Skip to content

Fortinet Integration Error #3897

Description

@janniten

Hi,
I've found errors in the Fortinet integration when ingesting Fortigate logs of type: utm and subtype: voip.
The error.message is field [email.from.address] already exists
Error is raising in logs-fortinet.firewall-1.7.0-utm pipeline in this processor

    {
        "rename": {
          "field": "fortinet.firewall.from",
          "target_field": "email.from.address",
          "ignore_missing": true
        }
      }

(In my environment I temporary solved adding "if": "ctx?.email?.from?.address == null condition to the processor)

Activity

  1. elasticmachine commented on Jul 29, 2022

    @elasticmachine

    Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

  2. added
    Integration:Fortinet(Deprecated) Use one of the specific fortinet_X labels. [Integration not found in source]
    bugSomething isn't working, use only for issues
    on Jul 29, 2022
  3. self-assigned this
    on Jul 29, 2022
  4. efd6 commented on Jul 29, 2022

    @efd6
    Contributor

    It looks like the pipeline is fighting with itself; if fortinet.firewall.from is non-null, email.from.address is populated with the content of fortinet.firewall.from and then unconditionally fortinet.firewall.from is attempted to be renamed to that now-constructed field.

      - append:
          field: email.from.address
          value: "{{fortinet.firewall.from}}"
          if: "ctx?.fortinet?.firewall?.from != null"
      - rename:
          field: fortinet.firewall.from
          target_field: email.from.address
          ignore_missing: true
    

    I suspect that the correct fix is to remove the rename processor entirely since email.from.address is supposed to be an array and I would guess that the from field in the Fortinet log it a single value. It would be helpful if you could provide a redacted log line from your firewall (you should be able to get this from the event.original in the failing document.

    Also, please note that the Fortinet integration is now deprecated and the fix will be into the Fortinet Fortigate integration. This is a drop-in replacement for the firewall dataset in the Fortinet integration.

  5. janniten commented on Jul 29, 2022

    @janniten
    Author

    Hi @efd6,
    Thank you for the information
    Here the event original (I' had to obfuscate some data)
    <190>date=2022-07-29 time=14:17:14 devname="FGT-Principal" devid="XXXXXXXX" eventtime=1659097034396946116 tz="+0200" logid="0814044032" type="utm" subtype="voip" eventtype="voip" level="information" vd="VDOMX" session_id=285812576 epoch=0 event_id=6939 srcip=10.1.1.2 src_port=57904 dstip=192.168.1.10 dst_port=5060 proto=6 src_int="Int1" dst_int="Int2" policy_id=314 profile="default" voip_proto="sip" kind="register" action="permit" status="succeeded" duration=0 dir="session_origin" call_id="9c7bef42-54490003-00000cd0-00004a9b@10.1.1.2" from="sip:4537@192.168.1.10" to="sip:4537@192.168.1.10"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Integration:Fortinet(Deprecated) Use one of the specific fortinet_X labels. [Integration not found in source]bugSomething isn't working, use only for issues

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions