</description>
  955. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  956. </rule>
  957. <rule id="100146" level="4">
  958. <!-- LOG_ID_ZOMBIE_DAEMON_CLEANUP -->
  959. <if_sid>100010</if_sid>
  960. <field name="logid">020208$</field>
  961. <description>Zombie daemon cleanup</description>
  962. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  963. </rule>
  964. <rule id="100147" level="4">
  965. <!-- LOG_ID_DISK_UNAVAIL -->
  966. <if_sid>100010</if_sid>
  967. <field name="logid">020209$</field>
  968. <description>Disk unavailable</description>
  969. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  970. </rule>
  971. <rule id="100148" level="4">
  972. <!-- LOG_ID_DISK_TRIM_START -->
  973. <if_sid>100010</if_sid>
  974. <field name="logid">020210$</field>
  975. <description>SSD TRIM started</description>
  976. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  977. </rule>
  978. <rule id="100149" level="4">
  979. <!-- LOG_ID_DISK_TRIM_END -->
  980. <if_sid>100010</if_sid>
  981. <field name="logid">020211$</field>
  982. <description>SSD TRIM finished</description>
  983. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  984. </rule>
  985. <rule id="100150" level="4">
  986. <!-- LOG_ID_DISK_SCAN_NEEDED -->
  987. <if_sid>100010</if_sid>
  988. <field name="logid">020212$</field>
  989. <description>Disk scan is needed</description>
  990. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  991. </rule>
  992. <rule id="100151" level="4">
  993. <!-- LOG_ID_DISK_LOG_CORRUPTED -->
  994. <if_sid>100010</if_sid>
  995. <field name="logid">020213$</field>
  996. <description>Log file on disk is corrupted</description>
  997. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  998. </rule>
  999. <rule id="100152" level="4">
  1000. <!-- LOG_ID_LOCAL_OUT_IOC -->
  1001. <if_sid>100010</if_sid>
  1002. <field name="logid">020214$</field>
  1003. <description>Locally generated traffic goes to IoC location</description>
  1004. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1005. </rule>
  1006. <rule id="100153" level="4">
  1007. <!-- LOGID_EVENT_SHAPER_OUTBOUND_MAXED_OUT -->
  1008. <if_sid>100010</if_sid>
  1009. <field name="logid">020220$</field>
  1010. <description>Outbound bandwidth rate exceeded</description>
  1011. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1012. </rule>
  1013. <rule id="100154" level="4">
  1014. <!-- LOGID_EVENT_SHAPER_INBOUND_MAXED_OUT -->
  1015. <if_sid>100010</if_sid>
  1016. <field name="logid">020221$</field>
  1017. <description>Inbound bandwidth rate exceeded</description>
  1018. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1019. </rule>
  1020. <rule id="100155" level="4">
  1021. <!-- LOG_ID_SYS_SECURITY_WRITE_VIOLATION -->
  1022. <if_sid>100010</if_sid>
  1023. <field name="logid">020230$</field>
  1024. <description>Write Permission Violation</description>
  1025. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1026. </rule>
  1027. <rule id="100156" level="4">
  1028. <!-- LOG_ID_SYS_SECURITY_HARDLINK_VIOLATION -->
  1029. <if_sid>100010</if_sid>
  1030. <field name="logid">020231$</field>
  1031. <description>Hard Link Creation Violation</description>
  1032. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1033. </rule>
  1034. <rule id="100157" level="4">
  1035. <!-- LOG_ID_SYS_SECURITY_LOAD_MODULE_VIOLATION -->
  1036. <if_sid>100010</if_sid>
  1037. <field name="logid">020232$</field>
  1038. <description>Load Kernel/Kernel Module/Firmware Violation</description>
  1039. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1040. </rule>
  1041. <rule id="100158" level="4">
  1042. <!-- LOG_ID_SYS_SECURITY_FILE_HASH_MISSING -->
  1043. <if_sid>100010</if_sid>
  1044. <field name="logid">020233$</field>
  1045. <description>Integrity check of Run/loading Excutable File failed without Integrity measure</description>
  1046. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1047. </rule>
  1048. <rule id="100159" level="4">
  1049. <!-- LOG_ID_SYS_SECURITY_FILE_HASH_MISMATCH -->
  1050. <if_sid>100010</if_sid>
  1051. <field name="logid">020234$</field>
  1052. <description>Integrity check of Run/loading Excutable File failed with mismatched measure</description>
  1053. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1054. </rule>
  1055. <rule id="100160" level="4">
  1056. <!-- LOG_ID_SYS_SECURITY_MOUNT_VIOLATION -->
  1057. <if_sid>100010</if_sid>
  1058. <field name="logid">020235$</field>
  1059. <description>Filesystem Mount Violation</description>
  1060. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1061. </rule>
  1062. <rule id="100161" level="4">
  1063. <!-- LOG_ID_BGP_NB_STAT_CHG -->
  1064. <if_sid>100010</if_sid>
  1065. <field name="logid">020300$</field>
  1066. <description>BGP neighbor status changed</description>
  1067. <group>fortios.event.event,fortios.category.router,fortios.severity.warning</group>
  1068. </rule>
  1069. <rule id="100162" level="4">
  1070. <!-- LOG_ID_VZ_LOG_INFO -->
  1071. <if_sid>100010</if_sid>
  1072. <field name="logid">020301$</field>
  1073. <description>Routing log information</description>
  1074. <group>fortios.event.event,fortios.category.router,fortios.severity.information</group>
  1075. </rule>
  1076. <rule id="100163" level="4">
  1077. <!-- LOG_ID_OSPF_NB_STAT_CHG -->
  1078. <if_sid>100010</if_sid>
  1079. <field name="logid">020302$</field>
  1080. <description>OSPF neighbor status changed</description>
  1081. <group>fortios.event.event,fortios.category.router,fortios.severity.warning</group>
  1082. </rule>
  1083. <rule id="100164" level="4">
  1084. <!-- LOG_ID_OSPF6_NB_STAT_CHG -->
  1085. <if_sid>100010</if_sid>
  1086. <field name="logid">020303$</field>
  1087. <description>OSPF6 neighbor status changed</description>
  1088. <group>fortios.event.event,fortios.category.router,fortios.severity.warning</group>
  1089. </rule>
  1090. <rule id="100165" level="4">
  1091. <!-- LOG_ID_VZ_LOG_WARNING -->
  1092. <if_sid>100010</if_sid>
  1093. <field name="logid">020304$</field>
  1094. <description>Routing log warning</description>
  1095. <group>fortios.event.event,fortios.category.router,fortios.severity.warning</group>
  1096. </rule>
  1097. <rule id="100166" level="4">
  1098. <!-- LOG_ID_VZ_LOG_CRITICAL -->
  1099. <if_sid>100010</if_sid>
  1100. <field name="logid">020305$</field>
  1101. <description>Routing log critical event</description>
  1102. <group>fortios.event.event,fortios.category.router,fortios.severity.critical</group>
  1103. </rule>
  1104. <rule id="100167" level="4">
  1105. <!-- LOG_ID_VZ_LOG_ERROR -->
  1106. <if_sid>100010</if_sid>
  1107. <field name="logid">020306$</field>
  1108. <description>Routing log error</description>
  1109. <group>fortios.event.event,fortios.category.router,fortios.severity.error</group>
  1110. </rule>
  1111. <rule id="100168" level="4">
  1112. <!-- LOG_ID_ROUTER_CLEAR -->
  1113. <if_sid>100010</if_sid>
  1114. <field name="logid">020401$</field>
  1115. <description>Router cleared</description>
  1116. <group>fortios.event.event,fortios.category.router,fortios.severity.notice</group>
  1117. </rule>
  1118. <rule id="100169" level="4">
  1119. <!-- LOG_ID_INV_PKT_LEN -->
  1120. <if_sid>100010</if_sid>
  1121. <field name="logid">022000$</field>
  1122. <description>Packet length mismatch</description>
  1123. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1124. </rule>
  1125. <rule id="100170" level="4">
  1126. <!-- LOG_ID_UNSUPPORTED_PROT_VER -->
  1127. <if_sid>100010</if_sid>
  1128. <field name="logid">022001$</field>
  1129. <description>Protocol version unsupported</description>
  1130. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1131. </rule>
  1132. <rule id="100171" level="4">
  1133. <!-- LOG_ID_INV_REQ_TYPE -->
  1134. <if_sid>100010</if_sid>
  1135. <field name="logid">022002$</field>
  1136. <description>Request type not supported</description>
  1137. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1138. </rule>
  1139. <rule id="100172" level="4">
  1140. <!-- LOG_ID_FAIL_SET_SIG_HANDLER -->
  1141. <if_sid>100010</if_sid>
  1142. <field name="logid">022003$</field>
  1143. <description>Signal handler setup failed</description>
  1144. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1145. </rule>
  1146. <rule id="100173" level="4">
  1147. <!-- LOG_ID_FAIL_CREATE_SOCKET -->
  1148. <if_sid>100010</if_sid>
  1149. <field name="logid">022004$</field>
  1150. <description>Socket creation failed</description>
  1151. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1152. </rule>
  1153. <rule id="100174" level="4">
  1154. <!-- LOG_ID_FAIL_CREATE_SOCKET_RETRY -->
  1155. <if_sid>100010</if_sid>
  1156. <field name="logid">022005$</field>
  1157. <description>Socket creation retry failed</description>
  1158. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1159. </rule>
  1160. <rule id="100175" level="4">
  1161. <!-- LOG_ID_FAIL_REG_CMDB_EVENT -->
  1162. <if_sid>100010</if_sid>
  1163. <field name="logid">022006$</field>
  1164. <description>Registration for CMDB events failed</description>
  1165. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1166. </rule>
  1167. <rule id="100176" level="4">
  1168. <!-- LOG_ID_FAIL_FIND_AV_PROFILE -->
  1169. <if_sid>100010</if_sid>
  1170. <field name="logid">022009$</field>
  1171. <description>AntiVirus profile not found</description>
  1172. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1173. </rule>
  1174. <rule id="100177" level="4">
  1175. <!-- LOG_ID_SENDTO_FAIL -->
  1176. <if_sid>100010</if_sid>
  1177. <field name="logid">022010$</field>
  1178. <description>URL filter packet send failure</description>
  1179. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  1180. </rule>
  1181. <rule id="100178" level="4">
  1182. <!-- LOG_ID_ENTER_MEM_CONSERVE_MODE -->
  1183. <if_sid>100010</if_sid>
  1184. <field name="logid">022011$</field>
  1185. <description>Memory conserve mode entered</description>
  1186. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1187. </rule>
  1188. <rule id="100179" level="4">
  1189. <!-- LOG_ID_LEAVE_MEM_CONSERVE_MODE -->
  1190. <if_sid>100010</if_sid>
  1191. <field name="logid">022012$</field>
  1192. <description>Memory conserve mode exited</description>
  1193. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1194. </rule>
  1195. <rule id="100180" level="4">
  1196. <!-- LOG_ID_IPPOOLPBA_BLOCK_EXHAUSTED -->
  1197. <if_sid>100010</if_sid>
  1198. <field name="logid">022013$</field>
  1199. <description>IP pool PBA block exhausted</description>
  1200. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1201. </rule>
  1202. <rule id="100181" level="4">
  1203. <!-- LOG_ID_IPPOOLPBA_NATIP_EXHAUSTED -->
  1204. <if_sid>100010</if_sid>
  1205. <field name="logid">022014$</field>
  1206. <description>IP pool PBA NAT IP exhausted</description>
  1207. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  1208. </rule>
  1209. <rule id="100182" level="4">
  1210. <!-- LOG_ID_IPPOOLPBA_CREATE -->
  1211. <if_sid>100010</if_sid>
  1212. <field name="logid">022015$</field>
  1213. <description>IP pool PBA created</description>
  1214. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1215. </rule>
  1216. <rule id="100183" level="4">
  1217. <!-- LOG_ID_IPPOOLPBA_DEALLOCATE -->
  1218. <if_sid>100010</if_sid>
  1219. <field name="logid">022016$</field>
  1220. <description>Deallocate IP pool PBA</description>
  1221. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1222. </rule>
  1223. <rule id="100184" level="4">
  1224. <!-- LOG_ID_EXCEED_GLOB_RES_LIMIT -->
  1225. <if_sid>100010</if_sid>
  1226. <field name="logid">022017$</field>
  1227. <description>Global resource limit exceeded</description>
  1228. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1229. </rule>
  1230. <rule id="100185" level="4">
  1231. <!-- LOG_ID_EXCEED_VD_RES_LIMIT -->
  1232. <if_sid>100010</if_sid>
  1233. <field name="logid">022018$</field>
  1234. <description>VDOM resource limit exceeded</description>
  1235. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1236. </rule>
  1237. <rule id="100186" level="4">
  1238. <!-- LOG_ID_LOGRATE_OVER_LIMIT -->
  1239. <if_sid>100010</if_sid>
  1240. <field name="logid">022019$</field>
  1241. <description>Log rate limit exceeded</description>
  1242. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1243. </rule>
  1244. <rule id="100187" level="4">
  1245. <!-- LOG_ID_FAIL_CREATE_HA_SOCKET -->
  1246. <if_sid>100010</if_sid>
  1247. <field name="logid">022020$</field>
  1248. <description>HA socket creation failed</description>
  1249. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1250. </rule>
  1251. <rule id="100188" level="4">
  1252. <!-- LOG_ID_FAIL_CREATE_HA_SOCKET_RETRY -->
  1253. <if_sid>100010</if_sid>
  1254. <field name="logid">022021$</field>
  1255. <description>UDP socket creation to relay URL request failed</description>
  1256. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1257. </rule>
  1258. <rule id="100189" level="4">
  1259. <!-- LOG_ID_SUCCESS_CSF_LOG_SYNC_CONFIG_CHANGED -->
  1260. <if_sid>100010</if_sid>
  1261. <field name="logid">022031$</field>
  1262. <description>Settings modified by Security Fabric service</description>
  1263. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1264. </rule>
  1265. <rule id="100190" level="4">
  1266. <!-- LOG_ID_CSF_LOOP_FOUND -->
  1267. <if_sid>100010</if_sid>
  1268. <field name="logid">022032$</field>
  1269. <description>Looped configuration in Security Fabric service</description>
  1270. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1271. </rule>
  1272. <rule id="100191" level="4">
  1273. <!-- LOG_ID_CSF_UPSTREAM_SN_CHANGED -->
  1274. <if_sid>100010</if_sid>
  1275. <field name="logid">022035$</field>
  1276. <description>Serial number of upstream is changed</description>
  1277. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1278. </rule>
  1279. <rule id="100192" level="4">
  1280. <!-- LOG_ID_CSF_FGT_CONNECTED -->
  1281. <if_sid>100010</if_sid>
  1282. <field name="logid">022036$</field>
  1283. <description>Connection with Security Fabric member established and authorized.</description>
  1284. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1285. </rule>
  1286. <rule id="100193" level="4">
  1287. <!-- LOG_ID_CSF_FGT_DISCONNECTED -->
  1288. <if_sid>100010</if_sid>
  1289. <field name="logid">022037$</field>
  1290. <description>Connection with authorized Security Fabric member terminated.</description>
  1291. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1292. </rule>
  1293. <rule id="100194" level="4">
  1294. <!-- LOG_ID_CSF_GLOBAL_SYNC_FAILED -->
  1295. <if_sid>100010</if_sid>
  1296. <field name="logid">022038$</field>
  1297. <description>Synchronization of global object failed.</description>
  1298. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  1299. </rule>
  1300. <rule id="100195" level="4">
  1301. <!-- LOG_ID_CSF_GLOBAL_SYNC_REPORT -->
  1302. <if_sid>100010</if_sid>
  1303. <field name="logid">022039$</field>
  1304. <description>Synchronization of global object report.</description>
  1305. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1306. </rule>
  1307. <rule id="100196" level="4">
  1308. <!-- LOG_ID_CSF_DEVICE_JOIN -->
  1309. <if_sid>100010</if_sid>
  1310. <field name="logid">022040$</field>
  1311. <description>Device joined the Security Fabric.</description>
  1312. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1313. </rule>
  1314. <rule id="100197" level="4">
  1315. <!-- LOG_ID_CSF_DEVICE_LEAVE -->
  1316. <if_sid>100010</if_sid>
  1317. <field name="logid">022041$</field>
  1318. <description>Device left the Security Fabric.</description>
  1319. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1320. </rule>
  1321. <rule id="100198" level="4">
  1322. <!-- LOG_ID_CSF_DEVICE_UPDATE -->
  1323. <if_sid>100010</if_sid>
  1324. <field name="logid">022042$</field>
  1325. <description>Device in the Security Fabric was updated.</description>
  1326. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1327. </rule>
  1328. <rule id="100199" level="4">
  1329. <!-- LOG_ID_CSF_NEW_AUTH_REQ -->
  1330. <if_sid>100010</if_sid>
  1331. <field name="logid">022043$</field>
  1332. <description>An authorization request was added.</description>
  1333. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1334. </rule>
  1335. <rule id="100200" level="4">
  1336. <!-- LOG_ID_CSF_UPDATE_AUTH_REQ -->
  1337. <if_sid>100010</if_sid>
  1338. <field name="logid">022044$</field>
  1339. <description>An authorization request was updated.</description>
  1340. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1341. </rule>
  1342. <rule id="100201" level="4">
  1343. <!-- LOG_ID_CSF_REMOVE_AUTH_REQ -->
  1344. <if_sid>100010</if_sid>
  1345. <field name="logid">022045$</field>
  1346. <description>An authorization request was removed.</description>
  1347. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1348. </rule>
  1349. <rule id="100202" level="4">
  1350. <!-- LOG_ID_CSF_ROLE_CHANGE -->
  1351. <if_sid>100010</if_sid>
  1352. <field name="logid">022046$</field>
  1353. <description>Device's authorization privilege changed.</description>
  1354. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1355. </rule>
  1356. <rule id="100203" level="4">
  1357. <!-- LOG_ID_CSF_FILE_MEM_USAGE -->
  1358. <if_sid>100010</if_sid>
  1359. <field name="logid">022047$</field>
  1360. <description>CSF daemon files memory usage warning.</description>
  1361. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1362. </rule>
  1363. <rule id="100204" level="4">
  1364. <!-- LOG_ID_CSF_ADVPN_SYNC -->
  1365. <if_sid>100010</if_sid>
  1366. <field name="logid">022048$</field>
  1367. <description>Fabric ADVPN configuration synchronized from root.</description>
  1368. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1369. </rule>
  1370. <rule id="100205" level="4">
  1371. <!-- LOG_ID_CSF_DAEMON_CLOSE -->
  1372. <if_sid>100010</if_sid>
  1373. <field name="logid">022049$</field>
  1374. <description>Daemon csfd has closed.</description>
  1375. <group>fortios.event.event,fortios.category.system,fortios.severity.debug</group>
  1376. </rule>
  1377. <rule id="100206" level="4">
  1378. <!-- LOG_ID_IPAMD_ADDRESS_ALLOCATED -->
  1379. <if_sid>100010</if_sid>
  1380. <field name="logid">022050$</field>
  1381. <description>Address allocated by FortiIPAM and applied to an interface</description>
  1382. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1383. </rule>
  1384. <rule id="100207" level="4">
  1385. <!-- LOG_ID_IPAMD_ADDRESS_SET_FAILED -->
  1386. <if_sid>100010</if_sid>
  1387. <field name="logid">022051$</field>
  1388. <description>Address received from FortiIPAM could not be applied to the interface</description>
  1389. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1390. </rule>
  1391. <rule id="100208" level="4">
  1392. <!-- LOG_ID_IPAMD_ADDRESS_INVALIDATED -->
  1393. <if_sid>100010</if_sid>
  1394. <field name="logid">022052$</field>
  1395. <description>FortiIPAM indicated that the address was no longer allocated to the interface</description>
  1396. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1397. </rule>
  1398. <rule id="100209" level="4">
  1399. <!-- LOG_ID_IPAMD_VALIDATION_COMPLETE -->
  1400. <if_sid>100010</if_sid>
  1401. <field name="logid">022053$</field>
  1402. <description>Startup validation of IPAM addresses was completed</description>
  1403. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1404. </rule>
  1405. <rule id="100210" level="4">
  1406. <!-- LOG_ID_IPAMSD_ADDRESS_ALLOCATED -->
  1407. <if_sid>100010</if_sid>
  1408. <field name="logid">022060$</field>
  1409. <description>Address allocated to IPAM interface</description>
  1410. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1411. </rule>
  1412. <rule id="100211" level="4">
  1413. <!-- LOG_ID_IPAMSD_ADDRESS_FREED -->
  1414. <if_sid>100010</if_sid>
  1415. <field name="logid">022061$</field>
  1416. <description>Address freed by IPAM interface</description>
  1417. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1418. </rule>
  1419. <rule id="100212" level="4">
  1420. <!-- LOG_ID_IPAMSD_FLAG_CONFLICT -->
  1421. <if_sid>100010</if_sid>
  1422. <field name="logid">022062$</field>
  1423. <description>Flag IPAM entry as conflict</description>
  1424. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1425. </rule>
  1426. <rule id="100213" level="4">
  1427. <!-- LOG_ID_IPAMSD_UNFLAG_CONFLICT -->
  1428. <if_sid>100010</if_sid>
  1429. <field name="logid">022063$</field>
  1430. <description>Unflag IPAM entry as conflict</description>
  1431. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1432. </rule>
  1433. <rule id="100214" level="4">
  1434. <!-- LOG_ID_PROVISION_LATEST_SUCCEEDED -->
  1435. <if_sid>100010</if_sid>
  1436. <field name="logid">022080$</field>
  1437. <description>Provisioning of latest firmware was completed</description>
  1438. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1439. </rule>
  1440. <rule id="100215" level="4">
  1441. <!-- LOG_ID_PROVISION_LATEST_FAILED -->
  1442. <if_sid>100010</if_sid>
  1443. <field name="logid">022081$</field>
  1444. <description>Provisioning of latest firmware failed</description>
  1445. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1446. </rule>
  1447. <rule id="100216" level="4">
  1448. <!-- LOG_ID_DEVICE_UPGRADE_SUCCEEDED -->
  1449. <if_sid>100010</if_sid>
  1450. <field name="logid">022085$</field>
  1451. <description>A device upgrade was completed</description>
  1452. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1453. </rule>
  1454. <rule id="100217" level="4">
  1455. <!-- LOG_ID_DEVICE_UPGRADE_FAILED -->
  1456. <if_sid>100010</if_sid>
  1457. <field name="logid">022086$</field>
  1458. <description>A device upgrade failed</description>
  1459. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1460. </rule>
  1461. <rule id="100218" level="4">
  1462. <!-- LOG_ID_FEDERATED_UPGRADE_CANCELLED -->
  1463. <if_sid>100010</if_sid>
  1464. <field name="logid">022090$</field>
  1465. <description>A federated upgrade was cancelled due to the CSF tree not being ready</description>
  1466. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1467. </rule>
  1468. <rule id="100219" level="4">
  1469. <!-- LOG_ID_FEDERATED_UPGRADE_SUCCEEDED -->
  1470. <if_sid>100010</if_sid>
  1471. <field name="logid">022091$</field>
  1472. <description>A federated upgrade was completed successfully</description>
  1473. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1474. </rule>
  1475. <rule id="100220" level="4">
  1476. <!-- LOG_ID_FEDERATED_UPGRADE_FAILED -->
  1477. <if_sid>100010</if_sid>
  1478. <field name="logid">022092$</field>
  1479. <description>A federated upgrade failed</description>
  1480. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1481. </rule>
  1482. <rule id="100221" level="4">
  1483. <!-- LOG_ID_FEDERATED_UPGRADE_STEP_COMPLETE -->
  1484. <if_sid>100010</if_sid>
  1485. <field name="logid">022093$</field>
  1486. <description>A step in a multi-step federated upgrade was completed</description>
  1487. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1488. </rule>
  1489. <rule id="100222" level="4">
  1490. <!-- LOG_ID_FEDERATED_UPGRADE_ROOT_COMPLETED -->
  1491. <if_sid>100010</if_sid>
  1492. <field name="logid">022094$</field>
  1493. <description>A federated upgrade was completed by the root FortiGate</description>
  1494. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1495. </rule>
  1496. <rule id="100223" level="4">
  1497. <!-- LOG_ID_FEDERATED_UPGRADE_ROOT_NOT_COMPLETED -->
  1498. <if_sid>100010</if_sid>
  1499. <field name="logid">022095$</field>
  1500. <description>A federated upgrade could not be completed by the root FortiGate</description>
  1501. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1502. </rule>
  1503. <rule id="100224" level="4">
  1504. <!-- LOG_ID_QUAR_DROP_TRAN_JOB -->
  1505. <if_sid>100010</if_sid>
  1506. <field name="logid">022100$</field>
  1507. <description>Files dropped by quarantine daemon</description>
  1508. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1509. </rule>
  1510. <rule id="100225" level="4">
  1511. <!-- LOG_ID_QUAR_DROP_TLL_JOB -->
  1512. <if_sid>100010</if_sid>
  1513. <field name="logid">022101$</field>
  1514. <description>Files dropped due to poor network connection</description>
  1515. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1516. </rule>
  1517. <rule id="100226" level="4">
  1518. <!-- LOG_ID_LOG_DISK_FAILURE -->
  1519. <if_sid>100010</if_sid>
  1520. <field name="logid">022102$</field>
  1521. <description>Log disk failure imminent</description>
  1522. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1523. </rule>
  1524. <rule id="100227" level="4">
  1525. <!-- LOG_ID_QUAR_LIMIT_REACHED -->
  1526. <if_sid>100010</if_sid>
  1527. <field name="logid">022103$</field>
  1528. <description>Sandbox limit reached</description>
  1529. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1530. </rule>
  1531. <rule id="100228" level="4">
  1532. <!-- LOG_ID_POWER_RESTORE -->
  1533. <if_sid>100010</if_sid>
  1534. <field name="logid">022104$</field>
  1535. <description>Power supply restored</description>
  1536. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1537. </rule>
  1538. <rule id="100229" level="4">
  1539. <!-- LOG_ID_POWER_FAILURE -->
  1540. <if_sid>100010</if_sid>
  1541. <field name="logid">022105$</field>
  1542. <description>Power supply failed</description>
  1543. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1544. </rule>
  1545. <rule id="100230" level="4">
  1546. <!-- LOG_ID_POWER_OPTIONAL_NOT_DETECTED -->
  1547. <if_sid>100010</if_sid>
  1548. <field name="logid">022106$</field>
  1549. <description>Optional power supply not detected</description>
  1550. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1551. </rule>
  1552. <rule id="100231" level="4">
  1553. <!-- LOG_ID_VOLT_ANOM -->
  1554. <if_sid>100010</if_sid>
  1555. <field name="logid">022107$</field>
  1556. <description>Voltage anomaly</description>
  1557. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1558. </rule>
  1559. <rule id="100232" level="4">
  1560. <!-- LOG_ID_FAN_ANOM -->
  1561. <if_sid>100010</if_sid>
  1562. <field name="logid">022108$</field>
  1563. <description>Fan anomaly</description>
  1564. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1565. </rule>
  1566. <rule id="100233" level="4">
  1567. <!-- LOG_ID_TEMP_TOO_HIGH -->
  1568. <if_sid>100010</if_sid>
  1569. <field name="logid">022109$</field>
  1570. <description>Temperature too high</description>
  1571. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1572. </rule>
  1573. <rule id="100234" level="4">
  1574. <!-- LOG_ID_SPARE_BLOCK_LOW -->
  1575. <if_sid>100010</if_sid>
  1576. <field name="logid">022110$</field>
  1577. <description>Spare blocks availability low</description>
  1578. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1579. </rule>
  1580. <rule id="100235" level="4">
  1581. <!-- LOG_ID_PSU_ACTION_FPC_DOWN -->
  1582. <if_sid>100010</if_sid>
  1583. <field name="logid">022111$</field>
  1584. <description>FPC down due to PSU action</description>
  1585. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  1586. </rule>
  1587. <rule id="100236" level="4">
  1588. <!-- LOG_ID_PSU_ACTION_FPC_UP -->
  1589. <if_sid>100010</if_sid>
  1590. <field name="logid">022112$</field>
  1591. <description>FPC up due to PSU action</description>
  1592. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1593. </rule>
  1594. <rule id="100237" level="4">
  1595. <!-- LOG_ID_FNBAM_FAILURE -->
  1596. <if_sid>100010</if_sid>
  1597. <field name="logid">022113$</field>
  1598. <description>Authentication error</description>
  1599. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1600. </rule>
  1601. <rule id="100238" level="4">
  1602. <!-- LOG_ID_POWER_FAILURE_WARNING -->
  1603. <if_sid>100010</if_sid>
  1604. <field name="logid">022114$</field>
  1605. <description>Power supply failed warning</description>
  1606. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1607. </rule>
  1608. <rule id="100239" level="4">
  1609. <!-- LOG_ID_POWER_RESTORE_NOTIF -->
  1610. <if_sid>100010</if_sid>
  1611. <field name="logid">022115$</field>
  1612. <description>Power supply restored notification</description>
  1613. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1614. </rule>
  1615. <rule id="100240" level="4">
  1616. <!-- LOG_ID_POWER_REDUNDANCY_DEGRADE -->
  1617. <if_sid>100010</if_sid>
  1618. <field name="logid">022116$</field>
  1619. <description>Power Supply Redundancy Degrade</description>
  1620. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1621. </rule>
  1622. <rule id="100241" level="4">
  1623. <!-- LOG_ID_POWER_REDUNDANCY_FAILURE -->
  1624. <if_sid>100010</if_sid>
  1625. <field name="logid">022117$</field>
  1626. <description>Power Supply Redundancy Lost</description>
  1627. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1628. </rule>
  1629. <rule id="100242" level="4">
  1630. <!-- LOG_ID_VOLT_NOM -->
  1631. <if_sid>100010</if_sid>
  1632. <field name="logid">022150$</field>
  1633. <description>Voltage normal</description>
  1634. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1635. </rule>
  1636. <rule id="100243" level="4">
  1637. <!-- LOG_ID_FAN_NOM -->
  1638. <if_sid>100010</if_sid>
  1639. <field name="logid">022151$</field>
  1640. <description>Fan normal</description>
  1641. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1642. </rule>
  1643. <rule id="100244" level="4">
  1644. <!-- LOG_ID_TEMP_TOO_LOW -->
  1645. <if_sid>100010</if_sid>
  1646. <field name="logid">022152$</field>
  1647. <description>Temperature too low</description>
  1648. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1649. </rule>
  1650. <rule id="100245" level="4">
  1651. <!-- LOG_ID_TEMP_NORM -->
  1652. <if_sid>100010</if_sid>
  1653. <field name="logid">022153$</field>
  1654. <description>Temperature normal</description>
  1655. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1656. </rule>
  1657. <rule id="100246" level="4">
  1658. <!-- LOG_ID_AUTO_UPT_CERT -->
  1659. <if_sid>100010</if_sid>
  1660. <field name="logid">022200$</field>
  1661. <description>Certificate will be auto-updated</description>
  1662. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1663. </rule>
  1664. <rule id="100247" level="4">
  1665. <!-- LOG_ID_AUTO_GEN_CERT -->
  1666. <if_sid>100010</if_sid>
  1667. <field name="logid">022201$</field>
  1668. <description>Certificate will be auto-regenerated</description>
  1669. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1670. </rule>
  1671. <rule id="100248" level="4">
  1672. <!-- LOG_ID_AUTO_GEN_CERT_FAIL -->
  1673. <if_sid>100010</if_sid>
  1674. <field name="logid">022203$</field>
  1675. <description>Certificate failed to auto-generate</description>
  1676. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  1677. </rule>
  1678. <rule id="100249" level="4">
  1679. <!-- LOG_ID_AUTO_GEN_CERT_PENDING -->
  1680. <if_sid>100010</if_sid>
  1681. <field name="logid">022204$</field>
  1682. <description>Certificate pending to auto-generate</description>
  1683. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1684. </rule>
  1685. <rule id="100250" level="4">
  1686. <!-- LOG_ID_AUTO_GEN_CERT_SUCC -->
  1687. <if_sid>100010</if_sid>
  1688. <field name="logid">022205$</field>
  1689. <description>Certificate succeed to auto-generate</description>
  1690. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1691. </rule>
  1692. <rule id="100251" level="4">
  1693. <!-- LOG_ID_CRL_EXPIRED -->
  1694. <if_sid>100010</if_sid>
  1695. <field name="logid">022206$</field>
  1696. <description>CRL is expired</description>
  1697. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1698. </rule>
  1699. <rule id="100252" level="4">
  1700. <!-- LOG_ID_CERT_EXPIRE_WARNING -->
  1701. <if_sid>100010</if_sid>
  1702. <field name="logid">022207$</field>
  1703. <description>Certificate will expire soon</description>
  1704. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1705. </rule>
  1706. <rule id="100253" level="4">
  1707. <!-- LOG_ID_EXT_RESOURCE -->
  1708. <if_sid>100010</if_sid>
  1709. <field name="logid">022220$</field>
  1710. <description>Threat feed updated</description>
  1711. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  1712. </rule>
  1713. <rule id="100254" level="4">
  1714. <!-- LOG_ID_EXT_RESOURCE_FAIL -->
  1715. <if_sid>100010</if_sid>
  1716. <field name="logid">022221$</field>
  1717. <description>Threat feed update failed</description>
  1718. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1719. </rule>
  1720. <rule id="100255" level="4">
  1721. <!-- LOG_ID_EXT_RESOURCE_LOAD -->
  1722. <if_sid>100010</if_sid>
  1723. <field name="logid">022222$</field>
  1724. <description>Threat feed loaded</description>
  1725. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1726. </rule>
  1727. <rule id="100256" level="4">
  1728. <!-- LOG_ID_EXT_RESOURCE_DEBUG -->
  1729. <if_sid>100010</if_sid>
  1730. <field name="logid">022223$</field>
  1731. <description>Threat feed debug</description>
  1732. <group>fortios.event.event,fortios.category.system,fortios.severity.debug</group>
  1733. </rule>
  1734. <rule id="100257" level="4">
  1735. <!-- LOG_ID_IPS_FAIL_OPEN -->
  1736. <if_sid>100010</if_sid>
  1737. <field name="logid">022700$</field>
  1738. <description>IPS session scan paused</description>
  1739. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1740. </rule>
  1741. <rule id="100258" level="4">
  1742. <!-- LOG_ID_IPS_FAIL_OPEN_END -->
  1743. <if_sid>100010</if_sid>
  1744. <field name="logid">022701$</field>
  1745. <description>IPS session scan resumed</description>
  1746. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1747. </rule>
  1748. <rule id="100259" level="4">
  1749. <!-- LOG_ID_SCAN_SERV_FAIL -->
  1750. <if_sid>100010</if_sid>
  1751. <field name="logid">022800$</field>
  1752. <description>Scan services session failed</description>
  1753. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1754. </rule>
  1755. <rule id="100260" level="4">
  1756. <!-- LOG_ID_ENTER_FD_CONSERVE_MODE -->
  1757. <if_sid>100010</if_sid>
  1758. <field name="logid">022802$</field>
  1759. <description>File descriptor conserve mode entered</description>
  1760. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1761. </rule>
  1762. <rule id="100261" level="4">
  1763. <!-- LOG_ID_LEAVE_FD_CONSERVE_MODE -->
  1764. <if_sid>100010</if_sid>
  1765. <field name="logid">022803$</field>
  1766. <description>File descriptor conserve mode exited</description>
  1767. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1768. </rule>
  1769. <rule id="100262" level="4">
  1770. <!-- LOG_ID_LIC_STATUS_CHG -->
  1771. <if_sid>100010</if_sid>
  1772. <field name="logid">022804$</field>
  1773. <description>License status changed</description>
  1774. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1775. </rule>
  1776. <rule id="100263" level="4">
  1777. <!-- LOG_ID_FAIL_TO_VALIDATE_LIC -->
  1778. <if_sid>100010</if_sid>
  1779. <field name="logid">022805$</field>
  1780. <description>License validation failure</description>
  1781. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1782. </rule>
  1783. <rule id="100264" level="4">
  1784. <!-- LOG_ID_DUP_LIC -->
  1785. <if_sid>100010</if_sid>
  1786. <field name="logid">022806$</field>
  1787. <description>Duplicate license detected</description>
  1788. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1789. </rule>
  1790. <rule id="100265" level="4">
  1791. <!-- LOG_ID_VDOM_LIC -->
  1792. <if_sid>100010</if_sid>
  1793. <field name="logid">022807$</field>
  1794. <description>VDOM license status changed</description>
  1795. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1796. </rule>
  1797. <rule id="100266" level="4">
  1798. <!-- LOG_ID_LIC_EXPIRE -->
  1799. <if_sid>100010</if_sid>
  1800. <field name="logid">022808$</field>
  1801. <description>VM license expired</description>
  1802. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  1803. </rule>
  1804. <rule id="100267" level="4">
  1805. <!-- LOG_ID_LIC_WILL_EXPIRE -->
  1806. <if_sid>100010</if_sid>
  1807. <field name="logid">022809$</field>
  1808. <description>VM license expiring</description>
  1809. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1810. </rule>
  1811. <rule id="100268" level="4">
  1812. <!-- LOG_ID_SCANUNIT_ERROR_BLOCK -->
  1813. <if_sid>100010</if_sid>
  1814. <field name="logid">022810$</field>
  1815. <description>Scan error - traffic blocked</description>
  1816. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  1817. </rule>
  1818. <rule id="100269" level="4">
  1819. <!-- LOG_ID_SCANUNIT_ERROR_PASS -->
  1820. <if_sid>100010</if_sid>
  1821. <field name="logid">022811$</field>
  1822. <description>Scan error - traffic passed</description>
  1823. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1824. </rule>
  1825. <rule id="100270" level="4">
  1826. <!-- LOG_ID_SCANUNIT_AVENG_RELOAD -->
  1827. <if_sid>100010</if_sid>
  1828. <field name="logid">022812$</field>
  1829. <description>Scanunit is reloading AV engine</description>
  1830. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1831. </rule>
  1832. <rule id="100271" level="4">
  1833. <!-- LOG_ID_SCANUNIT_AVDB_RELOAD -->
  1834. <if_sid>100010</if_sid>
  1835. <field name="logid">022813$</field>
  1836. <description>Scanunit reloaded AV Database</description>
  1837. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1838. </rule>
  1839. <rule id="100272" level="4">
  1840. <!-- LOG_ID_SCANUNIT_AVDB_RELOAD_ERROR -->
  1841. <if_sid>100010</if_sid>
  1842. <field name="logid">022814$</field>
  1843. <description>Scanunit AV Database reload error</description>
  1844. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  1845. </rule>
  1846. <rule id="100273" level="4">
  1847. <!-- LOG_ID_SCANUNIT_AVDB_LOAD -->
  1848. <if_sid>100010</if_sid>
  1849. <field name="logid">022815$</field>
  1850. <description>Scanunit loaded AV Database</description>
  1851. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  1852. </rule>
  1853. <rule id="100274" level="4">
  1854. <!-- LOG_ID_SCANUNIT_AVDB_LOAD_ERROR -->
  1855. <if_sid>100010</if_sid>
  1856. <field name="logid">022816$</field>
  1857. <description>Scanunit AV Database load error</description>
  1858. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  1859. </rule>
  1860. <rule id="100275" level="4">
  1861. <!-- LOG_ID_USER_QUARANTINE_MAC_ADD -->
  1862. <if_sid>100010</if_sid>
  1863. <field name="logid">022850$</field>
  1864. <description>User quarantine MAC added</description>
  1865. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  1866. </rule>
  1867. <rule id="100276" level="4">
  1868. <!-- LOG_ID_USER_QUARANTINE_MAC_DELETE -->
  1869. <if_sid>100010</if_sid>
  1870. <field name="logid">022851$</field>
  1871. <description>User quarantine MAC deleted</description>
  1872. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  1873. </rule>
  1874. <rule id="100277" level="4">
  1875. <!-- LOG_ID_USER_QUARANTINE_MAC_BOUNCE_PORT_HIT -->
  1876. <if_sid>100010</if_sid>
  1877. <field name="logid">022852$</field>
  1878. <description>User quarantine MAC bounce port hit</description>
  1879. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  1880. </rule>
  1881. <rule id="100278" level="4">
  1882. <!-- LOG_ID_USER_QUARANTINE_MAC_BOUNCE_PORT_MISS -->
  1883. <if_sid>100010</if_sid>
  1884. <field name="logid">022853$</field>
  1885. <description>User quarantine MAC bounce port miss</description>
  1886. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.warning</group>
  1887. </rule>
  1888. <rule id="100279" level="4">
  1889. <!-- LOG_ID_FLPOLD_NAC_ADD -->
  1890. <if_sid>100010</if_sid>
  1891. <field name="logid">022861$</field>
  1892. <description>NAC device addition</description>
  1893. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1894. </rule>
  1895. <rule id="100280" level="4">
  1896. <!-- LOG_ID_FLPOLD_NAC_DELETE -->
  1897. <if_sid>100010</if_sid>
  1898. <field name="logid">022862$</field>
  1899. <description>NAC device deletion</description>
  1900. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1901. </rule>
  1902. <rule id="100281" level="4">
  1903. <!-- LOG_ID_FLPOLD_NAC_MODIFY -->
  1904. <if_sid>100010</if_sid>
  1905. <field name="logid">022863$</field>
  1906. <description>NAC device modify</description>
  1907. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1908. </rule>
  1909. <rule id="100282" level="4">
  1910. <!-- LOG_ID_FLPOLD_DPP_ADD -->
  1911. <if_sid>100010</if_sid>
  1912. <field name="logid">022864$</field>
  1913. <description>DPP device addition</description>
  1914. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1915. </rule>
  1916. <rule id="100283" level="4">
  1917. <!-- LOG_ID_FLPOLD_DPP_DELETE -->
  1918. <if_sid>100010</if_sid>
  1919. <field name="logid">022865$</field>
  1920. <description>DPP device deletion</description>
  1921. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1922. </rule>
  1923. <rule id="100284" level="4">
  1924. <!-- LOG_ID_FLPOLD_DPP_MODIFY -->
  1925. <if_sid>100010</if_sid>
  1926. <field name="logid">022866$</field>
  1927. <description>DPP device modify</description>
  1928. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1929. </rule>
  1930. <rule id="100285" level="4">
  1931. <!-- LOG_ID_FLPOLD_DPP_INTF_TAGS_ADD -->
  1932. <if_sid>100010</if_sid>
  1933. <field name="logid">022867$</field>
  1934. <description>DPP interface tags add</description>
  1935. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1936. </rule>
  1937. <rule id="100286" level="4">
  1938. <!-- LOG_ID_FLPOLD_DPP_INTF_TAGS_DELETE -->
  1939. <if_sid>100010</if_sid>
  1940. <field name="logid">022868$</field>
  1941. <description>DPP interface tags delete</description>
  1942. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1943. </rule>
  1944. <rule id="100287" level="4">
  1945. <!-- LOG_ID_FLPOLD_NAC_DYNAMIC_ADDRESS_ADD -->
  1946. <if_sid>100010</if_sid>
  1947. <field name="logid">022869$</field>
  1948. <description>NAC device dynamic address addition</description>
  1949. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1950. </rule>
  1951. <rule id="100288" level="4">
  1952. <!-- LOG_ID_FLPOLD_NAC_DYNAMIC_ADDRESS_DELETE -->
  1953. <if_sid>100010</if_sid>
  1954. <field name="logid">022870$</field>
  1955. <description>NAC device dynamic address deletion</description>
  1956. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1957. </rule>
  1958. <rule id="100289" level="4">
  1959. <!-- LOG_ID_FLPOLD_NAC_MAC_CACHE_SYNC -->
  1960. <if_sid>100010</if_sid>
  1961. <field name="logid">022871$</field>
  1962. <description>NAC MAC cache sync</description>
  1963. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1964. </rule>
  1965. <rule id="100290" level="4">
  1966. <!-- LOG_ID_FLPOLD_NAC_MAX_ERROR -->
  1967. <if_sid>100010</if_sid>
  1968. <field name="logid">022872$</field>
  1969. <description>NAC device Max Limit Error</description>
  1970. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.warning</group>
  1971. </rule>
  1972. <rule id="100291" level="4">
  1973. <!-- LOG_ID_FLPOLD_DPP_MAX_ERROR -->
  1974. <if_sid>100010</if_sid>
  1975. <field name="logid">022873$</field>
  1976. <description>DPP device Max Limit Error</description>
  1977. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.warning</group>
  1978. </rule>
  1979. <rule id="100292" level="4">
  1980. <!-- LOG_ID_FORTILINKD -->
  1981. <if_sid>100010</if_sid>
  1982. <field name="logid">022890$</field>
  1983. <description>Switch-Controller Daemon Log (Notification)</description>
  1984. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  1985. </rule>
  1986. <rule id="100293" level="4">
  1987. <!-- LOG_ID_FLCFGD_SYNC_ERROR -->
  1988. <if_sid>100010</if_sid>
  1989. <field name="logid">022891$</field>
  1990. <description>Switch-Controller Switch Sync Error</description>
  1991. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.error</group>
  1992. </rule>
  1993. <rule id="100294" level="4">
  1994. <!-- LOG_ID_FLCFGD_SYNC_COMPLETE -->
  1995. <if_sid>100010</if_sid>
  1996. <field name="logid">022892$</field>
  1997. <description>Switch-Controller Switch Sync Complete</description>
  1998. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  1999. </rule>
  2000. <rule id="100295" level="4">
  2001. <!-- LOG_ID_FLCFGD_SYNC_STATE -->
  2002. <if_sid>100010</if_sid>
  2003. <field name="logid">022893$</field>
  2004. <description>Switch-Controller Switch Sync State</description>
  2005. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.debug</group>
  2006. </rule>
  2007. <rule id="100296" level="4">
  2008. <!-- LOG_ID_FLCFGD_UPGRADE_ERROR -->
  2009. <if_sid>100010</if_sid>
  2010. <field name="logid">022894$</field>
  2011. <description>Switch-Controller Switch Upgrade Error</description>
  2012. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.error</group>
  2013. </rule>
  2014. <rule id="100297" level="4">
  2015. <!-- LOG_ID_FLCFGD_UPGRADE_STATUS -->
  2016. <if_sid>100010</if_sid>
  2017. <field name="logid">022895$</field>
  2018. <description>Switch-Controller Switch Upgrade Status</description>
  2019. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  2020. </rule>
  2021. <rule id="100298" level="4">
  2022. <!-- LOG_ID_FORTILINKD_CRITICAL -->
  2023. <if_sid>100010</if_sid>
  2024. <field name="logid">022896$</field>
  2025. <description>Switch-Controller Daemon Log (Critical)</description>
  2026. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  2027. </rule>
  2028. <rule id="100299" level="4">
  2029. <!-- LOG_ID_FORTILINKD_SPLIT_PORT_INFO -->
  2030. <if_sid>100010</if_sid>
  2031. <field name="logid">022897$</field>
  2032. <description>Switch-controller split-port related configuration change detected</description>
  2033. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  2034. </rule>
  2035. <rule id="100300" level="4">
  2036. <!-- LOG_ID_CAPUTP_SESSION -->
  2037. <if_sid>100010</if_sid>
  2038. <field name="logid">022900$</field>
  2039. <description>CAPUTP session status</description>
  2040. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  2041. </rule>
  2042. <rule id="100301" level="4">
  2043. <!-- LOG_ID_FAZ_CON -->
  2044. <if_sid>100010</if_sid>
  2045. <field name="logid">022901$</field>
  2046. <description>FortiAnalyzer connection up</description>
  2047. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2048. </rule>
  2049. <rule id="100302" level="4">
  2050. <!-- LOG_ID_FAZ_DISCON -->
  2051. <if_sid>100010</if_sid>
  2052. <field name="logid">022902$</field>
  2053. <description>FortiAnalyzer connection down</description>
  2054. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2055. </rule>
  2056. <rule id="100303" level="4">
  2057. <!-- LOG_ID_FAZ_CON_ERR -->
  2058. <if_sid>100010</if_sid>
  2059. <field name="logid">022903$</field>
  2060. <description>FortiAnalyzer connection failed</description>
  2061. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2062. </rule>
  2063. <rule id="100304" level="4">
  2064. <!-- LOG_ID_CAPUTP_SESSION_NOTIF -->
  2065. <if_sid>100010</if_sid>
  2066. <field name="logid">022904$</field>
  2067. <description>CAPUTP session status notification</description>
  2068. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  2069. </rule>
  2070. <rule id="100305" level="4">
  2071. <!-- LOG_ID_FDS_SRV_ERRCON -->
  2072. <if_sid>100010</if_sid>
  2073. <field name="logid">022912$</field>
  2074. <description>FortiGate Cloud server connection failed</description>
  2075. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2076. </rule>
  2077. <rule id="100306" level="4">
  2078. <!-- LOG_ID_FDS_SRV_DISCON -->
  2079. <if_sid>100010</if_sid>
  2080. <field name="logid">022913$</field>
  2081. <description>FortiGate Cloud server disconnected</description>
  2082. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2083. </rule>
  2084. <rule id="100307" level="4">
  2085. <!-- LOG_ID_FDS_SRV_CON -->
  2086. <if_sid>100010</if_sid>
  2087. <field name="logid">022915$</field>
  2088. <description>FortiGate Cloud server connected</description>
  2089. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2090. </rule>
  2091. <rule id="100308" level="4">
  2092. <!-- LOG_ID_FDS_STATUS -->
  2093. <if_sid>100010</if_sid>
  2094. <field name="logid">022916$</field>
  2095. <description>FortiGuard Message Service status</description>
  2096. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2097. </rule>
  2098. <rule id="100309" level="4">
  2099. <!-- LOG_ID_FDS_SMS_QUOTA -->
  2100. <if_sid>100010</if_sid>
  2101. <field name="logid">022917$</field>
  2102. <description>SMS quota reached</description>
  2103. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2104. </rule>
  2105. <rule id="100310" level="4">
  2106. <!-- LOG_ID_FDS_CTRL_STATUS -->
  2107. <if_sid>100010</if_sid>
  2108. <field name="logid">022918$</field>
  2109. <description>FortiGuard Message Service controller status</description>
  2110. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2111. </rule>
  2112. <rule id="100311" level="4">
  2113. <!-- LOG_ID_SVR_LOG_STATUS_CHANGED -->
  2114. <if_sid>100010</if_sid>
  2115. <field name="logid">022919$</field>
  2116. <description>Server logging status changed</description>
  2117. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2118. </rule>
  2119. <rule id="100312" level="4">
  2120. <!-- LOG_ID_EVENT_ROUTE_INFO_CHANGED -->
  2121. <if_sid>100010</if_sid>
  2122. <field name="logid">022921$</field>
  2123. <description>Routing information changed</description>
  2124. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2125. </rule>
  2126. <rule id="100313" level="4">
  2127. <!-- LOG_ID_EVENT_LINK_MONITOR_STATUS -->
  2128. <if_sid>100010</if_sid>
  2129. <field name="logid">022922$</field>
  2130. <description>Link monitor status</description>
  2131. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2132. </rule>
  2133. <rule id="100314" level="4">
  2134. <!-- LOG_ID_EVENT_VWL_LQTY_STATUS -->
  2135. <if_sid>100010</if_sid>
  2136. <field name="logid">022923$</field>
  2137. <description>SDWAN status</description>
  2138. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  2139. </rule>
  2140. <rule id="100315" level="4">
  2141. <!-- LOG_ID_EVENT_VWL_VOLUME_STATUS -->
  2142. <if_sid>100010</if_sid>
  2143. <field name="logid">022924$</field>
  2144. <description>SDWAN volume status</description>
  2145. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  2146. </rule>
  2147. <rule id="100316" level="4">
  2148. <!-- LOG_ID_EVENT_VWL_SLA_INFO -->
  2149. <if_sid>100010</if_sid>
  2150. <field name="logid">022925$</field>
  2151. <description>SDWAN SLA information</description>
  2152. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.information</group>
  2153. </rule>
  2154. <rule id="100317" level="4">
  2155. <!-- LOG_ID_EVENT_VWL_NEIGHBOR_STATUS -->
  2156. <if_sid>100010</if_sid>
  2157. <field name="logid">022926$</field>
  2158. <description>SDWAN Neighbor status</description>
  2159. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  2160. </rule>
  2161. <rule id="100318" level="4">
  2162. <!-- LOG_ID_EVENT_VWL_NEIGHBOR_STANDALONE -->
  2163. <if_sid>100010</if_sid>
  2164. <field name="logid">022927$</field>
  2165. <description>SDWAN Neighbor standalone</description>
  2166. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  2167. </rule>
  2168. <rule id="100319" level="4">
  2169. <!-- LOG_ID_EVENT_VWL_NEIGHBOR_PRIMARY -->
  2170. <if_sid>100010</if_sid>
  2171. <field name="logid">022928$</field>
  2172. <description>SDWAN Neighbor primary</description>
  2173. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  2174. </rule>
  2175. <rule id="100320" level="4">
  2176. <!-- LOG_ID_EVENT_VWL_NEIGHBOR_SECONDARY -->
  2177. <if_sid>100010</if_sid>
  2178. <field name="logid">022929$</field>
  2179. <description>SDWAN Neighbor secondary</description>
  2180. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.warning</group>
  2181. </rule>
  2182. <rule id="100321" level="4">
  2183. <!-- LOG_ID_EVENT_VWL_LQTY_STATUS_WARNING -->
  2184. <if_sid>100010</if_sid>
  2185. <field name="logid">022930$</field>
  2186. <description>SDWAN status warning</description>
  2187. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.warning</group>
  2188. </rule>
  2189. <rule id="100322" level="4">
  2190. <!-- LOG_ID_EVENT_VWL_SLA_INFO_WARNING -->
  2191. <if_sid>100010</if_sid>
  2192. <field name="logid">022931$</field>
  2193. <description>SDWAN SLA information warning</description>
  2194. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.warning</group>
  2195. </rule>
  2196. <rule id="100323" level="4">
  2197. <!-- LOG_ID_EVENT_LINK_MONITOR_STATUS_WARNING -->
  2198. <if_sid>100010</if_sid>
  2199. <field name="logid">022932$</field>
  2200. <description>Link monitor status warning</description>
  2201. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2202. </rule>
  2203. <rule id="100324" level="4">
  2204. <!-- LOG_ID_EVENT_VWL_SLA_INFO_NOTIF -->
  2205. <if_sid>100010</if_sid>
  2206. <field name="logid">022933$</field>
  2207. <description>SDWAN SLA notification</description>
  2208. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  2209. </rule>
  2210. <rule id="100325" level="4">
  2211. <!-- LOG_ID_EVENT_VWL_LQTY_STATUS_INFO -->
  2212. <if_sid>100010</if_sid>
  2213. <field name="logid">022934$</field>
  2214. <description>SDWAN status information</description>
  2215. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.information</group>
  2216. </rule>
  2217. <rule id="100326" level="4">
  2218. <!-- LOG_ID_EVENT_VWL_LQTY_STATUS_DEBUG -->
  2219. <if_sid>100010</if_sid>
  2220. <field name="logid">022935$</field>
  2221. <description>SDWAN status debug</description>
  2222. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.debug</group>
  2223. </rule>
  2224. <rule id="100327" level="4">
  2225. <!-- LOG_ID_EVENT_VWL_INET_SVC_PQTY_STATUS_INFO -->
  2226. <if_sid>100010</if_sid>
  2227. <field name="logid">022936$</field>
  2228. <description>Virtual WAN Link internet service passive quality information</description>
  2229. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.information</group>
  2230. </rule>
  2231. <rule id="100328" level="4">
  2232. <!-- LOG_ID_FDS_JOIN -->
  2233. <if_sid>100010</if_sid>
  2234. <field name="logid">022949$</field>
  2235. <description>FortiGate Cloud auto-join attempted</description>
  2236. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2237. </rule>
  2238. <rule id="100329" level="4">
  2239. <!-- LOG_ID_FDS_LOGIN_SUCC -->
  2240. <if_sid>100010</if_sid>
  2241. <field name="logid">022950$</field>
  2242. <description>FortiGate Cloud activation successful</description>
  2243. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2244. </rule>
  2245. <rule id="100330" level="4">
  2246. <!-- LOG_ID_FDS_LOGOUT -->
  2247. <if_sid>100010</if_sid>
  2248. <field name="logid">022951$</field>
  2249. <description>FortiGate Cloud logout</description>
  2250. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2251. </rule>
  2252. <rule id="100331" level="4">
  2253. <!-- LOG_ID_FDS_LOGIN_FAIL -->
  2254. <if_sid>100010</if_sid>
  2255. <field name="logid">022952$</field>
  2256. <description>FortiGate Cloud activation failed</description>
  2257. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2258. </rule>
  2259. <rule id="100332" level="4">
  2260. <!-- LOG_ID_INET_SVC_OBSOLETE -->
  2261. <if_sid>100010</if_sid>
  2262. <field name="logid">022954$</field>
  2263. <description>Internet Service obsolete</description>
  2264. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2265. </rule>
  2266. <rule id="100333" level="4">
  2267. <!-- LOG_ID_INET_SVC_NAME_FAILURE -->
  2268. <if_sid>100010</if_sid>
  2269. <field name="logid">022955$</field>
  2270. <description>Internet Service name update failed</description>
  2271. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2272. </rule>
  2273. <rule id="100334" level="4">
  2274. <!-- LOG_ID_INET_SVC_NAME_UPDATE -->
  2275. <if_sid>100010</if_sid>
  2276. <field name="logid">022956$</field>
  2277. <description>Internet Service name update</description>
  2278. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2279. </rule>
  2280. <rule id="100335" level="4">
  2281. <!-- LOG_ID_IPSEC_TUNNEL_UP -->
  2282. <if_sid>100010</if_sid>
  2283. <field name="logid">023101$</field>
  2284. <description>IPsec VPN tunnel up</description>
  2285. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  2286. </rule>
  2287. <rule id="100336" level="4">
  2288. <!-- LOG_ID_IPSEC_TUNNEL_DOWN -->
  2289. <if_sid>100010</if_sid>
  2290. <field name="logid">023102$</field>
  2291. <description>IPsec VPN tunnel down</description>
  2292. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  2293. </rule>
  2294. <rule id="100337" level="4">
  2295. <!-- LOG_ID_IPSEC_TUNNEL_STAT -->
  2296. <if_sid>100010</if_sid>
  2297. <field name="logid">023103$</field>
  2298. <description>IPsec VPN tunnel statistics</description>
  2299. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  2300. </rule>
  2301. <rule id="100338" level="4">
  2302. <!-- LOG_ID_DHCP_ACK -->
  2303. <if_sid>100010</if_sid>
  2304. <field name="logid">026001$</field>
  2305. <description>DHCP Ack log</description>
  2306. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2307. </rule>
  2308. <rule id="100339" level="4">
  2309. <!-- LOG_ID_DHCP_RELEASE -->
  2310. <if_sid>100010</if_sid>
  2311. <field name="logid">026002$</field>
  2312. <description>DHCP Release log</description>
  2313. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2314. </rule>
  2315. <rule id="100340" level="4">
  2316. <!-- LOG_ID_DHCP_STAT -->
  2317. <if_sid>100010</if_sid>
  2318. <field name="logid">026003$</field>
  2319. <description>DHCP statistics</description>
  2320. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2321. </rule>
  2322. <rule id="100341" level="4">
  2323. <!-- LOG_ID_DHCP_CLIENT_LEASE -->
  2324. <if_sid>100010</if_sid>
  2325. <field name="logid">026004$</field>
  2326. <description>DHCP client lease granted</description>
  2327. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2328. </rule>
  2329. <rule id="100342" level="4">
  2330. <!-- LOG_ID_DHCP_LEASE_USAGE_HIGH -->
  2331. <if_sid>100010</if_sid>
  2332. <field name="logid">026005$</field>
  2333. <description>DHCP lease usage high</description>
  2334. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2335. </rule>
  2336. <rule id="100343" level="4">
  2337. <!-- LOG_ID_DHCP_LEASE_USAGE_FULL -->
  2338. <if_sid>100010</if_sid>
  2339. <field name="logid">026006$</field>
  2340. <description>DHCP lease usage full</description>
  2341. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2342. </rule>
  2343. <rule id="100344" level="4">
  2344. <!-- LOG_ID_DHCP_BLOCKED_MAC -->
  2345. <if_sid>100010</if_sid>
  2346. <field name="logid">026007$</field>
  2347. <description>DHCP client blocked log</description>
  2348. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2349. </rule>
  2350. <rule id="100345" level="4">
  2351. <!-- LOG_ID_DHCP_DDNS_ADD -->
  2352. <if_sid>100010</if_sid>
  2353. <field name="logid">026008$</field>
  2354. <description>DHCP DDNS add query</description>
  2355. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2356. </rule>
  2357. <rule id="100346" level="4">
  2358. <!-- LOG_ID_DHCP_DDNS_DELETE -->
  2359. <if_sid>100010</if_sid>
  2360. <field name="logid">026009$</field>
  2361. <description>DHCP DDNS delete query</description>
  2362. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2363. </rule>
  2364. <rule id="100347" level="4">
  2365. <!-- LOG_ID_DHCP_DDNS_COMPLETED -->
  2366. <if_sid>100010</if_sid>
  2367. <field name="logid">026010$</field>
  2368. <description>DHCP DDNS query completed</description>
  2369. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2370. </rule>
  2371. <rule id="100348" level="4">
  2372. <!-- LOG_ID_DHCPV6_REPLY -->
  2373. <if_sid>100010</if_sid>
  2374. <field name="logid">026011$</field>
  2375. <description>DHCPv6 Ack log</description>
  2376. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2377. </rule>
  2378. <rule id="100349" level="4">
  2379. <!-- LOG_ID_DHCPV6_RELEASE -->
  2380. <if_sid>100010</if_sid>
  2381. <field name="logid">026012$</field>
  2382. <description>DHCPv6 Release log</description>
  2383. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2384. </rule>
  2385. <rule id="100350" level="4">
  2386. <!-- LOG_ID_VRRP_STATE_CHG -->
  2387. <if_sid>100010</if_sid>
  2388. <field name="logid">027001$</field>
  2389. <description>VRRP state changed</description>
  2390. <group>fortios.event.event,fortios.category.router,fortios.severity.information</group>
  2391. </rule>
  2392. <rule id="100351" level="4">
  2393. <!-- LOG_ID_PPPD_MSG -->
  2394. <if_sid>100010</if_sid>
  2395. <field name="logid">029001$</field>
  2396. <description>PPP status</description>
  2397. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2398. </rule>
  2399. <rule id="100352" level="4">
  2400. <!-- LOG_ID_PPPD_AUTH_SUC -->
  2401. <if_sid>100010</if_sid>
  2402. <field name="logid">029002$</field>
  2403. <description>PPP authentication successful</description>
  2404. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2405. </rule>
  2406. <rule id="100353" level="4">
  2407. <!-- LOG_ID_PPPD_AUTH_FAIL -->
  2408. <if_sid>100010</if_sid>
  2409. <field name="logid">029003$</field>
  2410. <description>PPP authentication failed</description>
  2411. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2412. </rule>
  2413. <rule id="100354" level="4">
  2414. <!-- LOG_ID_PPPD_MSG_ERROR -->
  2415. <if_sid>100010</if_sid>
  2416. <field name="logid">029004$</field>
  2417. <description>PPP status error message</description>
  2418. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  2419. </rule>
  2420. <rule id="100355" level="4">
  2421. <!-- LOG_ID_PPPD_MSG_DEBUG -->
  2422. <if_sid>100010</if_sid>
  2423. <field name="logid">029005$</field>
  2424. <description>PPP status debug message</description>
  2425. <group>fortios.event.event,fortios.category.system,fortios.severity.debug</group>
  2426. </rule>
  2427. <rule id="100356" level="4">
  2428. <!-- LOG_ID_PPPOE_STATUS_REPORT_NOTIF -->
  2429. <if_sid>100010</if_sid>
  2430. <field name="logid">029010$</field>
  2431. <description>PPPoE status report</description>
  2432. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2433. </rule>
  2434. <rule id="100357" level="4">
  2435. <!-- LOG_ID_PPPD_FAIL_TO_EXEC -->
  2436. <if_sid>100010</if_sid>
  2437. <field name="logid">029011$</field>
  2438. <description>PPP execution failed</description>
  2439. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  2440. </rule>
  2441. <rule id="100358" level="4">
  2442. <!-- LOG_ID_PPPD_START -->
  2443. <if_sid>100010</if_sid>
  2444. <field name="logid">029013$</field>
  2445. <description>PPP daemon started</description>
  2446. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2447. </rule>
  2448. <rule id="100359" level="4">
  2449. <!-- LOG_ID_PPPD_EXIT -->
  2450. <if_sid>100010</if_sid>
  2451. <field name="logid">029014$</field>
  2452. <description>PPP daemon exited</description>
  2453. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2454. </rule>
  2455. <rule id="100360" level="4">
  2456. <!-- LOG_ID_PPP_RCV_BAD_PEER_IP -->
  2457. <if_sid>100010</if_sid>
  2458. <field name="logid">029015$</field>
  2459. <description>PPP received invalid peer IP</description>
  2460. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  2461. </rule>
  2462. <rule id="100361" level="4">
  2463. <!-- LOG_ID_PPP_RCV_BAD_LOCAL_IP -->
  2464. <if_sid>100010</if_sid>
  2465. <field name="logid">029016$</field>
  2466. <description>PPP received invalid local IP</description>
  2467. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  2468. </rule>
  2469. <rule id="100362" level="4">
  2470. <!-- LOG_ID_EVENT_AUTH_SNMP_QUERY_FAILED -->
  2471. <if_sid>100010</if_sid>
  2472. <field name="logid">029021$</field>
  2473. <description>SNMP query failed</description>
  2474. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2475. </rule>
  2476. <rule id="100363" level="4">
  2477. <!-- LOG_ID_DDNS_UPDATE_FAIL -->
  2478. <if_sid>100010</if_sid>
  2479. <field name="logid">029022$</field>
  2480. <description>DDNS update failed</description>
  2481. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  2482. </rule>
  2483. <rule id="100364" level="4">
  2484. <!-- LOG_ID_ADMIN_LOGIN_SUCC -->
  2485. <if_sid>100010</if_sid>
  2486. <field name="logid">032001$</field>
  2487. <description>Admin login successful</description>
  2488. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2489. </rule>
  2490. <rule id="100365" level="4">
  2491. <!-- LOG_ID_ADMIN_LOGIN_FAIL -->
  2492. <if_sid>100010</if_sid>
  2493. <field name="logid">032002$</field>
  2494. <description>Admin login failed</description>
  2495. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  2496. </rule>
  2497. <rule id="100366" level="4">
  2498. <!-- LOG_ID_ADMIN_LOGOUT -->
  2499. <if_sid>100010</if_sid>
  2500. <field name="logid">032003$</field>
  2501. <description>Admin logout successful</description>
  2502. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2503. </rule>
  2504. <rule id="100367" level="4">
  2505. <!-- LOG_ID_ADMIN_OVERIDE_VDOM -->
  2506. <if_sid>100010</if_sid>
  2507. <field name="logid">032005$</field>
  2508. <description>Admin overrode VDOM</description>
  2509. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2510. </rule>
  2511. <rule id="100368" level="4">
  2512. <!-- LOG_ID_ADMIN_ENTER_VDOM -->
  2513. <if_sid>100010</if_sid>
  2514. <field name="logid">032006$</field>
  2515. <description>Super admin entered VDOM</description>
  2516. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2517. </rule>
  2518. <rule id="100369" level="4">
  2519. <!-- LOG_ID_ADMIN_LEFT_VDOM -->
  2520. <if_sid>100010</if_sid>
  2521. <field name="logid">032007$</field>
  2522. <description>Super admin left VDOM</description>
  2523. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2524. </rule>
  2525. <rule id="100370" level="4">
  2526. <!-- LOG_ID_VIEW_DISK_LOG_FAIL -->
  2527. <if_sid>100010</if_sid>
  2528. <field name="logid">032008$</field>
  2529. <description>Disk log access failed</description>
  2530. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2531. </rule>
  2532. <rule id="100371" level="4">
  2533. <!-- LOG_ID_SYSTEM_START -->
  2534. <if_sid>100010</if_sid>
  2535. <field name="logid">032009$</field>
  2536. <description>FortiGate started</description>
  2537. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2538. </rule>
  2539. <rule id="100372" level="4">
  2540. <!-- LOG_ID_DISK_LOG_FULL -->
  2541. <if_sid>100010</if_sid>
  2542. <field name="logid">032010$</field>
  2543. <description>Disk full</description>
  2544. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2545. </rule>
  2546. <rule id="100373" level="4">
  2547. <!-- LOG_ID_LOG_ROLL -->
  2548. <if_sid>100010</if_sid>
  2549. <field name="logid">032011$</field>
  2550. <description>Disk log rolled</description>
  2551. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2552. </rule>
  2553. <rule id="100374" level="4">
  2554. <!-- LOG_ID_CS_LIC_EXPIRE -->
  2555. <if_sid>100010</if_sid>
  2556. <field name="logid">032014$</field>
  2557. <description>Support license expiring</description>
  2558. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2559. </rule>
  2560. <rule id="100375" level="4">
  2561. <!-- LOG_ID_DISK_LOG_USAGE -->
  2562. <if_sid>100010</if_sid>
  2563. <field name="logid">032015$</field>
  2564. <description>Log disk full</description>
  2565. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2566. </rule>
  2567. <rule id="100376" level="4">
  2568. <!-- LOG_ID_FDS_DAILY_QUOTA_FULL -->
  2569. <if_sid>100010</if_sid>
  2570. <field name="logid">032017$</field>
  2571. <description>FortiGate Cloud daily quota full</description>
  2572. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  2573. </rule>
  2574. <rule id="100377" level="4">
  2575. <!-- LOG_ID_FIPS_ENTER_ERR_MOD -->
  2576. <if_sid>100010</if_sid>
  2577. <field name="logid">032018$</field>
  2578. <description>FIPS CC entered error mode</description>
  2579. <group>fortios.event.event,fortios.category.system,fortios.severity.emergency</group>
  2580. </rule>
  2581. <rule id="100378" level="4">
  2582. <!-- LOG_ID_CC_ENTER_ERR_MOD -->
  2583. <if_sid>100010</if_sid>
  2584. <field name="logid">032019$</field>
  2585. <description>CC entered error mode</description>
  2586. <group>fortios.event.event,fortios.category.system,fortios.severity.emergency</group>
  2587. </rule>
  2588. <rule id="100379" level="4">
  2589. <!-- LOG_ID_SSH_CORRPUT_MAC -->
  2590. <if_sid>100010</if_sid>
  2591. <field name="logid">032020$</field>
  2592. <description>Message Authentication Code corrupted</description>
  2593. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2594. </rule>
  2595. <rule id="100380" level="4">
  2596. <!-- LOG_ID_ADMIN_LOGIN_DISABLE -->
  2597. <if_sid>100010</if_sid>
  2598. <field name="logid">032021$</field>
  2599. <description>Admin login disabled</description>
  2600. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  2601. </rule>
  2602. <rule id="100381" level="4">
  2603. <!-- LOG_ID_VDOM_ENABLED -->
  2604. <if_sid>100010</if_sid>
  2605. <field name="logid">032022$</field>
  2606. <description>VDOM enabled</description>
  2607. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2608. </rule>
  2609. <rule id="100382" level="4">
  2610. <!-- LOG_ID_MEM_LOG_FIRST_FULL -->
  2611. <if_sid>100010</if_sid>
  2612. <field name="logid">032023$</field>
  2613. <description>Memory log full over first warning level</description>
  2614. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2615. </rule>
  2616. <rule id="100383" level="4">
  2617. <!-- LOG_ID_ADMIN_PASSWD_EXPIRE -->
  2618. <if_sid>100010</if_sid>
  2619. <field name="logid">032024$</field>
  2620. <description>Admin password expired</description>
  2621. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2622. </rule>
  2623. <rule id="100384" level="4">
  2624. <!-- LOG_ID_SSH_REKEY -->
  2625. <if_sid>100010</if_sid>
  2626. <field name="logid">032025$</field>
  2627. <description>SSH server re-key</description>
  2628. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2629. </rule>
  2630. <rule id="100385" level="4">
  2631. <!-- LOG_ID_SSH_BAD_PACKET_LENGTH -->
  2632. <if_sid>100010</if_sid>
  2633. <field name="logid">032026$</field>
  2634. <description>SSH server received bad length packet</description>
  2635. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2636. </rule>
  2637. <rule id="100386" level="4">
  2638. <!-- LOG_ID_VIEW_DISK_LOG_SUCC -->
  2639. <if_sid>100010</if_sid>
  2640. <field name="logid">032027$</field>
  2641. <description>Disk logs viewed successfully</description>
  2642. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2643. </rule>
  2644. <rule id="100387" level="4">
  2645. <!-- LOG_ID_LOG_DEL_DIR -->
  2646. <if_sid>100010</if_sid>
  2647. <field name="logid">032028$</field>
  2648. <description>Disk log directory deleted</description>
  2649. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2650. </rule>
  2651. <rule id="100388" level="4">
  2652. <!-- LOG_ID_LOG_DEL_FILE -->
  2653. <if_sid>100010</if_sid>
  2654. <field name="logid">032029$</field>
  2655. <description>Disk log file deleted</description>
  2656. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2657. </rule>
  2658. <rule id="100389" level="4">
  2659. <!-- LOG_ID_SEND_FDS_STAT -->
  2660. <if_sid>100010</if_sid>
  2661. <field name="logid">032030$</field>
  2662. <description>FDS statistics sent</description>
  2663. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2664. </rule>
  2665. <rule id="100390" level="4">
  2666. <!-- LOG_ID_VIEW_MEM_LOG_FAIL -->
  2667. <if_sid>100010</if_sid>
  2668. <field name="logid">032031$</field>
  2669. <description>Memory log access failed</description>
  2670. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2671. </rule>
  2672. <rule id="100391" level="4">
  2673. <!-- LOG_ID_DISK_DLP_ARCH_FULL -->
  2674. <if_sid>100010</if_sid>
  2675. <field name="logid">032032$</field>
  2676. <description>DLP archive full</description>
  2677. <group>fortios.event.event,fortios.category.system,fortios.severity.emergency</group>
  2678. </rule>
  2679. <rule id="100392" level="4">
  2680. <!-- LOG_ID_DISK_QUAR_FULL -->
  2681. <if_sid>100010</if_sid>
  2682. <field name="logid">032033$</field>
  2683. <description>Quarantine full</description>
  2684. <group>fortios.event.event,fortios.category.system,fortios.severity.emergency</group>
  2685. </rule>
  2686. <rule id="100393" level="4">
  2687. <!-- LOG_ID_DISK_REPORT_FULL -->
  2688. <if_sid>100010</if_sid>
  2689. <field name="logid">032034$</field>
  2690. <description>Report db data full</description>
  2691. <group>fortios.event.event,fortios.category.system,fortios.severity.emergency</group>
  2692. </rule>
  2693. <rule id="100394" level="4">
  2694. <!-- LOG_ID_VDOM_DISABLED -->
  2695. <if_sid>100010</if_sid>
  2696. <field name="logid">032035$</field>
  2697. <description>VDOM disabled</description>
  2698. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2699. </rule>
  2700. <rule id="100395" level="4">
  2701. <!-- LOG_ID_DISK_IPS_ARCH_FULL -->
  2702. <if_sid>100010</if_sid>
  2703. <field name="logid">032036$</field>
  2704. <description>IPS archive full</description>
  2705. <group>fortios.event.event,fortios.category.system,fortios.severity.emergency</group>
  2706. </rule>
  2707. <rule id="100396" level="4">
  2708. <!-- LOG_ID_DISK_LOG_FIRST_FULL -->
  2709. <if_sid>100010</if_sid>
  2710. <field name="logid">032037$</field>
  2711. <description>Disk log full over first warning</description>
  2712. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2713. </rule>
  2714. <rule id="100397" level="4">
  2715. <!-- LOG_ID_LOG_ROLL_FORTICRON -->
  2716. <if_sid>100010</if_sid>
  2717. <field name="logid">032038$</field>
  2718. <description>Log rotation requested by FortiCron</description>
  2719. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2720. </rule>
  2721. <rule id="100398" level="4">
  2722. <!-- LOG_ID_VIEW_MEM_LOG_SUCC -->
  2723. <if_sid>100010</if_sid>
  2724. <field name="logid">032039$</field>
  2725. <description>Memory logs viewed successfully</description>
  2726. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2727. </rule>
  2728. <rule id="100399" level="4">
  2729. <!-- LOG_ID_REPORT_DELETED -->
  2730. <if_sid>100010</if_sid>
  2731. <field name="logid">032040$</field>
  2732. <description>Report deleted</description>
  2733. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2734. </rule>
  2735. <rule id="100400" level="4">
  2736. <!-- LOG_ID_REPORT_DELETED_GUI -->
  2737. <if_sid>100010</if_sid>
  2738. <field name="logid">032041$</field>
  2739. <description>Report deleted from GUI</description>
  2740. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2741. </rule>
  2742. <rule id="100401" level="4">
  2743. <!-- LOG_ID_MEM_LOG_SECOND_FULL -->
  2744. <if_sid>100010</if_sid>
  2745. <field name="logid">032042$</field>
  2746. <description>Memory log full over second warning level</description>
  2747. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2748. </rule>
  2749. <rule id="100402" level="4">
  2750. <!-- LOG_ID_MEM_LOG_FINAL_FULL -->
  2751. <if_sid>100010</if_sid>
  2752. <field name="logid">032043$</field>
  2753. <description>Memory log full over final warning level</description>
  2754. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2755. </rule>
  2756. <rule id="100403" level="4">
  2757. <!-- LOG_ID_LOG_DELETE -->
  2758. <if_sid>100010</if_sid>
  2759. <field name="logid">032044$</field>
  2760. <description>Log deleted by user</description>
  2761. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2762. </rule>
  2763. <rule id="100404" level="4">
  2764. <!-- LOG_ID_MGR_LIC_EXPIRE -->
  2765. <if_sid>100010</if_sid>
  2766. <field name="logid">032045$</field>
  2767. <description>FortiGuard management service license expiring</description>
  2768. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2769. </rule>
  2770. <rule id="100405" level="4">
  2771. <!-- LOG_ID_SCHEDULE_EXPIRE -->
  2772. <if_sid>100010</if_sid>
  2773. <field name="logid">032048$</field>
  2774. <description>One time schedule expiring</description>
  2775. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2776. </rule>
  2777. <rule id="100406" level="4">
  2778. <!-- LOG_ID_FC_EXPIRE -->
  2779. <if_sid>100010</if_sid>
  2780. <field name="logid">032049$</field>
  2781. <description>FortiGate Cloud license expiring</description>
  2782. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2783. </rule>
  2784. <rule id="100407" level="4">
  2785. <!-- LOG_ID_POL_PKT_CAPTURE_FULL -->
  2786. <if_sid>100010</if_sid>
  2787. <field name="logid">032050$</field>
  2788. <description>Policy packet capture full</description>
  2789. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2790. </rule>
  2791. <rule id="100408" level="4">
  2792. <!-- LOG_ID_LOG_UPLOAD -->
  2793. <if_sid>100010</if_sid>
  2794. <field name="logid">032051$</field>
  2795. <description>Disk logs upload started</description>
  2796. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2797. </rule>
  2798. <rule id="100409" level="4">
  2799. <!-- LOG_ID_UPLOAD_RUN_SCRIPT -->
  2800. <if_sid>100010</if_sid>
  2801. <field name="logid">032052$</field>
  2802. <description>Upload and run a script</description>
  2803. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2804. </rule>
  2805. <rule id="100410" level="4">
  2806. <!-- LOG_ID_VIEW_FAZ_LOG_FAIL -->
  2807. <if_sid>100010</if_sid>
  2808. <field name="logid">032057$</field>
  2809. <description>FortiAnalyzer log access failed</description>
  2810. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2811. </rule>
  2812. <rule id="100411" level="4">
  2813. <!-- LOG_ID_VIEW_FAZ_LOG_SUCC -->
  2814. <if_sid>100010</if_sid>
  2815. <field name="logid">032058$</field>
  2816. <description>FortiAnalyzer logs viewed successfully</description>
  2817. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2818. </rule>
  2819. <rule id="100412" level="4">
  2820. <!-- LOG_ID_GUI_CHG_SUB_MODULE -->
  2821. <if_sid>100010</if_sid>
  2822. <field name="logid">032095$</field>
  2823. <description>Admin performed an action from GUI</description>
  2824. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2825. </rule>
  2826. <rule id="100413" level="4">
  2827. <!-- LOG_ID_GUI_DOWNLOAD_LOG -->
  2828. <if_sid>100010</if_sid>
  2829. <field name="logid">032096$</field>
  2830. <description>Log file downloaded from GUI</description>
  2831. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2832. </rule>
  2833. <rule id="100414" level="4">
  2834. <!-- LOG_ID_DELETE_CAPTURE_PKT -->
  2835. <if_sid>100010</if_sid>
  2836. <field name="logid">032097$</field>
  2837. <description>Policy packet capture file deleted</description>
  2838. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2839. </rule>
  2840. <rule id="100415" level="4">
  2841. <!-- LOG_ID_CHG_CONFIG_INFO -->
  2842. <if_sid>100010</if_sid>
  2843. <field name="logid">032099$</field>
  2844. <description>Configuration changed information</description>
  2845. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2846. </rule>
  2847. <rule id="100416" level="4">
  2848. <!-- LOG_ID_FORTI_TOKEN_SYNC -->
  2849. <if_sid>100010</if_sid>
  2850. <field name="logid">032100$</field>
  2851. <description>FortiToken synchronized</description>
  2852. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2853. </rule>
  2854. <rule id="100417" level="4">
  2855. <!-- LOG_ID_CHG_CONFIG -->
  2856. <if_sid>100010</if_sid>
  2857. <field name="logid">032102$</field>
  2858. <description>Configuration changed</description>
  2859. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  2860. </rule>
  2861. <rule id="100418" level="4">
  2862. <!-- LOG_ID_NEW_FIRMWARE -->
  2863. <if_sid>100010</if_sid>
  2864. <field name="logid">032103$</field>
  2865. <description>New firmware available on FortiGuard</description>
  2866. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2867. </rule>
  2868. <rule id="100419" level="4">
  2869. <!-- LOG_ID_CHG_CONFIG_GUI -->
  2870. <if_sid>100010</if_sid>
  2871. <field name="logid">032104$</field>
  2872. <description>Configuration changed via GUI</description>
  2873. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  2874. </rule>
  2875. <rule id="100420" level="4">
  2876. <!-- LOG_ID_NTP_SVR_STAUS_CHG_REACHABLE -->
  2877. <if_sid>100010</if_sid>
  2878. <field name="logid">032105$</field>
  2879. <description>NTP server status changes to reachable</description>
  2880. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2881. </rule>
  2882. <rule id="100421" level="4">
  2883. <!-- LOG_ID_NTP_SVR_STAUS_CHG_RESOLVABLE -->
  2884. <if_sid>100010</if_sid>
  2885. <field name="logid">032106$</field>
  2886. <description>NTP server status changes to resolvable</description>
  2887. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2888. </rule>
  2889. <rule id="100422" level="4">
  2890. <!-- LOG_ID_NTP_SVR_STAUS_CHG_UNRESOLVABLE -->
  2891. <if_sid>100010</if_sid>
  2892. <field name="logid">032107$</field>
  2893. <description>NTP server status changes to unresolvable</description>
  2894. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2895. </rule>
  2896. <rule id="100423" level="4">
  2897. <!-- LOG_ID_NTP_SVR_STAUS_CHG_UNREACHABLE -->
  2898. <if_sid>100010</if_sid>
  2899. <field name="logid">032108$</field>
  2900. <description>NTP server status changes to unreachable</description>
  2901. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2902. </rule>
  2903. <rule id="100424" level="4">
  2904. <!-- LOG_ID_UPD_SIGN_AV_DB -->
  2905. <if_sid>100010</if_sid>
  2906. <field name="logid">032109$</field>
  2907. <description>Updating virus database</description>
  2908. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2909. </rule>
  2910. <rule id="100425" level="4">
  2911. <!-- LOG_ID_UPD_SIGN_IPS_DB -->
  2912. <if_sid>100010</if_sid>
  2913. <field name="logid">032110$</field>
  2914. <description>IPS database updated</description>
  2915. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2916. </rule>
  2917. <rule id="100426" level="4">
  2918. <!-- LOG_ID_UPD_SIGN_AVIPS_DB -->
  2919. <if_sid>100010</if_sid>
  2920. <field name="logid">032111$</field>
  2921. <description>AV, IPS, GeoIP, SRC-VIS, FortiFlow, URL White-list, Certificate databases updated</description>
  2922. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2923. </rule>
  2924. <rule id="100427" level="4">
  2925. <!-- LOG_ID_UPD_SIGN_SRCVIS_DB -->
  2926. <if_sid>100010</if_sid>
  2927. <field name="logid">032113$</field>
  2928. <description>SRC-VIS object updated</description>
  2929. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2930. </rule>
  2931. <rule id="100428" level="4">
  2932. <!-- LOG_ID_UPD_SIGN_GEOIP_DB -->
  2933. <if_sid>100010</if_sid>
  2934. <field name="logid">032114$</field>
  2935. <description>GeoIP object updated</description>
  2936. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2937. </rule>
  2938. <rule id="100429" level="4">
  2939. <!-- LOG_ID_UPD_SIGN_AVPKG_FAILURE -->
  2940. <if_sid>100010</if_sid>
  2941. <field name="logid">032116$</field>
  2942. <description>AV package update by SCP failed</description>
  2943. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2944. </rule>
  2945. <rule id="100430" level="4">
  2946. <!-- LOG_ID_UPD_SIGN_AVPKG_SUCCESS -->
  2947. <if_sid>100010</if_sid>
  2948. <field name="logid">032117$</field>
  2949. <description>AV package update by SCP successful</description>
  2950. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  2951. </rule>
  2952. <rule id="100431" level="4">
  2953. <!-- LOG_ID_UPD_ADMIN_AV_DB -->
  2954. <if_sid>100010</if_sid>
  2955. <field name="logid">032118$</field>
  2956. <description>AV updated by admin</description>
  2957. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2958. </rule>
  2959. <rule id="100432" level="4">
  2960. <!-- LOG_ID_UPD_SCANUNIT_AV_DB -->
  2961. <if_sid>100010</if_sid>
  2962. <field name="logid">032119$</field>
  2963. <description>AV database updated by scanunit</description>
  2964. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  2965. </rule>
  2966. <rule id="100433" level="4">
  2967. <!-- LOG_ID_ADD_GUEST -->
  2968. <if_sid>100010</if_sid>
  2969. <field name="logid">032129$</field>
  2970. <description>Guest user added</description>
  2971. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2972. </rule>
  2973. <rule id="100434" level="4">
  2974. <!-- LOG_ID_CHG_USER -->
  2975. <if_sid>100010</if_sid>
  2976. <field name="logid">032130$</field>
  2977. <description>User changed</description>
  2978. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2979. </rule>
  2980. <rule id="100435" level="4">
  2981. <!-- LOG_ID_DEL_GUEST -->
  2982. <if_sid>100010</if_sid>
  2983. <field name="logid">032131$</field>
  2984. <description>Guest user deleted</description>
  2985. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2986. </rule>
  2987. <rule id="100436" level="4">
  2988. <!-- LOG_ID_ADD_USER -->
  2989. <if_sid>100010</if_sid>
  2990. <field name="logid">032132$</field>
  2991. <description>Local user added</description>
  2992. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  2993. </rule>
  2994. <rule id="100437" level="4">
  2995. <!-- LOG_ID_REBOOT -->
  2996. <if_sid>100010</if_sid>
  2997. <field name="logid">032138$</field>
  2998. <description>Device rebooted</description>
  2999. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3000. </rule>
  3001. <rule id="100438" level="4">
  3002. <!-- LOG_ID_WAKE_ON_LAN -->
  3003. <if_sid>100010</if_sid>
  3004. <field name="logid">032139$</field>
  3005. <description>Wake on LAN device</description>
  3006. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3007. </rule>
  3008. <rule id="100439" level="4">
  3009. <!-- LOG_ID_TIME_USER_SETTING_CHG -->
  3010. <if_sid>100010</if_sid>
  3011. <field name="logid">032140$</field>
  3012. <description>Global time setting changed by user</description>
  3013. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3014. </rule>
  3015. <rule id="100440" level="4">
  3016. <!-- LOG_ID_TIME_NTP_SETTING_CHG -->
  3017. <if_sid>100010</if_sid>
  3018. <field name="logid">032141$</field>
  3019. <description>Global time setting changed by NTP</description>
  3020. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3021. </rule>
  3022. <rule id="100441" level="4">
  3023. <!-- LOG_ID_BACKUP_CONF -->
  3024. <if_sid>100010</if_sid>
  3025. <field name="logid">032142$</field>
  3026. <description>System configuration backed up</description>
  3027. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3028. </rule>
  3029. <rule id="100442" level="4">
  3030. <!-- LOG_ID_BACKUP_CONF_BY_SCP -->
  3031. <if_sid>100010</if_sid>
  3032. <field name="logid">032143$</field>
  3033. <description>System configuration backed up by SCP</description>
  3034. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3035. </rule>
  3036. <rule id="100443" level="4">
  3037. <!-- LOG_ID_BACKUP_CONF_ERROR -->
  3038. <if_sid>100010</if_sid>
  3039. <field name="logid">032144$</field>
  3040. <description>System configuration backed up error</description>
  3041. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  3042. </rule>
  3043. <rule id="100444" level="4">
  3044. <!-- LOG_ID_BACKUP_CONF_ALERT -->
  3045. <if_sid>100010</if_sid>
  3046. <field name="logid">032145$</field>
  3047. <description>System configuration backed up alert</description>
  3048. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  3049. </rule>
  3050. <rule id="100445" level="4">
  3051. <!-- LOG_ID_TIME_PTP_SETTING_CHG -->
  3052. <if_sid>100010</if_sid>
  3053. <field name="logid">032146$</field>
  3054. <description>Global time setting changed by PTP</description>
  3055. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3056. </rule>
  3057. <rule id="100446" level="4">
  3058. <!-- LOG_ID_GET_CRL -->
  3059. <if_sid>100010</if_sid>
  3060. <field name="logid">032148$</field>
  3061. <description>CRL update requested</description>
  3062. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3063. </rule>
  3064. <rule id="100447" level="4">
  3065. <!-- LOG_ID_COMMAND_FAIL -->
  3066. <if_sid>100010</if_sid>
  3067. <field name="logid">032149$</field>
  3068. <description>Command failed</description>
  3069. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3070. </rule>
  3071. <rule id="100448" level="4">
  3072. <!-- LOG_ID_ADD_IP6_LOCAL_POL -->
  3073. <if_sid>100010</if_sid>
  3074. <field name="logid">032151$</field>
  3075. <description>IPv6 firewall local in policy added</description>
  3076. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3077. </rule>
  3078. <rule id="100449" level="4">
  3079. <!-- LOG_ID_CHG_IP6_LOCAL_POL -->
  3080. <if_sid>100010</if_sid>
  3081. <field name="logid">032152$</field>
  3082. <description>IPv6 firewall local in policy setting changed</description>
  3083. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3084. </rule>
  3085. <rule id="100450" level="4">
  3086. <!-- LOG_ID_DEL_IP6_LOCAL_POL -->
  3087. <if_sid>100010</if_sid>
  3088. <field name="logid">032153$</field>
  3089. <description>IPv6 firewall local in policy deleted</description>
  3090. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3091. </rule>
  3092. <rule id="100451" level="4">
  3093. <!-- LOG_ID_ACT_FTOKEN_REQ -->
  3094. <if_sid>100010</if_sid>
  3095. <field name="logid">032155$</field>
  3096. <description>FortiToken activation requested</description>
  3097. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3098. </rule>
  3099. <rule id="100452" level="4">
  3100. <!-- LOG_ID_ACT_FTOKEN_SUCC -->
  3101. <if_sid>100010</if_sid>
  3102. <field name="logid">032156$</field>
  3103. <description>FortiToken activation successful</description>
  3104. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3105. </rule>
  3106. <rule id="100453" level="4">
  3107. <!-- LOG_ID_SYNC_FTOKEN_SUCC -->
  3108. <if_sid>100010</if_sid>
  3109. <field name="logid">032157$</field>
  3110. <description>FortiToken re-synchronized</description>
  3111. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3112. </rule>
  3113. <rule id="100454" level="4">
  3114. <!-- LOG_ID_SYNC_FTOKEN_FAIL -->
  3115. <if_sid>100010</if_sid>
  3116. <field name="logid">032158$</field>
  3117. <description>FortiToken re-synchronization failed</description>
  3118. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3119. </rule>
  3120. <rule id="100455" level="4">
  3121. <!-- LOG_ID_ACT_FTOKEN_FAIL -->
  3122. <if_sid>100010</if_sid>
  3123. <field name="logid">032159$</field>
  3124. <description>FortiToken activation failed</description>
  3125. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3126. </rule>
  3127. <rule id="100456" level="4">
  3128. <!-- LOG_ID_FTM_PUSH_SUCC -->
  3129. <if_sid>100010</if_sid>
  3130. <field name="logid">032160$</field>
  3131. <description>FortiToken mobile push message succeeded</description>
  3132. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3133. </rule>
  3134. <rule id="100457" level="4">
  3135. <!-- LOG_ID_FTM_PUSH_FAIL -->
  3136. <if_sid>100010</if_sid>
  3137. <field name="logid">032161$</field>
  3138. <description>FortiToken mobile push message failed</description>
  3139. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  3140. </rule>
  3141. <rule id="100458" level="4">
  3142. <!-- LOG_ID_REACH_VDOM_LIMIT -->
  3143. <if_sid>100010</if_sid>
  3144. <field name="logid">032168$</field>
  3145. <description>VDOM limit reached</description>
  3146. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3147. </rule>
  3148. <rule id="100459" level="4">
  3149. <!-- LOG_ID_ALARM_DLP_DB -->
  3150. <if_sid>100010</if_sid>
  3151. <field name="logid">032169$</field>
  3152. <description>DLP database space alarm</description>
  3153. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  3154. </rule>
  3155. <rule id="100460" level="4">
  3156. <!-- LOG_ID_ALARM_MSG -->
  3157. <if_sid>100010</if_sid>
  3158. <field name="logid">032170$</field>
  3159. <description>Alarm created</description>
  3160. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  3161. </rule>
  3162. <rule id="100461" level="4">
  3163. <!-- LOG_ID_ALARM_ACK -->
  3164. <if_sid>100010</if_sid>
  3165. <field name="logid">032171$</field>
  3166. <description>Alarm acknowledged</description>
  3167. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  3168. </rule>
  3169. <rule id="100462" level="4">
  3170. <!-- LOG_ID_ADD_IP4_LOCAL_POL -->
  3171. <if_sid>100010</if_sid>
  3172. <field name="logid">032172$</field>
  3173. <description>IPv4 firewall local in policy added</description>
  3174. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3175. </rule>
  3176. <rule id="100463" level="4">
  3177. <!-- LOG_ID_CHG_IP4_LOCAL_POL -->
  3178. <if_sid>100010</if_sid>
  3179. <field name="logid">032173$</field>
  3180. <description>IPv4 firewall local in policy's setting changed</description>
  3181. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3182. </rule>
  3183. <rule id="100464" level="4">
  3184. <!-- LOG_ID_DEL_IP4_LOCAL_POL -->
  3185. <if_sid>100010</if_sid>
  3186. <field name="logid">032174$</field>
  3187. <description>IPv4 firewall local in policy deleted</description>
  3188. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3189. </rule>
  3190. <rule id="100465" level="4">
  3191. <!-- LOG_ID_GEOIP_DB_INIT_FAIL -->
  3192. <if_sid>100010</if_sid>
  3193. <field name="logid">032180$</field>
  3194. <description>IP Geography DB initialization failed</description>
  3195. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3196. </rule>
  3197. <rule id="100466" level="4">
  3198. <!-- LOG_ID_UPT_INVALID_IMG -->
  3199. <if_sid>100010</if_sid>
  3200. <field name="logid">032190$</field>
  3201. <description>Invalid image loaded</description>
  3202. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3203. </rule>
  3204. <rule id="100467" level="4">
  3205. <!-- LOG_ID_UPT_INVALID_IMG_CC -->
  3206. <if_sid>100010</if_sid>
  3207. <field name="logid">032191$</field>
  3208. <description>Image with invalid CC signature loaded</description>
  3209. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3210. </rule>
  3211. <rule id="100468" level="4">
  3212. <!-- LOG_ID_UPT_INVALID_IMG_RSA -->
  3213. <if_sid>100010</if_sid>
  3214. <field name="logid">032192$</field>
  3215. <description>Image with invalid RSA signature loaded</description>
  3216. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3217. </rule>
  3218. <rule id="100469" level="4">
  3219. <!-- LOG_ID_UPT_IMG_RSA -->
  3220. <if_sid>100010</if_sid>
  3221. <field name="logid">032193$</field>
  3222. <description>Image with valid RSA signature loaded</description>
  3223. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3224. </rule>
  3225. <rule id="100470" level="4">
  3226. <!-- LOG_ID_UPT_IMG_FAIL -->
  3227. <if_sid>100010</if_sid>
  3228. <field name="logid">032194$</field>
  3229. <description>System upgrade failed due to file operation failure</description>
  3230. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3231. </rule>
  3232. <rule id="100471" level="4">
  3233. <!-- LOG_ID_SHUTDOWN -->
  3234. <if_sid>100010</if_sid>
  3235. <field name="logid">032200$</field>
  3236. <description>Device shutdown</description>
  3237. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3238. </rule>
  3239. <rule id="100472" level="4">
  3240. <!-- LOG_ID_LOAD_IMG_SUCC -->
  3241. <if_sid>100010</if_sid>
  3242. <field name="logid">032201$</field>
  3243. <description>Image loaded successfully</description>
  3244. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3245. </rule>
  3246. <rule id="100473" level="4">
  3247. <!-- LOG_ID_RESTORE_IMG -->
  3248. <if_sid>100010</if_sid>
  3249. <field name="logid">032202$</field>
  3250. <description>Image restored</description>
  3251. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3252. </rule>
  3253. <rule id="100474" level="4">
  3254. <!-- LOG_ID_RESTORE_CONF -->
  3255. <if_sid>100010</if_sid>
  3256. <field name="logid">032203$</field>
  3257. <description>Configuration restored</description>
  3258. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3259. </rule>
  3260. <rule id="100475" level="4">
  3261. <!-- LOG_ID_RESTORE_FGD_SVR -->
  3262. <if_sid>100010</if_sid>
  3263. <field name="logid">032204$</field>
  3264. <description>FortiGuard service restored</description>
  3265. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3266. </rule>
  3267. <rule id="100476" level="4">
  3268. <!-- LOG_ID_RESTORE_VDOM_LIC -->
  3269. <if_sid>100010</if_sid>
  3270. <field name="logid">032205$</field>
  3271. <description>VM license restored</description>
  3272. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3273. </rule>
  3274. <rule id="100477" level="4">
  3275. <!-- LOG_ID_RESTORE_SCRIPT -->
  3276. <if_sid>100010</if_sid>
  3277. <field name="logid">032206$</field>
  3278. <description>Script restored from management station</description>
  3279. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3280. </rule>
  3281. <rule id="100478" level="4">
  3282. <!-- LOG_ID_RETRIEVE_CONF_LIST -->
  3283. <if_sid>100010</if_sid>
  3284. <field name="logid">032207$</field>
  3285. <description>Configuration list retrieval failed</description>
  3286. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3287. </rule>
  3288. <rule id="100479" level="4">
  3289. <!-- LOG_ID_IMP_PKCS12_CERT -->
  3290. <if_sid>100010</if_sid>
  3291. <field name="logid">032208$</field>
  3292. <description>PKCS12 certificate imported</description>
  3293. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3294. </rule>
  3295. <rule id="100480" level="4">
  3296. <!-- LOG_ID_RESTORE_USR_DEF_IPS -->
  3297. <if_sid>100010</if_sid>
  3298. <field name="logid">032209$</field>
  3299. <description>IPS custom signatures restored</description>
  3300. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3301. </rule>
  3302. <rule id="100481" level="4">
  3303. <!-- LOG_ID_BACKUP_IMG_SUCC -->
  3304. <if_sid>100010</if_sid>
  3305. <field name="logid">032210$</field>
  3306. <description>Firmware image backed up successfully</description>
  3307. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3308. </rule>
  3309. <rule id="100482" level="4">
  3310. <!-- LOG_ID_UPLOAD_REVISION -->
  3311. <if_sid>100010</if_sid>
  3312. <field name="logid">032211$</field>
  3313. <description>Revision uploaded to flash disk</description>
  3314. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3315. </rule>
  3316. <rule id="100483" level="4">
  3317. <!-- LOG_ID_DEL_REVISION -->
  3318. <if_sid>100010</if_sid>
  3319. <field name="logid">032212$</field>
  3320. <description>Revision deleted</description>
  3321. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3322. </rule>
  3323. <rule id="100484" level="4">
  3324. <!-- LOG_ID_RESTORE_TEMPLATE -->
  3325. <if_sid>100010</if_sid>
  3326. <field name="logid">032213$</field>
  3327. <description>Template restored</description>
  3328. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3329. </rule>
  3330. <rule id="100485" level="4">
  3331. <!-- LOG_ID_RESTORE_FILE -->
  3332. <if_sid>100010</if_sid>
  3333. <field name="logid">032214$</field>
  3334. <description>File restore failed</description>
  3335. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3336. </rule>
  3337. <rule id="100486" level="4">
  3338. <!-- LOG_ID_UPT_IMG -->
  3339. <if_sid>100010</if_sid>
  3340. <field name="logid">032215$</field>
  3341. <description>Image updated</description>
  3342. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3343. </rule>
  3344. <rule id="100487" level="4">
  3345. <!-- LOG_ID_UPD_IPS -->
  3346. <if_sid>100010</if_sid>
  3347. <field name="logid">032217$</field>
  3348. <description>IPS package - Admin update successful</description>
  3349. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3350. </rule>
  3351. <rule id="100488" level="4">
  3352. <!-- LOG_ID_UPD_DLP -->
  3353. <if_sid>100010</if_sid>
  3354. <field name="logid">032218$</field>
  3355. <description>DLP fingerprint database update via SCP failed</description>
  3356. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3357. </rule>
  3358. <rule id="100489" level="4">
  3359. <!-- LOG_ID_BACKUP_OUTPUT -->
  3360. <if_sid>100010</if_sid>
  3361. <field name="logid">032219$</field>
  3362. <description>Error output backup via SCP successful</description>
  3363. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3364. </rule>
  3365. <rule id="100490" level="4">
  3366. <!-- LOG_ID_BACKUP_COMMAND -->
  3367. <if_sid>100010</if_sid>
  3368. <field name="logid">032220$</field>
  3369. <description>Batch mode command output backup via SCP successful</description>
  3370. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3371. </rule>
  3372. <rule id="100491" level="4">
  3373. <!-- LOG_ID_UPD_VDOM_LIC -->
  3374. <if_sid>100010</if_sid>
  3375. <field name="logid">032221$</field>
  3376. <description>VM license installed via SCP</description>
  3377. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3378. </rule>
  3379. <rule id="100492" level="4">
  3380. <!-- LOG_ID_GLB_SETTING_CHG -->
  3381. <if_sid>100010</if_sid>
  3382. <field name="logid">032222$</field>
  3383. <description>Global setting changed</description>
  3384. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3385. </rule>
  3386. <rule id="100493" level="4">
  3387. <!-- LOG_ID_BACKUP_USER_DEF_IPS -->
  3388. <if_sid>100010</if_sid>
  3389. <field name="logid">032223$</field>
  3390. <description>IPS custom signatures backup success</description>
  3391. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3392. </rule>
  3393. <rule id="100494" level="4">
  3394. <!-- LOG_ID_BACKUP_DISK_LOG -->
  3395. <if_sid>100010</if_sid>
  3396. <field name="logid">032224$</field>
  3397. <description>Disk logs backed up</description>
  3398. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3399. </rule>
  3400. <rule id="100495" level="4">
  3401. <!-- LOG_ID_DEL_ALL_REVISION -->
  3402. <if_sid>100010</if_sid>
  3403. <field name="logid">032225$</field>
  3404. <description>Revision database reset due to data corruption</description>
  3405. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3406. </rule>
  3407. <rule id="100496" level="4">
  3408. <!-- LOG_ID_LOAD_IMG_FAIL -->
  3409. <if_sid>100010</if_sid>
  3410. <field name="logid">032226$</field>
  3411. <description>Image failed to load</description>
  3412. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3413. </rule>
  3414. <rule id="100497" level="4">
  3415. <!-- LOG_ID_UPD_DLP_FAIL -->
  3416. <if_sid>100010</if_sid>
  3417. <field name="logid">032227$</field>
  3418. <description>DLP fingerprint database failed to update by SCP</description>
  3419. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3420. </rule>
  3421. <rule id="100498" level="4">
  3422. <!-- LOG_ID_LOAD_IMG_FAIL_WRONG_IMG -->
  3423. <if_sid>100010</if_sid>
  3424. <field name="logid">032228$</field>
  3425. <description>Firmware image loaded incorrect</description>
  3426. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3427. </rule>
  3428. <rule id="100499" level="4">
  3429. <!-- LOG_ID_LOAD_IMG_FAIL_NO_RSA -->
  3430. <if_sid>100010</if_sid>
  3431. <field name="logid">032229$</field>
  3432. <description>Firmware image without valid RSA signature loaded</description>
  3433. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3434. </rule>
  3435. <rule id="100500" level="4">
  3436. <!-- LOG_ID_LOAD_IMG_FAIL_INVALID_RSA -->
  3437. <if_sid>100010</if_sid>
  3438. <field name="logid">032230$</field>
  3439. <description>Firmware image with invalid RSA signature loaded</description>
  3440. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3441. </rule>
  3442. <rule id="100501" level="4">
  3443. <!-- LOG_ID_RESTORE_FGD_SVR_FAIL -->
  3444. <if_sid>100010</if_sid>
  3445. <field name="logid">032231$</field>
  3446. <description>FortiGuard service failed to restore</description>
  3447. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3448. </rule>
  3449. <rule id="100502" level="4">
  3450. <!-- LOG_ID_RESTORE_VDOM_LIC_FAIL -->
  3451. <if_sid>100010</if_sid>
  3452. <field name="logid">032232$</field>
  3453. <description>VM license failed to restore</description>
  3454. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3455. </rule>
  3456. <rule id="100503" level="4">
  3457. <!-- LOG_ID_BACKUP_IMG_FAIL -->
  3458. <if_sid>100010</if_sid>
  3459. <field name="logid">032233$</field>
  3460. <description>Firmware image backup failed</description>
  3461. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3462. </rule>
  3463. <rule id="100504" level="4">
  3464. <!-- LOG_ID_RESTORE_IMG_INVALID_CC -->
  3465. <if_sid>100010</if_sid>
  3466. <field name="logid">032234$</field>
  3467. <description>Image with invalid CC signature restored</description>
  3468. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3469. </rule>
  3470. <rule id="100505" level="4">
  3471. <!-- LOG_ID_RESTORE_IMG_FORTIGUARD -->
  3472. <if_sid>100010</if_sid>
  3473. <field name="logid">032235$</field>
  3474. <description>Image restored from FortiGuard Management</description>
  3475. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3476. </rule>
  3477. <rule id="100506" level="4">
  3478. <!-- LOG_ID_BACKUP_MEM_LOG -->
  3479. <if_sid>100010</if_sid>
  3480. <field name="logid">032236$</field>
  3481. <description>Memory logs backed up</description>
  3482. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3483. </rule>
  3484. <rule id="100507" level="4">
  3485. <!-- LOG_ID_BACKUP_MEM_LOG_FAIL -->
  3486. <if_sid>100010</if_sid>
  3487. <field name="logid">032237$</field>
  3488. <description>Memory logs failed to back up</description>
  3489. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3490. </rule>
  3491. <rule id="100508" level="4">
  3492. <!-- LOG_ID_BACKUP_DISK_LOG_FAIL -->
  3493. <if_sid>100010</if_sid>
  3494. <field name="logid">032238$</field>
  3495. <description>Disk logs failed to back up</description>
  3496. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3497. </rule>
  3498. <rule id="100509" level="4">
  3499. <!-- LOG_ID_BACKUP_DISK_LOG_USB -->
  3500. <if_sid>100010</if_sid>
  3501. <field name="logid">032239$</field>
  3502. <description>Disk logs backed up to USB</description>
  3503. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3504. </rule>
  3505. <rule id="100510" level="4">
  3506. <!-- LOG_ID_SYS_USB_MODE -->
  3507. <if_sid>100010</if_sid>
  3508. <field name="logid">032240$</field>
  3509. <description>System operating in USB mode</description>
  3510. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3511. </rule>
  3512. <rule id="100511" level="4">
  3513. <!-- LOG_ID_BACKUP_DISK_LOG_USB_FAIL -->
  3514. <if_sid>100010</if_sid>
  3515. <field name="logid">032241$</field>
  3516. <description>Disk logs failed to back up to USB</description>
  3517. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3518. </rule>
  3519. <rule id="100512" level="4">
  3520. <!-- LOG_ID_UPD_VDOM_LIC_FAIL -->
  3521. <if_sid>100010</if_sid>
  3522. <field name="logid">032242$</field>
  3523. <description>VM license failed to install via SCP</description>
  3524. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3525. </rule>
  3526. <rule id="100513" level="4">
  3527. <!-- LOG_ID_UPD_IPS_SCP -->
  3528. <if_sid>100010</if_sid>
  3529. <field name="logid">032243$</field>
  3530. <description>IPS package updated via SCP</description>
  3531. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3532. </rule>
  3533. <rule id="100514" level="4">
  3534. <!-- LOG_ID_UPD_IPS_SCP_FAIL -->
  3535. <if_sid>100010</if_sid>
  3536. <field name="logid">032244$</field>
  3537. <description>IPS package failed to update via SCP</description>
  3538. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3539. </rule>
  3540. <rule id="100515" level="4">
  3541. <!-- LOG_ID_BACKUP_USER_DEF_IPS_FAIL -->
  3542. <if_sid>100010</if_sid>
  3543. <field name="logid">032245$</field>
  3544. <description>IPS custom signatures backup failed</description>
  3545. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  3546. </rule>
  3547. <rule id="100516" level="4">
  3548. <!-- LOG_ID_RESTORE_USR_DEF_IPS_CRITICAL -->
  3549. <if_sid>100010</if_sid>
  3550. <field name="logid">032246$</field>
  3551. <description>IPS custom signatures restored critical</description>
  3552. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3553. </rule>
  3554. <rule id="100517" level="4">
  3555. <!-- LOG_ID_SSH_NEGOTIATION_FAILURE -->
  3556. <if_sid>100010</if_sid>
  3557. <field name="logid">032247$</field>
  3558. <description>SSH protocol cannot be negotiated</description>
  3559. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  3560. </rule>
  3561. <rule id="100518" level="4">
  3562. <!-- LOG_ID_FACTORY_RESET -->
  3563. <if_sid>100010</if_sid>
  3564. <field name="logid">032252$</field>
  3565. <description>Factory settings reset</description>
  3566. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3567. </rule>
  3568. <rule id="100519" level="4">
  3569. <!-- LOG_ID_FORMAT_RAID -->
  3570. <if_sid>100010</if_sid>
  3571. <field name="logid">032253$</field>
  3572. <description>RAID disk formatted</description>
  3573. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3574. </rule>
  3575. <rule id="100520" level="4">
  3576. <!-- LOG_ID_ENABLE_RAID -->
  3577. <if_sid>100010</if_sid>
  3578. <field name="logid">032254$</field>
  3579. <description>RAID enabled</description>
  3580. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3581. </rule>
  3582. <rule id="100521" level="4">
  3583. <!-- LOG_ID_DISABLE_RAID -->
  3584. <if_sid>100010</if_sid>
  3585. <field name="logid">032255$</field>
  3586. <description>RAID disabled</description>
  3587. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3588. </rule>
  3589. <rule id="100522" level="4">
  3590. <!-- LOG_ID_RESTORE_IMG_FORTIGUARD_NOTIF -->
  3591. <if_sid>100010</if_sid>
  3592. <field name="logid">032260$</field>
  3593. <description>Image restored from FortiGuard Management notification</description>
  3594. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3595. </rule>
  3596. <rule id="100523" level="4">
  3597. <!-- LOG_ID_RESTORE_SCRIPT_NOTIF -->
  3598. <if_sid>100010</if_sid>
  3599. <field name="logid">032261$</field>
  3600. <description>Script restored by user</description>
  3601. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3602. </rule>
  3603. <rule id="100524" level="4">
  3604. <!-- LOG_ID_RESTORE_IMG_CONFIRM -->
  3605. <if_sid>100010</if_sid>
  3606. <field name="logid">032262$</field>
  3607. <description>Image restore confirmed by user</description>
  3608. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3609. </rule>
  3610. <rule id="100525" level="4">
  3611. <!-- LOG_ID_BLE_FIRMWARE_CHECK -->
  3612. <if_sid>100010</if_sid>
  3613. <field name="logid">032263$</field>
  3614. <description>Bluetooth firmware check</description>
  3615. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3616. </rule>
  3617. <rule id="100526" level="4">
  3618. <!-- LOG_ID_BLE_FIRMWARE_UPDATE -->
  3619. <if_sid>100010</if_sid>
  3620. <field name="logid">032264$</field>
  3621. <description>Bluetooth firmware update</description>
  3622. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3623. </rule>
  3624. <rule id="100527" level="4">
  3625. <!-- LOG_ID_BLE_FIRMWARE_UPDATE -->
  3626. <if_sid>100010</if_sid>
  3627. <field name="logid">032265$</field>
  3628. <description>Bluetooth firmware update</description>
  3629. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3630. </rule>
  3631. <rule id="100528" level="4">
  3632. <!-- LOG_ID_SSH_HOST_KEY_REGEN -->
  3633. <if_sid>100010</if_sid>
  3634. <field name="logid">032270$</field>
  3635. <description>SSH host keys regenerated.</description>
  3636. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3637. </rule>
  3638. <rule id="100529" level="4">
  3639. <!-- LOG_ID_UPLOAD_RPT_IMG -->
  3640. <if_sid>100010</if_sid>
  3641. <field name="logid">032300$</field>
  3642. <description>Report image file uploaded</description>
  3643. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3644. </rule>
  3645. <rule id="100530" level="4">
  3646. <!-- LOG_ID_ADD_VDOM -->
  3647. <if_sid>100010</if_sid>
  3648. <field name="logid">032301$</field>
  3649. <description>VDOM added</description>
  3650. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3651. </rule>
  3652. <rule id="100531" level="4">
  3653. <!-- LOG_ID_DEL_VDOM -->
  3654. <if_sid>100010</if_sid>
  3655. <field name="logid">032302$</field>
  3656. <description>VDOM deleted</description>
  3657. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3658. </rule>
  3659. <rule id="100532" level="4">
  3660. <!-- LOG_ID_SYS_RESTART -->
  3661. <if_sid>100010</if_sid>
  3662. <field name="logid">032545$</field>
  3663. <description>Scheduled daily reboot started</description>
  3664. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3665. </rule>
  3666. <rule id="100533" level="4">
  3667. <!-- LOG_ID_APPLICATION_CRASH -->
  3668. <if_sid>100010</if_sid>
  3669. <field name="logid">032546$</field>
  3670. <description>Application crashed</description>
  3671. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3672. </rule>
  3673. <rule id="100534" level="4">
  3674. <!-- LOG_ID_AUTOSCRIPT_START -->
  3675. <if_sid>100010</if_sid>
  3676. <field name="logid">032547$</field>
  3677. <description>Autoscript start</description>
  3678. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3679. </rule>
  3680. <rule id="100535" level="4">
  3681. <!-- LOG_ID_AUTOSCRIPT_STOP -->
  3682. <if_sid>100010</if_sid>
  3683. <field name="logid">032548$</field>
  3684. <description>Autoscript stop</description>
  3685. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3686. </rule>
  3687. <rule id="100536" level="4">
  3688. <!-- LOG_ID_AUTOSCRIPT_STOP_AUTO -->
  3689. <if_sid>100010</if_sid>
  3690. <field name="logid">032549$</field>
  3691. <description>Autoscript stop automatically</description>
  3692. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3693. </rule>
  3694. <rule id="100537" level="4">
  3695. <!-- LOG_ID_AUTOSCRIPT_DELETE_RSLT -->
  3696. <if_sid>100010</if_sid>
  3697. <field name="logid">032550$</field>
  3698. <description>Autoscript delete result</description>
  3699. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3700. </rule>
  3701. <rule id="100538" level="4">
  3702. <!-- LOG_ID_AUTOSCRIPT_BACKUP_RSLT -->
  3703. <if_sid>100010</if_sid>
  3704. <field name="logid">032551$</field>
  3705. <description>Autoscript backup result</description>
  3706. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3707. </rule>
  3708. <rule id="100539" level="4">
  3709. <!-- LOG_ID_AUTOSCRIPT_CHECK_STATUS -->
  3710. <if_sid>100010</if_sid>
  3711. <field name="logid">032552$</field>
  3712. <description>Autoscript check status</description>
  3713. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3714. </rule>
  3715. <rule id="100540" level="4">
  3716. <!-- LOG_ID_AUTOSCRIPT_STOP_REACH_LIMIT -->
  3717. <if_sid>100010</if_sid>
  3718. <field name="logid">032553$</field>
  3719. <description>Autoscript stop due to limit reached</description>
  3720. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3721. </rule>
  3722. <rule id="100541" level="4">
  3723. <!-- LOG_ID_UPD_ADMIN_DB -->
  3724. <if_sid>100010</if_sid>
  3725. <field name="logid">032554$</field>
  3726. <description>Database updated by admin</description>
  3727. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3728. </rule>
  3729. <rule id="100542" level="4">
  3730. <!-- LOG_ID_ADMIN_LOGOUT_DISCONNECT -->
  3731. <if_sid>100010</if_sid>
  3732. <field name="logid">032561$</field>
  3733. <description>Admin disconnected</description>
  3734. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3735. </rule>
  3736. <rule id="100543" level="4">
  3737. <!-- LOG_ID_STORE_CONF_FAIL_SPACE -->
  3738. <if_sid>100010</if_sid>
  3739. <field name="logid">032562$</field>
  3740. <description>Store config failed - not enough flash space</description>
  3741. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3742. </rule>
  3743. <rule id="100544" level="4">
  3744. <!-- LOG_ID_RESTORE_CONF_FAIL -->
  3745. <if_sid>100010</if_sid>
  3746. <field name="logid">032564$</field>
  3747. <description>Configuration failed to restore</description>
  3748. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3749. </rule>
  3750. <rule id="100545" level="4">
  3751. <!-- LOG_ID_RESTORE_CONF_BY_MGMT -->
  3752. <if_sid>100010</if_sid>
  3753. <field name="logid">032565$</field>
  3754. <description>Configuration restored from management station</description>
  3755. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3756. </rule>
  3757. <rule id="100546" level="4">
  3758. <!-- LOG_ID_RESTORE_CONF_BY_SCP -->
  3759. <if_sid>100010</if_sid>
  3760. <field name="logid">032566$</field>
  3761. <description>Configuration restored by SCP</description>
  3762. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3763. </rule>
  3764. <rule id="100547" level="4">
  3765. <!-- LOG_ID_DEL_REVISION_DB -->
  3766. <if_sid>100010</if_sid>
  3767. <field name="logid">032568$</field>
  3768. <description>Revision Database deletion</description>
  3769. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  3770. </rule>
  3771. <rule id="100548" level="4">
  3772. <!-- LOG_ID_FSW_SWITCH_LOG_EVENT -->
  3773. <if_sid>100010</if_sid>
  3774. <field name="logid">032569$</field>
  3775. <description>Switch-Controller</description>
  3776. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3777. </rule>
  3778. <rule id="100549" level="4">
  3779. <!-- LOG_ID_RESTORE_CONF_FAIL_WARNING -->
  3780. <if_sid>100010</if_sid>
  3781. <field name="logid">032571$</field>
  3782. <description>Configuration failed to restore warning</description>
  3783. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3784. </rule>
  3785. <rule id="100550" level="4">
  3786. <!-- LOG_ID_FGT_SWITCH_LOG_DISCOVER -->
  3787. <if_sid>100010</if_sid>
  3788. <field name="logid">032601$</field>
  3789. <description>Switch-Controller discovered</description>
  3790. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3791. </rule>
  3792. <rule id="100551" level="4">
  3793. <!-- LOG_ID_FGT_SWITCH_LOG_AUTH -->
  3794. <if_sid>100010</if_sid>
  3795. <field name="logid">032602$</field>
  3796. <description>Switch-Controller authorized</description>
  3797. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3798. </rule>
  3799. <rule id="100552" level="4">
  3800. <!-- LOG_ID_FGT_SWITCH_LOG_DEAUTH -->
  3801. <if_sid>100010</if_sid>
  3802. <field name="logid">032603$</field>
  3803. <description>Switch-Controller deauthorized</description>
  3804. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3805. </rule>
  3806. <rule id="100553" level="4">
  3807. <!-- LOG_ID_FGT_SWITCH_LOG_DELETE -->
  3808. <if_sid>100010</if_sid>
  3809. <field name="logid">032604$</field>
  3810. <description>Switch-Controller deleted</description>
  3811. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3812. </rule>
  3813. <rule id="100554" level="4">
  3814. <!-- LOG_ID_FGT_SWITCH_LOG_TUNNEL_UP -->
  3815. <if_sid>100010</if_sid>
  3816. <field name="logid">032605$</field>
  3817. <description>Switch-Controller Tunnel Up</description>
  3818. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3819. </rule>
  3820. <rule id="100555" level="4">
  3821. <!-- LOG_ID_FGT_SWITCH_LOG_TUNNEL_DOWN -->
  3822. <if_sid>100010</if_sid>
  3823. <field name="logid">032606$</field>
  3824. <description>Switch-Controller Tunnel Down</description>
  3825. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.warning</group>
  3826. </rule>
  3827. <rule id="100556" level="4">
  3828. <!-- LOG_ID_FGT_SWITCH_PUSH_IMAGE -->
  3829. <if_sid>100010</if_sid>
  3830. <field name="logid">032607$</field>
  3831. <description>Image push to FortiSwitch</description>
  3832. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3833. </rule>
  3834. <rule id="100557" level="4">
  3835. <!-- LOG_ID_FGT_SWITCH_STAGE_IMAGE -->
  3836. <if_sid>100010</if_sid>
  3837. <field name="logid">032608$</field>
  3838. <description>Image stage to FortiSwitch</description>
  3839. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3840. </rule>
  3841. <rule id="100558" level="4">
  3842. <!-- LOG_ID_FGT_SWITCH_DISABLE_DISCOVERY -->
  3843. <if_sid>100010</if_sid>
  3844. <field name="logid">032609$</field>
  3845. <description>Disable FortiSwitch Discovery</description>
  3846. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3847. </rule>
  3848. <rule id="100559" level="4">
  3849. <!-- LOG_ID_FGT_SWITCH_LOG_WARNING -->
  3850. <if_sid>100010</if_sid>
  3851. <field name="logid">032610$</field>
  3852. <description>Switch-Controller warning</description>
  3853. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.warning</group>
  3854. </rule>
  3855. <rule id="100560" level="4">
  3856. <!-- LOG_ID_FGT_SWITCH_EXPORT_POOL -->
  3857. <if_sid>100010</if_sid>
  3858. <field name="logid">032611$</field>
  3859. <description>Export port to pool</description>
  3860. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3861. </rule>
  3862. <rule id="100561" level="4">
  3863. <!-- LOG_ID_FGT_SWITCH_EXPORT_VDOM -->
  3864. <if_sid>100010</if_sid>
  3865. <field name="logid">032612$</field>
  3866. <description>Export port to vdom</description>
  3867. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3868. </rule>
  3869. <rule id="100562" level="4">
  3870. <!-- LOG_ID_FGT_SWITCH_REQUEST_PORT -->
  3871. <if_sid>100010</if_sid>
  3872. <field name="logid">032613$</field>
  3873. <description>Request port from pool</description>
  3874. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3875. </rule>
  3876. <rule id="100563" level="4">
  3877. <!-- LOG_ID_FGT_SWITCH_RETURN_PORT -->
  3878. <if_sid>100010</if_sid>
  3879. <field name="logid">032614$</field>
  3880. <description>Return port to pool</description>
  3881. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3882. </rule>
  3883. <rule id="100564" level="4">
  3884. <!-- LOG_ID_FGT_SWITCH_MAC_ADD -->
  3885. <if_sid>100010</if_sid>
  3886. <field name="logid">032615$</field>
  3887. <description>FortiSwitch MAC add</description>
  3888. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3889. </rule>
  3890. <rule id="100565" level="4">
  3891. <!-- LOG_ID_FGT_SWITCH_MAC_DEL -->
  3892. <if_sid>100010</if_sid>
  3893. <field name="logid">032616$</field>
  3894. <description>FortiSwitch MAC delete</description>
  3895. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3896. </rule>
  3897. <rule id="100566" level="4">
  3898. <!-- LOG_ID_FGT_SWITCH_MAC_MOVE -->
  3899. <if_sid>100010</if_sid>
  3900. <field name="logid">032617$</field>
  3901. <description>FortiSwitch MAC move</description>
  3902. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  3903. </rule>
  3904. <rule id="100567" level="4">
  3905. <!-- LOG_ID_FGT_SWITCH_GROUP_SWC -->
  3906. <if_sid>100010</if_sid>
  3907. <field name="logid">032693$</field>
  3908. <description>FortiSwitch switch controller</description>
  3909. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3910. </rule>
  3911. <rule id="100568" level="4">
  3912. <!-- LOG_ID_FGT_SWITCH_GROUP_POE -->
  3913. <if_sid>100010</if_sid>
  3914. <field name="logid">032694$</field>
  3915. <description>FortiSwitch PoE</description>
  3916. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3917. </rule>
  3918. <rule id="100569" level="4">
  3919. <!-- LOG_ID_FGT_SWITCH_GROUP_LINK -->
  3920. <if_sid>100010</if_sid>
  3921. <field name="logid">032695$</field>
  3922. <description>FortiSwitch link</description>
  3923. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3924. </rule>
  3925. <rule id="100570" level="4">
  3926. <!-- LOG_ID_FGT_SWITCH_GROUP_STP -->
  3927. <if_sid>100010</if_sid>
  3928. <field name="logid">032696$</field>
  3929. <description>FortiSwitch spanning Tree</description>
  3930. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3931. </rule>
  3932. <rule id="100571" level="4">
  3933. <!-- LOG_ID_FGT_SWITCH_GROUP_SWITCH -->
  3934. <if_sid>100010</if_sid>
  3935. <field name="logid">032697$</field>
  3936. <description>FortiSwitch switch</description>
  3937. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3938. </rule>
  3939. <rule id="100572" level="4">
  3940. <!-- LOG_ID_FGT_SWITCH_GROUP_ROUTER -->
  3941. <if_sid>100010</if_sid>
  3942. <field name="logid">032698$</field>
  3943. <description>FortiSwitch router</description>
  3944. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3945. </rule>
  3946. <rule id="100573" level="4">
  3947. <!-- LOG_ID_FGT_SWITCH_GROUP_SYSTEM -->
  3948. <if_sid>100010</if_sid>
  3949. <field name="logid">032699$</field>
  3950. <description>FortiSwitch system</description>
  3951. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  3952. </rule>
  3953. <rule id="100574" level="4">
  3954. <!-- LOG_ID_NP6_IPSEC_ENGINE_BUSY -->
  3955. <if_sid>100010</if_sid>
  3956. <field name="logid">034415$</field>
  3957. <description>NP6 IPsec engine is busy</description>
  3958. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  3959. </rule>
  3960. <rule id="100575" level="4">
  3961. <!-- LOG_ID_NP6_IPSEC_ENGINE_POSSIBLY_LOCKUP -->
  3962. <if_sid>100010</if_sid>
  3963. <field name="logid">034416$</field>
  3964. <description>NP6 IPsec engine is possibly locked up</description>
  3965. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3966. </rule>
  3967. <rule id="100576" level="4">
  3968. <!-- LOG_ID_NP6_IPSEC_ENGINE_LOCKUP -->
  3969. <if_sid>100010</if_sid>
  3970. <field name="logid">034417$</field>
  3971. <description>NP6 IPsec engine is locked up</description>
  3972. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3973. </rule>
  3974. <rule id="100577" level="4">
  3975. <!-- LOG_ID_NP6_HPE_PACKET_DROP -->
  3976. <if_sid>100010</if_sid>
  3977. <field name="logid">034418$</field>
  3978. <description>NPU HPE is dropping packets</description>
  3979. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3980. </rule>
  3981. <rule id="100578" level="4">
  3982. <!-- LOG_ID_NP6_HPE_PACKET_FLOOD -->
  3983. <if_sid>100010</if_sid>
  3984. <field name="logid">034419$</field>
  3985. <description>NP6 HPE under a packets flood</description>
  3986. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  3987. </rule>
  3988. <rule id="100579" level="4">
  3989. <!-- LOG_ID_NP7_HPE_PACKET_DROP -->
  3990. <if_sid>100010</if_sid>
  3991. <field name="logid">034428$</field>
  3992. <description>NPU HPE is dropping packets</description>
  3993. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  3994. </rule>
  3995. <rule id="100580" level="4">
  3996. <!-- LOG_ID_NP7_HPE_PACKET_FLOOD -->
  3997. <if_sid>100010</if_sid>
  3998. <field name="logid">034430$</field>
  3999. <description>NPU HPE under packet flood</description>
  4000. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  4001. </rule>
  4002. <rule id="100581" level="4">
  4003. <!-- LOG_ID_HA_SYNC_VIRDB -->
  4004. <if_sid>100010</if_sid>
  4005. <field name="logid">035001$</field>
  4006. <description>HA secondary synchronized Virus database</description>
  4007. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4008. </rule>
  4009. <rule id="100582" level="4">
  4010. <!-- LOG_ID_HA_SYNC_ETDB -->
  4011. <if_sid>100010</if_sid>
  4012. <field name="logid">035002$</field>
  4013. <description>HA secondary synchronized Extended database</description>
  4014. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4015. </rule>
  4016. <rule id="100583" level="4">
  4017. <!-- LOG_ID_HA_SYNC_EXDB -->
  4018. <if_sid>100010</if_sid>
  4019. <field name="logid">035003$</field>
  4020. <description>HA secondary synchronized Extreme database</description>
  4021. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4022. </rule>
  4023. <rule id="100584" level="4">
  4024. <!-- LOG_ID_HA_SYNC_FLDB -->
  4025. <if_sid>100010</if_sid>
  4026. <field name="logid">035004$</field>
  4027. <description>HA secondary synchronized FLDB</description>
  4028. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4029. </rule>
  4030. <rule id="100585" level="4">
  4031. <!-- LOG_ID_HA_SYNC_IPS -->
  4032. <if_sid>100010</if_sid>
  4033. <field name="logid">035005$</field>
  4034. <description>HA secondary synchronized IDS package</description>
  4035. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4036. </rule>
  4037. <rule id="100586" level="4">
  4038. <!-- LOG_ID_HA_SYNC_AV -->
  4039. <if_sid>100010</if_sid>
  4040. <field name="logid">035007$</field>
  4041. <description>HA secondary synchronized AntiVirus package</description>
  4042. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4043. </rule>
  4044. <rule id="100587" level="4">
  4045. <!-- LOG_ID_HA_SYNC_CID -->
  4046. <if_sid>100010</if_sid>
  4047. <field name="logid">035009$</field>
  4048. <description>HA secondary synchronized CID package</description>
  4049. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4050. </rule>
  4051. <rule id="100588" level="4">
  4052. <!-- LOG_ID_HA_SYNC_FAIL -->
  4053. <if_sid>100010</if_sid>
  4054. <field name="logid">035011$</field>
  4055. <description>HA secondary synchronization failed</description>
  4056. <group>fortios.event.event,fortios.category.ha,fortios.severity.error</group>
  4057. </rule>
  4058. <rule id="100589" level="4">
  4059. <!-- LOG_ID_CONF_SYNC_FAIL -->
  4060. <if_sid>100010</if_sid>
  4061. <field name="logid">035012$</field>
  4062. <description>Secondary sync failed</description>
  4063. <group>fortios.event.event,fortios.category.ha,fortios.severity.error</group>
  4064. </rule>
  4065. <rule id="100590" level="4">
  4066. <!-- LOG_ID_HA_FAILOVER_FAIL -->
  4067. <if_sid>100010</if_sid>
  4068. <field name="logid">035013$</field>
  4069. <description>HA failover failed</description>
  4070. <group>fortios.event.event,fortios.category.ha,fortios.severity.error</group>
  4071. </rule>
  4072. <rule id="100591" level="4">
  4073. <!-- LOG_ID_HA_RESET_UPTIME -->
  4074. <if_sid>100010</if_sid>
  4075. <field name="logid">035014$</field>
  4076. <description>HA reset uptime</description>
  4077. <group>fortios.event.event,fortios.category.ha,fortios.severity.information</group>
  4078. </rule>
  4079. <rule id="100592" level="4">
  4080. <!-- LOG_ID_HA_CLEAR_HISTORY -->
  4081. <if_sid>100010</if_sid>
  4082. <field name="logid">035015$</field>
  4083. <description>HA clear history</description>
  4084. <group>fortios.event.event,fortios.category.ha,fortios.severity.information</group>
  4085. </rule>
  4086. <rule id="100593" level="4">
  4087. <!-- LOG_ID_HA_FAILOVER_SUCCESS -->
  4088. <if_sid>100010</if_sid>
  4089. <field name="logid">035016$</field>
  4090. <description>HA failover success</description>
  4091. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4092. </rule>
  4093. <rule id="100594" level="4">
  4094. <!-- LOG_ID_EVENT_SYSTEM_CFG_REVERT -->
  4095. <if_sid>100010</if_sid>
  4096. <field name="logid">036881$</field>
  4097. <description>Configuration reverted due to timeout</description>
  4098. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4099. </rule>
  4100. <rule id="100595" level="4">
  4101. <!-- LOG_ID_EVENT_SYSTEM_CFG_MANUALLY_SAVED -->
  4102. <if_sid>100010</if_sid>
  4103. <field name="logid">036882$</field>
  4104. <description>Configuration manually saved</description>
  4105. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4106. </rule>
  4107. <rule id="100596" level="4">
  4108. <!-- LOG_ID_EVENT_SYSTEM_CLEAR_ACTIVE_SESSION -->
  4109. <if_sid>100010</if_sid>
  4110. <field name="logid">036883$</field>
  4111. <description>Clear active sessions</description>
  4112. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  4113. </rule>
  4114. <rule id="100597" level="4">
  4115. <!-- MESGID_NEG_GENERIC_P1_NOTIF -->
  4116. <if_sid>100010</if_sid>
  4117. <field name="logid">037120$</field>
  4118. <description>Negotiate IPsec phase 1</description>
  4119. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4120. </rule>
  4121. <rule id="100598" level="4">
  4122. <!-- MESGID_NEG_GENERIC_P1_ERROR -->
  4123. <if_sid>100010</if_sid>
  4124. <field name="logid">037121$</field>
  4125. <description>Negotiate IPsec phase 1</description>
  4126. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4127. </rule>
  4128. <rule id="100599" level="4">
  4129. <!-- MESGID_NEG_GENERIC_P2_NOTIF -->
  4130. <if_sid>100010</if_sid>
  4131. <field name="logid">037122$</field>
  4132. <description>Negotiate IPsec phase 2</description>
  4133. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4134. </rule>
  4135. <rule id="100600" level="4">
  4136. <!-- MESGID_NEG_GENERIC_P2_ERROR -->
  4137. <if_sid>100010</if_sid>
  4138. <field name="logid">037123$</field>
  4139. <description>Negotiate IPsec phase 2</description>
  4140. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4141. </rule>
  4142. <rule id="100601" level="4">
  4143. <!-- MESGID_NEG_I_P1_ERROR -->
  4144. <if_sid>100010</if_sid>
  4145. <field name="logid">037124$</field>
  4146. <description>IPsec phase 1 error</description>
  4147. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4148. </rule>
  4149. <rule id="100602" level="4">
  4150. <!-- MESGID_NEG_I_P2_ERROR -->
  4151. <if_sid>100010</if_sid>
  4152. <field name="logid">037125$</field>
  4153. <description>IPsec phase 2 error</description>
  4154. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4155. </rule>
  4156. <rule id="100603" level="4">
  4157. <!-- MESGID_NEG_NO_STATE_ERROR -->
  4158. <if_sid>100010</if_sid>
  4159. <field name="logid">037126$</field>
  4160. <description>IPsec no state error</description>
  4161. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4162. </rule>
  4163. <rule id="100604" level="4">
  4164. <!-- MESGID_NEG_PROGRESS_P1_NOTIF -->
  4165. <if_sid>100010</if_sid>
  4166. <field name="logid">037127$</field>
  4167. <description>Progress IPsec phase 1</description>
  4168. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4169. </rule>
  4170. <rule id="100605" level="4">
  4171. <!-- MESGID_NEG_PROGRESS_P1_ERROR -->
  4172. <if_sid>100010</if_sid>
  4173. <field name="logid">037128$</field>
  4174. <description>Progress IPsec phase 1</description>
  4175. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4176. </rule>
  4177. <rule id="100606" level="4">
  4178. <!-- MESGID_NEG_PROGRESS_P2_NOTIF -->
  4179. <if_sid>100010</if_sid>
  4180. <field name="logid">037129$</field>
  4181. <description>Progress IPsec phase 2</description>
  4182. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4183. </rule>
  4184. <rule id="100607" level="4">
  4185. <!-- MESGID_NEG_PROGRESS_P2_ERROR -->
  4186. <if_sid>100010</if_sid>
  4187. <field name="logid">037130$</field>
  4188. <description>Progress IPsec phase 2</description>
  4189. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4190. </rule>
  4191. <rule id="100608" level="4">
  4192. <!-- MESGID_ESP_ERROR -->
  4193. <if_sid>100010</if_sid>
  4194. <field name="logid">037131$</field>
  4195. <description>IPsec ESP</description>
  4196. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4197. </rule>
  4198. <rule id="100609" level="4">
  4199. <!-- MESGID_ESP_CRITICAL -->
  4200. <if_sid>100010</if_sid>
  4201. <field name="logid">037132$</field>
  4202. <description>IPsec ESP</description>
  4203. <group>fortios.event.event,fortios.category.vpn,fortios.severity.critical</group>
  4204. </rule>
  4205. <rule id="100610" level="4">
  4206. <!-- MESGID_INSTALL_SA -->
  4207. <if_sid>100010</if_sid>
  4208. <field name="logid">037133$</field>
  4209. <description>IPsec SA installed</description>
  4210. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4211. </rule>
  4212. <rule id="100611" level="4">
  4213. <!-- MESGID_DELETE_P1_SA -->
  4214. <if_sid>100010</if_sid>
  4215. <field name="logid">037134$</field>
  4216. <description>IPsec phase 1 SA deleted</description>
  4217. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4218. </rule>
  4219. <rule id="100612" level="4">
  4220. <!-- MESGID_DELETE_P2_SA -->
  4221. <if_sid>100010</if_sid>
  4222. <field name="logid">037135$</field>
  4223. <description>IPsec phase 2 SA deleted</description>
  4224. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4225. </rule>
  4226. <rule id="100613" level="4">
  4227. <!-- MESGID_DPD_FAILURE -->
  4228. <if_sid>100010</if_sid>
  4229. <field name="logid">037136$</field>
  4230. <description>IPsec DPD failed</description>
  4231. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4232. </rule>
  4233. <rule id="100614" level="4">
  4234. <!-- MESGID_CONN_FAILURE -->
  4235. <if_sid>100010</if_sid>
  4236. <field name="logid">037137$</field>
  4237. <description>IPsec connection failed</description>
  4238. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4239. </rule>
  4240. <rule id="100615" level="4">
  4241. <!-- MESGID_CONN_UPDOWN -->
  4242. <if_sid>100010</if_sid>
  4243. <field name="logid">037138$</field>
  4244. <description>IPsec connection status changed</description>
  4245. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4246. </rule>
  4247. <rule id="100616" level="4">
  4248. <!-- MESGID_P2_UPDOWN -->
  4249. <if_sid>100010</if_sid>
  4250. <field name="logid">037139$</field>
  4251. <description>IPsec phase 2 status changed</description>
  4252. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4253. </rule>
  4254. <rule id="100617" level="4">
  4255. <!-- MESGID_CONN_STATS -->
  4256. <if_sid>100010</if_sid>
  4257. <field name="logid">037141$</field>
  4258. <description>IPsec tunnel statistics</description>
  4259. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4260. </rule>
  4261. <rule id="100618" level="4">
  4262. <!-- MESGID_VC_DELETE -->
  4263. <if_sid>100010</if_sid>
  4264. <field name="logid">037889$</field>
  4265. <description>Virtual cluster deleted</description>
  4266. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4267. </rule>
  4268. <rule id="100619" level="4">
  4269. <!-- MESGID_VC_MOVE_VDOM -->
  4270. <if_sid>100010</if_sid>
  4271. <field name="logid">037890$</field>
  4272. <description>Virtual cluster VDOM moved</description>
  4273. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4274. </rule>
  4275. <rule id="100620" level="4">
  4276. <!-- MESGID_VC_ADD_VDOM -->
  4277. <if_sid>100010</if_sid>
  4278. <field name="logid">037891$</field>
  4279. <description>Virtual cluster VDOM added</description>
  4280. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4281. </rule>
  4282. <rule id="100621" level="4">
  4283. <!-- MESGID_VC_MOVE_MEMB_STATE -->
  4284. <if_sid>100010</if_sid>
  4285. <field name="logid">037892$</field>
  4286. <description>Virtual cluster member state moved</description>
  4287. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4288. </rule>
  4289. <rule id="100622" level="4">
  4290. <!-- MESGID_VC_DETECT_MEMB_DEAD -->
  4291. <if_sid>100010</if_sid>
  4292. <field name="logid">037893$</field>
  4293. <description>Virtual cluster member dead</description>
  4294. <group>fortios.event.event,fortios.category.ha,fortios.severity.critical</group>
  4295. </rule>
  4296. <rule id="100623" level="4">
  4297. <!-- MESGID_VC_DETECT_MEMB_JOIN -->
  4298. <if_sid>100010</if_sid>
  4299. <field name="logid">037894$</field>
  4300. <description>Virtual cluster member joined</description>
  4301. <group>fortios.event.event,fortios.category.ha,fortios.severity.critical</group>
  4302. </rule>
  4303. <rule id="100624" level="4">
  4304. <!-- MESGID_VC_ADD_HADEV -->
  4305. <if_sid>100010</if_sid>
  4306. <field name="logid">037895$</field>
  4307. <description>Virtual cluster added HA device interface</description>
  4308. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4309. </rule>
  4310. <rule id="100625" level="4">
  4311. <!-- MESGID_VC_DEL_HADEV -->
  4312. <if_sid>100010</if_sid>
  4313. <field name="logid">037896$</field>
  4314. <description>Virtual cluster deleted HA device interface</description>
  4315. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4316. </rule>
  4317. <rule id="100626" level="4">
  4318. <!-- MESGID_HADEV_READY -->
  4319. <if_sid>100010</if_sid>
  4320. <field name="logid">037897$</field>
  4321. <description>HA device interface ready</description>
  4322. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4323. </rule>
  4324. <rule id="100627" level="4">
  4325. <!-- MESGID_HADEV_FAIL -->
  4326. <if_sid>100010</if_sid>
  4327. <field name="logid">037898$</field>
  4328. <description>HA device interface failed</description>
  4329. <group>fortios.event.event,fortios.category.ha,fortios.severity.warning</group>
  4330. </rule>
  4331. <rule id="100628" level="4">
  4332. <!-- MESGID_HADEV_PEERINFO -->
  4333. <if_sid>100010</if_sid>
  4334. <field name="logid">037899$</field>
  4335. <description>HA device interface peer information</description>
  4336. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4337. </rule>
  4338. <rule id="100629" level="4">
  4339. <!-- MESGID_HBDEV_DELETE -->
  4340. <if_sid>100010</if_sid>
  4341. <field name="logid">037900$</field>
  4342. <description>Heartbeat device interface deleted</description>
  4343. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4344. </rule>
  4345. <rule id="100630" level="4">
  4346. <!-- MESGID_HBDEV_DOWN -->
  4347. <if_sid>100010</if_sid>
  4348. <field name="logid">037901$</field>
  4349. <description>Heartbeat device interface down</description>
  4350. <group>fortios.event.event,fortios.category.ha,fortios.severity.critical</group>
  4351. </rule>
  4352. <rule id="100631" level="4">
  4353. <!-- MESGID_HBDEV_UP -->
  4354. <if_sid>100010</if_sid>
  4355. <field name="logid">037902$</field>
  4356. <description>Heartbeat device interface up</description>
  4357. <group>fortios.event.event,fortios.category.ha,fortios.severity.information</group>
  4358. </rule>
  4359. <rule id="100632" level="4">
  4360. <!-- MESGID_SYNC_STATUS -->
  4361. <if_sid>100010</if_sid>
  4362. <field name="logid">037903$</field>
  4363. <description>Synchronization status with primary</description>
  4364. <group>fortios.event.event,fortios.category.ha,fortios.severity.information</group>
  4365. </rule>
  4366. <rule id="100633" level="4">
  4367. <!-- MESGID_HA_ACTIVITY -->
  4368. <if_sid>100010</if_sid>
  4369. <field name="logid">037904$</field>
  4370. <description>Device set as HA primary</description>
  4371. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4372. </rule>
  4373. <rule id="100634" level="4">
  4374. <!-- MESGID_VLAN_HB_UP -->
  4375. <if_sid>100010</if_sid>
  4376. <field name="logid">037907$</field>
  4377. <description>VLAN heartbeat started</description>
  4378. <group>fortios.event.event,fortios.category.ha,fortios.severity.information</group>
  4379. </rule>
  4380. <rule id="100635" level="4">
  4381. <!-- MESGID_VLAN_HB_DOWN -->
  4382. <if_sid>100010</if_sid>
  4383. <field name="logid">037908$</field>
  4384. <description>VLAN heartbeat lost</description>
  4385. <group>fortios.event.event,fortios.category.ha,fortios.severity.error</group>
  4386. </rule>
  4387. <rule id="100636" level="4">
  4388. <!-- MESGID_VLAN_HB_DOWN_SUM -->
  4389. <if_sid>100010</if_sid>
  4390. <field name="logid">037909$</field>
  4391. <description>VLAN heartbeat lost summary</description>
  4392. <group>fortios.event.event,fortios.category.ha,fortios.severity.error</group>
  4393. </rule>
  4394. <rule id="100637" level="4">
  4395. <!-- MESGID_HB_PACKET_LOST -->
  4396. <if_sid>100010</if_sid>
  4397. <field name="logid">037910$</field>
  4398. <description>Heartbeat packet lost</description>
  4399. <group>fortios.event.event,fortios.category.ha,fortios.severity.critical</group>
  4400. </rule>
  4401. <rule id="100638" level="4">
  4402. <!-- MESGID_HA_ACTIVITY_INFO -->
  4403. <if_sid>100010</if_sid>
  4404. <field name="logid">037911$</field>
  4405. <description>Device set as HA master information</description>
  4406. <group>fortios.event.event,fortios.category.ha,fortios.severity.information</group>
  4407. </rule>
  4408. <rule id="100639" level="4">
  4409. <!-- MESGID_FGSP_MEMBER_JOIN -->
  4410. <if_sid>100010</if_sid>
  4411. <field name="logid">037912$</field>
  4412. <description>FGSP member joined</description>
  4413. <group>fortios.event.event,fortios.category.ha,fortios.severity.notice</group>
  4414. </rule>
  4415. <rule id="100640" level="4">
  4416. <!-- MESGID_FGSP_MEMBER_LEAVE -->
  4417. <if_sid>100010</if_sid>
  4418. <field name="logid">037913$</field>
  4419. <description>FGSP member left</description>
  4420. <group>fortios.event.event,fortios.category.ha,fortios.severity.critical</group>
  4421. </rule>
  4422. <rule id="100641" level="4">
  4423. <!-- LOG_ID_FIPS_ENCRY_FAIL -->
  4424. <if_sid>100010</if_sid>
  4425. <field name="logid">038010$</field>
  4426. <description>FIPS CC encryption failed</description>
  4427. <group>fortios.event.event,fortios.category.user,fortios.severity.alert</group>
  4428. </rule>
  4429. <rule id="100642" level="4">
  4430. <!-- LOG_ID_FIPS_DECRY_FAIL -->
  4431. <if_sid>100010</if_sid>
  4432. <field name="logid">038011$</field>
  4433. <description>FIPS CC decryption failed</description>
  4434. <group>fortios.event.event,fortios.category.user,fortios.severity.alert</group>
  4435. </rule>
  4436. <rule id="100643" level="4">
  4437. <!-- LOG_ID_ENTROPY_TOKEN -->
  4438. <if_sid>100010</if_sid>
  4439. <field name="logid">038012$</field>
  4440. <description>Seeding from entropy source</description>
  4441. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4442. </rule>
  4443. <rule id="100644" level="4">
  4444. <!-- LOG_ID_FSSO_LOGON -->
  4445. <if_sid>100010</if_sid>
  4446. <field name="logid">038031$</field>
  4447. <description>FSSO logon successful</description>
  4448. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4449. </rule>
  4450. <rule id="100645" level="4">
  4451. <!-- LOG_ID_FSSO_LOGOFF -->
  4452. <if_sid>100010</if_sid>
  4453. <field name="logid">038032$</field>
  4454. <description>FSSO logout successful</description>
  4455. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4456. </rule>
  4457. <rule id="100646" level="4">
  4458. <!-- LOG_ID_FSSO_SVR_STATUS -->
  4459. <if_sid>100010</if_sid>
  4460. <field name="logid">038033$</field>
  4461. <description>FSSO Active Directory server authentication status</description>
  4462. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4463. </rule>
  4464. <rule id="100647" level="4">
  4465. <!-- LOGID_EVENT_NOTIF_INSUFFICIENT_RESOURCE -->
  4466. <if_sid>100010</if_sid>
  4467. <field name="logid">038403$</field>
  4468. <description>Insufficient system resource notification</description>
  4469. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  4470. </rule>
  4471. <rule id="100648" level="4">
  4472. <!-- LOGID_EVENT_NOTIF_HOSTNAME_ERROR -->
  4473. <if_sid>100010</if_sid>
  4474. <field name="logid">038404$</field>
  4475. <description>FortiGuard hostname unresolvable</description>
  4476. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  4477. </rule>
  4478. <rule id="100649" level="4">
  4479. <!-- LOGID_NOTIF_CODE_SENDTO_SMS_PHONE -->
  4480. <if_sid>100010</if_sid>
  4481. <field name="logid">038405$</field>
  4482. <description>Guest user account login information sent to phone</description>
  4483. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4484. </rule>
  4485. <rule id="100650" level="4">
  4486. <!-- LOGID_NOTIF_CODE_SENDTO_SMS_TO -->
  4487. <if_sid>100010</if_sid>
  4488. <field name="logid">038406$</field>
  4489. <description>Guest user account login information sent as SMS</description>
  4490. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4491. </rule>
  4492. <rule id="100651" level="4">
  4493. <!-- LOGID_NOTIF_CODE_SENDTO_EMAIL -->
  4494. <if_sid>100010</if_sid>
  4495. <field name="logid">038407$</field>
  4496. <description>Guest user account login information sent to email</description>
  4497. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4498. </rule>
  4499. <rule id="100652" level="4">
  4500. <!-- LOGID_EVENT_OFTP_SSL_CONNECTED -->
  4501. <if_sid>100010</if_sid>
  4502. <field name="logid">038408$</field>
  4503. <description>SSL connection established</description>
  4504. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  4505. </rule>
  4506. <rule id="100653" level="4">
  4507. <!-- LOGID_EVENT_OFTP_SSL_DISCONNECTED -->
  4508. <if_sid>100010</if_sid>
  4509. <field name="logid">038409$</field>
  4510. <description>SSL connection closed</description>
  4511. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  4512. </rule>
  4513. <rule id="100654" level="4">
  4514. <!-- LOGID_EVENT_OFTP_SSL_FAILED -->
  4515. <if_sid>100010</if_sid>
  4516. <field name="logid">038410$</field>
  4517. <description>SSL connection failed</description>
  4518. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  4519. </rule>
  4520. <rule id="100655" level="4">
  4521. <!-- LOGID_EVENT_TWO_F_AUTH_CODE_SENDTO -->
  4522. <if_sid>100010</if_sid>
  4523. <field name="logid">038411$</field>
  4524. <description>Two-factor authentication code sent</description>
  4525. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4526. </rule>
  4527. <rule id="100656" level="4">
  4528. <!-- LOGID_EVENT_TOKEN_CODE_SENDTO -->
  4529. <if_sid>100010</if_sid>
  4530. <field name="logid">038412$</field>
  4531. <description>Token activation code sent</description>
  4532. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4533. </rule>
  4534. <rule id="100657" level="4">
  4535. <!-- LOGID_EVENT_RAD_RPT_PROTO_ERROR -->
  4536. <if_sid>100010</if_sid>
  4537. <field name="logid">038656$</field>
  4538. <description>RADIUS protocol error summary</description>
  4539. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4540. </rule>
  4541. <rule id="100658" level="4">
  4542. <!-- LOGID_EVENT_RAD_RPT_PROF_NOT_FOUND -->
  4543. <if_sid>100010</if_sid>
  4544. <field name="logid">038657$</field>
  4545. <description>RADIUS profile not found summary</description>
  4546. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4547. </rule>
  4548. <rule id="100659" level="4">
  4549. <!-- LOGID_EVENT_RAD_RPT_CTX_NOT_FOUND -->
  4550. <if_sid>100010</if_sid>
  4551. <field name="logid">038658$</field>
  4552. <description>RADIUS profile CTX not found summary</description>
  4553. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4554. </rule>
  4555. <rule id="100660" level="4">
  4556. <!-- LOGID_EVENT_RAD_RPT_ACCT_STOP_MISSED -->
  4557. <if_sid>100010</if_sid>
  4558. <field name="logid">038659$</field>
  4559. <description>RADIUS accounting stop message missing summary</description>
  4560. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4561. </rule>
  4562. <rule id="100661" level="4">
  4563. <!-- LOGID_EVENT_RAD_RPT_ACCT_EVENT -->
  4564. <if_sid>100010</if_sid>
  4565. <field name="logid">038660$</field>
  4566. <description>RADIUS accounting event summary</description>
  4567. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4568. </rule>
  4569. <rule id="100662" level="4">
  4570. <!-- LOGID_EVENT_RAD_RPT_OTHER -->
  4571. <if_sid>100010</if_sid>
  4572. <field name="logid">038661$</field>
  4573. <description>RADIUS endpoint block event or other event summary</description>
  4574. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4575. </rule>
  4576. <rule id="100663" level="4">
  4577. <!-- LOGID_EVENT_RAD_STAT_PROTO_ERROR -->
  4578. <if_sid>100010</if_sid>
  4579. <field name="logid">038662$</field>
  4580. <description>RADIUS accounting protocol error</description>
  4581. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4582. </rule>
  4583. <rule id="100664" level="4">
  4584. <!-- LOGID_EVENT_RAD_STAT_PROF_NOT_FOUND -->
  4585. <if_sid>100010</if_sid>
  4586. <field name="logid">038663$</field>
  4587. <description>RADIUS accounting profile not found</description>
  4588. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4589. </rule>
  4590. <rule id="100665" level="4">
  4591. <!-- LOGID_EVENT_RAD_STAT_ACCT_STOP_MISSED -->
  4592. <if_sid>100010</if_sid>
  4593. <field name="logid">038665$</field>
  4594. <description>RADIUS accounting stop message missing</description>
  4595. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4596. </rule>
  4597. <rule id="100666" level="4">
  4598. <!-- LOGID_EVENT_RAD_STAT_ACCT_EVENT -->
  4599. <if_sid>100010</if_sid>
  4600. <field name="logid">038666$</field>
  4601. <description>RADIUS accounting event</description>
  4602. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4603. </rule>
  4604. <rule id="100667" level="4">
  4605. <!-- LOGID_EVENT_RAD_STAT_OTHER -->
  4606. <if_sid>100010</if_sid>
  4607. <field name="logid">038667$</field>
  4608. <description>RADIUS other accounting event</description>
  4609. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4610. </rule>
  4611. <rule id="100668" level="4">
  4612. <!-- LOGID_EVENT_RAD_STAT_EP_BLK -->
  4613. <if_sid>100010</if_sid>
  4614. <field name="logid">038668$</field>
  4615. <description>RADIUS endpoint block event</description>
  4616. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  4617. </rule>
  4618. <rule id="100669" level="4">
  4619. <!-- LOG_ID_EVENT_SSL_VPN_USER_TUNNEL_UP -->
  4620. <if_sid>100010</if_sid>
  4621. <field name="logid">039424$</field>
  4622. <description>SSL VPN tunnel up</description>
  4623. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4624. </rule>
  4625. <rule id="100670" level="4">
  4626. <!-- LOG_ID_EVENT_SSL_VPN_USER_TUNNEL_DOWN -->
  4627. <if_sid>100010</if_sid>
  4628. <field name="logid">039425$</field>
  4629. <description>SSL VPN tunnel down</description>
  4630. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4631. </rule>
  4632. <rule id="100671" level="4">
  4633. <!-- LOG_ID_EVENT_SSL_VPN_USER_SSL_LOGIN_FAIL -->
  4634. <if_sid>100010</if_sid>
  4635. <field name="logid">039426$</field>
  4636. <description>SSL VPN login fail</description>
  4637. <group>fortios.event.event,fortios.category.vpn,fortios.severity.alert</group>
  4638. </rule>
  4639. <rule id="100672" level="4">
  4640. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_WEB_TUNNEL_STATS -->
  4641. <if_sid>100010</if_sid>
  4642. <field name="logid">039936$</field>
  4643. <description>SSL VPN statistics</description>
  4644. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4645. </rule>
  4646. <rule id="100673" level="4">
  4647. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_WEBAPP_DENY -->
  4648. <if_sid>100010</if_sid>
  4649. <field name="logid">039937$</field>
  4650. <description>SSL VPN deny</description>
  4651. <group>fortios.event.event,fortios.category.vpn,fortios.severity.warning</group>
  4652. </rule>
  4653. <rule id="100674" level="4">
  4654. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_WEBAPP_PASS -->
  4655. <if_sid>100010</if_sid>
  4656. <field name="logid">039938$</field>
  4657. <description>SSL VPN pass</description>
  4658. <group>fortios.event.event,fortios.category.vpn,fortios.severity.warning</group>
  4659. </rule>
  4660. <rule id="100675" level="4">
  4661. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_WEBAPP_TIMEOUT -->
  4662. <if_sid>100010</if_sid>
  4663. <field name="logid">039939$</field>
  4664. <description>SSL VPN timeout</description>
  4665. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4666. </rule>
  4667. <rule id="100676" level="4">
  4668. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_WEBAPP_CLOSE -->
  4669. <if_sid>100010</if_sid>
  4670. <field name="logid">039940$</field>
  4671. <description>SSL VPN close</description>
  4672. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4673. </rule>
  4674. <rule id="100677" level="4">
  4675. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_SYS_BUSY -->
  4676. <if_sid>100010</if_sid>
  4677. <field name="logid">039941$</field>
  4678. <description>SSL VPN system busy</description>
  4679. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4680. </rule>
  4681. <rule id="100678" level="4">
  4682. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_CERT_OK -->
  4683. <if_sid>100010</if_sid>
  4684. <field name="logid">039942$</field>
  4685. <description>SSL VPN certificate OK</description>
  4686. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4687. </rule>
  4688. <rule id="100679" level="4">
  4689. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_NEW_CON -->
  4690. <if_sid>100010</if_sid>
  4691. <field name="logid">039943$</field>
  4692. <description>SSL VPN new connection</description>
  4693. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4694. </rule>
  4695. <rule id="100680" level="4">
  4696. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_ALERT -->
  4697. <if_sid>100010</if_sid>
  4698. <field name="logid">039944$</field>
  4699. <description>SSL VPN alert</description>
  4700. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4701. </rule>
  4702. <rule id="100681" level="4">
  4703. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_EXIT_FAIL -->
  4704. <if_sid>100010</if_sid>
  4705. <field name="logid">039945$</field>
  4706. <description>SSL VPN exit fail</description>
  4707. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4708. </rule>
  4709. <rule id="100682" level="4">
  4710. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_EXIT_ERR -->
  4711. <if_sid>100010</if_sid>
  4712. <field name="logid">039946$</field>
  4713. <description>SSL VPN exit error</description>
  4714. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4715. </rule>
  4716. <rule id="100683" level="4">
  4717. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_UP -->
  4718. <if_sid>100010</if_sid>
  4719. <field name="logid">039947$</field>
  4720. <description>SSL VPN tunnel up</description>
  4721. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4722. </rule>
  4723. <rule id="100684" level="4">
  4724. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_DOWN -->
  4725. <if_sid>100010</if_sid>
  4726. <field name="logid">039948$</field>
  4727. <description>SSL VPN tunnel down</description>
  4728. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4729. </rule>
  4730. <rule id="100685" level="4">
  4731. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_STATS -->
  4732. <if_sid>100010</if_sid>
  4733. <field name="logid">039949$</field>
  4734. <description>SSL VPN statistics</description>
  4735. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4736. </rule>
  4737. <rule id="100686" level="4">
  4738. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_UNKNOWNTAG -->
  4739. <if_sid>100010</if_sid>
  4740. <field name="logid">039950$</field>
  4741. <description>SSL VPN unknown tag</description>
  4742. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4743. </rule>
  4744. <rule id="100687" level="4">
  4745. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_TUNNEL_ERROR -->
  4746. <if_sid>100010</if_sid>
  4747. <field name="logid">039951$</field>
  4748. <description>SSL VPN tunnel error</description>
  4749. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4750. </rule>
  4751. <rule id="100688" level="4">
  4752. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_ENTER_CONSERVE_MODE -->
  4753. <if_sid>100010</if_sid>
  4754. <field name="logid">039952$</field>
  4755. <description>SSL VPN enter conserve mode</description>
  4756. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4757. </rule>
  4758. <rule id="100689" level="4">
  4759. <!-- LOG_ID_EVENT_SSL_VPN_SESSION_LEAVE_CONSERVE_MODE -->
  4760. <if_sid>100010</if_sid>
  4761. <field name="logid">039953$</field>
  4762. <description>SSL VPN leave conserve mode</description>
  4763. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4764. </rule>
  4765. <rule id="100690" level="4">
  4766. <!-- LOG_ID_PPTP_TUNNEL_UP -->
  4767. <if_sid>100010</if_sid>
  4768. <field name="logid">040001$</field>
  4769. <description>PPTP tunnel up</description>
  4770. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4771. </rule>
  4772. <rule id="100691" level="4">
  4773. <!-- LOG_ID_PPTP_TUNNEL_DOWN -->
  4774. <if_sid>100010</if_sid>
  4775. <field name="logid">040002$</field>
  4776. <description>PPTP tunnel down</description>
  4777. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4778. </rule>
  4779. <rule id="100692" level="4">
  4780. <!-- LOG_ID_PPTP_TUNNEL_STAT -->
  4781. <if_sid>100010</if_sid>
  4782. <field name="logid">040003$</field>
  4783. <description>PPTP tunnel status</description>
  4784. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4785. </rule>
  4786. <rule id="100693" level="4">
  4787. <!-- LOG_ID_PPTP_REACH_MAX_CON -->
  4788. <if_sid>100010</if_sid>
  4789. <field name="logid">040014$</field>
  4790. <description>PPTP client connection limit reached</description>
  4791. <group>fortios.event.event,fortios.category.vpn,fortios.severity.warning</group>
  4792. </rule>
  4793. <rule id="100694" level="4">
  4794. <!-- LOG_ID_L2TPD_CLIENT_CON_FAIL -->
  4795. <if_sid>100010</if_sid>
  4796. <field name="logid">040017$</field>
  4797. <description>L2TP client connection failed</description>
  4798. <group>fortios.event.event,fortios.category.vpn,fortios.severity.warning</group>
  4799. </rule>
  4800. <rule id="100695" level="4">
  4801. <!-- LOG_ID_L2TPD_CLIENT_DISCON -->
  4802. <if_sid>100010</if_sid>
  4803. <field name="logid">040019$</field>
  4804. <description>L2TP client disconnected</description>
  4805. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4806. </rule>
  4807. <rule id="100696" level="4">
  4808. <!-- LOG_ID_PPTP_NOT_CONIG -->
  4809. <if_sid>100010</if_sid>
  4810. <field name="logid">040021$</field>
  4811. <description>PPTP not configured in VDOM</description>
  4812. <group>fortios.event.event,fortios.category.vpn,fortios.severity.debug</group>
  4813. </rule>
  4814. <rule id="100697" level="4">
  4815. <!-- LOG_ID_PPTP_NO_IP_AVAIL -->
  4816. <if_sid>100010</if_sid>
  4817. <field name="logid">040022$</field>
  4818. <description>PPTP IP addresses unavailable</description>
  4819. <group>fortios.event.event,fortios.category.vpn,fortios.severity.warning</group>
  4820. </rule>
  4821. <rule id="100698" level="4">
  4822. <!-- LOG_ID_PPTP_OUT_MEM -->
  4823. <if_sid>100010</if_sid>
  4824. <field name="logid">040024$</field>
  4825. <description>PPTP config list insufficient memory</description>
  4826. <group>fortios.event.event,fortios.category.vpn,fortios.severity.warning</group>
  4827. </rule>
  4828. <rule id="100699" level="4">
  4829. <!-- LOG_ID_PPTP_START -->
  4830. <if_sid>100010</if_sid>
  4831. <field name="logid">040034$</field>
  4832. <description>PPTP daemon started</description>
  4833. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4834. </rule>
  4835. <rule id="100700" level="4">
  4836. <!-- LOG_ID_PPTP_START_FAIL -->
  4837. <if_sid>100010</if_sid>
  4838. <field name="logid">040035$</field>
  4839. <description>PPTP daemon failed to start</description>
  4840. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  4841. </rule>
  4842. <rule id="100701" level="4">
  4843. <!-- LOG_ID_PPTP_EXIT -->
  4844. <if_sid>100010</if_sid>
  4845. <field name="logid">040036$</field>
  4846. <description>PPTP daemon exited</description>
  4847. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4848. </rule>
  4849. <rule id="100702" level="4">
  4850. <!-- LOG_ID_PPTPD_SVR_DISCON -->
  4851. <if_sid>100010</if_sid>
  4852. <field name="logid">040037$</field>
  4853. <description>PPTP daemon disconnected</description>
  4854. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4855. </rule>
  4856. <rule id="100703" level="4">
  4857. <!-- LOG_ID_PPTPD_CLIENT_CON -->
  4858. <if_sid>100010</if_sid>
  4859. <field name="logid">040038$</field>
  4860. <description>PPTP client connected</description>
  4861. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4862. </rule>
  4863. <rule id="100704" level="4">
  4864. <!-- LOG_ID_PPTPD_CLIENT_DISCON -->
  4865. <if_sid>100010</if_sid>
  4866. <field name="logid">040039$</field>
  4867. <description>PPTP client disconnected</description>
  4868. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4869. </rule>
  4870. <rule id="100705" level="4">
  4871. <!-- LOG_ID_L2TP_TUNNEL_UP -->
  4872. <if_sid>100010</if_sid>
  4873. <field name="logid">040101$</field>
  4874. <description>L2TP tunnel up</description>
  4875. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4876. </rule>
  4877. <rule id="100706" level="4">
  4878. <!-- LOG_ID_L2TP_TUNNEL_DOWN -->
  4879. <if_sid>100010</if_sid>
  4880. <field name="logid">040102$</field>
  4881. <description>L2TP tunnel down</description>
  4882. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4883. </rule>
  4884. <rule id="100707" level="4">
  4885. <!-- LOG_ID_L2TP_TUNNEL_STAT -->
  4886. <if_sid>100010</if_sid>
  4887. <field name="logid">040103$</field>
  4888. <description>L2TP tunnel status</description>
  4889. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4890. </rule>
  4891. <rule id="100708" level="4">
  4892. <!-- LOG_ID_L2TPD_START -->
  4893. <if_sid>100010</if_sid>
  4894. <field name="logid">040114$</field>
  4895. <description>L2TP daemon started</description>
  4896. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4897. </rule>
  4898. <rule id="100709" level="4">
  4899. <!-- LOG_ID_L2TPD_EXIT -->
  4900. <if_sid>100010</if_sid>
  4901. <field name="logid">040115$</field>
  4902. <description>L2TP daemon exited</description>
  4903. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  4904. </rule>
  4905. <rule id="100710" level="4">
  4906. <!-- LOG_ID_L2TPD_CLIENT_CON -->
  4907. <if_sid>100010</if_sid>
  4908. <field name="logid">040118$</field>
  4909. <description>L2TP client connected</description>
  4910. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  4911. </rule>
  4912. <rule id="100711" level="4">
  4913. <!-- LOG_ID_EVENT_SYS_PERF -->
  4914. <if_sid>100010</if_sid>
  4915. <field name="logid">040704$</field>
  4916. <description>System performance statistics</description>
  4917. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4918. </rule>
  4919. <rule id="100712" level="4">
  4920. <!-- LOG_ID_EVENT_SYS_CPU_USAGE -->
  4921. <if_sid>100010</if_sid>
  4922. <field name="logid">040705$</field>
  4923. <description>CPU usage statistics</description>
  4924. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4925. </rule>
  4926. <rule id="100713" level="4">
  4927. <!-- LOG_ID_EVENT_SYS_BROKEN_SYMBOLIC_LINK -->
  4928. <if_sid>100010</if_sid>
  4929. <field name="logid">040706$</field>
  4930. <description>Delete broken symbolic link</description>
  4931. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4932. </rule>
  4933. <rule id="100714" level="4">
  4934. <!-- LOG_ID_EVENT_SYS_CPU_USAGE_SINGLE_CORE -->
  4935. <if_sid>100010</if_sid>
  4936. <field name="logid">040707$</field>
  4937. <description>CPU single core usage statistics</description>
  4938. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4939. </rule>
  4940. <rule id="100715" level="4">
  4941. <!-- LOGID_EVENT_WAD_WEBPROXY_FWD_SRV_ERROR -->
  4942. <if_sid>100010</if_sid>
  4943. <field name="logid">040960$</field>
  4944. <description>Web proxy forward server error</description>
  4945. <group>fortios.event.event,fortios.category.wad,fortios.severity.notice</group>
  4946. </rule>
  4947. <rule id="100716" level="4">
  4948. <!-- LOG_ID_UPD_FGT_SUCC -->
  4949. <if_sid>100010</if_sid>
  4950. <field name="logid">041000$</field>
  4951. <description>FortiGate update succeeded</description>
  4952. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4953. </rule>
  4954. <rule id="100717" level="4">
  4955. <!-- LOG_ID_UPD_FGT_FAIL -->
  4956. <if_sid>100010</if_sid>
  4957. <field name="logid">041001$</field>
  4958. <description>FortiGate update failed</description>
  4959. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  4960. </rule>
  4961. <rule id="100718" level="4">
  4962. <!-- LOG_ID_UPD_SRC_VIS -->
  4963. <if_sid>100010</if_sid>
  4964. <field name="logid">041002$</field>
  4965. <description>Source visibility signature package updated</description>
  4966. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4967. </rule>
  4968. <rule id="100719" level="4">
  4969. <!-- LOG_ID_UPD_FSA_VIRDB -->
  4970. <if_sid>100010</if_sid>
  4971. <field name="logid">041006$</field>
  4972. <description>FortiSandbox AV database updated</description>
  4973. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4974. </rule>
  4975. <rule id="100720" level="4">
  4976. <!-- LOG_ID_UPD_MANUAL_LICENSE_SUCC -->
  4977. <if_sid>100010</if_sid>
  4978. <field name="logid">041007$</field>
  4979. <description>FortiGate Manual License update</description>
  4980. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  4981. </rule>
  4982. <rule id="100721" level="4">
  4983. <!-- LOG_ID_UPD_MANUAL_LICENSE_FAIL -->
  4984. <if_sid>100010</if_sid>
  4985. <field name="logid">041008$</field>
  4986. <description>FortiGate Manual License is invalid</description>
  4987. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  4988. </rule>
  4989. <rule id="100722" level="4">
  4990. <!-- LOG_ID_UPD_DB_SIGN_INVALID -->
  4991. <if_sid>100010</if_sid>
  4992. <field name="logid">041009$</field>
  4993. <description>FortiGate database signature invalid</description>
  4994. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  4995. </rule>
  4996. <rule id="100723" level="4">
  4997. <!-- LOG_ID_UPD_DB_UNSIGNED_INSTALLED -->
  4998. <if_sid>100010</if_sid>
  4999. <field name="logid">041011$</field>
  5000. <description>FortiGate database without signature installed</description>
  5001. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  5002. </rule>
  5003. <rule id="100724" level="4">
  5004. <!-- LOG_ID_EVENT_VPN_CERT_LOAD -->
  5005. <if_sid>100010</if_sid>
  5006. <field name="logid">041984$</field>
  5007. <description>Certificate loaded</description>
  5008. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5009. </rule>
  5010. <rule id="100725" level="4">
  5011. <!-- LOG_ID_EVENT_VPN_CERT_REMOVAL -->
  5012. <if_sid>100010</if_sid>
  5013. <field name="logid">041985$</field>
  5014. <description>Certificate removed</description>
  5015. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5016. </rule>
  5017. <rule id="100726" level="4">
  5018. <!-- LOG_ID_EVENT_VPN_CERT_REGEN -->
  5019. <if_sid>100010</if_sid>
  5020. <field name="logid">041986$</field>
  5021. <description>Certificate regenerated</description>
  5022. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5023. </rule>
  5024. <rule id="100727" level="4">
  5025. <!-- LOG_ID_EVENT_VPN_CERT_UPDATE -->
  5026. <if_sid>100010</if_sid>
  5027. <field name="logid">041987$</field>
  5028. <description>Certificate updated</description>
  5029. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5030. </rule>
  5031. <rule id="100728" level="4">
  5032. <!-- LOG_ID_EVENT_SSL_VPN_SETTING_UPDATE -->
  5033. <if_sid>100010</if_sid>
  5034. <field name="logid">041988$</field>
  5035. <description>SSL setting changed</description>
  5036. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5037. </rule>
  5038. <rule id="100729" level="4">
  5039. <!-- LOG_ID_EVENT_VPN_CERT_ERR -->
  5040. <if_sid>100010</if_sid>
  5041. <field name="logid">041989$</field>
  5042. <description>Certificate error</description>
  5043. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5044. </rule>
  5045. <rule id="100730" level="4">
  5046. <!-- LOG_ID_EVENT_VPN_CERT_UPDATE_FAILED -->
  5047. <if_sid>100010</if_sid>
  5048. <field name="logid">041990$</field>
  5049. <description>Certificate update failed</description>
  5050. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5051. </rule>
  5052. <rule id="100731" level="4">
  5053. <!-- LOG_ID_EVENT_VPN_CERT_EXPORT -->
  5054. <if_sid>100010</if_sid>
  5055. <field name="logid">041991$</field>
  5056. <description>Certificate exported</description>
  5057. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5058. </rule>
  5059. <rule id="100732" level="4">
  5060. <!-- LOG_ID_EVENT_VPN_CERT_CRL_EXPIRED -->
  5061. <if_sid>100010</if_sid>
  5062. <field name="logid">041992$</field>
  5063. <description>CRL certificate file is expired</description>
  5064. <group>fortios.event.event,fortios.category.vpn,fortios.severity.information</group>
  5065. </rule>
  5066. <rule id="100733" level="4">
  5067. <!-- LOG_ID_NETX_VMX_ATTACH -->
  5068. <if_sid>100010</if_sid>
  5069. <field name="logid">042201$</field>
  5070. <description>VMX instance successfully attached</description>
  5071. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  5072. </rule>
  5073. <rule id="100734" level="4">
  5074. <!-- LOG_ID_NETX_VMX_DETACH -->
  5075. <if_sid>100010</if_sid>
  5076. <field name="logid">042202$</field>
  5077. <description>VMX instance successfully detached</description>
  5078. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  5079. </rule>
  5080. <rule id="100735" level="4">
  5081. <!-- LOG_ID_NETX_VMX_DENIED -->
  5082. <if_sid>100010</if_sid>
  5083. <field name="logid">042203$</field>
  5084. <description>VMX instance successfully denied</description>
  5085. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  5086. </rule>
  5087. <rule id="100736" level="4">
  5088. <!-- LOG_ID_EVENT_AUTH_SUCCESS -->
  5089. <if_sid>100010</if_sid>
  5090. <field name="logid">043008$</field>
  5091. <description>Authentication success</description>
  5092. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5093. </rule>
  5094. <rule id="100737" level="4">
  5095. <!-- LOG_ID_EVENT_AUTH_FAILED -->
  5096. <if_sid>100010</if_sid>
  5097. <field name="logid">043009$</field>
  5098. <description>Authentication failed</description>
  5099. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5100. </rule>
  5101. <rule id="100738" level="4">
  5102. <!-- LOG_ID_EVENT_AUTH_LOCKOUT -->
  5103. <if_sid>100010</if_sid>
  5104. <field name="logid">043010$</field>
  5105. <description>Authentication lockout</description>
  5106. <group>fortios.event.event,fortios.category.user,fortios.severity.warning</group>
  5107. </rule>
  5108. <rule id="100739" level="4">
  5109. <!-- LOG_ID_EVENT_AUTH_TIME_OUT -->
  5110. <if_sid>100010</if_sid>
  5111. <field name="logid">043011$</field>
  5112. <description>Authentication timed out</description>
  5113. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5114. </rule>
  5115. <rule id="100740" level="4">
  5116. <!-- LOG_ID_EVENT_AUTH_FSAE_LOGON -->
  5117. <if_sid>100010</if_sid>
  5118. <field name="logid">043014$</field>
  5119. <description>FSSO logon authentication status</description>
  5120. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5121. </rule>
  5122. <rule id="100741" level="4">
  5123. <!-- LOG_ID_EVENT_AUTH_FSAE_LOGOFF -->
  5124. <if_sid>100010</if_sid>
  5125. <field name="logid">043015$</field>
  5126. <description>FSSO log off authentication status</description>
  5127. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5128. </rule>
  5129. <rule id="100742" level="4">
  5130. <!-- LOG_ID_EVENT_AUTH_NTLM_AUTH_SUCCESS -->
  5131. <if_sid>100010</if_sid>
  5132. <field name="logid">043016$</field>
  5133. <description>NTLM authentication successful</description>
  5134. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5135. </rule>
  5136. <rule id="100743" level="4">
  5137. <!-- LOG_ID_EVENT_AUTH_NTLM_AUTH_FAIL -->
  5138. <if_sid>100010</if_sid>
  5139. <field name="logid">043017$</field>
  5140. <description>NTLM authentication failed</description>
  5141. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5142. </rule>
  5143. <rule id="100744" level="4">
  5144. <!-- LOG_ID_EVENT_AUTH_FGOVRD_FAIL -->
  5145. <if_sid>100010</if_sid>
  5146. <field name="logid">043018$</field>
  5147. <description>FortiGuard override failed</description>
  5148. <group>fortios.event.event,fortios.category.user,fortios.severity.warning</group>
  5149. </rule>
  5150. <rule id="100745" level="4">
  5151. <!-- LOG_ID_EVENT_AUTH_FGOVRD_SUCCESS -->
  5152. <if_sid>100010</if_sid>
  5153. <field name="logid">043020$</field>
  5154. <description>FortiGuard override successful</description>
  5155. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5156. </rule>
  5157. <rule id="100746" level="4">
  5158. <!-- LOG_ID_EVENT_AUTH_PROXY_SUCCESS -->
  5159. <if_sid>100010</if_sid>
  5160. <field name="logid">043025$</field>
  5161. <description>Explicit proxy authentication successful</description>
  5162. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5163. </rule>
  5164. <rule id="100747" level="4">
  5165. <!-- LOG_ID_EVENT_AUTH_PROXY_FAILED -->
  5166. <if_sid>100010</if_sid>
  5167. <field name="logid">043026$</field>
  5168. <description>Explicit proxy authentication failed</description>
  5169. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5170. </rule>
  5171. <rule id="100748" level="4">
  5172. <!-- LOG_ID_EVENT_AUTH_PROXY_TIME_OUT -->
  5173. <if_sid>100010</if_sid>
  5174. <field name="logid">043027$</field>
  5175. <description>Explicit proxy authentication timed out</description>
  5176. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5177. </rule>
  5178. <rule id="100749" level="4">
  5179. <!-- LOG_ID_EVENT_AUTH_PROXY_GROUP_INFO_FAILED -->
  5180. <if_sid>100010</if_sid>
  5181. <field name="logid">043028$</field>
  5182. <description>Explicit proxy user group query failed</description>
  5183. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5184. </rule>
  5185. <rule id="100750" level="4">
  5186. <!-- LOG_ID_EVENT_AUTH_WARNING_SUCCESS -->
  5187. <if_sid>100010</if_sid>
  5188. <field name="logid">043029$</field>
  5189. <description>FortiGuard authentication override successful</description>
  5190. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5191. </rule>
  5192. <rule id="100751" level="4">
  5193. <!-- LOG_ID_EVENT_AUTH_WARNING_TBL_FULL -->
  5194. <if_sid>100010</if_sid>
  5195. <field name="logid">043030$</field>
  5196. <description>FortiGuard authentication override failed</description>
  5197. <group>fortios.event.event,fortios.category.user,fortios.severity.warning</group>
  5198. </rule>
  5199. <rule id="100752" level="4">
  5200. <!-- LOG_ID_EVENT_AUTH_PROXY_USER_LIMIT_REACHED -->
  5201. <if_sid>100010</if_sid>
  5202. <field name="logid">043032$</field>
  5203. <description>Explicit proxy authentication user limit reached</description>
  5204. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5205. </rule>
  5206. <rule id="100753" level="4">
  5207. <!-- LOG_ID_EVENT_AUTH_PROXY_MULTIPLE_LOGIN -->
  5208. <if_sid>100010</if_sid>
  5209. <field name="logid">043033$</field>
  5210. <description>Explicit proxy authentication user concurrent check failed</description>
  5211. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5212. </rule>
  5213. <rule id="100754" level="4">
  5214. <!-- LOG_ID_EVENT_AUTH_PROXY_NO_RESP -->
  5215. <if_sid>100010</if_sid>
  5216. <field name="logid">043034$</field>
  5217. <description>Explicit proxy authentication no response</description>
  5218. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5219. </rule>
  5220. <rule id="100755" level="4">
  5221. <!-- LOG_ID_EVENT_AUTH_IPV4_FLUSH -->
  5222. <if_sid>100010</if_sid>
  5223. <field name="logid">043037$</field>
  5224. <description>Authentication IPv4 logon flush</description>
  5225. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5226. </rule>
  5227. <rule id="100756" level="4">
  5228. <!-- LOG_ID_EVENT_AUTH_IPV6_FLUSH -->
  5229. <if_sid>100010</if_sid>
  5230. <field name="logid">043038$</field>
  5231. <description>Authentication IPv6 logon flush</description>
  5232. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5233. </rule>
  5234. <rule id="100757" level="4">
  5235. <!-- LOG_ID_EVENT_AUTH_LOGON -->
  5236. <if_sid>100010</if_sid>
  5237. <field name="logid">043039$</field>
  5238. <description>Authentication logon</description>
  5239. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5240. </rule>
  5241. <rule id="100758" level="4">
  5242. <!-- LOG_ID_EVENT_AUTH_LOGOUT -->
  5243. <if_sid>100010</if_sid>
  5244. <field name="logid">043040$</field>
  5245. <description>Authentication logout</description>
  5246. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5247. </rule>
  5248. <rule id="100759" level="4">
  5249. <!-- LOG_ID_EVENT_AUTH_DISCLAIMER_ACCEPT -->
  5250. <if_sid>100010</if_sid>
  5251. <field name="logid">043041$</field>
  5252. <description>Disclaimer accepted</description>
  5253. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5254. </rule>
  5255. <rule id="100760" level="4">
  5256. <!-- LOG_ID_EVENT_AUTH_DISCLAIMER_DECLINE -->
  5257. <if_sid>100010</if_sid>
  5258. <field name="logid">043042$</field>
  5259. <description>Disclaimer declined</description>
  5260. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5261. </rule>
  5262. <rule id="100761" level="4">
  5263. <!-- LOG_ID_EVENT_AUTH_EMAIL_COLLECTING_SUCCESS -->
  5264. <if_sid>100010</if_sid>
  5265. <field name="logid">043043$</field>
  5266. <description>Email collecting succeeded</description>
  5267. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5268. </rule>
  5269. <rule id="100762" level="4">
  5270. <!-- LOG_ID_EVENT_AUTH_EMAIL_COLLECTING_FAIL -->
  5271. <if_sid>100010</if_sid>
  5272. <field name="logid">043044$</field>
  5273. <description>Email collecting failed</description>
  5274. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5275. </rule>
  5276. <rule id="100763" level="4">
  5277. <!-- LOG_ID_EVENT_AUTH_8021X_SUCCESS -->
  5278. <if_sid>100010</if_sid>
  5279. <field name="logid">043045$</field>
  5280. <description>802.1x authentication succeeded</description>
  5281. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5282. </rule>
  5283. <rule id="100764" level="4">
  5284. <!-- LOG_ID_EVENT_AUTH_8021X_FAIL -->
  5285. <if_sid>100010</if_sid>
  5286. <field name="logid">043046$</field>
  5287. <description>802.1x authentication failed</description>
  5288. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5289. </rule>
  5290. <rule id="100765" level="4">
  5291. <!-- LOG_ID_EVENT_AUTH_FSAE_CONNECT -->
  5292. <if_sid>100010</if_sid>
  5293. <field name="logid">043050$</field>
  5294. <description>FSSO server connected</description>
  5295. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5296. </rule>
  5297. <rule id="100766" level="4">
  5298. <!-- LOG_ID_EVENT_AUTH_FSAE_DISCONNECT -->
  5299. <if_sid>100010</if_sid>
  5300. <field name="logid">043051$</field>
  5301. <description>FSSO server disconnected</description>
  5302. <group>fortios.event.event,fortios.category.user,fortios.severity.notice</group>
  5303. </rule>
  5304. <rule id="100767" level="4">
  5305. <!-- LOG_ID_EVENT_WIRELESS_SYS -->
  5306. <if_sid>100010</if_sid>
  5307. <field name="logid">043520$</field>
  5308. <description>Wireless system activity</description>
  5309. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5310. </rule>
  5311. <rule id="100768" level="4">
  5312. <!-- LOG_ID_EVENT_WIRELESS_ROGUE -->
  5313. <if_sid>100010</if_sid>
  5314. <field name="logid">043521$</field>
  5315. <description>Rogue AP activity</description>
  5316. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5317. </rule>
  5318. <rule id="100769" level="4">
  5319. <!-- LOG_ID_EVENT_WIRELESS_WTP -->
  5320. <if_sid>100010</if_sid>
  5321. <field name="logid">043522$</field>
  5322. <description>Physical AP activity</description>
  5323. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5324. </rule>
  5325. <rule id="100770" level="4">
  5326. <!-- LOG_ID_EVENT_WIRELESS_STA -->
  5327. <if_sid>100010</if_sid>
  5328. <field name="logid">043524$</field>
  5329. <description>Wireless client activity</description>
  5330. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5331. </rule>
  5332. <rule id="100771" level="4">
  5333. <!-- LOG_ID_EVENT_WIRELESS_ONWIRE -->
  5334. <if_sid>100010</if_sid>
  5335. <field name="logid">043525$</field>
  5336. <description>Rogue AP on wire</description>
  5337. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5338. </rule>
  5339. <rule id="100772" level="4">
  5340. <!-- LOG_ID_EVENT_WIRELESS_WTPR -->
  5341. <if_sid>100010</if_sid>
  5342. <field name="logid">043526$</field>
  5343. <description>Physical AP radio activity</description>
  5344. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5345. </rule>
  5346. <rule id="100773" level="4">
  5347. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_CFG -->
  5348. <if_sid>100010</if_sid>
  5349. <field name="logid">043527$</field>
  5350. <description>Rogue AP status configured</description>
  5351. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5352. </rule>
  5353. <rule id="100774" level="4">
  5354. <!-- LOG_ID_EVENT_WIRELESS_WTPR_ERROR -->
  5355. <if_sid>100010</if_sid>
  5356. <field name="logid">043528$</field>
  5357. <description>Physical AP radio error activity</description>
  5358. <group>fortios.event.event,fortios.category.wireless,fortios.severity.error</group>
  5359. </rule>
  5360. <rule id="100775" level="4">
  5361. <!-- LOG_ID_EVENT_WIRELESS_CLB -->
  5362. <if_sid>100010</if_sid>
  5363. <field name="logid">043529$</field>
  5364. <description>Wireless client load balancing</description>
  5365. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5366. </rule>
  5367. <rule id="100776" level="4">
  5368. <!-- LOG_ID_EVENT_WIRELESS_WIDS_WL_BRIDGE -->
  5369. <if_sid>100010</if_sid>
  5370. <field name="logid">043530$</field>
  5371. <description>Wireless bridge intrusion detected</description>
  5372. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5373. </rule>
  5374. <rule id="100777" level="4">
  5375. <!-- LOG_ID_EVENT_WIRELESS_WIDS_BR_DEAUTH -->
  5376. <if_sid>100010</if_sid>
  5377. <field name="logid">043531$</field>
  5378. <description>Wireless broadcasting deauthentication detected</description>
  5379. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5380. </rule>
  5381. <rule id="100778" level="4">
  5382. <!-- LOG_ID_EVENT_WIRELESS_WIDS_NL_PBRESP -->
  5383. <if_sid>100010</if_sid>
  5384. <field name="logid">043532$</field>
  5385. <description>Wireless null SSID probe response detected</description>
  5386. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5387. </rule>
  5388. <rule id="100779" level="4">
  5389. <!-- LOG_ID_EVENT_WIRELESS_WIDS_MAC_OUI -->
  5390. <if_sid>100010</if_sid>
  5391. <field name="logid">043533$</field>
  5392. <description>Wireless invalid MAC OUI detected</description>
  5393. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5394. </rule>
  5395. <rule id="100780" level="4">
  5396. <!-- LOG_ID_EVENT_WIRELESS_WIDS_LONG_DUR -->
  5397. <if_sid>100010</if_sid>
  5398. <field name="logid">043534$</field>
  5399. <description>Wireless long duration attack detected</description>
  5400. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5401. </rule>
  5402. <rule id="100781" level="4">
  5403. <!-- LOG_ID_EVENT_WIRELESS_WIDS_WEP_IV -->
  5404. <if_sid>100010</if_sid>
  5405. <field name="logid">043535$</field>
  5406. <description>Wireless Weak WEP IV detected</description>
  5407. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5408. </rule>
  5409. <rule id="100782" level="4">
  5410. <!-- LOG_ID_EVENT_WIRELESS_WIDS_EAPOL_FLOOD -->
  5411. <if_sid>100010</if_sid>
  5412. <field name="logid">043542$</field>
  5413. <description>Wireless EAPOL packet flooding detected</description>
  5414. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5415. </rule>
  5416. <rule id="100783" level="4">
  5417. <!-- LOG_ID_EVENT_WIRELESS_WIDS_MGMT_FLOOD -->
  5418. <if_sid>100010</if_sid>
  5419. <field name="logid">043544$</field>
  5420. <description>Wireless management flooding detected</description>
  5421. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5422. </rule>
  5423. <rule id="100784" level="4">
  5424. <!-- LOG_ID_EVENT_WIRELESS_WIDS_SPOOF_DEAUTH -->
  5425. <if_sid>100010</if_sid>
  5426. <field name="logid">043546$</field>
  5427. <description>Wireless spoofed deauthentication detected</description>
  5428. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5429. </rule>
  5430. <rule id="100785" level="4">
  5431. <!-- LOG_ID_EVENT_WIRELESS_WIDS_ASLEAP -->
  5432. <if_sid>100010</if_sid>
  5433. <field name="logid">043548$</field>
  5434. <description>Wireless Asleap attack detected</description>
  5435. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5436. </rule>
  5437. <rule id="100786" level="4">
  5438. <!-- LOG_ID_EVENT_WIRELESS_STA_LOCATE -->
  5439. <if_sid>100010</if_sid>
  5440. <field name="logid">043550$</field>
  5441. <description>Wireless station presence detection</description>
  5442. <group>fortios.event.event,fortios.category.wireless,fortios.severity.information</group>
  5443. </rule>
  5444. <rule id="100787" level="4">
  5445. <!-- LOG_ID_EVENT_WIRELESS_WTP_JOIN -->
  5446. <if_sid>100010</if_sid>
  5447. <field name="logid">043551$</field>
  5448. <description>Physical AP join</description>
  5449. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5450. </rule>
  5451. <rule id="100788" level="4">
  5452. <!-- LOG_ID_EVENT_WIRELESS_WTP_LEAVE -->
  5453. <if_sid>100010</if_sid>
  5454. <field name="logid">043552$</field>
  5455. <description>Physical AP leave</description>
  5456. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5457. </rule>
  5458. <rule id="100789" level="4">
  5459. <!-- LOG_ID_EVENT_WIRELESS_WTP_FAIL -->
  5460. <if_sid>100010</if_sid>
  5461. <field name="logid">043553$</field>
  5462. <description>Physical AP fail</description>
  5463. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5464. </rule>
  5465. <rule id="100790" level="4">
  5466. <!-- LOG_ID_EVENT_WIRELESS_WTP_UPDATE -->
  5467. <if_sid>100010</if_sid>
  5468. <field name="logid">043554$</field>
  5469. <description>Physical AP update</description>
  5470. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5471. </rule>
  5472. <rule id="100791" level="4">
  5473. <!-- LOG_ID_EVENT_WIRELESS_WTP_RESET -->
  5474. <if_sid>100010</if_sid>
  5475. <field name="logid">043555$</field>
  5476. <description>Physical AP reset</description>
  5477. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5478. </rule>
  5479. <rule id="100792" level="4">
  5480. <!-- LOG_ID_EVENT_WIRELESS_WTP_KICK -->
  5481. <if_sid>100010</if_sid>
  5482. <field name="logid">043556$</field>
  5483. <description>Physical AP kick</description>
  5484. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5485. </rule>
  5486. <rule id="100793" level="4">
  5487. <!-- LOG_ID_EVENT_WIRELESS_WTP_ADD_FAILURE -->
  5488. <if_sid>100010</if_sid>
  5489. <field name="logid">043557$</field>
  5490. <description>Physical AP add failure</description>
  5491. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5492. </rule>
  5493. <rule id="100794" level="4">
  5494. <!-- LOG_ID_EVENT_WIRELESS_WTP_CFG_ERR -->
  5495. <if_sid>100010</if_sid>
  5496. <field name="logid">043558$</field>
  5497. <description>Physical AP config error</description>
  5498. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5499. </rule>
  5500. <rule id="100795" level="4">
  5501. <!-- LOG_ID_EVENT_WIRELESS_WTP_SN_MISMATCH -->
  5502. <if_sid>100010</if_sid>
  5503. <field name="logid">043559$</field>
  5504. <description>Physical AP SN mismatch</description>
  5505. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5506. </rule>
  5507. <rule id="100796" level="4">
  5508. <!-- LOG_ID_EVENT_WIRELESS_SYS_AC_RESTARTED -->
  5509. <if_sid>100010</if_sid>
  5510. <field name="logid">043560$</field>
  5511. <description>Wireless system restarted</description>
  5512. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5513. </rule>
  5514. <rule id="100797" level="4">
  5515. <!-- LOG_ID_EVENT_WIRELESS_SYS_AC_HOSTAPD_UP -->
  5516. <if_sid>100010</if_sid>
  5517. <field name="logid">043561$</field>
  5518. <description>Wireless system hostapd up</description>
  5519. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5520. </rule>
  5521. <rule id="100798" level="4">
  5522. <!-- LOG_ID_EVENT_WIRELESS_SYS_AC_HOSTAPD_DOWN -->
  5523. <if_sid>100010</if_sid>
  5524. <field name="logid">043562$</field>
  5525. <description>Wireless system hostapd down</description>
  5526. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5527. </rule>
  5528. <rule id="100799" level="4">
  5529. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_DETECT -->
  5530. <if_sid>100010</if_sid>
  5531. <field name="logid">043563$</field>
  5532. <description>Rogue AP detected</description>
  5533. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5534. </rule>
  5535. <rule id="100800" level="4">
  5536. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_OFFAIR -->
  5537. <if_sid>100010</if_sid>
  5538. <field name="logid">043564$</field>
  5539. <description>Rogue AP off air</description>
  5540. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5541. </rule>
  5542. <rule id="100801" level="4">
  5543. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_ONAIR -->
  5544. <if_sid>100010</if_sid>
  5545. <field name="logid">043565$</field>
  5546. <description>Rogue AP on air</description>
  5547. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5548. </rule>
  5549. <rule id="100802" level="4">
  5550. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_OFFWIRE -->
  5551. <if_sid>100010</if_sid>
  5552. <field name="logid">043566$</field>
  5553. <description>Rogue AP off wire</description>
  5554. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5555. </rule>
  5556. <rule id="100803" level="4">
  5557. <!-- LOG_ID_EVENT_WIRELESS_FAKEAP_DETECT -->
  5558. <if_sid>100010</if_sid>
  5559. <field name="logid">043567$</field>
  5560. <description>Fake AP detected</description>
  5561. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5562. </rule>
  5563. <rule id="100804" level="4">
  5564. <!-- LOG_ID_EVENT_WIRELESS_FAKEAP_ONAIR -->
  5565. <if_sid>100010</if_sid>
  5566. <field name="logid">043568$</field>
  5567. <description>Fake AP on air</description>
  5568. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5569. </rule>
  5570. <rule id="100805" level="4">
  5571. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_SUPPRESSED -->
  5572. <if_sid>100010</if_sid>
  5573. <field name="logid">043569$</field>
  5574. <description>Rogue AP suppressed</description>
  5575. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5576. </rule>
  5577. <rule id="100806" level="4">
  5578. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_UNSUPPRESSED -->
  5579. <if_sid>100010</if_sid>
  5580. <field name="logid">043570$</field>
  5581. <description>Rogue AP unsuppressed</description>
  5582. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5583. </rule>
  5584. <rule id="100807" level="4">
  5585. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_DETECT_CHG -->
  5586. <if_sid>100010</if_sid>
  5587. <field name="logid">043571$</field>
  5588. <description>Rogue AP change detected</description>
  5589. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5590. </rule>
  5591. <rule id="100808" level="4">
  5592. <!-- LOG_ID_EVENT_WIRELESS_STA_ASSO -->
  5593. <if_sid>100010</if_sid>
  5594. <field name="logid">043572$</field>
  5595. <description>Wireless client associated</description>
  5596. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5597. </rule>
  5598. <rule id="100809" level="4">
  5599. <!-- LOG_ID_EVENT_WIRELESS_STA_AUTH -->
  5600. <if_sid>100010</if_sid>
  5601. <field name="logid">043573$</field>
  5602. <description>Wireless client authenticated</description>
  5603. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5604. </rule>
  5605. <rule id="100810" level="4">
  5606. <!-- LOG_ID_EVENT_WIRELESS_STA_DASS -->
  5607. <if_sid>100010</if_sid>
  5608. <field name="logid">043574$</field>
  5609. <description>Wireless client disassociated</description>
  5610. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5611. </rule>
  5612. <rule id="100811" level="4">
  5613. <!-- LOG_ID_EVENT_WIRELESS_STA_DAUT -->
  5614. <if_sid>100010</if_sid>
  5615. <field name="logid">043575$</field>
  5616. <description>Wireless client deauthenticated</description>
  5617. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5618. </rule>
  5619. <rule id="100812" level="4">
  5620. <!-- LOG_ID_EVENT_WIRELESS_STA_IDLE -->
  5621. <if_sid>100010</if_sid>
  5622. <field name="logid">043576$</field>
  5623. <description>Wireless client idle</description>
  5624. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5625. </rule>
  5626. <rule id="100813" level="4">
  5627. <!-- LOG_ID_EVENT_WIRELESS_STA_DENY -->
  5628. <if_sid>100010</if_sid>
  5629. <field name="logid">043577$</field>
  5630. <description>Wireless client denied</description>
  5631. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5632. </rule>
  5633. <rule id="100814" level="4">
  5634. <!-- LOG_ID_EVENT_WIRELESS_STA_KICK -->
  5635. <if_sid>100010</if_sid>
  5636. <field name="logid">043578$</field>
  5637. <description>Wireless client kicked</description>
  5638. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5639. </rule>
  5640. <rule id="100815" level="4">
  5641. <!-- LOG_ID_EVENT_WIRELESS_STA_IP -->
  5642. <if_sid>100010</if_sid>
  5643. <field name="logid">043579$</field>
  5644. <description>Wireless client IP assigned</description>
  5645. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5646. </rule>
  5647. <rule id="100816" level="4">
  5648. <!-- LOG_ID_EVENT_WIRELESS_STA_LEAVE_WTP -->
  5649. <if_sid>100010</if_sid>
  5650. <field name="logid">043580$</field>
  5651. <description>Wireless client left WTP</description>
  5652. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5653. </rule>
  5654. <rule id="100817" level="4">
  5655. <!-- LOG_ID_EVENT_WIRELESS_STA_WTP_DISCONN -->
  5656. <if_sid>100010</if_sid>
  5657. <field name="logid">043581$</field>
  5658. <description>Wireless client WTP disconnected</description>
  5659. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5660. </rule>
  5661. <rule id="100818" level="4">
  5662. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_CFG_UNCLASSIFIED -->
  5663. <if_sid>100010</if_sid>
  5664. <field name="logid">043582$</field>
  5665. <description>Rogue AP status configured as unclassified</description>
  5666. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5667. </rule>
  5668. <rule id="100819" level="4">
  5669. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_CFG_ACCEPTED -->
  5670. <if_sid>100010</if_sid>
  5671. <field name="logid">043583$</field>
  5672. <description>Rogue AP status configured as accepted</description>
  5673. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5674. </rule>
  5675. <rule id="100820" level="4">
  5676. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_CFG_ROGUE -->
  5677. <if_sid>100010</if_sid>
  5678. <field name="logid">043584$</field>
  5679. <description>Rogue AP status configured as rogue</description>
  5680. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5681. </rule>
  5682. <rule id="100821" level="4">
  5683. <!-- LOG_ID_EVENT_WIRELESS_ROGUE_CFG_SUPPRESSED -->
  5684. <if_sid>100010</if_sid>
  5685. <field name="logid">043585$</field>
  5686. <description>Rogue AP status configured as suppressed</description>
  5687. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5688. </rule>
  5689. <rule id="100822" level="4">
  5690. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DARRP_CHAN -->
  5691. <if_sid>100010</if_sid>
  5692. <field name="logid">043586$</field>
  5693. <description>Physical AP radio DARRP channel change</description>
  5694. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5695. </rule>
  5696. <rule id="100823" level="4">
  5697. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DARRP_START -->
  5698. <if_sid>100010</if_sid>
  5699. <field name="logid">043587$</field>
  5700. <description>Physical AP radio DARRP start</description>
  5701. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5702. </rule>
  5703. <rule id="100824" level="4">
  5704. <!-- LOG_ID_EVENT_WIRELESS_WTPR_OPER_CHAN -->
  5705. <if_sid>100010</if_sid>
  5706. <field name="logid">043588$</field>
  5707. <description>Physical AP radio operation channel change</description>
  5708. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5709. </rule>
  5710. <rule id="100825" level="4">
  5711. <!-- LOG_ID_EVENT_WIRELESS_WTPR_RADAR -->
  5712. <if_sid>100010</if_sid>
  5713. <field name="logid">043589$</field>
  5714. <description>Physical AP radio radar detected</description>
  5715. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5716. </rule>
  5717. <rule id="100826" level="4">
  5718. <!-- LOG_ID_EVENT_WIRELESS_WTPR_NOL -->
  5719. <if_sid>100010</if_sid>
  5720. <field name="logid">043590$</field>
  5721. <description>Physical AP radio channel removed from NOL</description>
  5722. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5723. </rule>
  5724. <rule id="100827" level="4">
  5725. <!-- LOG_ID_EVENT_WIRELESS_WTPR_COUNTRY_CFG_SUCCESS -->
  5726. <if_sid>100010</if_sid>
  5727. <field name="logid">043591$</field>
  5728. <description>Physical AP radio country config success</description>
  5729. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5730. </rule>
  5731. <rule id="100828" level="4">
  5732. <!-- LOG_ID_EVENT_WIRELESS_WTPR_OPER_COUNTRY -->
  5733. <if_sid>100010</if_sid>
  5734. <field name="logid">043592$</field>
  5735. <description>Physical AP radio operation country</description>
  5736. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5737. </rule>
  5738. <rule id="100829" level="4">
  5739. <!-- LOG_ID_EVENT_WIRELESS_WTPR_CFG_TXPOWER -->
  5740. <if_sid>100010</if_sid>
  5741. <field name="logid">043593$</field>
  5742. <description>Physical AP radio config TX power</description>
  5743. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5744. </rule>
  5745. <rule id="100830" level="4">
  5746. <!-- LOG_ID_EVENT_WIRELESS_WTPR_OPER_TXPOWER -->
  5747. <if_sid>100010</if_sid>
  5748. <field name="logid">043594$</field>
  5749. <description>Physical AP radio operation TX power</description>
  5750. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5751. </rule>
  5752. <rule id="100831" level="4">
  5753. <!-- LOG_ID_EVENT_WIRELESS_CLB_DENY -->
  5754. <if_sid>100010</if_sid>
  5755. <field name="logid">043595$</field>
  5756. <description>Wireless client load balancing denied</description>
  5757. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5758. </rule>
  5759. <rule id="100832" level="4">
  5760. <!-- LOG_ID_EVENT_WIRELESS_CLB_RETRY -->
  5761. <if_sid>100010</if_sid>
  5762. <field name="logid">043596$</field>
  5763. <description>Wireless client load balancing retry</description>
  5764. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5765. </rule>
  5766. <rule id="100833" level="4">
  5767. <!-- LOG_ID_EVENT_WIRELESS_WTP_ADD -->
  5768. <if_sid>100010</if_sid>
  5769. <field name="logid">043597$</field>
  5770. <description>Physical AP add</description>
  5771. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5772. </rule>
  5773. <rule id="100834" level="4">
  5774. <!-- LOG_ID_EVENT_WIRELESS_WTP_ADD_XSS -->
  5775. <if_sid>100010</if_sid>
  5776. <field name="logid">043598$</field>
  5777. <description>Physical AP add XSS</description>
  5778. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5779. </rule>
  5780. <rule id="100835" level="4">
  5781. <!-- LOG_ID_EVENT_WIRELESS_WTP_DEL -->
  5782. <if_sid>100010</if_sid>
  5783. <field name="logid">043599$</field>
  5784. <description>Physical AP delete</description>
  5785. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5786. </rule>
  5787. <rule id="100836" level="4">
  5788. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DARRP_STOP -->
  5789. <if_sid>100010</if_sid>
  5790. <field name="logid">043600$</field>
  5791. <description>Physical AP radio DARRP stop</description>
  5792. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5793. </rule>
  5794. <rule id="100837" level="4">
  5795. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_SIGNON -->
  5796. <if_sid>100010</if_sid>
  5797. <field name="logid">043601$</field>
  5798. <description>Wireless station sign on</description>
  5799. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5800. </rule>
  5801. <rule id="100838" level="4">
  5802. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_SIGNON_SUCCESS -->
  5803. <if_sid>100010</if_sid>
  5804. <field name="logid">043602$</field>
  5805. <description>Wireless station sign on success</description>
  5806. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5807. </rule>
  5808. <rule id="100839" level="4">
  5809. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_SIGNON_FAILURE -->
  5810. <if_sid>100010</if_sid>
  5811. <field name="logid">043603$</field>
  5812. <description>Wireless station sign on failed</description>
  5813. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5814. </rule>
  5815. <rule id="100840" level="4">
  5816. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_EMAIL_REQUEST -->
  5817. <if_sid>100010</if_sid>
  5818. <field name="logid">043604$</field>
  5819. <description>Captive-portal VAP e-mail collect request sent</description>
  5820. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5821. </rule>
  5822. <rule id="100841" level="4">
  5823. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_EMAIL_SUCCESS -->
  5824. <if_sid>100010</if_sid>
  5825. <field name="logid">043605$</field>
  5826. <description>Captive-portal VAP e-mail collect success</description>
  5827. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5828. </rule>
  5829. <rule id="100842" level="4">
  5830. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_EMAIL_FAILURE -->
  5831. <if_sid>100010</if_sid>
  5832. <field name="logid">043606$</field>
  5833. <description>Captive-portal VAP e-mail collect failed</description>
  5834. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5835. </rule>
  5836. <rule id="100843" level="4">
  5837. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_DISCLAIMER_CHECK -->
  5838. <if_sid>100010</if_sid>
  5839. <field name="logid">043607$</field>
  5840. <description>Captive-portal VAP disclaimer agreed</description>
  5841. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5842. </rule>
  5843. <rule id="100844" level="4">
  5844. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_DISCLAIMER_DECLINE -->
  5845. <if_sid>100010</if_sid>
  5846. <field name="logid">043608$</field>
  5847. <description>Captive-portal VAP disclaimer declined</description>
  5848. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5849. </rule>
  5850. <rule id="100845" level="4">
  5851. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DARRP_OPTIMIZATION_START -->
  5852. <if_sid>100010</if_sid>
  5853. <field name="logid">043609$</field>
  5854. <description>DARRP optimization start</description>
  5855. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5856. </rule>
  5857. <rule id="100846" level="4">
  5858. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DARRP_OPTIMIZATION_STOP -->
  5859. <if_sid>100010</if_sid>
  5860. <field name="logid">043610$</field>
  5861. <description>DARRP optimization stop</description>
  5862. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5863. </rule>
  5864. <rule id="100847" level="4">
  5865. <!-- LOG_ID_EVENT_WIRELESS_SYS_AC_UP -->
  5866. <if_sid>100010</if_sid>
  5867. <field name="logid">043611$</field>
  5868. <description>Wireless controller start</description>
  5869. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5870. </rule>
  5871. <rule id="100848" level="4">
  5872. <!-- LOG_ID_EVENT_WIRELESS_SYS_AC_CFG_LOADED -->
  5873. <if_sid>100010</if_sid>
  5874. <field name="logid">043612$</field>
  5875. <description>Wireless controller configuration loaded</description>
  5876. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5877. </rule>
  5878. <rule id="100849" level="4">
  5879. <!-- LOG_ID_EVENT_WIRELESS_WTP_ERR -->
  5880. <if_sid>100010</if_sid>
  5881. <field name="logid">043613$</field>
  5882. <description>Physical AP error</description>
  5883. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5884. </rule>
  5885. <rule id="100850" level="4">
  5886. <!-- LOG_ID_EVENT_WIRELESS_DHCP_STAVATION -->
  5887. <if_sid>100010</if_sid>
  5888. <field name="logid">043614$</field>
  5889. <description>DHCP Starvation detected</description>
  5890. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5891. </rule>
  5892. <rule id="100851" level="4">
  5893. <!-- LOG_ID_EVENT_WIRELESS_SYS_AC_IPSEC_FAIL -->
  5894. <if_sid>100010</if_sid>
  5895. <field name="logid">043615$</field>
  5896. <description>Wireless controller IPsec setup failed</description>
  5897. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5898. </rule>
  5899. <rule id="100852" level="4">
  5900. <!-- LOG_ID_EVENT_WIRELESS_WTPR_NOL_ADD -->
  5901. <if_sid>100010</if_sid>
  5902. <field name="logid">043616$</field>
  5903. <description>Physical AP radio NOL added</description>
  5904. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5905. </rule>
  5906. <rule id="100853" level="4">
  5907. <!-- LOG_ID_EVENT_WIRELESS_WTP_IMAGE_RC_SUCCESS -->
  5908. <if_sid>100010</if_sid>
  5909. <field name="logid">043618$</field>
  5910. <description>Physical AP image receive success</description>
  5911. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5912. </rule>
  5913. <rule id="100854" level="4">
  5914. <!-- LOG_ID_EVENT_WIRELESS_OFFENDINGAP_DETECT -->
  5915. <if_sid>100010</if_sid>
  5916. <field name="logid">043619$</field>
  5917. <description>Offending AP detected</description>
  5918. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5919. </rule>
  5920. <rule id="100855" level="4">
  5921. <!-- LOG_ID_EVENT_WIRELESS_OFFENDINGAP_ONAIR -->
  5922. <if_sid>100010</if_sid>
  5923. <field name="logid">043620$</field>
  5924. <description>Offending AP on air</description>
  5925. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5926. </rule>
  5927. <rule id="100856" level="4">
  5928. <!-- LOG_ID_EVENT_WIRELESS_WTP_DATA_CHAN_CHG -->
  5929. <if_sid>100010</if_sid>
  5930. <field name="logid">043621$</field>
  5931. <description>Wireless wtp data channel changed</description>
  5932. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5933. </rule>
  5934. <rule id="100857" level="4">
  5935. <!-- LOG_ID_EVENT_WIRELESS_WTP_VLAN_PROBE -->
  5936. <if_sid>100010</if_sid>
  5937. <field name="logid">043622$</field>
  5938. <description>WTP is probing vlan</description>
  5939. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5940. </rule>
  5941. <rule id="100858" level="4">
  5942. <!-- LOG_ID_EVENT_WIRELESS_WTP_VLAN_MISSING -->
  5943. <if_sid>100010</if_sid>
  5944. <field name="logid">043623$</field>
  5945. <description>VLAN not detected</description>
  5946. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5947. </rule>
  5948. <rule id="100859" level="4">
  5949. <!-- LOG_ID_EVENT_WIRELESS_WTP_VLAN_DETECTED -->
  5950. <if_sid>100010</if_sid>
  5951. <field name="logid">043624$</field>
  5952. <description>VLAN detected</description>
  5953. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5954. </rule>
  5955. <rule id="100860" level="4">
  5956. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_CMCC_SUCCESS -->
  5957. <if_sid>100010</if_sid>
  5958. <field name="logid">043625$</field>
  5959. <description>Wireless station CMCC sign on success</description>
  5960. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5961. </rule>
  5962. <rule id="100861" level="4">
  5963. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_CMCC_FAILURE -->
  5964. <if_sid>100010</if_sid>
  5965. <field name="logid">043626$</field>
  5966. <description>Wireless station CMCC sign on failed</description>
  5967. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5968. </rule>
  5969. <rule id="100862" level="4">
  5970. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_CMCC_TIMEOUT -->
  5971. <if_sid>100010</if_sid>
  5972. <field name="logid">043627$</field>
  5973. <description>Wireless station CMCC sign on timeout</description>
  5974. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5975. </rule>
  5976. <rule id="100863" level="4">
  5977. <!-- LOG_ID_EVENT_WIRELESS_STA_CAP_CMCC_MAC_AUTH_SUCCESS -->
  5978. <if_sid>100010</if_sid>
  5979. <field name="logid">043628$</field>
  5980. <description>Wireless station CMCC MAC auth success</description>
  5981. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  5982. </rule>
  5983. <rule id="100864" level="4">
  5984. <!-- LOG_ID_EVENT_WIRELESS_STA_RADIUS_AUTH_FAILURE -->
  5985. <if_sid>100010</if_sid>
  5986. <field name="logid">043629$</field>
  5987. <description>Wireless client RADIUS authentication failure</description>
  5988. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5989. </rule>
  5990. <rule id="100865" level="4">
  5991. <!-- LOG_ID_EVENT_WIRELESS_STA_RADIUS_AUTH_SUCCESS -->
  5992. <if_sid>100010</if_sid>
  5993. <field name="logid">043630$</field>
  5994. <description>Wireless client RADIUS authentication success</description>
  5995. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  5996. </rule>
  5997. <rule id="100866" level="4">
  5998. <!-- LOG_ID_EVENT_WIRELESS_STA_RADIUS_AUTH_NO_RESP -->
  5999. <if_sid>100010</if_sid>
  6000. <field name="logid">043631$</field>
  6001. <description>Wireless client RADIUS authentication server not responding</description>
  6002. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6003. </rule>
  6004. <rule id="100867" level="4">
  6005. <!-- LOG_ID_EVENT_WIRELESS_STA_RADIUS_MAC_AUTH_FAILURE -->
  6006. <if_sid>100010</if_sid>
  6007. <field name="logid">043632$</field>
  6008. <description>Wireless client RADIUS MAC authentication failure</description>
  6009. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6010. </rule>
  6011. <rule id="100868" level="4">
  6012. <!-- LOG_ID_EVENT_WIRELESS_STA_RADIUS_MAC_AUTH_SUCCESS -->
  6013. <if_sid>100010</if_sid>
  6014. <field name="logid">043633$</field>
  6015. <description>Wireless client RADIUS MAC authentication success</description>
  6016. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6017. </rule>
  6018. <rule id="100869" level="4">
  6019. <!-- LOG_ID_EVENT_WIRELESS_STA_RADIUS_MAC_AUTH_NO_RESP -->
  6020. <if_sid>100010</if_sid>
  6021. <field name="logid">043634$</field>
  6022. <description>Wireless client RADIUS MAC authentication server not responding</description>
  6023. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6024. </rule>
  6025. <rule id="100870" level="4">
  6026. <!-- LOG_ID_EVENT_WIRELESS_STA_OKC_NO_MATCH -->
  6027. <if_sid>100010</if_sid>
  6028. <field name="logid">043635$</field>
  6029. <description>Wireless client authenticates through OKC failed with no match</description>
  6030. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6031. </rule>
  6032. <rule id="100871" level="4">
  6033. <!-- LOG_ID_EVENT_WIRELESS_STA_OKC_LOCAL_MATCH -->
  6034. <if_sid>100010</if_sid>
  6035. <field name="logid">043636$</field>
  6036. <description>Wireless client authenticates through local OKC success</description>
  6037. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6038. </rule>
  6039. <rule id="100872" level="4">
  6040. <!-- LOG_ID_EVENT_WIRELESS_STA_OKC_INTER_AC_MATCH -->
  6041. <if_sid>100010</if_sid>
  6042. <field name="logid">043637$</field>
  6043. <description>Wireless client authenticates through inter AC OKC success</description>
  6044. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6045. </rule>
  6046. <rule id="100873" level="4">
  6047. <!-- LOG_ID_EVENT_WIRELESS_STA_OKC_INTER_AP_MATCH -->
  6048. <if_sid>100010</if_sid>
  6049. <field name="logid">043638$</field>
  6050. <description>Wireless client authenticates through inter AP OKC success</description>
  6051. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6052. </rule>
  6053. <rule id="100874" level="4">
  6054. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_INVALID_ACTION_REQ -->
  6055. <if_sid>100010</if_sid>
  6056. <field name="logid">043639$</field>
  6057. <description>Wireless client sent invalid FT action request</description>
  6058. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6059. </rule>
  6060. <rule id="100875" level="4">
  6061. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_INVALID_AUTH_REQ -->
  6062. <if_sid>100010</if_sid>
  6063. <field name="logid">043640$</field>
  6064. <description>Wireless client sent invalid FT auth request</description>
  6065. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6066. </rule>
  6067. <rule id="100876" level="4">
  6068. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_INVALID_REASSOC_REQ -->
  6069. <if_sid>100010</if_sid>
  6070. <field name="logid">043641$</field>
  6071. <description>Wireless client sent invalid FT reassociation request</description>
  6072. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6073. </rule>
  6074. <rule id="100877" level="4">
  6075. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_ACTION_REQ -->
  6076. <if_sid>100010</if_sid>
  6077. <field name="logid">043642$</field>
  6078. <description>Wireless client sent FT action reqeust</description>
  6079. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6080. </rule>
  6081. <rule id="100878" level="4">
  6082. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_ACTION_RESP -->
  6083. <if_sid>100010</if_sid>
  6084. <field name="logid">043643$</field>
  6085. <description>FT action response was sent to wireless client</description>
  6086. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6087. </rule>
  6088. <rule id="100879" level="4">
  6089. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_AUTH_REQ -->
  6090. <if_sid>100010</if_sid>
  6091. <field name="logid">043644$</field>
  6092. <description>Wireless client sent FT auth request</description>
  6093. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6094. </rule>
  6095. <rule id="100880" level="4">
  6096. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_AUTH_RESP -->
  6097. <if_sid>100010</if_sid>
  6098. <field name="logid">043645$</field>
  6099. <description>FT auth response was sent to wireless client</description>
  6100. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6101. </rule>
  6102. <rule id="100881" level="4">
  6103. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_REASSOC_REQ -->
  6104. <if_sid>100010</if_sid>
  6105. <field name="logid">043646$</field>
  6106. <description>Wireless client sent FT reassociation request</description>
  6107. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6108. </rule>
  6109. <rule id="100882" level="4">
  6110. <!-- LOG_ID_EVENT_WIRELESS_STA_FT_REASSOC_RESP -->
  6111. <if_sid>100010</if_sid>
  6112. <field name="logid">043647$</field>
  6113. <description>FT reassociation response was sent to wireless client</description>
  6114. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6115. </rule>
  6116. <rule id="100883" level="4">
  6117. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_INVALID_SECOND_MSG -->
  6118. <if_sid>100010</if_sid>
  6119. <field name="logid">043648$</field>
  6120. <description>Wireless client 4 way handshake failed with invalid 2/4 message</description>
  6121. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6122. </rule>
  6123. <rule id="100884" level="4">
  6124. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_INVALID_FOURTH_MSG -->
  6125. <if_sid>100010</if_sid>
  6126. <field name="logid">043649$</field>
  6127. <description>Wireless client 4 way handshake failed with invalid 4/4 message</description>
  6128. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6129. </rule>
  6130. <rule id="100885" level="4">
  6131. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_FIRST_MSG -->
  6132. <if_sid>100010</if_sid>
  6133. <field name="logid">043650$</field>
  6134. <description>AP sent 1/4 message of 4 way handshake to wireless client</description>
  6135. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6136. </rule>
  6137. <rule id="100886" level="4">
  6138. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_SECOND_MSG -->
  6139. <if_sid>100010</if_sid>
  6140. <field name="logid">043651$</field>
  6141. <description>Wireless client sent 2/4 message of 4 way handshake</description>
  6142. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6143. </rule>
  6144. <rule id="100887" level="4">
  6145. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_THIRD_MSG -->
  6146. <if_sid>100010</if_sid>
  6147. <field name="logid">043652$</field>
  6148. <description>AP sent 3/4 message of 4 way handshake to wireless client</description>
  6149. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6150. </rule>
  6151. <rule id="100888" level="4">
  6152. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_FOURTH_MSG -->
  6153. <if_sid>100010</if_sid>
  6154. <field name="logid">043653$</field>
  6155. <description>Wireless client sent 4/4 message of 4 way handshake</description>
  6156. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6157. </rule>
  6158. <rule id="100889" level="4">
  6159. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_FIRST_GROUP_MSG -->
  6160. <if_sid>100010</if_sid>
  6161. <field name="logid">043654$</field>
  6162. <description>AP sent 1/2 message of group key handshake to wireless client</description>
  6163. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6164. </rule>
  6165. <rule id="100890" level="4">
  6166. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_SECOND_GROUP_MSG -->
  6167. <if_sid>100010</if_sid>
  6168. <field name="logid">043655$</field>
  6169. <description>Wireless client sent 2/2 message of group key handshake</description>
  6170. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6171. </rule>
  6172. <rule id="100891" level="4">
  6173. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_MAX_STA_CNT -->
  6174. <if_sid>100010</if_sid>
  6175. <field name="logid">043656$</field>
  6176. <description>Max sta count limit for the PSK was reached</description>
  6177. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6178. </rule>
  6179. <rule id="100892" level="4">
  6180. <!-- LOG_ID_EVENT_WIRELESS_STA_ASSOC_FAIL -->
  6181. <if_sid>100010</if_sid>
  6182. <field name="logid">043657$</field>
  6183. <description>Wireless station association failed</description>
  6184. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6185. </rule>
  6186. <rule id="100893" level="4">
  6187. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_NO_RESP -->
  6188. <if_sid>100010</if_sid>
  6189. <field name="logid">043658$</field>
  6190. <description>Wireless station DHCP process failed with no server response</description>
  6191. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6192. </rule>
  6193. <rule id="100894" level="4">
  6194. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_DIFF_OFFER -->
  6195. <if_sid>100010</if_sid>
  6196. <field name="logid">043659$</field>
  6197. <description>Another DHCP server sent DHCP offer to wireless station</description>
  6198. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6199. </rule>
  6200. <rule id="100895" level="4">
  6201. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_NO_ACK -->
  6202. <if_sid>100010</if_sid>
  6203. <field name="logid">043660$</field>
  6204. <description>No DHCP ACK from server</description>
  6205. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6206. </rule>
  6207. <rule id="100896" level="4">
  6208. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_NAK -->
  6209. <if_sid>100010</if_sid>
  6210. <field name="logid">043661$</field>
  6211. <description>DHCP server sent DHCP NAK</description>
  6212. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6213. </rule>
  6214. <rule id="100897" level="4">
  6215. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_DUP_IP -->
  6216. <if_sid>100010</if_sid>
  6217. <field name="logid">043662$</field>
  6218. <description>IP offered has been used by another wireless station</description>
  6219. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6220. </rule>
  6221. <rule id="100898" level="4">
  6222. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_DISCOVER -->
  6223. <if_sid>100010</if_sid>
  6224. <field name="logid">043663$</field>
  6225. <description>Wireless station sent DHCP DISCOVER</description>
  6226. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6227. </rule>
  6228. <rule id="100899" level="4">
  6229. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_OFFER -->
  6230. <if_sid>100010</if_sid>
  6231. <field name="logid">043664$</field>
  6232. <description>DHCP server sent DHCP OFFER</description>
  6233. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6234. </rule>
  6235. <rule id="100900" level="4">
  6236. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_DECLINE -->
  6237. <if_sid>100010</if_sid>
  6238. <field name="logid">043665$</field>
  6239. <description>Wireless station sent DHCP DECLINE</description>
  6240. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6241. </rule>
  6242. <rule id="100901" level="4">
  6243. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_REQUEST -->
  6244. <if_sid>100010</if_sid>
  6245. <field name="logid">043666$</field>
  6246. <description>Wireless station sent DHCP REQUEST</description>
  6247. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6248. </rule>
  6249. <rule id="100902" level="4">
  6250. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_ACK -->
  6251. <if_sid>100010</if_sid>
  6252. <field name="logid">043667$</field>
  6253. <description>DHCP server sent DHCP ACK</description>
  6254. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6255. </rule>
  6256. <rule id="100903" level="4">
  6257. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_RELEASE -->
  6258. <if_sid>100010</if_sid>
  6259. <field name="logid">043668$</field>
  6260. <description>Wireless station sent DHCP RELEASE</description>
  6261. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6262. </rule>
  6263. <rule id="100904" level="4">
  6264. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_INFORM -->
  6265. <if_sid>100010</if_sid>
  6266. <field name="logid">043669$</field>
  6267. <description>Wireless station sent DHCP INFORM</description>
  6268. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6269. </rule>
  6270. <rule id="100905" level="4">
  6271. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_SELF_ASSIGNED -->
  6272. <if_sid>100010</if_sid>
  6273. <field name="logid">043670$</field>
  6274. <description>Wireless station is using self-assigned IP</description>
  6275. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6276. </rule>
  6277. <rule id="100906" level="4">
  6278. <!-- LOG_ID_EVENT_WIRELESS_STA_DNS_NO_RESP -->
  6279. <if_sid>100010</if_sid>
  6280. <field name="logid">043671$</field>
  6281. <description>Wireless station DNS process failed with no server response</description>
  6282. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6283. </rule>
  6284. <rule id="100907" level="4">
  6285. <!-- LOG_ID_EVENT_WIRELESS_STA_DNS_SERVER_FAILURE -->
  6286. <if_sid>100010</if_sid>
  6287. <field name="logid">043672$</field>
  6288. <description>Wireless station DNS process failed due to server failure</description>
  6289. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6290. </rule>
  6291. <rule id="100908" level="4">
  6292. <!-- LOG_ID_EVENT_WIRELESS_STA_DNS_NO_DOMAIN -->
  6293. <if_sid>100010</if_sid>
  6294. <field name="logid">043673$</field>
  6295. <description>Wireless station DNS process failed due to non-existing domain</description>
  6296. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6297. </rule>
  6298. <rule id="100909" level="4">
  6299. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_KRACK_FT_REASSOC -->
  6300. <if_sid>100010</if_sid>
  6301. <field name="logid">043674$</field>
  6302. <description>Wireless station WPA key reinstallation attack on FT reassociation</description>
  6303. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6304. </rule>
  6305. <rule id="100910" level="4">
  6306. <!-- LOG_ID_EVENT_WIRELESS_STA_AUTH_REQ -->
  6307. <if_sid>100010</if_sid>
  6308. <field name="logid">043675$</field>
  6309. <description>Authentication request from wireless station</description>
  6310. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6311. </rule>
  6312. <rule id="100911" level="4">
  6313. <!-- LOG_ID_EVENT_WIRELESS_STA_AUTH_RESP -->
  6314. <if_sid>100010</if_sid>
  6315. <field name="logid">043676$</field>
  6316. <description>Authentication response to wireless station</description>
  6317. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6318. </rule>
  6319. <rule id="100912" level="4">
  6320. <!-- LOG_ID_EVENT_WIRELESS_STA_ASSOC_REQ -->
  6321. <if_sid>100010</if_sid>
  6322. <field name="logid">043677$</field>
  6323. <description>Association request from wireless station</description>
  6324. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6325. </rule>
  6326. <rule id="100913" level="4">
  6327. <!-- LOG_ID_EVENT_WIRELESS_STA_REASSOC_REQ -->
  6328. <if_sid>100010</if_sid>
  6329. <field name="logid">043678$</field>
  6330. <description>Reassociation request from wireless station</description>
  6331. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6332. </rule>
  6333. <rule id="100914" level="4">
  6334. <!-- LOG_ID_EVENT_WIRELESS_STA_ASSOC_RESP -->
  6335. <if_sid>100010</if_sid>
  6336. <field name="logid">043679$</field>
  6337. <description>Association response to wireless station</description>
  6338. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6339. </rule>
  6340. <rule id="100915" level="4">
  6341. <!-- LOG_ID_EVENT_WIRELESS_STA_REASSOC_RESP -->
  6342. <if_sid>100010</if_sid>
  6343. <field name="logid">043680$</field>
  6344. <description>Reassociation response to wireless station</description>
  6345. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6346. </rule>
  6347. <rule id="100916" level="4">
  6348. <!-- LOG_ID_EVENT_WIRELESS_STA_PROBE_REQ -->
  6349. <if_sid>100010</if_sid>
  6350. <field name="logid">043681$</field>
  6351. <description>Probe request from wireless station</description>
  6352. <group>fortios.event.event,fortios.category.wireless,fortios.severity.information</group>
  6353. </rule>
  6354. <rule id="100917" level="4">
  6355. <!-- LOG_ID_EVENT_WIRELESS_STA_PROBE_RESP -->
  6356. <if_sid>100010</if_sid>
  6357. <field name="logid">043682$</field>
  6358. <description>Probe response to wireless station</description>
  6359. <group>fortios.event.event,fortios.category.wireless,fortios.severity.information</group>
  6360. </rule>
  6361. <rule id="100918" level="4">
  6362. <!-- LOG_ID_EVENT_WIRELESS_BLE_DEV_LOCATE -->
  6363. <if_sid>100010</if_sid>
  6364. <field name="logid">043683$</field>
  6365. <description>Wireless ble dev detection</description>
  6366. <group>fortios.event.event,fortios.category.wireless,fortios.severity.information</group>
  6367. </rule>
  6368. <rule id="100919" level="4">
  6369. <!-- LOG_ID_EVENT_WIRELESS_ADDRGRP_DUPLICATE_MAC -->
  6370. <if_sid>100010</if_sid>
  6371. <field name="logid">043684$</field>
  6372. <description>Wireless addrgrp duplicate mac</description>
  6373. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6374. </rule>
  6375. <rule id="100920" level="4">
  6376. <!-- LOG_ID_EVENT_WIRELESS_ADDRGRP_ADDR_APPLY -->
  6377. <if_sid>100010</if_sid>
  6378. <field name="logid">043685$</field>
  6379. <description>Wireless addrgrp address apply</description>
  6380. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6381. </rule>
  6382. <rule id="100921" level="4">
  6383. <!-- LOG_ID_EVENT_WIRELESS_STA_WPA_MSG_INVALID_SCHEDULE -->
  6384. <if_sid>100010</if_sid>
  6385. <field name="logid">043686$</field>
  6386. <description>PSK is out of any valid schedules</description>
  6387. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6388. </rule>
  6389. <rule id="100922" level="4">
  6390. <!-- LOG_ID_EVENT_WIRELESS_STA_WL_BRIDGE_TRAFFIC_STATS -->
  6391. <if_sid>100010</if_sid>
  6392. <field name="logid">043687$</field>
  6393. <description>Traffic stats for station with bridge wlan</description>
  6394. <group>fortios.event.event,fortios.category.wireless,fortios.severity.information</group>
  6395. </rule>
  6396. <rule id="100923" level="4">
  6397. <!-- LOG_ID_EVENT_WIRELESS_APCFG_RECEIVE -->
  6398. <if_sid>100010</if_sid>
  6399. <field name="logid">043688$</field>
  6400. <description>FortiAP receives the apcfg</description>
  6401. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6402. </rule>
  6403. <rule id="100924" level="4">
  6404. <!-- LOG_ID_EVENT_WIRELESS_APCFG_VALIDATING -->
  6405. <if_sid>100010</if_sid>
  6406. <field name="logid">043689$</field>
  6407. <description>FortiAP is validating the apcfg</description>
  6408. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6409. </rule>
  6410. <rule id="100925" level="4">
  6411. <!-- LOG_ID_EVENT_WIRELESS_APCFG_APPLY -->
  6412. <if_sid>100010</if_sid>
  6413. <field name="logid">043690$</field>
  6414. <description>FortiAP applies the apcfg</description>
  6415. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6416. </rule>
  6417. <rule id="100926" level="4">
  6418. <!-- LOG_ID_EVENT_WIRELESS_APCFG_REJECT -->
  6419. <if_sid>100010</if_sid>
  6420. <field name="logid">043691$</field>
  6421. <description>FortiAP rejects the apcfg</description>
  6422. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6423. </rule>
  6424. <rule id="100927" level="4">
  6425. <!-- LOG_ID_EVENT_WIRELESS_WTPR_ANTENNA_DEFECT_DETECT -->
  6426. <if_sid>100010</if_sid>
  6427. <field name="logid">043692$</field>
  6428. <description>Defect antenna detection</description>
  6429. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6430. </rule>
  6431. <rule id="100928" level="4">
  6432. <!-- LOG_ID_EVENT_WIRELESS_STA_WNM_ACTION_BSTM_REQ -->
  6433. <if_sid>100010</if_sid>
  6434. <field name="logid">043693$</field>
  6435. <description>AP sent WNM action BSTM request</description>
  6436. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6437. </rule>
  6438. <rule id="100929" level="4">
  6439. <!-- LOG_ID_EVENT_WIRELESS_STA_WNM_ACTION_BSTM_RESP_ACCEPT -->
  6440. <if_sid>100010</if_sid>
  6441. <field name="logid">043694$</field>
  6442. <description>Wireless client sent WNM action BSTM response accept</description>
  6443. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6444. </rule>
  6445. <rule id="100930" level="4">
  6446. <!-- LOG_ID_EVENT_WIRELESS_STA_WNM_ACTION_BSTM_RESP_REJECT -->
  6447. <if_sid>100010</if_sid>
  6448. <field name="logid">043695$</field>
  6449. <description>Wireless client sent WNM action BSTM response reject</description>
  6450. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6451. </rule>
  6452. <rule id="100931" level="4">
  6453. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DRMA_START -->
  6454. <if_sid>100010</if_sid>
  6455. <field name="logid">043696$</field>
  6456. <description>Physical AP radio DRMA start</description>
  6457. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6458. </rule>
  6459. <rule id="100932" level="4">
  6460. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DRMA_STOP -->
  6461. <if_sid>100010</if_sid>
  6462. <field name="logid">043697$</field>
  6463. <description>Physical AP radio DRMA stop</description>
  6464. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6465. </rule>
  6466. <rule id="100933" level="4">
  6467. <!-- LOG_ID_EVENT_WIRELESS_WTPR_DRMA_MODE -->
  6468. <if_sid>100010</if_sid>
  6469. <field name="logid">043698$</field>
  6470. <description>Physical AP radio DRMA mode</description>
  6471. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6472. </rule>
  6473. <rule id="100934" level="4">
  6474. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_SOLICIT -->
  6475. <if_sid>100010</if_sid>
  6476. <field name="logid">043699$</field>
  6477. <description>Wireless station sent DHCP6 SOLICIT</description>
  6478. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6479. </rule>
  6480. <rule id="100935" level="4">
  6481. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_ADVERTISE -->
  6482. <if_sid>100010</if_sid>
  6483. <field name="logid">043700$</field>
  6484. <description>DHCP6 server sent DHCP6 ADVERTISE</description>
  6485. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6486. </rule>
  6487. <rule id="100936" level="4">
  6488. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_REQUEST -->
  6489. <if_sid>100010</if_sid>
  6490. <field name="logid">043701$</field>
  6491. <description>Wireless station sent DHCP6 REQUEST</description>
  6492. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6493. </rule>
  6494. <rule id="100937" level="4">
  6495. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_CONFIRM -->
  6496. <if_sid>100010</if_sid>
  6497. <field name="logid">043702$</field>
  6498. <description>Wireless station sent DHCP6 CONFIRM</description>
  6499. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6500. </rule>
  6501. <rule id="100938" level="4">
  6502. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_RENEW -->
  6503. <if_sid>100010</if_sid>
  6504. <field name="logid">043703$</field>
  6505. <description>Wireless station sent DHCP6 RENEW</description>
  6506. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6507. </rule>
  6508. <rule id="100939" level="4">
  6509. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_REPLY -->
  6510. <if_sid>100010</if_sid>
  6511. <field name="logid">043704$</field>
  6512. <description>DHCP6 server sent DHCP6 REPLY</description>
  6513. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6514. </rule>
  6515. <rule id="100940" level="4">
  6516. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_RELEASE -->
  6517. <if_sid>100010</if_sid>
  6518. <field name="logid">043705$</field>
  6519. <description>Wireless station sent DHCP6 RELEASE</description>
  6520. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6521. </rule>
  6522. <rule id="100941" level="4">
  6523. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP6_RECONFIGURE -->
  6524. <if_sid>100010</if_sid>
  6525. <field name="logid">043706$</field>
  6526. <description>DHCP6 server sent DHCP6 RECONFIGURE</description>
  6527. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6528. </rule>
  6529. <rule id="100942" level="4">
  6530. <!-- LOG_ID_EVENT_WIRELESS_WTPR_SSID_UP -->
  6531. <if_sid>100010</if_sid>
  6532. <field name="logid">043707$</field>
  6533. <description>Physical AP radio ssid up</description>
  6534. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6535. </rule>
  6536. <rule id="100943" level="4">
  6537. <!-- LOG_ID_EVENT_WIRELESS_WTPR_SSID_DOWN -->
  6538. <if_sid>100010</if_sid>
  6539. <field name="logid">043708$</field>
  6540. <description>Physical AP radio ssid down</description>
  6541. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6542. </rule>
  6543. <rule id="100944" level="4">
  6544. <!-- LOG_ID_EVENT_WIRELESS_STA_DHCP_ENFORCEMENT -->
  6545. <if_sid>100010</if_sid>
  6546. <field name="logid">043709$</field>
  6547. <description>Wireless client denied by DHCP enforcement for using static IP address</description>
  6548. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6549. </rule>
  6550. <rule id="100945" level="4">
  6551. <!-- LOG_ID_EVENT_WIRELESS_SAM_IPERF -->
  6552. <if_sid>100010</if_sid>
  6553. <field name="logid">043710$</field>
  6554. <description>SAM iperf test result</description>
  6555. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6556. </rule>
  6557. <rule id="100946" level="4">
  6558. <!-- LOG_ID_EVENT_WIRELESS_SAM_PING -->
  6559. <if_sid>100010</if_sid>
  6560. <field name="logid">043711$</field>
  6561. <description>SAM ping test result</description>
  6562. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6563. </rule>
  6564. <rule id="100947" level="4">
  6565. <!-- LOG_ID_EVENT_WIRELESS_SAM_AUTH_FAILED -->
  6566. <if_sid>100010</if_sid>
  6567. <field name="logid">043712$</field>
  6568. <description>AP as station failed in SAM authentication</description>
  6569. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6570. </rule>
  6571. <rule id="100948" level="4">
  6572. <!-- LOG_ID_EVENT_WIRELESS_SAM_CWP_AUTH_FAILED -->
  6573. <if_sid>100010</if_sid>
  6574. <field name="logid">043713$</field>
  6575. <description>AP as station failed in SAM CWP authentication</description>
  6576. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6577. </rule>
  6578. <rule id="100949" level="4">
  6579. <!-- LOG_ID_EVENT_WIRELESS_WTP_PARTIAL_PASSWD -->
  6580. <if_sid>100010</if_sid>
  6581. <field name="logid">043714$</field>
  6582. <description>AP received partial login password</description>
  6583. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6584. </rule>
  6585. <rule id="100950" level="4">
  6586. <!-- LOG_ID_EVENT_WIRELESS_WTPR_BSS_COLOR_COLLISION -->
  6587. <if_sid>100010</if_sid>
  6588. <field name="logid">043715$</field>
  6589. <description>AP radio BSS color collision detected.</description>
  6590. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6591. </rule>
  6592. <rule id="100951" level="4">
  6593. <!-- LOG_ID_EVENT_WIRELESS_ADDRGRP_MAX_FW_ADDR -->
  6594. <if_sid>100010</if_sid>
  6595. <field name="logid">043716$</field>
  6596. <description>Wireless addrgrp reached firewal address maximum number</description>
  6597. <group>fortios.event.event,fortios.category.wireless,fortios.severity.warning</group>
  6598. </rule>
  6599. <rule id="100952" level="4">
  6600. <!-- LOG_ID_EVENT_WIRELESS_STA_L3R_REHOME -->
  6601. <if_sid>100010</if_sid>
  6602. <field name="logid">043717$</field>
  6603. <description>Wireless client layer3 roaming rehome</description>
  6604. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6605. </rule>
  6606. <rule id="100953" level="4">
  6607. <!-- LOG_ID_EVENT_WIRELESS_STA_PROBE_LOW_RSSI -->
  6608. <if_sid>100010</if_sid>
  6609. <field name="logid">043719$</field>
  6610. <description>Probe request from wireless station failed due to low rssi</description>
  6611. <group>fortios.event.event,fortios.category.wireless,fortios.severity.notice</group>
  6612. </rule>
  6613. <rule id="100954" level="4">
  6614. <!-- LOG_ID_EVENT_NAC_QUARANTINE -->
  6615. <if_sid>100010</if_sid>
  6616. <field name="logid">043776$</field>
  6617. <description>NAC quarantine</description>
  6618. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  6619. </rule>
  6620. <rule id="100955" level="4">
  6621. <!-- LOG_ID_EVENT_NAC_ANOMALY_QUARANTINE -->
  6622. <if_sid>100010</if_sid>
  6623. <field name="logid">043777$</field>
  6624. <description>NAC anomaly quarantine</description>
  6625. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  6626. </rule>
  6627. <rule id="100956" level="4">
  6628. <!-- LOG_ID_EVENT_ELBC_BLADE_JOIN -->
  6629. <if_sid>100010</if_sid>
  6630. <field name="logid">043800$</field>
  6631. <description>Blade ready to process traffic</description>
  6632. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6633. </rule>
  6634. <rule id="100957" level="4">
  6635. <!-- LOG_ID_EVENT_ELBC_BLADE_LEAVE -->
  6636. <if_sid>100010</if_sid>
  6637. <field name="logid">043801$</field>
  6638. <description>Blade not ready to process traffic</description>
  6639. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6640. </rule>
  6641. <rule id="100958" level="4">
  6642. <!-- LOG_ID_EVENT_ELBC_MASTER_BLADE_FOUND -->
  6643. <if_sid>100010</if_sid>
  6644. <field name="logid">043802$</field>
  6645. <description>Primary blade found</description>
  6646. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6647. </rule>
  6648. <rule id="100959" level="4">
  6649. <!-- LOG_ID_EVENT_ELBC_MASTER_BLADE_LOST -->
  6650. <if_sid>100010</if_sid>
  6651. <field name="logid">043803$</field>
  6652. <description>Primary blade lost</description>
  6653. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6654. </rule>
  6655. <rule id="100960" level="4">
  6656. <!-- LOG_ID_EVENT_ELBC_MASTER_BLADE_CHANGE -->
  6657. <if_sid>100010</if_sid>
  6658. <field name="logid">043804$</field>
  6659. <description>Primary blade changed</description>
  6660. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6661. </rule>
  6662. <rule id="100961" level="4">
  6663. <!-- LOG_ID_EVENT_ELBC_ACTIVE_CHANNEL_FOUND -->
  6664. <if_sid>100010</if_sid>
  6665. <field name="logid">043805$</field>
  6666. <description>ELBC channel active</description>
  6667. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6668. </rule>
  6669. <rule id="100962" level="4">
  6670. <!-- LOG_ID_EVENT_ELBC_ACTIVE_CHANNEL_LOST -->
  6671. <if_sid>100010</if_sid>
  6672. <field name="logid">043806$</field>
  6673. <description>ELBC channel inactive</description>
  6674. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6675. </rule>
  6676. <rule id="100963" level="4">
  6677. <!-- LOG_ID_EVENT_ELBC_ACTIVE_CHANNEL_CHANGE -->
  6678. <if_sid>100010</if_sid>
  6679. <field name="logid">043807$</field>
  6680. <description>ELBC channel failover</description>
  6681. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6682. </rule>
  6683. <rule id="100964" level="4">
  6684. <!-- LOG_ID_EVENT_ELBC_CHASSIS_ACTIVE -->
  6685. <if_sid>100010</if_sid>
  6686. <field name="logid">043808$</field>
  6687. <description>ELBC chassis active</description>
  6688. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6689. </rule>
  6690. <rule id="100965" level="4">
  6691. <!-- LOG_ID_EVENT_ELBC_CHASSIS_INACTIVE -->
  6692. <if_sid>100010</if_sid>
  6693. <field name="logid">043809$</field>
  6694. <description>ELBC chassis inactive</description>
  6695. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6696. </rule>
  6697. <rule id="100966" level="4">
  6698. <!-- LOGID_EVENT_CONFIG_PATH -->
  6699. <if_sid>100010</if_sid>
  6700. <field name="logid">044544$</field>
  6701. <description>Path configured</description>
  6702. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6703. </rule>
  6704. <rule id="100967" level="4">
  6705. <!-- LOGID_EVENT_CONFIG_OBJ -->
  6706. <if_sid>100010</if_sid>
  6707. <field name="logid">044545$</field>
  6708. <description>Object configured</description>
  6709. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6710. </rule>
  6711. <rule id="100968" level="4">
  6712. <!-- LOGID_EVENT_CONFIG_ATTR -->
  6713. <if_sid>100010</if_sid>
  6714. <field name="logid">044546$</field>
  6715. <description>Attribute configured</description>
  6716. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6717. </rule>
  6718. <rule id="100969" level="4">
  6719. <!-- LOGID_EVENT_CONFIG_OBJATTR -->
  6720. <if_sid>100010</if_sid>
  6721. <field name="logid">044547$</field>
  6722. <description>Object attribute configured</description>
  6723. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6724. </rule>
  6725. <rule id="100970" level="4">
  6726. <!-- LOGID_EVENT_CONFIG_EXEC -->
  6727. <if_sid>100010</if_sid>
  6728. <field name="logid">044548$</field>
  6729. <description>Action performed</description>
  6730. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6731. </rule>
  6732. <rule id="100971" level="4">
  6733. <!-- LOGID_EVENT_CMDB_DEADLOCK_DETECTED -->
  6734. <if_sid>100010</if_sid>
  6735. <field name="logid">044555$</field>
  6736. <description>CMDB lock deadlock is detected.</description>
  6737. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  6738. </rule>
  6739. <rule id="100972" level="4">
  6740. <!-- LOG_ID_FCC_ADD -->
  6741. <if_sid>100010</if_sid>
  6742. <field name="logid">045057$</field>
  6743. <description>FortiClient connection added</description>
  6744. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.information</group>
  6745. </rule>
  6746. <rule id="100973" level="4">
  6747. <!-- LOG_ID_FCC_CLOSE -->
  6748. <if_sid>100010</if_sid>
  6749. <field name="logid">045058$</field>
  6750. <description>FortiClient connection closed</description>
  6751. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.information</group>
  6752. </rule>
  6753. <rule id="100974" level="4">
  6754. <!-- LOG_ID_FCC_CLOSE_BY_TYPE -->
  6755. <if_sid>100010</if_sid>
  6756. <field name="logid">045061$</field>
  6757. <description>FortiClient connection closed by type</description>
  6758. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.information</group>
  6759. </rule>
  6760. <rule id="100975" level="4">
  6761. <!-- LOG_ID_FCC_VULN_SCAN -->
  6762. <if_sid>100010</if_sid>
  6763. <field name="logid">045071$</field>
  6764. <description>FortiClient Vulnerability Scan</description>
  6765. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.notice</group>
  6766. </rule>
  6767. <rule id="100976" level="4">
  6768. <!-- LOG_ID_EC_REG_QUARANTINE -->
  6769. <if_sid>100010</if_sid>
  6770. <field name="logid">045114$</field>
  6771. <description>FortiClient endpoint quarantined</description>
  6772. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.notice</group>
  6773. </rule>
  6774. <rule id="100977" level="4">
  6775. <!-- LOG_ID_EC_REG_UNQUARANTINE -->
  6776. <if_sid>100010</if_sid>
  6777. <field name="logid">045115$</field>
  6778. <description>FortiClient endpoint quarantine removed</description>
  6779. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.notice</group>
  6780. </rule>
  6781. <rule id="100978" level="4">
  6782. <!-- LOG_ID_EC_EMS_WS_NOTIFICATION -->
  6783. <if_sid>100010</if_sid>
  6784. <field name="logid">045121$</field>
  6785. <description>EMS WebSocket notification</description>
  6786. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.notice</group>
  6787. </rule>
  6788. <rule id="100979" level="4">
  6789. <!-- LOG_ID_EC_EMS_REST_API_ERROR -->
  6790. <if_sid>100010</if_sid>
  6791. <field name="logid">045122$</field>
  6792. <description>EMS REST API error</description>
  6793. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  6794. </rule>
  6795. <rule id="100980" level="4">
  6796. <!-- LOG_ID_EC_EMS_WS_CONN_ERROR -->
  6797. <if_sid>100010</if_sid>
  6798. <field name="logid">045123$</field>
  6799. <description>EMS WebSocket connection error</description>
  6800. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  6801. </rule>
  6802. <rule id="100981" level="4">
  6803. <!-- LOG_ID_EC_VPND_CONNECT -->
  6804. <if_sid>100010</if_sid>
  6805. <field name="logid">045124$</field>
  6806. <description>FortiClient VPN connected</description>
  6807. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  6808. </rule>
  6809. <rule id="100982" level="4">
  6810. <!-- LOG_ID_EC_VPND_DISCONNECT -->
  6811. <if_sid>100010</if_sid>
  6812. <field name="logid">045125$</field>
  6813. <description>FortiClient VPN disconnected</description>
  6814. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  6815. </rule>
  6816. <rule id="100983" level="4">
  6817. <!-- LOG_ID_EC_CLOUD_ENTITLEMENT_LOST -->
  6818. <if_sid>100010</if_sid>
  6819. <field name="logid">045126$</field>
  6820. <description>EMS Cloud entitlement lost and connection dropped</description>
  6821. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  6822. </rule>
  6823. <rule id="100984" level="4">
  6824. <!-- LOG_ID_EC_EMS_REST_API_NEW_SUCCESS -->
  6825. <if_sid>100010</if_sid>
  6826. <field name="logid">045128$</field>
  6827. <description>EMS REST API recovered from an error</description>
  6828. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.information</group>
  6829. </rule>
  6830. <rule id="100985" level="4">
  6831. <!-- LOG_ID_EC_EMS_EMS_VERIFY -->
  6832. <if_sid>100010</if_sid>
  6833. <field name="logid">045129$</field>
  6834. <description>FCEMS entry has been verified</description>
  6835. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.information</group>
  6836. </rule>
  6837. <rule id="100986" level="4">
  6838. <!-- LOG_ID_EC_EMS_EMS_VERIFY_FAILED -->
  6839. <if_sid>100010</if_sid>
  6840. <field name="logid">045130$</field>
  6841. <description>FCEMS entry has failed to be verified</description>
  6842. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  6843. </rule>
  6844. <rule id="100987" level="4">
  6845. <!-- LOG_ID_EC_EMS_EMS_UNVERIFY -->
  6846. <if_sid>100010</if_sid>
  6847. <field name="logid">045131$</field>
  6848. <description>FCEMS entry has been unverified</description>
  6849. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.information</group>
  6850. </rule>
  6851. <rule id="100988" level="4">
  6852. <!-- LOG_ID_VIP_REAL_SVR_ENA -->
  6853. <if_sid>100010</if_sid>
  6854. <field name="logid">046000$</field>
  6855. <description>VIP real server enabled</description>
  6856. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  6857. </rule>
  6858. <rule id="100989" level="4">
  6859. <!-- LOG_ID_VIP_REAL_SVR_DISA -->
  6860. <if_sid>100010</if_sid>
  6861. <field name="logid">046001$</field>
  6862. <description>VIP real server disabled</description>
  6863. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  6864. </rule>
  6865. <rule id="100990" level="4">
  6866. <!-- LOG_ID_VIP_REAL_SVR_UP -->
  6867. <if_sid>100010</if_sid>
  6868. <field name="logid">046002$</field>
  6869. <description>VIP real server up</description>
  6870. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  6871. </rule>
  6872. <rule id="100991" level="4">
  6873. <!-- LOG_ID_VIP_REAL_SVR_DOWN -->
  6874. <if_sid>100010</if_sid>
  6875. <field name="logid">046003$</field>
  6876. <description>VIP real server down</description>
  6877. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  6878. </rule>
  6879. <rule id="100992" level="4">
  6880. <!-- LOG_ID_VIP_REAL_SVR_ENT_HOLDDOWN -->
  6881. <if_sid>100010</if_sid>
  6882. <field name="logid">046004$</field>
  6883. <description>VIP real server entered hold-down</description>
  6884. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  6885. </rule>
  6886. <rule id="100993" level="4">
  6887. <!-- LOG_ID_VIP_REAL_SVR_FAIL_HOLDDOWN -->
  6888. <if_sid>100010</if_sid>
  6889. <field name="logid">046005$</field>
  6890. <description>VIP real server health check failed during hold-down</description>
  6891. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  6892. </rule>
  6893. <rule id="100994" level="4">
  6894. <!-- LOG_ID_VIP_REAL_SVR_FAIL -->
  6895. <if_sid>100010</if_sid>
  6896. <field name="logid">046006$</field>
  6897. <description>VIP real server health check failed</description>
  6898. <group>fortios.event.event,fortios.category.system,fortios.severity.debug</group>
  6899. </rule>
  6900. <rule id="100995" level="4">
  6901. <!-- LOG_ID_EVENT_EXT_SYS -->
  6902. <if_sid>100010</if_sid>
  6903. <field name="logid">046400$</field>
  6904. <description>FortiExtender system activity</description>
  6905. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.notice</group>
  6906. </rule>
  6907. <rule id="100996" level="4">
  6908. <!-- LOG_ID_EVENT_EXT_LOCAL -->
  6909. <if_sid>100010</if_sid>
  6910. <field name="logid">046401$</field>
  6911. <description>FortiExtender controller activity</description>
  6912. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.notice</group>
  6913. </rule>
  6914. <rule id="100997" level="4">
  6915. <!-- LOG_ID_EVENT_EXT_LOCAL_ERROR -->
  6916. <if_sid>100010</if_sid>
  6917. <field name="logid">046402$</field>
  6918. <description>FortiExtender controller activity error</description>
  6919. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.error</group>
  6920. </rule>
  6921. <rule id="100998" level="4">
  6922. <!-- LOG_ID_EVENT_EXT_REMOTE_EMERG -->
  6923. <if_sid>100010</if_sid>
  6924. <field name="logid">046403$</field>
  6925. <description>Remote FortiExtender emergency activity</description>
  6926. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.emergency</group>
  6927. </rule>
  6928. <rule id="100999" level="4">
  6929. <!-- LOG_ID_EVENT_EXT_REMOTE_ALERT -->
  6930. <if_sid>100010</if_sid>
  6931. <field name="logid">046404$</field>
  6932. <description>Remote FortiExtender alert activity</description>
  6933. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.alert</group>
  6934. </rule>
  6935. <rule id="101000" level="4">
  6936. <!-- LOG_ID_EVENT_EXT_REMOTE_CRITICAL -->
  6937. <if_sid>100010</if_sid>
  6938. <field name="logid">046405$</field>
  6939. <description>Remote FortiExtender critical activity</description>
  6940. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.critical</group>
  6941. </rule>
  6942. <rule id="101001" level="4">
  6943. <!-- LOG_ID_EVENT_EXT_REMOTE_ERROR -->
  6944. <if_sid>100010</if_sid>
  6945. <field name="logid">046406$</field>
  6946. <description>Remote FortiExtender error activity</description>
  6947. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.error</group>
  6948. </rule>
  6949. <rule id="101002" level="4">
  6950. <!-- LOG_ID_EVENT_EXT_REMOTE_WARNING -->
  6951. <if_sid>100010</if_sid>
  6952. <field name="logid">046407$</field>
  6953. <description>Remote FortiExtender warning activity</description>
  6954. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.warning</group>
  6955. </rule>
  6956. <rule id="101003" level="4">
  6957. <!-- LOG_ID_EVENT_EXT_REMOTE_NOTIF -->
  6958. <if_sid>100010</if_sid>
  6959. <field name="logid">046408$</field>
  6960. <description>Remote FortiExtender notify activity</description>
  6961. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.notice</group>
  6962. </rule>
  6963. <rule id="101004" level="4">
  6964. <!-- LOG_ID_EVENT_EXT_REMOTE_INFO -->
  6965. <if_sid>100010</if_sid>
  6966. <field name="logid">046409$</field>
  6967. <description>Remote FortiExtender info activity</description>
  6968. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.information</group>
  6969. </rule>
  6970. <rule id="101005" level="4">
  6971. <!-- LOG_ID_EVENT_EXT_REMOTE_DEBUG -->
  6972. <if_sid>100010</if_sid>
  6973. <field name="logid">046410$</field>
  6974. <description>Remote FortiExtender debug activity</description>
  6975. <group>fortios.event.event,fortios.category.fortiextender,fortios.severity.debug</group>
  6976. </rule>
  6977. <rule id="101006" level="4">
  6978. <!-- LOG_ID_INTERNAL_LTE_MODEM_DETECTION -->
  6979. <if_sid>100010</if_sid>
  6980. <field name="logid">046501$</field>
  6981. <description>LTE modem detection</description>
  6982. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6983. </rule>
  6984. <rule id="101007" level="4">
  6985. <!-- LOG_ID_INTERNAL_LTE_MODEM_GPSD -->
  6986. <if_sid>100010</if_sid>
  6987. <field name="logid">046502$</field>
  6988. <description>LTE modem GPS daemon started or stopped</description>
  6989. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6990. </rule>
  6991. <rule id="101008" level="4">
  6992. <!-- LOG_ID_INTERNAL_LTE_MODEM_GPS_LOC_ACQUISITION -->
  6993. <if_sid>100010</if_sid>
  6994. <field name="logid">046503$</field>
  6995. <description>LTE modem GPS location acquisition</description>
  6996. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  6997. </rule>
  6998. <rule id="101009" level="4">
  6999. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLD -->
  7000. <if_sid>100010</if_sid>
  7001. <field name="logid">046504$</field>
  7002. <description>LTE modem billing daemon started or stopped</description>
  7003. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7004. </rule>
  7005. <rule id="101010" level="4">
  7006. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLING_PURGED -->
  7007. <if_sid>100010</if_sid>
  7008. <field name="logid">046505$</field>
  7009. <description>LTE billing data purged</description>
  7010. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7011. </rule>
  7012. <rule id="101011" level="4">
  7013. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLING_DAILY_LOG -->
  7014. <if_sid>100010</if_sid>
  7015. <field name="logid">046506$</field>
  7016. <description>LTE billing daily usage information</description>
  7017. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7018. </rule>
  7019. <rule id="101012" level="4">
  7020. <!-- LOG_ID_INTERNAL_LTE_MODEM_FW_UPGRADE -->
  7021. <if_sid>100010</if_sid>
  7022. <field name="logid">046507$</field>
  7023. <description>LTE modem firmware upgrade event</description>
  7024. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7025. </rule>
  7026. <rule id="101013" level="4">
  7027. <!-- LOG_ID_INTERNAL_LTE_MODEM_QDL_DETECTION -->
  7028. <if_sid>100010</if_sid>
  7029. <field name="logid">046508$</field>
  7030. <description>LTE modem QDL device detection event</description>
  7031. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7032. </rule>
  7033. <rule id="101014" level="4">
  7034. <!-- LOG_ID_INTERNAL_LTE_MODEM_REBOOT -->
  7035. <if_sid>100010</if_sid>
  7036. <field name="logid">046509$</field>
  7037. <description>LTE modem reboot event</description>
  7038. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7039. </rule>
  7040. <rule id="101015" level="4">
  7041. <!-- LOG_ID_INTERNAL_LTE_MODEM_OP_MODE -->
  7042. <if_sid>100010</if_sid>
  7043. <field name="logid">046510$</field>
  7044. <description>LTE modem operation mode</description>
  7045. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7046. </rule>
  7047. <rule id="101016" level="4">
  7048. <!-- LOG_ID_INTERNAL_LTE_MODEM_POWER_ON_OFF -->
  7049. <if_sid>100010</if_sid>
  7050. <field name="logid">046511$</field>
  7051. <description>LTE modem powered on or powered off</description>
  7052. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7053. </rule>
  7054. <rule id="101017" level="4">
  7055. <!-- LOG_ID_INTERNAL_LTE_MODEM_SIM_STATE -->
  7056. <if_sid>100010</if_sid>
  7057. <field name="logid">046512$</field>
  7058. <description>LTE modem sim card state event</description>
  7059. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7060. </rule>
  7061. <rule id="101018" level="4">
  7062. <!-- LOG_ID_INTERNAL_LTE_MODEM_LINK_CONNECTION -->
  7063. <if_sid>100010</if_sid>
  7064. <field name="logid">046513$</field>
  7065. <description>LTE modem data link connection event</description>
  7066. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7067. </rule>
  7068. <rule id="101019" level="4">
  7069. <!-- LOG_ID_INTERNAL_LTE_MODEM_MANUAL_HANDOVER -->
  7070. <if_sid>100010</if_sid>
  7071. <field name="logid">046514$</field>
  7072. <description>LTE modem manual handover event</description>
  7073. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7074. </rule>
  7075. <rule id="101020" level="4">
  7076. <!-- LOG_ID_INTERNAL_LTE_MODEM_IP_ADDR -->
  7077. <if_sid>100010</if_sid>
  7078. <field name="logid">046515$</field>
  7079. <description>LTE modem ip address event</description>
  7080. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7081. </rule>
  7082. <rule id="101021" level="4">
  7083. <!-- LOG_ID_INTERNAL_LTE_MODEM_BEARER_TECH_CHANGE -->
  7084. <if_sid>100010</if_sid>
  7085. <field name="logid">046516$</field>
  7086. <description>LTE modem bearer event</description>
  7087. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7088. </rule>
  7089. <rule id="101022" level="4">
  7090. <!-- LOG_ID_INTERNAL_LTE_MODEM_WRONG_PIN -->
  7091. <if_sid>100010</if_sid>
  7092. <field name="logid">046517$</field>
  7093. <description>LTE unlock SIM PIM failed.</description>
  7094. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7095. </rule>
  7096. <rule id="101023" level="4">
  7097. <!-- LOG_ID_EVENT_AUTOMATION_TRIGGERED -->
  7098. <if_sid>100010</if_sid>
  7099. <field name="logid">046600$</field>
  7100. <description>Automation stitch triggered</description>
  7101. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7102. </rule>
  7103. <rule id="101024" level="4">
  7104. <!-- LOG_ID_POE_STATUS_REPORT -->
  7105. <if_sid>100010</if_sid>
  7106. <field name="logid">046900$</field>
  7107. <description>PoE device status reported</description>
  7108. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  7109. </rule>
  7110. <rule id="101025" level="4">
  7111. <!-- LOG_ID_MALWARE_LIST_TRUNCATED_ENTER -->
  7112. <if_sid>100010</if_sid>
  7113. <field name="logid">047000$</field>
  7114. <description>External blocklist list is truncated</description>
  7115. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7116. </rule>
  7117. <rule id="101026" level="4">
  7118. <!-- LOG_ID_MALWARE_LIST_TRUNCATED_EXIT -->
  7119. <if_sid>100010</if_sid>
  7120. <field name="logid">047001$</field>
  7121. <description>External blocklist list is no longer truncated</description>
  7122. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7123. </rule>
  7124. <rule id="101027" level="4">
  7125. <!-- LOG_ID_FILE_HASH_EMS_LIST_TRUNCATED_ENTER -->
  7126. <if_sid>100010</if_sid>
  7127. <field name="logid">047002$</field>
  7128. <description>EMS file-hash list is truncated</description>
  7129. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7130. </rule>
  7131. <rule id="101028" level="4">
  7132. <!-- LOG_ID_FILE_HASH_EMS_LIST_TRUNCATED_EXIT -->
  7133. <if_sid>100010</if_sid>
  7134. <field name="logid">047003$</field>
  7135. <description>EMS file-hash list is no longer truncated</description>
  7136. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7137. </rule>
  7138. <rule id="101029" level="4">
  7139. <!-- LOG_ID_FILE_HASH_EMS_LIST_LOAD -->
  7140. <if_sid>100010</if_sid>
  7141. <field name="logid">047004$</field>
  7142. <description>EMS file-hash list loaded</description>
  7143. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7144. </rule>
  7145. <rule id="101030" level="4">
  7146. <!-- LOG_ID_ENTER_BYPASS -->
  7147. <if_sid>100010</if_sid>
  7148. <field name="logid">047203$</field>
  7149. <description>Bypass ports pair entered bypass mode</description>
  7150. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7151. </rule>
  7152. <rule id="101031" level="4">
  7153. <!-- LOG_ID_EXIT_BYPASS -->
  7154. <if_sid>100010</if_sid>
  7155. <field name="logid">047204$</field>
  7156. <description>Bypass ports pair exited bypass mode</description>
  7157. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7158. </rule>
  7159. <rule id="101032" level="4">
  7160. <!-- LOG_ID_EVENT_REST_API_OK -->
  7161. <if_sid>100010</if_sid>
  7162. <field name="logid">047301$</field>
  7163. <description>REST API request success</description>
  7164. <group>fortios.event.event,fortios.category.rest-api,fortios.severity.information</group>
  7165. </rule>
  7166. <rule id="101033" level="4">
  7167. <!-- LOG_ID_EVENT_REST_API_ERR -->
  7168. <if_sid>100010</if_sid>
  7169. <field name="logid">047302$</field>
  7170. <description>REST API request failed</description>
  7171. <group>fortios.event.event,fortios.category.rest-api,fortios.severity.error</group>
  7172. </rule>
  7173. <rule id="101034" level="4">
  7174. <!-- LOG_ID_WAD_WANOPT_TUNNEL_CREATE -->
  7175. <if_sid>100010</if_sid>
  7176. <field name="logid">048040$</field>
  7177. <description>WANOPT Tunnel successfully created</description>
  7178. <group>fortios.event.event,fortios.category.wad,fortios.severity.information</group>
  7179. </rule>
  7180. <rule id="101035" level="4">
  7181. <!-- LOG_ID_WAD_WANOPT_TUNNEL_CLOSED -->
  7182. <if_sid>100010</if_sid>
  7183. <field name="logid">048041$</field>
  7184. <description>WANOPT Tunnel closed</description>
  7185. <group>fortios.event.event,fortios.category.wad,fortios.severity.information</group>
  7186. </rule>
  7187. <rule id="101036" level="4">
  7188. <!-- LOG_ID_WAD_AUTH_FAIL_PSK -->
  7189. <if_sid>100010</if_sid>
  7190. <field name="logid">048101$</field>
  7191. <description>WAN Optimization peer PSK authentication failed</description>
  7192. <group>fortios.event.event,fortios.category.wad,fortios.severity.error</group>
  7193. </rule>
  7194. <rule id="101037" level="4">
  7195. <!-- LOG_ID_WAD_AUTH_FAIL_OTH -->
  7196. <if_sid>100010</if_sid>
  7197. <field name="logid">048102$</field>
  7198. <description>WAN Optimization peer authentication failed</description>
  7199. <group>fortios.event.event,fortios.category.wad,fortios.severity.error</group>
  7200. </rule>
  7201. <rule id="101038" level="4">
  7202. <!-- LOG_ID_UNEXP_APP_TYPE -->
  7203. <if_sid>100010</if_sid>
  7204. <field name="logid">048301$</field>
  7205. <description>Unexpected application type for WAN Optimization</description>
  7206. <group>fortios.event.event,fortios.category.wad,fortios.severity.critical</group>
  7207. </rule>
  7208. <rule id="101039" level="4">
  7209. <!-- LOG_ID_VNP_DPDK_PRIMARY_RESTART -->
  7210. <if_sid>100010</if_sid>
  7211. <field name="logid">049002$</field>
  7212. <description>VNP Primary restarted</description>
  7213. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7214. </rule>
  7215. <rule id="101040" level="4">
  7216. <!-- LOGID_EVENT_HYPERV_SRIOV_SHOW_UP -->
  7217. <if_sid>100010</if_sid>
  7218. <field name="logid">049004$</field>
  7219. <description>Hyper-V SR-IOV VF secondary is hot plugged</description>
  7220. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7221. </rule>
  7222. <rule id="101041" level="4">
  7223. <!-- LOGID_EVENT_HYPERV_SRIOV_DISAPPEAR -->
  7224. <if_sid>100010</if_sid>
  7225. <field name="logid">049005$</field>
  7226. <description>Hyper-V SR-IOV VF secondary is hot unplugged</description>
  7227. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7228. </rule>
  7229. <rule id="101042" level="4">
  7230. <!-- LOG_ID_NB_TBL_CHG -->
  7231. <if_sid>100010</if_sid>
  7232. <field name="logid">051000$</field>
  7233. <description>Neighbor table changed</description>
  7234. <group>fortios.event.event,fortios.category.router,fortios.severity.information</group>
  7235. </rule>
  7236. <rule id="101043" level="4">
  7237. <!-- LOG_ID_EVENT_SECURITY_AUDIT_FABRIC_SUMMARY -->
  7238. <if_sid>100010</if_sid>
  7239. <field name="logid">052000$</field>
  7240. <description>Security Rating summary</description>
  7241. <group>fortios.event.event,fortios.category.security-rating,fortios.severity.notice</group>
  7242. </rule>
  7243. <rule id="101044" level="4">
  7244. <!-- LOG_ID_EVENT_SECURITY_AUDIT_FABRIC_CHANGE -->
  7245. <if_sid>100010</if_sid>
  7246. <field name="logid">052001$</field>
  7247. <description>Security Rating result change</description>
  7248. <group>fortios.event.event,fortios.category.security-rating,fortios.severity.notice</group>
  7249. </rule>
  7250. <rule id="101045" level="4">
  7251. <!-- LOG_ID_SDNC_CONNECTED -->
  7252. <if_sid>100010</if_sid>
  7253. <field name="logid">053000$</field>
  7254. <description>Connected to SDN server</description>
  7255. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7256. </rule>
  7257. <rule id="101046" level="4">
  7258. <!-- LOG_ID_SDNC_DISCONNECTED -->
  7259. <if_sid>100010</if_sid>
  7260. <field name="logid">053001$</field>
  7261. <description>Disconnected from SDN server</description>
  7262. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7263. </rule>
  7264. <rule id="101047" level="4">
  7265. <!-- LOG_ID_SDNC_SUBSCRIBE -->
  7266. <if_sid>100010</if_sid>
  7267. <field name="logid">053002$</field>
  7268. <description>Dynamic SDN address channel opened</description>
  7269. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7270. </rule>
  7271. <rule id="101048" level="4">
  7272. <!-- LOG_ID_SDNC_UNSUBSCRIBE -->
  7273. <if_sid>100010</if_sid>
  7274. <field name="logid">053003$</field>
  7275. <description>Dynamic SDN address channel closed</description>
  7276. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7277. </rule>
  7278. <rule id="101049" level="4">
  7279. <!-- LOG_ID_VPN_OCVPN_REGISTERED -->
  7280. <if_sid>100010</if_sid>
  7281. <field name="logid">053100$</field>
  7282. <description>Overlay Controller VPN registered</description>
  7283. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  7284. </rule>
  7285. <rule id="101050" level="4">
  7286. <!-- LOG_ID_VPN_OCVPN_UNREGISTERED -->
  7287. <if_sid>100010</if_sid>
  7288. <field name="logid">053101$</field>
  7289. <description>Overlay Controller VPN unregistered</description>
  7290. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  7291. </rule>
  7292. <rule id="101051" level="4">
  7293. <!-- LOG_ID_VPN_OCVPN_COMM_ESTABLISHED -->
  7294. <if_sid>100010</if_sid>
  7295. <field name="logid">053102$</field>
  7296. <description>Overlay Controller VPN server communication established</description>
  7297. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  7298. </rule>
  7299. <rule id="101052" level="4">
  7300. <!-- LOG_ID_VPN_OCVPN_COMM_ERROR -->
  7301. <if_sid>100010</if_sid>
  7302. <field name="logid">053103$</field>
  7303. <description>Overlay Controller VPN server communication error</description>
  7304. <group>fortios.event.event,fortios.category.vpn,fortios.severity.error</group>
  7305. </rule>
  7306. <rule id="101053" level="4">
  7307. <!-- LOG_ID_VPN_OCVPN_DNS_ERROR -->
  7308. <if_sid>100010</if_sid>
  7309. <field name="logid">053104$</field>
  7310. <description>Overlay Controller VPN DNS error</description>
  7311. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  7312. </rule>
  7313. <rule id="101054" level="4">
  7314. <!-- LOG_ID_VPN_OCVPN_ROUTE_ERROR -->
  7315. <if_sid>100010</if_sid>
  7316. <field name="logid">053105$</field>
  7317. <description>Overlay Controller VPN routing error</description>
  7318. <group>fortios.event.event,fortios.category.vpn,fortios.severity.notice</group>
  7319. </rule>
  7320. <rule id="101055" level="4">
  7321. <!-- LOG_ID_CONNECTOR_OBJECT_ADD -->
  7322. <if_sid>100010</if_sid>
  7323. <field name="logid">053200$</field>
  7324. <description>Dynamic address added</description>
  7325. <group>fortios.event.event,fortios.category.connector,fortios.severity.information</group>
  7326. </rule>
  7327. <rule id="101056" level="4">
  7328. <!-- LOG_ID_CONNECTOR_OBJECT_REMOVE -->
  7329. <if_sid>100010</if_sid>
  7330. <field name="logid">053201$</field>
  7331. <description>Dynamic address removed</description>
  7332. <group>fortios.event.event,fortios.category.connector,fortios.severity.information</group>
  7333. </rule>
  7334. <rule id="101057" level="4">
  7335. <!-- LOG_ID_CONNECTOR_API_FAILED -->
  7336. <if_sid>100010</if_sid>
  7337. <field name="logid">053202$</field>
  7338. <description>SDN Connector API failed</description>
  7339. <group>fortios.event.event,fortios.category.connector,fortios.severity.error</group>
  7340. </rule>
  7341. <rule id="101058" level="4">
  7342. <!-- LOG_ID_CONNECTOR_OBJECT_UPDATE -->
  7343. <if_sid>100010</if_sid>
  7344. <field name="logid">053203$</field>
  7345. <description>Dynamic address updated.</description>
  7346. <group>fortios.event.event,fortios.category.connector,fortios.severity.information</group>
  7347. </rule>
  7348. <rule id="101059" level="4">
  7349. <!-- LOG_ID_CONNECTOR_OBJECT_CANT_ADD -->
  7350. <if_sid>100010</if_sid>
  7351. <field name="logid">053204$</field>
  7352. <description>Dynamic address can't be added</description>
  7353. <group>fortios.event.event,fortios.category.connector,fortios.severity.warning</group>
  7354. </rule>
  7355. <rule id="101060" level="4">
  7356. <!-- LOG_ID_CONNECTOR_OBJECT_CANT_REMOVE -->
  7357. <if_sid>100010</if_sid>
  7358. <field name="logid">053205$</field>
  7359. <description>Dynamic address can't be removed</description>
  7360. <group>fortios.event.event,fortios.category.connector,fortios.severity.warning</group>
  7361. </rule>
  7362. <rule id="101061" level="4">
  7363. <!-- LOG_ID_VNE_PRO_UPDATE_COMPLETED -->
  7364. <if_sid>100010</if_sid>
  7365. <field name="logid">053300$</field>
  7366. <description>VNE provision server update completed</description>
  7367. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7368. </rule>
  7369. <rule id="101062" level="4">
  7370. <!-- LOG_ID_VNE_PRO_UPDATE_FAILED -->
  7371. <if_sid>100010</if_sid>
  7372. <field name="logid">053301$</field>
  7373. <description>VNE provision server update failed</description>
  7374. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7375. </rule>
  7376. <rule id="101063" level="4">
  7377. <!-- LOG_ID_NPU_PER_MAPPING_ALLOCATION -->
  7378. <if_sid>100010</if_sid>
  7379. <field name="logid">053311$</field>
  7380. <description>Resource per mapping allocation</description>
  7381. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7382. </rule>
  7383. <rule id="101064" level="4">
  7384. <!-- LOG_ID_NPD_INFO -->
  7385. <if_sid>100010</if_sid>
  7386. <field name="logid">053312$</field>
  7387. <description>NPD INFO</description>
  7388. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7389. </rule>
  7390. <rule id="101065" level="4">
  7391. <!-- LOG_ID_NPD_WARNING -->
  7392. <if_sid>100010</if_sid>
  7393. <field name="logid">053313$</field>
  7394. <description>NPD WARNING MSG</description>
  7395. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7396. </rule>
  7397. <rule id="101066" level="4">
  7398. <!-- LOG_ID_NPD_ERROR -->
  7399. <if_sid>100010</if_sid>
  7400. <field name="logid">053314$</field>
  7401. <description>NPD ERROR MSG</description>
  7402. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  7403. </rule>
  7404. <rule id="101067" level="4">
  7405. <!-- LOG_ID_LPM_ERROR -->
  7406. <if_sid>100010</if_sid>
  7407. <field name="logid">053315$</field>
  7408. <description>LPM ERROR MSG</description>
  7409. <group>fortios.event.event,fortios.category.system,fortios.severity.error</group>
  7410. </rule>
  7411. <rule id="101068" level="4">
  7412. <!-- LOG_ID_LPM_INFO -->
  7413. <if_sid>100010</if_sid>
  7414. <field name="logid">053316$</field>
  7415. <description>LPM INFO MSG</description>
  7416. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7417. </rule>
  7418. <rule id="101069" level="4">
  7419. <!-- LOG_ID_FMG_TUNNEL_UP -->
  7420. <if_sid>100010</if_sid>
  7421. <field name="logid">053400$</field>
  7422. <description>Central Management connectivity is active</description>
  7423. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  7424. </rule>
  7425. <rule id="101070" level="4">
  7426. <!-- LOG_ID_FMG_TUNNEL_DOWN -->
  7427. <if_sid>100010</if_sid>
  7428. <field name="logid">053401$</field>
  7429. <description>Central Management connectivity is inactive</description>
  7430. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7431. </rule>
  7432. <rule id="101071" level="4">
  7433. <!-- LOG_ID_DP_RX_DROP_DETECTED -->
  7434. <if_sid>100010</if_sid>
  7435. <field name="logid">053405$</field>
  7436. <description>DP channel RX drop detected.</description>
  7437. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  7438. </rule>
  7439. <rule id="101072" level="4">
  7440. <!-- LOG_ID_2GB_CSF_UPGRADE -->
  7441. <if_sid>100010</if_sid>
  7442. <field name="logid">053406$</field>
  7443. <description>Security Fabric settings changed during upgrade</description>
  7444. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  7445. </rule>
  7446. <rule id="101073" level="4">
  7447. <!-- LOG_ID_CIFS_CONN_FAIL -->
  7448. <if_sid>100010</if_sid>
  7449. <field name="logid">063002$</field>
  7450. <description>Unable to connect to the CIFS Domain Controller</description>
  7451. <group>fortios.event.event,fortios.category.cifs-auth-fail,fortios.severity.warning</group>
  7452. </rule>
  7453. <rule id="101074" level="4">
  7454. <!-- LOG_ID_CIFS_AUTH_FAIL -->
  7455. <if_sid>100010</if_sid>
  7456. <field name="logid">063003$</field>
  7457. <description>Unable to authenticate with the CIFS Domain Controller</description>
  7458. <group>fortios.event.event,fortios.category.cifs-auth-fail,fortios.severity.warning</group>
  7459. </rule>
  7460. <rule id="101075" level="4">
  7461. <!-- LOG_ID_CIFS_AUTH_INTERNAL_ERROR -->
  7462. <if_sid>100010</if_sid>
  7463. <field name="logid">063004$</field>
  7464. <description>An error occurred in processing CIFS authentication</description>
  7465. <group>fortios.event.event,fortios.category.cifs-auth-fail,fortios.severity.warning</group>
  7466. </rule>
  7467. <rule id="101076" level="4">
  7468. <!-- LOG_ID_CIFS_AUTH_KRB_ERROR -->
  7469. <if_sid>100010</if_sid>
  7470. <field name="logid">063005$</field>
  7471. <description>An error occurred in processing CIFS authentication.</description>
  7472. <group>fortios.event.event,fortios.category.cifs-auth-fail,fortios.severity.warning</group>
  7473. </rule>
  7474. <rule id="101077" level="4">
  7475. <!-- LOG_ID_FILE_FILTER_BLOCK -->
  7476. <if_sid>100010</if_sid>
  7477. <field name="logid">064000$</field>
  7478. <description>File was blocked by file filter</description>
  7479. <group>fortios.event.file-filter,fortios.category.file-filter,fortios.severity.warning</group>
  7480. </rule>
  7481. <rule id="101078" level="4">
  7482. <!-- LOG_ID_FILE_FILTER_LOG -->
  7483. <if_sid>100010</if_sid>
  7484. <field name="logid">064001$</field>
  7485. <description>File was detected by file filter</description>
  7486. <group>fortios.event.file-filter,fortios.category.file-filter,fortios.severity.notice</group>
  7487. </rule>
  7488. <rule id="101079" level="4">
  7489. <!-- LOG_ID_FSW_FLOW -->
  7490. <if_sid>100010</if_sid>
  7491. <field name="logid">056001$</field>
  7492. <description>LOG_ID_FSW_FLOW</description>
  7493. <group>fortios.event.forti-switch,fortios.category.fsw-flow,fortios.severity.information</group>
  7494. </rule>
  7495. <rule id="101080" level="4">
  7496. <!-- LOGID_GTP_FORWARD -->
  7497. <if_sid>100010</if_sid>
  7498. <field name="logid">041216$</field>
  7499. <description>GTP forward</description>
  7500. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7501. </rule>
  7502. <rule id="101081" level="4">
  7503. <!-- LOGID_GTP_DENY -->
  7504. <if_sid>100010</if_sid>
  7505. <field name="logid">041217$</field>
  7506. <description>GTP deny</description>
  7507. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7508. </rule>
  7509. <rule id="101082" level="4">
  7510. <!-- LOGID_GTP_RATE_LIMIT -->
  7511. <if_sid>100010</if_sid>
  7512. <field name="logid">041218$</field>
  7513. <description>GTP rate limit</description>
  7514. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7515. </rule>
  7516. <rule id="101083" level="4">
  7517. <!-- LOGID_GTP_STATE_INVALID -->
  7518. <if_sid>100010</if_sid>
  7519. <field name="logid">041219$</field>
  7520. <description>GTP state invalid</description>
  7521. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7522. </rule>
  7523. <rule id="101084" level="4">
  7524. <!-- LOGID_GTP_TUNNEL_LIMIT -->
  7525. <if_sid>100010</if_sid>
  7526. <field name="logid">041220$</field>
  7527. <description>Tunnel limit GTP message. These messages occur only when the maximum number of GTP</description>
  7528. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7529. </rule>
  7530. <rule id="101085" level="4">
  7531. <!-- LOGID_GTP_TRAFFIC_COUNT -->
  7532. <if_sid>100010</if_sid>
  7533. <field name="logid">041221$</field>
  7534. <description>Statistic summary information when the GTP tunnel is being torn down</description>
  7535. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7536. </rule>
  7537. <rule id="101086" level="4">
  7538. <!-- LOGID_GTP_USER_DATA -->
  7539. <if_sid>100010</if_sid>
  7540. <field name="logid">041222$</field>
  7541. <description>GTP user data</description>
  7542. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7543. </rule>
  7544. <rule id="101087" level="4">
  7545. <!-- LOGID_GTPV2_FORWARD -->
  7546. <if_sid>100010</if_sid>
  7547. <field name="logid">041223$</field>
  7548. <description>GTPv2 forward message</description>
  7549. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7550. </rule>
  7551. <rule id="101088" level="4">
  7552. <!-- LOGID_GTPV2_DENY -->
  7553. <if_sid>100010</if_sid>
  7554. <field name="logid">041224$</field>
  7555. <description>GTPv2 deny message</description>
  7556. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7557. </rule>
  7558. <rule id="101089" level="4">
  7559. <!-- LOGID_GTPV2_RATE_LIMIT -->
  7560. <if_sid>100010</if_sid>
  7561. <field name="logid">041225$</field>
  7562. <description>GTPv2 rate limit message</description>
  7563. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7564. </rule>
  7565. <rule id="101090" level="4">
  7566. <!-- LOGID_GTPV2_STATE_INVALID -->
  7567. <if_sid>100010</if_sid>
  7568. <field name="logid">041226$</field>
  7569. <description>GTPv2 state invalid message</description>
  7570. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7571. </rule>
  7572. <rule id="101091" level="4">
  7573. <!-- LOGID_GTPV2_TUNNEL_LIMIT -->
  7574. <if_sid>100010</if_sid>
  7575. <field name="logid">041227$</field>
  7576. <description>Tunnel limit GTP (version 2) message</description>
  7577. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7578. </rule>
  7579. <rule id="101092" level="4">
  7580. <!-- LOGID_GTPV2_TRAFFIC_COUNT -->
  7581. <if_sid>100010</if_sid>
  7582. <field name="logid">041228$</field>
  7583. <description>Statistic summary information when the GTPv2 tunnel is being torn down</description>
  7584. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7585. </rule>
  7586. <rule id="101093" level="4">
  7587. <!-- LOGID_GTPU_FORWARD -->
  7588. <if_sid>100010</if_sid>
  7589. <field name="logid">041229$</field>
  7590. <description>GTPU forward message</description>
  7591. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7592. </rule>
  7593. <rule id="101094" level="4">
  7594. <!-- LOGID_GTPU_DENY -->
  7595. <if_sid>100010</if_sid>
  7596. <field name="logid">041230$</field>
  7597. <description>GTPU deny message</description>
  7598. <group>fortios.event.gtp,fortios.category.gtp-all,fortios.severity.information</group>
  7599. </rule>
  7600. <rule id="101095" level="4">
  7601. <!-- LOGID_PFCP_FORWARD -->
  7602. <if_sid>100010</if_sid>
  7603. <field name="logid">041231$</field>
  7604. <description>PFCP forward message</description>
  7605. <group>fortios.event.gtp,fortios.category.pfcp-all,fortios.severity.information</group>
  7606. </rule>
  7607. <rule id="101096" level="4">
  7608. <!-- LOGID_PFCP_DENY -->
  7609. <if_sid>100010</if_sid>
  7610. <field name="logid">041232$</field>
  7611. <description>PFCP deny message</description>
  7612. <group>fortios.event.gtp,fortios.category.pfcp-all,fortios.severity.information</group>
  7613. </rule>
  7614. <rule id="101097" level="4">
  7615. <!-- LOGID_PFCP_TRAFFIC_COUNT -->
  7616. <if_sid>100010</if_sid>
  7617. <field name="logid">041233$</field>
  7618. <description>Statistic summary information when the PFCP session is being torn down</description>
  7619. <group>fortios.event.gtp,fortios.category.pfcp-all,fortios.severity.information</group>
  7620. </rule>
  7621. <rule id="101098" level="4">
  7622. <!-- LOG_ID_ICAP_SERVER_ERROR -->
  7623. <if_sid>100010</if_sid>
  7624. <field name="logid">060000$</field>
  7625. <description>Traffic blocked as it cannot be forwarded to ICAP Server.</description>
  7626. <group>fortios.event.icap,fortios.category.icap,fortios.severity.warning</group>
  7627. </rule>
  7628. <rule id="101099" level="4">
  7629. <!-- LOG_ID_ICAP_INFECTION_BLOCK -->
  7630. <if_sid>100010</if_sid>
  7631. <field name="logid">060001$</field>
  7632. <description>Traffic blocked as ICAP server found infection.</description>
  7633. <group>fortios.event.icap,fortios.category.icap,fortios.severity.warning</group>
  7634. </rule>
  7635. <rule id="101100" level="4">
  7636. <!-- LOG_ID_ICAP_SERVER_CLOSE_CONN -->
  7637. <if_sid>100010</if_sid>
  7638. <field name="logid">060002$</field>
  7639. <description>Traffic dropped as ICAP server connection is closed.</description>
  7640. <group>fortios.event.icap,fortios.category.icap,fortios.severity.warning</group>
  7641. </rule>
  7642. <rule id="101101" level="4">
  7643. <!-- LOGID_ATTCK_SIGNATURE_TCP_UDP -->
  7644. <if_sid>100010</if_sid>
  7645. <field name="logid">016384$</field>
  7646. <description>Attack detected by UDP/TCP signature</description>
  7647. <group>fortios.event.ips,fortios.category.signature,fortios.severity.alert</group>
  7648. </rule>
  7649. <rule id="101102" level="4">
  7650. <!-- LOGID_ATTCK_SIGNATURE_ICMP -->
  7651. <if_sid>100010</if_sid>
  7652. <field name="logid">016385$</field>
  7653. <description>Attack detected by ICMP signature</description>
  7654. <group>fortios.event.ips,fortios.category.signature,fortios.severity.alert</group>
  7655. </rule>
  7656. <rule id="101103" level="4">
  7657. <!-- LOGID_ATTCK_SIGNATURE_OTHERS -->
  7658. <if_sid>100010</if_sid>
  7659. <field name="logid">016386$</field>
  7660. <description>Attack detected by other signature</description>
  7661. <group>fortios.event.ips,fortios.category.signature,fortios.severity.alert</group>
  7662. </rule>
  7663. <rule id="101104" level="4">
  7664. <!-- LOGID_ATTACK_MALICIOUS_URL -->
  7665. <if_sid>100010</if_sid>
  7666. <field name="logid">016399$</field>
  7667. <description>Attack detected by a malicious URL</description>
  7668. <group>fortios.event.ips,fortios.category.malicious-url,fortios.severity.warning</group>
  7669. </rule>
  7670. <rule id="101105" level="4">
  7671. <!-- LOGID_ATTACK_BOTNET_WARNING -->
  7672. <if_sid>100010</if_sid>
  7673. <field name="logid">016400$</field>
  7674. <description>Botnet C&amp;C Communication (warning)</description>
  7675. <group>fortios.event.ips,fortios.category.botnet,fortios.severity.warning</group>
  7676. </rule>
  7677. <rule id="101106" level="4">
  7678. <!-- LOGID_ATTACK_BOTNET_NOTIF -->
  7679. <if_sid>100010</if_sid>
  7680. <field name="logid">016401$</field>
  7681. <description>Botnet C&amp;C Communication (notice)</description>
  7682. <group>fortios.event.ips,fortios.category.botnet,fortios.severity.notice</group>
  7683. </rule>
  7684. <rule id="101107" level="4">
  7685. <!-- LOG_ID_SSH_COMMAND_BLOCK -->
  7686. <if_sid>100010</if_sid>
  7687. <field name="logid">061000$</field>
  7688. <description>SSH shell command is blocked</description>
  7689. <group>fortios.event.ssh,fortios.category.ssh-command,fortios.severity.warning</group>
  7690. </rule>
  7691. <rule id="101108" level="4">
  7692. <!-- LOG_ID_SSH_COMMAND_BLOCK_ALERT -->
  7693. <if_sid>100010</if_sid>
  7694. <field name="logid">061001$</field>
  7695. <description>SSH shell command is blocked</description>
  7696. <group>fortios.event.ssh,fortios.category.ssh-command,fortios.severity.alert</group>
  7697. </rule>
  7698. <rule id="101109" level="4">
  7699. <!-- LOG_ID_SSH_COMMAND_PASS -->
  7700. <if_sid>100010</if_sid>
  7701. <field name="logid">061002$</field>
  7702. <description>SSH shell command is detected</description>
  7703. <group>fortios.event.ssh,fortios.category.ssh-command,fortios.severity.notice</group>
  7704. </rule>
  7705. <rule id="101110" level="4">
  7706. <!-- LOG_ID_SSH_COMMAND_PASS_ALERT -->
  7707. <if_sid>100010</if_sid>
  7708. <field name="logid">061003$</field>
  7709. <description>SSH shell command is detected</description>
  7710. <group>fortios.event.ssh,fortios.category.ssh-command,fortios.severity.alert</group>
  7711. </rule>
  7712. <rule id="101111" level="4">
  7713. <!-- LOG_ID_SSH_CHANNEL_BLOCK -->
  7714. <if_sid>100010</if_sid>
  7715. <field name="logid">061010$</field>
  7716. <description>SSH channel is blocked</description>
  7717. <group>fortios.event.ssh,fortios.category.ssh-channel,fortios.severity.warning</group>
  7718. </rule>
  7719. <rule id="101112" level="4">
  7720. <!-- LOG_ID_SSH_CHANNEL_PASS -->
  7721. <if_sid>100010</if_sid>
  7722. <field name="logid">061011$</field>
  7723. <description>SSH channel is detected</description>
  7724. <group>fortios.event.ssh,fortios.category.ssh-channel,fortios.severity.notice</group>
  7725. </rule>
  7726. <rule id="101113" level="4">
  7727. <!-- LOG_ID_SSH_HOST_KEY_WARNING -->
  7728. <if_sid>100010</if_sid>
  7729. <field name="logid">061012$</field>
  7730. <description>SSH connection is blocked, because host-key is not trust</description>
  7731. <group>fortios.event.ssh,fortios.category.ssh-hostkey,fortios.severity.warning</group>
  7732. </rule>
  7733. <rule id="101114" level="4">
  7734. <!-- LOG_ID_SSH_HOST_KEY_NOTIF -->
  7735. <if_sid>100010</if_sid>
  7736. <field name="logid">061013$</field>
  7737. <description>SSH host-key is not trust</description>
  7738. <group>fortios.event.ssh,fortios.category.ssh-hostkey,fortios.severity.notice</group>
  7739. </rule>
  7740. <rule id="101115" level="4">
  7741. <!-- LOG_ID_SSL_EXEMPT_ADDR -->
  7742. <if_sid>100010</if_sid>
  7743. <field name="logid">062004$</field>
  7744. <description>SSL connection is exempted based on address</description>
  7745. <group>fortios.event.ssl,fortios.category.ssl-exempt,fortios.severity.notice</group>
  7746. </rule>
  7747. <rule id="101116" level="4">
  7748. <!-- LOG_ID_SSL_EXEMPT_ALLOWLIST -->
  7749. <if_sid>100010</if_sid>
  7750. <field name="logid">062006$</field>
  7751. <description>SSL connection is exempted based on allowlist</description>
  7752. <group>fortios.event.ssl,fortios.category.ssl-exempt,fortios.severity.notice</group>
  7753. </rule>
  7754. <rule id="101117" level="4">
  7755. <!-- LOG_ID_SSL_EXEMPT_FTGD_CATEGORY -->
  7756. <if_sid>100010</if_sid>
  7757. <field name="logid">062007$</field>
  7758. <description>SSL connection is exempted based on FortiGuard category rating</description>
  7759. <group>fortios.event.ssl,fortios.category.ssl-exempt,fortios.severity.notice</group>
  7760. </rule>
  7761. <rule id="101118" level="4">
  7762. <!-- LOG_ID_SSL_EXEMPT_LOCAL_CATEGORY -->
  7763. <if_sid>100010</if_sid>
  7764. <field name="logid">062008$</field>
  7765. <description>SSL connection is exempted based on local category rating</description>
  7766. <group>fortios.event.ssl,fortios.category.ssl-exempt,fortios.severity.notice</group>
  7767. </rule>
  7768. <rule id="101119" level="4">
  7769. <!-- LOG_ID_SSL_EXEMPT_USER_CATEGORY -->
  7770. <if_sid>100010</if_sid>
  7771. <field name="logid">062009$</field>
  7772. <description>SSL connection is exempted based on user category rating</description>
  7773. <group>fortios.event.ssl,fortios.category.ssl-exempt,fortios.severity.notice</group>
  7774. </rule>
  7775. <rule id="101120" level="4">
  7776. <!-- LOG_ID_SSL_NEGOTIATION_INSPECT -->
  7777. <if_sid>100010</if_sid>
  7778. <field name="logid">062100$</field>
  7779. <description>Continue inspect the SSL connection</description>
  7780. <group>fortios.event.ssl,fortios.category.ssl-negotiation,fortios.severity.notice</group>
  7781. </rule>
  7782. <rule id="101121" level="4">
  7783. <!-- LOG_ID_SSL_NEGOTIATION_BLOCK -->
  7784. <if_sid>100010</if_sid>
  7785. <field name="logid">062101$</field>
  7786. <description>SSL connection is blocked due to its SSL negotiation</description>
  7787. <group>fortios.event.ssl,fortios.category.ssl-negotiation,fortios.severity.warning</group>
  7788. </rule>
  7789. <rule id="101122" level="4">
  7790. <!-- LOG_ID_SSL_NEGOTIATION_BYPASS -->
  7791. <if_sid>100010</if_sid>
  7792. <field name="logid">062102$</field>
  7793. <description>SSL connection is bypassed due to its SSL negotiation</description>
  7794. <group>fortios.event.ssl,fortios.category.ssl-negotiation,fortios.severity.notice</group>
  7795. </rule>
  7796. <rule id="101123" level="4">
  7797. <!-- LOG_ID_SSL_NEGOTIATION_INFO -->
  7798. <if_sid>100010</if_sid>
  7799. <field name="logid">062103$</field>
  7800. <description>SSL connection information</description>
  7801. <group>fortios.event.ssl,fortios.category.ssl-negotiation,fortios.severity.information</group>
  7802. </rule>
  7803. <rule id="101124" level="4">
  7804. <!-- LOG_ID_SSL_SERVER_CERT_INFO -->
  7805. <if_sid>100010</if_sid>
  7806. <field name="logid">062200$</field>
  7807. <description>SSL server certificate information</description>
  7808. <group>fortios.event.ssl,fortios.category.ssl-server-cert-info,fortios.severity.information</group>
  7809. </rule>
  7810. <rule id="101125" level="4">
  7811. <!-- LOG_ID_SSL_HANDSHAKE_INFO -->
  7812. <if_sid>100010</if_sid>
  7813. <field name="logid">062220$</field>
  7814. <description>SSL handshake information</description>
  7815. <group>fortios.event.ssl,fortios.category.ssl-handshake,fortios.severity.information</group>
  7816. </rule>
  7817. <rule id="101126" level="4">
  7818. <!-- LOG_ID_SSL_ANOMALY_CERT_BLOCKLISTED -->
  7819. <if_sid>100010</if_sid>
  7820. <field name="logid">062300$</field>
  7821. <description>SSL connection is blocked due to the server certificate is blocklisted</description>
  7822. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.warning</group>
  7823. </rule>
  7824. <rule id="101127" level="4">
  7825. <!-- LOG_ID_SSL_ANOMALY_CERT_RESIGN_TRUSTED -->
  7826. <if_sid>100010</if_sid>
  7827. <field name="logid">062301$</field>
  7828. <description>Server certificate has security problem</description>
  7829. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.notice</group>
  7830. </rule>
  7831. <rule id="101128" level="4">
  7832. <!-- LOG_ID_SSL_ANOMALY_CERT_RESIGN_UNTRUSTED -->
  7833. <if_sid>100010</if_sid>
  7834. <field name="logid">062302$</field>
  7835. <description>Re-signed server certificate as untrusted due to security problem</description>
  7836. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.notice</group>
  7837. </rule>
  7838. <rule id="101129" level="4">
  7839. <!-- LOG_ID_SSL_ANOMALY_CERT_BLOCKED -->
  7840. <if_sid>100010</if_sid>
  7841. <field name="logid">062303$</field>
  7842. <description>SSL connection is blocked due to server certificate security problem</description>
  7843. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.warning</group>
  7844. </rule>
  7845. <rule id="101130" level="4">
  7846. <!-- LOG_ID_SSL_ANOMALY_CERT_SNI_MISMATCHED -->
  7847. <if_sid>100010</if_sid>
  7848. <field name="logid">062304$</field>
  7849. <description>SSL connection is blocked due to server certificate and SNI mismatched</description>
  7850. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.warning</group>
  7851. </rule>
  7852. <rule id="101131" level="4">
  7853. <!-- LOG_ID_SSL_ANOMALY_CERT_PROBE_FAILURE_BLOCK -->
  7854. <if_sid>100010</if_sid>
  7855. <field name="logid">062305$</field>
  7856. <description>SSL connection is blocked due to unable to retrieve server's certificate</description>
  7857. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.warning</group>
  7858. </rule>
  7859. <rule id="101132" level="4">
  7860. <!-- LOG_ID_SSL_ANOMALY_CERT_PROBE_FAILURE_PASS -->
  7861. <if_sid>100010</if_sid>
  7862. <field name="logid">062306$</field>
  7863. <description>SSL connection is bypassed due to unable to retrieve server's certificate</description>
  7864. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.notice</group>
  7865. </rule>
  7866. <rule id="101133" level="4">
  7867. <!-- LOG_ID_SSL_ANOMALY_CERT_SNI_MISMATCHED_INFO -->
  7868. <if_sid>100010</if_sid>
  7869. <field name="logid">062307$</field>
  7870. <description>Server certificate and SNI mismatched</description>
  7871. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.information</group>
  7872. </rule>
  7873. <rule id="101134" level="4">
  7874. <!-- LOG_ID_TRAFFIC_ALLOW -->
  7875. <if_sid>100010</if_sid>
  7876. <field name="logid">000002$</field>
  7877. <description>Allowed traffic</description>
  7878. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7879. </rule>
  7880. <rule id="101135" level="4">
  7881. <!-- LOG_ID_TRAFFIC_DENY -->
  7882. <if_sid>100010</if_sid>
  7883. <field name="logid">000003$</field>
  7884. <description>Traffic violation</description>
  7885. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.warning</group>
  7886. </rule>
  7887. <rule id="101136" level="4">
  7888. <!-- LOG_ID_TRAFFIC_OTHER_START -->
  7889. <if_sid>100010</if_sid>
  7890. <field name="logid">000004$</field>
  7891. <description>Traffic other session start</description>
  7892. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7893. </rule>
  7894. <rule id="101137" level="4">
  7895. <!-- LOG_ID_TRAFFIC_OTHER_ICMP_ALLOW -->
  7896. <if_sid>100010</if_sid>
  7897. <field name="logid">000005$</field>
  7898. <description>Traffic allowed ICMP</description>
  7899. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7900. </rule>
  7901. <rule id="101138" level="4">
  7902. <!-- LOG_ID_TRAFFIC_OTHER_ICMP_DENY -->
  7903. <if_sid>100010</if_sid>
  7904. <field name="logid">000006$</field>
  7905. <description>Traffic denied ICMP</description>
  7906. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.warning</group>
  7907. </rule>
  7908. <rule id="101139" level="4">
  7909. <!-- LOG_ID_TRAFFIC_OTHER_INVALID -->
  7910. <if_sid>100010</if_sid>
  7911. <field name="logid">000007$</field>
  7912. <description>Traffic other invalid</description>
  7913. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.warning</group>
  7914. </rule>
  7915. <rule id="101140" level="4">
  7916. <!-- LOG_ID_TRAFFIC_WANOPT -->
  7917. <if_sid>100010</if_sid>
  7918. <field name="logid">000008$</field>
  7919. <description>WAN optimization traffic</description>
  7920. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7921. </rule>
  7922. <rule id="101141" level="4">
  7923. <!-- LOG_ID_TRAFFIC_WEBCACHE -->
  7924. <if_sid>100010</if_sid>
  7925. <field name="logid">000009$</field>
  7926. <description>Web cache traffic</description>
  7927. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7928. </rule>
  7929. <rule id="101142" level="4">
  7930. <!-- LOG_ID_TRAFFIC_EXPLICIT_PROXY -->
  7931. <if_sid>100010</if_sid>
  7932. <field name="logid">000010$</field>
  7933. <description>Explicit proxy traffic</description>
  7934. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7935. </rule>
  7936. <rule id="101143" level="4">
  7937. <!-- LOG_ID_TRAFFIC_FAIL_CONN -->
  7938. <if_sid>100010</if_sid>
  7939. <field name="logid">000011$</field>
  7940. <description>Failed connection attempts</description>
  7941. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.warning</group>
  7942. </rule>
  7943. <rule id="101144" level="4">
  7944. <!-- LOG_ID_TRAFFIC_MULTICAST -->
  7945. <if_sid>100010</if_sid>
  7946. <field name="logid">000012$</field>
  7947. <description>Multicast traffic</description>
  7948. <group>fortios.event.traffic,fortios.category.multicast,fortios.severity.notice</group>
  7949. </rule>
  7950. <rule id="101145" level="4">
  7951. <!-- LOG_ID_TRAFFIC_END_FORWARD -->
  7952. <if_sid>100010</if_sid>
  7953. <field name="logid">000013$</field>
  7954. <description>Forward traffic</description>
  7955. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7956. </rule>
  7957. <rule id="101146" level="4">
  7958. <!-- LOG_ID_TRAFFIC_END_LOCAL -->
  7959. <if_sid>100010</if_sid>
  7960. <field name="logid">000014$</field>
  7961. <description>Local traffic</description>
  7962. <group>fortios.event.traffic,fortios.category.local,fortios.severity.notice</group>
  7963. </rule>
  7964. <rule id="101147" level="4">
  7965. <!-- LOG_ID_TRAFFIC_START_FORWARD -->
  7966. <if_sid>100010</if_sid>
  7967. <field name="logid">000015$</field>
  7968. <description>Forward traffic session start</description>
  7969. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7970. </rule>
  7971. <rule id="101148" level="4">
  7972. <!-- LOG_ID_TRAFFIC_START_LOCAL -->
  7973. <if_sid>100010</if_sid>
  7974. <field name="logid">000016$</field>
  7975. <description>Local traffic session start</description>
  7976. <group>fortios.event.traffic,fortios.category.local,fortios.severity.notice</group>
  7977. </rule>
  7978. <rule id="101149" level="4">
  7979. <!-- LOG_ID_TRAFFIC_SNIFFER -->
  7980. <if_sid>100010</if_sid>
  7981. <field name="logid">000017$</field>
  7982. <description>Sniffer traffic</description>
  7983. <group>fortios.event.traffic,fortios.category.sniffer,fortios.severity.notice</group>
  7984. </rule>
  7985. <rule id="101150" level="4">
  7986. <!-- LOG_ID_TRAFFIC_BROADCAST -->
  7987. <if_sid>100010</if_sid>
  7988. <field name="logid">000019$</field>
  7989. <description>Broadcast traffic</description>
  7990. <group>fortios.event.traffic,fortios.category.multicast,fortios.severity.notice</group>
  7991. </rule>
  7992. <rule id="101151" level="4">
  7993. <!-- LOG_ID_TRAFFIC_STAT -->
  7994. <if_sid>100010</if_sid>
  7995. <field name="logid">000020$</field>
  7996. <description>Forward traffic statistics</description>
  7997. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  7998. </rule>
  7999. <rule id="101152" level="4">
  8000. <!-- LOG_ID_TRAFFIC_SNIFFER_STAT -->
  8001. <if_sid>100010</if_sid>
  8002. <field name="logid">000021$</field>
  8003. <description>Sniffer traffic statistics</description>
  8004. <group>fortios.event.traffic,fortios.category.sniffer,fortios.severity.notice</group>
  8005. </rule>
  8006. <rule id="101153" level="4">
  8007. <!-- LOG_ID_TRAFFIC_UTM_CORRELATION -->
  8008. <if_sid>100010</if_sid>
  8009. <field name="logid">000022$</field>
  8010. <description>Forward traffic for UTM correlation</description>
  8011. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  8012. </rule>
  8013. <rule id="101154" level="4">
  8014. <!-- LOG_ID_TRAFFIC_ZTNA -->
  8015. <if_sid>100010</if_sid>
  8016. <field name="logid">000024$</field>
  8017. <description>ZTNA traffic</description>
  8018. <group>fortios.event.traffic,fortios.category.ztna,fortios.severity.notice</group>
  8019. </rule>
  8020. <rule id="101155" level="4">
  8021. <!-- LOG_ID_TRAFFIC_SFLOW -->
  8022. <if_sid>100010</if_sid>
  8023. <field name="logid">000025$</field>
  8024. <description>Sflow sample</description>
  8025. <group>fortios.event.traffic,fortios.category.forward,fortios.severity.notice</group>
  8026. </rule>
  8027. <rule id="101156" level="4">
  8028. <!-- MESGID_INFECT_WARNING -->
  8029. <if_sid>100010</if_sid>
  8030. <field name="logid">08192$</field>
  8031. <description>Infected file detected by the FortiGate unit and blocked</description>
  8032. <group>fortios.event.virus,fortios.category.infected,fortios.severity.warning</group>
  8033. </rule>
  8034. <rule id="101157" level="4">
  8035. <!-- MESGID_INFECT_NOTIF -->
  8036. <if_sid>100010</if_sid>
  8037. <field name="logid">08193$</field>
  8038. <description>Infected file detected by the FortiGate unit and it passed</description>
  8039. <group>fortios.event.virus,fortios.category.infected,fortios.severity.notice</group>
  8040. </rule>
  8041. <rule id="101158" level="4">
  8042. <!-- MESGID_INFECT_MIME_WARNING -->
  8043. <if_sid>100010</if_sid>
  8044. <field name="logid">08194$</field>
  8045. <description>MIME header detected to have a virus and blocked</description>
  8046. <group>fortios.event.virus,fortios.category.infected,fortios.severity.warning</group>
  8047. </rule>
  8048. <rule id="101159" level="4">
  8049. <!-- MESGID_INFECT_MIME_NOTIF -->
  8050. <if_sid>100010</if_sid>
  8051. <field name="logid">08195$</field>
  8052. <description>MIME header infected and passed</description>
  8053. <group>fortios.event.virus,fortios.category.infected,fortios.severity.notice</group>
  8054. </rule>
  8055. <rule id="101160" level="4">
  8056. <!-- MESGID_MIME_FILETYPE_EXE_WARNING -->
  8057. <if_sid>100010</if_sid>
  8058. <field name="logid">08200$</field>
  8059. <description>File is an executable (warning)</description>
  8060. <group>fortios.event.virus,fortios.category.filetype-executable,fortios.severity.warning</group>
  8061. </rule>
  8062. <rule id="101161" level="4">
  8063. <!-- MESGID_MIME_FILETYPE_EXE_NOTIF -->
  8064. <if_sid>100010</if_sid>
  8065. <field name="logid">08201$</field>
  8066. <description>File is an executable (notice)</description>
  8067. <group>fortios.event.virus,fortios.category.filetype-executable,fortios.severity.notice</group>
  8068. </rule>
  8069. <rule id="101162" level="4">
  8070. <!-- MESGID_AVQUERY_WARNING -->
  8071. <if_sid>100010</if_sid>
  8072. <field name="logid">08202$</field>
  8073. <description>File reported infected by Outbreak Prevention (warning)</description>
  8074. <group>fortios.event.virus,fortios.category.outbreak-prevention,fortios.severity.warning</group>
  8075. </rule>
  8076. <rule id="101163" level="4">
  8077. <!-- MESGID_AVQUERY_NOTIF -->
  8078. <if_sid>100010</if_sid>
  8079. <field name="logid">08203$</field>
  8080. <description>File reported infected by Outbreak Prevention (notice)</description>
  8081. <group>fortios.event.virus,fortios.category.outbreak-prevention,fortios.severity.notice</group>
  8082. </rule>
  8083. <rule id="101164" level="4">
  8084. <!-- MESGID_MIME_AVQUERY_WARNING -->
  8085. <if_sid>100010</if_sid>
  8086. <field name="logid">08204$</field>
  8087. <description>MIME data reported infected by Outbreak Prevention (warning)</description>
  8088. <group>fortios.event.virus,fortios.category.outbreak-prevention,fortios.severity.warning</group>
  8089. </rule>
  8090. <rule id="101165" level="4">
  8091. <!-- MESGID_MIME_AVQUERY_NOTIF -->
  8092. <if_sid>100010</if_sid>
  8093. <field name="logid">08205$</field>
  8094. <description>MIME data reported infected by Outbreak Prevention (notice)</description>
  8095. <group>fortios.event.virus,fortios.category.outbreak-prevention,fortios.severity.notice</group>
  8096. </rule>
  8097. <rule id="101166" level="4">
  8098. <!-- MESGID_AV_EXEMPT_NOTIF -->
  8099. <if_sid>100010</if_sid>
  8100. <field name="logid">08206$</field>
  8101. <description>File reported matched AV exempt list (notice)</description>
  8102. <group>fortios.event.virus,fortios.category.exempt-hash,fortios.severity.notice</group>
  8103. </rule>
  8104. <rule id="101167" level="4">
  8105. <!-- MESGID_MIME_AV_EXEMPT_NOTIF -->
  8106. <if_sid>100010</if_sid>
  8107. <field name="logid">08207$</field>
  8108. <description>MIME data reported matched AV exempt list (notice)</description>
  8109. <group>fortios.event.virus,fortios.category.exempt-hash,fortios.severity.notice</group>
  8110. </rule>
  8111. <rule id="101168" level="4">
  8112. <!-- MESGID_MALWARE_LIST_WARNING -->
  8113. <if_sid>100010</if_sid>
  8114. <field name="logid">08212$</field>
  8115. <description>File reported infected by external malware list (warning)</description>
  8116. <group>fortios.event.virus,fortios.category.malware-list,fortios.severity.warning</group>
  8117. </rule>
  8118. <rule id="101169" level="4">
  8119. <!-- MESGID_MALWARE_LIST_NOTIF -->
  8120. <if_sid>100010</if_sid>
  8121. <field name="logid">08213$</field>
  8122. <description>File reported infected by external malware list (notice)</description>
  8123. <group>fortios.event.virus,fortios.category.malware-list,fortios.severity.notice</group>
  8124. </rule>
  8125. <rule id="101170" level="4">
  8126. <!-- MESGID_MIME_MALWARE_LIST_WARNING -->
  8127. <if_sid>100010</if_sid>
  8128. <field name="logid">08214$</field>
  8129. <description>MIME data reported infected by external malware list (warning)</description>
  8130. <group>fortios.event.virus,fortios.category.malware-list,fortios.severity.warning</group>
  8131. </rule>
  8132. <rule id="101171" level="4">
  8133. <!-- MESGID_MIME_MALWARE_LIST_NOTIF -->
  8134. <if_sid>100010</if_sid>
  8135. <field name="logid">08215$</field>
  8136. <description>MIME data reported infected by external malware list (notice)</description>
  8137. <group>fortios.event.virus,fortios.category.malware-list,fortios.severity.notice</group>
  8138. </rule>
  8139. <rule id="101172" level="4">
  8140. <!-- MESGID_FILE_HASH_EMS_WARNING -->
  8141. <if_sid>100010</if_sid>
  8142. <field name="logid">08216$</field>
  8143. <description>File reported infected by EMS threat feed (warning)</description>
  8144. <group>fortios.event.virus,fortios.category.ems-threat-feed,fortios.severity.warning</group>
  8145. </rule>
  8146. <rule id="101173" level="4">
  8147. <!-- MESGID_FILE_HASH_EMS_NOTIF -->
  8148. <if_sid>100010</if_sid>
  8149. <field name="logid">08217$</field>
  8150. <description>File reported infected by EMS threat feed (notice)</description>
  8151. <group>fortios.event.virus,fortios.category.ems-threat-feed,fortios.severity.notice</group>
  8152. </rule>
  8153. <rule id="101174" level="4">
  8154. <!-- MESGID_MIME_FILE_HASH_EMS_WARNING -->
  8155. <if_sid>100010</if_sid>
  8156. <field name="logid">08218$</field>
  8157. <description>MIME data reported infected by EMS threat feed (warning)</description>
  8158. <group>fortios.event.virus,fortios.category.ems-threat-feed,fortios.severity.warning</group>
  8159. </rule>
  8160. <rule id="101175" level="4">
  8161. <!-- MESGID_MIME_FILE_HASH_EMS_NOTIF -->
  8162. <if_sid>100010</if_sid>
  8163. <field name="logid">08219$</field>
  8164. <description>MIME data reported infected by EMS threat feed (notice)</description>
  8165. <group>fortios.event.virus,fortios.category.ems-threat-feed,fortios.severity.notice</group>
  8166. </rule>
  8167. <rule id="101176" level="4">
  8168. <!-- MESGID_FAI_WARNING -->
  8169. <if_sid>100010</if_sid>
  8170. <field name="logid">08220$</field>
  8171. <description>File reported infected by FortiNDR (warning)</description>
  8172. <group>fortios.event.virus,fortios.category.fortindr,fortios.severity.warning</group>
  8173. </rule>
  8174. <rule id="101177" level="4">
  8175. <!-- MESGID_FAI_NOTIF -->
  8176. <if_sid>100010</if_sid>
  8177. <field name="logid">08221$</field>
  8178. <description>File reported infected by FortiNDR (notice)</description>
  8179. <group>fortios.event.virus,fortios.category.fortindr,fortios.severity.notice</group>
  8180. </rule>
  8181. <rule id="101178" level="4">
  8182. <!-- MESGID_MIME_FAI_WARNING -->
  8183. <if_sid>100010</if_sid>
  8184. <field name="logid">08222$</field>
  8185. <description>MIME data reported infected by FortiNDR (warning)</description>
  8186. <group>fortios.event.virus,fortios.category.fortindr,fortios.severity.warning</group>
  8187. </rule>
  8188. <rule id="101179" level="4">
  8189. <!-- MESGID_MIME_FAI_NOTIF -->
  8190. <if_sid>100010</if_sid>
  8191. <field name="logid">08223$</field>
  8192. <description>MIME data reported infected by FortiNDR (notice)</description>
  8193. <group>fortios.event.virus,fortios.category.fortindr,fortios.severity.notice</group>
  8194. </rule>
  8195. <rule id="101180" level="4">
  8196. <!-- MESGID_ICB_TIMEOUT_WARNING -->
  8197. <if_sid>100010</if_sid>
  8198. <field name="logid">08224$</field>
  8199. <description>Inline Block scan timeout (warning)</description>
  8200. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.warning</group>
  8201. </rule>
  8202. <rule id="101181" level="4">
  8203. <!-- MESGID_ICB_TIMEOUT_NOTIF -->
  8204. <if_sid>100010</if_sid>
  8205. <field name="logid">08225$</field>
  8206. <description>Inline Block scan timeout (notice)</description>
  8207. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.notice</group>
  8208. </rule>
  8209. <rule id="101182" level="4">
  8210. <!-- MESGID_MIME_ICB_TIMEOUT_WARNING -->
  8211. <if_sid>100010</if_sid>
  8212. <field name="logid">08226$</field>
  8213. <description>MIME data reported Inline Block scan timeout (warning)</description>
  8214. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.warning</group>
  8215. </rule>
  8216. <rule id="101183" level="4">
  8217. <!-- MESGID_MIME_ICB_TIMEOUT_NOTIF -->
  8218. <if_sid>100010</if_sid>
  8219. <field name="logid">08227$</field>
  8220. <description>MIME data reported Inline Block scan timeout (notice)</description>
  8221. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.notice</group>
  8222. </rule>
  8223. <rule id="101184" level="4">
  8224. <!-- MESGID_ICB_ERROR_WARNING -->
  8225. <if_sid>100010</if_sid>
  8226. <field name="logid">08228$</field>
  8227. <description>Inline Block scan error (warning)</description>
  8228. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.warning</group>
  8229. </rule>
  8230. <rule id="101185" level="4">
  8231. <!-- MESGID_ICB_ERROR_NOTIF -->
  8232. <if_sid>100010</if_sid>
  8233. <field name="logid">08229$</field>
  8234. <description>Inline Block scan error (notice)</description>
  8235. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.notice</group>
  8236. </rule>
  8237. <rule id="101186" level="4">
  8238. <!-- MESGID_MIME_ICB_ERROR_WARNING -->
  8239. <if_sid>100010</if_sid>
  8240. <field name="logid">08230$</field>
  8241. <description>MIME data reported Inline Block scan error (warning)</description>
  8242. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.warning</group>
  8243. </rule>
  8244. <rule id="101187" level="4">
  8245. <!-- MESGID_MIME_ICB_ERROR_NOTIF -->
  8246. <if_sid>100010</if_sid>
  8247. <field name="logid">08231$</field>
  8248. <description>MIME data reported Inline Block scan error (notice)</description>
  8249. <group>fortios.event.virus,fortios.category.inline-block,fortios.severity.notice</group>
  8250. </rule>
  8251. <rule id="101188" level="4">
  8252. <!-- MESGID_ICB_FSA_WARNING -->
  8253. <if_sid>100010</if_sid>
  8254. <field name="logid">08232$</field>
  8255. <description>File reported infected by FortiSandbox (warning)</description>
  8256. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.warning</group>
  8257. </rule>
  8258. <rule id="101189" level="4">
  8259. <!-- MESGID_ICB_FSA_NOTIF -->
  8260. <if_sid>100010</if_sid>
  8261. <field name="logid">08233$</field>
  8262. <description>File reported infected by FortiSandbox (notice)</description>
  8263. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.notice</group>
  8264. </rule>
  8265. <rule id="101190" level="4">
  8266. <!-- MESGID_MIME_ICB_FSA_WARNING -->
  8267. <if_sid>100010</if_sid>
  8268. <field name="logid">08234$</field>
  8269. <description>MIME data reported infected by FortiSandbox (warning)</description>
  8270. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.warning</group>
  8271. </rule>
  8272. <rule id="101191" level="4">
  8273. <!-- MESGID_MIME_ICB_FSA_NOTIF -->
  8274. <if_sid>100010</if_sid>
  8275. <field name="logid">08235$</field>
  8276. <description>MIME data reported infected by FortiSandbox (notice)</description>
  8277. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.notice</group>
  8278. </rule>
  8279. <rule id="101192" level="4">
  8280. <!-- MESGID_ICB_FSA_TIMEOUT_WARNING -->
  8281. <if_sid>100010</if_sid>
  8282. <field name="logid">08236$</field>
  8283. <description>FortiSandbox scan timeout (warning)</description>
  8284. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.warning</group>
  8285. </rule>
  8286. <rule id="101193" level="4">
  8287. <!-- MESGID_ICB_FSA_TIMEOUT_NOTIF -->
  8288. <if_sid>100010</if_sid>
  8289. <field name="logid">08237$</field>
  8290. <description>FortiSandbox scan timeout (notice)</description>
  8291. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.notice</group>
  8292. </rule>
  8293. <rule id="101194" level="4">
  8294. <!-- MESGID_MIME_ICB_FSA_TIMEOUT_WARNING -->
  8295. <if_sid>100010</if_sid>
  8296. <field name="logid">08238$</field>
  8297. <description>MIME data reported FortiSandbox scan timeout (warning)</description>
  8298. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.warning</group>
  8299. </rule>
  8300. <rule id="101195" level="4">
  8301. <!-- MESGID_MIME_ICB_FSA_TIMEOUT_NOTIF -->
  8302. <if_sid>100010</if_sid>
  8303. <field name="logid">08239$</field>
  8304. <description>MIME data reported FortiSandbox scan timeout (notice)</description>
  8305. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.notice</group>
  8306. </rule>
  8307. <rule id="101196" level="4">
  8308. <!-- MESGID_ICB_FSA_ERROR_WARNING -->
  8309. <if_sid>100010</if_sid>
  8310. <field name="logid">08240$</field>
  8311. <description>FortiSandbox scan error (warning)</description>
  8312. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.warning</group>
  8313. </rule>
  8314. <rule id="101197" level="4">
  8315. <!-- MESGID_ICB_FSA_ERROR_NOTIF -->
  8316. <if_sid>100010</if_sid>
  8317. <field name="logid">08241$</field>
  8318. <description>FortiSandbox scan error (notice)</description>
  8319. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.notice</group>
  8320. </rule>
  8321. <rule id="101198" level="4">
  8322. <!-- MESGID_MIME_ICB_FSA_ERROR_WARNING -->
  8323. <if_sid>100010</if_sid>
  8324. <field name="logid">08242$</field>
  8325. <description>MIME data reported FortiSandbox scan error (warning)</description>
  8326. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.warning</group>
  8327. </rule>
  8328. <rule id="101199" level="4">
  8329. <!-- MESGID_MIME_ICB_FSA_ERROR_NOTIF -->
  8330. <if_sid>100010</if_sid>
  8331. <field name="logid">08243$</field>
  8332. <description>MIME data reported FortiSandbox scan error (notice)</description>
  8333. <group>fortios.event.virus,fortios.category.fortisandbox,fortios.severity.notice</group>
  8334. </rule>
  8335. <rule id="101200" level="4">
  8336. <!-- MESGID_BLOCK_WARNING -->
  8337. <if_sid>100010</if_sid>
  8338. <field name="logid">08448$</field>
  8339. <description>FortiGate unit blocked a file because it contains a virus</description>
  8340. <group>fortios.event.virus,fortios.category.filename,fortios.severity.warning</group>
  8341. </rule>
  8342. <rule id="101201" level="4">
  8343. <!-- MESGID_BLOCK_MIME_WARNING -->
  8344. <if_sid>100010</if_sid>
  8345. <field name="logid">08450$</field>
  8346. <description>FortiGate unit blocked a file because it contains a virus (MIME)</description>
  8347. <group>fortios.event.virus,fortios.category.mimefragmented,fortios.severity.warning</group>
  8348. </rule>
  8349. <rule id="101202" level="4">
  8350. <!-- MESGID_BLOCK_MIME_NOTIF -->
  8351. <if_sid>100010</if_sid>
  8352. <field name="logid">08451$</field>
  8353. <description>FortiGate unit blocked a file because it contains a virus (MIME)</description>
  8354. <group>fortios.event.virus,fortios.category.mimefragmented,fortios.severity.notice</group>
  8355. </rule>
  8356. <rule id="101203" level="4">
  8357. <!-- MESGID_BLOCK_COMMAND -->
  8358. <if_sid>100010</if_sid>
  8359. <field name="logid">08452$</field>
  8360. <description>FortiGate unit blocked a virus command</description>
  8361. <group>fortios.event.virus,fortios.category.command-blocked,fortios.severity.warning</group>
  8362. </rule>
  8363. <rule id="101204" level="4">
  8364. <!-- MESGID_OVERSIZE_WARNING -->
  8365. <if_sid>100010</if_sid>
  8366. <field name="logid">08704$</field>
  8367. <description>Defined file size limit was exceeded</description>
  8368. <group>fortios.event.virus,fortios.category.oversize,fortios.severity.warning</group>
  8369. </rule>
  8370. <rule id="101205" level="4">
  8371. <!-- MESGID_OVERSIZE_NOTIF -->
  8372. <if_sid>100010</if_sid>
  8373. <field name="logid">08705$</field>
  8374. <description>File size limit was exceeded</description>
  8375. <group>fortios.event.virus,fortios.category.oversize,fortios.severity.notice</group>
  8376. </rule>
  8377. <rule id="101206" level="4">
  8378. <!-- MESGID_OVERSIZE_STREAM_UNCOMP_WARNING -->
  8379. <if_sid>100010</if_sid>
  8380. <field name="logid">08708$</field>
  8381. <description>Stream-based uncompression reached size limit.</description>
  8382. <group>fortios.event.virus,fortios.category.oversize,fortios.severity.warning</group>
  8383. </rule>
  8384. <rule id="101207" level="4">
  8385. <!-- MESGID_OVERSIZE_STREAM_UNCOMP_NOTIF -->
  8386. <if_sid>100010</if_sid>
  8387. <field name="logid">08709$</field>
  8388. <description>Stream-based uncompression reached size limit.</description>
  8389. <group>fortios.event.virus,fortios.category.oversize,fortios.severity.notice</group>
  8390. </rule>
  8391. <rule id="101208" level="4">
  8392. <!-- MESGID_SWITCH_PROTO_WARNING -->
  8393. <if_sid>100010</if_sid>
  8394. <field name="logid">08720$</field>
  8395. <description>Switching protocols request (warning)</description>
  8396. <group>fortios.event.virus,fortios.category.switchproto,fortios.severity.warning</group>
  8397. </rule>
  8398. <rule id="101209" level="4">
  8399. <!-- MESGID_SWITCH_PROTO_NOTIF -->
  8400. <if_sid>100010</if_sid>
  8401. <field name="logid">08721$</field>
  8402. <description>Switching protocols request (notice)</description>
  8403. <group>fortios.event.virus,fortios.category.switchproto,fortios.severity.notice</group>
  8404. </rule>
  8405. <rule id="101210" level="4">
  8406. <!-- MESGID_SCAN_UNCOMPSIZELIMIT_WARNING -->
  8407. <if_sid>100010</if_sid>
  8408. <field name="logid">08960$</field>
  8409. <description>File reached the uncompressed nested limit</description>
  8410. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8411. </rule>
  8412. <rule id="101211" level="4">
  8413. <!-- MESGID_SCAN_UNCOMPSIZELIMIT_NOTIF -->
  8414. <if_sid>100010</if_sid>
  8415. <field name="logid">08961$</field>
  8416. <description>File reached the uncompressed size limit</description>
  8417. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8418. </rule>
  8419. <rule id="101212" level="4">
  8420. <!-- MESGID_SCAN_ARCHIVE_ENCRYPTED_WARNING -->
  8421. <if_sid>100010</if_sid>
  8422. <field name="logid">08962$</field>
  8423. <description>Archived file is corrupted</description>
  8424. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8425. </rule>
  8426. <rule id="101213" level="4">
  8427. <!-- MESGID_SCAN_ARCHIVE_ENCRYPTED_NOTIF -->
  8428. <if_sid>100010</if_sid>
  8429. <field name="logid">08963$</field>
  8430. <description>Archived file is encrypted</description>
  8431. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8432. </rule>
  8433. <rule id="101214" level="4">
  8434. <!-- MESGID_SCAN_ARCHIVE_CORRUPTED_WARNING -->
  8435. <if_sid>100010</if_sid>
  8436. <field name="logid">08964$</field>
  8437. <description>Corrupted archive (warning)</description>
  8438. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8439. </rule>
  8440. <rule id="101215" level="4">
  8441. <!-- MESGID_SCAN_ARCHIVE_CORRUPTED_NOTIF -->
  8442. <if_sid>100010</if_sid>
  8443. <field name="logid">08965$</field>
  8444. <description>Corrupted archive (notice)</description>
  8445. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8446. </rule>
  8447. <rule id="101216" level="4">
  8448. <!-- MESGID_SCAN_ARCHIVE_MULTIPART_WARNING -->
  8449. <if_sid>100010</if_sid>
  8450. <field name="logid">08966$</field>
  8451. <description>File is a multipart archive or contains multiple files within the archive</description>
  8452. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8453. </rule>
  8454. <rule id="101217" level="4">
  8455. <!-- MESGID_SCAN_ARCHIVE_MULTIPART_NOTIF -->
  8456. <if_sid>100010</if_sid>
  8457. <field name="logid">08967$</field>
  8458. <description>File is a multipart archive or contains multiple files within the archive</description>
  8459. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8460. </rule>
  8461. <rule id="101218" level="4">
  8462. <!-- MESGID_SCAN_ARCHIVE_NESTED_WARNING -->
  8463. <if_sid>100010</if_sid>
  8464. <field name="logid">08968$</field>
  8465. <description>File is a nested archived file</description>
  8466. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8467. </rule>
  8468. <rule id="101219" level="4">
  8469. <!-- MESGID_SCAN_ARCHIVE_NESTED_NOTIF -->
  8470. <if_sid>100010</if_sid>
  8471. <field name="logid">08969$</field>
  8472. <description>File is an archived type unhandled</description>
  8473. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8474. </rule>
  8475. <rule id="101220" level="4">
  8476. <!-- MESGID_SCAN_ARCHIVE_OVERSIZE_WARNING -->
  8477. <if_sid>100010</if_sid>
  8478. <field name="logid">08970$</field>
  8479. <description>Archived file is oversized</description>
  8480. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8481. </rule>
  8482. <rule id="101221" level="4">
  8483. <!-- MESGID_SCAN_ARCHIVE_OVERSIZE_NOTIF -->
  8484. <if_sid>100010</if_sid>
  8485. <field name="logid">08971$</field>
  8486. <description>Archived file is oversized</description>
  8487. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8488. </rule>
  8489. <rule id="101222" level="4">
  8490. <!-- MESGID_SCAN_ARCHIVE_UNHANDLED_WARNING -->
  8491. <if_sid>100010</if_sid>
  8492. <field name="logid">08972$</field>
  8493. <description>Unhandled archive (warning)</description>
  8494. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8495. </rule>
  8496. <rule id="101223" level="4">
  8497. <!-- MESGID_SCAN_ARCHIVE_UNHANDLED_NOTIF -->
  8498. <if_sid>100010</if_sid>
  8499. <field name="logid">08973$</field>
  8500. <description>Unhandled archive (notice)</description>
  8501. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8502. </rule>
  8503. <rule id="101224" level="4">
  8504. <!-- MESGID_SCAN_AV_ENGINE_LOAD_FAILED_ERROR -->
  8505. <if_sid>100010</if_sid>
  8506. <field name="logid">08974$</field>
  8507. <description>AV Engine load failed</description>
  8508. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.error</group>
  8509. </rule>
  8510. <rule id="101225" level="4">
  8511. <!-- MESGID_SCAN_ARCHIVE_PARTIALLYCORRUPTED_WARNING -->
  8512. <if_sid>100010</if_sid>
  8513. <field name="logid">08975$</field>
  8514. <description>Partially corrupted archive (warning)</description>
  8515. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8516. </rule>
  8517. <rule id="101226" level="4">
  8518. <!-- MESGID_SCAN_ARCHIVE_PARTIALLYCORRUPTED_NOTIF -->
  8519. <if_sid>100010</if_sid>
  8520. <field name="logid">08976$</field>
  8521. <description>Partially corrupted archive (notice)</description>
  8522. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8523. </rule>
  8524. <rule id="101227" level="4">
  8525. <!-- MESGID_SCAN_ARCHIVE_TIMEOUT_WARNING -->
  8526. <if_sid>100010</if_sid>
  8527. <field name="logid">08979$</field>
  8528. <description>Archive scan timeout (warning)</description>
  8529. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  8530. </rule>
  8531. <rule id="101228" level="4">
  8532. <!-- MESGID_SCAN_ARCHIVE_TIMEOUT_NOTIF -->
  8533. <if_sid>100010</if_sid>
  8534. <field name="logid">08980$</field>
  8535. <description>Archive scan timeout (notice)</description>
  8536. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  8537. </rule>
  8538. <rule id="101229" level="4">
  8539. <!-- MESGID_SCAN_AV_CDR_INTERNAL_ERROR -->
  8540. <if_sid>100010</if_sid>
  8541. <field name="logid">08981$</field>
  8542. <description>AV CDR engine internal error</description>
  8543. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.error</group>
  8544. </rule>
  8545. <rule id="101230" level="4">
  8546. <!-- MESGID_ANALYTICS_SUBMITTED -->
  8547. <if_sid>100010</if_sid>
  8548. <field name="logid">09233$</field>
  8549. <description>File submitted to Sandbox</description>
  8550. <group>fortios.event.virus,fortios.category.analytics,fortios.severity.information</group>
  8551. </rule>
  8552. <rule id="101231" level="4">
  8553. <!-- MESGID_ANALYTICS_INFECT_WARNING -->
  8554. <if_sid>100010</if_sid>
  8555. <field name="logid">09234$</field>
  8556. <description>File reported infected by FortiSandbox (warning)</description>
  8557. <group>fortios.event.virus,fortios.category.infected,fortios.severity.warning</group>
  8558. </rule>
  8559. <rule id="101232" level="4">
  8560. <!-- MESGID_ANALYTICS_INFECT_NOTIF -->
  8561. <if_sid>100010</if_sid>
  8562. <field name="logid">09235$</field>
  8563. <description>File reported infected by FortiSandbox (notice)</description>
  8564. <group>fortios.event.virus,fortios.category.infected,fortios.severity.notice</group>
  8565. </rule>
  8566. <rule id="101233" level="4">
  8567. <!-- MESGID_ANALYTICS_INFECT_MIME_WARNING -->
  8568. <if_sid>100010</if_sid>
  8569. <field name="logid">09236$</field>
  8570. <description>File reported infected by FortiSandbox (warning)</description>
  8571. <group>fortios.event.virus,fortios.category.infected,fortios.severity.warning</group>
  8572. </rule>
  8573. <rule id="101234" level="4">
  8574. <!-- MESGID_ANALYTICS_INFECT_MIME_NOTIF -->
  8575. <if_sid>100010</if_sid>
  8576. <field name="logid">09237$</field>
  8577. <description>File reported infected by FortiSandbox (notice)</description>
  8578. <group>fortios.event.virus,fortios.category.infected,fortios.severity.notice</group>
  8579. </rule>
  8580. <rule id="101235" level="4">
  8581. <!-- MESGID_ANALYTICS_FSA_RESULT -->
  8582. <if_sid>100010</if_sid>
  8583. <field name="logid">09238$</field>
  8584. <description>File verdict returned from FortiSandbox</description>
  8585. <group>fortios.event.virus,fortios.category.analytics,fortios.severity.notice</group>
  8586. </rule>
  8587. <rule id="101236" level="4">
  8588. <!-- MESGID_CONTENT_DISARM_NOTIF -->
  8589. <if_sid>100010</if_sid>
  8590. <field name="logid">09239$</field>
  8591. <description>Active content detected by Content Disarm engine</description>
  8592. <group>fortios.event.virus,fortios.category.content-disarm,fortios.severity.notice</group>
  8593. </rule>
  8594. <rule id="101237" level="4">
  8595. <!-- MESGID_CONTENT_DISARM_WARNING -->
  8596. <if_sid>100010</if_sid>
  8597. <field name="logid">09240$</field>
  8598. <description>File was disarmed by Content Disarm engine</description>
  8599. <group>fortios.event.virus,fortios.category.content-disarm,fortios.severity.warning</group>
  8600. </rule>
  8601. <rule id="101238" level="4">
  8602. <!-- LOGID_EVENT_VOIP_SIP -->
  8603. <if_sid>100010</if_sid>
  8604. <field name="logid">044032$</field>
  8605. <description>VoIP SIP</description>
  8606. <group>fortios.event.voip,fortios.category.voip,fortios.severity.information</group>
  8607. </rule>
  8608. <rule id="101239" level="4">
  8609. <!-- LOGID_EVENT_VOIP_SIP_BLOCK -->
  8610. <if_sid>100010</if_sid>
  8611. <field name="logid">044033$</field>
  8612. <description>VoIP SIP blocked</description>
  8613. <group>fortios.event.voip,fortios.category.voip,fortios.severity.notice</group>
  8614. </rule>
  8615. <rule id="101240" level="4">
  8616. <!-- LOGID_EVENT_VOIP_SIP_FUZZING -->
  8617. <if_sid>100010</if_sid>
  8618. <field name="logid">044034$</field>
  8619. <description>VoIP SIP fuzzing</description>
  8620. <group>fortios.event.voip,fortios.category.voip,fortios.severity.information</group>
  8621. </rule>
  8622. <rule id="101241" level="4">
  8623. <!-- LOGID_EVENT_VOIP_SCCP_REGISTER -->
  8624. <if_sid>100010</if_sid>
  8625. <field name="logid">044035$</field>
  8626. <description>VoIP SCCP registered</description>
  8627. <group>fortios.event.voip,fortios.category.voip,fortios.severity.information</group>
  8628. </rule>
  8629. <rule id="101242" level="4">
  8630. <!-- LOGID_EVENT_VOIP_SCCP_UNREGISTER -->
  8631. <if_sid>100010</if_sid>
  8632. <field name="logid">044036$</field>
  8633. <description>VoIP SCCP unregistered</description>
  8634. <group>fortios.event.voip,fortios.category.voip,fortios.severity.information</group>
  8635. </rule>
  8636. <rule id="101243" level="4">
  8637. <!-- LOGID_EVENT_VOIP_SCCP_CALL_BLOCK -->
  8638. <if_sid>100010</if_sid>
  8639. <field name="logid">044037$</field>
  8640. <description>VoIP SCCP call blocked</description>
  8641. <group>fortios.event.voip,fortios.category.voip,fortios.severity.information</group>
  8642. </rule>
  8643. <rule id="101244" level="4">
  8644. <!-- LOGID_EVENT_VOIP_SCCP_CALL_INFO -->
  8645. <if_sid>100010</if_sid>
  8646. <field name="logid">044038$</field>
  8647. <description>VoIP SCCP call information</description>
  8648. <group>fortios.event.voip,fortios.category.voip,fortios.severity.information</group>
  8649. </rule>
  8650. <rule id="101245" level="4">
  8651. <!-- LOGID_WAF_SIGNATURE_BLOCK -->
  8652. <if_sid>100010</if_sid>
  8653. <field name="logid">030248$</field>
  8654. <description>Web application firewall blocked application by signature</description>
  8655. <group>fortios.event.waf,fortios.category.waf-signature,fortios.severity.warning</group>
  8656. </rule>
  8657. <rule id="101246" level="4">
  8658. <!-- LOGID_WAF_SIGNATURE_PASS -->
  8659. <if_sid>100010</if_sid>
  8660. <field name="logid">030249$</field>
  8661. <description>Web application firewall passed application by signature</description>
  8662. <group>fortios.event.waf,fortios.category.waf-signature,fortios.severity.warning</group>
  8663. </rule>
  8664. <rule id="101247" level="4">
  8665. <!-- LOGID_WAF_SIGNATURE_ERASE -->
  8666. <if_sid>100010</if_sid>
  8667. <field name="logid">030250$</field>
  8668. <description>Web application firewall erased application by signature</description>
  8669. <group>fortios.event.waf,fortios.category.waf-signature,fortios.severity.warning</group>
  8670. </rule>
  8671. <rule id="101248" level="4">
  8672. <!-- LOGID_WAF_CUSTOM_SIGNATURE_BLOCK -->
  8673. <if_sid>100010</if_sid>
  8674. <field name="logid">030251$</field>
  8675. <description>Web application firewall blocked application by custom signature</description>
  8676. <group>fortios.event.waf,fortios.category.waf-custom-signature,fortios.severity.warning</group>
  8677. </rule>
  8678. <rule id="101249" level="4">
  8679. <!-- LOGID_WAF_CUSTOM_SIGNATURE_PASS -->
  8680. <if_sid>100010</if_sid>
  8681. <field name="logid">030252$</field>
  8682. <description>Web application firewall allowed application by custom signature</description>
  8683. <group>fortios.event.waf,fortios.category.waf-custom-signature,fortios.severity.warning</group>
  8684. </rule>
  8685. <rule id="101250" level="4">
  8686. <!-- LOGID_WAF_METHOD_BLOCK -->
  8687. <if_sid>100010</if_sid>
  8688. <field name="logid">030253$</field>
  8689. <description>Web application firewall blocked application by HTTP method</description>
  8690. <group>fortios.event.waf,fortios.category.waf-http-method,fortios.severity.warning</group>
  8691. </rule>
  8692. <rule id="101251" level="4">
  8693. <!-- LOGID_WAF_ADDRESS_LIST_BLOCK -->
  8694. <if_sid>100010</if_sid>
  8695. <field name="logid">030255$</field>
  8696. <description>Web application firewall blocked application by address list</description>
  8697. <group>fortios.event.waf,fortios.category.waf-address-list,fortios.severity.warning</group>
  8698. </rule>
  8699. <rule id="101252" level="4">
  8700. <!-- LOGID_WAF_CONSTRAINTS_BLOCK -->
  8701. <if_sid>100010</if_sid>
  8702. <field name="logid">030257$</field>
  8703. <description>Web application firewall blocked application by HTTP constraints</description>
  8704. <group>fortios.event.waf,fortios.category.waf-http-constraint,fortios.severity.warning</group>
  8705. </rule>
  8706. <rule id="101253" level="4">
  8707. <!-- LOGID_WAF_CONSTRAINTS_PASS -->
  8708. <if_sid>100010</if_sid>
  8709. <field name="logid">030258$</field>
  8710. <description>Web application firewall allowed application by HTTP constraints</description>
  8711. <group>fortios.event.waf,fortios.category.waf-http-constraint,fortios.severity.warning</group>
  8712. </rule>
  8713. <rule id="101254" level="4">
  8714. <!-- LOGID_WAF_URL_ACCESS_PERMIT -->
  8715. <if_sid>100010</if_sid>
  8716. <field name="logid">030259$</field>
  8717. <description>Web application firewall allowed application by URL access permit</description>
  8718. <group>fortios.event.waf,fortios.category.waf-url-access,fortios.severity.warning</group>
  8719. </rule>
  8720. <rule id="101255" level="4">
  8721. <!-- LOGID_WAF_URL_ACCESS_BYPASS -->
  8722. <if_sid>100010</if_sid>
  8723. <field name="logid">030260$</field>
  8724. <description>Web application firewall allowed application by URL access bypass</description>
  8725. <group>fortios.event.waf,fortios.category.waf-url-access,fortios.severity.warning</group>
  8726. </rule>
  8727. <rule id="101256" level="4">
  8728. <!-- LOGID_WAF_URL_ACCESS_BLOCK -->
  8729. <if_sid>100010</if_sid>
  8730. <field name="logid">030261$</field>
  8731. <description>Web application firewall blocked application by URL access</description>
  8732. <group>fortios.event.waf,fortios.category.waf-url-access,fortios.severity.warning</group>
  8733. </rule>
  8734. <rule id="101257" level="4">
  8735. <!-- LOG_ID_WEB_CONTENT_BANWORD -->
  8736. <if_sid>100010</if_sid>
  8737. <field name="logid">012288$</field>
  8738. <description>Web content banned word found</description>
  8739. <group>fortios.event.webfilter,fortios.category.content,fortios.severity.warning</group>
  8740. </rule>
  8741. <rule id="101258" level="4">
  8742. <!-- LOG_ID_WEB_CONTENT_EXEMPTWORD -->
  8743. <if_sid>100010</if_sid>
  8744. <field name="logid">012290$</field>
  8745. <description>Web content exempt word found</description>
  8746. <group>fortios.event.webfilter,fortios.category.content,fortios.severity.notice</group>
  8747. </rule>
  8748. <rule id="101259" level="4">
  8749. <!-- LOG_ID_WEB_CONTENT_KEYWORD -->
  8750. <if_sid>100010</if_sid>
  8751. <field name="logid">012292$</field>
  8752. <description>Message contained a key word in the profile list</description>
  8753. <group>fortios.event.webfilter,fortios.category.content,fortios.severity.notice</group>
  8754. </rule>
  8755. <rule id="101260" level="4">
  8756. <!-- LOG_ID_WEB_CONTENT_SEARCH -->
  8757. <if_sid>100010</if_sid>
  8758. <field name="logid">012293$</field>
  8759. <description>Search phrase detected</description>
  8760. <group>fortios.event.webfilter,fortios.category.content,fortios.severity.notice</group>
  8761. </rule>
  8762. <rule id="101261" level="4">
  8763. <!-- LOG_ID_URL_FILTER_BLOCK -->
  8764. <if_sid>100010</if_sid>
  8765. <field name="logid">012544$</field>
  8766. <description>URL address was blocked because it was found in the URL filter list</description>
  8767. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.warning</group>
  8768. </rule>
  8769. <rule id="101262" level="4">
  8770. <!-- LOG_ID_URL_FILTER_EXEMPT -->
  8771. <if_sid>100010</if_sid>
  8772. <field name="logid">012545$</field>
  8773. <description>URL address was exempted because it was found in the URL filter list</description>
  8774. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8775. </rule>
  8776. <rule id="101263" level="4">
  8777. <!-- LOG_ID_URL_FILTER_ALLOW -->
  8778. <if_sid>100010</if_sid>
  8779. <field name="logid">012546$</field>
  8780. <description>URL address was allowed because it was found in the URL filter list</description>
  8781. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8782. </rule>
  8783. <rule id="101264" level="4">
  8784. <!-- LOG_ID_URL_FILTER_INVALID_HOSTNAME_HTTP_BLK -->
  8785. <if_sid>100010</if_sid>
  8786. <field name="logid">012547$</field>
  8787. <description>The request contained an invalid domain name</description>
  8788. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8789. </rule>
  8790. <rule id="101265" level="4">
  8791. <!-- LOG_ID_URL_FILTER_INVALID_HOSTNAME_HTTPS_BLK -->
  8792. <if_sid>100010</if_sid>
  8793. <field name="logid">012548$</field>
  8794. <description>HTTP certificate request contained an invalid domain name</description>
  8795. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8796. </rule>
  8797. <rule id="101266" level="4">
  8798. <!-- LOG_ID_URL_FILTER_INVALID_HOSTNAME_HTTP_PASS -->
  8799. <if_sid>100010</if_sid>
  8800. <field name="logid">012549$</field>
  8801. <description>HTTP request contained an invalid name so the session has been filtered by IP only</description>
  8802. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8803. </rule>
  8804. <rule id="101267" level="4">
  8805. <!-- LOG_ID_URL_FILTER_INVALID_HOSTNAME_HTTPS_PASS -->
  8806. <if_sid>100010</if_sid>
  8807. <field name="logid">012550$</field>
  8808. <description>HTTPS request contained an invalid name so the session has been filtered by IP only</description>
  8809. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8810. </rule>
  8811. <rule id="101268" level="4">
  8812. <!-- LOG_ID_URL_FILTER_INVALID_HOSTNAME_SNI_BLK -->
  8813. <if_sid>100010</if_sid>
  8814. <field name="logid">012551$</field>
  8815. <description>Insufficient resources</description>
  8816. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8817. </rule>
  8818. <rule id="101269" level="4">
  8819. <!-- LOG_ID_URL_FILTER_INVALID_HOSTNAME_SNI_PASS -->
  8820. <if_sid>100010</if_sid>
  8821. <field name="logid">012552$</field>
  8822. <description>Getting the host name failed</description>
  8823. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8824. </rule>
  8825. <rule id="101270" level="4">
  8826. <!-- LOG_ID_URL_FILTER_INVALID_CERT -->
  8827. <if_sid>100010</if_sid>
  8828. <field name="logid">012553$</field>
  8829. <description>Server certificate validation failed</description>
  8830. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8831. </rule>
  8832. <rule id="101271" level="4">
  8833. <!-- LOG_ID_URL_FILTER_INVALID_SESSION -->
  8834. <if_sid>100010</if_sid>
  8835. <field name="logid">012554$</field>
  8836. <description>SSL session blocked because its identification number was unknown</description>
  8837. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8838. </rule>
  8839. <rule id="101272" level="4">
  8840. <!-- LOG_ID_URL_FILTER_SRV_CERT_ERR_BLK -->
  8841. <if_sid>100010</if_sid>
  8842. <field name="logid">012555$</field>
  8843. <description>SSL session blocked</description>
  8844. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8845. </rule>
  8846. <rule id="101273" level="4">
  8847. <!-- LOG_ID_URL_FILTER_SRV_CERT_ERR_PASS -->
  8848. <if_sid>100010</if_sid>
  8849. <field name="logid">012556$</field>
  8850. <description>SSL session ignored</description>
  8851. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.notice</group>
  8852. </rule>
  8853. <rule id="101274" level="4">
  8854. <!-- LOG_ID_URL_FILTER_FAMS_NOT_ACTIVE -->
  8855. <if_sid>100010</if_sid>
  8856. <field name="logid">012557$</field>
  8857. <description>The FortiGuard Analysis and Management Service is not active. You must enable this service</description>
  8858. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.critical</group>
  8859. </rule>
  8860. <rule id="101275" level="4">
  8861. <!-- LOG_ID_URL_FILTER_RATING_ERR -->
  8862. <if_sid>100010</if_sid>
  8863. <field name="logid">012558$</field>
  8864. <description>Rating error occurred</description>
  8865. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8866. </rule>
  8867. <rule id="101276" level="4">
  8868. <!-- LOG_ID_URL_FILTER_PASS -->
  8869. <if_sid>100010</if_sid>
  8870. <field name="logid">012559$</field>
  8871. <description>URL passed because it was in the URL filter list</description>
  8872. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8873. </rule>
  8874. <rule id="101277" level="4">
  8875. <!-- LOG_ID_URL_WISP_BLOCK -->
  8876. <if_sid>100010</if_sid>
  8877. <field name="logid">012560$</field>
  8878. <description>URL blocked by Websense service</description>
  8879. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.warning</group>
  8880. </rule>
  8881. <rule id="101278" level="4">
  8882. <!-- LOG_ID_URL_WISP_REDIR -->
  8883. <if_sid>100010</if_sid>
  8884. <field name="logid">012561$</field>
  8885. <description>URL blocked with redirect message by Websense service</description>
  8886. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.warning</group>
  8887. </rule>
  8888. <rule id="101279" level="4">
  8889. <!-- LOG_ID_URL_WISP_ALLOW -->
  8890. <if_sid>100010</if_sid>
  8891. <field name="logid">012562$</field>
  8892. <description>URL allowed by Websense service</description>
  8893. <group>fortios.event.webfilter,fortios.category.urlfilter,fortios.severity.information</group>
  8894. </rule>
  8895. <rule id="101280" level="4">
  8896. <!-- LOG_ID_WEB_SSL_EXEMPT -->
  8897. <if_sid>100010</if_sid>
  8898. <field name="logid">012688$</field>
  8899. <description>URL address was exempted because it was found in the ssl-exempt</description>
  8900. <group>fortios.event.webfilter,fortios.category.ssl-exempt,fortios.severity.information</group>
  8901. </rule>
  8902. <rule id="101281" level="4">
  8903. <!-- LOG_ID_WEB_FTGD_ERR -->
  8904. <if_sid>100010</if_sid>
  8905. <field name="logid">012800$</field>
  8906. <description>Rating error occurred (error)</description>
  8907. <group>fortios.event.webfilter,fortios.category.ftgd_err,fortios.severity.error</group>
  8908. </rule>
  8909. <rule id="101282" level="4">
  8910. <!-- LOG_ID_WEB_FTGD_WARNING -->
  8911. <if_sid>100010</if_sid>
  8912. <field name="logid">012801$</field>
  8913. <description>Rating error occurred (warning)</description>
  8914. <group>fortios.event.webfilter,fortios.category.ftgd_err,fortios.severity.warning</group>
  8915. </rule>
  8916. <rule id="101283" level="4">
  8917. <!-- LOG_ID_WEB_FTGD_QUOTA -->
  8918. <if_sid>100010</if_sid>
  8919. <field name="logid">012802$</field>
  8920. <description>Daily FortiGuard quota status</description>
  8921. <group>fortios.event.webfilter,fortios.category.ftgd_quota,fortios.severity.information</group>
  8922. </rule>
  8923. <rule id="101284" level="4">
  8924. <!-- LOG_ID_WEB_FTGD_CAT_BLK -->
  8925. <if_sid>100010</if_sid>
  8926. <field name="logid">013056$</field>
  8927. <description>URL belongs to an blocked category within the firewall policy</description>
  8928. <group>fortios.event.webfilter,fortios.category.ftgd_blk,fortios.severity.warning</group>
  8929. </rule>
  8930. <rule id="101285" level="4">
  8931. <!-- LOG_ID_WEB_FTGD_CAT_WARN -->
  8932. <if_sid>100010</if_sid>
  8933. <field name="logid">013057$</field>
  8934. <description>URL belongs to a category with warnings enabled</description>
  8935. <group>fortios.event.webfilter,fortios.category.ftgd_blk,fortios.severity.warning</group>
  8936. </rule>
  8937. <rule id="101286" level="4">
  8938. <!-- LOG_ID_WEB_FTGD_CAT_ALLOW -->
  8939. <if_sid>100010</if_sid>
  8940. <field name="logid">013312$</field>
  8941. <description>URL belongs to an allowed category within the firewall policy</description>
  8942. <group>fortios.event.webfilter,fortios.category.ftgd_allow,fortios.severity.notice</group>
  8943. </rule>
  8944. <rule id="101287" level="4">
  8945. <!-- LOG_ID_WEB_FTGD_QUOTA_COUNTING -->
  8946. <if_sid>100010</if_sid>
  8947. <field name="logid">013315$</field>
  8948. <description>FortiGuard web filter category quota counting log message</description>
  8949. <group>fortios.event.webfilter,fortios.category.ftgd_quota_counting,fortios.severity.notice</group>
  8950. </rule>
  8951. <rule id="101288" level="4">
  8952. <!-- LOG_ID_WEB_FTGD_QUOTA_EXPIRED -->
  8953. <if_sid>100010</if_sid>
  8954. <field name="logid">013316$</field>
  8955. <description>FortiGuard web filter category quota expired log message</description>
  8956. <group>fortios.event.webfilter,fortios.category.ftgd_quota_expired,fortios.severity.warning</group>
  8957. </rule>
  8958. <rule id="101289" level="4">
  8959. <!-- LOG_ID_WEB_URL -->
  8960. <if_sid>100010</if_sid>
  8961. <field name="logid">013317$</field>
  8962. <description>URL has been visited</description>
  8963. <group>fortios.event.webfilter,fortios.category.urlmonitor,fortios.severity.notice</group>
  8964. </rule>
  8965. <rule id="101290" level="4">
  8966. <!-- LOG_ID_WEB_SCRIPTFILTER_ACTIVEX -->
  8967. <if_sid>100010</if_sid>
  8968. <field name="logid">013568$</field>
  8969. <description>ActiveX script removed</description>
  8970. <group>fortios.event.webfilter,fortios.category.activexfilter,fortios.severity.notice</group>
  8971. </rule>
  8972. <rule id="101291" level="4">
  8973. <!-- LOG_ID_WEB_SCRIPTFILTER_COOKIE -->
  8974. <if_sid>100010</if_sid>
  8975. <field name="logid">013573$</field>
  8976. <description>Cookie removed</description>
  8977. <group>fortios.event.webfilter,fortios.category.cookiefilter,fortios.severity.notice</group>
  8978. </rule>
  8979. <rule id="101292" level="4">
  8980. <!-- LOG_ID_WEB_SCRIPTFILTER_APPLET -->
  8981. <if_sid>100010</if_sid>
  8982. <field name="logid">013584$</field>
  8983. <description>Java applet removed</description>
  8984. <group>fortios.event.webfilter,fortios.category.appletfilter,fortios.severity.notice</group>
  8985. </rule>
  8986. <rule id="101293" level="4">
  8987. <!-- LOG_ID_WEB_SCRIPTFILTER_OTHER -->
  8988. <if_sid>100010</if_sid>
  8989. <field name="logid">013600$</field>
  8990. <description>Script entity removed</description>
  8991. <group>fortios.event.webfilter,fortios.category.scriptfilter,fortios.severity.notice</group>
  8992. </rule>
  8993. <rule id="101294" level="4">
  8994. <!-- LOG_ID_WEB_WF_COOKIE -->
  8995. <if_sid>100010</if_sid>
  8996. <field name="logid">013601$</field>
  8997. <description>Cookie removed entirely</description>
  8998. <group>fortios.event.webfilter,fortios.category.cookiefilter,fortios.severity.notice</group>
  8999. </rule>
  9000. <rule id="101295" level="4">
  9001. <!-- LOG_ID_WEB_WF_REFERER -->
  9002. <if_sid>100010</if_sid>
  9003. <field name="logid">013602$</field>
  9004. <description>Referrer removed from request</description>
  9005. <group>fortios.event.webfilter,fortios.category.cookiefilter,fortios.severity.notice</group>
  9006. </rule>
  9007. <rule id="101296" level="4">
  9008. <!-- LOG_ID_WEB_WF_COMMAND_BLOCK -->
  9009. <if_sid>100010</if_sid>
  9010. <field name="logid">013603$</field>
  9011. <description>Command blocked</description>
  9012. <group>fortios.event.webfilter,fortios.category.webfilter_command_block,fortios.severity.warning</group>
  9013. </rule>
  9014. <rule id="101297" level="4">
  9015. <!-- LOG_ID_CONTENT_TYPE_BLOCK -->
  9016. <if_sid>100010</if_sid>
  9017. <field name="logid">013616$</field>
  9018. <description>Blocked by HTTP header content type</description>
  9019. <group>fortios.event.webfilter,fortios.category.content,fortios.severity.warning</group>
  9020. </rule>
  9021. <rule id="101298" level="4">
  9022. <!-- LOGID_HTTP_HDR_CHG_REQ -->
  9023. <if_sid>100010</if_sid>
  9024. <field name="logid">013632$</field>
  9025. <description>Depends on info in msg field</description>
  9026. <group>fortios.event.webfilter,fortios.category.http_header_change,fortios.severity.notice</group>
  9027. </rule>
  9028. <rule id="101299" level="4">
  9029. <!-- LOGID_HTTP_HDR_CHG_RESP -->
  9030. <if_sid>100010</if_sid>
  9031. <field name="logid">013633$</field>
  9032. <description>Depends on info in msg field</description>
  9033. <group>fortios.event.webfilter,fortios.category.http_header_change,fortios.severity.notice</group>
  9034. </rule>
  9035. <rule id="101300" level="4">
  9036. <!-- LOG_ID_WEB_WF_ANTIPHISH_MATCH_URL_ALLOW -->
  9037. <if_sid>100010</if_sid>
  9038. <field name="logid">013648$</field>
  9039. <description>Antiphishing matched a URL filter rule without blocking the request.</description>
  9040. <group>fortios.event.webfilter,fortios.category.antiphishing,fortios.severity.warning</group>
  9041. </rule>
  9042. <rule id="101301" level="4">
  9043. <!-- LOG_ID_WEB_WF_ANTIPHISH_MATCH_FTGD_ALLOW -->
  9044. <if_sid>100010</if_sid>
  9045. <field name="logid">013649$</field>
  9046. <description>Antiphishing matched a Fortiguard category rule without blocking the request.</description>
  9047. <group>fortios.event.webfilter,fortios.category.antiphishing,fortios.severity.warning</group>
  9048. </rule>
  9049. <rule id="101302" level="4">
  9050. <!-- LOG_ID_WEB_WF_ANTIPHISH_MATCH_DEFAULT_ALLOW -->
  9051. <if_sid>100010</if_sid>
  9052. <field name="logid">013650$</field>
  9053. <description>Antiphishing reached default action without blocking the request.</description>
  9054. <group>fortios.event.webfilter,fortios.category.antiphishing,fortios.severity.warning</group>
  9055. </rule>
  9056. <rule id="101303" level="4">
  9057. <!-- LOG_ID_WEB_WF_ANTIPHISH_MATCH_URL_BLOCK -->
  9058. <if_sid>100010</if_sid>
  9059. <field name="logid">013651$</field>
  9060. <description>Antiphishing matched a URL filter rule and blocked the request.</description>
  9061. <group>fortios.event.webfilter,fortios.category.antiphishing,fortios.severity.warning</group>
  9062. </rule>
  9063. <rule id="101304" level="4">
  9064. <!-- LOG_ID_WEB_WF_ANTIPHISH_MATCH_FTGD_BLOCK -->
  9065. <if_sid>100010</if_sid>
  9066. <field name="logid">013652$</field>
  9067. <description>Antiphishing matched a Fortiguard category rule and blocked the request.</description>
  9068. <group>fortios.event.webfilter,fortios.category.antiphishing,fortios.severity.warning</group>
  9069. </rule>
  9070. <rule id="101305" level="4">
  9071. <!-- LOG_ID_WEB_WF_ANTIPHISH_MATCH_DEFAULT_BLOCK -->
  9072. <if_sid>100010</if_sid>
  9073. <field name="logid">013653$</field>
  9074. <description>Antiphishing reached default action and blocked the request.</description>
  9075. <group>fortios.event.webfilter,fortios.category.antiphishing,fortios.severity.warning</group>
  9076. </rule>
  9077. <rule id="101306" level="4">
  9078. <!-- LOG_ID_VIDEOFILTER_CATEGORY_BLOCK -->
  9079. <if_sid>100010</if_sid>
  9080. <field name="logid">013664$</field>
  9081. <description>Video category is blocked.</description>
  9082. <group>fortios.event.webfilter,fortios.category.videofilter-category,fortios.severity.warning</group>
  9083. </rule>
  9084. <rule id="101307" level="4">
  9085. <!-- LOG_ID_VIDEOFILTER_CATEGORY_MONITOR -->
  9086. <if_sid>100010</if_sid>
  9087. <field name="logid">013665$</field>
  9088. <description>Video category is monitored</description>
  9089. <group>fortios.event.webfilter,fortios.category.videofilter-category,fortios.severity.notice</group>
  9090. </rule>
  9091. <rule id="101308" level="4">
  9092. <!-- LOG_ID_VIDEOFILTER_CATEGORY_ALLOW -->
  9093. <if_sid>100010</if_sid>
  9094. <field name="logid">013666$</field>
  9095. <description>Video category is allowed</description>
  9096. <group>fortios.event.webfilter,fortios.category.videofilter-category,fortios.severity.notice</group>
  9097. </rule>
  9098. <rule id="101309" level="4">
  9099. <!-- LOG_ID_VIDEOFILTER_CHANNEL_BLOCK -->
  9100. <if_sid>100010</if_sid>
  9101. <field name="logid">013680$</field>
  9102. <description>Video channel is blocked.</description>
  9103. <group>fortios.event.webfilter,fortios.category.videofilter-channel,fortios.severity.warning</group>
  9104. </rule>
  9105. <rule id="101310" level="4">
  9106. <!-- LOG_ID_VIDEOFILTER_CHANNEL_MONITOR -->
  9107. <if_sid>100010</if_sid>
  9108. <field name="logid">013681$</field>
  9109. <description>Video channel is monitored</description>
  9110. <group>fortios.event.webfilter,fortios.category.videofilter-channel,fortios.severity.notice</group>
  9111. </rule>
  9112. <rule id="101311" level="4">
  9113. <!-- LOG_ID_VIDEOFILTER_CHANNEL_ALLOW -->
  9114. <if_sid>100010</if_sid>
  9115. <field name="logid">013682$</field>
  9116. <description>Video channel is allowed</description>
  9117. <group>fortios.event.webfilter,fortios.category.videofilter-channel,fortios.severity.notice</group>
  9118. </rule>
  9119. <rule id="101312" level="4">
  9120. <!-- LOG_ID_UNKNOWN_CE_BLOCK -->
  9121. <if_sid>100010</if_sid>
  9122. <field name="logid">013696$</field>
  9123. <description>Unknown content-encoding detected and blocked.</description>
  9124. <group>fortios.event.webfilter,fortios.category.unknown-ce,fortios.severity.warning</group>
  9125. </rule>
  9126. <rule id="101313" level="4">
  9127. <!-- LOG_ID_UNKNOWN_CE_BYPASS -->
  9128. <if_sid>100010</if_sid>
  9129. <field name="logid">013697$</field>
  9130. <description>Scan is bypassed due to unknown content-encoding.</description>
  9131. <group>fortios.event.webfilter,fortios.category.unknown-ce,fortios.severity.notice</group>
  9132. </rule>
  9133. <rule id="101314" level="4">
  9134. <!-- LOG_ID_ENTER_EXTREME_LOW_MEM_MODE -->
  9135. <if_sid>100010</if_sid>
  9136. <field name="logid">022022$</field>
  9137. <description>Extreme low memory mode entered</description>
  9138. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9139. </rule>
  9140. <rule id="101315" level="4">
  9141. <!-- LOG_ID_LEAVE_EXTREME_LOW_MEM_MODE -->
  9142. <if_sid>100010</if_sid>
  9143. <field name="logid">022023$</field>
  9144. <description>Extreme low memory mode exited</description>
  9145. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9146. </rule>
  9147. <rule id="101316" level="4">
  9148. <!-- LOG_ID_CASB_ACCESS_BLOCKED -->
  9149. <if_sid>100010</if_sid>
  9150. <field name="logid">010000$</field>
  9151. <description>Web content banned activity found</description>
  9152. <group>fortios.event.casb,fortios.category.casb,fortios.severity.warning</group>
  9153. </rule>
  9154. <rule id="101317" level="4">
  9155. <!-- LOG_ID_CASB_ACCESS_BYPASS -->
  9156. <if_sid>100010</if_sid>
  9157. <field name="logid">010001$</field>
  9158. <description>Web content activity found</description>
  9159. <group>fortios.event.casb,fortios.category.casb,fortios.severity.information</group>
  9160. </rule>
  9161. <rule id="101318" level="4">
  9162. <!-- LOG_ID_CASB_ACCESS_MONITOR -->
  9163. <if_sid>100010</if_sid>
  9164. <field name="logid">010002$</field>
  9165. <description>Web content activity found</description>
  9166. <group>fortios.event.casb,fortios.category.casb,fortios.severity.information</group>
  9167. </rule>
  9168. <rule id="101319" level="4">
  9169. <!-- LOG_ID_DLP_LIC_EXPIRE -->
  9170. <if_sid>100010</if_sid>
  9171. <field name="logid">020136$</field>
  9172. <description>FortiGuard Data leak server prevention license expiring</description>
  9173. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9174. </rule>
  9175. <rule id="101320" level="4">
  9176. <!-- LOG_ID_FGSA_LIC_EXPIRE -->
  9177. <if_sid>100010</if_sid>
  9178. <field name="logid">020137$</field>
  9179. <description>Attack Surface Security Rating Service license expiring</description>
  9180. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9181. </rule>
  9182. <rule id="101321" level="4">
  9183. <!-- LOG_ID_SWOS_LIC_EXPIRE -->
  9184. <if_sid>100010</if_sid>
  9185. <field name="logid">020138$</field>
  9186. <description>FortiGuard SD-WAN Overlay as a Service license expiring</description>
  9187. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9188. </rule>
  9189. <rule id="101322" level="4">
  9190. <!-- LOG_ID_FGCS_ACC_LIC_EXPIRE -->
  9191. <if_sid>100010</if_sid>
  9192. <field name="logid">020139$</field>
  9193. <description>FortiGSLB Cloud Account Level license expiring</description>
  9194. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9195. </rule>
  9196. <rule id="101323" level="4">
  9197. <!-- LOG_ID_FSPA_LIC_EXPIRE -->
  9198. <if_sid>100010</if_sid>
  9199. <field name="logid">020140$</field>
  9200. <description>FortiSASE Secure Private Access license expiring</description>
  9201. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9202. </rule>
  9203. <rule id="101324" level="4">
  9204. <!-- LOG_ID_FSFG_LIC_EXPIRE -->
  9205. <if_sid>100010</if_sid>
  9206. <field name="logid">020141$</field>
  9207. <description>FortiSASE LAN Extension license expiring</description>
  9208. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9209. </rule>
  9210. <rule id="101325" level="4">
  9211. <!-- LOG_ID_DEV_VUNL_FTGD_LOOKUP -->
  9212. <if_sid>100010</if_sid>
  9213. <field name="logid">020150$</field>
  9214. <description>Device vulnerability lookup on FortiGuard</description>
  9215. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9216. </rule>
  9217. <rule id="101326" level="4">
  9218. <!-- LOG_ID_SCANUNIT_DLP_SIGNATURE_REMOVE -->
  9219. <if_sid>100010</if_sid>
  9220. <field name="logid">022817$</field>
  9221. <description>Scanunit DLP signature update error</description>
  9222. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9223. </rule>
  9224. <rule id="101327" level="4">
  9225. <!-- LOG_ID_FLTUND_NEW_CONN -->
  9226. <if_sid>100010</if_sid>
  9227. <field name="logid">022874$</field>
  9228. <description>Switch-controller FortilinkLite new connection</description>
  9229. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  9230. </rule>
  9231. <rule id="101328" level="4">
  9232. <!-- LOG_ID_FLTUND_CONN_DOWN -->
  9233. <if_sid>100010</if_sid>
  9234. <field name="logid">022875$</field>
  9235. <description>Switch-controller FortilinkLite connection down</description>
  9236. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  9237. </rule>
  9238. <rule id="101329" level="4">
  9239. <!-- LOG_ID_FLTUND_RCV_BOOTSTRAP -->
  9240. <if_sid>100010</if_sid>
  9241. <field name="logid">022876$</field>
  9242. <description>Switch-controller FortilinkLite received bootstrap</description>
  9243. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.information</group>
  9244. </rule>
  9245. <rule id="101330" level="4">
  9246. <!-- LOG_ID_FLTUND_CONN_ONLINE -->
  9247. <if_sid>100010</if_sid>
  9248. <field name="logid">022877$</field>
  9249. <description>Switch-controller FortilinkLite tunnel online</description>
  9250. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.notice</group>
  9251. </rule>
  9252. <rule id="101331" level="4">
  9253. <!-- LOG_ID_FLTUND_CONN_OFFLINE -->
  9254. <if_sid>100010</if_sid>
  9255. <field name="logid">022878$</field>
  9256. <description>Switch-controller FortilinkLite tunnel offline</description>
  9257. <group>fortios.event.event,fortios.category.switch-controller,fortios.severity.critical</group>
  9258. </rule>
  9259. <rule id="101332" level="4">
  9260. <!-- LOG_ID_EVENT_VWL_APP_PERF_METRICS -->
  9261. <if_sid>100010</if_sid>
  9262. <field name="logid">022937$</field>
  9263. <description>SDWAN application performance metrics via FortiMonitor</description>
  9264. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.information</group>
  9265. </rule>
  9266. <rule id="101333" level="4">
  9267. <!-- LOG_ID_EVENT_VWL_WAN_SPEEDTEST_RESULT -->
  9268. <if_sid>100010</if_sid>
  9269. <field name="logid">022938$</field>
  9270. <description>SD-WAN Bandwidth monitoring result</description>
  9271. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.information</group>
  9272. </rule>
  9273. <rule id="101334" level="4">
  9274. <!-- LOG_ID_EVENT_VWL_FAIL_DETECT -->
  9275. <if_sid>100010</if_sid>
  9276. <field name="logid">022939$</field>
  9277. <description>SD-WAN fail detect</description>
  9278. <group>fortios.event.event,fortios.category.sdwan,fortios.severity.notice</group>
  9279. </rule>
  9280. <rule id="101335" level="4">
  9281. <!-- LOG_ID_EVENT_LINK_MONITOR_FAIL_DETECT -->
  9282. <if_sid>100010</if_sid>
  9283. <field name="logid">022940$</field>
  9284. <description>Link monitor fail detect</description>
  9285. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9286. </rule>
  9287. <rule id="101336" level="4">
  9288. <!-- LOG_ID_CC_KAT_SUCCESS -->
  9289. <if_sid>100010</if_sid>
  9290. <field name="logid">032055$</field>
  9291. <description>KAT tests succeeded</description>
  9292. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9293. </rule>
  9294. <rule id="101337" level="4">
  9295. <!-- LOG_ID_NP6XLITE_HPE_PACKET_DROP -->
  9296. <if_sid>100010</if_sid>
  9297. <field name="logid">034420$</field>
  9298. <description>NP6XLITE HPE is dropping packets</description>
  9299. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9300. </rule>
  9301. <rule id="101338" level="4">
  9302. <!-- LOG_ID_NP6XLITE_HPE_PACKET_FLOOD -->
  9303. <if_sid>100010</if_sid>
  9304. <field name="logid">034421$</field>
  9305. <description>NP6XLITE HPE under a packets flood</description>
  9306. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9307. </rule>
  9308. <rule id="101339" level="4">
  9309. <!-- LOG_ID_PCP_MAPPING_CREATE -->
  9310. <if_sid>100010</if_sid>
  9311. <field name="logid">035051$</field>
  9312. <description>Create PCP mapping</description>
  9313. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9314. </rule>
  9315. <rule id="101340" level="4">
  9316. <!-- LOG_ID_PCP_MAPPING_DELETE -->
  9317. <if_sid>100010</if_sid>
  9318. <field name="logid">035052$</field>
  9319. <description>Delete PCP mapping</description>
  9320. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9321. </rule>
  9322. <rule id="101341" level="4">
  9323. <!-- LOG_ID_PCP_MAPPING_RENEW -->
  9324. <if_sid>100010</if_sid>
  9325. <field name="logid">035053$</field>
  9326. <description>Renew PCP mapping</description>
  9327. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9328. </rule>
  9329. <rule id="101342" level="4">
  9330. <!-- LOGID_EVENT_ICAP_REMOTE_SRV_STAT -->
  9331. <if_sid>100010</if_sid>
  9332. <field name="logid">040961$</field>
  9333. <description>Icap remote server stat</description>
  9334. <group>fortios.event.event,fortios.category.webproxy,fortios.severity.notice</group>
  9335. </rule>
  9336. <rule id="101343" level="4">
  9337. <!-- LOG_ID_EC_REG_SUCCEED -->
  9338. <if_sid>100010</if_sid>
  9339. <field name="logid">045101$</field>
  9340. <description>FortiClient registered</description>
  9341. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.notice</group>
  9342. </rule>
  9343. <rule id="101344" level="4">
  9344. <!-- LOG_ID_EC_EMS_UPGRADE_FAIL -->
  9345. <if_sid>100010</if_sid>
  9346. <field name="logid">045132$</field>
  9347. <description>EMS entry could not be upgraded</description>
  9348. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.error</group>
  9349. </rule>
  9350. <rule id="101345" level="4">
  9351. <!-- LOG_ID_EC_SHM_MISSING_QUERY -->
  9352. <if_sid>100010</if_sid>
  9353. <field name="logid">045133$</field>
  9354. <description>FCEMS shared memory missing query statistics</description>
  9355. <group>fortios.event.event,fortios.category.endpoint,fortios.severity.warning</group>
  9356. </rule>
  9357. <rule id="101346" level="4">
  9358. <!-- LOG_ID_INTERNAL_LTE_MODEM_SIM_SWITCH -->
  9359. <if_sid>100010</if_sid>
  9360. <field name="logid">046518$</field>
  9361. <description>LTE modem active SIM card switch event</description>
  9362. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9363. </rule>
  9364. <rule id="101347" level="4">
  9365. <!-- LOG_ID_INTERNAL_LTE_MODEM_SIM_SWITCH_CONNECTION_STATE -->
  9366. <if_sid>100010</if_sid>
  9367. <field name="logid">046519$</field>
  9368. <description>LTE modem active SIM card switched: modem disconnection detected</description>
  9369. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9370. </rule>
  9371. <rule id="101348" level="4">
  9372. <!-- LOG_ID_INTERNAL_LTE_MODEM_SIM_SWITCH_LINK_MONITOR -->
  9373. <if_sid>100010</if_sid>
  9374. <field name="logid">046520$</field>
  9375. <description>LTE modem active SIM card switched: link monitor probe failure detected</description>
  9376. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9377. </rule>
  9378. <rule id="101349" level="4">
  9379. <!-- LOG_ID_INTERNAL_LTE_MODEM_SIM_FLIP -->
  9380. <if_sid>100010</if_sid>
  9381. <field name="logid">046521$</field>
  9382. <description>LTE modem active SIM card slot flipped back and forth in short time</description>
  9383. <group>fortios.event.event,fortios.category.system,fortios.severity.warning</group>
  9384. </rule>
  9385. <rule id="101350" level="4">
  9386. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLING_DATA_ALERT -->
  9387. <if_sid>100010</if_sid>
  9388. <field name="logid">046522$</field>
  9389. <description>LTE billing data usage reached configured threshold</description>
  9390. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9391. </rule>
  9392. <rule id="101351" level="4">
  9393. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLING_TIME_REFRESH -->
  9394. <if_sid>100010</if_sid>
  9395. <field name="logid">046523$</field>
  9396. <description>LTE billing time passed, refresh billing date counter</description>
  9397. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9398. </rule>
  9399. <rule id="101352" level="4">
  9400. <!-- LOG_ID_INTERNAL_LTE_MODEM_SIM_SWITCH_DATA_PLAN -->
  9401. <if_sid>100010</if_sid>
  9402. <field name="logid">046524$</field>
  9403. <description>LTE modem active SIM card switched: data plan reached</description>
  9404. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9405. </rule>
  9406. <rule id="101353" level="4">
  9407. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLING_STOP_NETWORK -->
  9408. <if_sid>100010</if_sid>
  9409. <field name="logid">046525$</field>
  9410. <description>LTE modem stop network due to data plan reached</description>
  9411. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9412. </rule>
  9413. <rule id="101354" level="4">
  9414. <!-- LOG_ID_INTERNAL_LTE_MODEM_BILLING_DATA_PLAN_OVER -->
  9415. <if_sid>100010</if_sid>
  9416. <field name="logid">046526$</field>
  9417. <description>LTE billing data usage reached data limit</description>
  9418. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9419. </rule>
  9420. <rule id="101355" level="4">
  9421. <!-- LOG_ID_FORTICONVERTER_RESULT_READY -->
  9422. <if_sid>100010</if_sid>
  9423. <field name="logid">053320$</field>
  9424. <description>FortiConverter ticket has a result file ready</description>
  9425. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9426. </rule>
  9427. <rule id="101356" level="4">
  9428. <!-- LOG_ID_FORTICONVERTER_CONFIG_UPLOADED -->
  9429. <if_sid>100010</if_sid>
  9430. <field name="logid">053321$</field>
  9431. <description>Uploaded local config to a FortiConverter ticket</description>
  9432. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9433. </rule>
  9434. <rule id="101357" level="4">
  9435. <!-- LOG_ID_SSL_ANOMALY_HANDSHAKE_FAILURE -->
  9436. <if_sid>100010</if_sid>
  9437. <field name="logid">062308$</field>
  9438. <description>Error occured during SSL handshake.</description>
  9439. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.information</group>
  9440. </rule>
  9441. <rule id="101358" level="4">
  9442. <!-- LOG_ID_SSL_ANOMALY_CERT_INVALID -->
  9443. <if_sid>100010</if_sid>
  9444. <field name="logid">062309$</field>
  9445. <description>Server certificate has security problem</description>
  9446. <group>fortios.event.ssl,fortios.category.ssl-anomaly,fortios.severity.notice</group>
  9447. </rule>
  9448. <rule id="101359" level="4">
  9449. <!-- LOG_ID_OT_VPATCH_BLOCK -->
  9450. <if_sid>100010</if_sid>
  9451. <field name="logid">064600$</field>
  9452. <description>Traffic was blocked by OT virtual patch</description>
  9453. <group>fortios.event.virtual-patch,fortios.category.ot-vpatch,fortios.severity.warning</group>
  9454. </rule>
  9455. <rule id="101360" level="4">
  9456. <!-- LOG_ID_OT_VPATCH_LOG -->
  9457. <if_sid>100010</if_sid>
  9458. <field name="logid">064601$</field>
  9459. <description>Traffic was detected by OT virtual patch</description>
  9460. <group>fortios.event.virtual-patch,fortios.category.ot-vpatch,fortios.severity.notice</group>
  9461. </rule>
  9462. <rule id="101361" level="4">
  9463. <!-- LOG_ID_LOCALIN_VPATCH_BLOCK -->
  9464. <if_sid>100010</if_sid>
  9465. <field name="logid">064610$</field>
  9466. <description>Traffic was blocked by local-in virtual patch</description>
  9467. <group>fortios.event.virtual-patch,fortios.category.localin-vpatch,fortios.severity.warning</group>
  9468. </rule>
  9469. <rule id="101362" level="4">
  9470. <!-- LOG_ID_LOCALIN_VPATCH_LOG -->
  9471. <if_sid>100010</if_sid>
  9472. <field name="logid">064611$</field>
  9473. <description>Traffic was detected by local-in virtual patch</description>
  9474. <group>fortios.event.virtual-patch,fortios.category.localin-vpatch,fortios.severity.notice</group>
  9475. </rule>
  9476. <rule id="101363" level="4">
  9477. <!-- MESGID_SCAN_AV_MAX_MEMORY_REACHED_ERROR -->
  9478. <if_sid>100010</if_sid>
  9479. <field name="logid">08982$</field>
  9480. <description>Exceeded max AV memory</description>
  9481. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.error</group>
  9482. </rule>
  9483. <rule id="101364" level="4">
  9484. <!-- LOG_ID_CONTENT_TYPE_EXEMPT -->
  9485. <if_sid>100010</if_sid>
  9486. <field name="logid">013617$</field>
  9487. <description>Exempted by HTTP header content type</description>
  9488. <group>fortios.event.webfilter,fortios.category.content,fortios.severity.information</group>
  9489. </rule>
  9490. <rule id="101365" level="4">
  9491. <!-- LOG_ID_VIDEOFILTER_TITLE_BLOCK -->
  9492. <if_sid>100010</if_sid>
  9493. <field name="logid">013712$</field>
  9494. <description>Video title is blocked.</description>
  9495. <group>fortios.event.webfilter,fortios.category.videofilter-title,fortios.severity.warning</group>
  9496. </rule>
  9497. <rule id="101366" level="4">
  9498. <!-- LOG_ID_VIDEOFILTER_TITLE_MONITOR -->
  9499. <if_sid>100010</if_sid>
  9500. <field name="logid">013713$</field>
  9501. <description>Video title is monitored</description>
  9502. <group>fortios.event.webfilter,fortios.category.videofilter-title,fortios.severity.notice</group>
  9503. </rule>
  9504. <rule id="101367" level="4">
  9505. <!-- LOG_ID_VIDEOFILTER_TITLE_ALLOW -->
  9506. <if_sid>100010</if_sid>
  9507. <field name="logid">013714$</field>
  9508. <description>Video title is allowed</description>
  9509. <group>fortios.event.webfilter,fortios.category.videofilter-title,fortios.severity.notice</group>
  9510. </rule>
  9511. <rule id="101368" level="4">
  9512. <!-- LOG_ID_VIDEOFILTER_DESCRIPTION_BLOCK -->
  9513. <if_sid>100010</if_sid>
  9514. <field name="logid">013728$</field>
  9515. <description>Video description is blocked.</description>
  9516. <group>fortios.event.webfilter,fortios.category.videofilter-description,fortios.severity.warning</group>
  9517. </rule>
  9518. <rule id="101369" level="4">
  9519. <!-- LOG_ID_VIDEOFILTER_DESCRIPTION_MONITOR -->
  9520. <if_sid>100010</if_sid>
  9521. <field name="logid">013729$</field>
  9522. <description>Video description is monitored</description>
  9523. <group>fortios.event.webfilter,fortios.category.videofilter-description,fortios.severity.notice</group>
  9524. </rule>
  9525. <rule id="101370" level="4">
  9526. <!-- LOG_ID_VIDEOFILTER_DESCRIPTION_ALLOW -->
  9527. <if_sid>100010</if_sid>
  9528. <field name="logid">013730$</field>
  9529. <description>Video description is allowed</description>
  9530. <group>fortios.event.webfilter,fortios.category.videofilter-description,fortios.severity.notice</group>
  9531. </rule>
  9532. <rule id="101371" level="4">
  9533. <!-- LOG_ID_RAD_FAIL_IPV6_SOCKET -->
  9534. <if_sid>100010</if_sid>
  9535. <field name="logid">020047$</field>
  9536. <description>RADVD failed to create an IPv6 socket</description>
  9537. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9538. </rule>
  9539. <rule id="101372" level="4">
  9540. <!-- LOG_ID_RAD_FAIL_OPT_IPV6_PKTINFO -->
  9541. <if_sid>100010</if_sid>
  9542. <field name="logid">020048$</field>
  9543. <description>RADVD failed to set IPv6 packet info</description>
  9544. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9545. </rule>
  9546. <rule id="101373" level="4">
  9547. <!-- LOG_ID_RAD_FAIL_OPT_IPV6_CHECKSUM -->
  9548. <if_sid>100010</if_sid>
  9549. <field name="logid">020049$</field>
  9550. <description>RADVD failed to set IPv6 checksum</description>
  9551. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9552. </rule>
  9553. <rule id="101374" level="4">
  9554. <!-- LOG_ID_RAD_FAIL_OPT_IPV6_UNICAST_HOPS -->
  9555. <if_sid>100010</if_sid>
  9556. <field name="logid">020050$</field>
  9557. <description>RADVD failed to set IPv6 unicast hops</description>
  9558. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9559. </rule>
  9560. <rule id="101375" level="4">
  9561. <!-- LOG_ID_RAD_FAIL_OPT_IPV6_MULTICAST_HOPS -->
  9562. <if_sid>100010</if_sid>
  9563. <field name="logid">020051$</field>
  9564. <description>RADVD failed to set IPv6 multicast hops</description>
  9565. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9566. </rule>
  9567. <rule id="101376" level="4">
  9568. <!-- LOG_ID_RAD_FAIL_OPT_IPV6_HOPLIMIT -->
  9569. <if_sid>100010</if_sid>
  9570. <field name="logid">020052$</field>
  9571. <description>RADVD failed to set IPv6 hop limit</description>
  9572. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9573. </rule>
  9574. <rule id="101377" level="4">
  9575. <!-- LOG_ID_RAD_FAIL_OPT_IPPROTO_ICMPV6 -->
  9576. <if_sid>100010</if_sid>
  9577. <field name="logid">020053$</field>
  9578. <description>RADVD failed to set ICMPv6 filter</description>
  9579. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9580. </rule>
  9581. <rule id="101378" level="4">
  9582. <!-- LOG_ID_RAD_EXIT_BY_SIGNAL -->
  9583. <if_sid>100010</if_sid>
  9584. <field name="logid">020054$</field>
  9585. <description>RADVD exited due to received signal</description>
  9586. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9587. </rule>
  9588. <rule id="101379" level="4">
  9589. <!-- LOG_ID_RAD_FAIL_CMDB_QUERY -->
  9590. <if_sid>100010</if_sid>
  9591. <field name="logid">020055$</field>
  9592. <description>RADVD interface query creation failed</description>
  9593. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9594. </rule>
  9595. <rule id="101380" level="4">
  9596. <!-- LOG_ID_RAD_FAIL_CMDB_FOR_EACH -->
  9597. <if_sid>100010</if_sid>
  9598. <field name="logid">020056$</field>
  9599. <description>RADVD query error</description>
  9600. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9601. </rule>
  9602. <rule id="101381" level="4">
  9603. <!-- LOG_ID_RAD_FAIL_FIND_VIRT_INTF -->
  9604. <if_sid>100010</if_sid>
  9605. <field name="logid">020057$</field>
  9606. <description>RADVD virtual interface not found</description>
  9607. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9608. </rule>
  9609. <rule id="101382" level="4">
  9610. <!-- LOG_ID_RAD_UNLOAD_INTF -->
  9611. <if_sid>100010</if_sid>
  9612. <field name="logid">020058$</field>
  9613. <description>RADVD unloaded interface</description>
  9614. <group>fortios.event.event,fortios.category.system,fortios.severity.information</group>
  9615. </rule>
  9616. <rule id="101383" level="4">
  9617. <!-- LOG_ID_FDS_SRV_CHG -->
  9618. <if_sid>100010</if_sid>
  9619. <field name="logid">022914$</field>
  9620. <description>FortiGate Cloud server changed</description>
  9621. <group>fortios.event.event,fortios.category.system,fortios.severity.notice</group>
  9622. </rule>
  9623. <rule id="101384" level="4">
  9624. <!-- LOG_ID_ADMIN_MTNER_LOGIN_SUCC -->
  9625. <if_sid>100010</if_sid>
  9626. <field name="logid">032053$</field>
  9627. <description>Admin monitor login successful</description>
  9628. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9629. </rule>
  9630. <rule id="101385" level="4">
  9631. <!-- LOG_ID_ADMIN_MTNER_LOGOUT -->
  9632. <if_sid>100010</if_sid>
  9633. <field name="logid">032054$</field>
  9634. <description>Admin monitor logout successful</description>
  9635. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9636. </rule>
  9637. <rule id="101386" level="4">
  9638. <!-- LOG_ID_RESTORE_IMG_USB -->
  9639. <if_sid>100010</if_sid>
  9640. <field name="logid">032199$</field>
  9641. <description>Image restored from USB</description>
  9642. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9643. </rule>
  9644. <rule id="101387" level="4">
  9645. <!-- LOG_ID_RESTORE_CONF_BY_USB -->
  9646. <if_sid>100010</if_sid>
  9647. <field name="logid">032567$</field>
  9648. <description>Configuration restored by USB</description>
  9649. <group>fortios.event.event,fortios.category.system,fortios.severity.critical</group>
  9650. </rule>
  9651. <rule id="101388" level="4">
  9652. <!-- LOG_ID_ADMIN_MTNER_LOGOUT_DISCONNECT -->
  9653. <if_sid>100010</if_sid>
  9654. <field name="logid">032570$</field>
  9655. <description>Admin monitor disconnected</description>
  9656. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9657. </rule>
  9658. <rule id="101389" level="4">
  9659. <!-- LOGID_EVENT_CONFIG_OBJATTR_MTNER -->
  9660. <if_sid>100010</if_sid>
  9661. <field name="logid">044549$</field>
  9662. <description>Object attribute configured by maintainer</description>
  9663. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9664. </rule>
  9665. <rule id="101390" level="4">
  9666. <!-- LOGID_EVENT_CONFIG_OBJ_MTNER -->
  9667. <if_sid>100010</if_sid>
  9668. <field name="logid">044550$</field>
  9669. <description>Object configured by maintainer</description>
  9670. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9671. </rule>
  9672. <rule id="101391" level="4">
  9673. <!-- LOGID_EVENT_CONFIG_ATTR_MTNER -->
  9674. <if_sid>100010</if_sid>
  9675. <field name="logid">044551$</field>
  9676. <description>Attribute configured by maintainer</description>
  9677. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9678. </rule>
  9679. <rule id="101392" level="4">
  9680. <!-- LOGID_EVENT_CONFIG_PATH_MTNER -->
  9681. <if_sid>100010</if_sid>
  9682. <field name="logid">044552$</field>
  9683. <description>Path configured by maintainer</description>
  9684. <group>fortios.event.event,fortios.category.system,fortios.severity.alert</group>
  9685. </rule>
  9686. <rule id="101393" level="4">
  9687. <!-- MESGID_FORTIAI_FAILURE_WARNING -->
  9688. <if_sid>100010</if_sid>
  9689. <field name="logid">08983$</field>
  9690. <description>FortiNDR submission failure (warning)</description>
  9691. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  9692. </rule>
  9693. <rule id="101394" level="4">
  9694. <!-- MESGID_FORTIAI_FAILURE_NOTIF -->
  9695. <if_sid>100010</if_sid>
  9696. <field name="logid">08984$</field>
  9697. <description>FortiNDR submission failure (notice)</description>
  9698. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  9699. </rule>
  9700. <rule id="101395" level="4">
  9701. <!-- MESGID_FORTIAI_TIMEOUT_WARNING -->
  9702. <if_sid>100010</if_sid>
  9703. <field name="logid">08985$</field>
  9704. <description>FortiNDR scan timeout (warning)</description>
  9705. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.warning</group>
  9706. </rule>
  9707. <rule id="101396" level="4">
  9708. <!-- MESGID_FORTIAI_TIMEOUT_NOTIF -->
  9709. <if_sid>100010</if_sid>
  9710. <field name="logid">08986$</field>
  9711. <description>FortiNDR scan timeout (notice)</description>
  9712. <group>fortios.event.virus,fortios.category.scanerror,fortios.severity.notice</group>
  9713. </rule>
  9714. </group>